/* * The repository summary page and the about page. The summary stacks the * branch list, the tag list and the head of the log into one table and ends * with the clone urls, reusing the listings ui-refs.c and ui-log.c draw * elsewhere. The about page renders the readme that config parsing picked for * the repository, either through the configured about filter or escaped as * plain text, and it can serve a file sitting beside that readme so links * inside the readme resolve. */ #include "cgit.h" #include "filter.h" #include "html.h" #include "shared.h" #include "ui-blob.h" #include "ui-log.h" #include "ui-plain.h" #include "ui-refs.h" #include "ui-shared.h" #include "ui-summary.h" // Age, commit message and author, the three columns a log row always has. // ui-log.c adds one more for each of the two optional counts, and the rows // this page stretches across the table have to match that width. #define LOG_BASE_COLUMNS 3 static int clone_urls_printed; static int log_columns(void) { int columns = LOG_BASE_COLUMNS; if (ctx.repo->enable_log_filecount) columns++; if (ctx.repo->enable_log_linecount) columns++; return columns; } static void print_clone_url(const char *url) { int columns = log_columns(); // cgit_add_clone_urls may call back no times at all, so the heading // waits for a first url rather than being printed ahead of the walk. if (clone_urls_printed++ == 0) { htmlf(" ", columns); htmlf("Clone\n", columns); } htmlf(""); html_txt(url); html("\n"); } /* * Without the separator boundary a sibling directory that merely shares the * base as a name prefix, such as repo.git-backup beside repo.git, would pass. */ static int path_within(const char *base, const char *path) { size_t len = strlen(base); return starts_with(path, base) && (path[len] == '\0' || path[len] == '/'); } /* * Returns a path the caller must free, or NULL when the request cannot be * served. A null ref means the readme is a file on the server's disk rather * than a path inside a ref, and such a readme is confined to its own * directory, so one named without a directory has nothing to confine it to * and is refused. */ static char *resolve_about_path(const char *filename, const char *ref, const char *path) { char *copy, *base_dir, *full_path; char *resolved_base = NULL, *resolved_full = NULL; // dirname is allowed to write into its argument and to return a // pointer into it, so base_dir borrows from a copy we keep alive. copy = xstrdup(filename); base_dir = dirname(copy); if (!strcmp(base_dir, ".") || !strcmp(base_dir, "..")) { if (!ref) { free(copy); return NULL; } full_path = xstrdup(path); } else full_path = cgit_fmtalloc("%s/%s", base_dir, path); if (!ref) { resolved_base = realpath(base_dir, NULL); resolved_full = realpath(full_path, NULL); if (!resolved_base || !resolved_full || !path_within(resolved_base, resolved_full)) { free(full_path); full_path = NULL; } } free(copy); free(resolved_base); free(resolved_full); return full_path; } void cgit_print_summary(void) { int columns = log_columns(); cgit_print_layout_start(); html("\n"); cgit_print_branches(ctx.cfg.summary_branches); htmlf("\n", columns); cgit_print_tags(ctx.cfg.summary_tags); if (ctx.cfg.summary_log > 0) { htmlf("\n", columns); cgit_print_log(ctx.qry.head, 0, ctx.cfg.summary_log, NULL, NULL, NULL, 0, 0, 0); } clone_urls_printed = 0; cgit_add_clone_urls(print_clone_url); html("
 
 
"); cgit_print_layout_end(); } void cgit_print_repo_readme(const char *path) { char *filename, *ref, *mimetype; int free_filename = 0; mimetype = cgit_get_mimetype_for_filename(path); if (mimetype && (starts_with(mimetype, "image/") || starts_with(mimetype, "video/"))) { ctx.page.mimetype = mimetype; ctx.page.charset = NULL; cgit_print_plain(); free(mimetype); return; } free(mimetype); cgit_print_layout_start(); if (ctx.repo->readme.nr == 0) goto done; filename = ctx.repo->readme.items[0].string; ref = ctx.repo->readme.items[0].util; if (path) { free_filename = 1; filename = resolve_about_path(filename, ref, path); if (!filename) goto done; } html("
"); if (!ctx.repo->about_filter) { // With no about-filter configured there is nothing to turn the // readme source into safe HTML, so it is escaped rather than // served raw, which would let an untrusted repository put // script on this page. html("
");
		if (ref) {
			cgit_print_file(filename, ref, 1, 1);
		} else {
			struct strbuf sb = STRBUF_INIT;
			if (strbuf_read_file(&sb, filename, 0) >= 0)
				html_txt(sb.buf);
			strbuf_release(&sb);
		}
		html("
"); } else { // The filter is what makes the source safe here, so it is fed // through unescaped. cgit_open_filter(ctx.repo->about_filter, filename); if (ref) cgit_print_file(filename, ref, 1, 0); else html_include(filename); cgit_close_filter(ctx.repo->about_filter); } html("
"); if (free_filename) free(filename); done: cgit_print_layout_end(); }