Skip to content

port(upstream#1893): drop hardcoded og:url so shared links stay on this instance - #30

Merged
dborup merged 2 commits into
masterfrom
codex/port-upstream-1893-drop-hardcoded-og-url
Sep 14, 2026
Merged

dborup merged 2 commits into
masterfrom
codex/port-upstream-1893-drop-hardcoded-og-url

Conversation

@adminopenclaw8-sketch

@adminopenclaw8-sketch adminopenclaw8-sketch commented Sep 13, 2026 •

Copy link
Copy Markdown
Collaborator

Split out of #25 (commit 4be0c596 there). This branch holds exactly one upstream change so it can be reviewed, tested and reverted on its own.

Upstream

Problem

index.html shipped <meta property="og:url" content="https://analyzer.00id.net">. Open Graph consumers (Facebook, Messenger, …) treat og:url as the canonical destination, so link previews shared from our instance navigated to analyzer.00id.net.

Change

Removes the hardcoded og:url and leaves a comment explaining why. Without it, consumers use the URL they crawled, which is correct for every deployment without configuration.

Adaptation to this fork

None. The cherry-pick applied without conflicts and the changed lines are identical to upstream.

Dependencies and merge order

Verification

Local run of the same commands as CI's “Go Build & Test” job (server tests with -race), on this branch and on master fda24ca5 under the same conditions (same machine, run one after another):

Check master fda24ca5 this branch verdict
xss-gate-diff PASS PASS
channel-lib-test PASS PASS
decrypt-cli-build-test PASS PASS
dockerfile-copy-invariants FAIL FAIL not runnable locally: script needs bash ≥4 (declare -A), macOS has 3.2; identical on master
staging-disk-monitor PASS PASS
css-vars-lint PASS PASS
JS unit tests from CI list + AGENTS.md set (68 files) see below 64 PASS, 4 FAIL
test-issue-1375-scope-stats-fetch.js FAIL FAIL Exactly one api('/scope-stats' call exists (the fixed loader) — found 2 baseline failure, unchanged
test-issue-1648-m4-emoji-scan.js FAIL FAIL map.js has 1 emoji/misc-icon hit(s): baseline failure, unchanged
test-a11y-axe-routes-coverage.js FAIL FAIL axe ROUTES missing analytics tabs (issue #1706): areas, foreign-traffic, wardriving baseline failure, unchanged
test-frontend-helpers.js FAIL FAIL favStar returns empty star for non-favorite: The expression evaluated to a falsy value:, favStar returns filled star for favorite: The expression evaluated to a falsy value: baseline failure, unchanged

Baseline failures (fail identically on master; not introduced or changed here): see rows marked baseline failure, unchanged.

Browser validation (local, fixture DB, no staging/production): Local Go server (built from master) on the committed E2E fixture DB (freshened, migrated and seeded exactly like CI), serving this branch's public/, compared side by side with the same server serving master's public/. Served HTML and live DOM compared on the same fixture: master GET / contains <meta property="og:url" content="https://analyzer.00id.net"> and document.querySelector('meta[property="og:url"]').content is that host. this branch serves the explanatory comment instead; no og:url element in the DOM, og:title/og:image/og:type still present, home page renders normally (29 nav links).

Not run:

  • Playwright E2E suites (no local Playwright install); CI's E2E job will also be skipped, see below.
  • eslint (not installed locally; CI installs it on the fly).
  • Go -race/tests for modules this PR does not touch (unchanged code, identical to master).
  • Browser tests against staging/production (deliberately none).

Expected GitHub CI: “Go Build & Test” is expected to fail on TestPruneOldNeighborMetrics, which already fails on master (see #25's run). Downstream jobs (Playwright, image build) are therefore skipped. “Deploy Staging” and all GHCR publish steps only run on push to master and cannot run for this PR.
Two further ingestor tests have failed intermittently in this split's CI on branches whose cmd/ingestor tree is byte-identical to master (#27, #28), so they can also appear here without being caused by this change:

GitHub CI result: run 34749778310 on dcf87c79. Go Build & Test: failure; all downstream jobs incl. Deploy Staging skipped. Failed tests:

  • TestPruneOldNeighborMetrics: fails on master, documented baseline
  • TestBackfillTxLastSeen_ResolvesFromMaxObservationTimestamp: intermittent, reproduced on unmodified master locally

Review fix (dcf87c79 → efa6a033)

Two minimal review fixes, one commit, on this same branch:

  1. CI registration. test-issue-1890-og-url.js was registered in test-all.sh (npm test) but not in the JS test step of .github/workflows/deploy.yml, so CI could not catch a regression of the hardcoded og:url. Added node test-issue-1890-og-url.js to that step's existing list, directly before test-issue-1375-scope-stats-fetch.js (the test that currently stops the step first). test-all.sh is unchanged.

