Diffstat (limited to 'filters')
| -rwxr-xr-x | filters/ci-jenkins.sh | 58 | ||||
| -rwxr-xr-x | filters/commit-links.sh | 2 | ||||
| -rw-r--r-- | filters/email-gravatar.lua | 17 | ||||
| -rw-r--r-- | filters/email-libravatar.lua | 17 | ||||
| -rw-r--r-- | filters/file-authentication.lua | 31 | ||||
| -rw-r--r-- | filters/gentoo-ldap-authentication.lua | 31 | ||||
| -rwxr-xr-x | filters/html-converters/md2html | 104 | ||||
| -rw-r--r-- | filters/simple-authentication.lua | 31 | ||||
| -rwxr-xr-x | filters/syntax-highlighting.py | 45 | ||||
| -rwxr-xr-x | filters/syntax-highlighting.sh | 14 |
10 files changed, 80 insertions, 270 deletions
diff --git a/filters/ci-jenkins.sh b/filters/ci-jenkins.sh deleted file mode 100755 index 842af21..0000000 --- a/filters/ci-jenkins.sh +++ /dev/null @@ -1,58 +0,0 @@ -#!/bin/sh -# This script may be used with the ci-filter or repo.ci-filter setting in -# cgitrc to hide the "ci" tab for refs which have no pipeline on a Jenkins -# instance. -# -# Arguments: -# $1 the name of the branch or tag being viewed -# $2 "branch" or "tag" -# $3 the ci url which the "ci" tab would redirect to -# -# Exit with a zero status to show the tab, non-zero to hide it. This script -# must not write anything to standard output, as that would end up in the -# middle of the page cgit is rendering. -# -# The filter is consulted while rendering every repository page, so the -# verdict is cached on disk to keep Jenkins from being hammered, and the -# probe is given a short timeout so that an unreachable Jenkins degrades -# into a missing tab rather than a hanging web server. -# -# Set CI_NETRC to a netrc(5) file if the Jenkins instance requires -# authentication; without it a private job answers 403 and the tab is -# hidden even though the pipeline exists. - -CI_CACHE_DIR="${CI_CACHE_DIR:-/var/cache/cgit/ci-filter}" -CI_CACHE_TTL_MINUTES="${CI_CACHE_TTL_MINUTES:-5}" -CI_TIMEOUT="${CI_TIMEOUT:-2}" - -url="$3" -test -n "$url" || exit 1 - -# Jenkins job pages are often not readable anonymously, so query the REST -# API rather than the page the tab points at. -probe="$url/api/json?tree=name" - -key="$(printf '%s' "$url" | cksum | tr -cd '0-9')" -cache="$CI_CACHE_DIR/$key" - -mkdir -p "$CI_CACHE_DIR" 2>/dev/null - -if test -f "$cache" && - test -z "$(find "$cache" -mmin "+$CI_CACHE_TTL_MINUTES" 2>/dev/null)" -then - exit "$(cat "$cache")" -fi - -status=0 -curl --silent --fail --head --output /dev/null \ - --max-time "$CI_TIMEOUT" \ - ${CI_NETRC:+--netrc-file "$CI_NETRC"} \ - "$probe" >/dev/null 2>&1 || status=1 - -if test -d "$CI_CACHE_DIR" -then - printf '%s\n' "$status" >"$cache.$$" 2>/dev/null && - mv "$cache.$$" "$cache" 2>/dev/null -fi - -exit "$status" diff --git a/filters/commit-links.sh b/filters/commit-links.sh index 796ac30..5881952 100755 --- a/filters/commit-links.sh +++ b/filters/commit-links.sh @@ -19,7 +19,7 @@ regex='' # This expression generates links to commits referenced by their SHA1. regex=$regex' -s|\b([0-9a-fA-F]{7,64})\b|<a href="./?id=\1">\1</a>|g' +s|\b([0-9a-fA-F]{7,40})\b|<a href="./?id=\1">\1</a>|g' # This expression generates links to a fictional bugtracker. regex=$regex' diff --git a/filters/email-gravatar.lua b/filters/email-gravatar.lua index c39b490..52cf426 100644 --- a/filters/email-gravatar.lua +++ b/filters/email-gravatar.lua @@ -3,24 +3,15 @@ -- prefix in filters. It is much faster than the corresponding python script. -- -- Requirements: --- luaossl --- <http://25thandclement.com/~william/projects/luaossl.html> +-- luacrypto >= 0.3 +-- <http://mkottman.github.io/luacrypto/> -- -local digest = require("openssl.digest") - -function md5_hex(input) - local b = digest.new("md5"):final(input) - local x = "" - for i = 1, #b do - x = x .. string.format("%.2x", string.byte(b, i)) - end - return x -end +local crypto = require("crypto") function filter_open(email, page) buffer = "" - md5 = md5_hex(email:sub(2, -2):lower()) + md5 = crypto.digest("md5", email:sub(2, -2):lower()) end function filter_close() diff --git a/filters/email-libravatar.lua b/filters/email-libravatar.lua index 7336baf..b0e2447 100644 --- a/filters/email-libravatar.lua +++ b/filters/email-libravatar.lua @@ -3,24 +3,15 @@ -- prefix in filters. -- -- Requirements: --- luaossl --- <http://25thandclement.com/~william/projects/luaossl.html> +-- luacrypto >= 0.3 +-- <http://mkottman.github.io/luacrypto/> -- -local digest = require("openssl.digest") - -function md5_hex(input) - local b = digest.new("md5"):final(input) - local x = "" - for i = 1, #b do - x = x .. string.format("%.2x", string.byte(b, i)) - end - return x -end +local crypto = require("crypto") function filter_open(email, page) buffer = "" - md5 = md5_hex(email:sub(2, -2):lower()) + md5 = crypto.digest("md5", email:sub(2, -2):lower()) end function filter_close() diff --git a/filters/file-authentication.lua b/filters/file-authentication.lua index 0248804..6ee1e19 100644 --- a/filters/file-authentication.lua +++ b/filters/file-authentication.lua @@ -1,15 +1,15 @@ -- This script may be used with the auth-filter. -- -- Requirements: --- luaossl --- <http://25thandclement.com/~william/projects/luaossl.html> +-- luacrypto >= 0.3 +-- <http://mkottman.github.io/luacrypto/> -- luaposix -- <https://github.com/luaposix/luaposix> -- local sysstat = require("posix.sys.stat") local unistd = require("posix.unistd") -local rand = require("openssl.rand") -local hmac = require("openssl.hmac") +local crypto = require("crypto") + -- This file should contain a series of lines in the form of: -- username1:hash1 @@ -225,13 +225,6 @@ function get_cookie(cookies, name) return url_decode(string.match(cookies, ";" .. name .. "=(.-);")) end -function tohex(b) - local x = "" - for i = 1, #b do - x = x .. string.format("%.2x", string.byte(b, i)) - end - return x -end -- -- @@ -249,12 +242,12 @@ function get_secret() local secret_file = io.open(secret_filename, "r") if secret_file == nil then local old_umask = sysstat.umask(63) - local temporary_filename = secret_filename .. ".tmp." .. tohex(rand.bytes(16)) + local temporary_filename = secret_filename .. ".tmp." .. crypto.hex(crypto.rand.bytes(16)) local temporary_file = io.open(temporary_filename, "w") if temporary_file == nil then os.exit(177) end - temporary_file:write(tohex(rand.bytes(32))) + temporary_file:write(crypto.hex(crypto.rand.bytes(32))) temporary_file:close() unistd.link(temporary_filename, secret_filename) -- Intentionally fails in the case that another process is doing the same. unistd.unlink(temporary_filename) @@ -279,7 +272,7 @@ function validate_value(expected_field, cookie) local field = "" local expiration = 0 local salt = "" - local chmac = "" + local hmac = "" if cookie == nil or cookie:len() < 3 or cookie:sub(1, 1) == "|" then return nil @@ -298,19 +291,19 @@ function validate_value(expected_field, cookie) elseif i == 3 then salt = component elseif i == 4 then - chmac = component + hmac = component else break end i = i + 1 end - if chmac == nil or chmac:len() == 0 then + if hmac == nil or hmac:len() == 0 then return nil end -- Lua hashes strings, so these comparisons are time invariant. - if chmac ~= tohex(hmac.new(get_secret(), "sha256"):final(field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt)) then + if hmac ~= crypto.hmac.digest("sha256", field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt, get_secret()) then return nil end @@ -331,11 +324,11 @@ function secure_value(field, value, expiration) end local authstr = "" - local salt = tohex(rand.bytes(16)) + local salt = crypto.hex(crypto.rand.bytes(16)) value = url_encode(value) field = url_encode(field) authstr = field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt - authstr = authstr .. "|" .. tohex(hmac.new(get_secret(), "sha256"):final(authstr)) + authstr = authstr .. "|" .. crypto.hmac.digest("sha256", authstr, get_secret()) return authstr end diff --git a/filters/gentoo-ldap-authentication.lua b/filters/gentoo-ldap-authentication.lua index 673c88d..b4d98c2 100644 --- a/filters/gentoo-ldap-authentication.lua +++ b/filters/gentoo-ldap-authentication.lua @@ -1,8 +1,8 @@ -- This script may be used with the auth-filter. Be sure to configure it as you wish. -- -- Requirements: --- luaossl --- <http://25thandclement.com/~william/projects/luaossl.html> +-- luacrypto >= 0.3 +-- <http://mkottman.github.io/luacrypto/> -- lualdap >= 1.2 -- <https://git.zx2c4.com/lualdap/about/> -- luaposix @@ -10,9 +10,9 @@ -- local sysstat = require("posix.sys.stat") local unistd = require("posix.unistd") +local crypto = require("crypto") local lualdap = require("lualdap") -local rand = require("openssl.rand") -local hmac = require("openssl.hmac") + -- -- @@ -226,13 +226,6 @@ function get_cookie(cookies, name) return string.match(cookies, ";" .. name .. "=(.-);") end -function tohex(b) - local x = "" - for i = 1, #b do - x = x .. string.format("%.2x", string.byte(b, i)) - end - return x -end -- -- @@ -250,12 +243,12 @@ function get_secret() local secret_file = io.open(secret_filename, "r") if secret_file == nil then local old_umask = sysstat.umask(63) - local temporary_filename = secret_filename .. ".tmp." .. tohex(rand.bytes(16)) + local temporary_filename = secret_filename .. ".tmp." .. crypto.hex(crypto.rand.bytes(16)) local temporary_file = io.open(temporary_filename, "w") if temporary_file == nil then os.exit(177) end - temporary_file:write(tohex(rand.bytes(32))) + temporary_file:write(crypto.hex(crypto.rand.bytes(32))) temporary_file:close() unistd.link(temporary_filename, secret_filename) -- Intentionally fails in the case that another process is doing the same. unistd.unlink(temporary_filename) @@ -280,7 +273,7 @@ function validate_value(expected_field, cookie) local field = "" local expiration = 0 local salt = "" - local chmac = "" + local hmac = "" if cookie == nil or cookie:len() < 3 or cookie:sub(1, 1) == "|" then return nil @@ -299,19 +292,19 @@ function validate_value(expected_field, cookie) elseif i == 3 then salt = component elseif i == 4 then - chmac = component + hmac = component else break end i = i + 1 end - if chmac == nil or chmac:len() == 0 then + if hmac == nil or hmac:len() == 0 then return nil end -- Lua hashes strings, so these comparisons are time invariant. - if chmac ~= tohex(hmac.new(get_secret(), "sha256"):final(field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt)) then + if hmac ~= crypto.hmac.digest("sha256", field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt, get_secret()) then return nil end @@ -332,11 +325,11 @@ function secure_value(field, value, expiration) end local authstr = "" - local salt = tohex(rand.bytes(16)) + local salt = crypto.hex(crypto.rand.bytes(16)) value = url_encode(value) field = url_encode(field) authstr = field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt - authstr = authstr .. "|" .. tohex(hmac.new(get_secret(), "sha256"):final(authstr)) + authstr = authstr .. "|" .. crypto.hmac.digest("sha256", authstr, get_secret()) return authstr end diff --git a/filters/html-converters/md2html b/filters/html-converters/md2html index 4f6ad37..ebf3856 100755 --- a/filters/html-converters/md2html +++ b/filters/html-converters/md2html @@ -2,46 +2,7 @@ import markdown import sys import io -from