/* ui-summary.c: functions for generating repo summary page * * Copyright (C) 2006-2014 cgit Development Team * * Licensed under GNU General Public License v2 * (see LICENSE.txt for full license text) */ #include "cgit.h" #include "ui-summary.h" #include "html.h" #include "ui-blob.h" #include "ui-log.h" #include "ui-plain.h" #include "ui-refs.h" #include "ui-shared.h" static int urls; static void print_url(const char *url) { int columns = 3; if (ctx.repo->enable_log_filecount) columns++; if (ctx.repo->enable_log_linecount) columns++; if (urls++ == 0) { htmlf(" ", columns); htmlf("Clone\n", columns); } htmlf(""); html_txt(url); html("\n"); } void cgit_print_summary(void) { int columns = 3; if (ctx.repo->enable_log_filecount) columns++; if (ctx.repo->enable_log_linecount) columns++; cgit_print_layout_start(); html(""); cgit_print_branches(ctx.cfg.summary_branches); htmlf("", columns); cgit_print_tags(ctx.cfg.summary_tags); if (ctx.cfg.summary_log > 0) { htmlf("", columns); cgit_print_log(ctx.qry.head, 0, ctx.cfg.summary_log, NULL, NULL, NULL, 0, 0, 0); } urls = 0; cgit_add_clone_urls(print_url); html("
 
 
"); cgit_print_layout_end(); } /* The caller must free the return value. */ static char* append_readme_path(const char *filename, const char *ref, const char *path) { char *file, *base_dir, *full_path, *resolved_base = NULL, *resolved_full = NULL; /* If a subpath is specified for the about page, make it relative * to the directory containing the configured readme. */ file = xstrdup(filename); base_dir = dirname(file); if (!strcmp(base_dir, ".") || !strcmp(base_dir, "..")) { if (!ref) { free(file); return NULL; } full_path = xstrdup(path); } else full_path = fmtalloc("%s/%s", base_dir, path); if (!ref) { resolved_base = realpath(base_dir, NULL); resolved_full = realpath(full_path, NULL); /* Require a path-separator boundary after the base so a sibling * directory that merely shares the base as a name prefix (say * repo.git-backup next to repo.git) cannot pass the check. */ if (!resolved_base || !resolved_full || !starts_with(resolved_full, resolved_base) || (resolved_full[strlen(resolved_base)] != '\0' && resolved_full[strlen(resolved_base)] != '/')) { free(full_path); full_path = NULL; } } free(file); free(resolved_base); free(resolved_full); return full_path; } static int readme_is_markdown(const char *filename) { const char *ext = strrchr(filename, '.'); if (!ext || !ext[1]) return 0; ext++; return !strcasecmp(ext, "md") || !strcasecmp(ext, "markdown") || !strcasecmp(ext, "mkd") || !strcasecmp(ext, "mdown"); } void cgit_print_repo_readme(const char *path) { char *filename, *ref, *mimetype; int free_filename = 0; mimetype = get_mimetype_for_filename(path); if (mimetype && (!strncmp(mimetype, "image/", 6) || !strncmp(mimetype, "video/", 6))) { ctx.page.mimetype = mimetype; ctx.page.charset = NULL; cgit_print_plain(); free(mimetype); return; } free(mimetype); cgit_print_layout_start(); if (ctx.repo->readme.nr == 0) goto done; filename = ctx.repo->readme.items[0].string; ref = ctx.repo->readme.items[0].util; if (path) { free_filename = 1; filename = append_readme_path(filename, ref, path); if (!filename) goto done; } html("
"); if (!ctx.repo->about_filter && ctx.cfg.enable_markdown && readme_is_markdown(filename)) { /* No about-filter is set, so hand the markdown source to the * built-in client-side renderer in cgit.js. The source is * escaped here and rendered in the browser, and it degrades to * readable plain text when scripting is off. */ html("
"); if (ref) { cgit_print_file(filename, ref, 1, 1); } else { struct strbuf sb = STRBUF_INIT; if (strbuf_read_file(&sb, filename, 0) >= 0) html_txt(sb.buf); strbuf_release(&sb); } html("
"); } else if (!ctx.repo->about_filter) { /* No about-filter is configured, so there is nothing to turn * the readme source into safe HTML. Escape it rather than serve * repo content raw, which would let an untrusted repository * inject script into the about page. The pre keeps the line * structure of the text, which bare escaped output loses. */ html("
");
		if (ref) {
			cgit_print_file(filename, ref, 1, 1);
		} else {
			struct strbuf sb = STRBUF_INIT;
			if (strbuf_read_file(&sb, filename, 0) >= 0)
				html_txt(sb.buf);
			strbuf_release(&sb);
		}
		html("
"); } else { /* An about-filter is configured and is responsible for turning * the source into safe HTML, so pass it through the filter raw. */ cgit_open_filter(ctx.repo->about_filter, filename); if (ref) cgit_print_file(filename, ref, 1, 0); else html_include(filename); cgit_close_filter(ctx.repo->about_filter); } html("
"); if (free_filename) free(filename); done: cgit_print_layout_end(); }