Go to file
zeripath bbffcc3aec
Multiple Escaping Improvements (#17551)
There are multiple places where Gitea does not properly escape URLs that it is building and there are multiple places where it builds urls when there is already a simpler function available to use this.
    
This is an extensive PR attempting to fix these issues.

1. The first commit in this PR looks through all href, src and links in the Gitea codebase and has attempted to catch all the places where there is potentially incomplete escaping.
2. Whilst doing this we will prefer to use functions that create URLs over recreating them by hand.
3. All uses of strings should be directly escaped - even if they are not currently expected to contain escaping characters. The main benefit to doing this will be that we can consider relaxing the constraints on user names and reponames in future. 
4. The next commit looks at escaping in the wiki and re-considers the urls that are used there. Using the improved escaping here wiki files containing '/'. (This implementation will currently still place all of the wiki files the root directory of the repo but this would not be difficult to change.)
5. The title generation in feeds is now properly escaped.
6. EscapePound is no longer needed - urls should be PathEscaped / QueryEscaped as necessary but then re-escaped with Escape when creating html with locales Signed-off-by: Andrew Thornton <art27@cantab.net>

Signed-off-by: Andrew Thornton <art27@cantab.net>
2021-11-16 18:18:25 +00:00
.gitea Issue template form (#16349) 2021-09-15 20:33:13 +03:00
.github hide note message for pull request template (#17529) 2021-11-02 22:43:16 -05:00
assets Clean up SVG (#13680) 2020-12-17 16:33:53 -05:00
build Remove deprecated extendDefaultPlugins method of svgo (#17399) 2021-10-22 22:05:53 +02:00
cmd Move migrations into services and base into modules/migration (#17663) 2021-11-16 23:25:33 +08:00
contrib Decouple unit test code from business code (#17623) 2021-11-12 22:36:47 +08:00
custom/conf Fix documents for ALLOWED_HOST_LIST, its default value differs between 1.15 and 1.16 (#17530) 2021-11-08 11:25:41 +08:00
docker Change docker tag logic (#16421) 2021-07-14 18:08:43 +01:00
docs fix typo (#17614) 2021-11-14 17:32:48 -05:00
integrations Multiple Escaping Improvements (#17551) 2021-11-16 18:18:25 +00:00
models Multiple Escaping Improvements (#17551) 2021-11-16 18:18:25 +00:00
modules Multiple Escaping Improvements (#17551) 2021-11-16 18:18:25 +00:00
options Multiple Escaping Improvements (#17551) 2021-11-16 18:18:25 +00:00
public Fix GitBucket icon (#17644) 2021-11-16 12:24:22 +08:00
routers Multiple Escaping Improvements (#17551) 2021-11-16 18:18:25 +00:00
services Multiple Escaping Improvements (#17551) 2021-11-16 18:18:25 +00:00
snap Removable media support (#16136) 2021-06-11 14:51:05 -04:00
templates Multiple Escaping Improvements (#17551) 2021-11-16 18:18:25 +00:00
tools Add bundle download for repository (#14538) 2021-08-24 11:47:09 -05:00
vendor Simplify Gothic to use our session store instead of creating a different store (#17507) 2021-11-03 08:33:54 +08:00
web_src Multiple Escaping Improvements (#17551) 2021-11-16 18:18:25 +00:00
.air.toml Rename .air.conf to .air.toml (#17360) 2021-10-20 00:27:29 +08:00
.changelog.yml Changelog for v1.15.0-rc1 (#16422) 2021-07-15 11:47:57 -04:00
.drone.yml Add protection to disable Gitea when run as root (#17168) 2021-10-07 10:52:08 +02:00
.editorconfig add well-known config for OIDC (#15355) 2021-04-15 22:32:00 -04:00
.eslintrc Update JS dependencies (#17611) 2021-11-11 09:52:16 +08:00
.gitattributes Remove unused Fomantic sidebar module (#16853) 2021-08-29 21:57:07 +02:00
.gitignore Frontend refactor: move Vue related code from index.js to components dir, and remove unused codes. (#17301) 2021-10-15 10:35:26 +08:00
.golangci.yml Remove golint as linter (#17609) 2021-11-11 13:28:45 +08:00
.ignore
.lgtm
.npmrc Stop packaging node_modules in release tarballs (#15273) 2021-04-09 01:08:14 -04:00
.revive.toml Avoid double imports (#17569) 2021-11-08 09:04:13 +02:00
.stylelintrc Update JS dependencies (#17611) 2021-11-11 09:52:16 +08:00
BSDmakefile
build.go Add bundle download for repository (#14538) 2021-08-24 11:47:09 -05:00
CHANGELOG.md Changelog 1.15.6 (#17457) (#17468) 2021-10-28 10:22:27 +01:00
CONTRIBUTING.md [API] generalize list header (#16551) 2021-08-12 14:43:08 +02:00
DCO
Dockerfile chmod executables when copying to the docker (#17423) 2021-10-25 20:32:03 +02:00
Dockerfile.rootless Fix docker rootless build (#17441) 2021-10-26 17:21:01 +01:00
go.mod Simplify Gothic to use our session store instead of creating a different store (#17507) 2021-11-03 08:33:54 +08:00
go.sum Simplify Gothic to use our session store instead of creating a different store (#17507) 2021-11-03 08:33:54 +08:00
jest.config.js Add copy button to markdown code blocks (#17638) 2021-11-16 16:16:05 +08:00
LICENSE
main.go Dump github/gitlab/gitea repository data to a local directory and restore to gitea (#12244) 2020-12-27 11:34:19 +08:00
MAINTAINERS Remove me from the maintainers (#17599) 2021-11-09 22:40:16 +08:00
Makefile Rename .air.conf to .air.toml (#17360) 2021-10-20 00:27:29 +08:00
package-lock.json Add copy button to markdown code blocks (#17638) 2021-11-16 16:16:05 +08:00
package.json Add copy button to markdown code blocks (#17638) 2021-11-16 16:16:05 +08:00
README_ZH.md Fix report card link (#16885) 2021-08-31 01:06:30 +02:00
README.md Fix report card link (#16885) 2021-08-31 01:06:30 +02:00
SECURITY.md Add security policy to repo (#12536) 2020-08-19 17:15:55 +01:00
webpack.config.js Update JS dependencies (#17357) 2021-10-19 15:23:58 +08:00

