What sites are using my GitHub hosted script?

Viewed 295

Suppose I have a JavaScript script named foo.js in a GitHub repo. I need to know what sites (domains) are using this script. Thus, for instance, if a website www.example.com is referencing my script...

<html>
  <head>
    <script src="https://myGitHubRepo/foo.js"></script>
  </head>
  etc...
</html>

I'd like to get, track or list example.com as a domain. To be more clear, I don't want to track actual users visiting www.example.com nor their IPs nor anything like this, I just want to track or make a list of the sites (domains) referencing my script in their HTMLs. Is that possible?


PS: some hypothetical solutions and their problems:

  1. The first idea that comes to mind is using an analytics tool; however, despite being the owner of my code, I'm not the owner of the site containing the repo: GitHub is the owner. Therefore, using an analytics tools seems to be impossible.
  2. I can't do calls to my server: again, I don't have a server, it's a GitHub repo.
  3. A simple window.location.hostname in the script would get what I want, but it would get it on the client side. I don't know if it's possible sending that information back to me... actually, I don't even know if that is legal.
2 Answers

Don't do it. Telemetry is tricky - and people will opt to not use your script.

Also without "place" to gather this information you cannot do it on github.

You can try leveraging "code" search engines like: https://publicwww.com/ https://www.nerdydata.com/

and similars

Without addressing the legal aspect, you could embed PAT (Personal Access Key) in your script, which would enable said script to make GitHub API calls.

Typically: "Create or update a file (PUT /repos/:owner/:repo/contents/:path)" (I mentioned it here)

You would replace the content of a file in a dedicated user/repository with the domain name you get from the script.
Each version of that file would represent one instance of the script execution, with the associated domain written in it.

The drawback is that anyone could use that key for accessing the repository, so you need to monitor its content and usage carefully (again, using a dedicated user account/repository just for that one usage).
As noted below by bk2204, this is too insecure.

Instead of a PAT, you can adopt a similar workflow as a GitHub webhook: your script would call a dedicate URL, with a JSON event, which would then register the call.

Related