AgeCommit message (Collapse)AuthorLines
Prune and rename the filter extensionsBryce Kwon-461/+37
The gentoo LDAP filter is distro specific, the owner example only restates what cgit already renders, and the about converters are superseded by the built-in markdown rendering. The two auth filters do the same job and differ only in where their accounts live, so they become `auth-inline` for accounts kept in the script and `auth-file` for accounts kept on disk.
Convert the commit-links filter to LuaBryce Kwon-28/+27
Lua is becoming the one language for the filter extensions, and this was the last shell filter.
Drop unused config and query fieldsBryce Kwon-7/+0
Key the cache on scheme and hostBryce Kwon-2/+15
Clone urls and atom links are built from the request scheme and Host, but the cache key left them out, so a request with a spoofed Host could cache a page carrying a bogus clone url and serve it to other visitors.
Close the layout on stat-only diffsBryce Kwon-1/+4
The stat-only diff path returned before the closing call, so the content wrapper, footer and closing tags were never emitted.
Emit `updated` on an empty atom feedBryce Kwon-0/+7
The feed-level element was written only inside the commit loop, so a feed with no commits omitted an element the atom format requires.
Fix diffstat and submodule diff outputBryce Kwon-7/+11
The diffstat divided by zero when a commit changed no lines, and a submodule change was printed with a hardcoded length that dropped a digit of a sha-1 and most of a sha-256.
URL-encode the repolist pager linksBryce Kwon-2/+2
The pager html-escaped its search and sort values instead of url-encoding them, so a term with a hash or ampersand broke the link and dropped the active filter on the next page.
Bound the authenticate-post length safelyBryce Kwon-3/+4
The POST length was clamped with a signed comparison, so a very large Content-Length could turn negative and slip past the limit into the fixed-size buffer.
Compare repository idle times by signBryce Kwon-1/+7
The idle-sort comparator returned a 64-bit time difference truncated to int, which could flip sign and leave the ordering inconsistent.
Date repositories from HEAD and guard its branchBryce Kwon-2/+27
The index derived a repository's age from `refs/heads/master` alone, so a repository on any other default branch showed no age. HEAD is repo-controlled and the age stat walks under `refs/heads`, so a branch name carrying a parent-directory component is rejected.
Respect the cgitrc order of sectionsBryce Kwon-4/+4
The default sorted the sections and the repositories within them by name, so the order written in the cgitrc file was ignored.
Keep snapshots working under a global git configBryce Kwon-1/+7
cgit unsets HOME to isolate git from the calling user, but git still finds the global config through its getpwuid fallback and then dies expanding a `~` in `core.excludesfile`. That die happened after the snapshot headers and the gzip filter were already in place, so the error page was compressed into the archive and every snapshot came out undecompressable.
Reject option-like revisions in the log walkBryce Kwon-0/+12
The log page passed the `id` query parameter to git's revision parser without resolving it and ahead of the end-of-options marker. A value like `id=--output=/path` was then parsed as an option, so an unauthenticated request could create or truncate any file the server user could write. No valid ref or object name begins with a dash.
Clamp the log offset to bound history walksBryce Kwon-1/+11
A crafted `ofs` could send cgit walking most of the history for one request.
Require a boundary in the about-path prefix checkBryce Kwon-1/+7
The about subpath was confined to the readme directory with a plain byte-prefix match, so a sibling directory sharing the base name as a prefix passed the check and its files were served.
Build the tree line gutter in one bufferBryce Kwon-2/+5
The line-number gutter did one allocation and one write per line.
Check `max-blob-size` before reading, default 10 MBBryce Kwon-10/+37
Only the tree view honoured the limit, and only after loading the whole object. The raw blob, plain, blame and readme paths now check the size before reading, and the default moves from unlimited to 10 MB so a fresh install never buffers a huge object whole, with zero still the opt-out.
Harden the blob view error pathsBryce Kwon-13/+27
A blob requested by ref with an unknown path fell through to the commit object and was served with a 200 instead of a 404, two error pages passed a null pointer to a %s format when the request carried no object id, and the error pages left the layout open.
Keep an overlong path out of the tab titleBryce Kwon-4/+15
`fmt()` aborts the request rather than truncate, so a very long path fed into a context-sensitive tab title took down page rendering.
Fix the stats year label and a missing authorBryce Kwon-2/+4
The year period rendered without its label, and a commit with no author line crashed the view.
Cast signed chars before ctype callsBryce Kwon-6/+6
A plain char is undefined in the ctype functions for negative values, which a high byte produces wherever char is signed.
Avoid an out-of-bounds read on short scan pathsBryce Kwon-1/+1
A relative path shorter than five bytes made the `/.git` suffix test read before the buffer.
Bail out on a read error in `read_first_line`Bryce Kwon-2/+11
`read_in_full` returns a signed -1 on error, which became SIZE_MAX once stored in the size_t length and then wrote a terminator far out of bounds.
