git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitweb: URL-decode $my_url/$my_uri when stripping PATH_INFO

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 15, 2012, 18:47 UTC
Message-ID
<7vipck56xj.fsf@alter.siamese.dyndns.org>
In-Reply-To
<201208152015.49132.jnareb@gmail.com>
Jakub Narebski <jnareb@gmail.com> writes:
Show 50 quoted lines
> On Thu, 9 Aug 2012, Junio C Hamano wrote:
>> Jay Soffian <jaysoffian@gmail.com> writes:
>> 
>> > When gitweb is used as a DirectoryIndex, it attempts to strip
>> > PATH_INFO on its own, as $cgi->url() fails to do so.
>> >
>> > However, it fails to account for the fact that PATH_INFO has
>> > already been URL-decoded by the web server, but the value
>> > returned by $cgi->url() has not been. This causes the stripping
>> > to fail whenever the URL contains encoded characters.
>> >
>> > To see this in action, setup gitweb as a DirectoryIndex and
>> > then use it on a repository with a directory containing a
>> > space in the name. Navigate to tree view, examine the gitweb
>> > generated html and you'll see a link such as:
>> >
>> >   <a href="/test.git/tree/HEAD:/directory with spaces">directory with spaces</a>
>> >
>> > When clicked on, the browser will URL-encode this link, giving
>> > a $cgi->url() of the form:
>> >
>> >    /test.git/tree/HEAD:/directory%20with%20spaces
>> >
>> > While PATH_INFO is:
>> >
>> >    /test.git/tree/HEAD:/directory with spaces
>> >
>> > Fix this by calling unescape() on both $my_url and $my_uri before
>> > stripping PATH_INFO from them.
>> >
>> > Signed-off-by: Jay Soffian <jaysoffian@gmail.com>
>> > ---
>> 
>> Thanks.  From a cursory look, with the help from the explanation in
>> the proposed commit log message, the change looks sensible.
>> 
>> I wonder if a breakage like this is something we can catch in one of
>> the t95xx series of tests, though.
>
> No, it is unfortunately not possible with current test infrastructure
> for gitweb.  The gitweb_run from t/gitweb-lib.sh allows to set
> PATH_INFO and QUERY_STRING, but does not allow to set up URL.
>
> That might change in the future...
>
>> Jakub, Ack?
>
> Acked-by: Jakub Narebski <jnareb@gmail.com>
>
> Uf ut us bot too late...
Thanks.
Previous: Jakub Narebski
Message 4 of 4 in “gitweb: URL-decode $my_url/$my_uri when stripping PATH_INFO”
  1. gitweb: URL-decode $my_url/$my_uri when stripping PATH_INFOJay Soffian, Aug 9, 2012
  2. Junio C HamanoAug 9, 2012
  3. Jakub NarebskiAug 15, 2012
  4. Junio C HamanoAug 15, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.