git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: html page display via cgit

From
JJJoshua Juran <jjuran@gmail.com>
Date
Sep 1, 2010, 10:00 UTC
Message-ID
<9D2F75AD-B25E-4730-82FA-E8C5F73FCE1B@gmail.com>
In-Reply-To
<AANLkTik-02dJZF_0m=xccg4N5Mdaj=b2JzZaMKp=vuww@mail.gmail.com>
On Sep 1, 2010, at 2:46 AM, Ævar Arnfjörð Bjarmason wrote:
Show 28 quoted lines
> On Wed, Sep 1, 2010 at 09:32, Shivdas Gujare  
> <shivdas.tech@gmail.com> wrote:
>
>> I hope, this is the right mailing list for cgit as well.
>> I am trying to add some "html logs" inside cgit, but I can't open
>> these logs via cgit inside firefox, i.e. cgit open every files in
>> "plain" format,
>> would like to know if it is possible to open "html" pages inside cgit
>> so that if I click on html page added into git, it opens in html and
>> not in plain format.
>>
>> for example:
>> if I click on "download.html" from
>> "http://cgit.freedesktop.org/~lb/mesa/tree/docs" it shows a raw file
>> as "http://cgit.freedesktop.org/~lb/mesa/tree/docs/download.html"
>> and if I click on "plain" it opens in firefox like
>> "http://cgit.freedesktop.org/~lb/mesa/plain/docs/download.html"
>> but here I am trying to open this "download.html" inside cgit so that
>> I can view it like html web page and not as "plain" text file.
>>
>> Thanks for any help or pointers.
>
> I don't know, but that's probably deliberate. You're viewing a /plain/
> link, which should be the equivalent of "git show".
>
> There's also XSS security implications to serving things as text/html
> on a shared hosting site if the main site serves cookies or otherwise
> has user logins.

One solution is parse the content server-side and re-render as sanitized HTML. In addition to stripping out scripts and frames, this would avoid sending broken markup produced by someone else under your name, or serving up otherwise well-formed XHTML as text/html.

Josh
Previous: Ævar Arnfjörð BjarmasonNext: Ævar Arnfjörð Bjarmason
Message 3 of 9 in “html page display via cgit”
  1. Shivdas GujareSep 1, 2010
  2. Ævar Arnfjörð BjarmasonSep 1, 2010
  3. Joshua JuranSep 1, 2010
  4. Ævar Arnfjörð BjarmasonSep 1, 2010
  5. Joshua JuranSep 1, 2010
  6. Stefan NaeweSep 1, 2010
  7. Shivdas GujareSep 1, 2010
  8. Lars HjemliSep 1, 2010
  9. Stefan NaeweSep 2, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.