11import type { GitContext } from '../context.ts'
22import { defineRpcFunction } from 'devframe'
3- import { splitClean , tryGit , UNIT } from '../../node/git.ts'
3+ import { isSafeRevision , splitClean , tryGit , UNIT } from '../../node/git.ts'
44import { getGitContext } from '../context.ts'
55
66/** Hard cap on the returned patch text to keep payloads bounded. */
@@ -102,7 +102,10 @@ function parseNumstat(raw: string): CommitFile[] {
102102}
103103
104104async function readCommit ( git : GitContext , hash : string , includePatch : boolean ) : Promise < CommitDetail > {
105- const meta = await tryGit ( git . cwd , [ 'show' , '-s' , `--format=${ SHOW_FORMAT } ` , hash ] )
105+ if ( ! isSafeRevision ( hash ) )
106+ return { ...EMPTY_DETAIL , isRepo : true }
107+
108+ const meta = await tryGit ( git . cwd , [ 'show' , '-s' , `--format=${ SHOW_FORMAT } ` , '--end-of-options' , hash ] )
106109 if ( meta == null )
107110 return { ...EMPTY_DETAIL , isRepo : true }
108111
@@ -122,15 +125,15 @@ async function readCommit(git: GitContext, hash: string, includePatch: boolean):
122125 ] = meta . split ( UNIT )
123126
124127 // `--root` so the initial commit reports its full tree as additions.
125- const numstat = await tryGit ( git . cwd , [ 'diff-tree' , '--no-commit-id' , '--numstat' , '-r' , '--root' , hash ] )
128+ const numstat = await tryGit ( git . cwd , [ 'diff-tree' , '--no-commit-id' , '--numstat' , '-r' , '--root' , '--end-of-options' , hash ] )
126129 const files = numstat ? parseNumstat ( numstat ) : [ ]
127130 const totalAdditions = files . reduce ( ( sum , f ) => sum + f . additions , 0 )
128131 const totalDeletions = files . reduce ( ( sum , f ) => sum + f . deletions , 0 )
129132
130133 let patch : string | null = null
131134 let truncated = false
132135 if ( includePatch ) {
133- const raw = await tryGit ( git . cwd , [ 'diff-tree' , '-p' , '--no-commit-id' , '-r' , '--root' , hash ] )
136+ const raw = await tryGit ( git . cwd , [ 'diff-tree' , '-p' , '--no-commit-id' , '-r' , '--root' , '--end-of-options' , hash ] )
134137 if ( raw != null ) {
135138 if ( raw . length > PATCH_CHAR_LIMIT ) {
136139 patch = raw . slice ( 0 , PATCH_CHAR_LIMIT )
0 commit comments