[PATCH 1/1] filter: fix libravatar email-filter https issue

Christian Hesse list at eworm.de
Wed Sep 10 11:24:07 CEST 2014


From: Christian Hesse <mail at eworm.de>

Serving cgit via https and getting avatar via http gives error messages
about untrusted content. This decides whether or not to use https link
by looking at the environment variable HTTPS, which is set in CGI.
---
 filters/email-libravatar.lua | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/filters/email-libravatar.lua b/filters/email-libravatar.lua
index a248be4..b0e2447 100644
--- a/filters/email-libravatar.lua
+++ b/filters/email-libravatar.lua
@@ -15,7 +15,8 @@ function filter_open(email, page)
 end
 
 function filter_close()
-	html("<img src='//cdn.libravatar.org/avatar/" .. md5 .. "?s=13&d=retro' width='13' height='13' alt='Libravatar' /> " .. buffer)
+	baseurl = os.getenv("HTTPS") and "https://seccdn.libravatar.org/" or "http://cdn.libravatar.org/"
+	html("<img src='" .. baseurl .. "avatar/" .. md5 .. "?s=13&d=retro' width='13' height='13' alt='Libravatar' /> " .. buffer)
 	return 0
 end
 
-- 
2.1.0



More information about the CGit mailing list