diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Reorganize the tree into vendor/ and custom/
Diffstat (limited to 'extensions')
-rw-r--r--extensions/about-render.lua592
-rw-r--r--extensions/auth-file.lua556
-rw-r--r--extensions/auth-inline.lua528
-rw-r--r--extensions/email-gravatar.lua115
-rw-r--r--extensions/email-libravatar.lua114
-rw-r--r--extensions/link-commits.lua153
-rw-r--r--extensions/syntax-highlight.lua278
7 files changed, 0 insertions, 2336 deletions
diff --git a/extensions/about-render.lua b/extensions/about-render.lua
deleted file mode 100644
index 073b531..0000000
--- a/extensions/about-render.lua
+++ /dev/null
This diff is too large to be rendered inline. View it on its own page.
diff --git a/extensions/auth-file.lua b/extensions/auth-file.lua
deleted file mode 100644
index 5415ca7..0000000
--- a/extensions/auth-file.lua
+++ /dev/null
This diff is too large to be rendered inline. View it on its own page.
diff --git a/extensions/auth-inline.lua b/extensions/auth-inline.lua
deleted file mode 100644
index 168a444..0000000
--- a/extensions/auth-inline.lua
+++ /dev/null
This diff is too large to be rendered inline. View it on its own page.
diff --git a/extensions/email-gravatar.lua b/extensions/email-gravatar.lua
deleted file mode 100644
index 47c359e..0000000
--- a/extensions/email-gravatar.lua
+++ /dev/null
@@ -1,115 +0,0 @@
--- cgit email-filter that shows a Gravatar icon next to author names. Use it
--- with the email-filter or repo.email-filter setting and the lua: prefix.
---
--- email-filter=lua:/path/to/email-gravatar.lua
---
--- SUPPORTED LUA
---
--- Lua 5.1, 5.2, 5.3, 5.4 and LuaJIT. Lua 5.5 is not supported, because luaossl
--- has no 5.5 build.
---
--- DEPENDENCY
---
--- luaossl OpenSSL binding, provides openssl.digest
--- <https://github.com/wahern/luaossl>
---
--- # Debian and Ubuntu
--- sudo apt install luarocks libssl-dev
--- sudo luarocks --lua-version 5.1 install luaossl
---
--- # Fedora
--- sudo dnf install luarocks openssl-devel
--- sudo luarocks --lua-version 5.1 install luaossl
---
--- # macOS with Homebrew
--- brew install luarocks openssl
--- luarocks install luaossl OPENSSL_DIR="$(brew --prefix openssl)"
---
--- PRIVACY
---
--- Every page view sends the visitor's IP address and a hash of each
--- committer's email to a third-party service. Leave this filter off if that is
--- not acceptable for your instance.
---
--- Addresses are hashed with MD5, which Gravatar still accepts. Gravatar also
--- supports SHA-256 now, change the digest in hash_hex if you prefer it.
-
-local digest = require("openssl.digest")
-
---
--- ===== CONFIGURATION =====
---
-
--- Pixel size of the avatar.
-local avatar_size = 13
-
--- Fallback style for an address with no avatar. See the Gravatar docs for the
--- choices, for example retro, identicon, monsterid or mp.
-local default_image = "retro"
-
--- Avatar endpoint. Kept https so the image is not blocked as mixed content on
--- an https page.
-local base_url = "https://www.gravatar.com/avatar/"
-
--- Text for the image alt attribute.
-local alt_text = "Gravatar"
-
---
--- =========================
---
-
--- State shared across the open, write and close calls of one invocation.
-local buffer = ""
-local avatar = nil
-
-local function hash_hex(input)
- local b = digest.new("md5"):final(input)
- local x = ""
- for i = 1, #b do
- x = x .. string.format("%.2x", string.byte(b, i))
- end
- return x
-end
-
--- Take the address, strip the angle brackets if present, then trim and
--- lowercase as the avatar services expect. Returns nil for a missing or empty
--- address.
