git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v5.5 1/5] gitweb: prepare git_get_projects_list for use outside 'forks'.

From
BLBernhard R. Link <brl+git@mail.brlink.eu>
Date
Jan 30, 2012, 14:55 UTC
Message-ID
<20120130145538.GA2162@server.brlink.eu>
In-Reply-To
<201201301442.06707.jnareb@gmail.com>

Use of the filter option of git_get_projects_list is currently limited to forks. It hard codes removal of ".git" suffixes from the filter and assumes the project belonging to the filter directory was already validated to be visible in the project list.

To make it more generic move the .git suffix removal to the callers and add an optional argument to denote visibility verification is still needed.

If there is a projects list file (GITWEB_LIST) only projects from this list are returned anyway, so no more checks needed.

If there is no projects list file and the caller requests strict checking (GITWEB_STRICT_EXPORT), do not jump directly to the given directory but instead do a normal search and filter the results instead.

The only (hopefully non-existing) effect of GITWEB_STRICT_EXPORT without GITWEB_LIST is to make sure no project can be viewed without also be found starting from project root. git_get_projects_list without this patch does not enforce this but all callers only call it with a filter already checked this way. With this parameter a caller can request this check if the filter cannot be checked this way.

Signed-off-by: Bernhard R. Link <brlink@debian.org>
---
Changes since v5:
	- don't you use s/.../.../r
 gitweb/gitweb.perl |   13 ++++++++-----
 1 files changed, 8 insertions(+), 5 deletions(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index 9cf7e71..19daabc 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -2829,10 +2829,9 @@ sub git_get_project_url_list {
 
 sub git_get_projects_list {
 	my $filter = shift || '';
+	my $paranoid = shift;
 	my @list;
 
-	$filter =~ s/\.git$//;
-
 	if (-d $projects_list) {
 		# search in directory
 		my $dir = $projects_list;
@@ -2841,7 +2840,7 @@ sub git_get_projects_list {
 		my $pfxlen = length("$dir");
 		my $pfxdepth = ($dir =~ tr!/!!);
 		# when filtering, search only given subdirectory
-		if ($filter) {
+		if ($filter and not $paranoid) {
 			$dir .= "/$filter";
 			$dir =~ s!/+$!!;
 		}
@@ -2866,6 +2865,10 @@ sub git_get_projects_list {
 				}
 
 				my $path = substr($File::Find::name, $pfxlen + 1);
+				# paranoidly only filter here
+				if ($paranoid && $filter && $path !~ m!^\Q$filter\E/!) {
+					next;
+				}
 				# we check related file in $projectroot
 				if (check_export_ok("$projectroot/$path")) {
 					push @list, { path => $path };
@@ -6007,7 +6010,7 @@ sub git_forks {
 		die_error(400, "Unknown order parameter");
 	}
 
-	my @list = git_get_projects_list($project);
+	my @list = git_get_projects_list((my $filter = $project) =~ s/\.git$//);
 	if (!@list) {
 		die_error(404, "No forks found");
 	}
@@ -6066,7 +6069,7 @@ sub git_summary {
 
 	if ($check_forks) {
 		# find forks of a project
-		@forklist = git_get_projects_list($project);
+		@forklist = git_get_projects_list((my $filter = $project) =~ s/\.git$//);
 		# filter out forks of forks
 		@forklist = filter_forks_from_projects_list(\@forklist)
 			if (@forklist);
-- 
1.7.8.3
Previous: Jakub NarebskiNext: Jakub Narebski
Message 16 of 40 in “gitweb: add project_filter to limit project list to a subdirectory”
  1. 1/2 gitweb: add project_filter to limit project list to a subdirectoryBernhard R. Link, Jan 28, 2012
  2. 2/2 gitweb: place links to parent directories in page headerBernhard R. Link, Jan 28, 2012
  3. Jakub NarebskiJan 28, 2012
  4. Jakub NarebskiJan 28, 2012
  5. gitweb: add project_filter to limit project list to a subdirectoryBernhard R. Link, Jan 29, 2012
  6. Jakub NarebskiJan 29, 2012
  7. 1/2 gitweb: add project_filter to limit project list to a subdirectoryBernhard R. Link, Jan 29, 2012
  8. 2/2 gitweb: place links to parent directories in page headerBernhard R. Link, Jan 29, 2012
  9. Jakub NarebskiJan 29, 2012
  10. Jakub NarebskiJan 29, 2012
  11. Junio C HamanoJan 29, 2012
  12. Jakub NarebskiJan 29, 2012
  13. Bernhard R. LinkJan 30, 2012
  14. 1/5 gitweb: prepare git_get_projects_list for use outside 'forks'.Bernhard R. Link, Jan 30, 2012
  15. Jakub NarebskiJan 30, 2012
  16. 1/5 gitweb: prepare git_get_projects_list for use outside 'forks'.Bernhard R. Link, Jan 30, 2012
  17. Jakub NarebskiJan 30, 2012
  18. Bernhard R. LinkJan 30, 2012
  19. 2/5 gitweb: add project_filter to limit project list to a subdirectoryBernhard R. Link, Jan 30, 2012
  20. Jakub NarebskiJan 30, 2012
  21. Bernhard R. LinkJan 30, 2012
  22. 1/6 gitweb: move hard coded .git suffix out of git_get_projects_listBernhard R. Link, Jan 30, 2012
  23. 2/6 gitweb: prepare git_get_projects_list for use outside 'forks'.Bernhard R. Link, Jan 30, 2012
  24. 3/6 gitweb: add project_filter to limit project list to a subdirectoryBernhard R. Link, Jan 30, 2012
  25. 4/6 gitweb: limit links to alternate forms of project_list to active project_filterBernhard R. Link, Jan 30, 2012
  26. 5/6 gitweb: show active project_filter in project_list page headerBernhard R. Link, Jan 30, 2012
  27. 6/6 gitweb: place links to parent directories in page headerBernhard R. Link, Jan 30, 2012
  28. Junio C HamanoJan 30, 2012
  29. Jakub NarebskiJan 30, 2012
  30. Junio C HamanoJan 30, 2012
  31. Junio C HamanoJan 30, 2012
  32. Bernhard R. LinkJan 30, 2012
  33. Bernhard R. LinkFeb 1, 2012
  34. Junio C HamanoFeb 1, 2012
  35. 3/5 gitweb: limit links to alternate forms of project_list to active project_filterBernhard R. Link, Jan 30, 2012
  36. Jakub NarebskiJan 30, 2012
  37. 4/5 gitweb: show active project_filter in project_list page headerBernhard R. Link, Jan 30, 2012
  38. Jakub NarebskiJan 30, 2012
  39. 5/5 gitweb: place links to parent directories in page headerBernhard R. Link, Jan 30, 2012
  40. Jakub NarebskiJan 30, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.