Skip to content

fix(nextjs): withBotProtection honours mode and monitors by default - #55

Merged
cport1 merged 1 commit into
mainfrom
fix/nextjs-withbotprotection-mode
Sep 29, 2026
Merged

cport1 merged 1 commit into
mainfrom
fix/nextjs-withbotprotection-mode

Conversation

@cport1

@cport1 cport1 commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

withBotProtection ignored mode and returned 403 for any request protect() didn't allow. withWebDecoy and every other adapter monitor by default, so a Pages API route wrapped without a mode was blocking from install.

  • Fix: monitor is now the default. The handler runs and req.webdecoyDecision.allowed records what enforce would have done. mode: 'enforce' refuses the request.
  • Test: with-bot-protection.test.ts covers both modes. I confirmed it fails without the fix.
  • Docs: CHANGELOG and openwiki updated.

Behaviour change: anyone who relied on the wrapper blocking needs to add mode: 'enforce'. The CHANGELOG says so.

All tests pass: 566 across 6 packages. Lint and the edge check pass.

It ignored mode and refused any request protect() did not allow, while
withWebDecoy and every other adapter monitor by default. A Pages API route
wrapped with no mode was blocking on install. It now runs the handler in
monitor mode with the verdict on req.webdecoyDecision; mode: 'enforce'
refuses.
@cport1
cport1 merged commit 65fdf6a into main Sep 29, 2026
2 checks passed
@cport1
cport1 deleted the fix/nextjs-withbotprotection-mode branch September 29, 2026 17:11
@cport1 cport1 mentioned this pull request Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant