--- parser3/src/main/pa_http.C 2016/07/26 13:20:23 1.72 +++ parser3/src/main/pa_http.C 2024/12/24 02:58:47 1.132 @@ -1,25 +1,20 @@ /** @file Parser: http support functions. - Copyright (c) 2001-2015 Art. Lebedev Studio (http://www.artlebedev.com) - Author: Alexandr Petrosian (http://paf.design.ru) + Copyright (c) 2001-2024 Art. Lebedev Studio (http://www.artlebedev.com) + Authors: Konstantin Morshnev , Alexandr Petrosian */ #include "pa_http.h" #include "pa_common.h" +#include "pa_base64.h" #include "pa_charsets.h" #include "pa_request_charsets.h" #include "pa_request.h" #include "pa_vfile.h" #include "pa_random.h" -volatile const char * IDENT_PA_HTTP_C="$Id: pa_http.C,v 1.72 2016/07/26 13:20:23 moko Exp $" IDENT_PA_HTTP_H; - -#ifdef _MSC_VER -#include -#else -#define closesocket close -#endif +volatile const char * IDENT_PA_HTTP_C="$Id: pa_http.C,v 1.132 2024/12/24 02:58:47 moko Exp $" IDENT_PA_HTTP_H; // defines @@ -47,6 +42,51 @@ volatile const char * IDENT_PA_HTTP_C="$ // helpers +#ifdef HTTPD_DEBUG +void pa_log(const char* fmt, ...); +#define LOG(action) action +#else +#define LOG(action) +#endif + +ssize_t pa_send(int sock, const char *buffer, size_t len){ + size_t total_sent = 0; + while (total_sent < len) { + ssize_t bytes_sent=send(sock, buffer + total_sent, len - total_sent, 0); + if (bytes_sent < 0) { + return bytes_sent; + } else if (bytes_sent == 0) { + // Connection closed by the remote peer? + break; + } + LOG( + if(bytes_sent != len - total_sent) + pa_log("httpd [%d] partial send %d of (%d)", sock, bytes_sent, len - total_sent) + ); + total_sent += bytes_sent; + } + return total_sent; +} + +bool HTTP_Headers::add_header(const char *line){ + const char *value=strchr(line, ':'); + + if(value && value != line){ // we need only headers, not the response code + Header header(str_upper(line, value-line), String::Body(value+1).trim(String::TRIM_BOTH, " \t\n\r")); + + if(header.name == String::Body(HTTP_CONTENT_TYPE_UPPER) && content_type.is_empty()) + content_type=header.value; + + if(header.name == String::Body("CONTENT-LENGTH") && content_length==0) + ALTER_EXCEPTION_COMMENT(content_length=pa_atoul(header.value.cstr()), " for content-length"); + + headers+=header; + + return true; + } + return false; +} + class Cookies_table_template_columns: public ArrayString { public: Cookies_table_template_columns() { @@ -76,123 +116,160 @@ static bool set_addr(struct sockaddr_in return false; } -size_t guess_content_length(char* buf) { - char* ptr; - if((ptr=strstr(buf, "Content-Length:"))) // Apache - goto found; - if((ptr=strstr(buf, "content-length:"))) // Parser 3 before 3.4.0 - goto found; - if((ptr=strstr(buf, "Content-length:"))) // maybe 1 - goto found; - if((ptr=strstr(buf, "CONTENT-LENGTH:"))) // maybe 2 - goto found; - return 0; -found: - char *error_pos; - size_t result=(size_t)strtol(ptr+15/*strlen("Content-Length:")*/, &error_pos, 0); - - const size_t reasonable_initial_max=0x400*0x400*10 /*10M*/; - if(result>reasonable_initial_max) // sanity check - return reasonable_initial_max; - return 0;//result; -} +class HTTP_response : public PA_Allocated { +public: + char *buf; + size_t length; + size_t buf_size; + size_t body_offset; + + HTTP_Headers headers; + + HTTP_response() : buf(NULL), length(0), buf_size(0), body_offset(0){} + + void resize(size_t size){ + buf_size=size; + buf=(char *)pa_realloc(buf, size + 1); + } + + bool read(SOCKET sock, size_t size){ + if(length + size > buf_size) + resize(buf_size * 2 + size); + ssize_t received_size=recv(sock, buf + length, size, 0); + if(received_size == 0) + return false; + if(received_size < 0) { + if(int no = pa_socks_errno()) + throw Exception("http.timeout", 0, "error receiving response: %s (%d)", pa_socks_strerr(no), no); + return false; + } + length+=received_size; + buf[length]='\0'; + return true; + } -static int http_read_response(char*& response, size_t& response_size, int sock, bool fail_on_status_ne_200) { - int result=0; - // fetching some to local buffer, guessing on possible Content-Length - response_size=0x400*20; // initial size if Content-Length could not be determined - const size_t preview_size=0x400*20; - char preview_buf[preview_size+1/*terminator*/]; // 20K buffer to preview headers - ssize_t received_size=recv(sock, preview_buf, preview_size, 0); - if(received_size==0) - goto done; - if(received_size<0) { - if(int no=pa_socks_errno()) - throw Exception("http.timeout", - 0, - "error receiving response header: %s (%d)", pa_socks_strerr(no), no); - goto done; - } - // terminator [helps futher string searches] - preview_buf[received_size]=0; - // checking status - if(char* EOLat=strstr(preview_buf, "\n")) { - const String status_line(pa_strdup(preview_buf, EOLat-preview_buf)); - ArrayString astatus; - size_t pos_after=0; - status_line.split(astatus, pos_after, " "); - const String& status_code=*astatus.get(astatus.count()>1?1:0); - result=status_code.as_int(); - - if(fail_on_status_ne_200 && result!=200) - throw Exception("http.status", - &status_code, - "invalid HTTP response status"); + size_t first_line(){ + char *header=strchr(buf, '\n'); + if(!header) + return false; + + return header-buf; } - // detecting response_size - { - if(size_t content_length=guess_content_length(preview_buf)) - response_size=preview_size+content_length; // a little more than needed, will adjust response_size by actual received size later + + const char *status_code(char *status_line, int &result){ + char* status_start = strchr(status_line, ' '); + + if(!(status_start++)) + return status_line; + + char* status_end=strchr(status_start, ' '); + + if(!status_end) + return status_line; + + if(status_end==status_start) + return status_line; + + const char *result_str=pa_strdup(status_start, status_end-status_start); + ALTER_EXCEPTION_COMMENT(result=pa_atoui(result_str), " for HTTP status"); + return result_str; } - // [gcc is happier this way, see goto above] - { - // allocating initial buf - response=(char*)pa_malloc_atomic(response_size+1/*terminator*/); // just setting memory block type - char* ptr=response; - size_t todo_size=response_size; - // coping part of already received body - memcpy(ptr, preview_buf, received_size); - ptr+=received_size; - todo_size-=received_size; - - // we use terminator byte for two purposes here: - // 1. we return there zero always, not knowing: maybe they would want to create String form $file.body? - // invariant: all Strings should have zero-terminated buffers - // 2. we use that out-of-size byte to detect if our Content-Length guess was wrong - // when recv gets more than we expected - // a) we know that the Content-Length guess was wrong - // b) we have space to put the first byte of extra data - // c) we use less code to detect normal situation: on last while-cycle recv expected to just return 0 - while(true) { - received_size=recv(sock, ptr, todo_size+1/*there is always a place for terminator*/, 0); - if(received_size==0) { - response_size-=todo_size; // in case we received less than expected, cut down the reported size + bool body_start(){ + char *p=buf; + while((p=strchr(p, '\n'))) { + if(p[1]=='\r' && p[2]=='\n'){ // \r\n\r\n + *p='\0'; + body_offset=p-buf+3; + return true; + } + if(p[1]=='\n') { // \n\n + *p='\0'; + body_offset=p-buf+2; + return true; + } + p++; + } + return false; + } + + void parse_headers(){ + const String header_block(buf, String::L_TAINTED); + + ArrayString aheaders; + header_block.split(aheaders, 0, "\n"); + + ArrayString::Iterator i(aheaders); + i.next(); // skipping status + for(;i;){ + const char *line=i.next()->cstr(); + if(!headers.add_header(line)) + throw Exception("http.response", 0, "bad response from host - bad header \"%s\"", line); + } + } + + int read_response(SOCKET sock, bool fail_on_status_ne_200); +}; + +enum HTTP_response_state { + HTTP_STATUS_CODE, + HTTP_HEADERS, + HTTP_BODY +}; + +int HTTP_response::read_response(SOCKET sock, bool fail_on_status_ne_200) { + HTTP_response_state state=HTTP_STATUS_CODE; + int result=0; + + size_t chunk_size=0x400*16; + resize(2*chunk_size); + + while(read(sock, chunk_size)){ + switch(state){ + case HTTP_STATUS_CODE: { + size_t status_size=first_line(); + if(!status_size) + break; + + const char *status=status_code(pa_strdup(buf, status_size), result); + + if(!result || fail_on_status_ne_200 && result!