AgeCommit message (Collapse)AuthorLines
Send a charset only with a text typeBryce Kwon-1/+0
Archives, packs and the HEAD file went out as octet-stream or gzip with a UTF-8 charset on the end, since only the blob page cleared it. The headers now decide from the type itself, so the two places that cleared the charset by hand no longer need to.
Add stable markup hooks for site themesBryce Kwon-10/+10
Align with spaces instead of tabsBryce Kwon-2/+2
Harden the page renderersBryce Kwon-4/+13
Clean up the whole treeBryce Kwon-10/+5
Trim the comments and dead code across the treeBryce Kwon-8/+5
Point clone rows at a url a browser can followBryce Kwon-7/+1
Replace `nbsp` spacing with CSSBryce Kwon-4/+4
Tidy the structure of the generated markupBryce Kwon-2/+2
Remove the obsolete summary attributesBryce Kwon-3/+3
Let the listings wrap and the diff tables scrollBryce Kwon-2/+2
Restyle the sources and fix the audit's findingsBryce Kwon-60/+83
Settle the names, types and layout of the sourcesBryce Kwon-2/+2
Replace the browser markdown renderer with a filterBryce Kwon-30/+4
The readme is now escaped plain text unless `about-filter` points at the new `about-render.lua`, which renders markdown, man pages and plain text server-side. `enable-markdown` goes away with the renderer.
Keep line structure in plaintext readmesBryce Kwon-1/+4
Point the fork's links and credits at itselfBryce Kwon-1/+1
AUTHORS now records the upstream developers as the project's history rather than as maintainers of the fork.
Require a boundary in the about-path prefix checkBryce Kwon-1/+7
The about subpath was confined to the readme directory with a plain byte-prefix match, so a sibling directory sharing the base name as a prefix passed the check and its files were served.
Escape non-markdown readmes without a filterBryce Kwon-2/+16
A readme that is not markdown was written to the about page as raw HTML when no about-filter was configured, so an untrusted repository could inject script.
Render README markdown in the browserBryce Kwon-9/+39
cgit had no markdown support of its own, so a readme was rendered through an external python filter or not at all. Escaping the source and formatting it in cgit.js keeps the work in the browser like the blob highlighter, and the page stays readable as plain text without scripting.
Reorganize into source, assets and librariesBryce Kwon-0/+0
The C sources move to source/, the served files to assets/, the bundled Git submodule to libraries/git and the filter scripts to extensions/. Everything the build generates now lands in build/, so a clean is a single remove and the tree stays clean.
global: make 'char *path' const where possibleChristian Hesse-1/+1
Signed-off-by: Christian Hesse <mail@eworm.de>
ui-summary: send images plain for about pageChristian Hesse-2/+13
The about page used to display just fine, but images were broken: The binary image data was embedded in html code. Use cgit_print_plain() to send images in plain mode and make them available on about page. Signed-off-by: Christian Hesse <mail@eworm.de>
summary: move layout into page functionJohn Keeping-0/+2
Signed-off-by: John Keeping <john@keeping.me.uk>
about: move layout into page functionsJohn Keeping-2/+6
Signed-off-by: John Keeping <john@keeping.me.uk>
Remove redundant includesJohn Keeping-1/+0
These are all included in git-compat-util.h (when necessary), which we include in cgit.h. Signed-off-by: John Keeping <john@keeping.me.uk>
Avoid non-ANSI function declarationsJohn Keeping-1/+1
Sparse says things like: warning: non-ANSI function declaration of function 'calc_ttl' Signed-off-by: John Keeping <john@keeping.me.uk>
cgit: show clone URLs for empty repoJason A. Donenfeld-1/+1
ui-summary: add "rel='vcs-git'" to clone URL linksJohn Keeping-2/+4
This is described in the rel-vcs microformat[1]. [1] https://joeyh.name/rfc/rel-vcs/ Signed-off-by: John Keeping <john@keeping.me.uk>
Extract clone URL printing to ui-shared.cJohn Keeping-46/+12
This will allow us to reuse the same logic to add clone URL <link/> elements to the header of all repo-specific pages in order to support the rel-vcs microformat. Signed-off-by: John Keeping <john@keeping.me.uk>
git: update for git 2.0Christian Hesse-1/+1
prefixcmp() and suffixcmp() have been remove, functionality is now provided by starts_with() and ends_with(). Retrurn values have been changed, so instead of just renaming we have to fix logic. Everything else looks just fine.
