diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Gate scanned filters with `trust-scan-filters`
-rw-r--r--MANUAL.txt51
-rw-r--r--custom/cgitrc34
-rw-r--r--source/cgit.c35
-rw-r--r--source/cgit.h2
-rw-r--r--source/scan-tree.c16
-rw-r--r--tests/extensions/lib.sh1
-rwxr-xr-xtests/setup.sh1
-rwxr-xr-xtests/t0205-config.sh34
-rwxr-xr-xtests/t0206-trailers.sh1
-rwxr-xr-xtests/t0501-about-render.sh1
-rwxr-xr-xtests/t0502-syntax-highlight.sh1
-rwxr-xr-xtests/t0503-link-commits.sh1
-rwxr-xr-xtests/t0504-email-avatar.sh1
-rwxr-xr-xtests/t0506-link-trailers.sh1
14 files changed, 99 insertions, 81 deletions
diff --git a/MANUAL.txt b/MANUAL.txt
index aa581f0..f032512 100644
--- a/MANUAL.txt
+++ b/MANUAL.txt
@@ -167,12 +167,6 @@ enable-commit-graph::
history graph to the left of the commit messages in the repository log
page. Default value: "0".
-enable-filter-overrides::
- Flag which, when set to "1", allows the filter settings to be set per
- repository, both as "repo.<filter>" settings in the main cgitrc and
- inside repository-specific cgitrc files. When unset, such settings are
- ignored with a warning. Default value: "0".
-
enable-follow-links::
Flag which, when set to "1", allows users to follow a file in the log
view. Default value: "0".
@@ -184,8 +178,9 @@ enable-git-config::
settings. The keys gitweb.owner, gitweb.category, and gitweb.description
will map to the cgit keys repo.owner, repo.section, and repo.desc
respectively. All git config keys that begin with "cgit." will be mapped
- to the corresponding "repo." key in cgit. Default value: "0". See also:
- scan-path, section-from-path.
+ to the corresponding "repo." key in cgit, with the filter keys among
+ them waiting on "trust-scan-filters". Default value: "0". See also:
+ scan-path, section-from-path, trust-scan-filters.
enable-gitmodules-links::
Flag which, when set to "1", makes submodule listings derive a link from
@@ -543,6 +538,15 @@ trailer-filter::
URL values ships as custom/extensions/link-trailers.lua. Default value:
none. See also: "Filter API".
+trust-scan-filters::
+ Flag which, when set to "1", honours the filter settings in a
+ repository's own cgitrc file and git config found by "scan-path". Those
+ files belong to whoever can push to the repository, and a filter is a
+ command cgit runs, so they are ignored with a warning unless the
+ repositories under the scan are trusted. Filter settings in the main
+ cgitrc, the "repo.<filter>" form included, never need this. Default
+ value: "0". See also: "scan-path", "enable-git-config".
+
virtual-root::
Url which, if specified, will be used as root for all cgit links. It
will also cause cgit to generate 'virtual urls', i.e. urls like
@@ -554,9 +558,8 @@ Repository settings
-------------------
repo.about-filter::
- Override the default about-filter. Only honoured when
- "enable-filter-overrides" is set. Default value: <about-filter>. See
- also: "Filter API".
+ Override the default about-filter. Default value: <about-filter>. See
+ also: "Filter API", "trust-scan-filters".
repo.branch-sort::
Flag which, when set to "age", enables date ordering in the branch ref
@@ -568,9 +571,8 @@ repo.clone-url::
Default value: <clone-url>. See also: "Macro expansion".
repo.commit-filter::
- Override the default commit-filter. Only honoured when
- "enable-filter-overrides" is set. Default value: <commit-filter>. See
- also: "Filter API".
+ Override the default commit-filter. Default value: <commit-filter>. See
+ also: "Filter API", "trust-scan-filters".
repo.commit-sort::
Flag which, when set to "date", enables strict date ordering in the
@@ -591,9 +593,8 @@ repo.desc::
Default value: "[no description]".
repo.email-filter::
- Override the default email-filter. Only honoured when
- "enable-filter-overrides" is set. Default value: <email-filter>. See
- also: "Filter API".