=200) + throw Exception("http.status", status ? new String(status) : &String::Empty, "invalid HTTP response status"); + + state=HTTP_HEADERS; + } + + case HTTP_HEADERS: { + if(!body_start()) + break; + + parse_headers(); + + size_t content_length=check_file_size(headers.content_length, 0); + if(content_length>0 && (content_length + body_offset) > length){ + resize(content_length + body_offset + 0x400*64); + } + + state=HTTP_BODY; break; } - if(received_size<0) { - if(int no=pa_socks_errno()) - throw Exception("http.timeout", - 0, - "error receiving response body: %s (%d)", pa_socks_strerr(no), no); + + case HTTP_BODY: { + chunk_size=0x400*64; break; } - // they've touched the terminator? - if((size_t)received_size>todo_size) - { - // that means that our guessed response_size was not big enough - const size_t grow_chunk_size=0x400*0x400; // 1M - response_size+=grow_chunk_size; - size_t ptr_offset=ptr-response; - response=(char*)pa_realloc(response, response_size+1/*terminator*/); - ptr=response+ptr_offset; - todo_size+=grow_chunk_size; - } - // can't do this before realloc: we need =0) - closesocket(sock); - throw Exception("http.timeout", - 0, - "timeout occured while retrieving document"); + if(PA_NO_THREADS) signal(SIGALRM, timeout_handler); + if(PA_NO_THREADS && sigsetjmp(timeout_env, 1)) { + // duplicating closesocket to make code more simple for old compilers + if(sock != INVALID_SOCKET) + closesocket(sock); + throw Exception("http.timeout", 0, "timeout occurred while retrieving document"); return 0; // never - } else { - alarm(timeout_secs); + } else #endif + { + ALARM(timeout_secs); try { int result; struct sockaddr_in dest; if(!set_addr(&dest, host, port)) - throw Exception("http.host", - 0, - "can not resolve hostname \"%s\"", host); + throw Exception("http.host", 0, "cannot resolve hostname \"%s\"", host); - if((sock=socket(AF_INET, SOCK_STREAM, IPPROTO_TCP/*0*/))<0) { + if((sock=socket(AF_INET, SOCK_STREAM, IPPROTO_TCP/*0*/)) == INVALID_SOCKET) { int no=pa_socks_errno(); - throw Exception("http.connect", - 0, - "can not make socket: %s (%d)", pa_socks_strerr(no), no); + throw Exception("http.connect", 0, "cannot make socket: %s (%d)", pa_socks_strerr(no), no); } // To enable SO_DONTLINGER (that is, disable SO_LINGER) @@ -269,35 +337,25 @@ static int http_request(char*& response, if(connect(sock, (struct sockaddr *)&dest, sizeof(dest))) { int no=pa_socks_errno(); - throw Exception("http.connect", - 0, - "can not connect to host \"%s\": %s (%d)", host, pa_socks_strerr(no), no); + throw Exception("http.connect", 0, "cannot connect to host \"%s\": %s (%d)", host, pa_socks_strerr(no), no); } - if(send(sock, request, request_size, 0)!=(ssize_t)request_size) { + if(pa_send(sock, request, request_size) < 0) { int no=pa_socks_errno(); - throw Exception("http.timeout", - 0, - "error sending request: %s (%d)", pa_socks_strerr(no), no); + throw Exception("http.timeout", 0, "error sending request: %s (%d)", pa_socks_strerr(no), no); } - result=http_read_response(response, response_size, sock, fail_on_status_ne_200); - closesocket(sock); -#ifdef PA_USE_ALARM - alarm(0); -#endif + result=response.read_response(sock, fail_on_status_ne_200); + closesocket(sock); + ALARM(0); return result; } catch(...) { -#ifdef PA_USE_ALARM - alarm(0); -#endif - if(sock>=0) - closesocket(sock); + ALARM(0); + if(sock != INVALID_SOCKET) + closesocket(sock); rethrow; } -#ifdef PA_USE_ALARM } -#endif } #ifndef DOXYGEN @@ -322,9 +380,7 @@ char *pa_http_safe_header_name(const cha return result; } -static