From 3a00e194d2dcda520e1aaf00180921a15a7cf483 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 20:54:22 -1000 Subject: Keep the version numbers off the pages The generator meta, the footer and the patch signature named the exact cgit and git versions on every response, which only helps someone matching a site against an advisory. The shipped server configs already hide the server's own version for the same reason, and `cgit --version` still answers on the host. --- tests/t0109-patch.sh | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) (limited to 'tests') diff --git a/tests/t0109-patch.sh b/tests/t0109-patch.sh index f4168f4..3cb9d08 100755 --- a/tests/t0109-patch.sh +++ b/tests/t0109-patch.sh @@ -10,12 +10,9 @@ test_description='Check content on patch page' # The signature sits on the second-to-last line, above the trailing blank. check_cgit_signature() { - tail -2 tmp | head -1 | grep "^cgit" + tail -2 tmp | head -1 | grep "^cgit$" } -# The version the built binary signs its patches with. -CGIT_VERSION=$(sed -n "s/CGIT_VERSION = //p" "$TEST_OUTPUT_DIRECTORY/../build/VERSION") - test_expect_success 'generate foo/patch' ' cgit_query "url=foo/patch" >tmp ' @@ -38,7 +35,7 @@ test_expect_success 'find `cgit` signature' ' test_expect_success 'compare with output of git-format-patch(1)' ' git --git-dir="$PWD/repos/foo/.git" format-patch --subject-prefix="" \ - --signature="cgit $CGIT_VERSION" --stdout HEAD^ >tmp2 && + --signature="cgit" --stdout HEAD^ >tmp2 && strip_headers tmp_ && test_cmp tmp_ tmp2 ' @@ -67,7 +64,7 @@ test_expect_success 'find `cgit` signature on the range' ' test_expect_success 'compare the range with git-format-patch(1)' ' git --git-dir="$PWD/repos/foo/.git" format-patch --subject-prefix="" \ - -N --signature="cgit $CGIT_VERSION" --stdout HEAD~3..HEAD >tmp2 && + -N --signature="cgit" --stdout HEAD~3..HEAD >tmp2 && strip_headers tmp_ && test_cmp tmp_ tmp2 ' -- cgit v2.8.0