[PATCH] gitweb: Harden and improve $project_filter page title
From: Jakub Narebski <hidden>
Date: 2016-06-15 22:53:03
Subsystem:
the rest · Maintainer:
Linus Torvalds
Commit 19d2d23 (gitweb: add project_filter to limit project list to a subdirectory, 2012-01-30) added also support for displaying $project_filter, if present, in page title. Unfortunately it forgot to treat $project_filter as path, and escape it using esc_path(), like it is done for $filename. Also, it was not obvious that "$site_name - $project_filter" is about project filtering: use "$site_name - projects in '$project_filter'". Signed-off-by: Jakub Narebski <redacted> --- Though we should probably also esc_path($project), not only to_utf8($project) in get_page_title() subroutine. So I am not that sure if it is really necessary, or if I should follow it by further hardening of get_page_title(). Anyway I have noticed this when I was examining gitweb code for generating page title, considering adding information about search for project search. So this is patch I will be depending textually via context lines on. gitweb/gitweb.perl | 2 +- 1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index 081ac45..8ba2022 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl@@ -3751,7 +3751,7 @@ sub get_page_title { unless (defined $project) { if (defined $project_filter) { - $title .= " - " . to_utf8($project_filter); + $title .= " - projects in '" . esc_path($project_filter) . "'"; } return $title; }
--
1.7.9