void http_pass_header(HashStringValue::key_type aname, - HashStringValue::value_type avalue, - Http_pass_header_info *info) { +static void http_pass_header(HashStringValue::key_type aname, HashStringValue::value_type avalue, Http_pass_header_info *info) { const char* name_cstr=aname.cstr(); @@ -366,15 +422,11 @@ static const String* basic_authorization combined<key, *row->get(0), info->result); } -static void form_value2string( - HashStringValue::key_type key, - HashStringValue::value_type value, - String* result) -{ + +static void form_value2string(HashStringValue::key_type key, HashStringValue::value_type value, String* result) { if(const String* svalue=value->get_string()) form_string_value2string(key, *svalue, *result); else if(Table* tvalue=value->get_table()) { Form_table_value2string_info info(key, *result); tvalue->for_each(form_table_value2string, &info); } else - throw Exception(PARSER_RUNTIME, - new String(key, String::L_TAINTED), + throw Exception(PARSER_RUNTIME, new String(key, String::L_TAINTED), "is %s, " HTTP_FORM_NAME " option value can be string or table only (file is allowed for $." HTTP_METHOD_NAME "[POST] + $." HTTP_FORM_ENCTYPE_NAME "[" HTTP_CONTENT_TYPE_MULTIPART_FORMDATA "])", value->type()); } @@ -455,11 +503,8 @@ struct FormPart { } }; -static void form_part_boundary_header(FormPart& part, String::Body name, const char* file_name=0){ - *part.string << "--" << part.boundary - << CRLF CONTENT_DISPOSITION_CAPITALIZED ": form-data; name=\"" - << name - << "\""; +static void form_part_boundary_header(FormPart& part, String::Body name, const char* file_name=0) { + *part.string << "--" << part.boundary << CRLF CONTENT_DISPOSITION_CAPITALIZED ": form-data; name=\"" << name << "\""; if(file_name){ if(strcmp(file_name, NONAME_DAT)!=0) *part.string << "; filename=\"" << file_name << "\""; @@ -468,20 +513,12 @@ static void form_part_boundary_header(Fo *part.string << CRLF CRLF; } -static void form_string_value2part( - HashStringValue::key_type key, - const String& value, - FormPart& part) -{ +static void form_string_value2part(HashStringValue::key_type key, const String& value, FormPart& part) { form_part_boundary_header(part, key); *part.string << value << CRLF; } -static void form_file_value2part( - HashStringValue::key_type key, - VFile& vfile, - FormPart& part) -{ +static void form_file_value2part(HashStringValue::key_type key, VFile& vfile, FormPart& part) { form_part_boundary_header(part, key, vfile.fields().get(name_name)->as_string().cstr()); part.blocks+=FormPart::BinaryBlock(part.string, part.r); part.blocks+=FormPart::BinaryBlock(vfile.value_ptr(), vfile.value_size()); @@ -493,23 +530,17 @@ static void form_table_value2part(Table: form_string_value2part(part->info->key, *row->get(0), *part); } -static void form_value2part( - HashStringValue::key_type key, - HashStringValue::value_type value, - FormPart& part) -{ +static void form_value2part(HashStringValue::key_type key, HashStringValue::value_type value, FormPart& part) { if(const String* svalue=value->get_string()) form_string_value2part(key, *svalue, part); else if(Table* tvalue=value->get_table()) { Form_table_value2string_info info(key, *part.string); part.info = &info; tvalue->for_each(form_table_value2part, &part); - } else if(VFile* vfile=static_cast(value->as("file"))){ + } else if(VFile* vfile=dynamic_cast(value)){ form_file_value2part(key, *vfile, part); } else - throw Exception(PARSER_RUNTIME, - new String(key, String::L_TAINTED), - "is %s, " HTTP_FORM_NAME " option value can be string, table or file only", value->type()); + throw Exception(PARSER_RUNTIME, new String(key, String::L_TAINTED), "is %s, " HTTP_FORM_NAME " option value can be string, table or file only", value->type()); } const char* pa_form2string_multipart(HashStringValue& form, Request& r, const char* boundary, size_t& post_size){ @@ -520,25 +551,6 @@ const char* pa_form2string_multipart(Has return formpart.post(post_size); } -static void find_headers_end(char* p, - char*& headers_end_at, - char*& raw_body) -{ - raw_body=p; - // \n\n - // \r\n\r\n - while((p=strchr(p, '\n'))) { - headers_end_at=++p; // \n>.