feat(cms): keep the admin panel out of the index
X-Robots-Tag rather than the robots.txt Disallow alone, for the same reason the staging rule uses one: a Disallow blocks crawling, not indexing, so a URL found from an external link can be indexed without ever being fetched — and blocking the crawl means the noindex is never seen. Both mechanisms are applied to /admin and /cms-api. The existing CSP is frame-ancestors only, which restricts who may embed the site rather than what a page may load, so it cannot break the panel. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017YmbBhr8s7GusjDE12hrZM
This commit is contained in:
1 parent
c5a4d106da
commit
c2c76c5817
4 files changed
+48
-1
No files matched your search
@@ -88,6 +88,23 @@ const nextConfig = {
|
||||
},
|
||||
],
|
||||
},
|
||||
{
|
||||
/*
|
||||
* The admin panel and the CMS API must never be indexed.
|
||||
*
|
||||
* X-Robots-Tag, not just the robots.txt Disallow, for the same reason
|
||||
* the staging rule above uses one: a Disallow blocks crawling, which
|
||||
* is not indexing. A disallowed URL found from an external link can
|
||||
* still be indexed without ever being fetched — and worse, blocking
|
||||
* the crawl means the noindex is never seen.
|
||||
*/
|
||||
source: '/admin/:path*',
|
||||
headers: [{ key: 'X-Robots-Tag', value: 'noindex, nofollow' }],
|
||||
},
|
||||
{
|
||||
source: '/cms-api/:path*',
|
||||
headers: [{ key: 'X-Robots-Tag', value: 'noindex, nofollow' }],
|
||||
},
|
||||
{
|
||||
source: '/:path*',
|
||||
headers: [
|
||||
|
||||
Reference in new issue
Block a user