refactor: migrate backend to pnpm monorepo with Hono module architecture
- Replace Bun with pnpm 9 + Turborepo + tsx; apps/api renamed to apps/backend - Split backend into http/, modules/, lib/ layers mirroring tai-specguard - Add use-case + Result pattern, Problem Details RFC 7807, basePath /api/v1 - Mount Better Auth at /api/v1/auth, keep session-auth whitelist - Split Prisma schema into prisma/models/*, generate into generated/ - Rework packages/shared into lib/ + schemas/ with pagination DTOs - Implement health, groups, students, payments, waitlist modules - Add vitest suite with prisma mocks (21 tests), biome lint - Point web client to /api/v1/auth and /api/v1/groups/from-organization
This commit is contained in:
34
apps/backend/src/http/security-headers.ts
Normal file
34
apps/backend/src/http/security-headers.ts
Normal file
@@ -0,0 +1,34 @@
|
||||
import type { MiddlewareHandler } from 'hono';
|
||||
import { cors as honoCors } from 'hono/cors';
|
||||
|
||||
function getWebOrigin(): string {
|
||||
return process.env.WEB_URL ?? 'http://localhost:6173';
|
||||
}
|
||||
|
||||
export const corsMiddleware: MiddlewareHandler = honoCors({
|
||||
origin: (requestOrigin) => {
|
||||
const allowed = getWebOrigin();
|
||||
if (requestOrigin === allowed) {
|
||||
return requestOrigin;
|
||||
}
|
||||
return '';
|
||||
},
|
||||
allowMethods: ['GET', 'POST', 'PUT', 'PATCH', 'DELETE', 'OPTIONS'],
|
||||
allowHeaders: ['Content-Type', 'Authorization'],
|
||||
maxAge: 600,
|
||||
credentials: true,
|
||||
});
|
||||
|
||||
export const securityHeadersMiddleware: MiddlewareHandler = async (c, next) => {
|
||||
await next();
|
||||
|
||||
c.header('X-Content-Type-Options', 'nosniff');
|
||||
c.header('X-Frame-Options', 'DENY');
|
||||
c.header('X-XSS-Protection', '0');
|
||||
c.header('Referrer-Policy', 'strict-origin-when-cross-origin');
|
||||
c.header('Permissions-Policy', 'camera=(), microphone=(), geolocation=()');
|
||||
|
||||
if (process.env.NODE_ENV === 'production') {
|
||||
c.header('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
|
||||
}
|
||||
};
|
||||
Reference in New Issue
Block a user