markdown.extensions.toc import TocExtension - -# Pygments' token classes, mapped onto the --syn-* custom properties that -# cgit.css defines. The fallbacks are the palette those properties default to, -# so that the output stays readable under a stylesheet without them. -SYNTAX_COLORS = ( - (('k', 'kc', 'kd', 'kn', 'kr'), '--syn-keyword', '#000', - 'font-weight: bold'), - (('kp',), '--syn-keyword', '#000', None), - (('kt',), '--syn-type', '#010181', None), - (('nc', 'nf', 'nn', 'ne'), '--syn-keyword-alt', '#0057ae', None), - (('s', 'sa', 'sb', 'sc', 'dl', 'sd', 's2', 'sh', 'sx', 'sr', 's1', 'ss'), - '--syn-string', '#bf0303', None), - (('se',), '--syn-escape', '#f0f', None), - (('si',), '--syn-interpolation', '#0057ae', None), - (('c', 'ch', 'cm', 'c1', 'cs'), '--syn-comment', '#838183', - 'font-style: italic'), - (('cp', 'cpf'), '--syn-preproc', '#008200', None), - (('m', 'mb', 'mf', 'mh', 'mi', 'mo', 'il'), '--syn-number', '#b07e00', - None), - (('o', 'ow', 'p'), '--syn-operator', '#000', None), - (('err',), '--syn-error', '#bf0303', None), - (('gd',), '--red', 'red', None), - (('gi',), '--green', 'green', None), - (('lineno', 'linenos'), '--syn-linenum', '#555', None), -) - - -def style_defs(prefix='.highlight'): - rules = [] - for classes, prop, fallback, extra in SYNTAX_COLORS: - selector = ', '.join('%s .%s' % (prefix, c) for c in classes) - decls = 'color: var(%s, %s)' % (prop, fallback) - if extra: - decls += '; ' + extra - rules.append('%s { %s }' % (selector, decls)) - rules.append('%s .hll { background-color: var(--syn-mark-bg, #ffb) }' - % prefix) - return '\n'.join(rules) + '\n' - +from pygments.formatters import HtmlFormatter sys.stdin = io.TextIOWrapper(sys.stdin.buffer, encoding='utf-8') sys.stdout = io.TextIOWrapper(sys.stdout.buffer, encoding='utf-8') sys.stdout.write(''' @@ -58,7 +19,7 @@ sys.stdout.write(''' margin-bottom: 0 !important; } .markdown-body a.absent { - color: var(--red-mid, #c00); + color: #c00; } .markdown-body a.anchor { display: block; @@ -80,32 +41,28 @@ sys.stdout.write(''' } .markdown-body h1 .mini-icon-link, .markdown-body h2 .mini-icon-link, .markdown-body h3 .mini-icon-link, .markdown-body h4 .mini-icon-link, .markdown-body h5 .mini-icon-link, .markdown-body h6 .mini-icon-link { display: none; - color: var(--fg-strong, #000); + color: #000; } .markdown-body h1:hover a.anchor, .markdown-body h2:hover a.anchor, .markdown-body h3:hover a.anchor, .markdown-body h4:hover a.anchor, .markdown-body h5:hover a.anchor, .markdown-body h6:hover a.anchor { text-decoration: none; line-height: 1; padding-left: 0; margin-left: -22px; - top: 15%; -} + top: 15%} .markdown-body h1:hover a.anchor .mini-icon-link, .markdown-body h2:hover a.anchor .mini-icon-link, .markdown-body h3:hover a.anchor .mini-icon-link, .markdown-body h4:hover a.anchor .mini-icon-link, .markdown-body h5:hover a.anchor .mini-icon-link, .markdown-body h6:hover a.anchor .mini-icon-link { display: inline-block; } -div#cgit .markdown-body h1 a.toclink, div#cgit .markdown-body h2 a.toclink, div#cgit .markdown-body h3 a.toclink, div#cgit .markdown-body h4 a.toclink, div#cgit .markdown-body h5 a.toclink, div#cgit .markdown-body h6 a.toclink { - color: var(--fg-strong, #000); -} .markdown-body h1 tt, .markdown-body h1 code, .markdown-body h2 tt, .markdown-body h2 code, .markdown-body h3 tt, .markdown-body h3 code, .markdown-body h4 tt, .markdown-body h4 code, .markdown-body h5 tt, .markdown-body h5 code, .markdown-body h6 tt, .markdown-body h6 code { font-size: inherit; } .markdown-body h1 { font-size: 28px; - color: var(--fg-strong, #000); + color: #000; } .markdown-body h2 { font-size: 24px; - border-bottom: 1px solid var(--border, #ccc); - color: var(--fg-strong, #000); + border-bottom: 1px solid #ccc; + color: #000; } .markdown-body h3 { font-size: 18px; @@ -117,14 +74,18 @@ div#cgit .markdown-body h1 a.toclink, div#cgit .markdown-body h2 a.toclink, div# font-size: 14px; } .markdown-body h6 { - color: var(--fg-mute, #777); + color: #777; font-size: 14px; } .markdown-body p, .markdown-body blockquote, .markdown-body ul, .markdown-body ol, .markdown-body dl, .markdown-body table, .markdown-body pre { margin: 15px 0; } .markdown-body hr { - border: 2px solid var(--border, #ccc); + background: transparent url("/dirty-shade.png") repeat-x 0 0; + border: 0 none; + color: #ccc; + height: 4px; + padding: 0; } .markdown-body>h2:first-child, .markdown-body>h1:first-child, .markdown-body>h1:first-child+h2, .markdown-body>h3:first-child, .markdown-body>h4:first-child, .markdown-body>h5:first-child, .markdown-body>h6:first-child { margin-top: 0; @@ -186,9 +147,9 @@ div#cgit .markdown-body h1 a.toclink, div#cgit .markdown-body h2 a.toclink, div# margin-bottom: 0px; } .markdown-body blockquote { - border-left: 4px solid var(--border, #ddd); + border-left: 4px solid #DDD; padding: 0 15px; - color: var(--fg-mute, #777); + color: #777; } .markdown-body blockquote>:first-child { margin-top: 0px; @@ -200,15 +161,15 @@ div#cgit .markdown-body h1 a.toclink, div#cgit .markdown-body h2 a.toclink, div# font-weight: bold; } .markdown-body table th, .markdown-body table td { - border: 1px solid var(--border, #ccc); + border: 1px solid #ccc; padding: 6px 13px; } .markdown-body table tr { - border-top: 1px solid var(--border, #ccc); - background-color: var(--bg, #fff); + border-top: 1px solid #ccc; + background-color: #fff; } .markdown-body table tr:nth-child(2n) { - background-color: var(--bg-zebra, #f8f8f8); + background-color: #f8f8f8; } .markdown-body img { max-width: 100%; @@ -220,7 +181,7 @@ div#cgit .markdown-body h1 a.toclink, div#cgit .markdown-body h2 a.toclink, div# overflow: hidden; } .markdown-body span.frame>span { - border: 1px solid var(--border, #ddd); + border: 1px solid #ddd; display: block; float: left; overflow: hidden; @@ -234,7 +195,7 @@ div#cgit .markdown-body h1 a.toclink, div#cgit .markdown-body h2 a.toclink, div# } .markdown-body span.frame span span { clear: both; - color: var(--fg, #333); + color: #333; display: block; padding: 5px 0 0; } @@ -292,8 +253,8 @@ div#cgit .markdown-body h1 a.toclink, div#cgit .markdown-body h2 a.toclink, div# .markdown-body code, .markdown-body tt { margin: 0 2px; padding: 0px 5px; - border: 1px solid var(--border, #eaeaea); - background-color: var(--bg-zebra, #f8f8f8); + border: 1px solid #eaeaea; + background-color: #f8f8f8; border-radius: 3px; } .markdown-body code { @@ -307,8 +268,8 @@ div#cgit .markdown-body h1 a.toclink, div#cgit .markdown-body h2 a.toclink, div# background: transparent; } .markdown-body .highlight pre, .markdown-body pre { - background-color: var(--bg-zebra, #f8f8f8); - border: 1px solid var(--border, #ccc); + background-color: #f8f8f8; + border: 1px solid #ccc; font-size: 13px; line-height: 19px; overflow: auto; @@ -322,21 +283,12 @@ div#cgit .markdown-body h1 a.toclink, div#cgit .markdown-body h2 a.toclink, div# border: none; } ''') -sys.stdout.write(style_defs('.highlight')) +sys.stdout.write(HtmlFormatter(style='pastie').get_style_defs('.highlight')) sys.stdout.write(''' -</style> +</style> ''') sys.stdout.write("<div class='markdown-body'>") sys.stdout.flush() # Note: you may want to run this through bleach for sanitization -markdown.markdownFromFile( - output_format="html5", - extensions=[ - "markdown.extensions.fenced_code", - "markdown.extensions.codehilite", - "markdown.extensions.tables", - "markdown.extensions.sane_lists", - TocExtension(anchorlink=True)], - extension_configs={ - "markdown.extensions.codehilite":{"css_class":"highlight"}}) +markdown.markdownFromFile(output_format="html5", extensions=["markdown.extensions.fenced_code", "markdown.extensions.codehilite", "markdown.extensions.tables"], extension_configs={"markdown.extensions.codehilite":{"css_class":"highlight"}}) sys.stdout.write("</div>") diff --git a/filters/simple-authentication.lua b/filters/simple-authentication.lua index 23d3457..77d1fd0 100644 --- a/filters/simple-authentication.lua +++ b/filters/simple-authentication.lua @@ -1,15 +1,15 @@ -- This script may be used with the auth-filter. Be sure to configure it as you wish. -- -- Requirements: --- luaossl --- <http://25thandclement.com/~william/projects/luaossl.html> +-- luacrypto >= 0.3 +-- <http://mkottman.github.io/luacrypto/> -- luaposix -- <https://github.com/luaposix/luaposix> -- local sysstat = require("posix.sys.stat") local unistd = require("posix.unistd") -local rand = require("openssl.rand") -local hmac = require("openssl.hmac") +local crypto = require("crypto") + -- -- @@ -180,13 +180,6 @@ function get_cookie(cookies, name) return url_decode(string.match(cookies, ";" .. name .. "=(.-);")) end -function tohex(b) - local x = "" - for i = 1, #b do - x = x .. string.format("%.2x", string.byte(b, i)) - end - return x -end -- -- @@ -204,12 +197,12 @@ function get_secret() local secret_file = io.open(secret_filename, "r") if secret_file == nil then local old_umask = sysstat.umask(63) - local temporary_filename = secret_filename .. ".tmp." .. tohex(rand.bytes(16)) + local temporary_filename = secret_filename .. ".tmp." .. crypto.hex(crypto.rand.bytes(16)) local temporary_file = io.open(temporary_filename, "w") if temporary_file == nil then os.exit(177) end - temporary_file:write(tohex(rand.bytes(32))) + temporary_file:write(crypto.hex(crypto.rand.bytes(32))) temporary_file:close() unistd.link(temporary_filename, secret_filename) -- Intentionally fails in the case that another process is doing the same. unistd.unlink(temporary_filename) @@ -234,7 +227,7 @@ function validate_value(expected_field, cookie) local field = "" local expiration = 0 local salt = "" - local chmac = "" + local hmac = "" if cookie == nil or cookie:len() < 3 or cookie:sub(1, 1) == "|" then return nil @@ -253,19 +246,19 @@ function validate_value(expected_field, cookie) elseif i == 3 then salt = component elseif i == 4 then - chmac = component + hmac = component else break end i = i + 1 end - if chmac == nil or chmac:len() == 0 then + if hmac == nil or hmac:len() == 0 then return nil end -- Lua hashes strings, so these comparisons are time invariant. - if chmac ~= tohex(hmac.new(get_secret(), "sha256"):final(field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt)) then + if hmac ~= crypto.hmac.digest("sha256", field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt, get_secret()) then return nil end @@ -286,11 +279,11 @@ function secure_value(field, value, expiration) end local authstr = "" - local salt = tohex(rand.bytes(16)) + local salt = crypto.hex(crypto.rand.bytes(16)) value = url_encode(value) field = url_encode(field) authstr = field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt - authstr = authstr .. "|" .. tohex(hmac.new(get_secret(), "sha256"):final(authstr)) + authstr = authstr .. "|" .. crypto.hmac.digest("sha256", authstr, get_secret()) return authstr end diff --git a/filters/syntax-highlighting.py b/filters/syntax-highlighting.py index d757e2d..e912594 100755 --- a/filters/syntax-highlighting.py +++ b/filters/syntax-highlighting.py @@ -30,50 +30,11 @@ from pygments.lexers import guess_lexer_for_filename from pygments.formatters import HtmlFormatter -# Pygments' token classes, mapped onto the --syn-* custom properties that -# cgit.css defines. The fallbacks