{"thread":{"id":"32064","subject":"[PATCH] gitweb: git_summary - show $project in title","startedAt":"2012-11-11T05:20:58Z","lastAt":"2012-11-29T21:07:52Z","messageCount":4,"participants":["Henrich Schuchardt","Jeff King","Junio C Hamano","Xypron"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"202799","messageId":"1352611258-11450-1-git-send-email-xypron.glpk@gmx.de","threadId":"32064","inReplyTo":null,"subject":"[PATCH] gitweb: git_summary - show $project in title","fromName":"Henrich Schuchardt","fromEmail":"xypron.glpk@gmx.de","sentAt":"2012-11-11T05:20:58Z","receivedAt":"2012-11-11T05:20:58Z","isPatch":true,"sender":{"key":"xypron.glpk@gmx.de","avatar":"https://gravatar.com/avatar/ecfc545fcbe89519e2ffdf4eccf04756d830b2a7a26780b6f5b3d5d569d1d362?d=mp&s=160"},"body":"Gitweb pages are structured by divs of class title with grey background.\nThe shortlog, and the log page show the project name as the first title.\nPage summary only shows an empty grey box above the project details.\nThis provides an inconstent user experience.\n\nThis patch adds the missing project title.\n\nSigned-off-by: Henrich Schuchardt <xypron.glpk@gmx.de>\n---\n gitweb/gitweb.perl |    2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\nindex 10ed9e5..3e1c452 100755\n--- a/gitweb/gitweb.perl\n+++ b/gitweb/gitweb.perl\n@@ -6451,7 +6451,7 @@ sub git_summary {\n \tgit_header_html();\n \tgit_print_page_nav('summary','', $head);\n \n-\tprint \"<div class=\\\"title\\\">&nbsp;</div>\\n\";\n+\tprint \"<div class=\\\"title\\\">$project</div>\\n\";\n \tprint \"<table class=\\\"projects_list\\\">\\n\" .\n \t      \"<tr id=\\\"metadata_desc\\\"><td>description</td><td>\" . esc_html($descr) . \"</td></tr>\\n\";\n         unless ($omit_owner) {\n-- \n1.7.10.4\n"},{"id":"203019","messageId":"20121112232513.GF10531@sigill.intra.peff.net","threadId":"32064","inReplyTo":"1352611258-11450-1-git-send-email-xypron.glpk@gmx.de","subject":"Re: [PATCH] gitweb: git_summary - show $project in title","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2012-11-12T23:25:14Z","receivedAt":"2012-11-12T23:25:14Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Sun, Nov 11, 2012 at 06:20:58AM +0100, Henrich Schuchardt wrote:\n\n> Gitweb pages are structured by divs of class title with grey background.\n> The shortlog, and the log page show the project name as the first title.\n> Page summary only shows an empty grey box above the project details.\n> This provides an inconstent user experience.\n> \n> This patch adds the missing project title.\n> \n> Signed-off-by: Henrich Schuchardt <xypron.glpk@gmx.de>\n> ---\n>  gitweb/gitweb.perl |    2 +-\n>  1 file changed, 1 insertion(+), 1 deletion(-)\n> \n> diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\n> index 10ed9e5..3e1c452 100755\n> --- a/gitweb/gitweb.perl\n> +++ b/gitweb/gitweb.perl\n> @@ -6451,7 +6451,7 @@ sub git_summary {\n>  \tgit_header_html();\n>  \tgit_print_page_nav('summary','', $head);\n>  \n> -\tprint \"<div class=\\\"title\\\">&nbsp;</div>\\n\";\n> +\tprint \"<div class=\\\"title\\\">$project</div>\\n\";\n\nI do not have any opinion on whether the intent of the change is good or\nnot, but shouldn't $project be run through esc_html() here?\n\n-Peff\n"},{"id":"203028","messageId":"7v625agwiv.fsf@alter.siamese.dyndns.org","threadId":"32064","inReplyTo":"20121112232513.GF10531@sigill.intra.peff.net","subject":"Re: [PATCH] gitweb: git_summary - show $project in title","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2012-11-13T00:46:16Z","receivedAt":"2012-11-13T00:46:16Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> On Sun, Nov 11, 2012 at 06:20:58AM +0100, Henrich Schuchardt wrote:\n>\n>> Gitweb pages are structured by divs of class title with grey background.\n>> The shortlog, and the log page show the project name as the first title.\n>> Page summary only shows an empty grey box above the project details.\n>> This provides an inconstent user experience.\n>> \n>> This patch adds the missing project title.