Tolerate a missing or empty repository URLBryce Kwon-2/+4
`trim_end()` returns NULL when a repo url is empty or all slashes and the later newline trim dereferenced it. The legacy `r=` and `p=about` path also read the last byte of the url without checking it was set.
Clamp negative ages in the age refresherBryce Kwon-0/+6
Escape non-markdown readmes without a filterBryce Kwon-2/+16
A readme that is not markdown was written to the about page as raw HTML when no about-filter was configured, so an untrusted repository could inject script.
Render README markdown in the browserBryce Kwon-322/+313
cgit had no markdown support of its own, so a readme was rendered through an external python filter or not at all. Escaping the source and formatting it in cgit.js keeps the work in the browser like the blob highlighter, and the page stays readable as plain text without scripting.
Add built-in syntax highlightingBryce Kwon-181/+247
Highlighting previously required a source filter shelling out to something like Pygments. A configured source filter still takes precedence, every character is preserved so the line gutter stays aligned, and large files are skipped.
Adapt the layout to small screensBryce Kwon-8/+138
On a phone the description, owner and shortcut columns crowded the index and pushed the age off screen, and tapping the name already opens the repository, so the index collapses to name and age.
Add a light and dark theme toggleBryce Kwon-5/+108
The button is emitted hidden and only revealed by the script, so a browser without JavaScript never shows a control that cannot work and the page keeps tracking the system theme.
Overhaul the stylesheet with tokens and dark modeBryce Kwon-225/+466
The old sheet had no overflow rules, so wide code, diff, blame and stats blocks scrolled the whole page sideways on a phone. The classic layout, badge colours and age shading are kept.
Add viewport and color-scheme meta tagsBryce Kwon-0/+5
Without a viewport meta, mobile browsers assume a desktop-width page and scale it down, which is the root cause of content overflowing on small screens.
Rebuild the page chrome as semantic HTMLBryce Kwon-103/+189
The masthead, tab bar, breadcrumb, content region and footer were HTML tables, which cannot reflow and forced the page to scroll sideways on small screens. Class and id names are kept so custom themes keep matching, the tabs gain title hints and the form controls accessible names.
Add `enable-tree-group-dirs` to list dirs firstBryce Kwon-5/+69
Gate the cache listing behind `enable-cache-list`Bryce Kwon-0/+16
The `ls_cache` page printed the cache directory path and the urls other visitors had requested, with no gate at all.
Add gitattributesBryce Kwon-0/+3
Add a draft-release workflow that runs on tagsBryce Kwon-0/+54
Add a CI workflowBryce Kwon-0/+106
Let cgit build with or without LuaBryce Kwon-8/+17
Lua only powers the filter extensions, so it stays optional and autodetected. `NO_LUA` yields a self-contained binary and the release script links Lua only when asked to.
Add a hardened release build scriptBryce Kwon-0/+27
The hardening flags are ELF specific and would break local macOS development, so they stay out of the default build.
Add a local CGI preview server for developmentBryce Kwon-0/+205
cgit runs as a CGI program, so previewing it normally means running Apache or nginx, and Python 3.13 removed its built-in CGI handler. It is a development aid and not meant to face the internet.
Replace the glibc-only `memrchr` for portabilityBryce Kwon-1/+12
Drop the OpenSSL build dependencyBryce Kwon-2/+2
macOS selects CommonCrypto so this never surfaced there, but on Linux the build failed on a missing openssl header unless libssl-dev was installed. cgit is read-only and needs no crypto.
Reorganize into source, assets and librariesBryce Kwon-143/+144
The C sources move to source/, the served files to assets/, the bundled Git submodule to libraries/git and the filter scripts to extensions/. Everything the build generates now lands in build/, so a clean is a single remove and the tree stays clean.
Bump versionv1.3.1Jason A. Donenfeld-1/+1
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
global: fix libc constness warningsJason A. Donenfeld-7/+10
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
git: update to v2.54.0Christian Hesse-11/+15
Update to git version v2.54.0, this requires changes for these upstream commits: * d9ecf268ef3f69130fa269012318470d908978f6 odb: embed base source in the "files" backend * cb506a8a69c953f7b87bb3ae099e0bed8218d3ab odb: introduce "files" source ... and probably more related. Signed-off-by: Christian Hesse <mail@eworm.de> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgit: truncate all config values at the newlineJason A. Donenfeld-60/+62
These would be largely invalid anyway (save, I suppose, for Linux file paths that technically can contain new lines). The actual problem is that these get printed back out into cached -- and trusted -- cgitrc files, and if the fields have newlines, the git-config way of less trusted users configuring repos on a shared system can be abused to inject newlines, which then can be used to smuggle global options (including filters, which execute code) into the cached cgitrc. So now, only ever duplicate up to the newline, when dealing with these inputs. Reported-by: Adrian Denkiewicz <adrian@doyensec.com> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgit: use strchrnul instead of open codingJason A. Donenfeld-3/+1
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>