{"thread":{"id":"5840","subject":"[PATCH] gitweb: Convert Content-Disposition filenames into qtext","startedAt":"2006-10-06T19:18:01Z","lastAt":"2006-10-07T18:01:15Z","messageCount":10,"participants":["Luben Tuikov","Petr Baudis","Jakub Narebski","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"28321","messageId":"20061006191801.68649.qmail@web31815.mail.mud.yahoo.com","threadId":"5840","inReplyTo":null,"subject":"[PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Luben Tuikov","fromEmail":"ltuikov@yahoo.com","sentAt":"2006-10-06T19:18:01Z","receivedAt":"2006-10-06T19:18:01Z","isPatch":true,"sender":{"key":"ltuikov@yahoo.com","avatar":null},"body":"Convert a string (e.g. a filename) into qtext as defined\nin RFC 822, from RFC 2183.  To be used by Content-Disposition.\n\nSigned-off-by: Luben Tuikov <ltuikov@yahoo.com>\n---\n gitweb/gitweb.perl |   18 ++++++++++++++----\n 1 files changed, 14 insertions(+), 4 deletions(-)\n\n\ndiff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\nindex f848648..a35d02c 100755\n--- a/gitweb/gitweb.perl\n+++ b/gitweb/gitweb.perl\n@@ -520,6 +520,16 @@ sub esc_html {\n \treturn $str;\n }\n \n+# Convert a string (e.g. a filename) into qtext as defined\n+# in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n+sub to_qtext {\n+\tmy $str = shift;\n+\t$str =~ s/\\\\/\\\\\\\\/g;\n+\t$str =~ s/\\\"/\\\\\\\"/g;\n+\t$str =~ s/\\r/\\\\r/g;\n+\treturn $str;\n+}\n+\n # git may return quoted and escaped filenames\n sub unquote {\n \tmy $str = shift;\n@@ -2742,7 +2752,7 @@ sub git_blob_plain {\n \tprint $cgi->header(\n \t\t-type => \"$type\",\n \t\t-expires=>$expires,\n-\t\t-content_disposition => 'inline; filename=\"' . \"$save_as\" . '\"');\n+\t\t-content_disposition => 'inline; filename=\"' . to_qtext(\"$save_as\") . '\"');\n \tundef $/;\n \tbinmode STDOUT, ':raw';\n \tprint <$fd>;\n@@ -2917,7 +2927,7 @@ sub git_snapshot {\n \tprint $cgi->header(\n \t\t-type => 'application/x-tar',\n \t\t-content_encoding => $ctype,\n-\t\t-content_disposition => 'inline; filename=\"' . \"$filename\" . '\"',\n+\t\t-content_disposition => 'inline; filename=\"' . to_qtext(\"$filename\") . '\"',\n \t\t-status => '200 OK');\n \n \tmy $git = git_cmd_str();\n@@ -3224,7 +3234,7 @@ sub git_blobdiff {\n \t\t\t-type => 'text/plain',\n \t\t\t-charset => 'utf-8',\n \t\t\t-expires => $expires,\n-\t\t\t-content_disposition => 'inline; filename=\"' . \"$file_name\" . '.patch\"');\n+\t\t\t-content_disposition => 'inline; filename=\"' . to_qtext(\"$file_name\") . '.patch\"');\n \n \t\tprint \"X-Git-Url: \" . $cgi->self_url() . \"\\n\\n\";\n \n@@ -3327,7 +3337,7 @@ sub git_commitdiff {\n \t\t\t-type => 'text/plain',\n \t\t\t-charset => 'utf-8',\n \t\t\t-expires => $expires,\n-\t\t\t-content_disposition => 'inline; filename=\"' . \"$filename\" . '\"');\n+\t\t\t-content_disposition => 'inline; filename=\"' . to_qtext(\"$filename\") . '\"');\n \t\tmy %ad = parse_date($co{'author_epoch'}, $co{'author_tz'});\n \t\tprint <<TEXT;\n From: $co{'author'}\n-- \n1.4.2.3.g0954\n\n"},{"id":"28322","messageId":"20061006192006.GW20017@pasky.or.cz","threadId":"5840","inReplyTo":"20061006191801.68649.qmail@web31815.mail.mud.yahoo.com","subject":"Re: [PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Petr Baudis","fromEmail":"pasky@suse.cz","sentAt":"2006-10-06T19:20:06Z","receivedAt":"2006-10-06T19:20:06Z","isPatch":true,"sender":{"key":"pasky@ucw.cz","avatar":"https://avatars.githubusercontent.com/u/18439?v=4"},"body":"Dear diary, on Fri, Oct 06, 2006 at 09:18:01PM CEST, I got a letter\nwhere Luben Tuikov <ltuikov@yahoo.com> said that...