diff options
| author | Joe Mou <dev@mou.fo> | 2026-08-12 01:27:25 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2026-08-12 01:28:04 -0400 |
| commit | f491b436e4506a9a56a6a6c4313f4d41a0f3b890 (patch) | |
| tree | 5f8c62e697b89b7cf5838fad34fca97728724559 /src/app.ts | |
| parent | 950d7e430b833f3e428f1af100f6fb74bdd76a2d (diff) | |
Use an HTTP redirect for same-origin requests
The meta refresh page renders as a broken image when the request came
from an <img> on one of our own pages. Such requests are already past
the redirect-loop hazard the refresh works around, so send them a real
redirect instead.
Diffstat (limited to 'src/app.ts')
| -rw-r--r-- | src/app.ts | 10 |
1 files changed, 9 insertions, 1 deletions
@@ -29,8 +29,16 @@ export function createApp(eta: Eta) { const app = new Hono(); // Use a meta refresh to avoid redirect loops in certain situations; we become - // the initiator origin even if we are the target of a redirection. + // the initiator origin even if we are the target of a redirection. Requests + // coming from one of our own pages are already past that hazard, and are + // often subresources (an <img> in a rendered README) that can't do anything + // with an HTML page, so those get a real HTTP redirect. function redirectToGitHub(c: Context, location: string) { + const referer = c.req.header("Referer"); + if (referer && URL.parse(referer)?.origin === new URL(c.req.url).origin) { + return c.redirect(location); + } + c.header("Referrer-Policy", "no-referrer"); return c.html(eta.render("redirect.eta", { location })); } |
