Skip to content

Only follow robots.txt redirects on the same host - #2077

Open
rzo1 wants to merge 1 commit into
mainfrom
fix/robots-redirect-same-host
Open

Only follow robots.txt redirects on the same host#2077
rzo1 wants to merge 1 commit into
mainfrom
fix/robots-redirect-same-host

Conversation

@rzo1

@rzo1 rzo1 commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

HttpRobotRulesParser resolved the Location header of a robots.txt redirect and re-fetched it without checking scheme, host or port, so the fetch could end up on any host the redirect named. It is now followed only when the target is http or https and shares scheme, host and port with the URL it was reached from; otherwise the response is treated like any other that yields no rules.

Sites serving robots.txt through a redirect to another host, a CDN for instance, are affected: http.robots.redirect.crosshost.allow (default false) restores the old behaviour for http and https targets. Documented in crawler-default.yaml and configuration.adoc.

For all changes

  • Is there a issue associated with this PR? Is it referenced in the commit message? - no issue

  • Does your PR title start with #XXXX where XXXX is the issue number you are trying to resolve? - no issue

  • Has your PR been rebased against the latest commit within the target branch (typically main)?

  • Is your initial contribution a single, squashed commit?

  • Is the code properly formatted with mvn git-code-format:format-code -Dgcf.globPattern="**/*" -Dskip.format.code=false?

For code changes

  • Have you ensured that the full suite of tests is executed via mvn clean verify? - core module tests only
  • Have you written or updated unit tests to verify your changes? - new HttpRobotRulesParserRedirectTargetTest; the existing redirect test sets the new key, since its chain crosses ports
  • If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under ASF 2.0? - no new dependencies
  • If applicable, have you updated the LICENSE file, including the main LICENSE file? - n/a
  • If applicable, have you updated the NOTICE file, including the main NOTICE file? - n/a

@rzo1 rzo1 added this to the 4.0.0 milestone Aug 27, 2026
HttpRobotRulesParser resolved the Location header of a robots.txt redirect
and re-fetched it without looking at the scheme, host or port, so the fetch
could end up anywhere the redirect pointed to. The redirect is now followed
only if the target uses http or https and shares scheme, host and port with
the URL it was reached from, otherwise the response is handled like any
other one which does not provide rules.

This affects sites serving their robots.txt through a redirect to another
host, e.g. a CDN: set http.robots.redirect.crosshost.allow to true to keep
following those.
The existing redirect test follows chains across ports of the same host and
sets that option too.
@rzo1
rzo1 force-pushed the fix/robots-redirect-same-host branch from 3226dea to 1685474 Compare August 27, 2026 12:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants