git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] gitweb: Fix usability of $prevent_xss

From
Jakub Narebski <jnareb@gmail.com>
Date
Jun 4, 2011, 08:43 UTC
Message-ID
<1307177015-880-1-git-send-email-jnareb@gmail.com>

With XSS prevention on (enabled using $prevent_xss), blobs ('blob_plain') of all types except a few known safe ones are served with "Content-Disposition: attachment". However the check was too strict; it didn't take into account optional parameter attributes,

  media-type     = type "/" subtype *( ";" parameter )
as described in RFC 2616
  http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.17
  http://www.w3.org/Protocols/rfc2616/rfc2616-sec3.html#sec3.7

This fixes that, and it for example treats following as safe MIME media type:

  text/plain; charset=utf-8
Signed-off-by: Jakub Narebski <jnareb@gmail.com>
---
The fact that it this buglet was present for so long, since its
introduction by Matt McCutchen in 7e1100e (gitweb: add $prevent_xss
option to prevent XSS by repository content, 2009-02-07) without
complaint shows that not many people are using this feature...
That, and that we don't have automated tests for that.
 gitweb/gitweb.perl |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index dc3f37d..85acbed 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -6139,7 +6139,7 @@ sub git_blob_plain {
 	# want to be sure not to break that by serving the image as an
 	# attachment (though Firefox 3 doesn't seem to care).
 	my $sandbox = $prevent_xss &&
-		$type !~ m!^(?:text/plain|image/(?:gif|png|jpeg))$!;
+		$type !~ m!^(?:text/plain|image/(?:gif|png|jpeg))(?:[ ;]|$)!;
 
 	print $cgi->header(
 		-type => $type,
-- 
1.7.5
Next: Matt McCutchen
Message 1 of 14 in “gitweb: Fix usability of $prevent_xss”
  1. gitweb: Fix usability of $prevent_xssJakub Narebski, Jun 4, 2011
  2. Prevalence of $prevent_xssMatt McCutchen, Jun 4, 2011
  3. Jakub NarebskiJun 4, 2011
  4. Implementing CSP (Content Security Policy) for gitweb in the futureJakub Narebski, Jun 5, 2011
  5. Matt McCutchenJun 5, 2011
  6. Jakub NarebskiJun 5, 2011
  7. Matt McCutchenJun 5, 2011
  8. Jakub NarebskiJun 8, 2011
  9. J.H.Jun 8, 2011
  10. gitweb: Make $prevent_xss protection for 'blob_plain' more usableJakub Narebski, Jun 10, 2011
  11. Junio C HamanoJun 13, 2011
  12. Jakub NarebskiJun 13, 2011
  13. Junio C HamanoJun 13, 2011
  14. Jakub NarebskiJun 14, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.