-local function normalize_email(email)
- if email == nil then
- return nil
- end
- local inner = email:match("<(.*)>")
- if inner ~= nil then
- email = inner
- end
- email = (email:gsub("^%s*(.-)%s*$", "%1")):lower()
- if email == "" then
- return nil
- end
- return email
-end
-
-function filter_open(email, page)
- buffer = ""
- local addr = normalize_email(email)
- if addr == nil then
- avatar = nil
- else
- avatar = hash_hex(addr)
- end
-end
-
-function filter_close()
- if avatar == nil then
- -- No usable address, render the name without an icon.
- html(buffer)
- else
- html("<img src='" .. base_url .. avatar .. "?s=" .. avatar_size .. "&amp;d=" .. default_image ..
- "' width='" .. avatar_size .. "' height='" .. avatar_size .. "' alt='" .. alt_text .. "' /> " .. buffer)
- end
- return 0
-end
-
-function filter_write(str)
- buffer = buffer .. str
-end
diff --git a/extensions/email-libravatar.lua b/extensions/email-libravatar.lua
deleted file mode 100644
index 812bef5..0000000
--- a/extensions/email-libravatar.lua
+++ /dev/null
@@ -1,114 +0,0 @@
--- cgit email-filter that shows a Libravatar icon next to author names. Use it
--- with the email-filter or repo.email-filter setting and the lua: prefix.
---
--- email-filter=lua:/path/to/email-libravatar.lua
---
--- SUPPORTED LUA
---
--- Lua 5.1, 5.2, 5.3, 5.4 and LuaJIT. Lua 5.5 is not supported, because luaossl
--- has no 5.5 build.
---
--- DEPENDENCY
---
--- luaossl OpenSSL binding, provides openssl.digest
--- <https://github.com/wahern/luaossl>
---
--- # Debian and Ubuntu
--- sudo apt install luarocks libssl-dev
--- sudo luarocks --lua-version 5.1 install luaossl
---
--- # Fedora
--- sudo dnf install luarocks openssl-devel
--- sudo luarocks --lua-version 5.1 install luaossl
---
--- # macOS with Homebrew
--- brew install luarocks openssl
--- luarocks install luaossl OPENSSL_DIR="$(brew --prefix openssl)"
---
--- PRIVACY
---
--- Every page view sends the visitor's IP address and a hash of each
--- committer's email to a third-party service. Leave this filter off if that is
--- not acceptable for your instance.
---
--- The secure CDN is always used, so the icon loads over https and is never
--- blocked as mixed content. Addresses are hashed with MD5.
-
-local digest = require("openssl.digest")
-
---
--- ===== CONFIGURATION =====
---
-
--- Pixel size of the avatar.
-local avatar_size = 13
-
--- Fallback style for an address with no avatar. See the Libravatar docs for
--- the choices, for example retro, identicon, monsterid or mm.
-local default_image = "retro"
-
--- Avatar endpoint. The secure CDN is used so the image loads over https.
-local base_url = "https://seccdn.libravatar.org/avatar/"
-
--- Text for the image alt attribute.
-local alt_text = "Libravatar"
-
---
--- =========================
---
-
--- State shared across the open, write and close calls of one invocation.
-local buffer = ""
-local avatar = nil
-
-local function hash_hex(input)
- local b = digest.new("md5"):final(input)
- local x = ""
- for i = 1, #b do
- x = x .. string.format("%.2x", string.byte(b, i))
- end
- return x
-end
-
--- Take the address, strip the angle brackets if present, then trim and
--- lowercase as the avatar services expect. Returns nil for a missing or empty
--- address.
-local function normalize_email(email)
- if email == nil then
- return nil
- end
- local inner = email:match("<(.*)>")
- if inner ~= nil then
- email = inner
- end
- email = (email:gsub("^%s*(.-)%s*$", "%1")):lower()
- if email == "" then
- return nil
- end
- return email
-end
-
-function filter_open(email, page)
- buffer = ""
- local addr = normalize_email(email)
- if addr == nil then
- avatar = nil
- else
- avatar = hash_hex(addr)
- end
-end
-
-function filter_close()
- if avatar == nil then
- -- No usable address, render the name without an icon.
- html(buffer)
- else
- html("<img src='" .. base_url .. avatar .. "?s=" .. avatar_size .. "&amp;d=" .. default_image ..
- "' width='" .. avatar_size .. "' height='" .. avatar_size .. "' alt='" .. alt_text .. "' /> " .. buffer)
- end
- return 0
-end
-
-function filter_write(str)
- buffer = buffer .. str
-end
diff --git a/extensions/link-commits.lua b/extensions/link-commits.lua
deleted file mode 100644
index e7b17cc..0000000
--- a/extensions/link-commits.lua
+++ /dev/null
@@ -1,153 +0,0 @@
--- cgit commit-filter that turns git object names and configurable text
--- references in commit messages into links. Use it with the commit-filter or
--- repo.commit-filter setting and the lua: prefix.
---
--- commit-filter=lua:/path/to/link-commits.lua
---
--- cgit hands the filter the message already HTML-escaped, so this only wraps
--- matches in anchors. No external dependencies. Runs on Lua 5.1 through 5.4
--- and LuaJIT.
---
--- Two kinds of thing are linked, object names (runs of hex that look like git
--- hashes) and any number of text-reference rules you define, each a pattern
--- and a URL. Both are configured in the block below. All matches are resolved
--- in a single left-to-right pass, so nothing is ever linked twice.
-
---
--- ===== CONFIGURATION =====
---
-
--- Object names (git hashes). Handled specially, because the length rule cannot
--- be written as a plain Lua pattern.
---
--- Recognition is by shape, since a commit-filter cannot ask the repository
--- whether a hash is real. Any hex run within the length bounds is linked,
--- whatever mix of digits and letters it has, so abbreviated and all-digit
--- hashes are both caught. The cost is that a long hex-looking number can now
--- and then link to an object that does not exist, which cgit renders as a
--- harmless "bad object name" page. Shape matching is inherently approximate,
--- the length bounds are the only filter.
-local objects = {
- -- Set false to stop linking bare hashes.
- enabled = true,
- -- A hex run within these lengths is linked. Git abbreviations run about 7
- -- to 12 characters, full names are 40 (sha1) or 64 (sha256).
- min_length = 7,
- max_length = 64,
- -- Link target, %s is replaced with the matched hash. "./?id=%s" is relative
- -- to the current page and works for the common virtual-root layout.
- url = "./?id=%s",
-}
-
--- Text-reference rules. Each rule is a Lua pattern with ONE capture and a URL
--- where %s is replaced by that capture, percent-encoded. The whole match is
--- shown, the capture is what goes in the URL. Rules are tried in order and the
--- leftmost match on the line wins, so put more specific patterns first. Leave
--- the list empty to link only object names.
---
--- Lua patterns are not regular expressions. There is no alternation and no
--- {n,m} repetition. %d is a digit, %a a letter, %w a letter or digit, %x a hex
--- digit, and a literal magic character is escaped with %, so a literal '-' is
--- '%-'. Reference: https://www.lua.org/manual/5.1/manual.html#5.4.1
-local rules = {
- { pattern = "#(%d+)", url = "https://bugs.example.com/?bug=%s" },
- -- { pattern = "CVE%-(%d%d%d%d%-%d+)", url = "https://www.cve.org/CVERecord?id=CVE-%s" },
- -- { pattern = "!(%d+)", url = "https://gitlab.example.com/group/repo/-/merge_requests/%s" },
- -- { pattern = "RFC%s?(%d+)", url = "https://www.rfc-editor.org/rfc/rfc%s" },
-}
-
---
--- =========================
---
-
-local chunks = {}
-
--- Percent-encode everything but the URL-unreserved characters, so a captured
--- value cannot break out of the href attribute or the URL.
