From e3d85ae7a607cf98455b38657baed34fecb8bb38 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Wed, 15 Jul 2026 08:35:10 -1000 Subject: Gate the cache listing behind `enable-cache-list` The `ls_cache` page printed the cache directory path and the urls other visitors had requested, with no gate at all. --- source/cgit.c | 2 ++ source/cgit.h | 1 + source/cmd.c | 6 ++++++ 3 files changed, 9 insertions(+) (limited to 'source') diff --git a/source/cgit.c b/source/cgit.c index ca318e8..91dd9a7 100644 --- a/source/cgit.c +++ b/source/cgit.c @@ -201,6 +201,8 @@ static void config_cb(const char *name, const char *value) ctx.cfg.enable_tree_linenumbers = atoi(value); else if (!strcmp(name, "enable-git-config")) ctx.cfg.enable_git_config = atoi(value); + else if (!strcmp(name, "enable-cache-list")) + ctx.cfg.enable_cache_list = atoi(value); else if (!strcmp(name, "max-stats")) ctx.cfg.max_stats = cgit_find_stats_period(value, NULL); else if (!strcmp(name, "cache-size")) diff --git a/source/cgit.h b/source/cgit.h index 7d7ece7..634d2f5 100644 --- a/source/cgit.h +++ b/source/cgit.h @@ -243,6 +243,7 @@ struct cgit_config { int enable_html_serving; int enable_tree_linenumbers; int enable_git_config; + int enable_cache_list; int local_time; int max_atom_items; int max_repo_count; diff --git a/source/cmd.c b/source/cmd.c index 0eb75b1..7eb642c 100644 --- a/source/cmd.c +++ b/source/cmd.c @@ -107,6 +107,12 @@ static void log_fn(void) static void ls_cache_fn(void) { + /* The listing exposes the cache path and the URLs other visitors + * requested, so it stays off unless an admin opts in. */ + if (!ctx.cfg.enable_cache_list) { + cgit_print_error_page(404, "Not found", "Not found"); + return; + } ctx.page.mimetype = "text/plain"; ctx.page.filename = "ls-cache.txt"; cgit_print_http_headers(); -- cgit v2.8.0