Files
supabase/apps/studio/scripts
Alaister Young 7f8b8dbe06 fix(studio): migrate security headers (CSP etc.) to the TanStack build
The Next build sets X-Frame-Options / X-Content-Type-Options / HSTS /
Content-Security-Policy / Referrer-Policy via next.config.ts `headers()`. The
TanStack build never carried these over — vercel.ts only set cache-control, so
the deployed dashboard shipped with no CSP.

The TanStack deploy serves a static shell (no server to attach headers), so the
headers go in the Vercel config. Add security-headers.ts as the shared source of
truth (reuses getCSP(), env-gated exactly like next.config) and:
- vercel.ts: apply to every response (source '/(.*)'), all base-path prefixes —
  full getCSP() + HSTS on platform, the deployed surface that matters.
- scripts/serve.js: apply the non-platform set (frame-ancestors 'none') for the
  self-hosted server, matching next.config's non-platform branch.

Note: font-src in the CSP is 'self' + cloudflare + supabase-assets (no
fonts.gstatic.com), so vendoring the fonts locally in the previous commit is what
keeps them CSP-compliant. X-Content-Type-Options keeps next.config's 'no-sniff'
value verbatim for parity.
2026-07-07 00:20:32 +08:00
..