summary refs log tree commit diff
path: root/www/git.causal.agency/cgit/parsing.c
diff options
context:
space:
mode:
authorJune McEnroe <june@causal.agency>2021-09-25 18:33:40 -0400
committerJune McEnroe <june@causal.agency>2021-09-25 18:40:39 -0400
commitc775f259f076e971b4b14ad9533854ac3b3c98fa (patch)
tree52469ccf07f73c3ba1a40b8f8a42289f16a0b872 /www/git.causal.agency/cgit/parsing.c
parentSet SO_REUSEADDR in quick (diff)
downloadsrc-c775f259f076e971b4b14ad9533854ac3b3c98fa.tar.gz
src-c775f259f076e971b4b14ad9533854ac3b3c98fa.zip
Sandbox up on both FreeBSD and OpenBSD
This is a bit messy. pledge(2) calls based on [1].

[1]: https://kristaps.bsd.lv/kcgi/tutorial6.html
Diffstat (limited to 'www/git.causal.agency/cgit/parsing.c')
0 files changed, 0 insertions, 0 deletions
td>Jason A. Donenfeld This way we're sure to use virtual root, or any other strangeness encountered. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com> 2014-01-16auth: lua string comparisons are time invariantJason A. Donenfeld By default, strings are compared by hash, so we can remove this comment. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com> 2014-01-16authentication: use hidden form instead of refererJason A. Donenfeld This also gives us some CSRF protection. Note that we make use of the hmac to protect the redirect value. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com> 2014-01-16auth: add basic authentication filter frameworkJason A. Donenfeld This leverages the new lua support. See filters/simple-authentication.lua for explaination of how this works. There is also additional documentation in cgitrc.5.txt. Though this is a cookie-based approach, cgit's caching mechanism is preserved for authenticated pages. Very plugable and extendable depending on user needs. The sample script uses an HMAC-SHA1 based cookie to store the currently logged in user, with an expiration date. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com> 2014-01-16t0111: Additions and fixesLukas Fleischer * Rename the capitalize-* filters to dump.* since they also dump the arguments. * Add full argument validation to the email filters. Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de> 2014-01-16parsing.c: Remove leading space from committerLukas Fleischer