git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] gitweb: avoid double / in search form action link

From
Tony Finch <dot@dotat.at>
Date
Apr 8, 2015, 13:49 UTC
Message-ID
<alpine.LSU.2.00.1504081448410.10193@hermes-1.csi.cam.ac.uk>

The in-project search form needs to duplicate some of the logic of the href() subroutine, because the parameters need to be encoded in the form rather than in the URL. However it failed to correctly append the project PATH_INFO in cases when there is a trailing slash on gitweb's self-referential URL, and failed to correctly follow PATH_INFO escaping rules.

This change makes the form action URL consistent with the URL generated by href().

Signed-off-by: Tony Finch <dot@dotat.at>
---
 gitweb/gitweb.perl | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index a02f3e4..05acd73 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -4129,10 +4129,14 @@ sub print_search_form {
 	} else {
 		$search_hash = "HEAD";
 	}
+	# We can't use href() here because we need to encode the
+	# URL parameters into the form, not into the action link.
 	my $action = $my_uri;
 	my $use_pathinfo = gitweb_check_feature('pathinfo');
 	if ($use_pathinfo) {
-		$action .= "/".esc_url($project);
+		# See notes about doubled / in href()
+		$action =~ s,/$,,;
+		$action .= "/".esc_path_info($project);
 	}
 	print $cgi->start_form(-method => "get", -action => $action) .
 	      "<div class=\"search\">\n" .
-- 
2.2.1.68.g56d9796
Message 1 of 1 in “gitweb: avoid double / in search form action link”
  1. gitweb: avoid double / in search form action linkTony Finch, Apr 8, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.