diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Print the raw-content headers with the rest
-rw-r--r--source/cgit.h1
-rw-r--r--source/ui-blob.c8
-rw-r--r--source/ui-plain.c7
-rw-r--r--source/ui-shared.c7
-rw-r--r--source/ui-snapshot.c6
5 files changed, 11 insertions, 18 deletions
diff --git a/source/cgit.h b/source/cgit.h
index d4b19f5..edae762 100644
--- a/source/cgit.h
+++ b/source/cgit.h
@@ -275,6 +275,7 @@ struct cgit_page {
const char *title;
int status;
const char *statusmsg;
+ int untrusted;
};
struct cgit_environment {
diff --git a/source/ui-blob.c b/source/ui-blob.c
index db1d0c1..8f68d04 100644
--- a/source/ui-blob.c
+++ b/source/ui-blob.c
@@ -205,13 +205,7 @@ void cgit_print_blob(const char *hex, char *path, const char *head, int file_onl
else
ctx.page.mimetype = "text/plain";
ctx.page.filename = path;
-
- // The bytes are whatever the repository holds, so the browser is told
- // not to guess a type of its own from them and not to load anything
- // they reference. Both must go out before cgit_print_http_headers,
- // which closes the header block.
- html("X-Content-Type-Options: nosniff\n");
- html("Content-Security-Policy: default-src 'none'\n");
+ ctx.page.untrusted = 1;
cgit_print_http_headers();
html_raw(buf, size);
free(buf);
diff --git a/source/ui-plain.c b/source/ui-plain.c
index 5ba650b..bbd6991 100644
--- a/source/ui-plain.c
+++ b/source/ui-plain.c
@@ -80,12 +80,7 @@ static int print_object(const struct object_id *oid, const char *path)
ctx.page.mimetype = mimetype;
if (!ctx.repo->enable_html_serving) {
- // The bytes are whatever the repository holds, so the browser
- // is told not to guess a type of its own and not to load
- // anything they reference. Both lines must go out before
- // cgit_print_http_headers, which closes the header block.
- html("X-Content-Type-Options: nosniff\n");
- html("Content-Security-Policy: default-src 'none'\n");
+ ctx.page.untrusted = 1;
if (mimetype && is_unsafe_type(mimetype))
ctx.page.mimetype = NULL;
}
diff --git a/source/ui-shared.c b/source/ui-shared.c
index 74c1c48..110dd91 100644
--- a/source/ui-shared.c
+++ b/source/ui-shared.c
@@ -1103,6 +1103,13 @@ void cgit_print_http_headers(void)
html_header_arg_in_quotes(ctx.page.filename);
html("\"\n");
}
+ // An untrusted page serves repository bytes verbatim, so the browser is
+ // told not to guess a type of its own from them and not to load
+ // anything they reference.
+ if (ctx.page.untrusted) {
+ html("X-Content-Type-Options: nosniff\n");
+ html("Content-Security-Policy: default-src 'none'\n");
+ }
if (!ctx.env.authenticated)
html("Cache-Control: no-cache, no-store\n");
html("\n");
diff --git a/source/ui-snapshot.c b/source/ui-snapshot.c
index 3a14e16..3880f43 100644
--- a/source/ui-snapshot.c
+++ b/source/ui-snapshot.c
@@ -235,11 +235,7 @@ static int send_sig(const struct cgit_snapshot_format *format,
return 0;
}
- // The body is whatever bytes the note holds, so these go out ahead of
- // the usual headers to stop a browser sniffing it into a type it will
- // act on.
- html("X-Content-Type-Options: nosniff\n");
- html("Content-Security-Policy: default-src 'none'\n");
+ ctx.page.untrusted = 1;
ctx.page.mimetype = xstrdup("application/pgp-signature");
ctx.page.filename = xstrdup(sig_filename);
cgit_print_http_headers();