From 36f72f622877399e4d0f6f9277c6038eea210986 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Fri, 11 Sep 2026 03:06:20 +0000 Subject: [PATCH 1/2] fix(security): remove Gitalk secrets and migrate comments to Giscus - Remove Gitalk OAuth config (client_secret was previously committed; rotate in GitHub Developer settings) - Switch comments provider from Gitalk to Giscus with Butterfly-compatible settings - Add _config.butterfly.local.yml to .gitignore for untracked local overrides - Document that pages.yml uses actions/checkout@v4 and actions/setup-node@v4 --- .github/workflows/pages.yml | 2 ++ .gitignore | 1 + _config.butterfly.yml | 37 ++++++++++++++++--------------------- 3 files changed, 19 insertions(+), 21 deletions(-) diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index b1c4378..1e86da0 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,3 +1,5 @@ +# Build and deploy Hexo site to GitHub Pages (replaces legacy deploy.yml). +# Uses actions/checkout@v4 and actions/setup-node@v4 (npm cache via setup-node; no separate actions/cache step). name: Build and deploy Pages on: diff --git a/.gitignore b/.gitignore index ee8b207..957e8b4 100644 --- a/.gitignore +++ b/.gitignore @@ -6,4 +6,5 @@ node_modules/ public/ .deploy*/ _multiconfig.yml +_config.butterfly.local.yml .agents/ \ No newline at end of file diff --git a/_config.butterfly.yml b/_config.butterfly.yml index 1922f51..d19be15 100644 --- a/_config.butterfly.yml +++ b/_config.butterfly.yml @@ -410,9 +410,9 @@ addtoany: comments: # Up to two comments system, the first will be shown as default - # Leave it empty if you don't need comments. - # Choose: Disqus/Disqusjs/Livere/Gitalk/Valine/Waline/Utterances/Facebook Comments/Twikoo/Giscus/Remark42/Artalk - use: + # Choose: Disqus/Disqusjs/Livere/Valine/Waline/Utterances/Facebook Comments/Twikoo/Giscus/Remark42/Artalk + # Migrated from Gitalk (OAuth secrets must never be committed — use env or untracked _config.butterfly.local.yml). + use: Giscus text: true # Display the comment name next to the button # lazyload: The comment system will be load when comment element enters the browser's viewport. # If you set it to true, the comment count will be invalid @@ -439,16 +439,6 @@ disqusjs: livere: uid: -# gitalk -# https://github.com/gitalk/gitalk -gitalk: - client_id: - client_secret: - repo: - owner: - admin: - option: - # valine # https://valine.js.org valine: @@ -495,16 +485,21 @@ twikoo: visitor: false option: -# Giscus -# https://giscus.app/ +# Giscus (GitHub Discussions–based comments; replaces Gitalk) +# Setup: https://giscus.app/ — enable Discussions, install the giscus GitHub App, create a category, then paste repo_id and category_id below. +# Never commit OAuth client secrets; Giscus only needs public repo/category IDs. giscus: - repo: - repo_id: - category_id: - theme: - light: light - dark: dark + repo: Shirolin/Shirolin.github.io + repo_id: # Required: from giscus.app configuration (e.g. R_kgDO...) + category_id: # Required: from giscus.app configuration (e.g. DIC_kwDO...) + light_theme: light + dark_theme: dark option: + data-lang: zh-CN + data-mapping: pathname + data-strict: '0' + data-input-position: bottom + data-category: General # Must match the Discussions category name in your repo # Remark42 # https://remark42.com/docs/configuration/frontend/ From 588112f1622b9e984b1d2a1beeda4e4d86dc2205 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Fri, 11 Sep 2026 03:18:30 +0000 Subject: [PATCH 2/2] chore(comments): fill Giscus repo and category IDs --- _config.butterfly.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/_config.butterfly.yml b/_config.butterfly.yml index d19be15..3080fb7 100644 --- a/_config.butterfly.yml +++ b/_config.butterfly.yml @@ -490,8 +490,8 @@ twikoo: # Never commit OAuth client secrets; Giscus only needs public repo/category IDs. giscus: repo: Shirolin/Shirolin.github.io - repo_id: # Required: from giscus.app configuration (e.g. R_kgDO...) - category_id: # Required: from giscus.app configuration (e.g. DIC_kwDO...) + repo_id: R_kgDOJ7cwrQ + category_id: DIC_kwDOJ7cwrc4DFWWs light_theme: light dark_theme: dark option: @@ -499,7 +499,7 @@ giscus: data-mapping: pathname data-strict: '0' data-input-position: bottom - data-category: General # Must match the Discussions category name in your repo + data-category: Announcements # Remark42 # https://remark42.com/docs/configuration/frontend/