merge: refresh hosting header verification contract
This commit is contained in:
@@ -4,21 +4,25 @@
|
|||||||
"index": {
|
"index": {
|
||||||
"path": "/",
|
"path": "/",
|
||||||
"cacheControl": "no-cache",
|
"cacheControl": "no-cache",
|
||||||
|
"contentTypes": ["text/html"],
|
||||||
"securityHeaders": true
|
"securityHeaders": true
|
||||||
},
|
},
|
||||||
"runtimeConfig": {
|
"runtimeConfig": {
|
||||||
"path": "/config.json",
|
"path": "/config.json",
|
||||||
"cacheControl": "no-store",
|
"cacheControl": "no-store",
|
||||||
|
"contentTypes": ["application/json"],
|
||||||
"securityHeaders": true
|
"securityHeaders": true
|
||||||
},
|
},
|
||||||
"releaseManifest": {
|
"releaseManifest": {
|
||||||
"path": "/release-manifest.json",
|
"path": "/release-manifest.json",
|
||||||
"cacheControl": "no-store",
|
"cacheControl": "no-store",
|
||||||
|
"contentTypes": ["application/json"],
|
||||||
"securityHeaders": true
|
"securityHeaders": true
|
||||||
},
|
},
|
||||||
"hashedAsset": {
|
"hashedAsset": {
|
||||||
"pathPattern": "/assets/*",
|
"pathPattern": "/assets/*",
|
||||||
"cacheControl": "public, max-age=31536000, immutable",
|
"cacheControl": "public, max-age=31536000, immutable",
|
||||||
|
"contentTypes": ["text/javascript", "application/javascript"],
|
||||||
"securityHeaders": false
|
"securityHeaders": false
|
||||||
},
|
},
|
||||||
"sourceMap": {
|
"sourceMap": {
|
||||||
|
|||||||
@@ -3,6 +3,7 @@
|
|||||||
"responses": {
|
"responses": {
|
||||||
"index": {
|
"index": {
|
||||||
"cache-control": "no-cache",
|
"cache-control": "no-cache",
|
||||||
|
"content-type": "text/html; charset=utf-8",
|
||||||
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
"x-frame-options": "DENY",
|
"x-frame-options": "DENY",
|
||||||
@@ -12,6 +13,7 @@
|
|||||||
},
|
},
|
||||||
"runtimeConfig": {
|
"runtimeConfig": {
|
||||||
"cache-control": "no-store",
|
"cache-control": "no-store",
|
||||||
|
"content-type": "application/json; charset=utf-8",
|
||||||
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
"x-frame-options": "DENY",
|
"x-frame-options": "DENY",
|
||||||
@@ -21,6 +23,7 @@
|
|||||||
},
|
},
|
||||||
"releaseManifest": {
|
"releaseManifest": {
|
||||||
"cache-control": "no-store",
|
"cache-control": "no-store",
|
||||||
|
"content-type": "application/json; charset=utf-8",
|
||||||
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
"x-frame-options": "DENY",
|
"x-frame-options": "DENY",
|
||||||
@@ -29,7 +32,8 @@
|
|||||||
"permissions-policy": "camera=(), microphone=(), geolocation=()"
|
"permissions-policy": "camera=(), microphone=(), geolocation=()"
|
||||||
},
|
},
|
||||||
"hashedAsset": {
|
"hashedAsset": {
|
||||||
"cache-control": "public, max-age=31536000, immutable"
|
"cache-control": "public, max-age=31536000, immutable",
|
||||||
|
"content-type": "text/javascript; charset=utf-8"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -20,6 +20,10 @@ The provider-independent cache defaults are:
|
|||||||
- public source maps: disabled
|
- public source maps: disabled
|
||||||
- service worker/offline cache: disabled
|
- service worker/offline cache: disabled
|
||||||
|
|
||||||
|
HTML, JSON config/manifest, and hashed JavaScript MIME types are also compared
|
||||||
|
to the declared allowlist; a cache-correct response with a mismatched
|
||||||
|
`Content-Type` still fails the hosting gate.
|
||||||
|
|
||||||
`corepack pnpm verify:hosting-headers` uses a deterministic fixture locally.
|
`corepack pnpm verify:hosting-headers` uses a deterministic fixture locally.
|
||||||
Set `HOSTING_BASE_URL` to probe deployed responses; production promotion
|
Set `HOSTING_BASE_URL` to probe deployed responses; production promotion
|
||||||
requires the artifact to report `mode: "live"`.
|
requires the artifact to report `mode: "live"`.
|
||||||
|
|||||||
@@ -15,13 +15,13 @@ let mode;
|
|||||||
if (baseUrl) {
|
if (baseUrl) {
|
||||||
mode = "live";
|
mode = "live";
|
||||||
const assets = await readdir("dist/assets");
|
const assets = await readdir("dist/assets");
|
||||||
const hashedAsset = assets.find((file) => !file.endsWith(".map"));
|
const hashedJavaScript = assets.find((file) => file.endsWith(".js"));
|
||||||
if (!hashedAsset) throw new Error("No built hashed asset found.");
|
if (!hashedJavaScript) throw new Error("No built hashed JavaScript found.");
|
||||||
const paths = {
|
const paths = {
|
||||||
index: "/",
|
index: "/",
|
||||||
runtimeConfig: "/config.json",
|
runtimeConfig: "/config.json",
|
||||||
releaseManifest: "/release-manifest.json",
|
releaseManifest: "/release-manifest.json",
|
||||||
hashedAsset: `/assets/${hashedAsset}`,
|
hashedAsset: `/assets/${hashedJavaScript}`,
|
||||||
};
|
};
|
||||||
responses = {};
|
responses = {};
|
||||||
for (const [surface, pathname] of Object.entries(paths)) {
|
for (const [surface, pathname] of Object.entries(paths)) {
|
||||||
@@ -51,6 +51,18 @@ for (const [surface, policy] of Object.entries(cachePolicy.surfaces)) {
|
|||||||
observed,
|
observed,
|
||||||
passed: observed === policy.cacheControl,
|
passed: observed === policy.cacheControl,
|
||||||
});
|
});
|
||||||
|
const observedContentType = responses[surface]?.["content-type"];
|
||||||
|
const observedMime = observedContentType
|
||||||
|
?.split(";", 1)[0]
|
||||||
|
.trim()
|
||||||
|
.toLowerCase();
|
||||||
|
results.push({
|
||||||
|
surface,
|
||||||
|
header: "content-type",
|
||||||
|
expected: policy.contentTypes,
|
||||||
|
observed: observedContentType,
|
||||||
|
passed: policy.contentTypes.includes(observedMime),
|
||||||
|
});
|
||||||
if (policy.securityHeaders) {
|
if (policy.securityHeaders) {
|
||||||
for (const [header, expected] of Object.entries(securityPolicy.headers)) {
|
for (const [header, expected] of Object.entries(securityPolicy.headers)) {
|
||||||
const observedSecurity = responses[surface]?.[header.toLowerCase()];
|
const observedSecurity = responses[surface]?.[header.toLowerCase()];
|
||||||
@@ -100,7 +112,9 @@ await writeFile(
|
|||||||
);
|
);
|
||||||
|
|
||||||
if (!passed) {
|
if (!passed) {
|
||||||
process.stderr.write("Hosting cache/security header verification failed.\n");
|
process.stderr.write(
|
||||||
|
"Hosting cache/content-type/security header verification failed.\n",
|
||||||
|
);
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
}
|
}
|
||||||
process.stdout.write(
|
process.stdout.write(
|
||||||
|
|||||||
Reference in New Issue
Block a user