Skip to content

Chore: add deploy configuration for static hosting - #1

Merged
SandObserver merged 1 commit into
mainfrom
chore/deploy-config
Aug 22, 2026
Merged

SandObserver merged 1 commit into
mainfrom
chore/deploy-config

Conversation

@SandObserver

Copy link
Copy Markdown
Owner

Summary
Adds public/_headers with security and cache headers for the built site, and
.node-version pinning 22.12.0 so a host resolves the toolchain the build
expects.

Headers set: X-Content-Type-Options, Referrer-Policy, X-Frame-Options: SAMEORIGIN, a restrictive Permissions-Policy, and HSTS. Long immutable cache
for /img/* and /icons/*.

SAMEORIGIN rather than DENY, because the widget previews are same-origin
iframes and DENY blocks those too.

Testing
npm run build and npm run check both pass. The production build was served
with these headers applied and loaded in Chrome: all five widget iframes render
on the landing page and the Now Playing page, and the console is clean.

Checklist

  • npm run build and npm run check both pass.
  • Product UI is shown by running or capturing it, never recreated in CSS.
  • Any new preview or screenshot carries no private hostnames or real data.
  • Visual changes verified in both colour schemes and both docs themes.
  • Links to the app repo still resolve.

Security and cache headers for the built site, and a pinned Node version so a
host resolves the same toolchain the build expects.

Headers were verified against the production build served with them applied:
same-origin widget iframes still render and the console stays clean.
@SandObserver SandObserver added the github_actions Pull requests that update GitHub Actions code label Aug 22, 2026
@SandObserver
SandObserver merged commit 6cafc42 into main Aug 22, 2026
1 check passed
@SandObserver
SandObserver deleted the chore/deploy-config branch August 22, 2026 23:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant