From d17f75c4233d4415efdaa0ce3d4aaf4546eec8ec Mon Sep 17 00:00:00 2001 From: manue Date: Tue, 15 Sep 2026 10:31:33 +0200 Subject: [PATCH] fix(seo): add baseline security headers; unify brand name to singular - src/middleware.ts now sets HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy on every response -- all were absent per the 2026-09-15 audit. CSP deliberately left out: the site uses unnoned inline scripts, inline style attributes throughout, and a runtime-configured analytics script host, so a real CSP needs its own pass with live testing rather than a guess. - SiteHeader.astro and SiteFooter.astro logo alt/aria-label said 'MNQ Catering y Eventos' (plural) while every title tag, the JSON-LD name, og:site_name, and package.json all say 'MNQ Catering y Evento' (singular) -- unified to the singular form used everywhere else. --- src/components/SiteFooter.astro | 4 ++-- src/components/SiteHeader.astro | 4 ++-- src/middleware.ts | 23 +++++++++++++++++++++-- 3 files changed, 25 insertions(+), 6 deletions(-) diff --git a/src/components/SiteFooter.astro b/src/components/SiteFooter.astro index bfd543e..b11971a 100644 --- a/src/components/SiteFooter.astro +++ b/src/components/SiteFooter.astro @@ -7,10 +7,10 @@ const whatsappAriaLabel = 'Contactar con MNQ por WhatsApp';