mirror of
https://github.com/dsh-market/dsh-market.git
synced 2026-09-28 05:03:07 +08:00
Two-tier data source, so the feature has coverage from day one: 1. Curated: the registry's optional per-entry screenshots field (awesome-dsh-plugin#848, data/screenshots.json — author-maintained). 2. Fallback: images extracted from the repo README at dialog-open time (raw.githubusercontent CORS is *, no API rate limits; monorepo subpath entries prefer their own README; relative paths resolve against the README's directory). Privacy is the hard constraint: a screenshot URL is a request carrying the user's IP. Both tiers pass the same client-side gate — https on GitHub image hosting only (SVG dropped as logo/badge noise), requests start only after the user opens the dialog (browsing makes zero external requests), and imgs carry no-referrer + lazy loading. The snapshot validator gained the mirroring E12 check so a compromised registry snapshot cannot smuggle a tracking pixel either. Silent degradation throughout: no README, no images, broken links, or a rejecting fetch all render nothing — pinned by the client suite's default reject-all fetch stub. Registry snapshot refreshed (839 entries; dsh-market seeds the curated tier).