Skip to content

CrawlProof fix: [required] Redirects (301/302/308) - #41

Merged
ralyodio merged 2 commits into
masterfrom
crawlproof/fix/spec.mcp.33-2026-06-09T07-48-28
Jun 9, 2026
Merged

ralyodio merged 2 commits into
masterfrom
crawlproof/fix/spec.mcp.33-2026-06-09T07-48-28

Conversation

@crawlproof

@crawlproof crawlproof Bot commented Jun 9, 2026

Copy link
Copy Markdown

CrawlProof automated fix for the following audit finding:

[required] Redirects (301/302/308)
HTTP redirects send a client from one URL to another. Use 301 or 308 for permanent moves, 302 or 307 for temporary ones, and never chain more than necessary.

Reference: https://specification.website/spec/seo/redirects/

Check: spec.mcp.33 (priority 2)

What changed:

  • next.config.ts
  • proxy.ts

Why:
Added a declarative redirects() function to next.config.ts that permanently redirects www.crawlproof.com → crawlproof.com using status 308 (permanent, method-preserving), satisfying the spec requirement for explicit permanent redirect declarations. Also updated proxy.ts to pass an explicit 302 status code to the auth-guard NextResponse.redirect() call, making it clear that the login gate is a temporary redirect rather than relying on Next.js's implicit default.


Generated by Claude Sonnet 4.6 in agentic mode (17 tool iterations). Review the diff before merging — automated edits are not infallible. Disagree with the change? Close the PR and apply the fix manually using the audit recommendations on your CrawlProof project page.

Docs: https://crawlproof.com/docs/aeo-score

@github-actions

github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 5f19ebb into master Jun 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant