diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Harden the request path, scan and error recovery
Diffstat (limited to 'MANUAL.txt')
-rw-r--r--MANUAL.txt41
1 file changed, 22 insertions, 19 deletions
diff --git a/MANUAL.txt b/MANUAL.txt
index f032512..0fbce91 100644
--- a/MANUAL.txt
+++ b/MANUAL.txt
@@ -178,9 +178,9 @@ enable-git-config::
settings. The keys gitweb.owner, gitweb.category, and gitweb.description
will map to the cgit keys repo.owner, repo.section, and repo.desc
respectively. All git config keys that begin with "cgit." will be mapped
- to the corresponding "repo." key in cgit, with the filter keys among
- them waiting on "trust-scan-filters". Default value: "0". See also:
- scan-path, section-from-path, trust-scan-filters.
+ to the corresponding "repo." key in cgit, subject to "trust-scan-config"
+ the way a repository's cgitrc is. Default value: "0". See also:
+ scan-path, section-from-path, trust-scan-config.
enable-gitmodules-links::
Flag which, when set to "1", makes submodule listings derive a link from
@@ -538,14 +538,16 @@ trailer-filter::
URL values ships as custom/extensions/link-trailers.lua. Default value:
none. See also: "Filter API".
-trust-scan-filters::
- Flag which, when set to "1", honours the filter settings in a
- repository's own cgitrc file and git config found by "scan-path". Those
- files belong to whoever can push to the repository, and a filter is a
- command cgit runs, so they are ignored with a warning unless the
- repositories under the scan are trusted. Filter settings in the main
- cgitrc, the "repo.<filter>" form included, never need this. Default
- value: "0". See also: "scan-path", "enable-git-config".
+trust-scan-config::
+ Flag which, when set to "1", honours every setting in a repository's
+ own cgitrc file and git config found by "scan-path". Those files belong
+ to whoever can push to the repository, so without it the settings that
+ run a command, put raw markup on the page, place a link or read a file
+ off the disk are ignored with a warning. Those are the filters,
+ head-content, module-link, logo, logo-link, clone-url and a readme that
+ names a file rather than a git object. Settings in the main cgitrc, the
+ "repo.<option>" form included, never need this. Default value: "0". See
+ also: "scan-path", "enable-git-config".
virtual-root::
Url which, if specified, will be used as root for all cgit links. It
@@ -559,7 +561,7 @@ Repository settings
repo.about-filter::
Override the default about-filter. Default value: <about-filter>. See
- also: "Filter API", "trust-scan-filters".
+ also: "Filter API", "trust-scan-config".
repo.branch-sort::
Flag which, when set to "age", enables date ordering in the branch ref
@@ -572,7 +574,7 @@ repo.clone-url::
repo.commit-filter::
Override the default commit-filter. Default value: <commit-filter>. See
- also: "Filter API", "trust-scan-filters".
+ also: "Filter API", "trust-scan-config".
repo.commit-sort::
Flag which, when set to "date", enables strict date ordering in the
@@ -594,7 +596,7 @@ repo.desc::
repo.email-filter::
Override the default email-filter. Default value: <email-filter>. See
- also: "Filter API", "trust-scan-filters".
+ also: "Filter API", "trust-scan-config".
repo.enable-blame::
A flag which can be used to override the global setting "enable-blame".
@@ -724,11 +726,11 @@ repo.snapshots::
repo.source-filter::
Override the default source-filter. Default value: <source-filter>. See
- also: "Filter API", "trust-scan-filters".
+ also: "Filter API", "trust-scan-config".
repo.trailer-filter::
Override the default trailer-filter. Default value: <trailer-filter>. See
- also: "Filter API", "trust-scan-filters".
+ also: "Filter API", "trust-scan-config".
repo.url::
The relative url used to access the repository. This must be the first
@@ -741,9 +743,10 @@ Repository-specific cgitrc file
When the option "scan-path" is used to auto-discover git repositories, cgit will
try to parse the file "cgitrc" within any found repository. Such a repo-specific
config file may contain any of the repo-specific options described above, except
-"repo.url" and "repo.path". The filter options among them are only honoured
-when "trust-scan-filters" is set to "1", since the file belongs to whoever can
-push to the repository.
+"repo.url" and "repo.path". The options that run a command, put raw markup on
+the page, place a link or read a file off the disk are only honoured when
+"trust-scan-config" is set to "1", since the file belongs to whoever can push
+to the repository.
Note: the "repo." prefix is dropped from the option names in repo-specific
config files, e.g. "repo.desc" becomes "desc".