import { defineMiddleware } from 'astro:middleware'; const CANONICAL_HOST = 'www.mnqeventos.es'; /** * SEO: enforce the canonical host at the application layer. www.mnqeventos.es * is the real, registered, live production domain. mnqcatering.com was an * intended rename that was never actually registered (confirmed via WHOIS — * no match) — do NOT set CANONICAL_HOST back to it unless that domain is * actually purchased and its DNS points at this server, or this redirect * will send every visitor to a host that doesn't resolve. * * NOTE: this must also be verified at the reverse-proxy/hosting layer — host * detection here depends on how the Host header (or X-Forwarded-Host, when * behind a proxy) actually arrives in production. If the proxy doesn't * forward the original host, this check will see the wrong value. */ export const onRequest = defineMiddleware(async (context, next) => { const requestHost = context.url.host; if (requestHost !== CANONICAL_HOST) { const redirectUrl = new URL(context.url.pathname + context.url.search, `https://${CANONICAL_HOST}`); return context.redirect(redirectUrl.toString(), 301); } const response = await next(); // Baseline security headers (flagged missing in the 2026-09-15 SEO/security // audit — no HSTS, X-Content-Type-Options, X-Frame-Options, or // Referrer-Policy were present on any response). // // Deliberately NOT setting Content-Security-Policy here: the site relies on // inline