Treat website meta tags as label + full HTML snippets.

Public business-info now exposes metaTags as { html }, matching how admins paste complete <meta> tags in Tags & Badges.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Alireza Hassani
2026-10-03 18:39:19 +03:30
co-authored by Cursor
parent 63ae9b22b9
commit e0cd2327eb
7 changed files with 88 additions and 36 deletions
+3 -3
View File
@@ -336,13 +336,13 @@ These are **required on every crawlable page** (home, listing, product/blog/port
Business admins configure this under **Website → Tags & Badges**. Business admins configure this under **Website → Tags & Badges**.
1. `GET /tenants/{domain}/website/business-info` 1. `GET /tenants/{domain}/website/business-info`
2. For each item in `metaTags` (array of `{ name, content }`), emit once in the root layout `<head>`: 2. For each item in `metaTags` (array of `{ html }`), emit the full HTML once in the root layout `<head>`.
```html ```html
<meta name="{name}" content="{content}"> {html}
``` ```
In Next.js App Router, map them into `generateMetadata()` → `other: { [name]: content }`. Verification metas (eNamad, Google, etc.) belong here as custom name/value rows. Example `html` value: `<meta name="google-site-verification" content="…">` (also supports `property`, `http-equiv`, etc.). Parse attributes into a `<meta />` element, or inject the sanitized string into `<head>`. Do **not** wrap it again as `name`/`content` — `html` is already the whole tag. The dashboard “Name” field is an admin label only and is **not** in this public payload.
3. For each item in `trustBadges` (array of `{ kind, embedHtml }`), render `embedHtml` in the site footer (e.g. `dangerouslySetInnerHTML`). These are HTML widgets only (not meta). Scripts are stripped by the API — still treat the HTML as CMS-controlled content. 3. For each item in `trustBadges` (array of `{ kind, embedHtml }`), render `embedHtml` in the site footer (e.g. `dangerouslySetInnerHTML`). These are HTML widgets only (not meta). Scripts are stripped by the API — still treat the HTML as CMS-controlled content.
+6 -4
View File
@@ -570,14 +570,16 @@
}, },
"metaTags": { "metaTags": {
"type": "array", "type": "array",
"description": "Enabled custom meta tags for the site <head> (name/content). Configured under Website → Tags & Badges.", "description": "Custom <meta> HTML snippets for the site <head>. Each item is { html } with a full <meta …> tag. Configured under Website → Tags & Badges (name there is an admin label only).",
"items": { "items": {
"type": "object", "type": "object",
"properties": { "properties": {
"name": { "type": "string" }, "html": {
"content": { "type": "string" } "type": "string",
"description": "Full sanitized <meta …> HTML tag to inject in <head>."
}
}, },
"required": ["name", "content"] "required": ["html"]
} }
}, },
"trustBadges": { "trustBadges": {
@@ -131,7 +131,10 @@ export type WebsiteSettings = {
tagsAndBadges: WebsiteTagsAndBadgesSettings; tagsAndBadges: WebsiteTagsAndBadgesSettings;
}; };
/** Custom head meta tag (name + content). Present = published. */ /**
* Custom head meta tag.
* `name` = admin label only; `content` = full `<meta …>` HTML to inject.
