AgeCommit message (Collapse)AuthorLines
Harden the auth filter headers and session cookieBryce Kwon-5/+31
The filters signed the request url and later wrote it into a Location header, and the signing step re-encoded a newline that the verifying step decoded back, so a crafted url could smuggle CR and LF into the response. The cookie HMAC was also checked with a short-circuiting comparison and carried no SameSite attribute.
Prune and rename the filter extensionsBryce Kwon-0/+327
The gentoo LDAP filter is distro specific, the owner example only restates what cgit already renders, and the about converters are superseded by the built-in markdown rendering. The two auth filters do the same job and differ only in where their accounts live, so they become `auth-inline` for accounts kept in the script and `auth-file` for accounts kept on disk.