git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 01/11 GSoC] gitweb: fix esc_url

From
Pavan Kumar Sunkara <pavan.sss1991@gmail.com>
Date
Jun 21, 2010, 22:00 UTC
Message-ID
<1277157648-6029-2-git-send-email-pavan.sss1991@gmail.com>
In-Reply-To
<1277157648-6029-1-git-send-email-pavan.sss1991@gmail.com>

The custom CGI escaping done in esc_url failed to escape UTF-8 properly. Fix by using CGI::escape on each sequence of matched characters instead of sprintf()ing a custom escaping for each byte.

Additionally, the space -> + escape was being escaped due to greedy matching on the first substitution. Fix by adding space to the list of characters not handled on the first substitution.

Finally, remove an unnecessary escaping of the + sign.
commit 425e225 has missed fixing esc_url.
Signed-off-by: Pavan Kumar Sunkara <pavan.sss1991@gmail.com>
---
 gitweb/gitweb.perl |    3 +--
 1 files changed, 1 insertions(+), 2 deletions(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index 9446376..518328f 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -1322,8 +1322,7 @@ sub esc_param {
 sub esc_url {
 	my $str = shift;
 	return undef unless defined $str;
-	$str =~ s/([^A-Za-z0-9\-_.~();\/;?:@&=])/sprintf("%%%02X", ord($1))/eg;
-	$str =~ s/\+/%2B/g;
+	$str =~ s/([^A-Za-z0-9\-_.~();\/;?:@&= ]+)/CGI::escape($1)/eg;
 	$str =~ s/ /\+/g;
 	return $str;
 }
-- 
1.7.1.454.g276eb9.dirty
Previous: Pavan Kumar SunkaraNext: Pavan Kumar Sunkara
Message 2 of 21 in “gitweb: Split gitweb into modules”
  1. 00/11 gitweb: Split gitweb into modulesPavan Kumar Sunkara, Jun 21, 2010
  2. 01/11 gitweb: fix esc_urlPavan Kumar Sunkara, Jun 21, 2010
  3. 02/11 gitweb: Prepare for splitting gitwebPavan Kumar Sunkara, Jun 21, 2010
  4. 03/11 gitweb: Create Gitweb::Git modulePavan Kumar Sunkara, Jun 21, 2010
  5. 04/11 gitweb: Create Gitweb::Config modulePavan Kumar Sunkara, Jun 21, 2010
  6. 05/11 gitweb: Create Gitweb::Request modulePavan Kumar Sunkara, Jun 21, 2010
  7. 06/11 gitweb: Create Gitweb::Escape modulePavan Kumar Sunkara, Jun 21, 2010
  8. 07/11 gitweb: Create Gitweb::RepoConfig modulePavan Kumar Sunkara, Jun 21, 2010
  9. 08/11 gitweb: Create Gitweb::View modulePavan Kumar Sunkara, Jun 21, 2010
  10. 09/11 gitweb: Create Gitweb::Util modulePavan Kumar Sunkara, Jun 21, 2010
  11. 10/11 gitweb: Create Gitweb::Format modulePavan Kumar Sunkara, Jun 21, 2010
  12. 11/11 gitweb: Create Gitweb::Parse modulePavan Kumar Sunkara, Jun 21, 2010
  13. gitweb: Add support for enabling 'write' featurePavan Kumar Sunkara, Jun 21, 2010
  14. Jakub NarebskiJun 22, 2010
  15. Pavan Kumar SunkaraJun 22, 2010
  16. Jakub NarebskiJun 22, 2010
  17. Jakub NarebskiJun 22, 2010
  18. Pavan Kumar SunkaraJun 22, 2010
  19. Jakub NarebskiJun 22, 2010
  20. Pavan Kumar SunkaraJun 22, 2010
  21. Jakub NarebskiJun 23, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.