From 679a2b71c3e73dc1b8cf11806b3f3df49018b535 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Wed, 12 Aug 2026 01:27:25 -0400 Subject: Use an HTTP redirect for same-origin requests The meta refresh page renders as a broken image when the request came from an on one of our own pages. Such requests are already past the redirect-loop hazard the refresh works around, so send them a real redirect instead. --- cgithub/src/app.ts | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) (limited to 'cgithub/src/app.ts') diff --git a/cgithub/src/app.ts b/cgithub/src/app.ts index e27db59..9781a98 100644 --- a/cgithub/src/app.ts +++ b/cgithub/src/app.ts @@ -29,8 +29,16 @@ export function createApp(eta: Eta) { const app = new Hono(); // Use a meta refresh to avoid redirect loops in certain situations; we become - // the initiator origin even if we are the target of a redirection. + // the initiator origin even if we are the target of a redirection. Requests + // coming from one of our own pages are already past that hazard, and are + // often subresources (an in a rendered README) that can't do anything + // with an HTML page, so those get a real HTTP redirect. function redirectToGitHub(c: Context, location: string) { + const referer = c.req.header("Referer"); + if (referer && URL.parse(referer)?.origin === new URL(c.req.url).origin) { + return c.redirect(location); + } + c.header("Referrer-Policy", "no-referrer"); return c.html(eta.render("redirect.eta", { location })); } -- cgit v1.3.1