From 1456483a0b2b835d326f1a92571166c2c8ee41f6 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 14:30:23 -1000 Subject: Gate html serving behind trust-scan-config `enable-html-serving` makes the plain page send a repository file as text/html on the site's own origin, with no nosniff and no policy, so a scanned repository could switch it on from its git config or cgitrc without `trust-scan-config` and run script against every visitor. The warning for a key read from git config also named a null repository, because `repo->path` was set only after that file had been read. --- MANUAL.txt | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) (limited to 'MANUAL.txt') diff --git a/MANUAL.txt b/MANUAL.txt index 053bb5f..d1150ef 100644 --- a/MANUAL.txt +++ b/MANUAL.txt @@ -209,7 +209,9 @@ enable-html-serving:: Flag which, when set to "1", lets the /plain handler serve mimetype headers that result in the file being treated as HTML by the browser. When set to "0", such file types are returned instead as text/plain or - application/octet-stream. Default value: "0". See also: + application/octet-stream. In a repository found by "scan-path" the + setting waits on "trust-scan-config", since a page served this way runs + with the site's own origin. Default value: "0". See also: "repo.enable-html-serving". enable-http-clone:: @@ -536,12 +538,13 @@ trust-scan-config:: Flag which, when set to "1", honours every setting in a repository's own cgitrc file and git config found by "scan-path". Those files belong to whoever can push to the repository, so without it the settings that run - a command, put raw markup on the page, place a link or read a file off - the disk are ignored with a warning. Those are the filters, - head-content, module-link, logo, logo-link, clone-url and a readme that - names a file rather than a git object. Settings in the main cgitrc, the - "repo.