< - if(*p=='\r') // \r\n>\r?<\n - p++; - if(*p=='\n') { // \r\n\r>\n?< - raw_body=p+1; - return; - } - } - headers_end_at=0; -} - // Set-Cookie: name=value; Domain=docs.foo.com; Path=/accounts; Expires=Wed, 13-Jan-2021 22:23:01 GMT; Secure; HttpOnly static ArrayString* parse_cookie(Request& r, const String& cookie) { char *current=pa_strdup(cookie.cstr()); @@ -565,7 +577,8 @@ static ArrayString* parse_cookie(Request if(first_pair) { // name + value name=sname; - value=smeaning; + if(smeaning) + value=smeaning; first_pair=false; } else { const String& slower=sname->change_case(r.charsets.source(), String::CC_LOWER); @@ -608,14 +621,14 @@ static ArrayString* parse_cookie(Request Table* parse_cookies(Request& r, Table *cookies){ Table& result=*new Table(new Cookies_table_template_columns); - for(Array_iterator i(*cookies); i.has_next(); ) + for(Array_iterator i(*cookies); i; ) if(ArrayString* row=parse_cookie(r, *i.next()->get(0))) result+=row; return &result; } -void *tables_update(HashStringValue& tables, const String::Body name, const String& value){ +void tables_update(HashStringValue& tables, const String::Body name, const String& value){ Table *table; if(Value *valready=tables.get(name)) { // second+ appearence @@ -694,11 +707,11 @@ File_read_http_result pa_internal_file_r omit_post_charset=vomit_post_charset->as_bool(); } if(Value* vcharset_name=options->get(PA_CHARSET_NAME)) { - asked_remote_charset=&charsets.get(vcharset_name->as_string().change_case(r.charsets.source(), String::CC_UPPER)); + asked_remote_charset=&pa_charsets.get(vcharset_name->as_string()); } if(Value* vresponse_charset_name=options->get(PA_RESPONSE_CHARSET_NAME)) { valid_options++; - real_remote_charset=&charsets.get(vresponse_charset_name->as_string().change_case(r.charsets.source(), String::CC_UPPER)); + real_remote_charset=&pa_charsets.get(vresponse_charset_name->as_string()); } if(Value* vuser=options->get(HTTP_USER)) { valid_options++; @@ -717,7 +730,7 @@ File_read_http_result pa_internal_file_r if(encode){ if(method_is_get) - throw Exception(PARSER_RUNTIME, 0, "you can not use $." HTTP_FORM_ENCTYPE_NAME " option with method GET"); + throw Exception(PARSER_RUNTIME, 0, "you cannot use $." HTTP_FORM_ENCTYPE_NAME " option with method GET"); multipart=strcasecmp(encode, HTTP_CONTENT_TYPE_MULTIPART_FORMDATA)==0; @@ -727,10 +740,10 @@ File_read_http_result pa_internal_file_r if(vbody){ if(method_is_get) - throw Exception(PARSER_RUNTIME, 0, "you can not use $." HTTP_BODY_NAME " option with method GET"); + throw Exception(PARSER_RUNTIME, 0, "you cannot use $." HTTP_BODY_NAME " option with method GET"); if(form) - throw Exception(PARSER_RUNTIME, 0, "you can not use options $." HTTP_BODY_NAME " and $." HTTP_FORM_NAME " together"); + throw Exception(PARSER_RUNTIME, 0, "you cannot use options $." HTTP_BODY_NAME " and $." HTTP_FORM_NAME " together"); } //preparing request @@ -749,7 +762,7 @@ File_read_http_result pa_internal_file_r throw Exception(PARSER_RUNTIME, &connect_string, "does not start with http://"); //never current+=7; - strncpy(host, current, sizeof(host)-1); host[sizeof(host)-1]=0; + pa_strncpy(host, current, sizeof(host)); char* host_uri=lsplit(host, '/'); uri=host_uri?current+(host_uri-1-host):"/"; char* port_cstr=lsplit(host, ':'); @@ -845,7 +858,7 @@ File_read_http_result pa_internal_file_r } if(request_body) - head << "Content-Length: " << format(post_size, "%u") << CRLF; + head << "Content-Length: " << pa_uitoa(post_size) << CRLF; head << CRLF; @@ -864,53 +877,32 @@ File_read_http_result pa_internal_file_r } } - char* response_str; - size_t response_size; + + HTTP_response response; // sending request - int status_code=http_request(response_str, response_size, idna_host, port, request, request_size, timeout_secs, fail_on_status_ne_200); - + int