Annotation of parser3/src/types/pa_vform.C, revision 1.100
1.27 paf 1: /** @file
2: Parser: @b form class.
1.10 paf 3:
1.95 misha 4: Copyright(c) 2001-2009 ArtLebedev Group (http://www.artlebedev.com)
1.52 paf 5: Author: Alexandr Petrosian <paf@design.ru> (http://paf.design.ru)
1.39 parser 6:
1.38 parser 7: based on The CGI_C library, by Thomas Boutell.
1.3 paf 8: */
1.59 paf 9:
1.100 ! misha 10: static const char * const IDENT_VFORM_C="$Date: 2009-08-22 14:06:14 $";
1.3 paf 11:
1.14 paf 12: #include "pa_sapi.h"
1.1 paf 13: #include "pa_vform.h"
14: #include "pa_vstring.h"
1.3 paf 15: #include "pa_globals.h"
16: #include "pa_request.h"
1.9 paf 17: #include "pa_vfile.h"
1.21 paf 18: #include "pa_common.h"
1.30 parser 19: #include "pa_vtable.h"
1.50 paf 20: #include "pa_charset.h"
1.86 misha 21: //#include "pa_charsets.h"
1.3 paf 22:
1.62 paf 23: // defines
24:
25: //#define DEBUG_POST
26:
1.3 paf 27: // parse helper funcs
28:
1.75 paf 29: static size_t getHeader(const char* data, size_t len){
1.97 misha 30: size_t i;
31: int enter=-1;
32: if (data)
1.62 paf 33: for (i=0;i<len;i++)
34: if (data[i]=='\n'){
35: if (enter>=0) enter++;
36: if (enter>1) return i;
37: } else if (data[i]!='\r') enter=0;
1.100 ! misha 38: return 0;
1.3 paf 39: }
40:
1.75 paf 41: static const char* searchAttribute(const char* data,
42: const char* attr, //< expected to be lowercased
1.62 paf 43: size_t len){
1.97 misha 44: size_t i;
45: if (data)
1.62 paf 46: for (i=0;i<len;i++)
1.83 paf 47: if (tolower((unsigned char)data[i])==*attr){
1.62 paf 48: size_t j;
49: for (j=i+1;j<=len;j++)
50: if (!attr[j-i]) return &data[j];
51: else {
52: if (j==len) break;
1.83 paf 53: if (attr[j-i]!=tolower((unsigned char)data[j])) break;
1.62 paf 54: }
55: }
56:
57: return NULL;
1.3 paf 58: }
59:
60: // VForm
61:
1.75 paf 62: extern Methoded* form_base_class;
1.57 paf 63:
1.77 paf 64: VForm::VForm(Request_charsets& acharsets, Request_info& arequest_info): VStateless_class(0, form_base_class),
65: fcharsets(acharsets),
66: frequest_info(arequest_info),
67: filled_source(0),
1.91 misha 68: filled_client(0),
1.96 misha 69: fpost_charset(0)
70: {
71: is_post=(arequest_info.method && StrStartFromNC(arequest_info.method, "post", true));
1.99 misha 72: is_post_charset_detected=false;
1.96 misha 73:
74: post_content_type=UNKNOWN;
75: if(is_post && arequest_info.content_type)
1.99 misha 76: if(StrStartFromNC(arequest_info.content_type, HTTP_CONTENT_TYPE_FORM_URLENCODED))
1.96 misha 77: post_content_type=FORM_URLENCODED;
1.99 misha 78: else if(StrStartFromNC(arequest_info.content_type, HTTP_CONTENT_TYPE_MULTIPART_FORMDATA))
1.96 misha 79: post_content_type=MULTIPART_FORMDATA;
1.3 paf 80: }
81:
1.92 misha 82: char *VForm::strpart(const char* str, size_t len) {
1.96 misha 83: char *result=new(PointerFreeGC) char[len+1];
84: memcpy(result, str, len);
85: result[len]=0;
86: return result;
1.92 misha 87: }
88:
1.75 paf 89: char *VForm::getAttributeValue(const char* data, char *attr, size_t len) {
1.96 misha 90: const char* value=searchAttribute(data, attr, len);
91: if (value){
1.18 paf 92: size_t i;
93: if (!(len-=value-data)) return NULL;
94: if (*value=='"') {
95: for (i=1;i<len;i++) if (value[i]=='"') break;
96: return strpart(&value[1], i-1);
97: } else {
98: for (i=0;i<len;i++) if (strchr(" ;\"\n\r", value[i])) break;
99: return strpart(value, i);
100: }
1.96 misha 101: }
102: return NULL;
