AgeCommit message (Collapse)AuthorLines
Drop the example cgitrc from the manualBryce Kwon-190/+0
Replace the browser markdown renderer with a filterBryce Kwon-13/+6
The readme is now escaped plain text unless `about-filter` points at the new `about-render.lua`, which renders markdown, man pages and plain text server-side. `enable-markdown` goes away with the renderer.
Add `max-patch-count` to bound the patch viewBryce Kwon-0/+5
Emit a conforming `rel=icon` for the favicon linkBryce Kwon-3/+4
Gate the stats page and add a language breakdownBryce Kwon-3/+14
`max-stats` only bounds the selectable periods now and no longer doubles as the enable switch. The tree walk runs before the history walk on purpose. Releasing commit memory while walking history resets each commit slab index, and a commit graph lookup afterwards would read another commit slot and walk the wrong tree. The stats fixture writes a commit graph so the tests cover that path. The history walk bounds the window in process rather than passing a formatted since date to `setup_revisions`, and parses each commit once.
Remove the owner filter hookBryce Kwon-18/+0
Move syntax highlighting to a Lua source filterBryce Kwon-5/+7
Stat oversized diffs instead of inlining themBryce Kwon-0/+12
Cap and paginate the ref listingsBryce Kwon-0/+6
Add a help page with common workflowsBryce Kwon-0/+6
Prune and rename the filter extensionsBryce Kwon-6/+7
The gentoo LDAP filter is distro specific, the owner example only restates what cgit already renders, and the about converters are superseded by the built-in markdown rendering. The two auth filters do the same job and differ only in where their accounts live, so they become `auth-inline` for accounts kept in the script and `auth-file` for accounts kept on disk.
Respect the cgitrc order of sectionsBryce Kwon-3/+3
The default sorted the sections and the repositories within them by name, so the order written in the cgitrc file was ignored.
Check `max-blob-size` before reading, default 10 MBBryce Kwon-2/+4
Only the tree view honoured the limit, and only after loading the whole object. The raw blob, plain, blame and readme paths now check the size before reading, and the default moves from unlimited to 10 MB so a fresh install never buffers a huge object whole, with zero still the opt-out.
Render README markdown in the browserBryce Kwon-4/+13
cgit had no markdown support of its own, so a readme was rendered through an external python filter or not at all. Escaping the source and formatting it in cgit.js keeps the work in the browser like the blob highlighter, and the page stays readable as plain text without scripting.
Add built-in syntax highlightingBryce Kwon-4/+6
Highlighting previously required a source filter shelling out to something like Pygments. A configured source filter still takes precedence, every character is preserved so the line gutter stays aligned, and large files are skipped.
Add `enable-tree-group-dirs` to list dirs firstBryce Kwon-0/+6
Gate the cache listing behind `enable-cache-list`Bryce Kwon-0/+6
The `ls_cache` page printed the cache directory path and the urls other visitors had requested, with no gate at all.
Reorganize into source, assets and librariesBryce Kwon-1/+1
The C sources move to source/, the served files to assets/, the bundled Git submodule to libraries/git and the filter scripts to extensions/. Everything the build generates now lands in build/, so a clean is a single remove and the tree stays clean.
ui-log: allow link following to be disabled per-repoJason A. Donenfeld-0/+4
This exists for other CPU heavy operations like blame, but doesn't for the follow functionality. Add it for that. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
config: add jsAndy Green-0/+5
Just like the config allows setting css URL path, add a config for setting the js URL path Signed-off-by: Andy Green <andy@warmcat.com> Reviewed-by: John Keeping <john@keeping.me.uk> Signed-off-by: Christian Hesse <mail@eworm.de>
css: change to be a listAndy Green-1/+2
Without changing the default behaviour of including /cgit.css if nothing declared, allow the "css" config to be given multiple times listing one or more alternative URL paths to be included in the document head area. Signed-off-by: Andy Green <andy@warmcat.com> Signed-off-by: Christian Hesse <mail@eworm.de>
cgitrc: handle value "0" for max-repo-countChristian Hesse-1/+2
Setting max-repo-count to "0" makes cgit loop forever generating page links. Make this a special value to show all repositories. Signed-off-by: Christian Hesse <mail@eworm.de>
about: allow to give head from queryChristian Hesse-5/+5
Reading the README from repository used to be limited to default branch or a branch given in configuration. Let's allow a branch from query if not specified explicitly. Signed-off-by: Christian Hesse <mail@eworm.de>
ui-snapshot: add support for zstd compressionChristian Hesse-3/+6
This patch adds support for zstd [0] compressed snapshots (*.tar.zst). We enable multiple working threads (-T0), but keep default compression level. The latter can be influenced by environment variable. [0] https://www.zstd.net/ Signed-off-by: Christian Hesse <mail@eworm.de>
ui-snapshot: add support for lzip compressionHanspeter Portner-2/+2
This patch adds support for lzip [1] compressed snapshots (*.tar.lz) [1] https://www.nongnu.org/lzip/ Signed-off-by: Hanspeter Portner <dev@open-music-kontrollers.ch> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
ui-tree: allow per repository override for enable-blameChristian Hesse-0/+4
The blame operation can cause high cost in terms of CPU load for huge repositories. Let's add a per repository override for enable-blame. Signed-off-by: Christian Hesse <mail@eworm.de>
cgitrc.5: add local tar signature exampleJason A. Donenfeld-3/+14
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgitrc.5: document new signature notesJason A. Donenfeld-1/+17
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
extra-head-content: introduce another option for meta tagsJason A. Donenfeld-0/+4
This is to support things like go-import meta tags, which are on a per-repo basis. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
manpage: fix sorting orderAndy Green-88/+88
You maybe didn't know you had OCD until you saw an alpha sorted list that has stuff out of order in it. Signed-off-by: Andy Green <andy@warmcat.com> Reviewed-by: John Keeping <john@keeping.me.uk>
