git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitweb: Make $prevent_xss protection for 'blob_plain' more usable

From
Jakub Narebski <jnareb@gmail.com>
Date
Jun 14, 2011, 01:33 UTC
Message-ID
<201106140333.58351.jnareb@gmail.com>
In-Reply-To
<7vy615mily.fsf@alter.siamese.dyndns.org>
Junio C Hamano wrote:
Show 27 quoted lines
> Jakub Narebski <jnareb@gmail.com> writes:
> 
>>> Hmph, wouldn't it be more straightforward if you dropped the statement
>>> modifier?  I.e.
>>> 
>>> 	my ($subtype, $rest) = ($1, $2);
>>> 	$rest = '' unless defined $rest;
>>> 	$type = "text/plain$rest";
>>
>> Yes, of course.
>>
>> I don't know why I decided that avoiding rewriting 'text/plain; 
>> charset=utf-8' case was important.
> 
> Just to make sure I understand what you are saying...
> 
>     my $type = 'text/plain; charset=utf-8';
>     if ($type =~ m|^text/([a-z]+)\b(.*)$|) {
>  	my ($subtype, $rest) = ($1, $2);
>  	$rest = '' unless defined $rest;
>  	$type = "text/plain$rest";
>         print "Type is now <$type>\n";
>     }
> 
> 
> does yield "text/plain; charset=utf-8". It does rewrite but rewrite to
> exactly the same thing, so...

Yes, it does rewrite to the same thing. And the code is simpler, therefore better.

-- 
Jakub Narebski
Poland
Previous: Junio C Hamano
Message 14 of 14 in “gitweb: Fix usability of $prevent_xss”
  1. gitweb: Fix usability of $prevent_xssJakub Narebski, Jun 4, 2011
  2. Prevalence of $prevent_xssMatt McCutchen, Jun 4, 2011
  3. Jakub NarebskiJun 4, 2011
  4. Implementing CSP (Content Security Policy) for gitweb in the futureJakub Narebski, Jun 5, 2011
  5. Matt McCutchenJun 5, 2011
  6. Jakub NarebskiJun 5, 2011
  7. Matt McCutchenJun 5, 2011
  8. Jakub NarebskiJun 8, 2011
  9. J.H.Jun 8, 2011
  10. gitweb: Make $prevent_xss protection for 'blob_plain' more usableJakub Narebski, Jun 10, 2011
  11. Junio C HamanoJun 13, 2011
  12. Jakub NarebskiJun 13, 2011
  13. Junio C HamanoJun 13, 2011
  14. Jakub NarebskiJun 14, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.