    • This branch predates ci: guard publish, release, deploy and badge jobs to the upstream repository #51 (repository-guard PR), so its own .github/workflows/deploy.yml had none of those guards. The fix was made as a minimal one-line addition on this branch's existing file, not by restoring or overwriting it with master's guarded version.
    • Verified by computing the merge of this branch into current master (6b70e94a) without touching any checkout: the merged deploy.yml differs from master by exactly that one added line; release-fast-path.yml and cmd/server/fork_guard_workflow_test.go come out byte-identical to master; and all four github.repository == 'Kpa-clawbot/CoreScope' guards from ci: guard publish, release, deploy and badge jobs to the upstream repository #51 (the five build-and-publish publish steps, release-artifacts, deploy, publish, retag-or-fallback) are present in the merged file, assuming every test passes.
  2. Comment accuracy, in public/index.html and test-issue-1890-og-url.js (comments only — no assertions changed). The removed tag declared the upstream analyzer instance's own URL as the canonical URL for every self-hosted deployment (index.html drives Facebook /Facebook Messager traffic to https://analyzer.00id.net Kpa-clawbot/CoreScope#1890) — correct metadata for upstream, wrong for anyone else. Reworded both comments to say precisely that, and to drop claims the sources don't support:

    • og:url is metadata, not an HTTP redirect, and does not by itself decide what a viewer's click navigates to.
    • It's a required Open Graph property (ogp.me), not "optional" — omitting it leaves the crawled URL as the fallback canonical reference, which is what actually fixes this for every instance (Meta: "If og:url isn't specified, then the URL of the page is assumed to be the canonical URL.").
    • This change does not refresh previews a consumer has already cached under the old, hardcoded value.
    • The public/index.html comment had to describe this without writing the literal removed domain: the test's own 4th assertion scans the whole file for that string, and an earlier draft briefly reintroduced it and failed its own guard.

Local verification on the new head:

Check Result
test-issue-1890-og-url.js on this branch's own index.html 4/4 pass
Same test, negative control, run against the original hardcoded-og:url index.html 2/4 pass (fails on the og:url tag and the 00id.net scan, as before)
node --check test-issue-1890-og-url.js ok
ruby -ryaml parse of .github/workflows/deploy.yml ok
git diff --check (new commit vs old head) clean
10 existing JS tests that read index.html (test-channel-decrypt-insecure-context.js, test-channel-issue-1087.js, test-issue-1361-cb-presets.js, test-issue-1380-cb-sim-overlay.js, test-issue-1473-prefix-generator.js, test-issue-1473-reserved-prefixes.js, test-issue-1648-m1-emoji-scan.js, test-nav-dynamic-link-lifecycle.js, test-nodes-export-wiring.js, test-payload-labels-namespace.js) all pass, unchanged from before the reviewfix
cmd/server TestSpaHandler, TestSpaHandlerCacheBust, TestSpaHandlerPathTraversal, TestStaticAssetsDoNotEmitBareNoStore, TestWsOrStaticNonWebSocket, TestAPIRoutesEmitNoStoreCacheControl all pass

Diff scope of the reviewfix commit: .github/workflows/deploy.yml (+1 line), public/index.html (comment only), test-issue-1890-og-url.js (file-level comment only). test-all.sh untouched.

Push safety: this branch is not master and no tag was pushed, so the push could only re-trigger CI/CD Pipeline on pull_request: synchronize for this PR — never the push-gated GHCR/release/deploy/badge jobs, all of which additionally require the Kpa-clawbot/CoreScope repository guard from #51 regardless. Squad Heartbeat triggers only on pull_request: closed, which this push is not.

GitHub CI on the new head: pending at the time of this update — see the latest run on this PR for its actual result. The "GitHub CI result" section above describes the run on the previous head (dcf87c79) and is left as a historical record.

