Files
Claude dd639a86f5 WP-00: application foundation
Scaffolds the project: Next.js 16 App Router with strict TypeScript,
Prisma 7 on PostgreSQL 16, Tailwind 4, Vitest, Playwright, CI, and a
standalone Docker image that applies migrations on boot.

Makes the no-tracker rule of PLAN.md 3.7 enforceable rather than
stated. A per-request nonce-based CSP names no external origin, a unit
test fails if any network directive gains one, and a second test fails
if a tracking package appears in package.json. The end-to-end test
drives the standalone server the Docker image runs, not `next dev`,
so a proxy matcher that stopped matching could not pass unnoticed.

Environment is validated at import, so a missing DATABASE_URL fails at
boot with a readable message instead of surfacing later as a driver
error mid-export. ENCRYPTION_KEY is checked to be 32 bytes.

Three deviations from the plan, recorded in PLAN.md and README:
Next 16 rather than 15, `proxy.ts` rather than the now-deprecated
`middleware.ts`, and database-backed sessions rather than Auth.js v5,
which is still beta and whose JWTs would make the session revocation
required by compliance item 23 awkward.

Verified locally against PostgreSQL 16: migrations apply, extensions
created, typecheck, lint, 9 unit tests and the end-to-end header test
all pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
2026-08-07 17:54:11 +00:00

65 lines
2.1 KiB
TypeScript

import { describe, expect, it } from 'vitest';
import {
buildContentSecurityPolicy,
NETWORK_DIRECTIVES,
} from '@/lib/security/csp';
function parse(policy: string): Map<string, string[]> {
return new Map(
policy.split('; ').map((directive) => {
const [name, ...values] = directive.split(' ');
return [name ?? '', values];
}),
);
}
/** Any source that is neither a keyword, a nonce, nor a safe scheme. */
function externalOrigins(values: string[]): string[] {
return values.filter((value) => {
if (value.startsWith("'")) return false; // 'self', 'none', 'nonce-…', …
if (value === 'blob:' || value === 'data:') return false;
return true;
});
}
describe('Content-Security-Policy', () => {
const policy = buildContentSecurityPolicy({ nonce: 'dGVzdC1ub25jZQ==' });
const directives = parse(policy);
it('names no external origin on any network directive', () => {
// PLAN.md §3.7 — the audited product shipped Segment, LinkedIn Ads, Google
// Ads, DoubleClick, Clarity, Hotjar and Bugsnag. This assertion is what
// keeps that from creeping back in as a "small" addition.
for (const directive of NETWORK_DIRECTIVES) {
const values = directives.get(directive) ?? [];
expect(
externalOrigins(values),
`${directive} autorise une origine tierce`,
).toEqual([]);
}
});
it('carries the request nonce on script-src', () => {
expect(directives.get('script-src')).toContain("'nonce-dGVzdC1ub25jZQ=='");
});
it('never allows unsafe-eval outside development', () => {
expect(policy).not.toContain("'unsafe-eval'");
});
it('allows unsafe-eval in development only, for React Refresh', () => {
const devPolicy = buildContentSecurityPolicy({
nonce: 'dGVzdA==',
isDevelopment: true,
});
expect(devPolicy).toContain("'unsafe-eval'");
});
it('forbids inline scripts, framing and object embedding', () => {
expect(directives.get('script-src')).not.toContain("'unsafe-inline'");
expect(directives.get('frame-ancestors')).toEqual(["'none'"]);
expect(directives.get('object-src')).toEqual(["'none'"]);
});
});