From mboxrd@z Thu Jan 1 00:00:00 1970 From: normalperson at yhbt.net (Eric Wong) Date: Wed, 13 Jan 2016 19:11:00 +0000 Subject: XSS in cgit In-Reply-To: References: Message-ID: <20160113191100.GA1660@dcvr.yhbt.net> "Jason A. Donenfeld" wrote: > Given all this, could somebody remind me why we have both /plain and > /blob handlers? And if it's still necessary to maintain a distinction? > If not, I will gladly accept patches to unify these. IIRC, the main difference was blob allows serving tree objects as-is in binary form while plain generates an HTML directory listing.