\n> Convert a string (e.g. a filename) into qtext as defined\n> in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n> \n> Signed-off-by: Luben Tuikov <ltuikov@yahoo.com>\n> ---\n>  gitweb/gitweb.perl |   18 ++++++++++++++----\n>  1 files changed, 14 insertions(+), 4 deletions(-)\n\nContent-Description: 1207600725-p1.txt\n> diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\n> index f848648..a35d02c 100755\n> --- a/gitweb/gitweb.perl\n> +++ b/gitweb/gitweb.perl\n> @@ -520,6 +520,16 @@ sub esc_html {\n>  \treturn $str;\n>  }\n>  \n> +# Convert a string (e.g. a filename) into qtext as defined\n> +# in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n> +sub to_qtext {\n> +\tmy $str = shift;\n> +\t$str =~ s/\\\\/\\\\\\\\/g;\n> +\t$str =~ s/\\\"/\\\\\\\"/g;\n> +\t$str =~ s/\\r/\\\\r/g;\n\n\\r? Not \\n?\n\n> +\treturn $str;\n> +}\n> +\n>  # git may return quoted and escaped filenames\n>  sub unquote {\n>  \tmy $str = shift;\n\nOther than that,\n\nAcked-by: Petr Baudis <pasky@suse.cz>\n\n-- \n\t\t\t\tPetr \"Pasky\" Baudis\nStuff: http://pasky.or.cz/\n#!/bin/perl -sp0777i<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<j]dsj\n$/=unpack('H*',$_);$_=`echo 16dio\\U$k\"SK$/SM$n\\EsN0p[lN*1\nlK[d2%Sa2/d0$^Ixp\"|dc`;s/\\W//g;$_=pack('H*',/((..)*)$/)\n"},{"id":"28324","messageId":"20061006193059.21334.qmail@web31807.mail.mud.yahoo.com","threadId":"5840","inReplyTo":"20061006192006.GW20017@pasky.or.cz","subject":"Re: [PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Luben Tuikov","fromEmail":"ltuikov@yahoo.com","sentAt":"2006-10-06T19:30:59Z","receivedAt":"2006-10-06T19:30:59Z","isPatch":true,"sender":{"key":"ltuikov@yahoo.com","avatar":null},"body":"--- Petr Baudis <pasky@suse.cz> wrote:\n> Dear diary, on Fri, Oct 06, 2006 at 09:18:01PM CEST, I got a letter\n> where Luben Tuikov <ltuikov@yahoo.com> said that...\n> > Convert a string (e.g. a filename) into qtext as defined\n> > in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n> > \n> > Signed-off-by: Luben Tuikov <ltuikov@yahoo.com>\n> > ---\n> >  gitweb/gitweb.perl |   18 ++++++++++++++----\n> >  1 files changed, 14 insertions(+), 4 deletions(-)\n> \n> Content-Description: 1207600725-p1.txt\n> > diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\n> > index f848648..a35d02c 100755\n> > --- a/gitweb/gitweb.perl\n> > +++ b/gitweb/gitweb.perl\n> > @@ -520,6 +520,16 @@ sub esc_html {\n> >  \treturn $str;\n> >  }\n> >  \n> > +# Convert a string (e.g. a filename) into qtext as defined\n> > +# in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n> > +sub to_qtext {\n> > +\tmy $str = shift;\n> > +\t$str =~ s/\\\\/\\\\\\\\/g;\n> > +\t$str =~ s/\\\"/\\\\\\\"/g;\n> > +\t$str =~ s/\\r/\\\\r/g;\n> \n> \\r? Not \\n?\n\nYes, \\r, not \\n.\n\n\\n is LF, \\r is CR, from ASCII(7).\n\nLF is legal in qtext as defined in RFC 822.\nThe illegals in qtext are CR, backslash and double quote.