diff options
context:
space:
mode:
Diffstat (limited to '')
-rw-r--r--cgitrc.5.txt6
-rw-r--r--source/cgit.c2
-rw-r--r--source/cgit.h1
-rw-r--r--source/cmd.c6
-rwxr-xr-xtests/setup.sh1
5 files changed, 16 insertions, 0 deletions
diff --git a/cgitrc.5.txt b/cgitrc.5.txt
index 7a0cf03..d9f0b93 100644
--- a/cgitrc.5.txt
+++ b/cgitrc.5.txt
@@ -156,6 +156,12 @@ enable-filter-overrides::
Flag which, when set to "1", allows all filter settings to be
overridden in repository-specific cgitrc files. Default value: none.
+enable-cache-list::
+ Flag which, when set to "1", exposes the "ls_cache" page. That page
+ lists the cache directory path and the URLs of requests other visitors
+ made, so it is disabled by default and should stay off on any instance
+ where that disclosure matters. Default value: "0".
+
enable-follow-links::
Flag which, when set to "1", allows users to follow a file in the log
view. Default value: "0".
diff --git a/source/cgit.c b/source/cgit.c
index ca318e8..91dd9a7 100644
--- a/source/cgit.c
+++ b/source/cgit.c
@@ -201,6 +201,8 @@ static void config_cb(const char *name, const char *value)
ctx.cfg.enable_tree_linenumbers = atoi(value);
else if (!strcmp(name, "enable-git-config"))
ctx.cfg.enable_git_config = atoi(value);
+ else if (!strcmp(name, "enable-cache-list"))
+ ctx.cfg.enable_cache_list = atoi(value);
else if (!strcmp(name, "max-stats"))
ctx.cfg.max_stats = cgit_find_stats_period(value, NULL);
else if (!strcmp(name, "cache-size"))
diff --git a/source/cgit.h b/source/cgit.h
index 7d7ece7..634d2f5 100644
--- a/source/cgit.h
+++ b/source/cgit.h
@@ -243,6 +243,7 @@ struct cgit_config {
int enable_html_serving;
int enable_tree_linenumbers;
int enable_git_config;
+ int enable_cache_list;
int local_time;
int max_atom_items;
int max_repo_count;
diff --git a/source/cmd.c b/source/cmd.c
index 0eb75b1..7eb642c 100644
--- a/source/cmd.c
+++ b/source/cmd.c
@@ -107,6 +107,12 @@ static void log_fn(void)
static void ls_cache_fn(void)
{
+ /* The listing exposes the cache path and the URLs other visitors
+ * requested, so it stays off unless an admin opts in. */
+ if (!ctx.cfg.enable_cache_list) {
+ cgit_print_error_page(404, "Not found", "Not found");
+ return;
+ }
ctx.page.mimetype = "text/plain";
ctx.page.filename = "ls-cache.txt";
cgit_print_http_headers();
diff --git a/tests/setup.sh b/tests/setup.sh
index db5361c..a49a52b 100755
--- a/tests/setup.sh
+++ b/tests/setup.sh
@@ -108,6 +108,7 @@ virtual-root=/
cache-root=$PWD/cache
cache-size=1021
+enable-cache-list=1
snapshots=tar.gz tar.bz tar.lz tar.xz tar.zst zip
enable-log-filecount=1
enable-log-linecount=1