sfnext-security
Configure Storefront Next security response headers, Content Security Policy (CSP), CSP contributors, Cloudflare Turnstile bot protection, and the shared cookie domain. Use for "Refused to load the script/connect/image" CSP violations, adding a third-party origin, app.security.headers, defaultCspDirectives, csp reportOnly rollout, writing a CSP contributor under src/middlewares/csp-contributors, HSTS or Permissions-Policy, Turnstile widget or enforceTurnstile, TURNSTILE_SECRET_KEYS, log-only rollout, or app.cookies.domain across subdomains. Do not use for auth tokens, cookie names or login flows (use storefront-next:sfnext-authentication), SFRA proxy routing (use storefront-next:sfnext-hybrid-storefronts), or consent banners and tracking (use storefront-next:sfnext-analytics-consent).
Pinned to revision 0d6b966d3aa9, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/sfnext-security/SKILL.md
- skills/sfnext-security/evals/trigger-evals.json
- skills/sfnext-security/references/COOKIE-DOMAIN.md
- skills/sfnext-security/references/TURNSTILE.md
Every link opens the file at its source, pinned to the revision this page describes.