/** @type {import('next').NextConfig} */ const nextConfig = { experimental: { serverComponentsExternalPackages: ["bcryptjs"], }, async headers() { const corsOrigin = process.env.CORS_ORIGIN || "*"; const primaryOrigin = corsOrigin.includes(",") ? corsOrigin.split(",")[0].trim() : corsOrigin; return [ { source: "/api/(.*)", headers: [ { key: "Access-Control-Allow-Origin", value: primaryOrigin }, { key: "Access-Control-Allow-Methods", value: "GET,POST,PUT,PATCH,DELETE,OPTIONS" }, { key: "Access-Control-Allow-Headers", value: "Content-Type, Authorization, x-csrf-token" }, { key: "Access-Control-Allow-Credentials", value: "true" }, { key: "Vary", value: "Origin" }, ], }, { source: "/(.*)", headers: [ { key: "X-Content-Type-Options", value: "nosniff" }, { key: "X-Frame-Options", value: "SAMEORIGIN" }, { key: "X-XSS-Protection", value: "1; mode=block" }, { key: "Referrer-Policy", value: "strict-origin-when-cross-origin" }, ], }, { source: "/pdf.worker.min.mjs", headers: [ { key: "Content-Type", value: "application/javascript" }, ], }, ]; }, webpack: (config) => { config.resolve.alias.canvas = false; config.module.rules.push({ test: /pdf\.mjs$/, include: /node_modules[\\/]pdfjs-dist/, type: "javascript/auto", resolve: { fullySpecified: false }, }); return config; }, }; export default nextConfig;