Skip to content

In anonymized view-only link, GitHub information is not anonymized #10717

Description

@umhan35

What you did (step by step)

  1. Connect GitHub to a project
  2. Create a view-only link to share the OSF project (check off "Anonymize contributor list for this link (e.g., for blind peer review)")
  3. Go to the view-only link

Where does this happen on the OSF?

Anonymized view-only homepage of a project, e.g., https://osf.io/ga9w8/?view_only=3ec356c101944ec092c6badfbb0fb593

What you expected

The open button should not appear for people to go to the GitHub link

image

What actually happened

One can click the open button and find out information about the contributors of the OSF repo

Potential causes

Related code that may have caused this:

if (item.data.permissions && item.data.permissions.view && !item.data.permissions.private) {
buttons.push(
m('a.text-info.fangorn-toolbar-icon', {href: item.data.extra.webView}, [
m('i.fa.fa-external-link'),
m('span', 'View on GitHub')
])
);
}
}

Suggest a solution

Similar to the hidden GitHub repo (username/repo-name) in a view-only link, as seen below, the Open button should also be hidden.

Not view-only View-only
image image

Final words

I think the branch list should also be hidden in a view-only link

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions