Skip to content

fix(route-rules): allow rules beat a catch-all noindex header - #337

Merged
harlan-zw merged 2 commits into
mainfrom
fix/issue-336
Oct 8, 2026
Merged

harlan-zw merged 2 commits into
mainfrom
fix/issue-336

Conversation

@harlan-zw

Copy link
Copy Markdown
Contributor

🔗 Linked issue

Closes #336

❓ Type of change

  • 📖 Documentation (updates to the documentation or readme)
  • 🐞 Bug fix (a non-breaking change that fixes an issue)
  • 👌 Enhancement (improving an existing functionality)
  • ✨ New feature (a non-breaking change that adds functionality)
  • 🧹 Chore (updates to the build process or auxiliary tools and libraries)
  • ⚠️ Breaking change (fix or feature that would cause existing functionality to change)

📚 Description

I run a default-deny config ('/**': { robots: false } plus robots: true on the public routes) and upgrading to 6.2.4 took the public pages out of the index, which issue #336 reports. The boolean rule now writes an X-Robots-Tag header while the allowed routes write nothing, so Nitro hands them the catch-all value. From the issue, on the same config:

robots 6.2.4 6.2.3
/ (prerendered) X-Robots-Tag noindex, nofollow ❌ none
sitemap.xml <loc> none ❌ /, /about
robots.txt banner (indexing disabled) ❌ (indexable)

Allow rules now emit an explicit header with robotsEnabledValue, so the more specific rule wins the route rule merge. That fixes prerendered pages, the sitemap and presets like Vercel. Static hosts send every matching _headers rule, where noindex would still beat the allow, so a noindex rule covering an allowed route drops out of the output. The robots.txt banner also stays (indexable) when an allow rule overrides the catch-all.

One tradeoff a reviewer should weigh in on: with a catch-all robots: false and an allow rule, denied routes no longer get a noindex header on static hosts. 6.2.3 behaved the same, denied pages keep the <meta name="robots"> tag, and robots.txt crawling rules still apply. When no allow rule overlaps, the 6.2.4 headers are unchanged, which the tests from #329 pin.

The resolver feeds Nitro route rules, which reach prerendered files, static hosts and the sitemap. The banner check reads the same route rules at runtime.

🤖 AI disclosure: Harlan Agent Kit modified this description. My AI open-source policy.

…er A `robots: false` catch-all emitted the disabled value while allowed routes emitted nothing, so Nitro handed them the noindex header. Prerendered pages got noindexed an
@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@nuxtjs/robots@337

commit: cef0c7e

@harlan-zw harlan-zw added harlan-agent-running An Agent holds a Task on this issue or pull request right now. harlan-agent-review-required Pull request triage requires an adversarial Review for this head commit. labels Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Nuxt logo Nuxt Module Size Analyzer

Runtime size changed.

Module Client gzip Server raw
@nuxtjs/robots 629 B 173 kB
🔴 +217 B (+0.1%)
Package files (6)

Rows overlap and include unused code. These totals do not measure deployed output or npm downloads.
Excludes dependency files, types, source maps, and other non-code files.

Package files Summed gzip Raw Δ gzip
@nuxtjs/robots · export . 7.0 kB 26 kB 🔴 +57 B (+0.8%)
@nuxtjs/robots · export ./content 292 B 503 B —
@nuxtjs/robots · export ./util 6.7 kB 25 kB —
@nuxtjs/robots · built code files 42 kB 137 kB 🔴 +163 B (+0.4%)
@nuxtjs/robots · app source files 3.3 kB 7.2 kB —
@nuxtjs/robots · server source files 9.8 kB 24 kB 🔴 +49 B (+0.5%)
Dependencies (8)

Declared dependencies. Their installed size does not show runtime cost.

