FixVibe

// 프로브 / 스포트라이트

Next.js Header Configuration Drift

Headers set on `/` do not always protect nested routes.

What it is

Next.js makes it easy to add headers in `next.config.js`, but the source pattern decides which routes get them. A rule that protects the homepage can still miss an API route, dashboard path, or nested page.

How it happens

Next.js applies the headers in next.config.js by matching each route against a source pattern. A pattern that covers the homepage can miss nested pages, API routes, or the dashboard, so CSP, HSTS, frame protection, and nosniff quietly disappear on the routes that hold real user data. A leftover `X-Powered-By: Next.js` banner also tells attackers which framework to target.

What an attacker gets

Header drift weakens defense-in-depth exactly where real app behavior lives: dashboards, API routes, and nested pages. Missing CSP leaves XSS with fewer guardrails, missing frame protection invites clickjacking, and framework banners give attackers cleaner fingerprinting.

// what fixvibe reports

What FixVibe reports

Runs in active scans of a domain you have verified you own, on Hobby and above. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Set `poweredByHeader: false` and use broad `/:path*` header coverage for site-wide protections, with explicit exceptions only where needed. Verify root, nested, and API routes after deploy.

// 내 앱에서 직접 실행해보세요

FixVibe가 지켜보는 동안 계속 배포하세요.

Verify you own the domain, then run active checks alongside the passive ones.

능동 프로브
138
이 카테고리에서 실행되는 테스트
모듈
58
전용 능동 프로브 검사
verified domains
130+
active checks after verification
Verify your domain →

// 최신 체크 · 실용적인 수정 · 자신 있게 배포

Next.js Header Configuration Drift: what it is and how to fix it · FixVibe