git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH] gitweb: Support filtering projects by .htaccess files.

From
Jakub Narebski <jnareb@gmail.com>
Date
Nov 5, 2008, 23:26 UTC
Message-ID
<200811060026.59340.jnareb@gmail.com>
In-Reply-To
<200811060136.23806.angavrilov@gmail.com>
Alexander Gavrilov wrote:
 
> How about the following patch, that simply adds a hook, and provides
> an example using mod_perl in the documentation?
Very nice, simple yet powerfull solution.
 
Show 13 quoted lines
> --- >8 ---
> Subject: [PATCH] gitweb: Add a per-repository authorization hook.
> 
> Add a configuration variable that can be used to specify an
> arbitrary subroutine that will be called in the same situations
> where $export_ok is checked, and its return value used
> to decide whether the repository is to be shown.
> 
> This allows the user to implement custom authentication
> schemes, for example by issuing a subrequest through mod_perl
> and checking if Apache will authorize it.
> 
> Signed-off-by: Alexander Gavrilov <angavrilov@gmail.com>
If somebody could check out example given for this feature, I'd add
Acked-by: Jakub Narebski <jnareb@gmail.com>
Show 32 quoted lines
> ---
>  gitweb/INSTALL     |   21 +++++++++++++++++++++
>  gitweb/gitweb.perl |    8 +++++++-
>  2 files changed, 28 insertions(+), 1 deletions(-)
> 
> diff --git a/gitweb/INSTALL b/gitweb/INSTALL
> index 26967e2..fa5917a 100644
> --- a/gitweb/INSTALL
> +++ b/gitweb/INSTALL
> @@ -166,6 +166,27 @@ Gitweb repositories
>    shows repositories only if this file exists in its object database
>    (if directory has the magic file named $export_ok).
>  
> +- Finally, it is possible to specify an arbitrary perl subroutine that
> +  will be called for each project to determine if it can be exported.
> +  The subroutine receives an absolute path to the project as its only
> +  parameter.
> +
> +  For example, if you use mod_perl to run the script, and have dumb
> +  http protocol authentication configured for your repositories, you
> +  can use the following hook to allow access only if the user is
> +  authorized to read the files:
> +
> +    $export_auth_hook = sub {
> +        use Apache2::SubRequest ();
> +        use Apache2::Const -compile => qw(HTTP_OK);
> +        my $path = "$_[0]/HEAD";
> +        my $r    = Apache2::RequestUtil->request;
> +        my $sub  = $r->lookup_file($path);
> +        return $sub->filename eq $path 
> +            && $sub->status == Apache2::Const::HTTP_OK;
> +    };
Can anybody check this? Or was it checked by author?
Show 18 quoted lines
> +
> +
>  Generating projects list using gitweb
>  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>  
> diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
> index 172ea6b..9329880 100755
> --- a/gitweb/gitweb.perl
> +++ b/gitweb/gitweb.perl
> @@ -95,6 +95,11 @@ our $default_projects_order = "project";
>  # (only effective if this variable evaluates to true)
>  our $export_ok = "++GITWEB_EXPORT_OK++";
>  
> +# show repository only if this subroutine returns true
> +# when given the path to the project, for example:
> +#    sub { return -e "$_[0]/git-daemon-export-ok"; }
> +our $export_auth_hook = undef;
> +
Simple, yet powerfull. Nice short example.
Show 10 quoted lines
>  # only allow viewing of repositories also shown on the overview page
>  our $strict_export = "++GITWEB_STRICT_EXPORT++";
>  
> @@ -400,7 +405,8 @@ sub check_head_link {
>  sub check_export_ok {
>  	my ($dir) = @_;
>  	return (check_head_link($dir) &&
> -		(!$export_ok || -e "$dir/$export_ok"));
> +		(!$export_ok || -e "$dir/$export_ok") &&
> +		(!$export_auth_hook || $export_auth_hook->($dir)));
Nice.
Show 6 quoted lines
>  }
>  
>  # process alternate names for backward compatibility
> -- 
> tg: (0d4f9de..) t/authenticate/hook (depends on: t/authenticate/unify-exportok)
> 
P.S. Why doesn't TopGit add git and TopGit version to signature?
-- 
Jakub Narebski
Poland
Previous: Alexander GavrilovNext: Alexander Gavrilov
Message 13 of 14 in “gitweb: Support filtering projects by .htaccess files.”
  1. gitweb: Support filtering projects by .htaccess files.Alexander Gavrilov, Nov 3, 2008
  2. Francis GaliegueNov 3, 2008
  3. Alexander GavrilovNov 3, 2008
  4. Francis GaliegueNov 3, 2008
  5. Jakub NarebskiNov 3, 2008
  6. Francis GaliegueNov 3, 2008
  7. Jakub NarebskiNov 3, 2008
  8. Francis GaliegueNov 3, 2008
  9. Jakub NarebskiNov 4, 2008
  10. Francis GaliegueNov 4, 2008
  11. Jakub NarebskiNov 3, 2008
  12. Alexander GavrilovNov 5, 2008
  13. Jakub NarebskiNov 5, 2008
  14. Alexander GavrilovNov 6, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.