Repository navigation
Show CrawlProof ad units on /blog/** only - #112
Merged
Merged
Conversation
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
The auto-installer injected the embed into lib/email.ts, so the units would have rendered inside every transactional email we send (where the script never runs and the markup is just dead weight) and nowhere on the site itself. Revert that and mount the units in a /blog layout instead: it covers the index and every post, and nothing outside /blog/**. The RSS route is a route handler, so the feed stays ad-free. AdUnit re-triggers /ad.js's scan on mount — the script only auto-scans once at load, so units arriving via client-side navigation need the manual trigger it exposes. Format is left unset so each unit sizes to the column: leaderboard on desktop, mobile banner on narrow screens. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ralyodio
added a commit
that referenced
this pull request
Sep 28, 2026
…way (#330) Supabase SSR auth sets several chunked sb-*-auth-token cookies on sign-in; they overflow nginx's default proxy_buffer_size, which logs "upstream sent too big header" and turns a successful login into a 502. Same fix as the rest of dev2 (cli-tools #112). Applied to the live vhost in place, since certbot owns its TLS lines. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds the CrawlProof ad units so this site can show network ads and earn crypto for clicks — scoped to the blog.
94cd644a-bcc2-4bba-ab66-b4a89f3727cc(overridable viaNEXT_PUBLIC_AD_SLOT_ID)/blogand/blog/[slug]only, viaapp/(marketing)/blog/layout.tsx. Nothing outside/blog/**— marketing pages, the app, and email are untouched./blog/rss.xmlis a route handler, so the feed stays ad-free.Changed from the auto-installed version: the installer put the embed in
lib/email.ts, which would have shipped the markup inside every transactional email (where the script never runs) and shown nothing on the site. That's reverted.components/ads/ad-unit.tsxre-triggerswindow.crawlproofAds.scan()on mount —/ad.jsonly auto-scans once at load, so units mounted by client-side navigation need the manual trigger it exposes.Each unit renders inside a sandboxed iframe and never blocks page load. Manage the slot at https://crawlproof.com/ads/slots