frontmcp.config server settings --- they are injected as environment variables at build time and read by the built-in middleware.
Quick Start
Add security headers tofrontmcp.config.ts:
CSP Configuration
Example Directives
Security Headers
X-Content-Type-Options: nosniff and X-Frame-Options: DENY are applied by default even without explicit configuration. Set them to empty strings to disable.Environment Variables
All settings are injected as environment variables at build time by the deployment adapter:
You can override these at runtime without rebuilding:
Programmatic Access
For custom middleware or adapters, use the security header functions directly:Report-Only Mode
UsereportOnly: true to test CSP rules without blocking content:
Content-Security-Policy-Report-Only header instead of Content-Security-Policy, allowing you to monitor violations before enforcing the policy.
Related
Configuration File
Full configuration reference
Production Build
Build and deploy for production