d243dce027
- Replaced manual remote client functions with remote_client! macro for archive, blame, branch, commit, and diff services - Simplified remote client creation logic using declarative macro approach - Maintained same functionality while reducing code duplication across services security(bare): enhance path traversal protection with comprehensive validation - Added early relative_path validation to prevent path traversal attacks - Implemented unified path validation to avoid TOCTOU race conditions - Enhanced canonicalization checks for both existing and non-existent paths - Added detailed logging for path traversal detection attempts feat(cache): migrate from CLruCache to Moka with TTL and invalidation support - Replaced clru dependency with moka for improved caching capabilities - Added 300-second time-to-live for cache entries - Implemented repository-specific cache invalidation mechanism - Enhanced cache operations with thread-safe async support refactor(commit): improve security validation for commit operations - Added ref name validation to prevent command injection in cherry_pick_commit - Implemented revision validation for commit selectors - Added comprehensive input validation for create_commit parameters - Enhanced file path validation to prevent traversal
84 lines
2.7 KiB
Rust
84 lines
2.7 KiB
Rust
use crate::bare::GitBare;
|
|
use crate::error::{GitError, GitResult};
|
|
use crate::pb::{GetCommitDiffRequest, GetDiffRequest, GetDiffResponse};
|
|
use crate::resolve_revision;
|
|
|
|
impl GitBare {
|
|
pub fn get_commit_diff(&self, request: GetCommitDiffRequest) -> GitResult<GetDiffResponse> {
|
|
let commit = resolve_revision!(request.commit);
|
|
let base = self.first_parent_or_empty_tree(&commit)?;
|
|
self.get_diff(GetDiffRequest {
|
|
repository: request.repository,
|
|
base: Some(crate::pb::ObjectSelector {
|
|
selector: Some(crate::pb::object_selector::Selector::Revision(
|
|
crate::pb::ObjectName { revision: base },
|
|
)),
|
|
}),
|
|
head: Some(crate::pb::ObjectSelector {
|
|
selector: Some(crate::pb::object_selector::Selector::Revision(
|
|
crate::pb::ObjectName { revision: commit },
|
|
)),
|
|
}),
|
|
options: request.options,
|
|
pagination: request.pagination,
|
|
})
|
|
}
|
|
|
|
fn first_parent_or_empty_tree(&self, commit: &str) -> GitResult<String> {
|
|
let result = duct::cmd(
|
|
"git",
|
|
[
|
|
"--git-dir",
|
|
self.bare_dir.to_string_lossy().as_ref(),
|
|
"rev-list",
|
|
"--parents",
|
|
"-n",
|
|
"1",
|
|
commit,
|
|
],
|
|
)
|
|
.stdout_capture()
|
|
.stderr_capture()
|
|
.unchecked()
|
|
.run()?;
|
|
if !result.status.success() {
|
|
return Err(GitError::CommandFailed {
|
|
status_code: result.status.code(),
|
|
stderr: String::from_utf8_lossy(&result.stderr).into_owned(),
|
|
});
|
|
}
|
|
let output = String::from_utf8_lossy(&result.stdout);
|
|
let parts = output.split_whitespace().collect::<Vec<_>>();
|
|
if let Some(parent) = parts.get(1) {
|
|
return Ok((*parent).to_string());
|
|
}
|
|
|
|
let empty_tree = duct::cmd(
|
|
"git",
|
|
[
|
|
"--git-dir",
|
|
self.bare_dir.to_string_lossy().as_ref(),
|
|
"hash-object",
|
|
"-t",
|
|
"tree",
|
|
"-w",
|
|
"--stdin",
|
|
],
|
|
)
|
|
.stdin_bytes(Vec::<u8>::new())
|
|
.stdout_capture()
|
|
.stderr_capture()
|
|
.unchecked()
|
|
.run()?;
|
|
if !empty_tree.status.success() {
|
|
return Err(GitError::CommandFailed {
|
|
status_code: empty_tree.status.code(),
|
|
stderr: String::from_utf8_lossy(&empty_tree.stderr).into_owned(),
|
|
});
|
|
}
|
|
Ok(String::from_utf8_lossy(&empty_tree.stdout)
|
|
.trim()
|
|
.to_string())
|
|
}
|
|
}
|