git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH GSoC 1/3] gitweb: Create Gitweb::Config module

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Jun 3, 2010, 16:00 UTC
Message-ID
<AANLkTinUrK3zdFCWashnGquEtVovmihT1qYQAM5gHk5X@mail.gmail.com>
In-Reply-To
<1275573356-21466-1-git-send-email-pavan.sss1991@gmail.com>

On Thu, Jun 3, 2010 at 13:55, Pavan Kumar Sunkara <pavan.sss1991@gmail.com> wrote:

Show 10 quoted lines
> +sub evaluate_gitweb_config {
> +       # die if there are errors parsing config file
> +       if (-e $GITWEB_CONFIG) {
> +               do $GITWEB_CONFIG;
> +               die $@ if $@;
> +       } elsif (-e $GITWEB_CONFIG_SYSTEM) {
> +               do $GITWEB_CONFIG_SYSTEM;
> +               die $@ if $@;
> +       }
> +}

I think I mentioned this before, but why not *optionally* use Config::Any (or something similar) and if it doesn't exists fall back on do(), and document this, along with a way to disable Perl execution.

It'd be completely compatible, but admins could then allow someone to edit a gitweb config file without opening themselves up to that someone having permission to execute code as the webserver.

Check out Gitalist (the Catalyst rewrite of Gitweb) for some prior art.

Previous: Pavan Kumar Sunkara
Message 13 of 13 in “gitweb: Create Gitweb::Config module”
  1. 1/3 gitweb: Create Gitweb::Config modulePavan Kumar Sunkara, Jun 3, 2010
  2. 2/3 gitweb: Create Gitweb::Request modulePavan Kumar Sunkara, Jun 3, 2010
  3. 3/3 git-instaweb: Add support for --reuse-config using gitconfigPavan Kumar Sunkara, Jun 3, 2010
  4. Petr BaudisJun 3, 2010
  5. Ævar Arnfjörð BjarmasonJun 3, 2010
  6. Jakub NarebskiJun 3, 2010
  7. Ævar Arnfjörð BjarmasonJun 3, 2010
  8. Jakub NarebskiJun 3, 2010
  9. Petr BaudisJun 3, 2010
  10. Pavan Kumar SunkaraJun 3, 2010
  11. Jakub NarebskiJun 3, 2010
  12. Pavan Kumar SunkaraJun 3, 2010
  13. Ævar Arnfjörð BjarmasonJun 3, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.