From e3d85ae7a607cf98455b38657baed34fecb8bb38 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Wed, 15 Jul 2026 08:35:10 -1000 Subject: Gate the cache listing behind `enable-cache-list` The `ls_cache` page printed the cache directory path and the urls other visitors had requested, with no gate at all. --- source/cmd.c | 6 ++++++ 1 file changed, 6 insertions(+) (limited to 'source/cmd.c') diff --git a/source/cmd.c b/source/cmd.c index 0eb75b1..7eb642c 100644 --- a/source/cmd.c +++ b/source/cmd.c @@ -107,6 +107,12 @@ static void log_fn(void) static void ls_cache_fn(void) { + /* The listing exposes the cache path and the URLs other visitors + * requested, so it stays off unless an admin opts in. */ + if (!ctx.cfg.enable_cache_list) { + cgit_print_error_page(404, "Not found", "Not found"); + return; + } ctx.page.mimetype = "text/plain"; ctx.page.filename = "ls-cache.txt"; cgit_print_http_headers(); -- cgit v2.8.0