diff options
Diffstat (limited to 'src/network/access/qhttpheaderparser.cpp')
-rw-r--r-- | src/network/access/qhttpheaderparser.cpp | 164 |
1 files changed, 75 insertions, 89 deletions
diff --git a/src/network/access/qhttpheaderparser.cpp b/src/network/access/qhttpheaderparser.cpp index 4a6bbd49a7..0b7882c18a 100644 --- a/src/network/access/qhttpheaderparser.cpp +++ b/src/network/access/qhttpheaderparser.cpp @@ -1,44 +1,10 @@ -/**************************************************************************** -** -** Copyright (C) 2021 The Qt Company Ltd. -** Contact: https://www.qt.io/licensing/ -** -** This file is part of the QtNetwork module of the Qt Toolkit. -** -** $QT_BEGIN_LICENSE:LGPL$ -** Commercial License Usage -** Licensees holding valid commercial Qt licenses may use this file in -** accordance with the commercial license agreement provided with the -** Software or, alternatively, in accordance with the terms contained in -** a written agreement between you and The Qt Company. For licensing terms -** and conditions see https://www.qt.io/terms-conditions. For further -** information use the contact form at https://www.qt.io/contact-us. -** -** GNU Lesser General Public License Usage -** Alternatively, this file may be used under the terms of the GNU Lesser -** General Public License version 3 as published by the Free Software -** Foundation and appearing in the file LICENSE.LGPL3 included in the -** packaging of this file. Please review the following information to -** ensure the GNU Lesser General Public License version 3 requirements -** will be met: https://www.gnu.org/licenses/lgpl-3.0.html. -** -** GNU General Public License Usage -** Alternatively, this file may be used under the terms of the GNU -** General Public License version 2.0 or (at your option) the GNU General -** Public license version 3 or any later version approved by the KDE Free -** Qt Foundation. The licenses are as published by the Free Software -** Foundation and appearing in the file LICENSE.GPL2 and LICENSE.GPL3 -** included in the packaging of this file. Please review the following -** information to ensure the GNU General Public License requirements will -** be met: https://www.gnu.org/licenses/gpl-2.0.html and -** https://www.gnu.org/licenses/gpl-3.0.html. -** -** $QT_END_LICENSE$ -** -****************************************************************************/ +// Copyright (C) 2022 The Qt Company Ltd. +// SPDX-License-Identifier: LicenseRef-Qt-Commercial OR LGPL-3.0-only OR GPL-2.0-only OR GPL-3.0-only #include "qhttpheaderparser_p.h" +#include <algorithm> + QT_BEGIN_NAMESPACE QHttpHeaderParser::QHttpHeaderParser() @@ -57,36 +23,69 @@ void QHttpHeaderParser::clear() fields.clear(); } +static bool fieldNameCheck(QByteArrayView name) +{ + static constexpr QByteArrayView otherCharacters("!#$%&'*+-.^_`|~"); + static const auto fieldNameChar = [](char c) { + return ('a' <= c && c <= 'z') || ('A' <= c && c <= 'Z') || ('0' <= c && c <= '9') + || otherCharacters.contains(c); + }; + + return !name.empty() && std::all_of(name.begin(), name.end(), fieldNameChar); +} + bool QHttpHeaderParser::parseHeaders(QByteArrayView header) { // see rfc2616, sec 4 for information about HTTP/1.1 headers. // allows relaxed parsing here, accepts both CRLF & LF line endings - int i = 0; - while (i < header.size()) { - int j = header.indexOf(':', i); // field-name - if (j == -1) - break; - QByteArrayView field = header.sliced(i, j - i).trimmed(); - j++; - // any number of LWS is allowed before and after the value + Q_ASSERT(fields.isEmpty()); + const auto hSpaceStart = [](QByteArrayView h) { + return h.startsWith(' ') || h.startsWith('\t'); + }; + // Headers, if non-empty, start with a non-space and end with a newline: + if (hSpaceStart(header) || (!header.empty() && !header.endsWith('\n'))) + return false; + + while (int tail = header.endsWith("\n\r\n") ? 2 : header.endsWith("\n\n") ? 1 : 0) + header.chop(tail); + + if (header.size() - (header.endsWith("\r\n") ? 2 : 1) > maxTotalSize) + return false; + + QHttpHeaders result; + while (!header.empty()) { + const qsizetype colon = header.indexOf(':'); + if (colon == -1) // if no colon check if empty headers + return result.isEmpty() && (header == "\n" || header == "\r\n"); + if (result.size() >= maxFieldCount) + return false; + QByteArrayView name = header.first(colon); + if (!fieldNameCheck(name)) + return false; + header = header.sliced(colon + 1); QByteArray value; + qsizetype valueSpace = maxFieldSize - name.size() - 1; do { - i = header.indexOf('\n', j); - if (i == -1) - break; - if (!value.isEmpty()) - value += ' '; - // check if we have CRLF or only LF - bool hasCR = i && header[i - 1] == '\r'; - int length = i - (hasCR ? 