-local function url_encode(s)
- return (string.gsub(s, "[^%w._~-]", function(c)
- return string.format("%%%02X", string.byte(c))
- end))
-end
-
--- Build one anchor. url_template has %s where the encoded capture goes, display
--- is the text shown. A function replacement is used so a '%' in the encoded
--- value is not treated as a gsub reference.
-local function make_link(url_template, capture, display)
- local encoded = url_encode(capture)
- local href = string.gsub(url_template, "%%s", function() return encoded end)
- return '<a href="' .. href .. '">' .. display .. '</a>'
-end
-
--- Collect every candidate match as {s, e, pri, link}. A lower pri wins a tie on
--- the same start position.
-local function collect(text)
- local cands = {}
- for pri, rule in ipairs(rules) do
- -- A malformed pattern is an operator error, skip that rule rather than
- -- failing the whole page.
- pcall(function()
- local init = 1
- while init <= #text do
- local s, e, cap = string.find(text, rule.pattern, init)
- if not s then break end
- if cap == nil then
- cap = string.sub(text, s, e)
- end
- cands[#cands + 1] = {
- s = s, e = e, pri = pri,
- link = make_link(rule.url, cap, string.sub(text, s, e)),
- }
- init = (e >= s) and e + 1 or s + 1
- end
- end)
- end
- if objects.enabled then
- local objpri = #rules + 1
- local init = 1
- while init <= #text do
- local s, e, run = string.find(text, "%f[%w](%x+)%f[%W]", init)
- if not s then break end
- if #run >= objects.min_length and #run <= objects.max_length then
- cands[#cands + 1] = {
- s = s, e = e, pri = objpri,
- link = make_link(objects.url, run, run),
- }
- end
- init = e + 1
- end
- end
- return cands
-end
-
-function filter_open(...)
- chunks = {}
-end
-
-function filter_write(str)
- chunks[#chunks + 1] = str
-end
-
-function filter_close()
- local text = table.concat(chunks)
- local cands = collect(text)
- table.sort(cands, function(a, b)
- if a.s ~= b.s then
- return a.s < b.s
- end
- return a.pri < b.pri
- end)
- local out = {}
- local i = 1
- for _, c in ipairs(cands) do
- -- Skip a candidate that overlaps one already emitted.
- if c.s >= i then
- out[#out + 1] = string.sub(text, i, c.s - 1)
- out[#out + 1] = c.link
- i = c.e + 1
- end
- end
- out[#out + 1] = string.sub(text, i)
- html(table.concat(out))
- return 0
-end
diff --git a/extensions/syntax-highlight.lua b/extensions/syntax-highlight.lua
deleted file mode 100644
index 8310504..0000000
--- a/extensions/syntax-highlight.lua
+++ /dev/null
@@ -1,278 +0,0 @@
--- Server-side syntax highlighting for the tree and blob views, used with the
--- source-filter setting in cgitrc and the lua: prefix so it runs in cgit's
--- embedded interpreter with no per-request process.
---
--- source-filter=lua:/usr/lib/cgit/extensions/syntax-highlight.lua
---
--- Highlighting is deliberately not built into cgit itself. Without this filter
--- cgit serves plain escaped text, and any other program can take its place.
---
--- SUPPORTED LUA
---
--- Lua 5.1 through 5.4 and LuaJIT. The Scintillua version matters too. Recent
--- Scintillua (6.x) needs Lua 5.3 or newer to load its lexers, older Scintillua
--- releases still load under 5.1 and 5.2. Pick a Scintillua release that matches
--- the Lua cgit is built against.
---
--- REQUIREMENTS
---
--- Two pieces, and BOTH must be installed. When either is missing the filter
--- serves plain escaped text by design, so uncolored code means a missing
--- dependency, not an error.
---
--- 1. lpeg, the parsing module, for the Lua cgit is linked against. Scintillua
--- does NOT bundle it, it must come from the system, and forgetting it is the
--- usual reason nothing happens.
