mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 04:52:50 +08:00
Searching "TsmusicBot" surfaced many deployed instances' WebUI URLs, letting strangers walk into other people's control pages (issue #128). Add defence-in-depth so crawlers stop indexing public deployments: - send `X-Robots-Tag: noindex, nofollow` on every Express response - serve `/robots.txt` with `User-agent: * / Disallow: /` - add `<meta name="robots" content="noindex, nofollow">` to index.html, which also covers the /bot/<id> dedicated-link pages (same SPA shell) These layers only prevent indexing; real protection stays with WebUI auth and the reverse proxy. Document this in the README security section and warn users not to post their WebUI link on public pages. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
33 lines
1.8 KiB
HTML
33 lines
1.8 KiB
HTML
<!DOCTYPE html>
|
|
<html lang="zh-CN">
|
|
<head>
|
|
<meta charset="UTF-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
<!-- Keep deployed instances out of search-engine indexes (issue #128:
|
|
searching "TsmusicBot" surfaced strangers' WebUI URLs). Defence in depth
|
|
alongside the server's X-Robots-Tag header and /robots.txt. Applies to
|
|
the SPA shell and every in-app route (incl. /bot/<id> dedicated links),
|
|
since they all share this single index.html. -->
|
|
<meta name="robots" content="noindex, nofollow">
|
|
<!-- Bilibili / NetEase / QQ image CDNs reject requests whose Referer is not on
|
|
their whitelist, so we must not leak a Referer cross-origin. "same-origin"
|
|
does exactly that: full Referer for our own requests, none for cross-origin
|
|
ones — so cover thumbnails (<img> AND CSS background-image) still load.
|
|
Do NOT switch this back to "no-referrer": per the WHATWG Fetch spec
|
|
("Append a request Origin header") no-referrer downgrades the Origin header
|
|
to the literal string "null" on same-origin non-GET requests. The /api/*
|
|
CSRF guard (src/web/middleware/csrf.ts) then can't parse a host from it and
|
|
responds 403 "bad origin", silently breaking EVERY POST/PUT/DELETE — QR
|
|
login, cookie save, playback controls, bot management, user admin, etc.
|
|
"same-origin" keeps the real Origin on same-origin requests, so CSRF passes. -->
|
|
<meta name="referrer" content="same-origin">
|
|
<title>TSMusicBot</title>
|
|
<link rel="preconnect" href="https://fonts.googleapis.com">
|
|
<link href="https://fonts.googleapis.com/css2?family=Barlow:wght@400;500;600;700;800&display=swap" rel="stylesheet">
|
|
</head>
|
|
<body>
|
|
<div id="app"></div>
|
|
<script type="module" src="/src/main.ts"></script>
|
|
</body>
|
|
</html>
|