mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 11:25:06 +03:00
The Next build sets X-Frame-Options / X-Content-Type-Options / HSTS / Content-Security-Policy / Referrer-Policy via next.config.ts `headers()`. The TanStack build never carried these over — vercel.ts only set cache-control, so the deployed dashboard shipped with no CSP. The TanStack deploy serves a static shell (no server to attach headers), so the headers go in the Vercel config. Add security-headers.ts as the shared source of truth (reuses getCSP(), env-gated exactly like next.config) and: - vercel.ts: apply to every response (source '/(.*)'), all base-path prefixes — full getCSP() + HSTS on platform, the deployed surface that matters. - scripts/serve.js: apply the non-platform set (frame-ancestors 'none') for the self-hosted server, matching next.config's non-platform branch. Note: font-src in the CSP is 'self' + cloudflare + supabase-assets (no fonts.gstatic.com), so vendoring the fonts locally in the previous commit is what keeps them CSP-compliant. X-Content-Type-Options keeps next.config's 'no-sniff' value verbatim for parity.