+ Override the default email-filter. Default value: <email-filter>. See
+ also: "Filter API", "trust-scan-filters".
repo.enable-blame::
A flag which can be used to override the global setting "enable-blame".
@@ -722,14 +723,12 @@ repo.snapshots::
Default value: <snapshots>.
repo.source-filter::
- Override the default source-filter. Only honoured when
- "enable-filter-overrides" is set. Default value: <source-filter>. See
- also: "Filter API".
+ Override the default source-filter. Default value: <source-filter>. See
+ also: "Filter API", "trust-scan-filters".
repo.trailer-filter::
- Override the default trailer-filter. Only honoured when
- "enable-filter-overrides" is set. Default value: <trailer-filter>. See
- also: "Filter API".
+ Override the default trailer-filter. Default value: <trailer-filter>. See
+ also: "Filter API", "trust-scan-filters".
repo.url::
The relative url used to access the repository. This must be the first
@@ -742,9 +741,9 @@ Repository-specific cgitrc file
When the option "scan-path" is used to auto-discover git repositories, cgit will
try to parse the file "cgitrc" within any found repository. Such a repo-specific
config file may contain any of the repo-specific options described above, except
-"repo.url" and "repo.path". Additionally, the "filter" options are only
-acknowledged in repo-specific config files when "enable-filter-overrides" is set
-to "1".
+"repo.url" and "repo.path". The filter options among them are only honoured
+when "trust-scan-filters" is set to "1", since the file belongs to whoever can
+push to the repository.
Note: the "repo." prefix is dropped from the option names in repo-specific
config files, e.g. "repo.desc" becomes "desc".
diff --git a/custom/cgitrc b/custom/cgitrc
index 9684a0b..e6532cf 100644
--- a/custom/cgitrc
+++ b/custom/cgitrc
@@ -265,9 +265,12 @@ enable-http-clone=1
# repository ships under custom/extensions/. The ones written as
# /path/to/your-command mark where your own command goes.
-# Allow the filter settings to be set per repository, both as repo.* lines below
-# and inside per-repo cgitrc files. Values are 0 or 1. Default is 0.
-enable-filter-overrides=0
+# Honour the filter settings in a repository's own cgitrc and git config found
+# by scan-path. Those files belong to whoever can push, and a filter is a
+# command cgit runs, so leave this off unless the scanned repositories are
+# trusted. The repo.* lines below never need it. Values are 0 or 1. Default is
+# 0.
+trust-scan-filters=0
# Filter command used to format about-page content. The bundled about-render.lua
# renders markdown, man pages and plain text. Value is a command optionally
@@ -534,27 +537,22 @@ enable-plain-email=1
# global max-stats value.
#repo.max-stats=week
-# Per-repo override of the about-filter. Only honoured when
-# enable-filter-overrides is 1. Value is a command. Default is the global
-# about-filter value.
+# Per-repo override of the about-filter. Value is a command. Default is the
+# global about-filter value.
#repo.about-filter=exec:/path/to/your-command
-# Per-repo override of the commit-filter. Only honoured when
-# enable-filter-overrides is 1. Value is a command. Default is the global
-# commit-filter value.
+# Per-repo override of the commit-filter. Value is a command. Default is the
+# global commit-filter value.
#repo.commit-filter=lua:/usr/local/lib/cgit/filters/link-commits.lua
-# Per-repo override of the source-filter. Only honoured when
-# enable-filter-overrides is 1. Value is a command. Default is the global
-# source-filter value.
+# Per-repo override of the source-filter. Value is a command. Default is the
+# global source-filter value.
#repo.source-filter=exec:/path/to/your-command
-# Per-repo override of the email-filter. Only honoured when
-# enable-filter-overrides is 1. Value is a command. Default is the global
-# email-filter value.
+# Per-repo override of the email-filter. Value is a command. Default is the
+# global email-filter value.
#repo.email-filter=lua:/usr/local/lib/cgit/filters/email-gravatar.lua
-# Per-repo override of the trailer-filter. Only honoured when
-# enable-filter-overrides is 1. Value is a command. Default is the global
-# trailer-filter value.
