| Age | Commit message (Collapse) | Author | Lines |
|
The generator meta, the footer and the patch signature named the exact
cgit and git versions on every response, which only helps someone
matching a site against an advisory. The shipped server configs
already hide the server's own version for the same reason, and
`cgit --version` still answers on the host.
|
|
Only the login page carried a Cache-Control, so a page an auth filter
had let a visitor see could be kept by a cache shared with the next
visitor. The page also varies on the cookie that got them in.
|
|
Archives, packs and the HEAD file went out as octet-stream or gzip
with a UTF-8 charset on the end, since only the blob page cleared it.
The headers now decide from the type itself, so the two places that
cleared the charset by hand no longer need to.
|
|
Such a name is refused as a head before git could read it as an
option, and the fallback branch already skips it, so the switcher
offered a choice that led only to an error page.
|
|
The hop to the trailing-slash form of the about page, and the hop back
to the summary of a repository without a readme, were built from the
path alone, so a request for the about page of another branch landed
on the default one. The query goes into the Location line as the
client sent it, with any byte a header cannot carry percent-encoded.
|
|
|
|
|
|
|
|
|
|
`compose_snapshot_prefix` dropped the leading v of a tag only when just
one of the names 1.2, v1.2 and V1.2 resolved as a tag, so that the
shorter snapshot name could always be traced back to one tag. Those
probes went through ref lookups, and on a case-insensitive filesystem
a lookup for V1.2 finds the loose file of v1.2, so every freshly made
tag counted as ambiguous and kept its v. Once git packed the refs the
lookups became exact and the same tag quietly changed its snapshot
names.
The claimants on a stripped name are now counted over the tag list
itself with exact string comparison, so the answer no longer depends
on how a ref is stored or on the filesystem underneath. Two tags that
really differ only by the letter's case still both keep it.
|
|
|
|
|
|
|
|
|
|
noplainemail enable-plain-email
noheader enable-header
cache-root-ttl cache-index-ttl
cache-repo-ttl cache-summary-ttl
cache-scanrc-ttl cache-scan-ttl
agefile age-file
renamelimit rename-limit
extra-head-content head-content
|
|
A `max-stats` period enables the page again, as it did before
v2.2.0, so one key does both jobs.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
A submodule row linked to a path with its trailing slash stripped,
was labelled by its path rather than its entry name, shared the
name's element with its hash, claimed a size of zero and offered a
blame button that cannot work on a gitlink.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
`max-stats` only bounds the selectable periods now and no longer
doubles as the enable switch.
The tree walk runs before the history walk on purpose. Releasing
commit memory while walking history resets each commit slab index,
and a commit graph lookup afterwards would read another commit slot
and walk the wrong tree. The stats fixture writes a commit graph so
the tests cover that path. The history walk bounds the window in
process rather than passing a formatted since date to
`setup_revisions`, and parses each commit once.
|
|
|
|
|
|
|