Repository navigation
fix(route-rules): allow rules beat a catch-all noindex header - #337
Conversation
…er A `robots: false` catch-all emitted the disabled value while allowed routes emitted nothing, so Nitro handed them the noindex header. Prerendered pages got noindexed an
commit: |
|
| Module | Client gzip | Server raw |
|---|---|---|
| @nuxtjs/robots | 629 B | 173 kB 🔴 +217 B (+0.1%) |
Package files (6)
Rows overlap and include unused code. These totals do not measure deployed output or npm downloads.
Excludes dependency files, types, source maps, and other non-code files.
| Package files | Summed gzip | Raw | Δ gzip |
|---|---|---|---|
| @nuxtjs/robots · export . | 7.0 kB | 26 kB | 🔴 +57 B (+0.8%) |
| @nuxtjs/robots · export ./content | 292 B | 503 B | — |
| @nuxtjs/robots · export ./util | 6.7 kB | 25 kB | — |
| @nuxtjs/robots · built code files | 42 kB | 137 kB | 🔴 +163 B (+0.4%) |
| @nuxtjs/robots · app source files | 3.3 kB | 7.2 kB | — |
| @nuxtjs/robots · server source files | 9.8 kB | 24 kB | 🔴 +49 B (+0.5%) |
Dependencies (8)
Declared dependencies. Their installed size does not show runtime cost.
| Package | Dependency | Requested |
|---|---|---|
| @nuxtjs/robots | @fingerprintjs/botd | catalog: |
| @nuxtjs/robots | @nuxt/kit | catalog: |
| @nuxtjs/robots | @vueuse/core | catalog: |
| @nuxtjs/robots | consola | catalog: |
| @nuxtjs/robots | defu | catalog: |
| @nuxtjs/robots | nuxt-site-config | catalog: |
| @nuxtjs/robots | nuxtseo-shared | catalog: |
| @nuxtjs/robots | ufo | catalog: |
How this is measured
- Compare the same app with and without the module.
- Client: all emitted JS/CSS, summed per-file gzip. This includes lazy chunks.
- Server: deployed files, including external dependencies. Source maps are excluded.
- Default module settings, Node server preset. Memory and request speed are outside this report.
Base: main @ 0cdf1bc · 2026-10-08 · differences below 16 B are ignored
🤖 MERGED
GitHub merged this pull request.
766ac618-5ae9-4f2e-bcca-44de7848cceb Selected findings run after merge and open separate pull requests. |
This release includes breaking changes. Run a manual major release. Automatic releases support patch and minor only. |
🔗 Linked issue
Closes #336
❓ Type of change
📚 Description
I run a default-deny config (
'/**': { robots: false }plusrobots: trueon the public routes) and upgrading to 6.2.4 took the public pages out of the index, which issue #336 reports. The boolean rule now writes anX-Robots-Tagheader while the allowed routes write nothing, so Nitro hands them the catch-all value. From the issue, on the same config:/(prerendered)X-Robots-Tagnoindex, nofollow❌sitemap.xml<loc>/,/aboutrobots.txtbanner(indexing disabled)❌(indexable)Allow rules now emit an explicit header with
robotsEnabledValue, so the more specific rule wins the route rule merge. That fixes prerendered pages, the sitemap and presets like Vercel. Static hosts send every matching_headersrule, where noindex would still beat the allow, so a noindex rule covering an allowed route drops out of the output. The robots.txt banner also stays(indexable)when an allow rule overrides the catch-all.One tradeoff a reviewer should weigh in on: with a catch-all
robots: falseand an allow rule, denied routes no longer get anoindexheader on static hosts. 6.2.3 behaved the same, denied pages keep the<meta name="robots">tag, androbots.txtcrawling rules still apply. When no allow rule overlaps, the 6.2.4 headers are unchanged, which the tests from #329 pin.