diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Gate scanned filters with `trust-scan-filters`
Diffstat (limited to '')
-rw-r--r--source/scan-tree.c16
1 file changed, 14 insertions, 2 deletions
diff --git a/source/scan-tree.c b/source/scan-tree.c
index c46b47d..ba2149a 100644
--- a/source/scan-tree.c
+++ b/source/scan-tree.c
@@ -48,6 +48,17 @@ static int is_git_dir(const char *path)
return 1;
}
+// A filter is a command cgit runs, and a repository's own files belong to
+// whoever can push to it, so their filter keys wait on trust-scan-filters.
+static int trusted_key(const char *name)
+{
+ if (!ends_with(name, "-filter") || ctx.cfg.trust_scan_filters)
+ return 1;
+ fprintf(stderr, "[cgit] Ignoring %s in %s: trust-scan-filters is not set\n", name,
+ current_repo->path);
+ return 0;
+}
+
static int apply_gitconfig(const char *key, const char *value,
const __attribute__((unused)) struct config_context *cfg_ctx, void *cb)
{
@@ -59,7 +70,7 @@ static int apply_gitconfig(const char *key, const char *value,
cgit_repo_config(current_repo, "desc", value);
else if (!strcmp(key, "gitweb.category"))
cgit_repo_config(current_repo, "section", value);
- else if (skip_prefix(key, "cgit.", &name))
+ else if (skip_prefix(key, "cgit.", &name) && trusted_key(name))
cgit_repo_config(current_repo, name, value);
return 0;
@@ -67,7 +78,8 @@ static int apply_gitconfig(const char *key, const char *value,
static void apply_cgitrc(const char *name, const char *value)
{
- cgit_repo_config(current_repo, name, value);
+ if (trusted_key(name))
+ cgit_repo_config(current_repo, name, value);
}
static char *find_char_back(char *start, char *from, int c)