Assist_Design/apps/portal/next.config.mjs
T. Narantuya cc2a6a3046 Enhance authentication and password management features
- Added new endpoint for retrieving account status by email in AuthController.
- Implemented change password functionality with validation in AuthService.
- Updated password strength validation to require special characters across relevant DTOs.
- Introduced optional API Access Key in environment configuration for WHMCS.
- Refactored user address update logic in UsersController to improve clarity and maintainability.
- Enhanced error handling in various services to provide more user-friendly messages.
- Updated frontend components to support new password change and account status features.
2025-09-02 13:52:13 +09:00

106 lines
2.9 KiB
JavaScript

/* eslint-env node */
/* no-op */
/** @type {import('next').NextConfig} */
const nextConfig = {
// Disable Next DevTools to avoid manifest errors in dev
devtools: { enabled: false },
// Enable standalone output only for production deployment
output: process.env.NODE_ENV === "production" ? "standalone" : undefined,
// Ensure workspace package resolves/transpiles correctly in monorepo
transpilePackages: ["@customer-portal/shared"],
experimental: {
externalDir: true,
},
// Tell Next to NOT bundle these server-only libs
serverExternalPackages: [
"pino",
"pino-pretty",
"pino-abstract-transport",
"thread-stream",
"sonic-boom",
],
// Turbopack configuration (Next.js 15.5+)
turbopack: {
// Enable Turbopack optimizations
resolveAlias: {
// Path aliases for cleaner imports
"@": "./src",
},
},
// Environment variables validation
env: {
NEXT_PUBLIC_API_BASE: process.env.NEXT_PUBLIC_API_BASE,
NEXT_PUBLIC_APP_NAME: process.env.NEXT_PUBLIC_APP_NAME,
NEXT_PUBLIC_APP_VERSION: process.env.NEXT_PUBLIC_APP_VERSION,
},
// Image optimization
images: {
remotePatterns: [
{
protocol: "https",
hostname: "**",
},
],
},
// Disable ESLint blocking during production builds to avoid CI/CD failures
eslint: {
ignoreDuringBuilds: true,
},
// Security headers
async headers() {
return [
{
// Apply security headers to all routes
source: "/(.*)",
headers: [
{
key: "X-Frame-Options",
value: "DENY",
},
{
key: "X-Content-Type-Options",
value: "nosniff",
},
{
key: "Referrer-Policy",
value: "strict-origin-when-cross-origin",
},
{
key: "X-XSS-Protection",
value: "1; mode=block",
},
// Content Security Policy - development-friendly
{
key: "Content-Security-Policy",
value:
process.env.NODE_ENV === "development"
? "default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self' https: http://localhost:* ws://localhost:*; frame-ancestors 'none';"
: "default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self' https:; frame-ancestors 'none';",
},
],
},
];
},
// Production optimizations
compiler: {
// Remove console.logs in production
removeConsole: process.env.NODE_ENV === "production",
},
// Keep type checking enabled; monorepo paths provide types
typescript: { ignoreBuildErrors: false },
// Prefer Turbopack; no custom webpack override needed
};
export default nextConfig;