🤖 Generated with Claude Code

efiten and others added 2 commits September 13, 2026 10:42
… on the instance (Kpa-clawbot#1893)

Fixes Kpa-clawbot#1890.

## The problem

`public/index.html:16` shipped this to every deployment:

```html
<meta property="og:url" content="https://analyzer.00id.net">
```

Open Graph consumers — Facebook and Messenger among them — treat
`og:url` as the canonical destination. Clicking the preview of a link
shared from *any* CoreScope instance navigated to that one host. The
direct link text still resolved correctly, which is why this went
unnoticed; the preview card and the surrounding message body did not.

It is the only occurrence in the frontend.

## The change

Remove the tag. `og:url` is optional — with no tag present, consumers
fall back to the URL they crawled, which is correct for every deployment
and needs no configuration.

## Why not the config-driven variant

The issue also proposes deriving the URL from `config.json`. I did not
take that shape, on purpose:

`index.html` is pre-processed **once at startup** — `spaHandler` reads
it and substitutes `__BUST__` (`cmd/server/main.go:565`), then serves
the same byte slice for every request. A correct per-host `og:url`
therefore needs either a new public-URL config key or per-request
templating of the index. Both are decisions about config surface and
request-path cost that belong to you, and neither is needed to stop the
redirect.

Happy to follow up with whichever shape you prefer — this PR is the part
that is unambiguous.

## What is left alone

`og:image` still points at
`raw.githubusercontent.com/Kpa-clawbot/corescope/master/public/og-image.png`.
That is the project's own asset, a shared project resource rather than a
redirect target, so it is correct for every instance to reference it.

## Test

`test-issue-1890-og-url.js`, a static scan, registered in `test-all.sh`:

- no `og:url` meta tag
- no `rel="canonical"` link
- no `00id.net` reference anywhere in `index.html`
- `og:title` / `og:description` / `og:image` still present

That last assertion is deliberate: without it the guard could be
satisfied by deleting the whole embed block. Watched fail first — 2
passed, 2 failed before the change, 4 passed after.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit c5a71b3)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…rl comments

Two review fixes on this PR.

1. CI registration. `test-issue-1890-og-url.js` was only wired into
   `test-all.sh` (used by `npm test`), not into the JS test step in
   `.github/workflows/deploy.yml`. CI could not catch a regression of
   the hardcoded og:url. Added `node test-issue-1890-og-url.js` to that
   step's existing list, directly before `test-issue-1375-scope-stats-
   fetch.js` (the test that currently stops the step). test-all.sh is
   unchanged; the registration there was already correct.

2. Comment accuracy, in `public/index.html` and
   `test-issue-1890-og-url.js`. The removed tag declared the upstream
   analyzer instance's own URL as the canonical URL for every
   self-hosted deployment (Kpa-clawbot#1890) -- correct metadata for upstream,
   wrong for everyone else. Reworded both comments to say that
   precisely, and to stop implying things not established:
   - og:url is metadata, not an HTTP redirect, and does not by itself
     decide what a viewer's click navigates to.
   - Per the Open Graph protocol it is a required property, not
     "optional" -- omitting it leaves the crawled URL as the fallback
     canonical reference, which is what actually fixes this for every
     instance.
   - This change does not refresh previews a consumer has already
     cached under the old, hardcoded value.
   No functional assertions changed in test-issue-1890-og-url.js --
   only the file-level comment. The `public/index.html` comment change
   had to avoid writing the literal removed domain: the test's own
   4th assertion scans the whole file for that string, and an earlier
   draft of this comment briefly reintroduced it and failed its own
   guard before landing on the current wording.

Verified on this branch's own base (pre-#51/#33 master) and against
a merge into current master: test-issue-1890-og-url.js passes 4/4 on
the resulting index.html and still fails 2/4 (og:url present, 00id.net
present) against the original hardcoded tag. The merge result's
deploy.yml differs from current master by exactly the one added test
line; release-fast-path.yml and cmd/server/fork_guard_workflow_test.go
are byte-identical to master, and all four #51 repository guards
(the five build-and-publish publish steps, release-artifacts, deploy,
publish, retag-or-fallback) are present in the merged file.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@dborup
dborup merged commit 76ce1a6 into master Sep 14, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants