d243dce027
- Replaced manual remote client functions with remote_client! macro for archive, blame, branch, commit, and diff services - Simplified remote client creation logic using declarative macro approach - Maintained same functionality while reducing code duplication across services security(bare): enhance path traversal protection with comprehensive validation - Added early relative_path validation to prevent path traversal attacks - Implemented unified path validation to avoid TOCTOU race conditions - Enhanced canonicalization checks for both existing and non-existent paths - Added detailed logging for path traversal detection attempts feat(cache): migrate from CLruCache to Moka with TTL and invalidation support - Replaced clru dependency with moka for improved caching capabilities - Added 300-second time-to-live for cache entries - Implemented repository-specific cache invalidation mechanism - Enhanced cache operations with thread-safe async support refactor(commit): improve security validation for commit operations - Added ref name validation to prevent command injection in cherry_pick_commit - Implemented revision validation for commit selectors - Added comprehensive input validation for create_commit parameters - Enhanced file path validation to prevent traversal
76 lines
2.6 KiB
Rust
76 lines
2.6 KiB
Rust
use crate::bare::GitBare;
|
|
use crate::error::{GitError, GitResult};
|
|
use crate::paginate;
|
|
use crate::pb::{ListMergeConflictsRequest, ListMergeConflictsResponse, MergeConflict};
|
|
|
|
impl GitBare {
|
|
pub fn list_merge_conflicts(
|
|
&self,
|
|
request: ListMergeConflictsRequest,
|
|
) -> GitResult<ListMergeConflictsResponse> {
|
|
let target = match request.target.and_then(|s| s.selector) {
|
|
Some(crate::pb::object_selector::Selector::Oid(oid)) => oid.hex,
|
|
Some(crate::pb::object_selector::Selector::Revision(name)) => {
|
|
crate::sanitize::validate_revision(&name.revision)?;
|
|
name.revision
|
|
}
|
|
None => return Err(GitError::InvalidArgument("target is required".into())),
|
|
};
|
|
let source = match request.source.and_then(|s| s.selector) {
|
|
Some(crate::pb::object_selector::Selector::Oid(oid)) => oid.hex,
|
|
Some(crate::pb::object_selector::Selector::Revision(name)) => {
|
|
crate::sanitize::validate_revision(&name.revision)?;
|
|
name.revision
|
|
}
|
|
None => return Err(GitError::InvalidArgument("source is required".into())),
|
|
};
|
|
|
|
let result = duct::cmd(
|
|
"git",
|
|
[
|
|
"--git-dir",
|
|
self.bare_dir.to_string_lossy().as_ref(),
|
|
"merge-tree",
|
|
"--write-tree",
|
|
"--name-only",
|
|
"-z",
|
|
target.as_str(),
|
|
source.as_str(),
|
|
],
|
|
)
|
|
.stdout_capture()
|
|
.stderr_capture()
|
|
.unchecked()
|
|
.run()?;
|
|
|
|
let stdout = String::from_utf8_lossy(&result.stdout);
|
|
|
|
if result.status.success() {
|
|
return Ok(ListMergeConflictsResponse {
|
|
conflicts: vec![],
|
|
page_info: Some(crate::pb::PageInfo {
|
|
next_page_token: String::new(),
|
|
has_next_page: false,
|
|
total_count: 0,
|
|
}),
|
|
});
|
|
}
|
|
|
|
let mut conflicts: Vec<MergeConflict> = stdout
|
|
.split('\0')
|
|
.filter(|s| !s.is_empty())
|
|
.map(|path| MergeConflict {
|
|
path: path.to_string(),
|
|
..Default::default()
|
|
})
|
|
.collect();
|
|
|
|
paginate::apply_sort(&mut conflicts, 0);
|
|
let (conflicts, page_info) = paginate::paginate(&conflicts, request.pagination.as_ref());
|
|
Ok(ListMergeConflictsResponse {
|
|
conflicts,
|
|
page_info: Some(page_info),
|
|
})
|
|
}
|
|
}
|