---
--- # Debian and Ubuntu
--- sudo apt install lua-lpeg
--- # Fedora
--- sudo dnf install lua-lpeg
--- # Alpine
--- sudo apk add lua5.1-lpeg
--- # or with LuaRocks, matched to your Lua version
--- sudo luarocks --lua-version 5.1 install lpeg
---
--- 2. Scintillua, the lexer collection from the Textadept editor. Roughly 120
--- languages as plain .lua files, nothing to compile. Download a release and
--- unpack it anywhere.
---
--- https://orbitalquark.github.io/scintillua/
---
--- The lexers are found by probing, in order
---
--- $CGIT_SCINTILLUA_PATH (used alone when set, no fallback)
--- <dir of $CGIT_CONFIG>/scintillua/lexers
--- the scintillua_dirs list in the CONFIGURATION block below
---
--- so either set the variable in the web server environment, or place (or
--- symlink) the scintillua directory next to your cgitrc.
---
--- SECURITY
---
--- Every probed directory is placed on package.path and its Lua is executed in
--- cgit's process. Make sure none of them is writable by other users, or someone
--- who can write there gains code execution as the web server. On macOS in
--- particular, /opt/homebrew/share is group-writable by default.
---
--- LIMITATIONS
---
--- cgit sends the filter output through a C string sink that stops at the first
--- NUL byte, so a blob containing a NUL is truncated there. This affects binary
--- files that slip past cgit's text detection, not ordinary source.
---
--- OUTPUT
---
--- Tokens are wrapped in <span> elements carrying the hl- classes that
--- assets/cgit.css styles. Every input byte up to the first NUL is preserved, so
--- the line number gutter stays aligned.
-
---
--- ===== CONFIGURATION =====
---
-
--- Files larger than this many bytes are served escaped but unhighlighted, so a
--- huge blob does not cost a lexing pass. Kept well below cgit's max-blob-size.
-local max_bytes = 512 * 1024
-
--- Environment variable that, when set, points straight at the Scintillua
--- lexers directory and is used alone.
-local scintillua_env = "CGIT_SCINTILLUA_PATH"
-
--- Directories probed for the lexers when that variable is not set. The
--- directory of $CGIT_CONFIG, when set, is tried ahead of these. Keep every one
--- of these unwritable by others, see the SECURITY note above.
-local scintillua_dirs = {
- "/usr/local/share/scintillua/lexers",
- "/usr/share/scintillua/lexers",
- "/opt/homebrew/share/scintillua/lexers",
-}
-
--- Scintillua tag name (its first dotted component) to a cgit css class. Only
--- the six classes below exist in assets/cgit.css. Add a class there and a row
--- here to style more token kinds. Tokens with no row render as plain text,
--- which is what most themes want for operators and identifiers.
-local css = {
- comment = "hl-comment",
- string = "hl-string",
- regex = "hl-string",
- number = "hl-number",
- constant = "hl-number",
- keyword = "hl-keyword",
- preprocessor = "hl-keyword",
- tag = "hl-keyword",
- label = "hl-keyword",
- annotation = "hl-keyword",
- type = "hl-type",
- class = "hl-type",
- attribute = "hl-type",
- ["function"] = "hl-func",
-}
-
--- Extension to lexer-name fixes for the fallback path, used only when this
--- Scintillua has no detect(). Most extensions already equal their lexer name,
--- these are the frequent exceptions. A wrong guess just falls back to plain
--- text, so there is no harm in listing best-effort entries.
-local ext_lexer = {
- py = "python", js = "javascript", ts = "typescript",
- rb = "ruby", pl = "perl", pm = "perl", sh = "bash",
- md = "markdown", htm = "html", yml = "yaml",
- rs = "rust", c = "ansi_c", h = "ansi_c",
-}
-
---
--- =========================
---
-
-local lexer_mod = nil
-local filename = ""
-local chunks = {}
-
-local escape_map = { ["&"] = "&amp;", ["<"] = "&lt;", [">"] = "&gt;" }
-
--- Escape the three HTML metacharacters in a single pass.
