From 5104f90310a2028e50667ea12d9e75e820fbbd36 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sat, 25 Jul 2026 15:03:48 -1000 Subject: Replace the browser markdown renderer with a filter The readme is now escaped plain text unless `about-filter` points at the new `about-render.lua`, which renders markdown, man pages and plain text server-side. `enable-markdown` goes away with the renderer. --- source/ui-summary.c | 34 ++++------------------------------ 1 file changed, 4 insertions(+), 30 deletions(-) (limited to 'source/ui-summary.c') diff --git a/source/ui-summary.c b/source/ui-summary.c index 8dd191b..80d1e5b 100644 --- a/source/ui-summary.c +++ b/source/ui-summary.c @@ -105,17 +105,6 @@ static char* append_readme_path(const char *filename, const char *ref, const cha return full_path; } -static int readme_is_markdown(const char *filename) -{ - const char *ext = strrchr(filename, '.'); - - if (!ext || !ext[1]) - return 0; - ext++; - return !strcasecmp(ext, "md") || !strcasecmp(ext, "markdown") || - !strcasecmp(ext, "mkd") || !strcasecmp(ext, "mdown"); -} - void cgit_print_repo_readme(const char *path) { char *filename, *ref, *mimetype; @@ -146,29 +135,14 @@ void cgit_print_repo_readme(const char *path) } html("
"); - if (!ctx.repo->about_filter && ctx.cfg.enable_markdown && - readme_is_markdown(filename)) { - /* No about-filter is set, so hand the markdown source to the - * built-in client-side renderer in cgit.js. The source is - * escaped here and rendered in the browser, and it degrades to - * readable plain text when scripting is off. - */ - html("
"); - if (ref) { - cgit_print_file(filename, ref, 1, 1); - } else { - struct strbuf sb = STRBUF_INIT; - if (strbuf_read_file(&sb, filename, 0) >= 0) - html_txt(sb.buf); - strbuf_release(&sb); - } - html("
"); - } else if (!ctx.repo->about_filter) { + if (!ctx.repo->about_filter) { /* No about-filter is configured, so there is nothing to turn * the readme source into safe HTML. Escape it rather than serve * repo content raw, which would let an untrusted repository * inject script into the about page. The pre keeps the line - * structure of the text, which bare escaped output loses. + * structure of the text, which bare escaped output loses. Point + * about-filter at the bundled about-render.lua to render a + * markdown or man readme instead, see cgitrc.5.txt. */ html("
");
 		if (ref) {
-- 
cgit v2.8.0