{"_id":"@drkaachen/next-site-runtime","_rev":"4-016e255041452b71e42bba0bbfa6a171","name":"@drkaachen/next-site-runtime","dist-tags":{"latest":"1.2.1"},"versions":{"1.0.1":{"name":"@drkaachen/next-site-runtime","version":"1.0.1","license":"MIT","_id":"@drkaachen/next-site-runtime@1.0.1","maintainers":[{"name":"alikilicaslan","email":"ali.kilicaslan@drk-aachen.de"}],"homepage":"https://github.com/DRKAachen/drk-design-system/tree/main/packages/next-site-runtime","bugs":{"url":"https://github.com/DRKAachen/drk-design-system/issues"},"dist":{"shasum":"c3dcfafb746e2cbbcf1752cf1dd3935ea2372165","tarball":"https://registry.npmjs.org/@drkaachen/next-site-runtime/-/next-site-runtime-1.0.1.tgz","fileCount":5,"integrity":"sha512-XDMb5c0MtfpIof0CYbxuy4IRct/Ytx8Ef0cPOgVuhY2lfSiwvdYuIsLyPSAs7bZNuOgilQkNccfMN26yPQj+Aw==","signatures":[{"sig":"MEUCIARo2nJ+jKzUwnMQEDz+Bx0iUFYqfG30wM7azeu93b5wAiEArRxcRXyBIXSd5PKdcUzd0fMHCqgb4cnKW9r+hh4rAq8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@drkaachen%2fnext-site-runtime@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5830},"main":"./index.ts","types":"./index.ts","exports":{".":"./index.ts","./lib/*":"./lib/*","./middleware":"./middleware.ts"},"gitHead":"46a94dba99e32a65d90d2f45e680305ffeb2670f","private":false,"scripts":{"typecheck":"tsc --noEmit"},"_npmUser":{"name":"alikilicaslan","email":"ali.kilicaslan@drk-aachen.de"},"repository":{"url":"git+https://github.com/DRKAachen/drk-design-system.git","type":"git"},"_npmVersion":"11.9.0","description":"Optional Next.js site runtime helpers for DRK apps","directories":{},"_nodeVersion":"24.14.0","dependencies":{"@drkaachen/content-sanity":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"peerDependencies":{"next":">=14.0.0","react":">=18.0.0","react-dom":">=18.0.0"},"_npmOperationalInternal":{"tmp":"tmp/next-site-runtime_1.0.1_1772714123559_0.709769609121307","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@drkaachen/next-site-runtime","version":"1.1.1","license":"MIT","_id":"@drkaachen/next-site-runtime@1.1.1","maintainers":[{"name":"afielen","email":"axel.fielen@drk-aachen.de"},{"name":"alikilicaslan","email":"ali.kilicaslan@drk-aachen.de"}],"homepage":"https://github.com/DRKAachen/drk-design-system/tree/main/packages/next-site-runtime","bugs":{"url":"https://github.com/DRKAachen/drk-design-system/issues"},"dist":{"shasum":"50d851366f5e601a8e84afd6339a5a6a2c173b5c","tarball":"https://registry.npmjs.org/@drkaachen/next-site-runtime/-/next-site-runtime-1.1.1.tgz","fileCount":5,"integrity":"sha512-14po0Bzu7BIp1ovW+Mgf7TJpKgHbFtFAUb5Eae2jemm43shRxQOVgJQvl5qQAlhDw0vgRKGYPxA+WDAMmpt7KQ==","signatures":[{"sig":"MEUCIQC8h17z/qM7hqNfqwjzjxNN+Ioblf2Re4TBRp0PFcDcLwIgIi4u7g2YSsqIvInPRFytCZPLY5/BWIHARXjQ4v6cZ/o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@drkaachen%2fnext-site-runtime@1.