## 安全修复 - 修复地图标记与悬浮卡片中的存储型 XSS - 限制登录后的重定向目标为当前站点 - 提前清除邮箱确认和密码重置 URL 中的令牌 - 将 Vite 升级到 8.0.16,修复已公开的高危漏洞 - 收紧 Referrer Policy 并增加 HSTS ## 验证 - `npm audit --audit-level=low`:0 个漏洞 - `npm run build` - 6 组正常与恶意重定向用例 - 危险 DOM API 残留检查Reviewed-on: #5
37 lines
752 B
JSON
37 lines
752 B
JSON
{
|
|
"$schema": "https://openapi.vercel.sh/vercel.json",
|
|
"headers": [
|
|
{
|
|
"source": "/(.*)",
|
|
"headers": [
|
|
{
|
|
"key": "X-Frame-Options",
|
|
"value": "DENY"
|
|
},
|
|
{
|
|
"key": "X-Content-Type-Options",
|
|
"value": "nosniff"
|
|
},
|
|
{
|
|
"key": "Referrer-Policy",
|
|
"value": "strict-origin"
|
|
},
|
|
{
|
|
"key": "Strict-Transport-Security",
|
|
"value": "max-age=31536000"
|
|
},
|
|
{
|
|
"key": "Permissions-Policy",
|
|
"value": "camera=(), microphone=(), payment=(), usb=(), geolocation=(self)"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"rewrites": [
|
|
{
|
|
"source": "/(.*)",
|
|
"destination": "/index.html"
|
|
}
|
|
]
|
|
}
|