From 969e9554a31385b2d2c09695dab984d585dc2693 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Mon, 21 Sep 2026 06:42:39 -1000 Subject: Harden the request path, scan and error recovery --- custom/cgitrc | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) (limited to 'custom/cgitrc') diff --git a/custom/cgitrc b/custom/cgitrc index e6532cf..18c973d 100644 --- a/custom/cgitrc +++ b/custom/cgitrc @@ -265,12 +265,12 @@ enable-http-clone=1 # repository ships under custom/extensions/. The ones written as # /path/to/your-command mark where your own command goes. -# Honour the filter settings in a repository's own cgitrc and git config found -# by scan-path. Those files belong to whoever can push, and a filter is a -# command cgit runs, so leave this off unless the scanned repositories are -# trusted. The repo.* lines below never need it. Values are 0 or 1. Default is -# 0. -trust-scan-filters=0 +# Honour every setting in a repository's own cgitrc and git config found by +# scan-path. Those files belong to whoever can push, so without this the +# settings that run a command, put raw markup on the page, place a link or read +# a file off the disk are ignored. The repo.* lines below never need it. Values +# are 0 or 1. Default is 0. +trust-scan-config=0 # Filter command used to format about-page content. The bundled about-render.lua # renders markdown, man pages and plain text. Value is a command optionally -- cgit v2.8.0