remove trailing whitespaces from source filesChristian Hesse-2/+2
filter: return on null filter from open and closeJason A. Donenfeld-6/+2
So that we don't have to include the if(filter) open_filter(filter) block everywhere, we introduce the guard in the function itself. This should simplify quite a bit of code. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: pass extra arguments via cgit_open_filterJohn Keeping-7/+6
This avoids poking into the filter data structure at various points in the code. We rely on the fact that the number of arguments is fixed based on the filter type (set in cgit_new_filter) and that the call sites all know which filter type they're using. Signed-off-by: John Keeping <john@keeping.me.uk>
Replace most uses of strncmp() with prefixcmp()Lukas Fleischer-1/+1
This is a preparation for replacing all prefix checks with either strip_prefix() or starts_with() when Git 1.8.6 is released. Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
Update copyright informationLukas Fleischer-2/+1
* Name "cgit Development Team" as copyright holder to avoid listing every single developer. * Update copyright ranges. Signed-off-by: Lukas Fleischer <cgit@crytocrack.de>
ui-summary: do not free refJason A. Donenfeld-1/+0
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
readme: use string_list instead of space deliminationsJason A. Donenfeld-55/+45
Now this is possible in cgitrc - readme=:README.md readme=:readme.md readme=:README.mkd readme=:readme.mkd readme=:README.rst readme=:readme.rst readme=:README.html readme=:readme.html readme=:README.htm readme=:readme.htm readme=:README.txt readme=:readme.txt readme=:README readme=:readme readme=:INSTALL.txt readme=:install.txt readme=:INSTALL readme=:install Suggested-by: John Keeping <john@keeping.me.uk> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
ui-summary: Disallow directory traversalJason A. Donenfeld-0/+16
Using the url= query string, it was possible request arbitrary files from the filesystem if the readme for a given page was set to a filesystem file. The following request would return my /etc/passwd file: http://git.zx2c4.com/?url=/somerepo/about/../../../../etc/passwd http://data.zx2c4.com/cgit-directory-traversal.png This fix uses realpath(3) to canonicalize all paths, and then compares the base components. This fix introduces a subtle timing attack, whereby a client can check whether or not strstr is called using timing measurements in order to determine if a given file exists on the filesystem. This fix also does not account for filesystem race conditions (TOCTOU) in resolving symlinks. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
readme: Accept multiple candidates and test them.Jason A. Donenfeld-30/+31
The readme variable may now contain multiple space deliminated entries, which per usual are either a filepath or a git ref filepath. If multiple are specified, cgit will now select the first one in the list that exists. This is to make it easier to specify multiple default readme types in the main cgitrc file and have them automatically get applied to each repo based on what exists. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
ui-summary: Pass filename to about-filterJason A. Donenfeld-2/+10
This gives the about-filter API the same semantics as source-filter, where the filter receives the filename so it can decide what to do next with it. While we're at it, plug a memory leak. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
ui-summary: Use default branch for readme if : prefixJason A. Donenfeld-1/+6
If the readme value begins with ":", and has no specified branch before it, use the repository's default branch. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
use struct strbuf instead of static buffersJohn Keeping-4/+8
Use "struct strbuf" from Git to remove the limit on file path length. Notes on scan-tree: This is slightly involved since I decided to pass the strbuf into add_repo() and modify if whenever a new file name is required, which should avoid any extra allocations within that function. The pattern there is to append the filename, use it and then reset the buffer to its original length (retaining a trailing '/'). Notes on ui-snapshot: Since write_archive modifies the argv array passed to it we copy the argv_array values into a new array of char* and then free the original argv_array structure and the new array without worrying about what the values now look like. Signed-off-by: John Keeping <john@keeping.me.uk>
