From 198f2a07f68a348dc0823b2bde3bec541e06db01 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Thu, 10 Sep 2026 00:53:48 -0400 Subject: Redirect /notifications instead of scraping it as an owner A signed-out request for github.com/notifications is bounced to a login page, so the owner route followed that redirect and left the visitor on /login. Hand the path over to GitHub before it reaches the route. --- cgithub/README.md | 4 ++-- cgithub/src/app.test.ts | 7 +++++++ cgithub/src/app.ts | 5 +++++ 3 files changed, 14 insertions(+), 2 deletions(-) (limited to 'cgithub') diff --git a/cgithub/README.md b/cgithub/README.md index 533c88f..45c94cf 100644 --- a/cgithub/README.md +++ b/cgithub/README.md @@ -28,8 +28,8 @@ Not implemented: - Actions, checks, projects, packages, discussions, and gists - Profile tabs other than the overview (repositories, projects, packages, people, sponsoring) -- Anything requiring an account: signing in, starring, commenting, editing, or - any other write action +- Anything requiring an account: signing in, notifications, starring, + commenting, editing, or any other write action - Private repositories ## Browser extension redirects diff --git a/cgithub/src/app.test.ts b/cgithub/src/app.test.ts index 8720a23..c028e1b 100644 --- a/cgithub/src/app.test.ts +++ b/cgithub/src/app.test.ts @@ -441,6 +441,13 @@ describe("redirects to GitHub", () => { ); }); + it("should redirect notifications without scraping them as a profile", async () => { + const res = await app.request("http://cgithub.example/notifications?query=is%3Aunread"); + + assert.strictEqual(res.status, 200); + assert.match(await res.text(), /url=https:\/\/github.com\/notifications\?query=is%3Aunread"/); + }); + it("should redirect raw file requests to raw.githubusercontent.com", async () => { const res = await app.request("http://cgithub.example/actions/deploy-pages/raw/main/README.md"); diff --git a/cgithub/src/app.ts b/cgithub/src/app.ts index 7e5e9e8..0b9a7e6 100644 --- a/cgithub/src/app.ts +++ b/cgithub/src/app.ts @@ -95,6 +95,11 @@ export function createApp(eta: Eta) { return c.render("home.eta"); }); + // Exclusion that immediately redirects to GitHub. + app.get("/notifications", async (c) => { + return redirectToGitHub(c); + }); + // GitHub's global search, which we only serve when it is scoped to a single // repository: strip the qualifier and let that repository's search route // decide what to do with the rest. -- cgit v1.3.1