From b75e3deb6a8d0860167e66a8f1e128dfec452c69 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Wed, 15 Jul 2026 14:05:37 -1000 Subject: Harden the blob view error paths A blob requested by ref with an unknown path fell through to the commit object and was served with a 200 instead of a 404, two error pages passed a null pointer to a %s format when the request carried no object id, and the error pages left the layout open. --- source/ui-blob.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) (limited to 'source/ui-blob.c') diff --git a/source/ui-blob.c b/source/ui-blob.c index 7720a28..ad84f3d 100644 --- a/source/ui-blob.c +++ b/source/ui-blob.c @@ -156,19 +156,24 @@ void cgit_print_blob(const char *hex, char *path, const char *head, int file_onl commit = lookup_commit_reference(the_repository, &oid); read_tree(the_repository, repo_get_commit_tree(the_repository, commit), &paths, walk_tree, &walk_tree_ctx); + if (!walk_tree_ctx.found_path) { + cgit_print_error_page(404, "Not found", + "Path not found: %s", path); + return; + } type = odb_read_object_info(the_repository->objects, &oid, &size); } if (type == OBJ_BAD) { cgit_print_error_page(404, "Not found", - "Bad object name: %s", hex); + "Bad object name: %s", hex ? hex : path); return; } buf = odb_read_object(the_repository->objects, &oid, &type, &size); if (!buf) { cgit_print_error_page(500, "Internal server error", - "Error reading object %s", hex); + "Error reading object %s", hex ? hex : path); return; } -- cgit v2.8.0