Only follow robots.txt redirects on the same host - #2077
Open
rzo1 wants to merge 1 commit into
Open
Conversation
HttpRobotRulesParser resolved the Location header of a robots.txt redirect and re-fetched it without looking at the scheme, host or port, so the fetch could end up anywhere the redirect pointed to. The redirect is now followed only if the target uses http or https and shares scheme, host and port with the URL it was reached from, otherwise the response is handled like any other one which does not provide rules. This affects sites serving their robots.txt through a redirect to another host, e.g. a CDN: set http.robots.redirect.crosshost.allow to true to keep following those. The existing redirect test follows chains across ports of the same host and sets that option too.
rzo1
force-pushed
the
fix/robots-redirect-same-host
branch
from
August 27, 2026 12:53
3226dea to
1685474
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
HttpRobotRulesParserresolved theLocationheader of a robots.txt redirect and re-fetched it without checking scheme, host or port, so the fetch could end up on any host the redirect named. It is now followed only when the target is http or https and shares scheme, host and port with the URL it was reached from; otherwise the response is treated like any other that yields no rules.Sites serving robots.txt through a redirect to another host, a CDN for instance, are affected:
http.robots.redirect.crosshost.allow(default false) restores the old behaviour for http and https targets. Documented incrawler-default.yamlandconfiguration.adoc.For all changes
Is there a issue associated with this PR? Is it referenced in the commit message? - no issue
Does your PR title start with
#XXXXwhereXXXXis the issue number you are trying to resolve? - no issueHas your PR been rebased against the latest commit within the target branch (typically main)?
Is your initial contribution a single, squashed commit?
Is the code properly formatted with
mvn git-code-format:format-code -Dgcf.globPattern="**/*" -Dskip.format.code=false?For code changes
mvn clean verify? -coremodule tests onlyHttpRobotRulesParserRedirectTargetTest; the existing redirect test sets the new key, since its chain crosses ports