diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Escape non-markdown readmes without a filter
A readme that is not markdown was written to the about page as raw HTML when no about-filter was configured, so an untrusted repository could inject script.
Diffstat (limited to 'source')
-rw-r--r--source/ui-summary.c18
1 file changed, 16 insertions, 2 deletions
diff --git a/source/ui-summary.c b/source/ui-summary.c
index 7e533e1..471f0c9 100644
--- a/source/ui-summary.c
+++ b/source/ui-summary.c
@@ -157,9 +157,23 @@ void cgit_print_repo_readme(const char *path)
strbuf_release(&sb);
}
html("</div>");
+ } else if (!ctx.repo->about_filter) {
+ /* No about-filter is configured, so there is nothing to turn
+ * the readme source into safe HTML. Escape it rather than serve
+ * repo content raw, which would let an untrusted repository
+ * inject script into the about page.
+ */
+ if (ref) {
+ cgit_print_file(filename, ref, 1, 1);
+ } else {
+ struct strbuf sb = STRBUF_INIT;
+ if (strbuf_read_file(&sb, filename, 0) >= 0)
+ html_txt(sb.buf);
+ strbuf_release(&sb);
+ }
} else {
- /* Otherwise print the readme through the about-filter, or raw
- * when none is configured.
+ /* An about-filter is configured and is responsible for turning
+ * the source into safe HTML, so pass it through the filter raw.
*/
cgit_open_filter(ctx.repo->about_filter, filename);
if (ref)