Files
agentic-dev/apps/cms/middleware.ts
Danijel Martinek cd61b31e65 fix(cms): thread a per-request nonce through the admin CSP
The prod CSP emitted script-src 'strict-dynamic' with no nonce seed,
blocking every Payload admin script (A8). Reuse the shared nonce-based
withSecurityHeaders: Payload admin pages are always dynamically
rendered, so Next propagates the nonce read from the forwarded
request's CSP header onto the admin's scripts.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-10 17:25:04 +02:00

17 lines
760 B
TypeScript

import { withSecurityHeaders } from "@repo/core-shared/security/next";
import type { NextRequest, NextResponse } from "next/server";
// Payload's admin UI is served by this Next.js app and is always dynamically
// rendered, so the shared nonce-based middleware works here: it generates a
// per-request nonce, threads it into the CSP, and sets the CSP on the
// forwarded request headers — which is how Next propagates the nonce onto
// the admin's scripts. Without a nonce, the prod CSP's `strict-dynamic`
// script-src would block every Payload admin script.
export function middleware(request: NextRequest): NextResponse {
return withSecurityHeaders(request);
}
export const config = {
matcher: ["/((?!_next/static|_next/image|favicon.ico).*)"],
};