1.3 paf 103: }
104:
1.96 misha 105: String::C VForm::transcode(const char* client, size_t client_size, Charset* client_charset) {
1.75 paf 106: return Charset::transcode(
1.96 misha 107: String::C(strdup(client, client_size), client_size),
108: client_charset?*client_charset:fcharsets.client(),
109: fcharsets.source());
1.49 paf 110: }
111:
1.75 paf 112: void VForm::ParseGetFormInput(const char* query_string, size_t length) {
1.42 parser 113: ParseFormInput(query_string, length);
1.3 paf 114: }
115:
1.69 paf 116:
1.75 paf 117: static int atoi(const char* data, size_t alength) {
1.69 paf 118: char buf[MAX_STRING];
1.82 paf 119: size_t length=min(alength, sizeof(buf)-1);
120: memcpy(buf, data, length); buf[length]=0;
1.69 paf 121: return atoi(buf);
122: }
1.96 misha 123:
124: void VForm::ParseFormInput(const char* data, size_t length, Charset* client_charset) {
1.68 paf 125: // cut out ?image_map_tail
126: {
1.67 paf 127: for(size_t pos=0; pos<length; pos++) {
128: if(data[pos]=='?') {
1.69 paf 129: size_t start=pos+1;
130: size_t aftercomma=start;
131: size_t lookingcomma=start;
1.96 misha 132: for(; lookingcomma<length; lookingcomma++)
1.69 paf 133: if(data[lookingcomma]==',') {
134: aftercomma=++lookingcomma;
135: break;
136: }
137:
138: if(aftercomma>start) { // ?x,y
139: int x=atoi(data+start, aftercomma-1-start);
140: int y=atoi(data+aftercomma, length-aftercomma);
1.75 paf 141: imap.put(String("x"), new VInt(x));
142: imap.put(String("y"), new VInt(y));
1.69 paf 143: } else { // ?qtail
1.96 misha 144: AppendFormEntry("qtail", data+start, length-start, client_charset);
1.69 paf 145: }
1.67 paf 146: // cut tail
147: length=pos;
148: break;
149: }
150: }
151: }
1.68 paf 152: // Scan for pairs, unescaping and storing them as they are found
153: for(size_t pos=0; pos<length; ) {
1.16 paf 154: size_t start=pos;
1.68 paf 155: size_t finish=length;
1.96 misha 156: for(; pos<length; pos++)
1.68 paf 157: if(data[pos]=='&') {
158: finish=pos++;
1.3 paf 159: break;
160: }
1.68 paf 161:
162: size_t aftereq=start;
163: size_t lookingeq=start;
1.96 misha 164: for(; lookingeq<finish; lookingeq++)
1.68 paf 165: if(data[lookingeq]=='=') {
166: aftereq=++lookingeq;
1.3 paf 167: break;
168: }
1.45 paf 169:
1.96 misha 170: const char* attr=(aftereq>start)?unescape_chars(data+start, aftereq-1-start, &fcharsets.client()):"nameless";
1.91 misha 171: char *value=unescape_chars(data+aftereq, finish-aftereq, &fcharsets.client());
1.96 misha 172: AppendFormEntry(attr, value, strlen(value), client_charset);
1.3 paf 173: }
174: }
175:
1.92 misha 176: static char* pa_tolower(char *str){
177: if(!str)
178: return 0;
179: for(char *p=str; *p; p++)
180: *p=(char)tolower((unsigned char)*p);
181: return str;
182: }
183:
1.49 paf 184: void VForm::ParseMimeInput(
1.96 misha 185: char *content_type,
186: const char* data, size_t length, Charset* client_charset) {
1.3 paf 187: /* Scan for mime-presented pairs, storing them as they are found. */
1.92 misha 188: const char* boundary=pa_tolower(getAttributeValue(content_type, "boundary=", strlen(content_type)));
189: if(!boundary)
1.54 paf 190: throw Exception(0,
1.18 paf 191: 0,
1.3 paf 192: "VForm::ParseMimeInput no boundary attribute of Content-Type");
193:
1.92 misha 194: const char* lastData=&data[length];
195:
1.3 paf 196: while(true) {
1.66 paf 197: const char
1.18 paf 198: *dataStart=searchAttribute(data, boundary, lastData-data),
