Original Summary

Checked Search Console on a whim last week. Zero indexed pages. Zero organic clicks. My SaaS boilerplate had been live for months and Google had no record it existed. Turned out my own auth middleware was blocking it. I'd written a route protection check with an explicit allowlist of public pages (home, terms, privacy, a couple others), and everything not on that list required a login. Made sense for the app itself. Except sitemap.xml and robots.txt aren't on any allowlist by default, they're supposed to be public by convention, and my middleware didn't know that convention existed. Google tried to fetch my sitemap, got redirected to a login page, and gave up. The fix was two lines in the middleware and a robots.ts file I didn't have. Took ten minutes once I found it. Finding it took way longer, because the site looked completely fine to me, I was always logged in when I checked it. What got me is how reasonable the bug was at every step. Protect everything by default, allowlist the exceptions, that's the correct instinct for security. Nobody sits down and thinks "let me remember to explicitly unblock the sitemap." It just falls through the cracks of a pattern that's right for everything else. Anyone else find a security-conscious default that quietly broke something totally unrelated? Feels like a common shape of bug and I'm curious what versions of it other people have hit.   submitted by   /u/NatureAccording1655 [link]   [comments]


  • 情报分类:商业与市场研究
  • 分类依据:内容涉及商业、投资或市场动态
  • 信息来源:Reddit · SideProject
  • 发布时间:2026/9/15 21:45:34