fix(web): 404 single-segment paths that are not registered locales - #6786
Merged
Hmbown merged 7 commits intoSep 30, 2026
Merged
Conversation
Stray single-segment paths that contain a dot (/foo.txt, /llms-full.txt) skip the middleware's locale redirect by design, then bind `[locale]` to that segment and render the shared home page as a 200 with `lang="foo.txt"` - a soft 404 for crawlers and generative-engine probes. The locale layout rejects any locale outside the routed registry with notFound(), so those URLs answer a real 404 (noindex, branded not-found page), while every registered locale, static asset, and route handler keeps its current behavior.
Resolves the conflict with 49f11f7 (main independently added the same isValidLocale/notFound guard). Kept main's import (the `Locale` type is no longer used) and this PR's fuller comment, noting main's /wp-login.php case. The PR's guard test now matches the isValidLocale import by pattern instead of the exact old import list. Tests: vitest locale-layout-guard, locale-layout, typography-contract, docs-ia, site-schema, docs-theme-contract 6 files / 35 passed; tsc --noEmit clean. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks
Contributor
Author
|
Okay, it looks like this PR duplicates the fix in #6749. I’ll leave it open for now, just for comparison and verification. If you think it should be closed, feel free to close it anytime. |
Preserve PR Hmbown#6786 and its contributor commits while consolidating its source-string assertions into the existing behavior suite. Cover six invalid segments before dictionary access, noindex metadata without home canonical links, every registered locale and text direction, and the default-locale not-found shell. Keep the dotted-path explanation at the existing production guard. Focused locale-layout/registry/middleware tests: 56 passed, 0 failed. Removing both locale guards produces 12 intended failures and 19 passes; exact source restored afterward. Full npm and check:web gates pending at this checkpoint.
Six typed-save fixtures used quiet even though the validated enum accepts normal, concise and verbose. Use concise for these writes; preserve the separate raw legacy-load coverage. Six focused config tests passed, zero failed. Shared source gate: npm test674 passed/0 failed; check:web passed. No production configuration behavior changed. Signed-off-by: Hunter B <hmbown@gmail.com>
…tracts Portable imports reject machine-bound authority settings. Keep closed-choice acceptance coverage on portable verbosity and preserve unknown existing fields. Run ordinary typed plugin activation under normal supervision rather than the 600 ms fault watchdog, and use the clippy-approved search error assertion. Validation on combined source 69824d3 plus recorded patch: CLI bundle tests 61 passed, 0 failed; typed plugin activation 1 passed; custom search fallback 1 passed. Combined all-feature CLI/TUI/workflow/workflow-js test build passed. Unrelated Calm glyph assertion remains open (TUI combined 97 passed, 1 failed). Full npm test: 740 passed, 0 failed (68 wrapper + 16 SDK + 54 extension + 602 web); check:web passed. Windows handshake scheduling remains separate, unverified. Signed-off-by: Hunter B <hmbown@gmail.com>
Windows full-suite runs on PRs6776 and6780 reported normal extension hosts missing the production five-second handshake deadline. Serialize the host fixture family across nextest processes without changing production deadlines, hang-detection tests, or retries. Nextest profile ci resolves all39 tests (35 extension-host module and4 engine callers) to max-threads1; governed focused run39/39 passed in28.901s on macOS. Exact config SHA256456e681709fe5838e404fbf537f6a934d700d0577ec15bf6a18eeae17aecde53. Full npm740/0 and check:web passed. Windows resolution still requires new hosted runs. Signed-off-by: Hunter B <hmbown@gmail.com> PR Hmbown#6786 recovery validation: npm test 767 passed, 0 failed (68 wrapper, 16 SDK, 54 extension, 629 web); check:web passed. Focused locale-layout, locale registry, and middleware tests: 56 passed, 0 failed. Removing the two locale guards produced 12 intended failures and 19 passes; exact source restored. Built local server: 17 HTTP probes passed, including dotted parent/child paths and localized missing routes as 404/noindex/no canonical, plus known pages and static assets as 200. Browser surfaces unavailable, so no visual QA claim. Shared Rust fixture validation is the separately recorded parent receipt; no Rust rebuild for this web-only change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds behavior coverage for rejecting unregistered locale segments before loading dictionaries. Dotted paths such as
/foo.txt,/llms-full.txt,/robots.json, and/foo.txt/faqbypass locale redirection for static-file compatibility; they must still receive a real 404 when no file exists.The production layout and metadata guards are already on main. This PR now clarifies that boundary and extends the existing executable layout suite instead of checking source strings: six invalid segment values, dictionary access blocked, noindex metadata without a home canonical link, all 18 registered locales and their text direction, and the default-locale shell for the root not-found boundary. The original contributor commits remain in this PR's ancestry.
Current main is merged, together with shared CI-only repairs for portable config fixtures, supported verbosity values, normal typed-plugin supervision, and serialized extension-host fixtures. Production deadlines and retry behavior are unchanged.
Validation on the prepared source:
npm test: 767 passed, 0 failed (68 wrapper, 16 SDK, 54 extension, 629 web).npm run check:webandgit diff --check: passed.No Rust runtime implementation changed in this slice; shared Rust fixture receipts were verified separately. Browser surfaces were unavailable, so responsive visual/client-render inspection remains unverified. Fresh hosted checks must pass on this PR head; no deployment or publication is included.
Original contribution by @SparkofSpike; contributor PR and commits preserved.
No-Issue: regression coverage for invalid locale segments whose runtime guard is already on main; preserves the contributor PR and validates real layout and HTTP behavior.