// @vitest-environment node import { describe, expect, it } from "vitest"; import nextConfig from "./next.config"; describe("Next.js security headers", () => { it("applies the required browser security policy to every route", async () => { expect(nextConfig.headers).toBeTypeOf("function"); const rules = await nextConfig.headers!(); const allRoutes = rules.find((rule) => rule.source === "/:path*"); const headers = new Map( allRoutes?.headers.map(({ key, value }) => [key, value]), ); expect(headers.get("X-Content-Type-Options")).toBe("nosniff"); expect(headers.get("Referrer-Policy")).toBe("no-referrer"); expect(headers.get("X-Frame-Options")).toBe("DENY"); const csp = headers.get("Content-Security-Policy"); expect(csp).toContain("default-src 'self'"); expect(csp).toContain("object-src 'none'"); expect(csp).toContain("base-uri 'self'"); expect(csp).toContain("frame-ancestors 'none'"); expect(csp).not.toMatch(/https?:\/\//); }); });