global: remove functionality we deprecated for cgit v1.0Christian Hesse-21/+0
The man page states these were deprecated for v1.0. We are past v1.1, so remove the functionality. Signed-off-by: Christian Hesse <mail@eworm.de> Reviewed-by: John Keeping <john@keeping.me.uk>
snapshot: support special value 'all' to enable all formatsChristian Hesse-0/+1
Signed-off-by: Christian Hesse <mail@eworm.de> Reviewed-by: John Keeping <john@keeping.me.uk>
Add "snapshot-prefix" repo configurationJohn Keeping-0/+7
Allow using a user-specified value for the prefix in snapshot files instead of the repository basename. For example, files downloaded from the linux-stable.git repository should be named linux-$VERSION and not linux-stable-$VERSION, which can be achieved by setting: repo.snapshot-prefix=linux Signed-off-by: John Keeping <john@keeping.me.uk> Reviewed-by: Christian Hesse <mail@eworm.de>
ui-blame: add blame UIJeff Smith-0/+9
Implement a page which provides the blame view of a specified file. This feature is controlled by a new config variable, "enable-blame", which is disabled by default. Signed-off-by: Jeff Smith <whydoubt@gmail.com> Reviewed-by: John Keeping <john@keeping.me.uk>
Fix spelling in man pagePeter Colberg-2/+2
Signed-off-by: Peter Colberg <peter@colberg.org>
Renamed repo-specific configuration for enable-html-serving in cgitrc.5.txtMatt Comben-1/+1
ui-shared: add homepage to tabsJason A. Donenfeld-5/+8
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
ui-plain: add enable-html-serving flagJason A. Donenfeld-0/+11
Unrestricts plain/ to contents likely to be executed by browser.
log: allow users to follow a fileJohn Keeping-0/+4
Teach the "log" UI to behave in the same way as "git log --follow", when given a suitable instruction by the user. The default behaviour remains to show the log without following renames, but the follow behaviour can be activated by following a link in the page header. Follow is not the default because outputting merges in follow mode is tricky ("git log --follow" will not show merges). We also disable the graph in follow mode because the commit graph is not simplified so we end up with frequent gaps in the graph and many lines that do not connect with any commits we're actually showing. We also teach the "diff" and "commit" UIs to respect the follow flag on URLs, causing the single-file version of these UIs to detect renames. This feature is needed only for commits that rename the path we're interested in. For commits before the file has been renamed (i.e. that appear later in the log list) we change the file path in the links from the log to point to the old name; this means that links to commits always limit by the path known to that commit. If we didn't do this we would need to walk down the log diff'ing every commit whenever we want to show a commit. The drawback is that the "Log" link in the top bar of such a page links to the log limited by the old name, so it will only show pre-rename commits. I consider this a reasonable trade-off since the "Back" button still works and the log matches the path displayed in the top bar. Since following renames requires running diff on every commit we consider, I've added a knob to the configuration file to globally enable/disable this feature. Note that we may consider a large number of commits the revision walking machinery no longer performs any path limitation so we have to examine every commit until we find a page full of commits that affect the target path or something related to it. Suggested-by: René Neumann <necoro@necoro.eu> Signed-off-by: John Keeping <john@keeping.me.uk>
Add repo.hide and repo.ignoreLukas Fleischer-0/+10
These options can be used to hide a repository from the index or completely ignore a repository, respectively. They are particularly useful when used in combination with scan-path. Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
repolist: add owner-filterChris Burroughs-0/+18
This allows custom links to be used for repository owners by configuring a filter to be applied in the "Owner" column in the repository list.
cgitrc.5: we mean a cgi response, not requestJason A. Donenfeld-1/+1
remove trailing whitespaces from source filesChristian Hesse-1/+1
Clean up cache documentation.Jason A. Donenfeld-22/+25
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Skip cache slot when time-to-live is zeroLukas Fleischer-8/+14
If time-to-live is set to zero, we don't need to regenerate the cache slots on every request. Instead, just skip the caching process and immediately provide the dynamically generated version of the page. Setting time-to-live to zero is useful when you want to disable caching for certain pages. Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
Add a cache-snapshot-ttl configuration variableLukas Fleischer-0/+5
This can be used to specify the TTL for snapshots. Snapshots are usually static and do not ever change. On the other hand, tarball generation is CPU intensive. One use case of this setting (apart from increasing the lifetime of snapshot cache slots) is caching of snapshots while disabling the cache for static/dynamic HTML pages (by setting TTL to zero for everything except for snapshot requests). Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
auth: have cgit calculate login addressJason A. Donenfeld-2/+3
This way we're sure to use virtual root, or any other strangeness encountered. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
authentication: use hidden form instead of refererJason A. Donenfeld-1/+2
This also gives us some CSRF protection. Note that we make use of the hmac to protect the redirect value. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
auth: add basic authentication filter frameworkJason A. Donenfeld-1/+35
This leverages the new lua support. See filters/simple-authentication.lua for explaination of how this works. There is also additional documentation in cgitrc.5.txt. Though this is a cookie-based approach, cgit's caching mechanism is preserved for authenticated pages. Very plugable and extendable depending on user needs. The sample script uses an HMAC-SHA1 based cookie to store the currently logged in user, with an expiration date. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: allow returning exit code from filterJason A. Donenfeld-1/+2
Filters can now indicate a status back to cgit by means of the exit code for exec, or the return value from close for Lua. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>