git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] Escape project names before creating pathinfo URLs

From
MKmartin f. krafft <madduck@madduck.net>
Date
Apr 20, 2008, 21:23 UTC
Message-ID
<1208726618-27477-1-git-send-email-madduck@madduck.net>
In-Reply-To
<1208725436-25408-1-git-send-email-madduck@madduck.net>

If a project name contains special URL characters like +, gitweb's links break in subtle ways. The solution is to pass the project name through esc_url() and using the return value.

Signed-off-by: martin f. krafft <madduck@madduck.net>
---
 gitweb/gitweb.perl |    4 ++--
 1 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index a48bebb..241ae17 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -633,7 +633,7 @@ sub href(%) {
 	my ($use_pathinfo) = gitweb_check_feature('pathinfo');
 	if ($use_pathinfo) {
 		# use PATH_INFO for project name
-		$href .= "/$params{'project'}" if defined $params{'project'};
+		$href .= "/".esc_url($params{'project'}) if defined $params{'project'};
 		delete $params{'project'};
 
 		# Summary just uses the project path URL
@@ -2575,7 +2575,7 @@ EOF
 		my $action = $my_uri;
 		my ($use_pathinfo) = gitweb_check_feature('pathinfo');
 		if ($use_pathinfo) {
-			$action .= "/$project";
+			$action .= "/".esc_url($project);
 		} else {
 			$cgi->param("p", $project);
 		}
-- 
1.5.5.rc2
Previous: martin f. krafftNext: Junio C Hamano
Message 5 of 6 in “gitweb fails with pathinfo and project with ++ in the name”
  1. martin f krafftApr 20, 2008
  2. Frank LichtenheldApr 20, 2008
  3. martin f krafftApr 20, 2008
  4. Escape project name in regexpmartin f. krafft, Apr 20, 2008
  5. Escape project names before creating pathinfo URLsmartin f. krafft, Apr 20, 2008
  6. Junio C HamanoApr 22, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.