fix(seo): add baseline security headers; unify brand name to singular
- src/middleware.ts now sets HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy on every response -- all were absent per the 2026-09-15 audit. CSP deliberately left out: the site uses unnoned inline scripts, inline style attributes throughout, and a runtime-configured analytics script host, so a real CSP needs its own pass with live testing rather than a guess. - SiteHeader.astro and SiteFooter.astro logo alt/aria-label said 'MNQ Catering y Eventos' (plural) while every title tag, the JSON-LD name, og:site_name, and package.json all say 'MNQ Catering y Evento' (singular) -- unified to the singular form used everywhere else.
This commit is contained in:
@@ -7,10 +7,10 @@ const whatsappAriaLabel = 'Contactar con MNQ por WhatsApp';
|
||||
<div class="footer-inner">
|
||||
|
||||
<div class="footer-brand">
|
||||
<a href="/" aria-label="MNQ Catering y Eventos">
|
||||
<a href="/" aria-label="MNQ Catering y Evento">
|
||||
<img
|
||||
src="/images/logo-secondary.webp"
|
||||
alt="MNQ Catering y Eventos"
|
||||
alt="MNQ Catering y Evento"
|
||||
width="224"
|
||||
height="224"
|
||||
style="height: 3.5rem; width: auto; mix-blend-mode: multiply; margin-bottom: 1rem;"
|
||||
|
||||
@@ -17,10 +17,10 @@ const links = [
|
||||
<header class="site-header">
|
||||
<div class="page-wrap">
|
||||
|
||||
<a href="/" class="site-brand-link" aria-label="MNQ Catering y Eventos — inicio">
|
||||
<a href="/" class="site-brand-link" aria-label="MNQ Catering y Evento — inicio">
|
||||
<img
|
||||
src="/images/logo-nav-dark.webp"
|
||||
alt="MNQ Catering y Eventos"
|
||||
alt="MNQ Catering y Evento"
|
||||
class="site-logo-banner"
|
||||
width="600"
|
||||
height="232"
|
||||
|
||||
+21
-2
@@ -15,7 +15,7 @@ const CANONICAL_HOST = 'www.mnqeventos.es';
|
||||
* behind a proxy) actually arrives in production. If the proxy doesn't
|
||||
* forward the original host, this check will see the wrong value.
|
||||
*/
|
||||
export const onRequest = defineMiddleware((context, next) => {
|
||||
export const onRequest = defineMiddleware(async (context, next) => {
|
||||
const requestHost = context.url.host;
|
||||
|
||||
if (requestHost !== CANONICAL_HOST) {
|
||||
@@ -23,5 +23,24 @@ export const onRequest = defineMiddleware((context, next) => {
|
||||
return context.redirect(redirectUrl.toString(), 301);
|
||||
}
|
||||
|
||||
return next();
|
||||
const response = await next();
|
||||
|
||||
// Baseline security headers (flagged missing in the 2026-09-15 SEO/security
|
||||
// audit — no HSTS, X-Content-Type-Options, X-Frame-Options, or
|
||||
// Referrer-Policy were present on any response).
|
||||
//
|
||||
// Deliberately NOT setting Content-Security-Policy here: the site relies on
|
||||
// inline <script> blocks (no nonce/hash setup), inline style="" attributes
|
||||
// throughout every page, and an optional analytics script loaded from a
|
||||
// runtime-configured host (PUBLIC_UMAMI_URL). A CSP tight enough to matter
|
||||
// would need nonces wired through every inline script/style or it will
|
||||
// silently break rendering/interactivity in production. Needs its own pass
|
||||
// with live testing, not a guess baked in here.
|
||||
response.headers.set('Strict-Transport-Security', 'max-age=63072000; includeSubDomains; preload');
|
||||
response.headers.set('X-Content-Type-Options', 'nosniff');
|
||||
response.headers.set('X-Frame-Options', 'DENY');
|
||||
response.headers.set('Referrer-Policy', 'strict-origin-when-cross-origin');
|
||||
response.headers.set('Permissions-Policy', 'camera=(), microphone=(), geolocation=()');
|
||||
|
||||
return response;
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user