git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Prevalence of $prevent_xss

From
Matt McCutchen <matt@mattmccutchen.net>
Date
Jun 4, 2011, 21:15 UTC
Message-ID
<1307222101.5994.13.camel@localhost>
In-Reply-To
<1307177015-880-1-git-send-email-jnareb@gmail.com>
On Sat, 2011-06-04 at 10:43 +0200, Jakub Narebski wrote:
> The fact that it this buglet was present for so long, since its
> introduction by Matt McCutchen in 7e1100e (gitweb: add $prevent_xss
> option to prevent XSS by repository content, 2009-02-07) without
> complaint shows that not many people are using this feature...
Yes.  Well, I'm still using it, and I found a few mentions on the web:

https://android.git.kernel.org/?p=tools/gerrit.git;a=blob;f=gerrit-httpd/src/main/java/com/google/gerrit/httpd/gitweb/GitWebServlet.java;h=947fbb423f1f8cf46db9876f4b80c600cdf9ee41;hb=HEAD#l193 http://ao2.it/wiki/How_to_setup_a_GIT_server_with_gitosis_and_gitweb http://www.digitalfoo.net/posts/2009/11/git,_gitosis,_gitweb_on_FreeBSD/

And there are probably others who did their own custom things (GitHub?) before the feature was added upstream.

-- 
Matt
Previous: Jakub NarebskiNext: Jakub Narebski
Message 2 of 14 in “gitweb: Fix usability of $prevent_xss”
  1. gitweb: Fix usability of $prevent_xssJakub Narebski, Jun 4, 2011
  2. Prevalence of $prevent_xssMatt McCutchen, Jun 4, 2011
  3. Jakub NarebskiJun 4, 2011
  4. Implementing CSP (Content Security Policy) for gitweb in the futureJakub Narebski, Jun 5, 2011
  5. Matt McCutchenJun 5, 2011
  6. Jakub NarebskiJun 5, 2011
  7. Matt McCutchenJun 5, 2011
  8. Jakub NarebskiJun 8, 2011
  9. J.H.Jun 8, 2011
  10. gitweb: Make $prevent_xss protection for 'blob_plain' more usableJakub Narebski, Jun 10, 2011
  11. Junio C HamanoJun 13, 2011
  12. Jakub NarebskiJun 13, 2011
  13. Junio C HamanoJun 13, 2011
  14. Jakub NarebskiJun 14, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.