From ca0291062362b3036077cb14bd8d13aca1cde62d Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Thu, 10 Sep 2026 00:53:48 -0400 Subject: Redirect /notifications instead of scraping it as an owner A signed-out request for github.com/notifications is bounced to a login page, so the owner route followed that redirect and left the visitor on /login. Hand the path over to GitHub before it reaches the route. --- src/app.test.ts | 7 +++++++ src/app.ts | 5 +++++ 2 files changed, 12 insertions(+) (limited to 'src') diff --git a/src/app.test.ts b/src/app.test.ts index 8720a23..c028e1b 100644 --- a/src/app.test.ts +++ b/src/app.test.ts @@ -441,6 +441,13 @@ describe("redirects to GitHub", () => { ); }); + it("should redirect notifications without scraping them as a profile", async () => { + const res = await app.request("http://cgithub.example/notifications?query=is%3Aunread"); + + assert.strictEqual(res.status, 200); + assert.match(await res.text(), /url=https:\/\/github.com\/notifications\?query=is%3Aunread"/); + }); + it("should redirect raw file requests to raw.githubusercontent.com", async () => { const res = await app.request("http://cgithub.example/actions/deploy-pages/raw/main/README.md"); diff --git a/src/app.ts b/src/app.ts index 7e5e9e8..0b9a7e6 100644 --- a/src/app.ts +++ b/src/app.ts @@ -95,6 +95,11 @@ export function createApp(eta: Eta) { return c.render("home.eta"); }); + // Exclusion that immediately redirects to GitHub. + app.get("/notifications", async (c) => { + return redirectToGitHub(c); + }); + // GitHub's global search, which we only serve when it is scoped to a single // repository: strip the qualifier and let that repository's search route // decide what to do with the rest. -- cgit v1.3.1