1: 0) - j; - value += header.sliced(j, length).trimmed(); - j = ++i; - } while (i < header.size() && (header.at(i) == ' ' || header.at(i) == '\t')); - if (i == -1) - return false; // something is wrong - - fields.append(qMakePair(field.toByteArray(), value)); + const qsizetype endLine = header.indexOf('\n'); + Q_ASSERT(endLine != -1); + auto line = header.first(endLine); // includes space + valueSpace -= line.size() - (line.endsWith('\r') ? 1 : 0); + if (valueSpace < 0) + return false; + line = line.trimmed(); + if (!line.empty()) { + if (value.size()) + value += ' ' + line; + else + value = line.toByteArray(); + } + header = header.sliced(endLine + 1); + } while (hSpaceStart(header)); + Q_ASSERT(name.size() + 1 + value.size() <= maxFieldSize); + result.append(name, value); } + + fields = result; return true; } @@ -103,7 +102,7 @@ bool QHttpHeaderParser::parseStatus(QByteArrayView status) static const int spacePos = 8; static const char httpMagic[] = "HTTP/"; - if (status.length() < minLength + if (status.size() < minLength || !status.startsWith(httpMagic) || status.at(dotPos) != '.' || status.at(spacePos) != ' ') { @@ -116,11 +115,11 @@ bool QHttpHeaderParser::parseStatus(QByteArrayView status) minorVersion = status.at(dotPos + 1) - '0'; int i = spacePos; - int j = status.indexOf(' ', i + 1); + qsizetype j = status.indexOf(' ', i + 1); const QByteArrayView code = j > i ? status.sliced(i + 1, j - i - 1) : status.sliced(i + 1); - bool ok; + bool ok = false; statusCode = code.toInt(&ok); reasonPhrase = j > i ? QString::fromLatin1(status.sliced(j + 1)) @@ -129,62 +128,49 @@ bool QHttpHeaderParser::parseStatus(QByteArrayView status) return ok && uint(majorVersion) <= 9 && uint(minorVersion) <= 9; } -const QList<QPair<QByteArray, QByteArray> >& QHttpHeaderParser::headers() const +const QHttpHeaders& QHttpHeaderParser::headers() const { return fields; } -QByteArray QHttpHeaderParser::firstHeaderField(const QByteArray &name, +QByteArray QHttpHeaderParser::firstHeaderField(QByteArrayView name, const QByteArray &defaultValue) const { - for (auto it = fields.constBegin(); it != fields.constEnd(); ++it) { - if (name.compare(it->first, Qt::CaseInsensitive) == 0) - return it->second; - } - return defaultValue; + return fields.value(name, defaultValue).toByteArray(); } -QByteArray QHttpHeaderParser::combinedHeaderValue(const QByteArray &name, const QByteArray &defaultValue) const +QByteArray QHttpHeaderParser::combinedHeaderValue(QByteArrayView name, const QByteArray &defaultValue) const { const QList<QByteArray> allValues = headerFieldValues(name); if (allValues.isEmpty()) return defaultValue; - else - return allValues.join(", "); + return allValues.join(", "); } -QList<QByteArray> QHttpHeaderParser::headerFieldValues(const QByteArray &name) const +QList<QByteArray> QHttpHeaderParser::headerFieldValues(QByteArrayView name) const { - QList<QByteArray> result; - for (auto it = fields.constBegin(); it != fields.constEnd(); ++it) - if (name.compare(it->first, Qt::CaseInsensitive) == 0) - result += it->second; - - return result; + return fields.values(name); } -void QHttpHeaderParser::removeHeaderField(const QByteArray &name) +void QHttpHeaderParser::removeHeaderField(QByteArrayView name) { - auto firstEqualsName = [&name](const QPair<QByteArray, QByteArray> &header) { - return name.compare(header.first, Qt::CaseInsensitive) == 0; - }; - fields.removeIf(firstEqualsName); + fields.removeAll(name); } void QHttpHeaderParser::setHeaderField(const QByteArray &name, const QByteArray &data) { removeHeaderField(name); - fields.append(qMakePair(name, data)); + fields.append(name, data); } void QHttpHeaderParser::prependHeaderField(const QByteArray &name, const QByteArray &data) { - fields.prepend(qMakePair(name, data)); + fields.insert(0, name, data); } void QHttpHeaderParser::appendHeaderField(const QByteArray &name, const QByteArray &data) { - fields.append(qMakePair(name, data)); + fields.append(name, data); } void QHttpHeaderParser::clearHeaders() |