Skip to content

fix: SC-HARD-01/02 workspace reconciliation & event migration; FE-HAR… - #1459

Open
Danieljyde wants to merge 1 commit into
StellarDevHub:mainfrom
Danieljyde:fix/sc-hard-01-02-fe-hard-49-50
Open

Danieljyde wants to merge 1 commit into
StellarDevHub:mainfrom
Danieljyde:fix/sc-hard-01-02-fe-hard-49-50

Conversation

@Danieljyde

Copy link
Copy Markdown

…D-49/50 CSP hardening & Dockerfile optimization

SC-HARD-01 (#1347):

  • Add automated_testing_suite and cicd_pipeline to workspace members
  • Ensure contract_events and peer_review are fully reconciled in members list
  • Remove exclude block; all 36 crates now compile under a single workspace
  • Release profile already tuned: opt-level=z, lto, strip

SC-HARD-02 (#1348):

  • Annotate all event structs in contract_events/src/lib.rs with #[contractevent]
  • Migrate hackathon-team-matching/src/lib.rs: replace symbol_short publish calls with typed #[contractevent] structs (DeveloperRegistered, TeamCreated, JoinRequested, JoinAccepted, DeveloperInvited, InvitationAccepted, TeamLeft, MemberRemoved, TeamClosed)

FE-HARD-49 (#1345):

  • Remove unsafe-inline / unsafe-eval from production CSP in middleware.ts
  • Add nonce-based script-src with strict-dynamic in production
  • Add HSTS (max-age=63072000; includeSubDomains; preload) in production
  • Add X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy hardening headers
  • Rewrite csp-config.ts: strict production policy, permissive dev policy, DOMPurify sanitizeHtml() and sanitizeText() wrappers for markdown/terminal

FE-HARD-50 (#1346):

  • Add output: standalone to next.config.ts for minimal Docker image
  • Add immutable Cache-Control headers for /_next/static and font assets
  • Fix Dockerfile: correct apk add syntax, remove redundant node_modules copy, use standalone output correctly, wget-based healthcheck
  • Add frontend/.dockerignore to exclude tests, snapshots, env files, docs

Misc:

…D-49/50 CSP hardening & Dockerfile optimization

SC-HARD-01 (StellarDevHub#1347):
- Add automated_testing_suite and cicd_pipeline to workspace members
- Ensure contract_events and peer_review are fully reconciled in members list
- Remove exclude block; all 36 crates now compile under a single workspace
- Release profile already tuned: opt-level=z, lto, strip

SC-HARD-02 (StellarDevHub#1348):
- Annotate all event structs in contract_events/src/lib.rs with #[contractevent]
- Migrate hackathon-team-matching/src/lib.rs: replace symbol_short publish calls
  with typed #[contractevent] structs (DeveloperRegistered, TeamCreated,
  JoinRequested, JoinAccepted, DeveloperInvited, InvitationAccepted,
  TeamLeft, MemberRemoved, TeamClosed)

FE-HARD-49 (StellarDevHub#1345):
- Remove unsafe-inline / unsafe-eval from production CSP in middleware.ts
- Add nonce-based script-src with strict-dynamic in production
- Add HSTS (max-age=63072000; includeSubDomains; preload) in production
- Add X-Content-Type-Options, X-Frame-Options, Referrer-Policy,
  Permissions-Policy hardening headers
- Rewrite csp-config.ts: strict production policy, permissive dev policy,
  DOMPurify sanitizeHtml() and sanitizeText() wrappers for markdown/terminal

FE-HARD-50 (StellarDevHub#1346):
- Add output: standalone to next.config.ts for minimal Docker image
- Add immutable Cache-Control headers for /_next/static and font assets
- Fix Dockerfile: correct apk add syntax, remove redundant node_modules copy,
  use standalone output correctly, wget-based healthcheck
- Add frontend/.dockerignore to exclude tests, snapshots, env files, docs

Misc:
- Update .gitignore: add .vitest-cache/, k6-results/ to snapshot/coverage block
@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

@Danieljyde Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@vercel

vercel Bot commented Sep 27, 2026

Copy link
Copy Markdown

@Danieljyde is attempting to deploy a commit to the Ayomide Adeniran's projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment