mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
## Summary The `ChatGPT-User` live-fetch agent's user-facing reader hard-fails (`(400) OK`) on pages we serve it as markdown via user-agent matching, which made supabase.com blog and product pages unreadable in that assistant. I root-caused this with a controlled fetch diagnostic cross-checked against our request logs: the failing fetches never reach our origin (the failure is cached on their side), pages served as plain HTML read fine everywhere we tested, and the same failure reproduces on other major sites that serve UA-matched markdown, so the reader bug is upstream. This PR removes user-agent-based markdown serving entirely rather than special-casing one agent: UA sniffing is a guess about contractless clients whose fetchers change without notice, and this incident showed the failure mode is silent (we keep serving 200s while the user-facing agent breaks). Markdown remains available on every explicit signal — `Accept: text/markdown` q-value negotiation, explicit `.md` URLs, and llms.txt — which is the same contract-driven model the Claude fetcher already uses successfully (it sends `Accept: text/markdown, text/html, */*` and keeps receiving markdown after this change). ## Changes - Remove the `LLM_USER_AGENT` regex and the `userAgent` parameter from `negotiateMarkdown` in `packages/common/markdown-negotiation.ts`; decisions now depend only on `Accept`, the `.md` suffix, and the markdown-variant manifest - Update both consuming middlewares (`apps/www`, `apps/docs`) to the new signature; no behavior change for Accept-negotiated or `.md` requests - Add the missing `Vary: Accept` header to docs guides-md 200 responses (the www `api-v2/md` route already declares it) - Fix a pre-existing www bug surfaced in review: explicit changelog `.md` URLs rewrote to a doubled `.md.md` path (404) under a markdown-preferring `Accept`, and 406'd on a non-matching `Accept`. The www middleware now strips the `.md` suffix before slug lookup and passes `isMarkdownSuffix` into `negotiateMarkdown`, folding the separate `MD_PAGES` `.md` block into the single negotiation path (same shape as the docs middleware) - Rework tests: UA-independence suites replace the per-agent rewrite tests; a probe Accept header now 406s regardless of user agent (previously agent UAs were exempt); new changelog `.md` negotiation coverage ## Testing Tested locally: - [x] www middleware suite 36/36, docs middleware suite 17/17 - [x] typecheck green for common, www, docs Verified on the Vercel previews (www + docs) with curl: - [x] `ChatGPT-User` and `Claude-User` UA GETs on blog/pricing/guide pages return `text/html` with a default Accept - [x] Claude's real Accept (`text/markdown, text/html, */*`) still returns `text/markdown`; `Accept: text/markdown` and `.md` URLs return `text/markdown`; probe Accept returns 406 - [x] `/changelog/<slug>.md` with `Accept: text/markdown` returns the entry markdown as a direct 200 (production today detours through a 308 to the bare URL); changelog index `.md` and bare-entry Accept negotiation also verified - [x] docs guides markdown 200s carry `Vary: Accept` The intermediate commit (ChatGPT-User-only exclusion) was already verified on the preview: `ChatGPT-User` got HTML while `Accept`/`.md`/other-UA markdown was unaffected. Expected effects post-merge: UA-driven markdown volume in the request logs (~92% of md traffic) collapses to the Accept + `.md` baseline; named-agent page requests return to prerendered/static serving, reversing the extra Vercel function invocations the UA rewrite introduced; user-facing readability in the affected assistant recovers within ~24h as its fetch cache revalidates. The md-share dashboard gets a dated annotation; the ratio is not comparable across this change. ## Linear - fixes GROWTH-973 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Markdown and HTML routing now depends on the request’s `Accept` header and `.md` links, making content negotiation more predictable. * Requests that don’t accept available content now consistently return `406 Not Acceptable`, even for bot-like user agents. * Guide markdown responses now include an `Accept`-based cache variation header to improve correct caching behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
160 lines
6.3 KiB
TypeScript
160 lines
6.3 KiB
TypeScript
import { NextRequest } from 'next/server'
|
|
import { describe, expect, it } from 'vitest'
|
|
|
|
import { middleware } from './middleware'
|
|
|
|
// BASE_PATH defaults to '/docs' when NEXT_PUBLIC_BASE_PATH is unset, so test
|
|
// paths include the /docs prefix to match the middleware's GUIDES_PATH check.
|
|
function makeRequest(
|
|
path: string,
|
|
{ accept, userAgent }: { accept?: string; userAgent?: string } = {}
|
|
): NextRequest {
|
|
const headers: Record<string, string> = {}
|
|
if (accept) headers.accept = accept
|
|
if (userAgent) headers['user-agent'] = userAgent
|
|
return new NextRequest(new URL(path, 'https://supabase.com'), { headers })
|
|
}
|
|
|
|
const REWRITE_HEADER = 'x-middleware-rewrite'
|
|
const GUIDES_MD_REWRITE = (slug: string) => `https://supabase.com/docs/api/guides-md/${slug}`
|
|
|
|
describe('docs middleware — /guides/* content negotiation', () => {
|
|
it('rewrites to /api/guides-md/<slug> when Accept includes text/markdown', () => {
|
|
const req = makeRequest('/docs/guides/auth', { accept: 'text/markdown' })
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBe(GUIDES_MD_REWRITE('auth'))
|
|
})
|
|
|
|
it('rewrites /<slug>.md to /api/guides-md/<slug> regardless of Accept', () => {
|
|
for (const accept of [undefined, 'text/html']) {
|
|
const req = makeRequest('/docs/guides/auth.md', accept ? { accept } : {})
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBe(GUIDES_MD_REWRITE('auth'))
|
|
}
|
|
})
|
|
|
|
it('serves HTML for browser-style Accept', () => {
|
|
const req = makeRequest('/docs/guides/auth', {
|
|
accept: 'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8',
|
|
})
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBeNull()
|
|
})
|
|
|
|
it('serves markdown when md q-value beats html', () => {
|
|
const req = makeRequest('/docs/guides/auth', {
|
|
accept: 'text/html;q=0.5, text/markdown;q=1.0',
|
|
})
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBe(GUIDES_MD_REWRITE('auth'))
|
|
})
|
|
|
|
it('falls through to HTML when no Accept header is sent', () => {
|
|
expect(middleware(makeRequest('/docs/guides/auth')).headers.get(REWRITE_HEADER)).toBeNull()
|
|
})
|
|
|
|
it('falls through to HTML for bare Accept: */* (no explicit md preference)', () => {
|
|
const req = makeRequest('/docs/guides/auth', { accept: '*/*' })
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBeNull()
|
|
})
|
|
|
|
it('does not serve markdown when client explicitly rejects it (q=0)', () => {
|
|
const req = makeRequest('/docs/guides/auth', {
|
|
accept: 'text/markdown;q=0, text/html;q=1.0',
|
|
})
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBeNull()
|
|
})
|
|
|
|
it('tolerates OWS in q-params and clamps out-of-range q-values', () => {
|
|
// OWS around q: html wins.
|
|
const ows = makeRequest('/docs/guides/auth', {
|
|
accept: 'text/html ; q = 1.0, text/markdown ; q = 0.5',
|
|
})
|
|
expect(middleware(ows).headers.get(REWRITE_HEADER)).toBeNull()
|
|
// q=2.0 is out-of-range, falls back to default 1.0; tie -> markdown.
|
|
const oor = makeRequest('/docs/guides/auth', {
|
|
accept: 'text/html;q=2.0, text/markdown;q=1.0',
|
|
})
|
|
expect(middleware(oor).headers.get(REWRITE_HEADER)).toBe(GUIDES_MD_REWRITE('auth'))
|
|
})
|
|
|
|
it('returns 406 with Cache-Control: no-store and Vary: Accept when Accept excludes every type', () => {
|
|
const req = makeRequest('/docs/guides/auth', {
|
|
accept: 'application/x-content-negotiation-probe',
|
|
})
|
|
const res = middleware(req)
|
|
expect(res.status).toBe(406)
|
|
expect(res.headers.get('Cache-Control')).toBe('no-store')
|
|
expect(res.headers.get('Vary')).toBe('Accept')
|
|
})
|
|
|
|
it('does not 406 for .md suffix paths even with a probe Accept', () => {
|
|
const md = makeRequest('/docs/guides/auth.md', {
|
|
accept: 'application/x-content-negotiation-probe',
|
|
})
|
|
expect(middleware(md).status).not.toBe(406)
|
|
expect(middleware(md).headers.get(REWRITE_HEADER)).toBe(GUIDES_MD_REWRITE('auth'))
|
|
})
|
|
|
|
it('returns 406 for a probe Accept header regardless of user agent', () => {
|
|
const req = makeRequest('/docs/guides/auth', {
|
|
accept: 'application/x-content-negotiation-probe',
|
|
userAgent: 'Claude-User/1.0',
|
|
})
|
|
expect(middleware(req).status).toBe(406)
|
|
})
|
|
|
|
it('does not 406 on /reference/* (negotiation contract is /guides/* only)', () => {
|
|
const req = makeRequest('/docs/reference/javascript/introduction', {
|
|
accept: 'application/x-content-negotiation-probe',
|
|
})
|
|
expect(middleware(req).status).not.toBe(406)
|
|
})
|
|
|
|
it('does not rewrite for agent user agents without a markdown Accept preference', () => {
|
|
for (const ua of [
|
|
'Claude-User (claude-code/2.1.119; +https://support.anthropic.com/)',
|
|
'Claude-Web/1.0',
|
|
'PerplexityBot/1.0',
|
|
]) {
|
|
const req = makeRequest('/docs/guides/auth', { userAgent: ua })
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBeNull()
|
|
}
|
|
})
|
|
|
|
it('still serves ChatGPT-User markdown when Accept asks for it', () => {
|
|
const req = makeRequest('/docs/guides/auth', {
|
|
accept: 'text/markdown',
|
|
userAgent: 'Mozilla/5.0 (compatible; ChatGPT-User/1.0)',
|
|
})
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBe(GUIDES_MD_REWRITE('auth'))
|
|
})
|
|
|
|
it('serves HTML when Accept prefers HTML, regardless of user agent', () => {
|
|
const req = makeRequest('/docs/guides/auth', {
|
|
accept: 'text/html;q=1.0, text/markdown;q=0.1',
|
|
userAgent: 'Claude-User/1.0',
|
|
})
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBeNull()
|
|
})
|
|
|
|
it('falls through for non-LLM UAs (browsers, training crawlers, excluded agents, substring embeds)', () => {
|
|
for (const ua of [
|
|
'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36',
|
|
'GPTBot/1.0',
|
|
'ClaudeBot/1.0',
|
|
'CCBot/2.0',
|
|
'Mozilla/5.0 (compatible; ChatGPT-User/1.0)',
|
|
'chatgpt-userscript/2.0',
|
|
'NotPerplexityBot',
|
|
]) {
|
|
const req = makeRequest('/docs/guides/auth', { userAgent: ua })
|
|
expect(middleware(req).headers.get(REWRITE_HEADER)).toBeNull()
|
|
}
|
|
})
|
|
|
|
it('does not apply LLM UA rewrite to /reference/* (guides-only)', () => {
|
|
const req = makeRequest('/docs/reference/javascript/introduction', {
|
|
userAgent: 'Claude-User/1.0',
|
|
})
|
|
const rewrite = middleware(req).headers.get(REWRITE_HEADER) ?? ''
|
|
expect(rewrite).not.toContain('/api/guides-md/')
|
|
})
|
|
})
|