git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] gitweb: URL-decode $my_url/$my_uri when stripping PATH_INFO

From
Jay Soffian <jaysoffian@gmail.com>
Date
Aug 9, 2012, 02:29 UTC
Message-ID
<1344479366-8957-1-git-send-email-jaysoffian@gmail.com>

When gitweb is used as a DirectoryIndex, it attempts to strip PATH_INFO on its own, as $cgi->url() fails to do so.

However, it fails to account for the fact that PATH_INFO has already been URL-decoded by the web server, but the value returned by $cgi->url() has not been. This causes the stripping to fail whenever the URL contains encoded characters.

To see this in action, setup gitweb as a DirectoryIndex and then use it on a repository with a directory containing a space in the name. Navigate to tree view, examine the gitweb generated html and you'll see a link such as:

  <a href="/test.git/tree/HEAD:/directory with spaces">directory with spaces</a>

When clicked on, the browser will URL-encode this link, giving a $cgi->url() of the form:

   /test.git/tree/HEAD:/directory%20with%20spaces
While PATH_INFO is:
   /test.git/tree/HEAD:/directory with spaces

Fix this by calling unescape() on both $my_url and $my_uri before stripping PATH_INFO from them.

Signed-off-by: Jay Soffian <jaysoffian@gmail.com>
---
 gitweb/gitweb.perl | 5 +++++
 1 file changed, 5 insertions(+)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index 3d6a705388..7f8c1878d4 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -54,6 +54,11 @@ sub evaluate_uri {
 	# to build the base URL ourselves:
 	our $path_info = decode_utf8($ENV{"PATH_INFO"});
 	if ($path_info) {
+		# $path_info has already been URL-decoded by the web server, but
+		# $my_url and $my_uri have not. URL-decode them so we can properly
+		# strip $path_info.
+		$my_url = unescape($my_url);
+		$my_uri = unescape($my_uri);
 		if ($my_url =~ s,\Q$path_info\E$,, &&
 		    $my_uri =~ s,\Q$path_info\E$,, &&
 		    defined $ENV{'SCRIPT_NAME'}) {
-- 
1.7.11.3
Next: Junio C Hamano
Message 1 of 4 in “gitweb: URL-decode $my_url/$my_uri when stripping PATH_INFO”
  1. gitweb: URL-decode $my_url/$my_uri when stripping PATH_INFOJay Soffian, Aug 9, 2012
  2. Junio C HamanoAug 9, 2012
  3. Jakub NarebskiAug 15, 2012
  4. Junio C HamanoAug 15, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.