WP-00: application foundation

Scaffolds the project: Next.js 16 App Router with strict TypeScript,
Prisma 7 on PostgreSQL 16, Tailwind 4, Vitest, Playwright, CI, and a
standalone Docker image that applies migrations on boot.

Makes the no-tracker rule of PLAN.md 3.7 enforceable rather than
stated. A per-request nonce-based CSP names no external origin, a unit
test fails if any network directive gains one, and a second test fails
if a tracking package appears in package.json. The end-to-end test
drives the standalone server the Docker image runs, not `next dev`,
so a proxy matcher that stopped matching could not pass unnoticed.

Environment is validated at import, so a missing DATABASE_URL fails at
boot with a readable message instead of surfacing later as a driver
error mid-export. ENCRYPTION_KEY is checked to be 32 bytes.

Three deviations from the plan, recorded in PLAN.md and README:
Next 16 rather than 15, `proxy.ts` rather than the now-deprecated
`middleware.ts`, and database-backed sessions rather than Auth.js v5,
which is still beta and whose JWTs would make the session revocation
required by compliance item 23 awkward.

Verified locally against PostgreSQL 16: migrations apply, extensions
created, typecheck, lint, 9 unit tests and the end-to-end header test
all pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
This commit is contained in:
Claude committed 2026-08-07 17:54:11 +00:00
1 parent 21c98f3b47
commit dd639a86f5
32 files changed
+7533 -1

No files matched your search

+30
View File
@@ -0,0 +1,30 @@
import { expect, test } from '@playwright/test';
/**
* The unit tests prove the policy builder is correct. This proves the running
* application actually sends it — a middleware matcher that quietly stops
* matching would pass every unit test and ship an unprotected app.
*/
test('les en-têtes de sécurité sont servis par l’application', async ({
request,
}) => {
const response = await request.get('/');
expect(response.status()).toBe(200);
const headers = response.headers();
const csp = headers['content-security-policy'];
expect(csp, 'aucune Content-Security-Policy servie').toBeTruthy();
expect(csp).toContain("default-src 'self'");
expect(csp).toContain("frame-ancestors 'none'");
expect(csp).toMatch(/script-src [^;]*'nonce-/);
expect(headers['x-frame-options']).toBe('DENY');
expect(headers['x-content-type-options']).toBe('nosniff');
expect(headers['referrer-policy']).toBe('no-referrer');
expect(headers['permissions-policy']).toContain('geolocation=()');
// Next.js advertises itself by default; there is no reason to tell an
// attacker which framework and version to look up.
expect(headers['x-powered-by']).toBeUndefined();
});