\n\n   Luben\n\n> \n> > +\treturn $str;\n> > +}\n> > +\n> >  # git may return quoted and escaped filenames\n> >  sub unquote {\n> >  \tmy $str = shift;\n> \n> Other than that,\n> \n> Acked-by: Petr Baudis <pasky@suse.cz>\n> \n> -- \n> \t\t\t\tPetr \"Pasky\" Baudis\n> Stuff: http://pasky.or.cz/\n> #!/bin/perl -sp0777i<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<j]dsj\n> $/=unpack('H*',$_);$_=`echo 16dio\\U$k\"SK$/SM$n\\EsN0p[lN*1\n> lK[d2%Sa2/d0$^Ixp\"|dc`;s/\\W//g;$_=pack('H*',/((..)*)$/)\n> \n"},{"id":"28344","messageId":"eg7qj5$d7d$1@sea.gmane.org","threadId":"5840","inReplyTo":"20061006191801.68649.qmail@web31815.mail.mud.yahoo.com","subject":"Re: [PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2006-10-07T09:05:25Z","receivedAt":"2006-10-07T09:05:25Z","isPatch":true,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Luben Tuikov wrote:\n\n> +# Convert a string (e.g. a filename) into qtext as defined\n> +# in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n> +sub to_qtext {\n> +       my $str = shift;\n> +       $str =~ s/\\\\/\\\\\\\\/g;\n> +       $str =~ s/\\\"/\\\\\\\"/g;\n> +       $str =~ s/\\r/\\\\r/g;\n> +       return $str;\n> +}\n\nI'd rather add \\n too.\n\n-- \nJakub Narebski\nWarsaw, Poland\nShadeHawk on #git\n"},{"id":"28348","messageId":"7vk63ctq47.fsf@assigned-by-dhcp.cox.net","threadId":"5840","inReplyTo":"20061006193059.21334.qmail@web31807.mail.mud.yahoo.com","subject":"Re: [PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2006-10-07T09:46:48Z","receivedAt":"2006-10-07T09:46:48Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Luben Tuikov <ltuikov@yahoo.com> writes:\n\n>> > +# Convert a string (e.g. a filename) into qtext as defined\n>> > +# in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n>> > +sub to_qtext {\n>> > +\tmy $str = shift;\n>> > +\t$str =~ s/\\\\/\\\\\\\\/g;\n>> > +\t$str =~ s/\\\"/\\\\\\\"/g;\n>> > +\t$str =~ s/\\r/\\\\r/g;\n>> \n>> \\r? Not \\n?\n>\n> Yes, \\r, not \\n.\n\n\\r to \\\\r? Not to \\\\\\r?\n"},{"id":"28352","messageId":"eg7u5n$mt9$1@sea.gmane.org","threadId":"5840","inReplyTo":"7vk63ctq47.fsf@assigned-by-dhcp.cox.net","subject":"Re: [PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2006-10-07T10:06:31Z","receivedAt":"2006-10-07T10:06:31Z","isPatch":true,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Junio C Hamano wrote:\n\n> Luben Tuikov <ltuikov@yahoo.com> writes:\n> \n>>>> +# Convert a string (e.g. a filename) into qtext as defined\n>>>> +# in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n>>>> +sub to_qtext {\n>>>> +  my $str = shift;\n>>>> +  $str =~ s/\\\\/\\\\\\\\/g;\n>>>> +  $str =~ s/\\\"/\\\\\\\"/g;\n\nHere probably it could be\n        $str =~ s/\"/\\\\\"/g;\n\n>>>> +  $str =~ s/\\r/\\\\r/g;\n>>> \n>>> \\r? Not \\n?\n>>\n>> Yes, \\r, not \\n.\n> \n> \\r to \\\\r? Not to \\\\\\r?\n\nWe want \"\\r\" in suggested filename, not \"\\\n\" I think, so it is \"\\\\r\".