status_code; + ALTER_EXCEPTION_SOURCE(status_code=http_request(response, idna_host, port, request, request_size, timeout_secs, fail_on_status_ne_200), &connect_string); + // processing results - char* raw_body; size_t raw_body_size; - char* headers_end_at; - find_headers_end(response_str, headers_end_at, raw_body); - raw_body_size=response_size-(raw_body-response_str); - + char* raw_body=response.buf + response.body_offset; + size_t raw_body_size=response.length - response.body_offset; + result.headers=new HashStringValue; VHash* vtables=new VHash; result.headers->put("tables", vtables); - ResponseHeaders response; - - if(headers_end_at) { - *headers_end_at=0; - const String header_block(String::C(response_str, headers_end_at-response_str), String::L_TAINTED); - - ArrayString aheaders; - - size_t pos_after=0; - header_block.split(aheaders, pos_after, "\n"); - - Array_iterator i(aheaders); - i.next(); // skipping status - for(;i.has_next();){ - const char *line=i.next()->cstr(); - if(!response.add_header(line)) - throw Exception("http.response", &connect_string, "bad response from host - bad header \"%s\"", line); - } - } - - if (!real_remote_charset && !response.content_type.is_empty()) - real_remote_charset= detect_charset(response.content_type.cstr()); + if (!real_remote_charset && !response.headers.content_type.is_empty()) + real_remote_charset=detect_charset(response.headers.content_type.cstr()); if(as_text) - real_remote_charset=charsets.checkBOM(raw_body, raw_body_size, real_remote_charset); + real_remote_charset=pa_charsets.checkBOM(raw_body, raw_body_size, real_remote_charset); if (!real_remote_charset) real_remote_charset=asked_remote_charset; // never null - for(Array_iterator i(response.headers); i.has_next(); ){ - ResponseHeaders::Header header=i.next(); + for(Array_iterator i(response.headers.headers); i; ){ + HTTP_Headers::Header header=i.next(); header.transcode(*real_remote_charset, r.charsets.source()); @@ -921,7 +913,7 @@ File_read_http_result pa_internal_file_r } // filling $.cookies - if(Value *vcookies=vtables->hash().get("SET-COOKIE")) + if(vcookies=vtables->hash().get("SET-COOKIE")) result.headers->put(HTTP_COOKIES_NAME, new VTable(parse_cookies(r, vcookies->get_table()))); // output response @@ -941,3 +933,367 @@ File_read_http_result pa_internal_file_r return result; } + +/* ********************** httpd *************************** */ + +enum EscapeState { + Initial, + Default, + EscapeFirst, + EscapeSecond +}; + +static bool check_uri(const char *uri){ + EscapeState state=Initial; + uint escapedValue=0; + + const char *pattern="/../"; + const char *pos=pattern; + + while(*uri){ + uchar c=(uchar)*(uri++); + switch(state) { + case Initial: + if(c!='/') + return false; + state=Default; + break; + case Default: + if(c=='%'){ + state=EscapeFirst; + continue; + } + if(c=='?') + return true; + break; + case EscapeFirst: + if(isxdigit(c)){ + state=EscapeSecond; + escapedValue=hex_value[c] << 4; + continue; + } + return false; + case EscapeSecond: + if(isxdigit(c)){ + state=Default; + c=(uchar)(escapedValue + hex_value[c]); + + // implementing Apache AllowEncodedSlashes Off just in case + if(c=='/' || c=='\\') + return false; + + break; + } + return false; + } + + if(c==*pos || c=='\\' && *pos=='/'){ + if(!*(++pos)) + return false; + } else { + pos=pattern; + } + } + return true; +} + +class HTTPD_request : public HTTP_response { +public: + const char *method; + const char *uri; + + HTTPD_request() : HTTP_response(), method(NULL), uri(NULL){}; + + ssize_t pa_recv(SOCKET sockfd, char *buf, size_t len); + + bool read(SOCKET sock, size_t size){ + if(length + size > buf_size) + resize(buf_size * 2 + size); + ssize_t received_size=pa_recv(sock, buf + length, size); + if(received_size == 0) + return false; + if(received_size < 0) { + if(int no = pa_socks_errno()) + throw Exception("httpd.read", 0, "error receiving request: %s (%d)", pa_socks_strerr(no), no); + return false; + } + length+=received_size; + buf[length]='\0'; + return true; + } + + const char *extract_method(char *method_line){ + char* uri_start = strchr(method_line, ' '); + + if(!uri_start || uri_start == method_line) + return NULL; + + char* uri_end=strchr(uri_start+1, ' '); + + if(!uri_end || uri_end == uri_start+1) + return NULL; + + uri=pa_strdup(uri_start+1, uri_end-uri_start-1); + if(!check_uri(uri)) + throw Exception("httpd.request", 0, "invalid uri '%s'", uri); + + return str_upper(method_line, uri_start-method_line); + } + + + bool read_header(SOCKET); + size_t read_post(SOCKET, char *, size_t); +}; + +enum HTTPD_request_state { + HTTPD_METHOD, + HTTPD_HEADERS +}; + +ssize_t HTTPD_request::pa_recv(SOCKET sockfd, char *buffer, size_t len){ + LOG(pa_log("httpd [%d] recv %d appending to %d ...", sockfd, len, length)); + +#ifdef PA_USE_ALARM + if(PA_NO_THREADS) signal(SIGALRM, timeout_handler); + if(PA_NO_THREADS && sigsetjmp(timeout_env, 1)) { + LOG(pa_log("httpd [%d] recv got %d sec timeout", sockfd, pa_httpd_timeout)); + if(length) // timeout on "void" connection is normal + throw Exception("httpd.timeout", 0, "timeout occurred while receiving request"); + return 0; + } else +#endif + { + ALARM(pa_httpd_timeout); + ssize_t result=recv(sockfd, buffer, len, 0); + ALARM(0); + LOG(pa_log("httpd [%d] recv got %d bytes", sockfd, result)); + LOG(pa_log("httpd [%d] %s", sockfd, buffer)); + return result; + } +} + +static bool valid_http_method(const char * method){ + return method && ( + !strcmp(method, "GET") || + !strcmp(method, "HEAD") || + !strcmp(method, "POST") || + !strcmp(method, "PUT") || + !strcmp(method, "DELETE") || + !strcmp(method, "CONNECT") || + !strcmp(method, "OPTIONS") || + !strcmp(method, "TRACE") || + !strcmp(method, "PATCH") + ); +} + +bool HTTPD_request::read_header(SOCKET sock) { + enum HTTPD_request_state state = HTTPD_METHOD; + + size_t chunk_size = 0x400*4; + resize(chunk_size); + + while(read(sock, chunk_size)){ + switch(state){ + case HTTPD_METHOD: { + size_t method_size = first_line(); + if(!method_size) + break; + + char *method_line = pa_strdup(buf, method_size); + method = extract_method(method_line); + + if(!valid_http_method(method)) + throw Exception("httpd.method", new String(method ? method : method_line), "invalid request method"); + state = HTTPD_HEADERS; + } + + case HTTPD_HEADERS: { + if(!body_start()) + break; + + parse_headers(); + return true; + } + } + } + + if(!length){ // browsers open connections in advance and they will be empty unless user requests more pages + LOG(pa_log("httpd [%d] void request", sock)); + return false; + } + + if(state == HTTPD_METHOD) + throw Exception("httpd.request", 0, "bad request from host - no method found (size=%u)", length); + + if(state == HTTPD_HEADERS){ + parse_headers(); + body_offset=length; + } + + return true; +} + +size_t HTTPD_request::read_post(SOCKET sock, char *body, size_t max_bytes) { + size_t total_read = min(length - body_offset, max_bytes); + memcpy(body, buf + body_offset, total_read); + + while (total_read < max_bytes){ + ssize_t received_size = pa_recv(sock, body + total_read, max_bytes - total_read); + if(received_size == 0) + return total_read; + if(received_size < 0) { + if(int no = pa_socks_errno()) + throw Exception("httpd.read", new String(uri), "error receiving request body: %s (%d)", pa_socks_strerr(no), no); + return total_read; + } + total_read += received_size; + } + return total_read; +} + +/* ********************************************************** */ + +Array &HTTPD_Connection::headers() { + return request->headers.headers; +} + +const char *HTTPD_Connection::method() { + return request->method; +} + +const char *HTTPD_Connection::uri() { + return request->uri; +} + +const char *HTTPD_Connection::content_type() { + return request->headers.content_type.cstr(); +} + +uint64_t HTTPD_Connection::content_length(){ + return