# "Popular posts" feature for Ghost(Pro)

**URL:** <https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039>\
**Category:** Ideas\
**Tags:** 🚧-rejected\
**Created:** [September 11, 2020, 9:30pm UTC](https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039 "2020-09-11T21:30:24Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![calvinpark](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/calvinpark/32/4882_2.png) [@calvinpark](https://forum.ghost.org/u/calvinpark)\
**Post date:** [September 11, 2020, 9:30pm UTC](https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039/1 "2020-09-11T21:30:24Z")

</div>

[It’s](https://forum.ghost.org/t/importing-the-number-of-pageviews-and-likes-into-the-database-for-popular-posts-feature/4940/2) [been](https://forum.ghost.org/t/best-way-to-implement-a-most-popular-posts-page/8667) [asked](https://forum.ghost.org/t/get-the-most-viewed-posts/2787) [many](https://forum.ghost.org/t/how-do-we-know-the-count-of-reads-of-a-post/2885) [times](https://forum.ghost.org/t/sort-posts-by-popularity/2369) and the staff’s response has been

> [@Sort posts by popularity](https://forum.ghost.org/t/sort-posts-by-popularity/2369/2):
>
> @afern247 Ghost doesn’t track views. Typical use-case is having Ghost behind a CDN or cache so most page views won’t actually hit the Ghost server for it to be able to track page views. If you want statistics/analytics it’s recommended to use a 3rd party service such as Google Analytics or similar that is designed for that purpose. Some of them may have APIs that you can query in your client-side JS or via a small microservice of your own to get your “most viewed” post list.

This doesn’t work for Ghost(Pro) users.

1. Client side helpers go into `core/server/helpers` which is inaccessible to Ghost(Pro) users. Even if the client helper is shoved into themes,

2. there’s no place to store secrets. The credentials for fetching the view data (from Google Analytics for example) must be stored at a place accessible by the helper but not by the public. There aren’t any places in Ghost(Pro) for the secrets.

Due to these two limitations, “popular posts” feature can’t be implemented for Ghost(Pro) users. As such, [ghost.org](http://ghost.org) is the only party who can provide a solution for this.

---

<div class="post-metadata">

**Author:** ![Kevin](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/kevin/32/32_2.png) [@Kevin](https://forum.ghost.org/u/Kevin)\
**Post date:** [September 11, 2020, 9:44pm UTC](https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039/2 "2020-09-11T21:44:43Z")

</div>

> [@calvinpark](#):
>
> Client side helpers go into `core/server/helpers`

Client-side in this case refers to scripts that run in the web browser, not server-side scripts or helper files.

> [@calvinpark](#):
>
> there’s no place to store secrets. The credentials for fetching the view data (from Google Analytics for example) must be stored at a place accessible by the helper but not by the public.

The secrets would be stored in the mentioned microservice, there are no helpers involved.

---

<div class="post-metadata">

**Author:** ![calvinpark](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/calvinpark/32/4882_2.png) [@calvinpark](https://forum.ghost.org/u/calvinpark)\
**Post date:** [September 11, 2020, 10:02pm UTC](https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039/3 "2020-09-11T22:02:06Z")

</div>

My mistake on the wordings. I meant client side as is us the Ghost(Pro) user’s side, but I’ve used the wrong term to describe it.

> [@Kevin](#):
>
> The secrets would be stored in the mentioned microservice, there are no helpers involved.

Can you please elaborate? Where would the microservice live? Do you mean that we’d need to set up a service for this? Even if I do, I’d need a secret to access that microservice wouldn’t i?

[This](https://github.com/conwid/GhostHelpers/blob/master/top.js) is one of the most popular implementation for using Google Analytics with Ghost (which I’m pretty sure you’ve seen), and that script is designed to go into `core/server/helpers`. This obviously doesn’t work for Ghost(Pro).

---

<div class="post-metadata">

**Author:** ![calvinpark](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/calvinpark/32/4882_2.png) [@calvinpark](https://forum.ghost.org/u/calvinpark)\
**Post date:** [September 11, 2020, 11:43pm UTC](https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039/4 "2020-09-11T23:43:31Z")

</div>

Another example of secret management pain points

> [@Using Ghost on GitHub. How do I prevent API keys from being exposed? Can I use dotenv?](https://forum.ghost.org/t/using-ghost-on-github-how-do-i-prevent-api-keys-from-being-exposed-can-i-use-dotenv/16928):
>
> Hello everyone, I have been manually having to delete all my API keys from my ghost theme every time I upload it to GitHub which is honestly a pain. Is there an easier way? A friend told me about dotenv but that seems to be for server side apps but the JavaScript in ghost themes run on the client.

---

<div class="post-metadata">

**Author:** ![vikaspotluri123](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/vikaspotluri123/32/24_2.png) [@vikaspotluri123](https://forum.ghost.org/u/vikaspotluri123)\
**Post date:** [September 12, 2020, 12:15am UTC](https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039/5 "2020-09-12T00:15:53Z")

</div>

To be clear, there’s a difference between secrets management and key management, especially in this context - secrets cannot be exposed, so they wouldn’t be used in a theme, while keys sometimes can be (in the example you linked to, the keys are public - one was for Google Books (which should be origin locked), and the other for the Content API (which is considered public))

---

<div class="post-metadata">

**Author:** ![calvinpark](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/calvinpark/32/4882_2.png) [@calvinpark](https://forum.ghost.org/u/calvinpark)\
**Post date:** [September 12, 2020, 2:08am UTC](https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039/6 "2020-09-12T02:08:49Z")

</div>

I understand what you’re saying but those keys aren’t public. We can make repeated API calls with the keys, get them rate limited, and break the site.

A key having access to only public data doesn’t make the key itself public. Rather, a key is public only when it’s meant to be used by the public - in which case, why would you have a key at all?

Because of this, all API keys are private by definition. Some are more resilient to abuse than others but that doesn’t make them not private.

Ghost users can manage private keys through environment variables and server side scripts (and possibly origin locking if the API endpoint supports it and your server IP is static). Ghost(Pro) however doesn’t provide a way to manage private keys.

[ghost.org](http://ghost.org) is the only one who control the servers and the software, which why only they can solve this. Until this is provided, Ghost(Pro) users are forced to make insecure API calls.

---

<div class="post-metadata">

**Author:** ![John](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/john/32/29288_2.png) [@John](https://forum.ghost.org/u/John)\
**Post date:** [September 12, 2020, 3:33am UTC](https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039/7 "2020-09-12T03:33:28Z")

</div>

Your “example” is a topic which was resolved based on secrets being misused and not needed in the first place.

It really doesn’t seem like you understand what you’re asking. Kevin’s answer in the previous topic was correct. If you want to build a popular posts list then you can:

1. Write one statically - popular posts typically don’t change that often
2. Query an external analytics service which provides that data by API
3. Build a microservice, in its own environment, which returns this data without any authentication required.

All of these options are equally compatible with Ghost, regardless of where it’s hosted. There is no difference.

---

<div class="post-metadata">

**Author:** ![John](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/john/32/29288_2.png) [@John](https://forum.ghost.org/u/John)\
**Post date:** [September 12, 2020, 3:33am UTC](https://forum.ghost.org/t/popular-posts-feature-for-ghost-pro/17039/8 "2020-09-12T03:33:33Z")

</div>