\n\nOtherwise we could use simplier\n        $str =~ s/([\\\\\"\\r])/\\\\\\1/g;\n\n-- \nJakub Narebski\nWarsaw, Poland\nShadeHawk on #git\n"},{"id":"28356","messageId":"7vvemwqusl.fsf@assigned-by-dhcp.cox.net","threadId":"5840","inReplyTo":"eg7u5n$mt9$1@sea.gmane.org","subject":"Re: [PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2006-10-07T10:34:02Z","receivedAt":"2006-10-07T10:34:02Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jakub Narebski <jnareb@gmail.com> writes:\n\n> Junio C Hamano wrote:\n>\n>> Luben Tuikov <ltuikov@yahoo.com> writes:\n>> \n>>>>> +# Convert a string (e.g. a filename) into qtext as defined\n>>>>> +# in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n>>>>> +sub to_qtext {\n>>>>> +  my $str = shift;\n>>>>> +  $str =~ s/\\\\/\\\\\\\\/g;\n>>>>> +  $str =~ s/\\\"/\\\\\\\"/g;\n>\n> Here probably it could be\n>         $str =~ s/\"/\\\\\"/g;\n>\n>>>>> +  $str =~ s/\\r/\\\\r/g;\n>>>> \n>>>> \\r? Not \\n?\n>>>\n>>> Yes, \\r, not \\n.\n>> \n>> \\r to \\\\r? Not to \\\\\\r?\n>\n> We want \"\\r\" in suggested filename, not \"\\\n> \" I think, so it is \"\\\\r\".\n\nIs that what you guys are attempting to achieve?\n\nIf we are trying to suggest a filename that is safe by avoiding\ncertain characters, I suspect leaving a backslash and dq as-is\nis just as bad as leaving a CR in.  So if that is the goal here,\nI think it might be better and a lot simpler to just replace\neach run of bytes not in Portable Filename Character Set with an\nunderscore '_'.\n"},{"id":"28359","messageId":"20061007114602.GX20017@pasky.or.cz","threadId":"5840","inReplyTo":"eg7u5n$mt9$1@sea.gmane.org","subject":"Re: [PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Petr Baudis","fromEmail":"pasky@suse.cz","sentAt":"2006-10-07T11:46:03Z","receivedAt":"2006-10-07T11:46:03Z","isPatch":true,"sender":{"key":"pasky@ucw.cz","avatar":"https://avatars.githubusercontent.com/u/18439?v=4"},"body":"Dear diary, on Sat, Oct 07, 2006 at 12:06:31PM CEST, I got a letter\nwhere Jakub Narebski <jnareb@gmail.com> said that...\n> >>>> +  $str =~ s/\\r/\\\\r/g;\n> >>> \n> >>> \\r? Not \\n?\n> >>\n> >> Yes, \\r, not \\n.\n> > \n> > \\r to \\\\r? Not to \\\\\\r?\n> \n> We want \"\\r\" in suggested filename, not \"\\\n> \" I think, so it is \"\\\\r\".\n\nOh, yes. Lubin wants. It looked sane until I've read it as you\nexplicitly wrote it. ;-)\n\nThat's \"obviously\" wrong. In qtext, \\r means just r, no special\ninterpretation is done. So we indeed _would_ want \"\\\n\". Which is of course a nice trap for buggy browsers so in fact we\nobviously do not want that. I think it's not wort the potential problems\nto try to carry newlines in the header, so I would just replace that\nline with\n\n\t$str =~ s/[\\n\\r]/_/g;\n\nas per Junio's suggestion.\n\n-- \n\t\t\t\tPetr \"Pasky\" Baudis\nStuff: http://pasky.or.cz/\n#!/bin/perl -sp0777i<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<j]dsj\n$/=unpack('H*',$_);$_=`echo 16dio\\U$k\"SK$/SM$n\\EsN0p[lN*1\nlK[d2%Sa2/d0$^Ixp\"|dc`;s/\\W//g;$_=pack('H*',/((..)*)$/)\n"},{"id":"28360","messageId":"eg85ga$9g6$1@sea.gmane.org","threadId":"5840","inReplyTo":"20061007114602.GX20017@pasky.or.cz","subject":"Re: [PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2006-10-07T12:11:38Z","receivedAt":"2006-10-07T12:11:38Z","isPatch":true,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Petr Baudis wrote:\n\n> Dear diary, on Sat, Oct 07, 2006 at 12:06:31PM CEST, I got a letter\n> where Jakub Narebski <jnareb@gmail.com> said that...\n>> >>>> +  $str =~ s/\\r/\\\\r/g;\n>> >>> \n>> >>> \\r? Not \\n?\n>> >>\n>> >> Yes, \\r, not \\n.\n>> > \n>> > \\r to \\\\r? Not to \\\\\\r?