diff options
| -rw-r--r-- | assets/cgit.js | 29 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| -rw-r--r-- | source/ui-diff.c | 8 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| -rw-r--r-- | source/ui-shared.c | 2 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| -rw-r--r-- | source/ui-stats.c | 6 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| -rwxr-xr-x | tests/t0301-security.sh | 8 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
5 files changed, 16 insertions, 37 deletions
diff --git a/assets/cgit.js b/assets/cgit.js index 636ad33..c5bdf33 100644 --- a/assets/cgit.js +++ b/assets/cgit.js @@ -2,11 +2,10 @@ * The client side script that cgit serves with every page. Its main job is * to refresh the relative ages that cgit_print_age renders in * source/ui-shared.c, so the thresholds, suffixes and class names tabulated - * below mirror the constants there and the two have to move together. Two - * smaller pieces follow, the selects that reload the page when they change, - * and the highlight laid over the source line a URL fragment names. Each - * piece is wrapped in a function of its own so that nothing is left behind - * in the global scope. + * below mirror the constants there and the two have to move together. One + * smaller piece follows, the highlight laid over the source line a URL + * fragment names. Each piece is wrapped in a function of its own so that + * nothing is left behind in the global scope. */ (function () { @@ -97,26 +96,6 @@ document.addEventListener("DOMContentLoaded", function () { })(); /* - * Selects marked data-autosubmit reload the page with the new setting. They - * are wired up from here rather than with an inline onchange handler because - * a strict Content-Security-Policy blocks those, and a reader without - * scripting still has the noscript reload button the forms carry. - */ - -(function () { - -document.addEventListener("DOMContentLoaded", function () { - var i, selects = document.querySelectorAll("select[data-autosubmit]"); - - for (i = 0; i < selects.length; i++) - selects[i].addEventListener("change", function () { - this.form.submit(); - }); -}, false); - -})(); - -/* * Washes a faded highlight over the source line a URL fragment names, either * a single line as in #n231 or a range as in #n5-n12. The line anchors live * in the number gutter, so the anchor is measured and a bar of the same diff --git a/source/ui-diff.c b/source/ui-diff.c index 63c0148..e08b096 100644 --- a/source/ui-diff.c +++ b/source/ui-diff.c @@ -578,7 +578,7 @@ void cgit_print_diff_ctrls(void) html("<tr>"); html("<td class='label'>context:</td>"); html("<td class='ctrl'>"); - html("<select name='context' data-autosubmit='1'>"); + html("<select name='context'>"); selected = ctx.qry.context; if (!selected) selected = DEFAULT_CONTEXT_LINES; @@ -591,7 +591,7 @@ void cgit_print_diff_ctrls(void) html("</tr><tr>"); html("<td class='label'>space:</td>"); html("<td class='ctrl'>"); - html("<select name='ignorews' data-autosubmit='1'>"); + html("<select name='ignorews'>"); html_intoption(0, "include", ctx.qry.ignorews); html_intoption(1, "ignore", ctx.qry.ignorews); html("</select>"); @@ -599,14 +599,14 @@ void cgit_print_diff_ctrls(void) html("</tr><tr>"); html("<td class='label'>mode:</td>"); html("<td class='ctrl'>"); - html("<select name='dt' data-autosubmit='1'>"); + html("<select name='dt'>"); selected = ctx.qry.has_difftype ? ctx.qry.difftype : ctx.cfg.difftype; html_intoption(0, "unified", selected); html_intoption(1, "ssdiff", selected); html_intoption(2, "stat only", selected); html("</select></td></tr>"); html("<tr><td></td><td class='ctrl'>"); - html("<noscript><input type='submit' value='reload'></noscript>"); + html("<input type='submit' value='reload'>"); html("</td></tr></table>"); html("</form>\n"); html("</div>\n"); diff --git a/source/ui-shared.c b/source/ui-shared.c index 307dba0..a79c291 100644 --- a/source/ui-shared.c +++ b/source/ui-shared.c @@ -529,7 +529,7 @@ static void print_header(void) cgit_add_hidden_formfields(0, 1, ctx.qry.page); ctx.qry.oid = oid; ctx.qry.oid2 = oid2; - html("<select name='h' aria-label='Branch' data-autosubmit='1'>\n"); + html("<select name='h' aria-label='Branch'>\n"); if (pinned) { const char *hex = oid_to_hex(pinned); diff --git a/source/ui-stats.c b/source/ui-stats.c index 97918e0..5b36f54 100644 --- a/source/ui-stats.c +++ b/source/ui-stats.c @@ -385,7 +385,7 @@ static void print_options_form(const struct cgit_period *period, int top) if (ctx.repo->max_stats > 1) { choices = ctx.repo->max_stats; html("<tr><td class='label'>Period:</td>"); - html("<td class='ctrl'><select name='period' data-autosubmit='1'>"); + html("<td class='ctrl'><select name='period'>"); for (i = 0; i < choices; i++) html_option(cgit_fmt("%c", periods[i].code), periods[i].name, @@ -393,7 +393,7 @@ static void print_options_form(const struct cgit_period *period, int top) html("</select></td></tr>\n"); } html("<tr><td class='label'>Authors:</td>"); - html("<td class='ctrl'><select name='ofs' data-autosubmit='1'>"); + html("<td class='ctrl'><select name='ofs'>"); html_intoption(10, "10", top); html_intoption(25, "25", top); html_intoption(50, "50", top); @@ -401,7 +401,7 @@ static void print_options_form(const struct cgit_period *period, int top) html_intoption(-1, "all", top); html("</select></td></tr>\n"); html("<tr><td></td><td class='ctrl'>"); - html("<noscript><input type='submit' value='Reload'></noscript>"); + html("<input type='submit' value='reload'>"); html("</td></tr></table>"); html("</form>\n"); html("</div>\n"); diff --git a/tests/t0301-security.sh b/tests/t0301-security.sh index 8fce5f4..9a3af3c 100755 --- a/tests/t0301-security.sh +++ b/tests/t0301-security.sh @@ -118,12 +118,12 @@ test_expect_success 'non-markdown readme keeps its line structure' ' ' # A Content-Security-Policy without unsafe-inline stops an inline onchange -# handler from ever running, so the option forms only mark their selects and -# cgit.js wires the submit up from outside the page. -test_expect_success 'diff option selects use the autosubmit marker' ' +# handler from ever running, so the option form submits through a plain +# button and its selects carry no handlers at all. +test_expect_success 'diff options submit through a button' ' sha=$(git -C repos/foo rev-parse HEAD) && cgit_query "url=foo/commit&id=$sha" >tmp && - grep "data-autosubmit" tmp && + grep "type=.submit. value=.reload." tmp && ! grep "onchange" tmp ' |
