AgeCommit message (Collapse)AuthorLines
Move syntax highlighting to a Lua source filterBryce Kwon-0/+202
Harden the auth filter headers and session cookieBryce Kwon-10/+62
The filters signed the request url and later wrote it into a Location header, and the signing step re-encoded a newline that the verifying step decoded back, so a crafted url could smuggle CR and LF into the response. The cookie HMAC was also checked with a short-circuiting comparison and carried no SameSite attribute.
Prune and rename the filter extensionsBryce Kwon-455/+30
The gentoo LDAP filter is distro specific, the owner example only restates what cgit already renders, and the about converters are superseded by the built-in markdown rendering. The two auth filters do the same job and differ only in where their accounts live, so they become `auth-inline` for accounts kept in the script and `auth-file` for accounts kept on disk.
Convert the commit-links filter to LuaBryce Kwon-28/+27
Lua is becoming the one language for the filter extensions, and this was the last shell filter.
Render README markdown in the browserBryce Kwon-306/+0
cgit had no markdown support of its own, so a readme was rendered through an external python filter or not at all. Escaping the source and formatting it in cgit.js keeps the work in the browser like the blob highlighter, and the page stays readable as plain text without scripting.
Add built-in syntax highlightingBryce Kwon-176/+0
Highlighting previously required a source filter shelling out to something like Pygments. A configured source filter still takes precedence, every character is preserved so the line gutter stays aligned, and large files are skipped.
Reorganize into source, assets and librariesBryce Kwon-0/+1705
The C sources move to source/, the served files to assets/, the bundled Git submodule to libraries/git and the filter scripts to extensions/. Everything the build generates now lands in build/, so a clean is a single remove and the tree stays clean.