Gitea

Gitea - Git with a cup of tea

View the chinese version of this document

Purpose

The goal of this project is to make the easiest, fastest, and most painless way of setting up a self-hosted Git service. Using Go, this can be done with an independent binary distribution across all platforms which Go supports, including Linux, macOS, and Windows on x86, amd64, ARM and PowerPC architectures. Want to try it before doing anything else? Do it with the online demo! This project has been forked from Gogs since 2016.11 but changed a lot.

Building

From the root of the source tree, run:

TAGS="bindata" make build

or if sqlite support is required:

TAGS="bindata sqlite sqlite_unlock_notify" make build

The build target is split into two sub-targets:

  • make backend which requires Go 1.16 or greater.
  • make frontend which requires Node.js 12.17 or greater and Internet connectivity to download npm dependencies.

When building from the official source tarballs which include pre-built frontend files, the frontend target will not be triggered, making it possible to build without Node.js and Internet connectivity.

Parallelism (make -j <num>) is not supported.

More info: https://docs.gitea.io/en-us/install-from-source/

Using

./gitea web

NOTE: If you're interested in using our APIs, we have experimental support with documentation.

Contributing

Expected workflow is: Fork -> Patch -> Push -> Pull Request

NOTES:

  1. YOU MUST READ THE CONTRIBUTORS GUIDE BEFORE STARTING TO WORK ON A PULL REQUEST.
  2. If you have found a vulnerability in the project, please write privately to security@gitea.io. Thanks!

Translating

Translations are done through Crowdin. If you want to translate to a new language ask one of the managers in the Crowdin project to add a new language there.

You can also just create an issue for adding a language or ask on discord on the #translation channel. If you need context or find some translation issues, you can leave a comment on the string or ask on Discord. For general translation questions there is a section in the docs. Currently a bit empty but we hope fo fill it as questions pop up.

https://docs.gitea.io/en-us/translation-guidelines/

Crowdin

Further information

For more information and instructions about how to install Gitea, please look at our documentation. If you have questions that are not covered by the documentation, you can get in contact with us on our Discord server or create a post in the discourse forum.

We maintain a list of Gitea-related projects at gitea/awesome-gitea.
The hugo-based documentation theme is hosted at gitea/theme.
The official Gitea CLI is developed at gitea/tea.

Authors

Backers

Thank you to all our backers! 🙏 [Become a backer]

Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]

FAQ

How do you pronounce Gitea?

Gitea is pronounced /ɡɪti:/ as in "gi-tea" with a hard g.

Why is this not hosted on a Gitea instance?

We're working on it.

License

This project is licensed under the MIT License. See the LICENSE file for the full license text.

Screenshots

Looking for an overview of the interface? Check it out!

Dashboard User Profile Global Issues
Branches Web Editor Activity
New Migration Migrating Pull Request View
Pull Request Dark Diff Review Dark Diff Dark