X-Robots-Tag rather than the robots.txt Disallow alone, for the same reason the staging rule uses one: a Disallow blocks crawling, not indexing, so a URL found from an external link can be indexed without ever being fetched — and blocking the crawl means the noindex is never seen. Both mechanisms are applied to /admin and /cms-api. The existing CSP is frame-ancestors only, which restricts who may embed the site rather than what a page may load, so it cannot break the panel. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017YmbBhr8s7GusjDE12hrZM
67 lines
2.3 KiB
TypeScript
67 lines
2.3 KiB
TypeScript
/**
|
|
* next.config.mjs carries the staging noindex rule. Breaking it turns
|
|
* stx.schoolcompare.co.uk into a fully crawlable duplicate of production,
|
|
* and nothing else in the suite would notice.
|
|
*
|
|
* The non-null assertions are deliberate: every key asserted here is optional
|
|
* on NextConfig, and a missing one is precisely the regression under test, so
|
|
* the assertion below should fail the test rather than the compile.
|
|
*/
|
|
import nextConfig from '@/next.config.mjs';
|
|
|
|
async function headerRules() {
|
|
return nextConfig.headers!();
|
|
}
|
|
|
|
describe('next.config.mjs', () => {
|
|
it('keeps the staging host out of the index', async () => {
|
|
const headers = await headerRules();
|
|
const stagingRule = headers.find((rule) =>
|
|
rule.has?.some(
|
|
(cond) => cond.type === 'host' && cond.value === 'stx.schoolcompare.co.uk',
|
|
),
|
|
);
|
|
expect(stagingRule).toBeDefined();
|
|
expect(stagingRule!.headers).toContainEqual({
|
|
key: 'X-Robots-Tag',
|
|
value: 'noindex, nofollow',
|
|
});
|
|
});
|
|
|
|
it('still emits standalone output for the Docker runner', () => {
|
|
expect(nextConfig.output).toBe('standalone');
|
|
});
|
|
|
|
it('still traces the share-card fonts into the standalone bundle', () => {
|
|
expect(nextConfig.outputFileTracingIncludes!['/opengraph-image']).toEqual([
|
|
'./assets/**',
|
|
]);
|
|
});
|
|
|
|
it('still allows the analytics subdomain to frame the site', async () => {
|
|
const headers = await headerRules();
|
|
const csp = headers
|
|
.flatMap((rule) => rule.headers)
|
|
.find((header) => header.key === 'Content-Security-Policy');
|
|
expect(csp).toBeDefined();
|
|
expect(csp!.value).toContain('https://analytics.schoolcompare.co.uk');
|
|
});
|
|
});
|
|
|
|
describe('admin surface', () => {
|
|
it('serves noindex on the admin panel and the CMS API', async () => {
|
|
// robots.txt disallows these too, but a Disallow only blocks crawling — a
|
|
// URL found from an external link can still be indexed without ever being
|
|
// fetched. This header is what actually keeps them out.
|
|
const headers = await headerRules();
|
|
for (const source of ['/admin/:path*', '/cms-api/:path*']) {
|
|
const rule = headers.find((entry) => entry.source === source);
|
|
expect(rule).toBeDefined();
|
|
expect(rule!.headers).toContainEqual({
|
|
key: 'X-Robots-Tag',
|
|
value: 'noindex, nofollow',
|
|
});
|
|
}
|
|
});
|
|
});
|