\n>> \n>> We want \"\\r\" in suggested filename, not \"\\\n>> \" I think, so it is \"\\\\r\".\n> \n> Oh, yes. Lubin wants. It looked sane until I've read it as you\n> explicitly wrote it. ;-)\n> \n> That's \"obviously\" wrong. In qtext, \\r means just r, no special\n> interpretation is done. So we indeed _would_ want \"\\\n> \". Which is of course a nice trap for buggy browsers so in fact we\n> obviously do not want that. I think it's not wort the potential problems\n> to try to carry newlines in the header, so I would just replace that\n> line with\n> \n>       $str =~ s/[\\n\\r]/_/g;\n> \n> as per Junio's suggestion.\n\nBu the way, using the following script:\n\n-- >8 --\n#!/usr/bin/perl\n\nuse strict;\nuse warnings;\nuse CGI qw(:standard :escapeHTML -nosticky);\n\nbinmode STDOUT, ':utf8';\n\nour $cgi = new CGI;\n\nprint $cgi->header(\n        -type => 'text/plain',\n        -charset => 'utf-8',\n        -content_disposition => 'inline; filename=\"test\\\".\\\\\"test\\\\n.\\\\\\n\"');\n\nprint \"TEST\\n\";\n-- >8 --\n\nI've checked that at least Mozilla 1.7.12 wants to using \"\\n\"\nin file name instead of literal eoln.\n-- \nJakub Narebski\nWarsaw, Poland\nShadeHawk on #git\n"},{"id":"28375","messageId":"20061007180115.59728.qmail@web31814.mail.mud.yahoo.com","threadId":"5840","inReplyTo":"7vvemwqusl.fsf@assigned-by-dhcp.cox.net","subject":"Re: [PATCH] gitweb: Convert Content-Disposition filenames into qtext","fromName":"Luben Tuikov","fromEmail":"ltuikov@yahoo.com","sentAt":"2006-10-07T18:01:15Z","receivedAt":"2006-10-07T18:01:15Z","isPatch":true,"sender":{"key":"ltuikov@yahoo.com","avatar":null},"body":"--- Junio C Hamano <junkio@cox.net> wrote:\n> Jakub Narebski <jnareb@gmail.com> writes:\n> \n> > Junio C Hamano wrote:\n> >\n> >> Luben Tuikov <ltuikov@yahoo.com> writes:\n> >> \n> >>>>> +# Convert a string (e.g. a filename) into qtext as defined\n> >>>>> +# in RFC 822, from RFC 2183.  To be used by Content-Disposition.\n> >>>>> +sub to_qtext {\n> >>>>> +  my $str = shift;\n> >>>>> +  $str =~ s/\\\\/\\\\\\\\/g;\n> >>>>> +  $str =~ s/\\\"/\\\\\\\"/g;\n> >\n> > Here probably it could be\n> >         $str =~ s/\"/\\\\\"/g;\n> >\n> >>>>> +  $str =~ s/\\r/\\\\r/g;\n> >>>> \n> >>>> \\r? Not \\n?\n> >>>\n> >>> Yes, \\r, not \\n.\n> >> \n> >> \\r to \\\\r? Not to \\\\\\r?\n> >\n> > We want \"\\r\" in suggested filename, not \"\\\n> > \" I think, so it is \"\\\\r\".\n> \n> Is that what you guys are attempting to achieve?\n\nI think so.\n\n> If we are trying to suggest a filename that is safe by avoiding\n> certain characters, I suspect leaving a backslash and dq as-is\n> is just as bad as leaving a CR in.  So if that is the goal here,\n> I think it might be better and a lot simpler to just replace\n> each run of bytes not in Portable Filename Character Set with an\n> underscore '_'.\n\nI think that if I were to download a file which had those chars\nin it, I'd like to at least be able to see the _intention_ of what\nchars the actual file name had.\n\nSo if I download a filename which looks like this:\n\n     This is a \\\" test \\\" file \\\\.\\r\n\nThen I know that the intention had been:\n\n     This is a \" test \" file \\.<CR>\n\nIt becomes an intention, since it needs to be carried over\na qtext.\n\n   Luben\n"}]}