are the palette those properties default to, -# so that the output stays readable under a stylesheet without them. -SYNTAX_COLORS = ( - (('k', 'kc', 'kd', 'kn', 'kr'), '--syn-keyword', '#000', - 'font-weight: bold'), - (('kp',), '--syn-keyword', '#000', None), - (('kt',), '--syn-type', '#010181', None), - (('nc', 'nf', 'nn', 'ne'), '--syn-keyword-alt', '#0057ae', None), - (('s', 'sa', 'sb', 'sc', 'dl', 'sd', 's2', 'sh', 'sx', 'sr', 's1', 'ss'), - '--syn-string', '#bf0303', None), - (('se',), '--syn-escape', '#f0f', None), - (('si',), '--syn-interpolation', '#0057ae', None), - (('c', 'ch', 'cm', 'c1', 'cs'), '--syn-comment', '#838183', - 'font-style: italic'), - (('cp', 'cpf'), '--syn-preproc', '#008200', None), - (('m', 'mb', 'mf', 'mh', 'mi', 'mo', 'il'), '--syn-number', '#b07e00', - None), - (('o', 'ow', 'p'), '--syn-operator', '#000', None), - (('err',), '--syn-error', '#bf0303', None), - (('gd',), '--red', 'red', None), - (('gi',), '--green', 'green', None), - (('lineno', 'linenos'), '--syn-linenum', '#555', None), -) - - -def style_defs(prefix='.highlight'): - rules = [] - for classes, prop, fallback, extra in SYNTAX_COLORS: - selector = ', '.join('%s .%s' % (prefix, c) for c in classes) - decls = 'color: var(%s, %s)' % (prop, fallback) - if extra: - decls += '; ' + extra - rules.append('%s { %s }' % (selector, decls)) - rules.append('%s .hll { background-color: var(--syn-mark-bg, #ffb) }' - % prefix) - return '\n'.join(rules) + '\n' - - sys.stdin = io.TextIOWrapper(sys.stdin.buffer, encoding='utf-8', errors='replace') sys.stdout = io.TextIOWrapper(sys.stdout.buffer, encoding='utf-8', errors='replace') data = sys.stdin.read() filename = sys.argv[1] -formatter = HtmlFormatter(nobackground=True) +formatter = HtmlFormatter(style='pastie', nobackground=True) try: lexer = guess_lexer_for_filename(filename, data) @@ -87,8 +48,8 @@ except TypeError: lexer = TextLexer() # highlight! :-) -# printout the css definitions for pygments' token classes as well +# printout pygments' css definitions as well sys.stdout.write('<style>') -sys.stdout.write(style_defs('.highlight')) +sys.stdout.write(formatter.get_style_defs('.highlight')) sys.stdout.write('</style>') sys.stdout.write(highlight(data, lexer, formatter, outfile=None)) diff --git a/filters/syntax-highlighting.sh b/filters/syntax-highlighting.sh index bb8d60c..840bc34 100755 --- a/filters/syntax-highlighting.sh +++ b/filters/syntax-highlighting.sh @@ -8,10 +8,8 @@ # might have to use an external call to sed instead. # # Note: the highlight command (http://www.andre-simon.de/) uses css for syntax -# highlighting. cgit.css defines these classes in terms of its --syn-* custom -# properties, so nothing has to be added when using the default stylesheet. -# The palette below, from highlight 3.13, is what those properties default to; -# a custom stylesheet wanting the same colors can use it directly: +# highlighting, so you'll probably want something like the following included +# in your css file: # # Style definition file generated by highlight 2.4.8, http://www.andre-simon.de/ # @@ -116,12 +114,8 @@ EXTENSION="${BASENAME##*.}" # Version 2 can be found (for example) on EPEL 5, while version 3 can be # found (for example) on EPEL 6. # -# Note that -I (--include-style) is not used: the stylesheet it embeds in the -# output would override the .hl rules in cgit.css and with them any theming -# done through the --syn-* custom properties. -# # This is for version 2 -exec highlight --force -f -X -S "$EXTENSION" 2>/dev/null +exec highlight --force -f -I -X -S "$EXTENSION" 2>/dev/null # This is for version 3 -#exec highlight --force -f -O xhtml -S "$EXTENSION" 2>/dev/null +#exec highlight --force -f -I -O xhtml -S "$EXTENSION" 2>/dev/null |