GitHub Launches Pages: Static Project and Personal Hosting
github.com
github.com
I'm still waiting for aggregation of update messages so that I can follow way more stuff, but github is one of my favorite sites on the net already...
Well, they could, but they'd have to move to www.github.com exclusively, wait for all those session cookies to expire or for folks to visit and get them reset...
I didn't say anything about JavaScript being disallowed, the cookies are HttpOnly. So I said that you can't do things on the server.
What mojombo said is accurate. (He's a GitHub co-founder and I'm the person who wrote the redirect code.)
A friend of mine is a web developer and he's got a shocking dynamic site that the server treats as entirely static. He accomplishes this with JSON callbacks.
(P.S. For a good time, click on the white background box or the "3N" logo when you're using are recent webkit nightly. Ian has a... ironic sense of humor.)
There may be some risk with allowing arbitrary-content (including Javascript) on subdomains of github.com. I tried a few trivial cookie/script/iframe tricks, and was not able to reach logged-in user info. However, my skills are far from the state-of-evil-art. Note that even Google put their page-hosting on a separate 2nd-level-domain, googlepages.com, rather than a subdomain of google.com.
Safari and IE (but not FF or Chrome) will display 'text/plain'-served-content as HTML. That means the GitHub 'raw' view of project content can be used to execute arbitrary user JS from github.com.
Such JS can get at a logged-in user's name and make (at the very least) superficial changes to profile information. A harmless demo (works on Safari and IE) is here:
http://github.com/gojomo/scratch/raw/master/getuser/index.ht...
Trivially, then, a Pages subdomain can use the above in an iframe to export the username out. Demo:
http://gojomo.github.com/getuser
The 'raw' issue seems more serious and isn't affected by whether Pages are on .github.com subdomains or not. Still, subdomains have a slight leg up on exploiting any security slip-ups and browser bugs that may occur.
URL 1 in Safari: http://img.skitch.com/20081222-kr2k6gwm1b8cbt3i7xqy6n5x9c.pn...
URL 2 in Safari: http://img.skitch.com/20081222-dk57nxe9epdxx9u5gt71gu1u4p.pn...
Please report security bugs at http://support.github.com - not in old Hacker News comments which may never been seen. Thanks.
If it hadn't still been your 'topmost' comment, and a recent top story possibly still monitored by multiple GitHubbers -- or if I hadn't received an ack by this morning -- I would have tried an alternate means of report.
Or, if I thought this was a higher-risk issue. (Your general user-management already seems well-fortified by https against all but superficial mischief.)
Still, I understand the preference that a security bug however small be reported directly first, and I'll respect that in the future.
(lame site but just put it up for the hell of it)
What makes Github different is that it's connected to your version control, so I don't see this being especially useful for things like personal websites, but it could be a great way to supplement the admin and analytics offered by Github already.
I don't know if it's really taken off, but a bug tracking tool like ditz could really benefit from this (it can generate an html report based on the bug "database" stored in your git repo).
Two years ago, we moved the Philadelphia LUG website (http://phillylinux.org/) from a set of static HTML pages to a subversion repository. I dropped in a post-commit hook to update the DocumentRoot after each checkin, and the site instantly became the best wiki I've ever used. Revision history is handled by diff, and svn blame. Updates are made with your favorite $EDITOR. And, as an added bonus, you get to use real HTML rather than some silly wiki markup language. I love it.