withPayload() is ESM-only, so next.config.js has to become .mjs. That file also carries the rule that keeps staging out of Google's index, so the conversion goes in on its own, behind a test that asserts the rule survived — along with the standalone output, the opengraph-image font tracing and the analytics frame-ancestors CSP. Jest resolves the .mjs config without extra configuration, so jest.config.js is untouched. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017YmbBhr8s7GusjDE12hrZM
131 lines
4.4 KiB
JavaScript
131 lines
4.4 KiB
JavaScript
/** @type {import('next').NextConfig} */
|
|
const nextConfig = {
|
|
// Enable standalone output for Docker
|
|
output: 'standalone',
|
|
|
|
// app/opengraph-image.tsx reads the Schibsted Grotesk files off disk at
|
|
// request time (Satori needs a font buffer; it has no system fallback).
|
|
// File tracing currently picks these up on its own, but that relies on the
|
|
// tracer resolving a runtime join() — declare them so a Next upgrade can't
|
|
// silently drop them and turn every link preview into a 500.
|
|
outputFileTracingIncludes: {
|
|
'/opengraph-image': ['./assets/**'],
|
|
},
|
|
|
|
// The /api/* and /sitemap.xml proxies to the FastAPI backend are route
|
|
// handlers (app/api/[...path]/route.ts, app/sitemap.xml/route.ts) rather
|
|
// than rewrites, so the backend host is read from FASTAPI_URL at runtime
|
|
// instead of being baked into the build.
|
|
|
|
// Image optimization
|
|
images: {
|
|
remotePatterns: [
|
|
{ protocol: 'https', hostname: '*.tile.openstreetmap.org' },
|
|
{ protocol: 'https', hostname: 'tile.openstreetmap.org' },
|
|
{ protocol: 'https', hostname: 'cdnjs.cloudflare.com' },
|
|
],
|
|
formats: ['image/avif', 'image/webp'],
|
|
minimumCacheTTL: 31536000,
|
|
},
|
|
|
|
// Performance optimizations
|
|
compiler: {
|
|
// Remove console logs in production
|
|
removeConsole: process.env.NODE_ENV === 'production',
|
|
},
|
|
|
|
// Compression
|
|
compress: true,
|
|
|
|
// React strict mode for better error detection
|
|
reactStrictMode: true,
|
|
|
|
// Power optimizations
|
|
poweredByHeader: false,
|
|
|
|
// Production source maps (disable for smaller bundles)
|
|
productionBrowserSourceMaps: false,
|
|
|
|
// Experimental features for performance
|
|
experimental: {
|
|
// Optimize package imports
|
|
optimizePackageImports: ['chart.js', 'react-chartjs-2', 'leaflet'],
|
|
},
|
|
|
|
// Headers for caching and security
|
|
async headers() {
|
|
return [
|
|
{
|
|
/*
|
|
* Keep non-production hosts out of the index.
|
|
*
|
|
* Staging serves the same image as production off stx., so without
|
|
* this it is a full crawlable duplicate of the site.
|
|
*
|
|
* X-Robots-Tag, NOT a robots.txt Disallow. Disallow blocks crawling,
|
|
* which is not the same as blocking indexing — a disallowed URL can
|
|
* still be indexed from external links, and worse, blocking the crawl
|
|
* means Google never fetches the page and never sees a noindex at all.
|
|
* Staging therefore stays crawlable and answers "noindex" when crawled.
|
|
*
|
|
* Matched on the staging host explicitly rather than "any host that is
|
|
* not production". The inverted form is tempting because it would cover
|
|
* future environments automatically, but its failure mode is
|
|
* deindexing production if the Host header ever arrives rewritten by a
|
|
* proxy. This form's failure mode is a new environment being indexable
|
|
* until someone adds it here — recoverable, where the other is not.
|
|
*
|
|
* Any new non-production hostname must be added to this list.
|
|
*/
|
|
source: '/:path*',
|
|
has: [{ type: 'host', value: 'stx.schoolcompare.co.uk' }],
|
|
headers: [
|
|
{
|
|
key: 'X-Robots-Tag',
|
|
value: 'noindex, nofollow',
|
|
},
|
|
],
|
|
},
|
|
{
|
|
source: '/:path*',
|
|
headers: [
|
|
{
|
|
key: 'X-DNS-Prefetch-Control',
|
|
value: 'on',
|
|
},
|
|
{
|
|
// Allow the analytics subdomain (Umami heatmap/recorder) to embed
|
|
// the site while blocking all other origins. frame-ancestors is the
|
|
// modern replacement for X-Frame-Options, which cannot allow a
|
|
// specific sibling subdomain (ALLOW-FROM is deprecated/ignored).
|
|
key: 'Content-Security-Policy',
|
|
value: "frame-ancestors 'self' https://analytics.schoolcompare.co.uk",
|
|
},
|
|
{
|
|
key: 'X-Content-Type-Options',
|
|
value: 'nosniff',
|
|
},
|
|
{
|
|
key: 'Referrer-Policy',
|
|
value: 'origin-when-cross-origin',
|
|
},
|
|
],
|
|
},
|
|
{
|
|
// The mark is now the supplied raster artwork, so the favicon is
|
|
// app/icon.png rather than an SVG. Pointing this at the old path was
|
|
// caching a 404.
|
|
source: '/icon.png',
|
|
headers: [
|
|
{
|
|
key: 'Cache-Control',
|
|
value: 'public, max-age=31536000, immutable',
|
|
},
|
|
],
|
|
},
|
|
];
|
|
},
|
|
};
|
|
|
|
export default nextConfig;
|