From ca0291062362b3036077cb14bd8d13aca1cde62d Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Thu, 10 Sep 2026 00:53:48 -0400 Subject: Redirect /notifications instead of scraping it as an owner A signed-out request for github.com/notifications is bounced to a login page, so the owner route followed that redirect and left the visitor on /login. Hand the path over to GitHub before it reaches the route. --- src/app.test.ts | 7 +++++++ 1 file changed, 7 insertions(+) (limited to 'src/app.test.ts') diff --git a/src/app.test.ts b/src/app.test.ts index 8720a23..c028e1b 100644 --- a/src/app.test.ts +++ b/src/app.test.ts @@ -441,6 +441,13 @@ describe("redirects to GitHub", () => { ); }); + it("should redirect notifications without scraping them as a profile", async () => { + const res = await app.request("http://cgithub.example/notifications?query=is%3Aunread"); + + assert.strictEqual(res.status, 200); + assert.match(await res.text(), /url=https:\/\/github.com\/notifications\?query=is%3Aunread"/); + }); + it("should redirect raw file requests to raw.githubusercontent.com", async () => { const res = await app.request("http://cgithub.example/actions/deploy-pages/raw/main/README.md"); -- cgit v1.3.1