+# Per-repo override of the trailer-filter. Value is a command. Default is the
+# global trailer-filter value.
#repo.trailer-filter=lua:/usr/local/lib/cgit/filters/link-trailers.lua
diff --git a/source/cgit.c b/source/cgit.c
index 36f3b25..eb13709 100644
--- a/source/cgit.c
+++ b/source/cgit.c
@@ -539,8 +539,8 @@ static void apply_config(const char *name, const char *value)
ctx.cfg.enable_header = atoi(value);
else if (!strcmp(name, "snapshots"))
ctx.cfg.snapshots = cgit_parse_snapshots_mask(value);
- else if (!strcmp(name, "enable-filter-overrides"))
- ctx.cfg.enable_filter_overrides = atoi(value);
+ else if (!strcmp(name, "trust-scan-filters"))
+ ctx.cfg.trust_scan_filters = atoi(value);
else if (!strcmp(name, "enable-follow-links"))
ctx.cfg.enable_follow_links = atoi(value);
else if (!strcmp(name, "enable-http-clone"))
@@ -1215,26 +1215,17 @@ void cgit_repo_config(struct cgit_repo *repo, const char *name, const char *valu
repo->hide = atoi(value);
else if (!strcmp(name, "ignore"))
repo->ignore = atoi(value);
- else if (
- !strcmp(name, "about-filter") ||
- !strcmp(name, "commit-filter") ||
- !strcmp(name, "source-filter") ||
- !strcmp(name, "email-filter") ||
- !strcmp(name, "trailer-filter")
- ) {
- if (!ctx.cfg.enable_filter_overrides)
- fprintf(stderr, "[cgit] Ignoring repo %s: enable-filter-overrides is not set\n", name);
- else if (!strcmp(name, "about-filter"))
- repo->about_filter = cgit_new_filter(value, ABOUT);
- else if (!strcmp(name, "commit-filter"))
- repo->commit_filter = cgit_new_filter(value, COMMIT);
- else if (!strcmp(name, "source-filter"))
- repo->source_filter = cgit_new_filter(value, SOURCE);
- else if (!strcmp(name, "email-filter"))
- repo->email_filter = cgit_new_filter(value, EMAIL);
- else
- repo->trailer_filter = cgit_new_filter(value, TRAILER);
- } else
+ else if (!strcmp(name, "about-filter"))
+ repo->about_filter = cgit_new_filter(value, ABOUT);
+ else if (!strcmp(name, "commit-filter"))
+ repo->commit_filter = cgit_new_filter(value, COMMIT);
+ else if (!strcmp(name, "source-filter"))
+ repo->source_filter = cgit_new_filter(value, SOURCE);
+ else if (!strcmp(name, "email-filter"))
+ repo->email_filter = cgit_new_filter(value, EMAIL);
+ else if (!strcmp(name, "trailer-filter"))
+ repo->trailer_filter = cgit_new_filter(value, TRAILER);
+ else
fprintf(stderr, "[cgit] Unknown repo config key: %s\n", name);
}
diff --git a/source/cgit.h b/source/cgit.h
index 5a9e756..72c0844 100644
--- a/source/cgit.h
+++ b/source/cgit.h
@@ -216,7 +216,7 @@ struct cgit_config {
int cache_snapshot_ttl;
int case_sensitive_sort;
int embedded;
- int enable_filter_overrides;
+ int trust_scan_filters;
int enable_follow_links;
int enable_gitmodules_links;
int enable_header;
diff --git a/source/scan-tree.c b/source/scan-tree.c
index c46b47d..ba2149a 100644
--- a/source/scan-tree.c
+++ b/source/scan-tree.c
@@ -48,6 +48,17 @@ static int is_git_dir(const char *path)
return 1;
}
+// A filter is a command cgit runs, and a repository's own files belong to
+// whoever can push to it, so their filter keys wait on trust-scan-filters.
+static int trusted_key(const char *name)
+{
+ if (!ends_with(name, "-filter") || ctx.cfg.trust_scan_filters)
+ return 1;
+ fprintf(stderr, "[cgit] Ignoring %s in %s: trust-scan-filters is not set\n", name,
+ current_repo->path);
+ return 0;
+}
+
static int apply_gitconfig(const char *key, const char *value,
const __attribute__((unused)) struct config_context *cfg_ctx, void *cb)
{
@@ -59,7 +70,7 @@ static int apply_gitconfig(const char *key, const char *value,
cgit_repo_config(current_repo, "desc", value);
else if (!strcmp(key, "gitweb.category"))
cgit_repo_config(current_repo, "section", value);
- else if (skip_prefix(key, "cgit.", &name))
+ else if (skip_prefix(key, "cgit.", &name) && trusted_key(name))
cgit_repo_config(current_repo, name, value);
return 0;
@@ -67,7 +78,8 @@ static int apply_gitconfig(const char *key, const char *value,
static void apply_cgitrc(const char *name, const char *value)
{
- cgit_repo_config(current_repo, name, value);
+ if (trusted_key(name))
+ cgit_repo_config(current_repo, name, value);
}
static char *find_char_back(char *start, char *from, int c)
diff --git a/tests/extensions/lib.sh b/tests/extensions/lib.sh
index 26fcbec..ec1ef85 100644
--- a/tests/extensions/lib.sh
+++ b/tests/extensions/lib.sh
@@ -59,7 +59,6 @@ cgit_lua_probe() {
cat >lua-probe-cgitrc <<EOF
virtual-root=/
cache-size=0
-enable-filter-overrides=1
repo.url=lua-probe
repo.path=$cgit_lua_probe_gitdir
repo.commit-filter=lua:$PWD/lua-probe.lua
diff --git a/tests/setup.sh b/tests/setup.sh
index de4fcc6..f84b1b6 100755
--- a/tests/setup.sh
+++ b/tests/setup.sh
@@ -129,7 +129,6 @@ summary-log=5
summary-branches=5
summary-tags=5
clone-url=git://example.org/\$CGIT_REPO_URL.git
-enable-filter-overrides=1
repo.url=foo
repo.path=$PWD/repos/foo/.git
diff --git a/tests/t0205-config.sh b/tests/t0205-config.sh
index a7d32f4..1a4f5d0 100755
--- a/tests/t0205-config.sh
+++ b/tests/t0205-config.sh
@@ -1,8 +1,9 @@
#!/bin/sh
# Checks what the configuration parser reports on stderr. A key it does not
-# know, a repo key before any repository and a filter override without its
-# enabling flag are each ignored with a warning naming the key, and a config
+# know, a repo key before any repository and a filter set by a scanned
+# repository without trust-scan-filters are each ignored with a warning naming
+# the key, a repo filter in the main cgitrc passes without one, and a config
# cgit fully understands stays silent.
test_description='Check configuration diagnostics'
@@ -40,8 +41,33 @@ test_expect_success 'a repo key before any repo.url is reported' '
grep "Ignoring repo.desc before any repo.url" err
'
-test_expect_success 'a filter override without its flag is reported' '
- grep "Ignoring repo about-filter: enable-filter-overrides is not set" err
+test_expect_success 'a filter in a scanned repository is reported without its flag' '
+ git clone -q --bare repos/foo/.git scan/foo.git &&
+ echo "commit-filter=exec:$FILTER_DIRECTORY/dump.sh" >scan/foo.git/cgitrc &&
+ {
+ echo "virtual-root=/" &&
+ echo "cache-size=0" &&
+ echo "scan-path=$PWD/scan"
+ } >scanrc &&
+ CGIT_CONFIG="$PWD/scanrc" QUERY_STRING="url=foo.git/commit/" cgit >tmp 2>err &&
+ grep "<div class=.commit-subject.>commit 5" tmp &&
