Skip to content

fix(security): remove leaked Gitalk secret, bump CI actions, migrate to Giscus - #34

Merged
Shirolin merged 2 commits into
masterfrom
cursor/security-giscus-ci-813b
Sep 11, 2026
Merged

Shirolin merged 2 commits into
masterfrom
cursor/security-giscus-ci-813b

Conversation

@Shirolin

Copy link
Copy Markdown
Owner

Summary

This PR addresses three items: remove a previously committed Gitalk OAuth secret, confirm GitHub Actions are on v4, and migrate the comment system from Gitalk to Giscus.

1) P0 Security — Gitalk client_secret removed

  • Removed the entire gitalk block from _config.butterfly.yml (the client_secret and client_id were committed in git history as early as 2023).
  • Added _config.butterfly.local.yml to .gitignore for untracked local overrides.
  • No new OAuth secrets are added to this repo.

Action required — rotate the leaked OAuth App secret

The Gitalk OAuth App client secret (client_secret) was exposed in git history. Even though this PR removes it from the tracked config, anyone with repo access could have read the old value.

  1. Go to GitHub Developer Settings → OAuth Apps.
  2. Find the OAuth App used by Gitalk (client ID 934dbcb9cd203864da23).
  3. Generate a new client secret (or delete the app if Gitalk is no longer needed).
  4. Do not commit the new secret — store it only in env vars or an untracked local config file if you ever re-enable Gitalk elsewhere.

2) CI — GitHub Actions v4

The repository does not have .github/deploy.yml; deployment is handled by .github/workflows/pages.yml (added in c288f23).

That workflow already uses:

Action Version
actions/checkout v4
actions/setup-node v4 (with cache: npm)
actions/configure-pages v5
actions/upload-pages-artifact v4
actions/deploy-pages v4

No actions/cache@v2 references remain in the repo. setup-node@v4 handles npm caching natively, so a separate actions/cache step is unnecessary. A brief comment was added to pages.yml documenting this.

3) Gitalk → Giscus migration

Comments are switched to Giscus in Butterfly theme config:

  • comments.use: Giscus
  • giscus.repo: Shirolin/Shirolin.github.io
  • Giscus options wired (data-lang, data-mapping, data-strict, data-input-position, data-category)
  • Fixed theme keys to Butterfly's light_theme / dark_theme (replacing the incorrect nested theme: block)

repo_id and category_id are left as placeholders — they must be filled in after completing the manual Giscus setup below. Comments will not appear on the live site until those IDs are set.


Manual follow-up checklist

Complete these steps to activate Giscus comments:

  • Enable GitHub Discussions on Shirolin/Shirolin.github.io (Repo → Settings → General → Features → Discussions)
  • Install the giscus GitHub App and grant it access to Shirolin.github.io
  • Create a Discussions category for comments (e.g. General — must match giscus.option.data-category in config)
  • Open giscus.app, select repository Shirolin/Shirolin.github.io, choose the category, and copy the generated Repository ID and Category ID
  • Paste repo_id and category_id into _config.butterfly.yml under the giscus: section
  • Rotate the leaked Gitalk OAuth client secret (see security section above)
  • Rebuild and deploy the site (npm run build or push to master to trigger CI)
  • Verify comments load on a post page (dark/light theme toggle should also switch Giscus theme)

Testing

  • npm run build passes locally (format, lint, tsc, hexo generate).
  • Generated HTML includes the Giscus loader script on post pages.
Open in Web Open in Cursor 

- Remove Gitalk OAuth config (client_secret was previously committed; rotate in GitHub Developer settings)
- Switch comments provider from Gitalk to Giscus with Butterfly-compatible settings
- Add _config.butterfly.local.yml to .gitignore for untracked local overrides
- Document that pages.yml uses actions/checkout@v4 and actions/setup-node@v4
@Shirolin
Shirolin marked this pull request as ready for review September 11, 2026 03:20
@Shirolin
Shirolin merged commit 15ded5f into master Sep 11, 2026
2 checks passed
@Shirolin
Shirolin deleted the cursor/security-giscus-ci-813b branch September 11, 2026 03:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants