git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitweb: URL-decode $my_url/$my_uri when stripping PATH_INFO

From
Jakub Narebski <jnareb@gmail.com>
Date
Aug 15, 2012, 18:15 UTC
Message-ID
<201208152015.49132.jnareb@gmail.com>
In-Reply-To
<7vr4rgoz1u.fsf@alter.siamese.dyndns.org>
On Thu, 9 Aug 2012, Junio C Hamano wrote:
Show 37 quoted lines
> Jay Soffian <jaysoffian@gmail.com> writes:
> 
> > When gitweb is used as a DirectoryIndex, it attempts to strip
> > PATH_INFO on its own, as $cgi->url() fails to do so.
> >
> > However, it fails to account for the fact that PATH_INFO has
> > already been URL-decoded by the web server, but the value
> > returned by $cgi->url() has not been. This causes the stripping
> > to fail whenever the URL contains encoded characters.
> >
> > To see this in action, setup gitweb as a DirectoryIndex and
> > then use it on a repository with a directory containing a
> > space in the name. Navigate to tree view, examine the gitweb
> > generated html and you'll see a link such as:
> >
> >   <a href="/test.git/tree/HEAD:/directory with spaces">directory with spaces</a>
> >
> > When clicked on, the browser will URL-encode this link, giving
> > a $cgi->url() of the form:
> >
> >    /test.git/tree/HEAD:/directory%20with%20spaces
> >
> > While PATH_INFO is:
> >
> >    /test.git/tree/HEAD:/directory with spaces
> >
> > Fix this by calling unescape() on both $my_url and $my_uri before
> > stripping PATH_INFO from them.
> >
> > Signed-off-by: Jay Soffian <jaysoffian@gmail.com>
> > ---
> 
> Thanks.  From a cursory look, with the help from the explanation in
> the proposed commit log message, the change looks sensible.
> 
> I wonder if a breakage like this is something we can catch in one of
> the t95xx series of tests, though.

No, it is unfortunately not possible with current test infrastructure for gitweb. The gitweb_run from t/gitweb-lib.sh allows to set PATH_INFO and QUERY_STRING, but does not allow to set up URL.

That might change in the future...
> Jakub, Ack?
Acked-by: Jakub Narebski <jnareb@gmail.com>
Uf ut us bot too late...
-- 
Jakub Narebski
Poland
Previous: Junio C HamanoNext: Junio C Hamano
Message 3 of 4 in “gitweb: URL-decode $my_url/$my_uri when stripping PATH_INFO”
  1. gitweb: URL-decode $my_url/$my_uri when stripping PATH_INFOJay Soffian, Aug 9, 2012
  2. Junio C HamanoAug 9, 2012
  3. Jakub NarebskiAug 15, 2012
  4. Junio C HamanoAug 15, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.