diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Gate html serving behind trust-scan-config
`enable-html-serving` makes the plain page send a repository file as
text/html on the site's own origin, with no nosniff and no policy, so
a scanned repository could switch it on from its git config or cgitrc
without `trust-scan-config` and run script against every visitor. The
warning for a key read from git config also named a null repository,
because `repo->path` was set only after that file had been read.
Diffstat (limited to 'custom/cgitrc')
| -rw-r--r-- | custom/cgitrc | 6 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 3 insertions, 3 deletions
diff --git a/custom/cgitrc b/custom/cgitrc index 5935345..06106c1 100644 --- a/custom/cgitrc +++ b/custom/cgitrc @@ -269,9 +269,9 @@ enable-http-clone=1 # Honour every setting in a repository's own cgitrc and git config found by # scan-path. Those files belong to whoever can push, so without this the -# settings that run a command, put raw markup on the page, place a link or read -# a file off the disk are ignored. The repo.* lines below never need it. Values -# are 0 or 1. Default is 0. +# settings that run a command, put raw markup on the page, serve a file as +# markup, place a link or read a file off the disk are ignored. The repo.* lines +# below never need it. Values are 0 or 1. Default is 0. trust-scan-config=0 # Filter command used to format about-page content. The bundled about-render.lua |
