feat: 首次推送到Gitea - 完整项目代码 + 安全加固 + 知识库

This commit is contained in:
ZhuiGuangAI Dev
2026-10-02 18:52:49 +08:00
parent b44601bb66
commit 8205ae709c
1185 changed files with 49841 additions and 12802 deletions
+19 -5
View File
@@ -1,4 +1,10 @@
/** @type {import('next').NextConfig} */
import bundleAnalyzer from "@next/bundle-analyzer";
const withBundleAnalyzer = bundleAnalyzer({
enabled: process.env.ANALYZE === "true",
});
const nextConfig = {
images: {
remotePatterns: [
@@ -9,6 +15,10 @@ const nextConfig = {
],
minimumCacheTTL: 3600,
formats: ["image/avif", "image/webp"],
// 预设头像库使用本地 SVG(/avatars/*.svg),需放行 SVG 走优化器,否则 next/image 返回 400
dangerouslyAllowSVG: true,
// SVG 以 sandbox 方式渲染,禁用脚本,防止恶意 SVG 执行
contentSecurityPolicy: "default-src 'self'; script-src 'none'; sandbox;",
},
compress: true,
poweredByHeader: false,
@@ -32,7 +42,7 @@ const nextConfig = {
pagesBufferLength: 5,
},
experimental: {
optimizeCss: true,
optimizeCss: false,
},
headers: async () => {
const isDev = process.env.NODE_ENV === "development";
@@ -50,9 +60,13 @@ const nextConfig = {
{
source: "/:path*",
headers: [
{ key: "Strict-Transport-Security", value: "max-age=31536000; includeSubDomains" },
{ key: "Content-Security-Policy", value: "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' https: data:; font-src 'self'; connect-src 'self' https:; frame-ancestors 'none'" },
{ key: "Permissions-Policy", value: "camera=(), microphone=(), geolocation=()" },
{ key: "Strict-Transport-Security", value: "max-age=31536000; includeSubDomains; preload" },
{ key: "Content-Security-Policy", value: "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' https: data: blob:; font-src 'self' data:; connect-src 'self' https: wss:; frame-ancestors 'none'; base-uri 'self'; form-action 'self'" },
{ key: "Permissions-Policy", value: "camera=(), microphone=(), geolocation=(), payment=()" },
{ key: "X-Content-Type-Options", value: "nosniff" },
{ key: "X-Frame-Options", value: "DENY" },
{ key: "X-XSS-Protection", value: "1; mode=block" },
{ key: "Referrer-Policy", value: "strict-origin-when-cross-origin" },
],
},
{
@@ -83,4 +97,4 @@ const nextConfig = {
},
};
export default nextConfig;
export default withBundleAnalyzer(nextConfig);