Ignore bogus Next-Action probes that spam admin-ui logs.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jos Vooges | STH 2026-09-03 02:05:51 +02:00
parent a6a922bf05
commit 227dee4a53

View file

@ -0,0 +1,24 @@
import { NextRequest, NextResponse } from "next/server";
/**
* Admin UI uses client-side fetch only — no Server Actions.
* Bots/scanners probe with Next-Action headers ("action", "x", "0", …)
* and spam Next.js logs. Reject those early without logging noise.
*/
export function middleware(request: NextRequest) {
const actionId = request.headers.get("next-action");
if (actionId) {
return new NextResponse(null, { status: 404 });
}
return NextResponse.next();
}
export const config = {
matcher: [
/*
* Run on all paths except static assets and the API proxy.
* API proxy must stay untouched for real admin traffic.
*/
"/((?!api|_next/static|_next/image|favicon.ico|sw.js|manifest.webmanifest|icons/).*)",
],
};