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":8563},"main":"./index.ts","types":"./index.ts","exports":{".":"./index.ts","./lib/*":"./lib/*","./middleware":"./middleware.ts"},"gitHead":"0995b7523a95586042332ad00ab4f0ce59e9e302","private":false,"scripts":{"typecheck":"tsc --noEmit"},"_npmUser":{"name":"alikilicaslan","email":"ali.kilicaslan@drk-aachen.de"},"repository":{"url":"git+https://github.com/DRKAachen/drk-design-system.git","type":"git"},"_npmVersion":"11.9.0","description":"Optional Next.js site runtime helpers for DRK apps","directories":{},"_nodeVersion":"24.14.0","dependencies":{"@drkaachen/content-sanity":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"peerDependencies":{"next":">=14.0.0","react":">=18.0.0","react-dom":">=18.0.0"},"_npmOperationalInternal":{"tmp":"tmp/next-site-runtime_1.1.1_1772796419679_0.5129210147277188","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@drkaachen/next-site-runtime","version":"1.2.1","description":"Optional Next.js site runtime helpers for DRK apps","repository":{"type":"git","url":"git+https://github.com/DRKAachen/drk-design-system.git"},"homepage":"https://github.com/DRKAachen/drk-design-system/tree/main/packages/next-site-runtime","private":false,"license":"MIT","main":"./index.ts","types":"./index.ts","exports":{".":"./index.ts","./middleware":"./middleware.ts","./lib/*":"./lib/*"},"publishConfig":{"access":"public"},"peerDependencies":{"next":">=14.0.0","react":">=18.0.0","react-dom":">=18.0.0"},"dependencies":{"@drkaachen/content-sanity":"^1.0.0"},"scripts":{"typecheck":"tsc --noEmit"},"gitHead":"1c92f5e60ef7f0251917de3da11462a2df8aab10","_id":"@drkaachen/next-site-runtime@1.2.1","bugs":{"url":"https://github.com/DRKAachen/drk-design-system/issues"},"_nodeVersion":"24.14.0","_npmVersion":"11.9.0","dist":{"integrity":"sha512-yKHrjXSXP0kWVSp2q+5Dx2iKgpn7oryEZYRYmF4tm8rYENxEOvzNrtGvtb4udJmLP3kzIKzbsTbk1QiMDlAhhQ==","shasum":"55dd7e86e76c197f34ae3ebab9be0500b6d2a1fd","tarball":"https://registry.npmjs.org/@drkaachen/next-site-runtime/-/next-site-runtime-1.2.1.tgz","fileCount":5,"unpackedSize":8563,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@drkaachen%2fnext-site-runtime@1.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCVDKYEBgKrKx+ZGiRD4ygKJqrCzQuNN8MeFedM5EtLIAIhANQv6ioJg5u/PJlCQZv+YUzlIcfhYpupBbY+6+nZ8lIT"}]},"_npmUser":{"name":"alikilicaslan","email":"ali.kilicaslan@drk-aachen.de"},"directories":{},"maintainers":[{"name":"afielen","email":"axel.fielen@drk-aachen.de"},{"name":"alikilicaslan","email":"ali.kilicaslan@drk-aachen.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/next-site-runtime_1.2.1_1773142103882_0.11353180710011457"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-05T12:35:23.190Z","modified":"2026-03-10T11:28:24.381Z","1.0.1":"2026-03-05T12:35:23.711Z","1.1.1":"2026-03-06T11:26:59.808Z","1.2.1":"2026-03-10T11:28:24.041Z"},"bugs":{"url":"https://github.com/DRKAachen/drk-design-system/issues"},"license":"MIT","homepage":"https://github.com/DRKAachen/drk-design-system/tree/main/packages/next-site-runtime","repository":{"type":"git","url":"git+https://github.com/DRKAachen/drk-design-system.git"},"description":"Optional Next.js site runtime helpers for DRK apps","maintainers":[{"name":"afielen","email":"axel.fielen@drk-aachen.de"},{"name":"alikilicaslan","email":"ali.kilicaslan@drk-aachen.de"}],"readme":"# @drkaachen/next-site-runtime\n\nOptional Next.js runtime helpers for DRK multi-site apps.\n\nThis package contains:\n- Next middleware for hostname-based site resolution\n- request header propagation (`x-site-id`, `x-site-hostname`)\n- helper functions to read site headers in Next server contexts\n\n## When to use\n\nUse this package if your app needs centralized multi-site hostname handling in middleware.