request->headers.content_length; +} + +bool HTTPD_Connection::read_header(){ + request = new HTTPD_request(); + bool result = request->read_header(sock); + LOG(if(result){ + pa_log("httpd [%d] got %s \"%s\"", sock, method(), uri()); + }) + return result; +} + +size_t HTTPD_Connection::read_post(char *body, size_t max_bytes) { + return request->read_post(sock, body, max_bytes); +} + +size_t HTTPD_Connection::send_body(const void *buf, size_t size) { + LOG(pa_log("httpd [%d] response %d bytes", sock, size)); + LOG(pa_log("httpd [%d] %s", sock, buf)); + ssize_t result=pa_send(sock, (const char*)buf, size); + if(result < 0) { + int no=pa_socks_errno(); + throw Exception("httpd.write", 0, "error sending response: %s (%d)", pa_socks_strerr(no), no); + } + return result; +} + +HTTPD_Connection::~HTTPD_Connection(){ + if(sock != INVALID_SOCKET){ + LOG(pa_log("httpd [%d] closed", sock)); + closesocket(sock); + } +} + +static int sock_ready(SOCKET fd, int timeout_value){ + struct timeval timeout = {0, timeout_value * 1000}; + fd_set fds; + FD_ZERO(&fds); + FD_SET(fd, &fds); + int nfds = (int)fd + 1; /* typecast as nfds is ignored in MSVC anyway */ + return select(nfds, &fds, NULL, NULL, &timeout)>0; /* read */ +} + +bool HTTPD_Connection::accept(SOCKET server_sock, int timeout_value) { + int ready = sock_ready(server_sock, timeout_value); + if (ready < 0) { + int no=pa_socks_errno(); + if(no == EINTR) + return false; + throw Exception("httpd.accept", 0, "error waiting for connection: %s (%d)", pa_socks_strerr(no), no); + } + if (ready == 0) + return false; /* Timeout */ + + struct sockaddr_in addr; + socklen_t sock_addr_len = sizeof(struct sockaddr_in); + memset(&addr, 0, sock_addr_len); + + sock = ::accept(server_sock, (struct sockaddr *)&addr, &sock_addr_len); + if(sock == INVALID_SOCKET){ + int no=pa_socks_errno(); + throw Exception("httpd.accept", 0, "error accepting connection: %s (%d)", pa_socks_strerr(no), no); + } + +// Has no positive performance effect, requires include +// static int sock_on=1; +// setsockopt(sock, IPPROTO_TCP, TCP_NODELAY, (char *)&sock_on, sizeof(sock_on)); + + remote_addr = pa_strdup(inet_ntoa(addr.sin_addr)); + LOG(pa_log("httpd [%d] accepted from %s", sock, remote_addr)); + return true; +} + +HTTPD_Server::HTTPD_MODE HTTPD_Server::mode = HTTPD_Server::SEQUENTIAL; +const char *HTTPD_Server::port=NULL; + +void HTTPD_Server::set_mode(const String &value){ + if(value == "sequental") mode = SEQUENTIAL; +#ifdef HAVE_TLS + else if (value == "threaded") mode = MULTITHREADED; +#endif +#ifdef _MSC_VER + else throw Exception("httpd.mode", &value, "$MAIN:HTTPD.mode must be 'sequental' or 'threaded'"); +#else + else if (value == "parallel") mode = PARALLEL; + else throw Exception("httpd.mode", &value, "$MAIN:HTTPD.mode must be 'sequental', 'parallel' or 'threaded'"); +#endif +} + +SOCKET HTTPD_Server::bind(const char *host_port){ + struct sockaddr_in me; + + port = strchr(host_port, ':'); + const char *host = NULL; + if(port){ + if(port > host_port) + host = pa_strdup(host_port, port - host_port); + port += 1; + } else { + port = host_port; + } + + if(!set_addr(&me, host, (short)pa_atoui(port))){ + if (host) + throw Exception("httpd.bind", 0, "cannot resolve hostname \"%s\"", host); + me.sin_addr.s_addr=INADDR_ANY; + } + + SOCKET sock = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP/*0*/); + + if(sock == INVALID_SOCKET){ + int no=pa_socks_errno(); + throw Exception("httpd.bind", 0, "cannot make socket: %s (%d)", pa_socks_strerr(no), no); + } + + static int sock_on = 1; + + if (setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, (char *)&sock_on, sizeof(sock_on)) || + setsockopt(sock, SOL_SOCKET, SO_KEEPALIVE, (char *)&sock_on, sizeof(sock_on)) || + ::bind(sock, (struct sockaddr*)&me, sizeof(me)) || + listen(sock, 16)) { + closesocket(sock); + int no = pa_socks_errno(); + throw Exception("httpd.bind", 0, "cannot bind socket: %s (%d)", pa_socks_strerr(no), no); + } + return sock; +}