From b034fde5cb6463d354670e26eeaaae765810d6bd Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 16:58:07 -1000 Subject: Withhold the alternates file on the dumb transport It lists object directories by their path on the server, which a client fetching over http can neither use nor needs to learn. The http-alternates file written for such clients still goes out. --- source/ui-clone.c | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'source') diff --git a/source/ui-clone.c b/source/ui-clone.c index 833c170..832a056 100644 --- a/source/ui-clone.c +++ b/source/ui-clone.c @@ -166,6 +166,14 @@ void cgit_clone_objects(void) return; } + // The alternates file names directories on the server's disk, which a + // client fetching over http cannot reach, so only the http form that + // is written for such clients goes out. + if (!strcmp(ctx.qry.path, "info/alternates")) { + cgit_print_error_page(404, "Not Found", "Not found"); + return; + } + if (!path_is_safe(ctx.qry.path)) goto err; -- cgit v2.8.0