Commit 19d2d23 (gitweb: add project_filter to limit project list to a subdirectory, 2012-01-30) added also support for displaying $project_filter, if present, in page title. Unfortunately it forgot to treat $project_filter as path, and escape it using esc_path(), like it is done for $filename. Also, it was not obvious that "$site_name - $project_filter" is about project filtering: use "$site_name - projects in '$project_filter'". Signed-off-by: Jakub Narebski <jnareb@xxxxxxxxx> --- Though we should probably also esc_path($project), not only to_utf8($project) in get_page_title() subroutine. So I am not that sure if it is really necessary, or if I should follow it by further hardening of get_page_title(). Anyway I have noticed this when I was examining gitweb code for generating page title, considering adding information about search for project search. So this is patch I will be depending textually via context lines on. gitweb/gitweb.perl | 2 +- 1 files changed, 1 insertions(+), 1 deletions(-) diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl index 081ac45..8ba2022 100755 --- a/gitweb/gitweb.perl +++ b/gitweb/gitweb.perl @@ -3751,7 +3751,7 @@ sub get_page_title { unless (defined $project) { if (defined $project_filter) { - $title .= " - " . to_utf8($project_filter); + $title .= " - projects in '" . esc_path($project_filter) . "'"; } return $title; } -- 1.7.9 -- To unsubscribe from this list: send the line "unsubscribe git" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html