fix(security): resolve audit findings — logging, endpoints, contact details
- Stop logging submitted password forms to the browser console - Drive analytics from NEXT_PUBLIC_UMAMI_* instead of a hardcoded vendor script URL and site ID; renders nothing when unset - Replace the wildcard image remote host "**" with an explicit allowlist (adds DigitalOcean Spaces) - Fix the socket URL fallback to the API port (:3001, was :4000) - Replace placeholder and personal contact emails with support@re-quest.com, including the privacy policy and terms pages Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -7,18 +7,11 @@ const nextConfig: NextConfig = {
|
||||
// Image optimization
|
||||
images: {
|
||||
remotePatterns: [
|
||||
{
|
||||
protocol: "https",
|
||||
hostname: "**",
|
||||
},
|
||||
{
|
||||
protocol: "http",
|
||||
hostname: "localhost",
|
||||
},
|
||||
{
|
||||
protocol: "http",
|
||||
hostname: "127.0.0.1",
|
||||
},
|
||||
{ protocol: "https", hostname: "*.contabostorage.com" },
|
||||
{ protocol: "https", hostname: "*.amazonaws.com" },
|
||||
{ protocol: "https", hostname: "*.digitaloceanspaces.com" },
|
||||
{ protocol: "http", hostname: "localhost" },
|
||||
{ protocol: "http", hostname: "127.0.0.1" },
|
||||
],
|
||||
// Don't proxy external images through Next.js server
|
||||
// Avoids SSL cert issues with Contabo S3 (sin1.contabostorage.com)
|
||||
|
||||
Reference in New Issue
Block a user