-local function escape(s)
- return (string.gsub(s, "[&<>]", escape_map))
-end
-
-local function scintillua_path()
- local env = os.getenv(scintillua_env)
- if env then
- return env
- end
- local candidates = {}
- local config = os.getenv("CGIT_CONFIG")
- if config then
- local dir = string.match(config, "^(.*)/[^/]+$")
- if dir then
- candidates[#candidates + 1] = dir .. "/scintillua/lexers"
- end
- end
- for _, d in ipairs(scintillua_dirs) do
- candidates[#candidates + 1] = d
- end
- for _, dir in ipairs(candidates) do
- local f = io.open(dir .. "/lexer.lua", "r")
- if f then
- f:close()
- return dir
- end
- end
- return nil
-end
-
-local function load_scintillua()
- local dir = scintillua_path()
- if not dir then
- return nil
- end
- if not string.find(package.path, dir, 1, true) then
- package.path = dir .. "/?.lua;" .. package.path
- end
- local ok, mod = pcall(require, "lexer")
- -- A real Scintillua exposes load(). Anything else on the path that happens
- -- to be called lexer is not usable.
- if ok and type(mod) == "table" and type(mod.load) == "function" then
- return mod
- end
- return nil
-end
-
-local function load_lexer_name(name)
- if name == nil then
- return nil
- end
- local ok, lex = pcall(lexer_mod.load, name)
- if ok and lex then
- return lex
- end
- return nil
-end
-
--- Resolve a lexer for the file, preferring Scintillua's own filename detection
--- when this version provides it, then an extension map, then the raw extension.
-local function lexer_for(name)
- if type(lexer_mod.detect) == "function" then
- local ok, lang = pcall(lexer_mod.detect, name)
- if ok and lang then
- local lex = load_lexer_name(lang)
- if lex then
- return lex
- end
- end
- end
- local ext = string.match(name, "%.([^.]+)$")
- if not ext then
- return nil
- end
- ext = string.lower(ext)
- return load_lexer_name(ext_lexer[ext]) or load_lexer_name(ext)
-end
-
-local function highlight(text)
- local lex = lexer_for(filename)
- if not lex then
- return nil
- end
- local ok, tokens = pcall(lex.lex, lex, text)
- if not ok or type(tokens) ~= "table" then
- return nil
- end
- local out = {}
- local pos = 1
- for i = 1, #tokens, 2 do
- local tag = tokens[i]
- local fin = tokens[i + 1]
- local part = escape(string.sub(text, pos, fin - 1))
- local class = css[string.match(tag, "^[%w_]+")]
- if class and part ~= "" then
- part = "<span class='" .. class .. "'>" .. part .. "</span>"
- end
- out[#out + 1] = part
- pos = fin
- end
- -- Anything the lexer left unconsumed is kept, escaped.
- if pos <= #text then
- out[#out + 1] = escape(string.sub(text, pos))
- end
- return table.concat(out)
-end
-
-function filter_open(name)
- filename = name or ""
- chunks = {}
-end
-
-function filter_write(str)
- chunks[#chunks + 1] = str
-end
-
-function filter_close()
- local text = table.concat(chunks)
- chunks = {}
- if #text <= max_bytes then
- if lexer_mod == nil then
- lexer_mod = load_scintillua() or false
- end
- if lexer_mod then
- local ok, marked = pcall(highlight, text)
- if ok and marked then
- html(marked)
- return 0
- end
- end
- end
- -- Fallback, escaped plain text emitted in slices so a large blob does not
- -- cost a full-size second copy all at once.
- local n = #text
- if n == 0 then
- html("")
- return 0
- end
- local pos = 1
- while pos <= n do
- html(escape(string.sub(text, pos, pos + 65535)))
- pos = pos + 65536
- end
- return 0
-end