Always #include corresponding .h in .c filesJohn Keeping-0/+1
While doing this, remove declarations from header files where the corresponding definition is declared "static" in order to avoid build errors. Also re-order existing headers in ui-*.c so that the file-specific header always comes immediately after "cgit.h", helping with future consistency. Signed-off-by: John Keeping <john@keeping.me.uk>
ui-summary.c: Move urls variable into print_urls()Lukas Fleischer-6/+14
There's no need for this variable to be global. Printing the header in print_urls() instead of print_url() allows for moving this variable into print_urls() without having to pass any status to print_url(). Note that this only works as long as we don't call print_urls() more than once. Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
Fix colspan valuesLukas Fleischer-5/+19
This fixes a couple of minor oversights in previous commits and adjusts all cells using colspan to use the correct width. Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
ui-log: Add "commit-sort" option for controlling commit orderingTobias Bieniek-1/+1
This makes it possible to use strict commit date ordering or strict topological ordering by passing the corresponding flags to "git log". Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgit.c: add 'clone-url' setting with support for macro expansionLars Hjemli-1/+1
The current 'clone-prefix' setting has some known issues: * All repos get the same 'clone-prefix' value since the setting is not adopted during repo registration (in cgitrc, or during scan-path traversal), but only when the setting is used. * The generated clone-urls for a repo is a combination of 'clone-prefix', a slash and the repo url. This doesn't work well with e.g. ssh-style urls like 'git@example.org:repo.git', since the inserted slash will make the repo relative to the filesystem root. * If 'remove-suffix' is enabled, the generated clone-urls will not work for cloning (except for http-urls to cgit itself) since they miss the '.git' suffix. The new 'clone-url' setting is designed to avoid the mentioned issues: * Each repo adopts the default 'clone-url' when the repo is defined. This allows different groups of repos to adopt different values. * The clone-urls for a repo is generated by expanding environment variables in a string template without inserting arbitrary characters, hence any kind of clone-url can be generated. * Macro expansion also eases the 'remove-suffix' pain since it's now possible to define e.g. 'clone-url=git://foo.org/$CGIT_REPO_URL.git' for a set of repos. A furter improvement would be to define e.g. $CGIT_REPO_SUFFIX to '.git' for all repos which had their url prettified, or to store the original $CGIT_REPO_URL in e.g. $CGIT_REPO_REAL_URL before suffix removal. Reviewed-by: Ferry Huberts <mailings@hupie.com> Signed-off-by: Lars Hjemli <hjemli@gmail.com>
cgit.c: always setup cgit repo environment variablesLars Hjemli-1/+1
When cgit learned to setup environment variables for certain repo settings before invoking a filter process, the setup occurred inside cgit_open_filter(). This patch moves the setup out of cgit_open_filter() and into prepare_repo_cmd() to prepare for additional uses of these variables. Reviewed-by: Ferry Huberts <mailings@hupie.com> Signed-off-by: Lars Hjemli <hjemli@gmail.com>
cgit_open_filter: also take the repo as a parameterFerry Huberts-1/+1
To prepare for handing repo configuration to the filter script that is executed. Signed-off-by: Ferry Huberts <ferry.huberts@pelagic.nl> Signed-off-by: Lars Hjemli <hjemli@gmail.com>
ui-log: Line-wrap long commit subjects when showmsg is enabledJohan Herland-1/+1
When showmsg is disabled ui-log truncates long commit subjects. This is good. However, the same is not desirable when showmsg is enabled, since you then end up with a truncated commit subject followed by the rest of the commit message below. Instead, when showmsg is enabled (and we're using all this space to display the entire commit message, anyway), line-wrap the commit subject instead of truncating it. Signed-off-by: Johan Herland <johan@herland.net> Signed-off-by: Lars Hjemli <hjemli@gmail.com>