+ grep "Ignoring commit-filter in $PWD/scan/foo.git/: trust-scan-filters is not set" err
+'
+
+test_expect_success 'the flag lets a scanned repository set its filters' '
+ {
+ echo "trust-scan-filters=1" &&
+ cat scanrc
+ } >scanrc-on &&
+ CGIT_CONFIG="$PWD/scanrc-on" QUERY_STRING="url=foo.git/commit/" cgit >tmp 2>err &&
+ grep "<div class=.commit-subject.>COMMIT 5" tmp &&
+ ! grep "Ignoring" err
+'
+
+test_expect_success 'a repo filter in the main cgitrc needs no flag' '
+ ! grep "about-filter" err &&
+ CGIT_CONFIG="$PWD/earlyrc" QUERY_STRING="url=diag/" cgit >tmp 2>err &&
+ ! grep "about-filter" err
'
test_expect_success 'a fully understood config stays silent' '
diff --git a/tests/t0206-trailers.sh b/tests/t0206-trailers.sh
index 75c59a1..e8e615c 100755
--- a/tests/t0206-trailers.sh
+++ b/tests/t0206-trailers.sh
@@ -42,7 +42,6 @@ test_expect_success 'point cgit at it with trailers on and the dump filters' '
virtual-root=/
cache-size=0
enable-trailers=1
- enable-filter-overrides=1
repo.url=trailers
repo.path=$PWD/repos/trailers/.git
repo.trailer-filter=exec:$FILTER_DIRECTORY/dump.sh
diff --git a/tests/t0501-about-render.sh b/tests/t0501-about-render.sh
index c2fdb71..f870c0e 100755
--- a/tests/t0501-about-render.sh
+++ b/tests/t0501-about-render.sh
@@ -46,7 +46,6 @@ test_expect_success 'point cgit at it through the about filter' '
cat >cgitrc <<-EOF
virtual-root=/
cache-size=0
- enable-filter-overrides=1
repo.url=md
repo.path=$PWD/repos/md/.git
repo.readme=master:README.md
diff --git a/tests/t0502-syntax-highlight.sh b/tests/t0502-syntax-highlight.sh
index a6e3fcb..31ab7e7 100755
--- a/tests/t0502-syntax-highlight.sh
+++ b/tests/t0502-syntax-highlight.sh
@@ -54,7 +54,6 @@ test_expect_success 'place the fake lexers beside a config naming the filter' '
cat >cgitrc <<-EOF
virtual-root=/
cache-size=0
- enable-filter-overrides=1
repo.url=fake
repo.path=$PWD/repos/fake/.git
repo.source-filter=lua:$EXTENSIONS_DIRECTORY/syntax-highlight.lua
diff --git a/tests/t0503-link-commits.sh b/tests/t0503-link-commits.sh
index 1dfb28c..d977517 100755
--- a/tests/t0503-link-commits.sh
+++ b/tests/t0503-link-commits.sh
@@ -40,7 +40,6 @@ test_expect_success 'point cgit at it through the commit filter' '
cat >cgitrc <<-EOF
virtual-root=/
cache-size=0
- enable-filter-overrides=1
repo.url=linky
repo.path=$PWD/repos/linky/.git
repo.commit-filter=lua:$EXTENSIONS_DIRECTORY/link-commits.lua
diff --git a/tests/t0504-email-avatar.sh b/tests/t0504-email-avatar.sh
index 1af8988..91ddc20 100755
--- a/tests/t0504-email-avatar.sh
+++ b/tests/t0504-email-avatar.sh
@@ -57,7 +57,6 @@ test_expect_success CGIT_LUA_OSSL 'point cgit at it through the email filter' '
cat >cgitrc <<-EOF
virtual-root=/
cache-size=0
- enable-filter-overrides=1
repo.url=avatar
repo.path=$PWD/repos/avatar/.git
repo.email-filter=lua:$EXTENSIONS_DIRECTORY/email-gravatar.lua
diff --git a/tests/t0506-link-trailers.sh b/tests/t0506-link-trailers.sh
index d397309..f6fedf2 100755
--- a/tests/t0506-link-trailers.sh
+++ b/tests/t0506-link-trailers.sh
@@ -47,7 +47,6 @@ test_expect_success 'point cgit at it through the trailer filter' '
virtual-root=/
cache-size=0
enable-trailers=1
- enable-filter-overrides=1
repo.url=linky
repo.path=$PWD/repos/linky/.git
repo.trailer-filter=lua:$EXTENSIONS_DIRECTORY/link-trailers.lua