diff --git a/gitweb.cgi b/gitweb.cgi index fdecffca02..d1314d8489 100755 --- a/gitweb.cgi +++ b/gitweb.cgi @@ -80,8 +80,8 @@ if (defined $project) { undef $project; die_error(undef, "No such project."); } - $rss_link = ""; + $rss_link = ""; $ENV{'GIT_DIR'} = "$projectroot/$project"; } else { git_project_list(); @@ -146,7 +146,7 @@ sub validate_input { if ($input =~ m/(^|\/)(|\.|\.\.)($|\/)/) { return undef; } - if ($input =~ m/[^a-zA-Z0-9_ \.\/\-\+\#\~]/) { + if ($input =~ m/[^a-zA-Z0-9_\x80-\xff\ \.\/\-\+\#\~\%]/) { return undef; } return $input; @@ -209,13 +209,17 @@ if (!defined $action || $action eq "summary") { exit; } -sub esc_url { +# quote unsafe chars, but keep the slash, even when it's not +# correct, but quoted slashes look too horrible in bookmarks +sub esc_param { my $str = shift; + $str =~ s/([^A-Za-z0-9\-_.~();\/;?:@&=])/sprintf("%%%02X", ord($1))/eg; $str =~ s/\+/%2B/g; $str =~ s/ /\+/g; return $str; } +# replace invalid utf8 character with SUBSTITUTION sequence sub esc_html { my $str = shift; $str = decode("utf8", $str, Encode::FB_DEFAULT); @@ -223,6 +227,16 @@ sub esc_html { return $str; } +# git may return quoted and escaped filenames +sub unquote { + my $str = shift; + if ($str =~ m/^"(.*)"$/) { + $str = $1; + $str =~ s/\\([0-7]{1,3})/chr(oct($1))/eg; + } + return $str; +} + sub git_header_html { my $status = shift || "200 OK"; my $expires = shift; @@ -303,11 +317,11 @@ a.rss_logo:hover { background-color:#ee5500; } EOF print "