- src/middleware.ts now sets HSTS, X-Content-Type-Options, X-Frame-Options,
Referrer-Policy, and Permissions-Policy on every response -- all were
absent per the 2026-09-15 audit. CSP deliberately left out: the site
uses unnoned inline scripts, inline style attributes throughout, and a
runtime-configured analytics script host, so a real CSP needs its own
pass with live testing rather than a guess.
- SiteHeader.astro and SiteFooter.astro logo alt/aria-label said 'MNQ
Catering y Eventos' (plural) while every title tag, the JSON-LD name,
og:site_name, and package.json all say 'MNQ Catering y Evento'
(singular) -- unified to the singular form used everywhere else.
mnqcatering.com was never actually registered (WHOIS: no match, no DNS
records) -- it was an intended rename that never happened. The real,
live, registered production domain is www.mnqeventos.es. Every
canonical/OG/schema/sitemap/robots reference and the host-redirect
middleware pointed at the wrong, non-resolving domain; left as-is, the
middleware would have 301'd every real visitor away to a dead host.
Also fixes two schema.org validity issues found during audit:
- '@type': 'CateringService' is not a real schema.org type -- corrected
to 'CateringBusiness' (LocalBusiness/FoodEstablishment subtype)
- 'serviceType' is a Service property, not valid on LocalBusiness --
restructured as makesOffer -> Offer -> itemOffered Service entities
- telephone normalized to E.164 in the schema block
mnqeventos.es (and the bare mnqcatering.com apex) were serving the same
content as www.mnqcatering.com with no redirect, causing duplicate
content. Add middleware that 301-redirects any request whose host isn't
exactly www.mnqcatering.com to the canonical domain, preserving path and
query.
Still needs verification at the reverse-proxy/hosting layer, since host
detection here depends on how the Host header arrives in production.