9aced4790c
* feat(api): implement caching and logging in health check endpoint - Added in-memory caching for health check responses to reduce load on Postgres. - Introduced logging for error handling in health check. - Updated response structure to exclude error details from public responses. feat(api): enhance OAuth consent UI and scope handling - Improved consent UI to reflect exact requested scopes and added better user guidance. - Updated scope handling logic to ensure least-privilege access. - Enhanced styling for better user experience and accessibility. chore(docker): improve security and resource management in Docker setup - Updated Docker Compose configuration to enforce read-only file systems and resource limits. - Added health checks and logging options for better observability. - Introduced optional Caddy reverse proxy for TLS termination. fix(migrations): resolve ambiguity in create_company_with_owner function - Dropped orphaned 3-arg overload of create_company_with_owner function. - Recreated canonical 4-arg version with cash account seeding logic. - Ensured proper permissions for function execution in Postgres. * feat: enhance security checks for team membership in company creation
12 lines
466 B
Caddyfile
12 lines
466 B
Caddyfile
{$DOMAIN} {
|
|
reverse_proxy app:3000
|
|
|
|
# HSTS: lock clients onto HTTPS for one year.
|
|
# `preload` is intentionally omitted — submission to browser preload lists
|
|
# is irreversible on short timescales (months of lead time to remove a
|
|
# domain). Operators who want preload eligibility can add the directive
|
|
# after committing to HTTPS-only permanently and submitting via
|
|
# hstspreload.org.
|
|
header Strict-Transport-Security "max-age=31536000; includeSubDomains"
|
|
}
|