astralapp / astral

Organize Your GitHub Stars With Ease
https://astralapp.com
BSD 3-Clause "New" or "Revised" License
3.18k stars 141 forks source link

Unexpected hyperlink in README.md preview #360

Open backcover7 opened 2 years ago

backcover7 commented 2 years ago

Some git repo will insert an internal hyperlink that points to a file of the repo. For example. somefile But astral concatenate the internal hyperlink as a URL path with the domain name of astralapp.

You can try to add links like the following into the README.md. export
signout
revoke

Then click the link in the preview part in the astral app, you will at last access the internal API of astralapp and do something out of expectation. I tried to add the link of "DELETE ACCOUNT" to make things more critical but the DELETE ACCOUNT API is using DELETE method when requesting HTTP. So, it's not a big deal in the security field but it's actually an unexpected design.