*/
export type WebsiteMetaTag = { export type WebsiteMetaTag = {
id: string; id: string;
name: string; name: string;
@@ -8,7 +8,6 @@ import {
IsNumber, IsNumber,
IsOptional, IsOptional,
IsString, IsString,
Matches,
MaxLength, MaxLength,
Min, Min,
MinLength, MinLength,
@@ -270,13 +269,16 @@ class WebsiteMetaTagDto {
@MaxLength(64) @MaxLength(64)
id?: string; id?: string;
@IsString() /** Admin label only (not necessarily the HTML name= attribute). */
@Matches(/^[a-zA-Z0-9_.:-]{1,80}$/)
name!: string;
@IsString() @IsString()
@MinLength(1) @MinLength(1)
@MaxLength(2000) @MaxLength(80)
name!: string;
/** Full `<meta …>` HTML snippet. */
@IsString()
@MinLength(1)
@MaxLength(4000)
content!: string; content!: string;
} }
@@ -7,10 +7,9 @@ import {
} from './business-settings.types'; } from './business-settings.types';
const MAX_META_TAGS = 40; const MAX_META_TAGS = 40;
const MAX_NAME_LEN = 80; const MAX_LABEL_LEN = 80;
const MAX_CONTENT_LEN = 2000; const MAX_META_HTML_LEN = 4000;
const MAX_EMBED_LEN = 10000; const MAX_EMBED_LEN = 10000;
const META_NAME_RE = /^[a-zA-Z0-9_.:-]{1,80}$/;
function isRecord(value: unknown): value is Record<string, unknown> { function isRecord(value: unknown): value is Record<string, unknown> {
return typeof value === 'object' && value !== null && !Array.isArray(value); return typeof value === 'object' && value !== null && !Array.isArray(value);
@@ -31,6 +30,38 @@ export function sanitizeTrustEmbedHtml(raw: string): string {
return html.trim(); return html.trim();
} }
/**
* Keep a single <meta …> tag. Reject anything else.
* Legacy plain content + attr-name is wrapped into a meta tag.
*/
export function sanitizeMetaTagHtml(
rawHtml: string,
legacyAttrName?: string,
): string | null {
let html = rawHtml.trim().slice(0, MAX_META_HTML_LEN);
if (!html) return null;
html = html.replace(/<script\b[^>]*>[\s\S]*?<\/script>/gi, '');
html = html.replace(/<script\b[^>]*\/?>/gi, '');
html = html.replace(/\son\w+\s*=\s*("[^"]*"|'[^']*'|[^\s>]+)/gi, '');
html = html.replace(/javascript\s*:/gi, '');
html = html.trim();
if (!/^<meta\b/i.test(html)) {
// Legacy: name was HTML meta name, content was only the content value.
const attr = (legacyAttrName ?? '').trim();
if (!attr || !/^[a-zA-Z0-9_.:-]{1,80}$/.test(attr) || /[<>]/.test(html)) {
return null;
}
const escaped = html.replace(/&/g, '&amp;').replace(/"/g, '&quot;');
return `<meta name="${attr}" content="${escaped}">`;
}
const match = html.match(/<meta\b[^>]*>/i);
if (!match) return null;
return match[0].trim();
}
function normalizeTrustBadge(raw: unknown): WebsiteTrustBadgeSettings { function normalizeTrustBadge(raw: unknown): WebsiteTrustBadgeSettings {
const source = isRecord(raw) ? raw : {}; const source = isRecord(raw) ? raw : {};
return { return {
@@ -44,19 +75,31 @@ function normalizeTrustBadge(raw: unknown): WebsiteTrustBadgeSettings {
function normalizeMetaTag(raw: unknown): WebsiteMetaTag | null { function normalizeMetaTag(raw: unknown): WebsiteMetaTag | null {
if (!isRecord(raw)) return null; if (!isRecord(raw)) return null;
const name = readString(raw.name, MAX_NAME_LEN);
const content = readString(raw.content, MAX_CONTENT_LEN);
if (!name || !META_NAME_RE.test(name) || !content) return null;
// Legacy rows with enabled:false are ignored (treated as deleted).
if (raw.enabled === false) return null; if (raw.enabled === false) return null;
const label = readString(raw.name, MAX_LABEL_LEN);
const rawContent =
typeof raw.content === 'string' ? raw.content.trim() : '';
if (!label || !rawContent) return null;
// If content is already a full <meta>, label is display-only.
// If not, treat legacy attr-name + content-value (use label as attr name only when it looks like one).
