AgeCommit message (Collapse)AuthorLines
Release v2.1.0v2.1.0Bryce Kwon-1/+1
Keep the version fallback in shallow buildsBryce Kwon-2/+8
A checkout without tags made `git describe` fail and the empty result overwrote the fallback, so CI release binaries carried no version at all. The release workflow now also fetches tags so a tag build stamps its exact version.
Run CI only on branch pushesBryce Kwon-1/+2
Even out font sizes and drop dead stylesBryce Kwon-116/+47
Remove the owner filter hookBryce Kwon-55/+3
Declutter the interface on small screensBryce Kwon-36/+32
Follow the theme in the external tab iconBryce Kwon-3/+13
Highlight and center fragment-targeted linesBryce Kwon-0/+79
Move syntax highlighting to a Lua source filterBryce Kwon-250/+247
Stat oversized diffs instead of inlining themBryce Kwon-3/+130
Cap and paginate the ref listingsBryce Kwon-14/+189
Add a help page with common workflowsBryce Kwon-0/+182
Keep line structure in plaintext readmesBryce Kwon-1/+29
Submit option forms without inline handlersBryce Kwon-6/+34
Add security and fork-behaviour regression testsv2.0.0Bryce Kwon-0/+113
Rewrite the README for the fork as `README.txt`Bryce Kwon-99/+144
Point the fork's links and credits at itselfBryce Kwon-34/+42
AUTHORS now records the upstream developers as the project's history rather than as maintainers of the fork.
Add a post-update hook for HTTP clonesBryce Kwon-0/+18
cgit's built-in clone support speaks the dumb HTTP protocol, which serves static files that only `git update-server-info` refreshes. Without this hook a clone can miss refs pushed after the repository was created.
Add example web server configurationsBryce Kwon-0/+477
The wiring has real pitfalls around PATH_INFO and the link base, so these ship as working commented configs. nginx needs the fcgiwrap bridge while apache and lighttpd run the CGI directly. The security headers live here rather than in cgit because they must also cover the static assets the server serves itself.
Add a commented example configurationBryce Kwon-0/+548
Harden the auth filter headers and session cookieBryce Kwon-10/+62
The filters signed the request url and later wrote it into a Location header, and the signing step re-encoded a newline that the verifying step decoded back, so a crafted url could smuggle CR and LF into the response. The cookie HMAC was also checked with a short-circuiting comparison and carried no SameSite attribute.
Prune and rename the filter extensionsBryce Kwon-461/+37
The gentoo LDAP filter is distro specific, the owner example only restates what cgit already renders, and the about converters are superseded by the built-in markdown rendering. The two auth filters do the same job and differ only in where their accounts live, so they become `auth-inline` for accounts kept in the script and `auth-file` for accounts kept on disk.
Convert the commit-links filter to LuaBryce Kwon-28/+27
Lua is becoming the one language for the filter extensions, and this was the last shell filter.
Drop unused config and query fieldsBryce Kwon-7/+0
Key the cache on scheme and hostBryce Kwon-2/+15
Clone urls and atom links are built from the request scheme and Host, but the cache key left them out, so a request with a spoofed Host could cache a page carrying a bogus clone url and serve it to other visitors.
Close the layout on stat-only diffsBryce Kwon-1/+4
The stat-only diff path returned before the closing call, so the content wrapper, footer and closing tags were never emitted.
Emit `updated` on an empty atom feedBryce Kwon-0/+7
The feed-level element was written only inside the commit loop, so a feed with no commits omitted an element the atom format requires.
Fix diffstat and submodule diff outputBryce Kwon-7/+11
The diffstat divided by zero when a commit changed no lines, and a submodule change was printed with a hardcoded length that dropped a digit of a sha-1 and most of a sha-256.
URL-encode the repolist pager linksBryce Kwon-2/+2
The pager html-escaped its search and sort values instead of url-encoding them, so a term with a hash or ampersand broke the link and dropped the active filter on the next page.
Bound the authenticate-post length safelyBryce Kwon-3/+4
The POST length was clamped with a signed comparison, so a very large Content-Length could turn negative and slip past the limit into the fixed-size buffer.
