From d466c1122b89625ef3ccec55d184f0aed8a61541 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sat, 8 Aug 2026 12:50:10 -1000 Subject: Bound the search and cache key a request can ask --- source/cgit.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) (limited to 'source/cgit.c') diff --git a/source/cgit.c b/source/cgit.c index 2ecfb4f..7cce3d3 100644 --- a/source/cgit.c +++ b/source/cgit.c @@ -360,7 +360,14 @@ static void querystring_cb(const char *name, const char *value) } else if (!strcmp(name, "qt")) { ctx.qry.grep = xstrdup(value); } else if (!strcmp(name, "q")) { - ctx.qry.search = xstrdup(value); + /* A query is matched against every repository, ref or commit + * the page lists, so bound what one request can ask to be + * compared. Nothing legible reaches this length, and the value + * also lands in the cache key. */ + if (strlen(value) > CGIT_MAX_SEARCH_LEN) + ctx.qry.search = xstrndup(value, CGIT_MAX_SEARCH_LEN); + else + ctx.qry.search = xstrdup(value); } else if (!strcmp(name, "h")) { ctx.qry.head = xstrdup(value); ctx.qry.has_symref = 1; -- cgit v2.8.0