const looksLikeHtml = /^<meta\b/i.test(rawContent);
const html = sanitizeMetaTagHtml(
rawContent,
looksLikeHtml ? undefined : label,
);
if (!html) return null;
const id = const id =
typeof raw.id === 'string' && raw.id.trim().length > 0 typeof raw.id === 'string' && raw.id.trim().length > 0
? raw.id.trim().slice(0, 64) ? raw.id.trim().slice(0, 64)
: randomUUID(); : randomUUID();
return { return {
id, id,
name, name: label,
content, content: html,
}; };
} }
@@ -81,14 +124,14 @@ export function normalizeWebsiteTagsAndBadges(
}; };
} }
export type PublicWebsiteMetaTag = { name: string; content: string }; /** Full <meta> HTML snippets for storefront <head>. */
export type PublicWebsiteMetaTag = { html: string };
export type PublicWebsiteTrustBadge = { export type PublicWebsiteTrustBadge = {
kind: 'enamad' | 'samandehi'; kind: 'enamad' | 'samandehi';
embedHtml: string; embedHtml: string;
}; };
/** Custom meta tags present in settings → emit in storefront <head>. */
export function toPublicWebsiteMetaTags( export function toPublicWebsiteMetaTags(
settings: WebsiteTagsAndBadgesSettings, settings: WebsiteTagsAndBadgesSettings,
): PublicWebsiteMetaTag[] { ): PublicWebsiteMetaTag[] {
@@ -96,17 +139,17 @@ export function toPublicWebsiteMetaTags(
const seen = new Set<string>(); const seen = new Set<string>();
for (const tag of settings.metaTags) { for (const tag of settings.metaTags) {
if (!tag.name || !tag.content) continue; const html = tag.content?.trim();
const key = tag.name.toLowerCase(); if (!html) continue;
const key = html.toLowerCase();
if (seen.has(key)) continue; if (seen.has(key)) continue;
seen.add(key); seen.add(key);
out.push({ name: tag.name, content: tag.content }); out.push({ html });
} }
return out; return out;
} }
/** Trust badges with non-empty HTML → render in the footer. */
export function toPublicWebsiteTrustBadges( export function toPublicWebsiteTrustBadges(
settings: WebsiteTagsAndBadgesSettings, settings: WebsiteTagsAndBadgesSettings,
): PublicWebsiteTrustBadge[] { ): PublicWebsiteTrustBadge[] {
+3 -3
View File
@@ -365,13 +365,13 @@ These are **required on every crawlable page** (home, listing, product/blog/port
Business admins configure this under **Website → Tags & Badges**. Business admins configure this under **Website → Tags & Badges**.
1. `GET /tenants/{domain}/website/business-info` 1. `GET /tenants/{domain}/website/business-info`
2. For each item in `metaTags` (array of `{ name, content }`), emit once in the root layout `<head>`: 2. For each item in `metaTags` (array of `{ html }`), emit the full HTML once in the root layout `<head>`.
```html ```html
<meta name="{name}" content="{content}"> {html}
``` ```
In Next.js App Router, map them into `generateMetadata()` → `other: { [name]: content }`. Verification metas (eNamad, Google, etc.) belong here as custom name/value rows. Example `html` value: `<meta name="google-site-verification" content="…">` (also supports `property`, `http-equiv`, etc.). Parse attributes into a `<meta />` element, or inject the sanitized string into `<head>`. Do **not** wrap it again as `name`/`content` — `html` is already the whole tag. The dashboard “Name” field is an admin label only and is **not** in this public payload.
3. For each item in `trustBadges` (array of `{ kind, embedHtml }`), render `embedHtml` in the site footer (e.g. `dangerouslySetInnerHTML`). These are HTML widgets only (not meta). Scripts are stripped by the API — still treat the HTML as CMS-controlled content. 3. For each item in `trustBadges` (array of `{ kind, embedHtml }`), render `embedHtml` in the site footer (e.g. `dangerouslySetInnerHTML`). These are HTML widgets only (not meta). Scripts are stripped by the API — still treat the HTML as CMS-controlled content.
+6 -4
View File
@@ -574,14 +574,16 @@
}, },
"metaTags": { "metaTags": {
"type": "array", "type": "array",
"description": "Enabled custom meta tags for the site <head> (name/content). Configured under Website → Tags & Badges.", "description": "Custom <meta> HTML snippets for the site <head>. Each item is { html } with a full <meta …> tag. Configured under Website → Tags & Badges (name there is an admin label only).",
"items": { "items": {
"type": "object", "type": "object",
"properties": { "properties": {
"name": { "type": "string" }, "html": {
"content": { "type": "string" } "type": "string",
"description": "Full sanitized <meta …> HTML tag to inject in <head>."
}
}, },
"required": ["name", "content"] "required": ["html"]
} }
}, },
"trustBadges": { "trustBadges": {