From 28596952f646259ce4b2a7c72735a9a62a8bcda0 Mon Sep 17 00:00:00 2001 From: SandObserver <260779319+SandObserver@users.noreply.github.com> Date: Sat, 22 Aug 2026 19:15:07 -0400 Subject: [PATCH] Chore: add deploy configuration for static hosting Security and cache headers for the built site, and a pinned Node version so a host resolves the same toolchain the build expects. Headers were verified against the production build served with them applied: same-origin widget iframes still render and the console stays clean. --- .node-version | 1 + public/_headers | 15 +++++++++++++++ 2 files changed, 16 insertions(+) create mode 100644 .node-version create mode 100644 public/_headers diff --git a/.node-version b/.node-version new file mode 100644 index 0000000..1d9b783 --- /dev/null +++ b/.node-version @@ -0,0 +1 @@ +22.12.0 diff --git a/public/_headers b/public/_headers new file mode 100644 index 0000000..d2006af --- /dev/null +++ b/public/_headers @@ -0,0 +1,15 @@ +/* + X-Content-Type-Options: nosniff + Referrer-Policy: strict-origin-when-cross-origin + X-Frame-Options: SAMEORIGIN + Permissions-Policy: accelerometer=(), camera=(), geolocation=(), gyroscope=(), microphone=(), payment=(), usb=() + Strict-Transport-Security: max-age=31536000; includeSubDomains + +/img/* + Cache-Control: public, max-age=31536000, immutable + +/icons/* + Cache-Control: public, max-age=31536000, immutable + +/favicon.svg + Cache-Control: public, max-age=604800