Package Dependency Requested
@nuxtjs/robots @fingerprintjs/botd catalog:
@nuxtjs/robots @nuxt/kit catalog:
@nuxtjs/robots @vueuse/core catalog:
@nuxtjs/robots consola catalog:
@nuxtjs/robots defu catalog:
@nuxtjs/robots nuxt-site-config catalog:
@nuxtjs/robots nuxtseo-shared catalog:
@nuxtjs/robots ufo catalog:
How this is measured
  • Compare the same app with and without the module.
  • Client: all emitted JS/CSS, summed per-file gzip. This includes lazy chunks.
  • Server: deployed files, including external dependencies. Source maps are excluded.
  • Default module settings, Node server preset. Memory and request speed are outside this report.

Base: main @ 0cdf1bc · 2026-10-08 · differences below 16 B are ignored

@harlan-zw

harlan-zw commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor Author

🤖 MERGED

Harlan Agent Kit posted this automated review. It is not Harlan's personal review or approval. AI open source policy. Last updated: 2026-10-08 15:53 UTC.

GitHub merged this pull request.

  • Logged (45/100): Dropping an overlapping noindex rule removes the noindex header from denied non-HTML paths (API JSON, prerendered PDFs/images) on both static hosts and dynamic Nitro servers, leaving them with no indexing signal by default, a broader loss t View code
    • Ask an agent to verify and fix this finding
  • Logged (25/100): A catch-all allow rule combined with a specific deny rule now makes static hosts send contradictory duplicate X-Robots-Tag headers on the denied paths. View code
    • Ask an agent to verify and fix this finding

766ac618-5ae9-4f2e-bcca-44de7848cceb

Selected findings run after merge and open separate pull requests.

@harlan-zw harlan-zw added harlan-agent-ready The automated Review passed every gate on this head commit. and removed harlan-agent-running An Agent holds a Task on this issue or pull request right now. harlan-agent-review-required Pull request triage requires an adversarial Review for this head commit. labels Oct 6, 2026
@harlan-zw

harlan-zw commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor Author

Harlan Agent Kit posted this automated status. AI open source policy.

This release includes breaking changes. Run a manual major release. Automatic releases support patch and minor only.
Includes all unreleased changes since v6.2.4.
Checked head cef0c7ef32e87371f1bacdbf6bec726e7b6fcf3f.

@harlan-zw harlan-zw added harlan-agent-running An Agent holds a Task on this issue or pull request right now. harlan-agent-review-required Pull request triage requires an adversarial Review for this head commit. harlan-agent-ready The automated Review passed every gate on this head commit. harlan-agent-pending The automated Review is waiting on a gate for this head commit. harlan-agent-blocked The automated Review found a material defect in this head commit. and removed harlan-agent-ready The automated Review passed every gate on this head commit. harlan-agent-running An Agent holds a Task on this issue or pull request right now. harlan-agent-review-required Pull request triage requires an adversarial Review for this head commit. harlan-agent-pending The automated Review is waiting on a gate for this head commit. labels Oct 7, 2026
@harlan-zw harlan-zw added harlan-agent-running An Agent holds a Task on this issue or pull request right now. harlan-agent-blocked The automated Review found a material defect in this head commit. and removed harlan-agent-blocked The automated Review found a material defect in this head commit. harlan-agent-running An Agent holds a Task on this issue or pull request right now. labels Oct 8, 2026
@harlan-zw harlan-zw added harlan-agent-review Approve automated work for the current issue state or pull request head commit. harlan-agent-review-required Pull request triage requires an adversarial Review for this head commit. harlan-agent-running An Agent holds a Task on this issue or pull request right now. harlan-agent-ready The automated Review passed every gate on this head commit. and removed harlan-agent-review Approve automated work for the current issue state or pull request head commit. harlan-agent-blocked The automated Review found a material defect in this head commit. harlan-agent-running An Agent holds a Task on this issue or pull request right now. labels Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: 6.2.4 turns /**: { robots: false } into a noindex header that overrides robots: true routes (prerendered pages, empty sitemap)

1 participant