git/list[1] front-page[2] threads[3] people[4] search[5] about
 

RE: gitweb not friendly to firefox?

From
LYLi Yang-r58472 <leoli@freescale.com>
Date
Mar 2, 2007, 10:27 UTC
Message-ID
<989B956029373F45A0B8AF02970818902DA81D@zch01exm26.fsl.freescale.net>
In-Reply-To
<7vabyweypw.fsf@assigned-by-dhcp.cox.net>
Show 5 quoted lines
> -----Original Message-----
> From: Junio C Hamano [mailto:junkio@cox.net]
> Sent: Friday, March 02, 2007 6:18 PM
> To: Li Yang-r58472
> Cc: Jakub Narebski; rea-git@codelabs.ru; Raimund Bauer;
git@vger.kernel.org
Show 7 quoted lines
> Subject: Re: gitweb not friendly to firefox?
> 
> "Li Yang-r58472" <LeoLi@freescale.com> writes:
> 
> > Hi Jakub,
> >
> > Problem sovled, using the following patch.  I'm not an expert of
perl,
> > so I don't know if it is problem of the gitweb or problem with my
perl
Show 35 quoted lines
> > environment.  My environment is perl-5.8.0 and perl-CGI-2.81.
> >
> > Signed-off-by: Li Yang<leoli@freecale.com>
> > ---
> > diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
> > index 653ca3c..8c9a291 100755
> > --- a/gitweb/gitweb.perl
> > +++ b/gitweb/gitweb.perl
> > @@ -591,7 +591,7 @@ sub esc_html ($;%) {
> >         my %opts = @_;
> >
> >         $str = to_utf8($str);
> > -       $str = escapeHTML($str);
> > +       $str = $cgi->escapeHTML($str);
> >         if ($opts{'-nbsp'}) {
> >                 $str =~ s/ /&nbsp;/g;
> >         }
> >
> 
> This is puzzling....
> 
>  (1) we have two call sites of escapeHTML(), but your patch
>      touches only one.
> 
>  (2) we do "use CGI qw(:standard :escapeHTML -nosticky);"
>      upfront, presumably after doing this when we say
>      escapeHTML() it means the same as CGI::escapeHTML().
> 
>  (3) we do "$cgi = new CGI" upfront.
> 
> So I am wondering how the patch can have any effect...
> 
> I am not saying that I do not believe you when you say the patch
> fixes the problem for you.  I just do not understand why and I
> hate not knowing why something works.
Here is the phenomenon I observed. In CGI.pm,
# Escape HTML -- used internally
'escapeHTML' => <<'END_OF_FUNC',
sub escapeHTML {
         # hack to work around  earlier hacks
         push @_,$_[0] if @_==1 && $_[0] eq 'CGI';
         my ($self,$toencode,$newlinestoo) = CGI::self_or_default(@_);
         return undef unless defined($toencode);
         return $toencode if ref($self) && !$self->{'escape'};
         $toencode =~ s{&}{&amp;}gso;
         $toencode =~ s{<}{&lt;}gso;
         $toencode =~ s{>}{&gt;}gso;
         $toencode =~ s{"}{&quot;}gso;
         my $latin = uc $self->{'.charset'} eq 'ISO-8859-1' ||
                     uc $self->{'.charset'} eq 'WINDOWS-1252';
         if ($latin) {  # bug in some browsers
                $toencode =~ s{'}{&#39;}gso;
                $toencode =~ s{\x8b}{&#8249;}gso;
                $toencode =~ s{\x9b}{&#8250;}gso;
                if (defined $newlinestoo && $newlinestoo) {
                     $toencode =~ s{\012}{&#10;}gso;
                     $toencode =~ s{\015}{&#13;}gso;
                }
         }
         return $toencode;
}
END_OF_FUNC

The escapeHTML() returns on " return $toencode if ref($self) && !$self->{'escape'};". So the $self->{'ecscape'} = 0. However, $cgi->{'escape'} = 1. So I know, the $self is not the $cgi in gitweb, but another CGI with 'escape' undefined.

- Leo
Previous: Junio C HamanoNext: Oleg Verych
Message 9 of 24 in “Re: gitweb not friendly to firefox?”
  1. Eygene RyabinkinMar 1, 2007
  2. Raimund BauerMar 1, 2007
  3. Li Yang-r58472Mar 2, 2007
  4. Junio C HamanoMar 2, 2007
  5. Li Yang-r58472Mar 2, 2007
  6. Junio C HamanoMar 2, 2007
  7. Li Yang-r58472Mar 2, 2007
  8. Junio C HamanoMar 2, 2007
  9. Li Yang-r58472Mar 2, 2007
  10. (Re: gitweb not friendly to firefox?) and unusable in the lynxOleg Verych, Mar 2, 2007
  11. Jakub NarebskiMar 3, 2007
  12. Nicolas PitreMar 3, 2007
  13. Jakub NarebskiMar 3, 2007
  14. Nicolas PitreMar 3, 2007
  15. Jakub NarebskiMar 3, 2007
  16. Nicolas PitreMar 3, 2007
  17. Jakub NarebskiMar 4, 2007
  18. Uwe Kleine-KönigMar 4, 2007
  19. Nicolas PitreMar 3, 2007
  20. Oleg VerychMar 3, 2007
  21. Johannes SchindelinMar 3, 2007
  22. Junio C HamanoMar 3, 2007
  23. Oleg VerychMar 3, 2007
  24. sfMar 8, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.