From a102fa8748a836d031e2e0e263b58af8c855332f Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 17:12:28 -1000 Subject: Keep the query string across the about redirects The hop to the trailing-slash form of the about page, and the hop back to the summary of a repository without a readme, were built from the path alone, so a request for the about page of another branch landed on the default one. The query goes into the Location line as the client sent it, with any byte a header cannot carry percent-encoded. --- source/cmd.c | 13 +++++++++---- source/html.c | 22 ++++++++++++++++++++++ source/html.h | 1 + source/ui-shared.c | 21 +++++++++++++++------ source/ui-shared.h | 10 ++++++++-- 5 files changed, 55 insertions(+), 12 deletions(-) (limited to 'source') diff --git a/source/cmd.c b/source/cmd.c index 38fe596..49c1eb4 100644 --- a/source/cmd.c +++ b/source/cmd.c @@ -34,7 +34,7 @@ static void head_fn(void) static void about_fn(void) { - char *currenturl, *redirect; + char *currenturl, *query, *redirect; size_t path_info_len; if (!ctx.repo) { @@ -43,23 +43,28 @@ static void about_fn(void) } // The about page resolves relative links against its own URL, so it - // only works with a trailing slash. + // only works with a trailing slash. The branch and the rest of the + // query travel along with either redirect. path_info_len = ctx.env.path_info ? strlen(ctx.env.path_info) : 0; if (!ctx.qry.path && (!ctx.qry.url || !*ctx.qry.url || ctx.qry.url[strlen(ctx.qry.url) - 1] != '/') && (!path_info_len || ctx.env.path_info[path_info_len - 1] != '/')) { currenturl = cgit_currenturl(); + query = cgit_currentquery(); redirect = cgit_fmtalloc("%s/", currenturl); - cgit_redirect(redirect, true); + cgit_redirect(redirect, query, true); free(currenturl); + free(query); free(redirect); } else if (ctx.repo->readme.nr) { cgit_print_repo_readme(ctx.qry.path); } else { currenturl = cgit_currenturl(); + query = cgit_currentquery(); redirect = cgit_fmtalloc("%s../", currenturl); - cgit_redirect(redirect, false); + cgit_redirect(redirect, query, false); free(currenturl); + free(query); free(redirect); } } diff --git a/source/html.c b/source/html.c index a1d244b..96b1b52 100644 --- a/source/html.c +++ b/source/html.c @@ -339,6 +339,28 @@ void html_header_arg_in_quotes(const char *txt) html(txt); } +/* + * A query string goes into a header the way it arrived, already encoded by + * the client, except that a byte a header line cannot carry is percent-encoded + * so the line stays one line. + */ +void html_header_query(const char *txt) +{ + const char *p = txt; + + while (p && *p) { + unsigned char c = *p; + if (c <= ' ' || c >= 0x7f) { + html_raw(txt, p - txt); + html(url_escape_table[c]); + txt = p + 1; + } + p++; + } + if (p != txt) + html(txt); +} + void html_hidden(const char *name, const char *value) { html("