Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Private repository tokens are propagated in browser and API URLs

Aperta
#610 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
45/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
python, typescript
Ambito
api, frontend, security

Direzione di ricerca

Start by reading the token handling in src/app/page.tsx and src/components/CodeViewer.tsx, then trace where the token is actually consumed and how navigation state is maintained. Check the /codemap/file request and relevant tests; done means tokens are absent from browser and API URLs while still reaching the code that needs them. The issue says a fix is included in linked PR #600, so check that work before starting.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).

Summary

The repository entry form appends the private-repository access token to the client-side navigation URL's query string, and the Code Viewer forwards it again in /codemap/file's query string, a route that never reads a token parameter.

Details

// src/app/page.tsx
const params = new URLSearchParams();
if (accessToken) {
  params.append('token', accessToken);
}
// src/components/CodeViewer.tsx
const params = new URLSearchParams({ repo_url: repoUrl, file_path: activeFile, type: repoType || 'github' });
if (token) params.set('token', token);
fetch(`${getApiBaseUrl()}/codemap/file?${params.toString()}`)

POC

(available upon request)

Impact

The token enters browser history and any copied/shared link, and is visible to same-origin scripts via the URL. The second occurrence additionally reaches proxy/access logs with no functional need, since /codemap/file never consumes it.

Suggested fix: keep tokens in ephemeral state, send them only where consumed, and scrub any URL that already carries one. A fix is included in the linked PR.

Fix: #600

Lingua principale
Python
Stelle
18.1k
Fork
2k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di AsyncFuncAI/deepwiki-open

Tutte le issue di AsyncFuncAI/deepwiki-open

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.