.hgignore
author Jonas Schäfer <jonas@wielicki.name>
Mon, 10 Jan 2022 18:23:54 +0100
branch0.11
changeset 12185 783056b4e448
parent 8348 850c433eb862
permissions -rw-r--r--
util.xml: Do not allow doctypes, comments or processing instructions Yes. This is as bad as it sounds. CVE pending. In Prosody itself, this only affects mod_websocket, which uses util.xml to parse the <open/> frame, thus allowing unauthenticated remote DoS using Billion Laughs. However, third-party modules using util.xml may also be affected by this. This commit installs handlers which disallow the use of doctype declarations and processing instructions without any escape hatch. It, by default, also introduces such a handler for comments, however, there is a way to enable comments nontheless. This is because util.xml is used to parse human-facing data, where comments are generally a desirable feature, and also because comments are generally harmless.
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
1296
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
     1
syntax: glob
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
     2
.hgignore
7773
f0024972489e hgignore: Ignore luacheck cache file
Kim Alvefur <zash@zash.se>
parents: 3636
diff changeset
     3
.luacheckcache
1296
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
     4
data
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
     5
local
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
     6
www_files
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
     7
html/*
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
     8
prosody.lua
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
     9
prosody.cfg.lua
2905
b924d915c4d0 .hgignore: Ignore prosody.version (thanks Florob)
Matthew Wild <mwild1@gmail.com>
parents: 1296
diff changeset
    10
prosody.version
1296
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    11
config.unix
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    12
*.patch
3636
88e4397e39a9 .hgignore: Ignore *.diff.
Waqas Hussain <waqas20@gmail.com>
parents: 3635
diff changeset
    13
*.diff
1296
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    14
*.orig
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    15
*.rej
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    16
*.save
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    17
*~
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    18
*.o
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    19
*.so
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    20
*.install
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    21
*.pid
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    22
*.log
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    23
*.err
5cf4c444d3f9 Adding .hgignore
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
    24
*.debug
3635
72f3619eeabd .hgignore: Ignore Windows compilation artifacts.
Waqas Hussain <waqas20@gmail.com>
parents: 2905
diff changeset
    25
*.dll
72f3619eeabd .hgignore: Ignore Windows compilation artifacts.
Waqas Hussain <waqas20@gmail.com>
parents: 2905
diff changeset
    26
*.exp
72f3619eeabd .hgignore: Ignore Windows compilation artifacts.
Waqas Hussain <waqas20@gmail.com>
parents: 2905
diff changeset
    27
*.lib
72f3619eeabd .hgignore: Ignore Windows compilation artifacts.
Waqas Hussain <waqas20@gmail.com>
parents: 2905
diff changeset
    28
*.obj
8247
6a27e5f276f7 .hgignore: Add luacov.report.out, luacov.report.out.index and luacov.stats.out
Waqas Hussain <waqas20@gmail.com>
parents: 7773
diff changeset
    29
luacov.report.out
6a27e5f276f7 .hgignore: Add luacov.report.out, luacov.report.out.index and luacov.stats.out
Waqas Hussain <waqas20@gmail.com>
parents: 7773
diff changeset
    30
luacov.report.out.index
6a27e5f276f7 .hgignore: Add luacov.report.out, luacov.report.out.index and luacov.stats.out
Waqas Hussain <waqas20@gmail.com>
parents: 7773
diff changeset
    31
luacov.stats.out