\n>> \n>> Signed-off-by: Henrich Schuchardt <xypron.glpk@gmx.de>\n>> ---\n>>  gitweb/gitweb.perl |    2 +-\n>>  1 file changed, 1 insertion(+), 1 deletion(-)\n>> \n>> diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\n>> index 10ed9e5..3e1c452 100755\n>> --- a/gitweb/gitweb.perl\n>> +++ b/gitweb/gitweb.perl\n>> @@ -6451,7 +6451,7 @@ sub git_summary {\n>>  \tgit_header_html();\n>>  \tgit_print_page_nav('summary','', $head);\n>>  \n>> -\tprint \"<div class=\\\"title\\\">&nbsp;</div>\\n\";\n>> +\tprint \"<div class=\\\"title\\\">$project</div>\\n\";\n>\n> I do not have any opinion on whether the intent of the change is good or\n> not, but shouldn't $project be run through esc_html() here?\n\nI think the answer is yes.  And if $project needs to be escaped, the\ngit_feed function you fixed today has another codepath that needs to\nbe fixed.  When git_get_project_description($project) returns undef,\nthe description is taken from $project without any escaping.\n"},{"id":"204295","messageId":"50B7CEA8.8050308@gmx.de","threadId":"32064","inReplyTo":"7v625agwiv.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH] gitweb: git_summary - show $project in title","fromName":"Xypron","fromEmail":"xypron.glpk@gmx.de","sentAt":"2012-11-29T21:07:52Z","receivedAt":"2012-11-29T21:07:52Z","isPatch":true,"sender":{"key":"xypron.glpk@gmx.de","avatar":"https://gravatar.com/avatar/ecfc545fcbe89519e2ffdf4eccf04756d830b2a7a26780b6f5b3d5d569d1d362?d=mp&s=160"},"body":"Thank you for your comments. In the appended version of the patch\nthe project title is escaped:\n\nSubject: [PATCH] gitweb: git_summary - show $project in title\n\nGitweb pages are structured by divs of class title with grey background.\nThe shortlog, and the log page show the project name as the first title.\nPage summary only shows an empty grey box above the project details.\nThis provides an inconsistent user experience.\n\nSigned-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>\n---\n gitweb/gitweb.perl |    2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\nindex e8812fa..be94b0b 100755\n--- a/gitweb/gitweb.perl\n+++ b/gitweb/gitweb.perl\n@@ -6450,7 +6450,7 @@ sub git_summary {\n \tgit_header_html();\n \tgit_print_page_nav('summary','', $head);\n \n-\tprint \"<div class=\\\"title\\\">&nbsp;</div>\\n\";\n+\tprint \"<div class=\\\"title\\\">\" . esc_html($project) . \"</div>\\n\";\n \tprint \"<table class=\\\"projects_list\\\">\\n\" .\n \t\t\"<tr id=\\\"metadata_desc\\\"><td>description</td><td>\" . esc_html($descr) . \"</td></tr>\\n\";\n         unless ($omit_owner) {\n-- \n1.7.10.4\n\n\nOn 13.11.2012 01:46, Junio C Hamano wrote:\n> Jeff King <peff@peff.net> writes:\n>\n>> On Sun, Nov 11, 2012 at 06:20:58AM +0100, Henrich Schuchardt wrote:\n>>\n>>> Gitweb pages are structured by divs of class title with grey background.\n>>> The shortlog, and the log page show the project name as the first title.\n>>> Page summary only shows an empty grey box above the project details.\n>>> This provides an inconstent user experience.\n>>>\n>>> This patch adds the missing project title.\n>>>\n>>> Signed-off-by: Henrich Schuchardt <xypron.glpk@gmx.de>\n>>> ---\n>>>  gitweb/gitweb.perl |    2 +-\n>>>  1 file changed, 1 insertion(+), 1 deletion(-)\n>>>\n>>> diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\n>>> index 10ed9e5..3e1c452 100755\n>>> --- a/gitweb/gitweb.perl\n>>> +++ b/gitweb/gitweb.perl\n>>> @@ -6451,7 +6451,7 @@ sub git_summary {\n>>>  \tgit_header_html();\n>>>  \tgit_print_page_nav('summary','', $head);\n>>>  \n>>> -\tprint \"<div class=\\\"title\\\">&nbsp;</div>\\n\";\n>>> +\tprint \"<div class=\\\"title\\\">$project</div>\\n\";\n>> I do not have any opinion on whether the intent of the change is good or\n>> not, but shouldn't $project be run through esc_html() here?\n> I think the answer is yes.  And if $project needs to be escaped, the\n> git_feed function you fixed today has another codepath that needs to\n> be fixed.  When git_get_project_description($project) returns undef,\n> the description is taken from $project without any escaping.\n>\n>\n>\n"}]}