From 5104f90310a2028e50667ea12d9e75e820fbbd36 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sat, 25 Jul 2026 15:03:48 -1000 Subject: Replace the browser markdown renderer with a filter The readme is now escaped plain text unless `about-filter` points at the new `about-render.lua`, which renders markdown, man pages and plain text server-side. `enable-markdown` goes away with the renderer. --- tests/t0200-security.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'tests') diff --git a/tests/t0200-security.sh b/tests/t0200-security.sh index 83cdbfd..425708e 100644 --- a/tests/t0200-security.sh +++ b/tests/t0200-security.sh @@ -73,7 +73,7 @@ test_expect_success 'a small blob is still served' ' ' # --- Readme rendering escapes untrusted repository content ------------------ -test_expect_success 'markdown readme is escaped and marked for the client' ' +test_expect_success 'markdown readme without a filter is escaped as plain text' ' { echo "virtual-root=/" && echo "cache-size=0" && @@ -82,7 +82,7 @@ test_expect_success 'markdown readme is escaped and marked for the client' ' echo "repo.readme=master:README.md" } >secmdrc && CGIT_CONFIG="$PWD/secmdrc" QUERY_STRING="url=md/about/" cgit >tmp && - grep "data-markdown" tmp && + grep "pre class=.plaintext." tmp && grep "<script>" tmp && ! grep "" tmp ' -- cgit v2.8.0