From 1456483a0b2b835d326f1a92571166c2c8ee41f6 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 14:30:23 -1000 Subject: Gate html serving behind trust-scan-config `enable-html-serving` makes the plain page send a repository file as text/html on the site's own origin, with no nosniff and no policy, so a scanned repository could switch it on from its git config or cgitrc without `trust-scan-config` and run script against every visitor. The warning for a key read from git config also named a null repository, because `repo->path` was set only after that file had been read. --- custom/cgitrc | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) (limited to 'custom') diff --git a/custom/cgitrc b/custom/cgitrc index 5935345..06106c1 100644 --- a/custom/cgitrc +++ b/custom/cgitrc @@ -269,9 +269,9 @@ enable-http-clone=1 # Honour every setting in a repository's own cgitrc and git config found by # scan-path. Those files belong to whoever can push, so without this the -# settings that run a command, put raw markup on the page, place a link or read -# a file off the disk are ignored. The repo.* lines below never need it. Values -# are 0 or 1. Default is 0. +# settings that run a command, put raw markup on the page, serve a file as +# markup, place a link or read a file off the disk are ignored. The repo.* lines +# below never need it. Values are 0 or 1. Default is 0. trust-scan-config=0 # Filter command used to format about-page content. The bundled about-render.lua -- cgit v2.8.0