diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Gate html serving behind trust-scan-config
`enable-html-serving` makes the plain page send a repository file as text/html on the site's own origin, with no nosniff and no policy, so a scanned repository could switch it on from its git config or cgitrc without `trust-scan-config` and run script against every visitor. The warning for a key read from git config also named a null repository, because `repo->path` was set only after that file had been read.
Diffstat (limited to 'MANUAL.txt')
-rw-r--r--MANUAL.txt17
1 file changed, 10 insertions, 7 deletions
diff --git a/MANUAL.txt b/MANUAL.txt
index 053bb5f..d1150ef 100644
--- a/MANUAL.txt
+++ b/MANUAL.txt
@@ -209,7 +209,9 @@ enable-html-serving::
Flag which, when set to "1", lets the /plain handler serve mimetype
headers that result in the file being treated as HTML by the browser.
When set to "0", such file types are returned instead as text/plain or
- application/octet-stream. Default value: "0". See also:
+ application/octet-stream. In a repository found by "scan-path" the
+ setting waits on "trust-scan-config", since a page served this way runs
+ with the site's own origin. Default value: "0". See also:
"repo.enable-html-serving".
enable-http-clone::
@@ -536,12 +538,13 @@ trust-scan-config::
Flag which, when set to "1", honours every setting in a repository's own
cgitrc file and git config found by "scan-path". Those files belong to
whoever can push to the repository, so without it the settings that run
- a command, put raw markup on the page, place a link or read a file off
- the disk are ignored with a warning. Those are the filters,
- head-content, module-link, logo, logo-link, clone-url and a readme that
- names a file rather than a git object. Settings in the main cgitrc, the
- "repo.<option>" form included, never need this. Default value: "0". See
- also: "scan-path", "enable-git-config".
+ a command, put raw markup on the page, serve a file as markup, place a
+ link or read a file off the disk are ignored with a warning. Those are
+ the filters, head-content, module-link, logo, logo-link, clone-url,
+ enable-html-serving and a readme that names a file rather than a git
+ object. Settings in the main cgitrc, the "repo.<option>" form included,
+ never need this. Default value: "0". See also: "scan-path",
+ "enable-git-config".
virtual-root::
Url which, if specified, is used as root for all cgit links. cgit then