diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Check `max-blob-size` before reading, default 10 MB
Only the tree view honoured the limit, and only after loading the whole object. The raw blob, plain, blame and readme paths now check the size before reading, and the default moves from unlimited to 10 MB so a fresh install never buffers a huge object whole, with zero still the opt-out.
Diffstat (limited to 'source/ui-tree.c')
-rw-r--r--source/ui-tree.c15
1 file changed, 8 insertions, 7 deletions
diff --git a/source/ui-tree.c b/source/ui-tree.c
index 292bfc6..f820f1f 100644
--- a/source/ui-tree.c
+++ b/source/ui-tree.c
@@ -117,6 +117,14 @@ static int print_object(const struct object_id *oid, const char *path, const cha
return 0;
}
+ /* Reject an oversized object before reading it whole into memory. */
+ if (ctx.cfg.max_blob_size && size / 1024 > (unsigned long)ctx.cfg.max_blob_size) {
+ cgit_print_error_page(413, "Too large",
+ "blob size (%luKB) exceeds display size limit (%dKB)",
+ size / 1024, ctx.cfg.max_blob_size);
+ return 0;
+ }
+
buf = odb_read_object(the_repository->objects, oid, &type, &size);
if (!buf) {
cgit_print_error_page(500, "Internal server error",
@@ -138,13 +146,6 @@ static int print_object(const struct object_id *oid, const char *path, const cha
}
html(")\n");
- if (ctx.cfg.max_blob_size && size / 1024 > ctx.cfg.max_blob_size) {
- htmlf("<div class='error'>blob size (%ldKB) exceeds display size limit (%dKB).</div>",
- size / 1024, ctx.cfg.max_blob_size);
- free(buf);
- return 1;
- }
-
if (is_binary)
print_binary_buffer(buf, size);
else