199: *dataEnd=searchAttribute(dataStart, boundary, lastData-dataStart);
1.92 misha 200:
1.18 paf 201: size_t headerSize=getHeader(dataStart, lastData-dataStart);
1.3 paf 202:
203: if(!dataStart|!dataEnd|!headerSize) break;
1.47 paf 204: if(searchAttribute(dataStart, "content-disposition: form-data", headerSize)) {
1.16 paf 205: size_t valueSize=(dataEnd-dataStart)-headerSize-5-strlen(boundary);
1.18 paf 206: char *attr=getAttributeValue(dataStart, " name=", headerSize),
207: *fName=getAttributeValue(dataStart, " filename=", headerSize);
1.3 paf 208:
1.78 paf 209: if(attr) {
1.3 paf 210: /* OK, we have a new pair, add it to the list. */
1.80 paf 211: // fName checks are because MSIE passes unassigned <input type=file> as filename="" and empty body
1.85 misha 212: if( fName && (strlen(fName) || valueSize) ){
1.100 ! misha 213: AppendFormFileEntry(attr,
! 214: valueSize? &dataStart[headerSize+1]: "",
! 215: valueSize,
1.96 misha 216: fName,
1.100 ! misha 217: client_charset);
1.85 misha 218: } else {
1.100 ! misha 219: AppendFormEntry(attr,
! 220: valueSize? &dataStart[headerSize+1]: "",
1.96 misha 221: valueSize,
1.100 ! misha 222: client_charset);
1.85 misha 223: }
1.3 paf 224: }
225: }
226: data=(dataEnd-strlen(boundary));
227: }
228: }
229:
1.85 misha 230: void VForm::AppendFormFileEntry(const char* cname_cstr,
1.96 misha 231: const char* raw_cvalue_ptr, const size_t raw_cvalue_size,
232: const char* file_name_cstr, Charset* client_charset){
1.85 misha 233:
1.87 misha 234: const char* fname = strdup(file_name_cstr);
1.96 misha 235: const String& sfile_name=*new String(transcode(fname, strlen(fname), client_charset));
1.87 misha 236:
1.96 misha 237: const String& sname=*new String(transcode(cname_cstr, strlen(cname_cstr), client_charset));
1.87 misha 238: // maybe transcode text/* files?
1.89 misha 239: // NO!!! some users want to upload file 'as is' or file encoding can be unknown
1.87 misha 240:
1.85 misha 241: VFile* vfile=new VFile;
242: vfile->set(true/*tainted*/, raw_cvalue_ptr, raw_cvalue_size, sfile_name.cstr());
243:
244: fields.put_dont_replace(sname, vfile);
245:
246: // files
247: Value* vhash=files.get(sname);
248: if(!vhash){
249: // first appearence
250: vhash=new VHash;
251: files.put(sname, vhash);
252: }
253: HashStringValue& hash=*vhash->get_hash();
1.75 paf 254:
1.85 misha 255: hash.put(String::Body::Format(hash.count()), vfile);
256: }
257:
1.96 misha 258: void VForm::AppendFormEntry(const char* cname_cstr, const char* raw_cvalue_ptr, const size_t raw_cvalue_size, Charset* client_charset) {
259: const String& sname=*new String(transcode(cname_cstr, strlen(cname_cstr), client_charset));
1.75 paf 260:
1.85 misha 261: const char* premature_zero_pos=(const char* )memchr(raw_cvalue_ptr, 0, raw_cvalue_size);
262: size_t cvalue_size=premature_zero_pos?premature_zero_pos-(const char* )raw_cvalue_ptr
263: :raw_cvalue_size;
264: char *cvalue_ptr=strdup(raw_cvalue_ptr, cvalue_size);
265: fix_line_breaks(cvalue_ptr, cvalue_size);
1.96 misha 266: String& string=*new String(transcode(cvalue_ptr, cvalue_size, client_charset), String::L_TAINTED);
1.85 misha 267:
268: // tables
269: {
270: Value* vtable=tables.get(sname);
271: if(!vtable) {
272: // first appearence
273: Table::columns_type columns(new ArrayString(1));
274: *columns+=new String("field");
1.75 paf 275:
1.85 misha 276: vtable=new VTable(new Table(columns));
