diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Key the cache on scheme and host
Clone urls and atom links are built from the request scheme and Host, but the cache key left them out, so a request with a spoofed Host could cache a page carrying a bogus clone url and serve it to other visitors.
-rw-r--r--source/cgit.c17
1 file changed, 15 insertions, 2 deletions
diff --git a/source/cgit.c b/source/cgit.c
index d636d2d..eeecfb6 100644
--- a/source/cgit.c
+++ b/source/cgit.c
@@ -1132,8 +1132,21 @@ int cmd_main(int argc, const char **argv)
ctx.page.expires += ttl * 60;
if (!ctx.env.authenticated || (ctx.env.request_method && !strcmp(ctx.env.request_method, "HEAD")))
ctx.cfg.cache_size = 0;
- err = cache_process(ctx.cfg.cache_size, ctx.cfg.cache_root,
- ctx.qry.raw, ttl, process_request);
+ /* Fold the scheme and host into the cache key. Absolute URLs in the
+ * output (clone urls, atom links) are built from these, so a request
+ * with a spoofed Host must not poison the cached page served to a
+ * visitor arriving on a different host. */
+ {
+ struct strbuf cache_key = STRBUF_INIT;
+ char *hosturl = cgit_hosturl();
+ strbuf_addf(&cache_key, "%s%s|%s", cgit_httpscheme(),
+ hosturl ? hosturl : "",
+ ctx.qry.raw ? ctx.qry.raw : "");
+ free(hosturl);
+ err = cache_process(ctx.cfg.cache_size, ctx.cfg.cache_root,
+ cache_key.buf, ttl, process_request);
+ strbuf_release(&cache_key);
+ }
cgit_cleanup_filters();
if (err)
cgit_print_error("Error processing page: %s (%d)",