From 538b6b6c674c12bf445f0cc20e7c4c5c38bac937 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sat, 25 Jul 2026 09:11:43 -1000 Subject: Percent-encode file paths in side-by-side diffs --- source/ui-ssdiff.c | 18 ++++++++++++++++-- tests/t0200-security.sh | 26 ++++++++++++++++++++++++++ 2 files changed, 42 insertions(+), 2 deletions(-) diff --git a/source/ui-ssdiff.c b/source/ui-ssdiff.c index af8bc9e..ed5a2f4 100644 --- a/source/ui-ssdiff.c +++ b/source/ui-ssdiff.c @@ -237,13 +237,20 @@ static void print_ssdiff_line(char *class, struct diff_filespec *old_file = cgit_get_current_old_file(); char *lineno_str = fmt("n%d", old_line_no); char *id_str = fmt("id=%s#%s", is_null_oid(&old_file->oid)?"HEAD":oid_to_hex(old_rev_oid), lineno_str); - char *fileurl = cgit_fileurl(ctx.repo->url, "tree", old_file->path, id_str); + struct strbuf path = STRBUF_INIT; + char *fileurl; + // The file path is repository content, so percent-encode it + // before it lands raw in the href below. + if (old_file->path) + strbuf_add_percentencode(&path, old_file->path, 0); + fileurl = cgit_fileurl(ctx.repo->url, "tree", path.buf, id_str); html("%s", lineno_str + 1); html(""); htmlf("", class); free(fileurl); + strbuf_release(&path); } else if (old_line) htmlf("", class); else @@ -260,13 +267,20 @@ static void print_ssdiff_line(char *class, struct diff_filespec *new_file = cgit_get_current_new_file(); char *lineno_str = fmt("n%d", new_line_no); char *id_str = fmt("id=%s#%s", is_null_oid(&new_file->oid)?"HEAD":oid_to_hex(new_rev_oid), lineno_str); - char *fileurl = cgit_fileurl(ctx.repo->url, "tree", new_file->path, id_str); + struct strbuf path = STRBUF_INIT; + char *fileurl; + // The file path is repository content, so percent-encode it + // before it lands raw in the href below. + if (new_file->path) + strbuf_add_percentencode(&path, new_file->path, 0); + fileurl = cgit_fileurl(ctx.repo->url, "tree", path.buf, id_str); html("%s", lineno_str + 1); html(""); htmlf("", class); free(fileurl); + strbuf_release(&path); } else if (new_line) htmlf("", class); else diff --git a/tests/t0200-security.sh b/tests/t0200-security.sh index 44703c9..4eee9ae 100644 --- a/tests/t0200-security.sh +++ b/tests/t0200-security.sh @@ -149,4 +149,30 @@ test_expect_success 'enable-help=0 hides the tab and the page' ' grep "Status: 404" tmp ' +# --- Side-by-side diff percent-encodes a file path into its links ----------- +# A file name is repository content and may contain a quote, which would +# otherwise break out of the href attribute of the line-number links. +test_expect_success 'ssdiff percent-encodes a quoted file path' ' + mkrepo repos/xss 1 && + name=$(printf "x\047y.txt") && + ( + cd repos/xss && + printf "a\nb\n" >"$name" && + git add -A && + git commit -m add && + printf "a\nc\n" >"$name" && + git commit -am change + ) && + { + echo "virtual-root=/" && + echo "cache-size=0" && + echo "repo.url=xss" && + echo "repo.path=$PWD/repos/xss/.git" + } >xssrc && + sha=$(git -C repos/xss rev-parse HEAD) && + CGIT_CONFIG="$PWD/xssrc" QUERY_STRING="url=xss/diff/&id=$sha&ss=1" cgit >tmp && + grep "tree/x%27y.txt" tmp && + ! grep "href=.[^>]*x.y.txt.[^>]*>" tmp +' + test_done -- cgit v2.8.0