fix(quick-261009-p0m): Schutz-Kopfzeilen in der Weboberfläche, X-Powered-By abgeschaltet
- next.config.ts: nosniff, Referrer-Policy, X-Frame-Options SAMEORIGIN, CSP nur frame-ancestors 'self', Permissions-Policy (Kamera, Mikrofon, Standort, Zahlung, USB), COOP same-origin-allow-popups, poweredByHeader aus - API: X-Powered-By (Express) in configureHttp abgeschaltet - Tests: next-config.test.ts, http-setup.spec.ts - Sicherheitsprotokoll (Zeilen der Außenprüfung), Entwicklungsanleitung, CHANGELOG Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
import { describe, expect, it } from 'vitest';
|
||||
import nextConfig from '../next.config';
|
||||
|
||||
/**
|
||||
* Schutz-Kopfzeilen der Weboberflaeche (quick-261009-p0m). Der Test haelt fest, dass sie fuer
|
||||
* alle Pfade gelten und dass die Zwischenablage (clipboard-write fuer "Link kopieren") nicht
|
||||
* gesperrt wird.
|
||||
*/
|
||||
describe('next.config: Schutz-Kopfzeilen', () => {
|
||||
it('sendet keinen X-Powered-By', () => {
|
||||
expect(nextConfig.poweredByHeader).toBe(false);
|
||||
});
|
||||
|
||||
it('setzt die Kopfzeilen fuer alle Pfade', async () => {
|
||||
const rules = await nextConfig.headers?.();
|
||||
expect(rules).toHaveLength(1);
|
||||
expect(rules?.[0].source).toBe('/:path*');
|
||||
const h = Object.fromEntries((rules?.[0].headers ?? []).map((x) => [x.key, x.value]));
|
||||
expect(h['X-Content-Type-Options']).toBe('nosniff');
|
||||
expect(h['Referrer-Policy']).toBe('strict-origin-when-cross-origin');
|
||||
expect(h['X-Frame-Options']).toBe('SAMEORIGIN');
|
||||
expect(h['Cross-Origin-Opener-Policy']).toBe('same-origin-allow-popups');
|
||||
});
|
||||
|
||||
it('beschraenkt die Content-Security-Policy auf frame-ancestors', async () => {
|
||||
const rules = await nextConfig.headers?.();
|
||||
const csp = rules?.[0].headers.find((x) => x.key === 'Content-Security-Policy');
|
||||
expect(csp?.value).toBe("frame-ancestors 'self'");
|
||||
});
|
||||
|
||||
it('sperrt Kamera, Mikrofon, Standort, Zahlung und USB, aber nicht die Zwischenablage', async () => {
|
||||
const rules = await nextConfig.headers?.();
|
||||
const pp = rules?.[0].headers.find((x) => x.key === 'Permissions-Policy')?.value ?? '';
|
||||
for (const f of ['camera', 'microphone', 'geolocation', 'payment', 'usb']) {
|
||||
expect(pp).toContain(`${f}=()`);
|
||||
}
|
||||
expect(pp).not.toContain('clipboard');
|
||||
expect(pp).not.toContain('fullscreen');
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user