| Age | Commit message (Collapse) | Author | Lines |
|
|
|
|
|
|
|
|
|
|
|
The filters signed the request url and later wrote it into a Location
header, and the signing step re-encoded a newline that the verifying
step decoded back, so a crafted url could smuggle CR and LF into the
response. The cookie HMAC was also checked with a short-circuiting
comparison and carried no SameSite attribute.
|
|
The gentoo LDAP filter is distro specific, the owner example only
restates what cgit already renders, and the about converters are
superseded by the built-in markdown rendering. The two auth filters
do the same job and differ only in where their accounts live, so they
become `auth-inline` for accounts kept in the script and `auth-file`
for accounts kept on disk.
|
|
Lua is becoming the one language for the filter extensions, and this
was the last shell filter.
|
|
cgit had no markdown support of its own, so a readme was rendered
through an external python filter or not at all. Escaping the source
and formatting it in cgit.js keeps the work in the browser like the
blob highlighter, and the page stays readable as plain text without
scripting.
|
|
Highlighting previously required a source filter shelling out to
something like Pygments. A configured source filter still takes
precedence, every character is preserved so the line gutter stays
aligned, and large files are skipped.
|
|
The C sources move to source/, the served files to assets/, the bundled
Git submodule to libraries/git and the filter scripts to extensions/.
Everything the build generates now lands in build/, so a clean is a
single remove and the tree stays clean.
|