\n\nIf your app does not need middleware/site routing features, do not install this package.\n\n## Installation\n\n```bash\nnpm install @drkaachen/next-site-runtime\n```\n\nThis package expects `@drkaachen/content-sanity` to be available for site lookup.\n\n## Middleware Setup\n\nCreate a `middleware.ts` file in your consuming app root:\n\n```ts\nexport { middleware, config } from '@drkaachen/next-site-runtime/middleware'\n```\n\n## Runtime Helpers\n\n```ts\nimport {\n  getSiteIdFromHeaders,\n  getSiteHostnameFromHeaders,\n  getSiteHostname,\n} from '@drkaachen/next-site-runtime'\n```\n\n## Environment Variables\n\nOptional but recommended for hardened deployments:\n- `ALLOWED_SITE_HOSTNAMES` (comma-separated allowlist, e.g. `example.de,www.example.de`)\n\nBehavior:\n- if `ALLOWED_SITE_HOSTNAMES` is set, only listed hostnames are accepted\n- if not set, all normalized hostnames are allowed\n\n## Request Flow\n\n1. Middleware reads incoming host headers\n2. Hostname is normalized and validated\n3. Site is loaded via `@drkaachen/content-sanity`\n4. Site headers are attached to the forwarded request\n\n## Boundaries\n\n- Keep framework/runtime concerns here, not in UI package.\n- Keep CMS query/client concerns in `@drkaachen/content-sanity`.\n- Keep presentational components and styles in `@drkaachen/design-system-ui`.\n\n## Security Notes\n\n- Use explicit hostname allowlists in production to reduce host-header abuse risks.\n- Do not trust forwarded host headers without normalization and allowlist checks.\n\n## Security Configuration\n\nWhen deploying behind a reverse proxy (e.g. nginx, Cloudflare, AWS ALB), additional configuration is required to ensure secure header handling.\n\n### TRUST_PROXY\n\nSet `TRUST_PROXY=true` in your environment when the application runs behind a reverse proxy. This tells the middleware to trust the `x-forwarded-host` header for hostname resolution instead of relying solely on the `Host` header.\n\n**Without `TRUST_PROXY=true`**, the middleware ignores `x-forwarded-host` entirely, which means hostname resolution may fail or resolve incorrectly when behind a proxy.\n\n### ALLOWED_SITE_HOSTNAMES\n\nSet `ALLOWED_SITE_HOSTNAMES` to a comma-separated list of hostnames that your deployment serves. This acts as a strict allowlist — any request whose resolved hostname does not match the list is rejected.\n\n```\nALLOWED_SITE_HOSTNAMES=www.example.de,example.de,staging.example.de\n```\n\nIn production, always set this variable to prevent host-header injection attacks.\n\n### Header stripping\n\nThe middleware strips any incoming `x-site-id` and `x-site-hostname` headers before processing the request and setting its own values. This prevents upstream clients or attackers from spoofing site identity by injecting these headers into requests.\n\n### Reverse proxy requirements\n\nYour reverse proxy **must** be configured to strip the `x-forwarded-host` header from untrusted client requests before forwarding them to the application. If untrusted clients can set `x-forwarded-host` and `TRUST_PROXY=true` is enabled, they could influence hostname resolution.\n\nExample nginx configuration:\n\n```nginx\nproxy_set_header X-Forwarded-Host $host;\n```\n\nThis overwrites any client-supplied `X-Forwarded-Host` with the actual host, preventing spoofing.\n","readmeFilename":"README.md"}