Reinstate the Vercel build settings

Reverts 61ccce5, which reverted ecbda3f. The decision came back to Vercel,
so the two platform accommodations return: output: "standalone" is
conditional on VERCEL again, and /api/import goes back to 60 seconds, the
free tier's ceiling.

The Docker path is unaffected and stays documented — including the internal
network notes and deploy/Caddyfile written in between, which remain correct
for anyone taking that road. DEPLOYMENT.md conflicted at the top and now
carries both introductions instead of one replacing the other.

Verified with VERCEL=1: builds clean and emits no standalone directory.

Stated once and recorded here rather than repeated: Vercel's Hobby plan
excludes commercial use, and this is a company's HR system. Defensible while
the database holds nothing but the 852 invented people from the seed;
Pro at $20/month is the licensed path once real personnel data is in it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-07 08:32:47 +02:00
parent 780f8fe2b7
commit d8a1fdf43b
3 changed files with 78 additions and 6 deletions

View File

@@ -44,8 +44,12 @@ function contentSecurityPolicy(): string {
const nextConfig: NextConfig = {
// Emits a self-contained .next/standalone server (only the deps actually
// used at runtime, no full node_modules) - what the Dockerfile copies in.
output: "standalone",
// used at runtime, no full node_modules) — what the Dockerfile copies in.
//
// Auf Vercel ist das falsch: dort baut die Plattform selbst und erwartet
// die übliche Ausgabe. `VERCEL` setzt sie in jeder Baustrecke, die Angabe
// entfällt dort also von selbst — und der Docker-Weg bleibt unberührt.
output: process.env.VERCEL ? undefined : "standalone",
// Baseline security headers (clickjacking, MIME-sniffing, referrer leakage,
// browser feature access) plus the report-only CSP described above.
async headers() {