Compare repository idle times by signBryce Kwon-1/+7
The idle-sort comparator returned a 64-bit time difference truncated to int, which could flip sign and leave the ordering inconsistent.
Date repositories from HEAD and guard its branchBryce Kwon-2/+27
The index derived a repository's age from `refs/heads/master` alone, so a repository on any other default branch showed no age. HEAD is repo-controlled and the age stat walks under `refs/heads`, so a branch name carrying a parent-directory component is rejected.
Respect the cgitrc order of sectionsBryce Kwon-4/+4
The default sorted the sections and the repositories within them by name, so the order written in the cgitrc file was ignored.
Keep snapshots working under a global git configBryce Kwon-1/+7
cgit unsets HOME to isolate git from the calling user, but git still finds the global config through its getpwuid fallback and then dies expanding a `~` in `core.excludesfile`. That die happened after the snapshot headers and the gzip filter were already in place, so the error page was compressed into the archive and every snapshot came out undecompressable.
Reject option-like revisions in the log walkBryce Kwon-0/+12
The log page passed the `id` query parameter to git's revision parser without resolving it and ahead of the end-of-options marker. A value like `id=--output=/path` was then parsed as an option, so an unauthenticated request could create or truncate any file the server user could write. No valid ref or object name begins with a dash.
Clamp the log offset to bound history walksBryce Kwon-1/+11
A crafted `ofs` could send cgit walking most of the history for one request.
Require a boundary in the about-path prefix checkBryce Kwon-1/+7
The about subpath was confined to the readme directory with a plain byte-prefix match, so a sibling directory sharing the base name as a prefix passed the check and its files were served.
Build the tree line gutter in one bufferBryce Kwon-2/+5
The line-number gutter did one allocation and one write per line.
Check `max-blob-size` before reading, default 10 MBBryce Kwon-10/+37
Only the tree view honoured the limit, and only after loading the whole object. The raw blob, plain, blame and readme paths now check the size before reading, and the default moves from unlimited to 10 MB so a fresh install never buffers a huge object whole, with zero still the opt-out.
Harden the blob view error pathsBryce Kwon-13/+27
A blob requested by ref with an unknown path fell through to the commit object and was served with a 200 instead of a 404, two error pages passed a null pointer to a %s format when the request carried no object id, and the error pages left the layout open.
Keep an overlong path out of the tab titleBryce Kwon-4/+15
`fmt()` aborts the request rather than truncate, so a very long path fed into a context-sensitive tab title took down page rendering.
Fix the stats year label and a missing authorBryce Kwon-2/+4
The year period rendered without its label, and a commit with no author line crashed the view.
Cast signed chars before ctype callsBryce Kwon-6/+6
A plain char is undefined in the ctype functions for negative values, which a high byte produces wherever char is signed.
Avoid an out-of-bounds read on short scan pathsBryce Kwon-1/+1
A relative path shorter than five bytes made the `/.git` suffix test read before the buffer.
Bail out on a read error in `read_first_line`Bryce Kwon-2/+11
`read_in_full` returns a signed -1 on error, which became SIZE_MAX once stored in the size_t length and then wrote a terminator far out of bounds.
Tolerate a missing or empty repository URLBryce Kwon-2/+4
`trim_end()` returns NULL when a repo url is empty or all slashes and the later newline trim dereferenced it. The legacy `r=` and `p=about` path also read the last byte of the url without checking it was set.
Clamp negative ages in the age refresherBryce Kwon-0/+6
Escape non-markdown readmes without a filterBryce Kwon-2/+16
A readme that is not markdown was written to the about page as raw HTML when no about-filter was configured, so an untrusted repository could inject script.
Render README markdown in the browserBryce Kwon-322/+313
cgit had no markdown support of its own, so a readme was rendered through an external python filter or not at all. Escaping the source and formatting it in cgit.js keeps the work in the browser like the blob highlighter, and the page stays readable as plain text without scripting.
Add built-in syntax highlightingBryce Kwon-181/+247
Highlighting previously required a source filter shelling out to something like Pygments. A configured source filter still takes precedence, every character is preserved so the line gutter stays aligned, and large files are skipped.