277: tables.put(sname, vtable);
1.36 parser 278: }
1.85 misha 279: Table& table=*vtable->get_table();
280:
281: // this string becomes next row
282: Table::element_type row(new ArrayString(1));
283: *row+=&string;
284: table+=row;
1.3 paf 285: }
1.69 paf 286:
1.85 misha 287: fields.put_dont_replace(sname, new VString(string));
1.69 paf 288: }
289:
1.85 misha 290:
291: void VForm::refill_fields_tables_and_files() {
1.77 paf 292: fields.clear();
293: tables.clear();
1.85 misha 294: files.clear();
1.77 paf 295: imap.clear();
1.75 paf 296:
1.77 paf 297: //frequest_info.query_string="a=123";
1.3 paf 298: // parsing QS [GET and ?name=value from uri rewrite)]
1.77 paf 299: if(frequest_info.query_string) {
300: size_t length=strlen(frequest_info.query_string);
301: char *buf=strdup(frequest_info.query_string, length);
1.42 parser 302: ParseGetFormInput(buf, length);
303: }
1.62 paf 304:
305: #ifdef DEBUG_POST
1.77 paf 306: frequest_info.method="POST";
1.96 misha 307: File_read_result file=file_read(fcharsets, *new String("test.stdin"), true/*as_text*/, 0, true, 0, 0, 0, false/*transcode*/);
308: frequest_info.post_size=file.length;
309: frequest_info.post_data=(char*)file.str;
1.77 paf 310: frequest_info.content_type="multipart/form-data; boundary=----------mcqY2UDNcdEAoN1mLmne2i";
1.62 paf 311:
312: #endif
1.57 paf 313:
314: // parsing POST data
1.96 misha 315: if(is_post && frequest_info.content_type)
316: switch(post_content_type){
317: case FORM_URLENCODED:
318: {
1.99 misha 319: detect_post_charset();
1.96 misha 320: ParseFormInput(frequest_info.post_data, frequest_info.post_size, fpost_charset);
321: break;
322: }
323: case MULTIPART_FORMDATA:
324: {
325: ParseMimeInput(strdup(frequest_info.content_type), frequest_info.post_data, frequest_info.post_size);
326: break;
327: }
328: }
1.56 paf 329:
1.77 paf 330: filled_source=&fcharsets.source();
331: filled_client=&fcharsets.client();
332: }
333:
1.99 misha 334: void VForm::detect_post_charset(){
335: if(is_post && !is_post_charset_detected){
336: fpost_charset=detect_charset(frequest_info.content_type);
337: is_post_charset_detected=true;
338: }
339: }
340:
1.85 misha 341: bool VForm::should_refill_fields_tables_and_files() {
1.96 misha 342: return &fcharsets.source()!=filled_source || &fcharsets.client()!=filled_client;
1.1 paf 343: }
1.33 parser 344:
1.98 misha 345: Value* VForm::get_element(const String& aname) {
1.85 misha 346: if(should_refill_fields_tables_and_files())
347: refill_fields_tables_and_files();
1.56 paf 348:
1.36 parser 349: // $fields
350: if(aname==FORM_FIELDS_ELEMENT_NAME)
1.75 paf 351: return new VHash(fields);
1.36 parser 352:
353: // $tables
354: if(aname==FORM_TABLES_ELEMENT_NAME)
1.75 paf 355: return new VHash(tables);
1.69 paf 356:
1.85 misha 357: // $files
358: if(aname==FORM_FILES_ELEMENT_NAME)
359: return new VHash(files);
360:
1.77 paf 361: // $imap
1.69 paf 362: if(aname==FORM_IMAP_ELEMENT_NAME)
1.75 paf 363: return new VHash(imap);
1.36 parser 364:
1.96 misha 365: // CLASS, CLASS_NAME
1.98 misha 366: if(Value* result=VStateless_class::get_element(aname))
1.33 parser 367: return result;
368:
1.95 misha 369: // $field
1.75 paf 370: return fields.get(aname);
1.72 paf 371: }
1.93 misha 372:
373: Charset* VForm::get_post_charset(){
1.99 misha 374: detect_post_charset();
1.96 misha 375: return fpost_charset;
1.93 misha 376: }
E-mail: