XRootD
Loading...
Searching...
No Matches
XrdOucPrivateUtils.hh File Reference
#include "XrdOuc/XrdOucString.hh"
#include <regex>
#include <string>
#include <unordered_set>
#include <string_view>
#include <vector>
Include dependency graph for XrdOucPrivateUtils.hh:
This graph shows which files directly or indirectly include this file:

Go to the source code of this file.

Functions

static bool is_subdirectory (const std::string_view dir, const std::string_view subdir)
std::string obfuscateAuth (const std::string &input)
void splitHostCgi (std::string_view target, std::string &host, std::string &cgi)
void stripCgi (std::string &url, const std::unordered_set< std::string > &cgiKeys)
void stripCgi (XrdOucString &url, const std::unordered_set< std::string > &cgiKeys)

Function Documentation

◆ is_subdirectory()

bool is_subdirectory ( const std::string_view dir,
const std::string_view subdir )
inlinestatic

PRIVATE HEADER for utility functions, implementation in XrdOucUtils.cc Returns true if path subdir is a subdirectory of dir.

Definition at line 37 of file XrdOucPrivateUtils.hh.

39{
40 if (subdir.size() < dir.size() || dir.empty())
41 return false;
42
43 if (subdir.compare(0, dir.size(), dir, 0, dir.size()) != 0)
44 return false;
45
46 return dir.size() == subdir.size() || subdir[dir.size()] == '/' || dir.back() == '/';
47}

References is_subdirectory().

Referenced by is_subdirectory().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ obfuscateAuth()

std::string obfuscateAuth ( const std::string & input)

Obfuscates strings containing "authz=value", "Authorization: value", "TransferHeaderAuthorization: value", "WhateverAuthorization: value" in a case insensitive way.

Parameters
inputthe string to obfuscate

This function obfuscates away authz= cgi elements and/or HTTP authorization headers from URL or other log line strings which might contain them.

Parameters
inputthe string to obfuscate
Returns
the string with token values obfuscated

Definition at line 1637 of file XrdOucUtils.cc.

1638{
1639 static const regex_t auth_regex = []() {
1640 constexpr char re[] =
1641 "(authz=|(transferheader)?(www-|proxy-)?auth(orization|enticate)([[:space:]]*:[[:space:]]*|[[:space:]]+))"
1642 "(Bearer([[:space:]]|%20)?(token([[:space:]]|%20)?)?)?";
1643
1644 regex_t regex;
1645
1646 if (regcomp(&regex, re, REG_EXTENDED | REG_ICASE) != 0)
1647 throw std::runtime_error("Failed to compile regular expression");
1648
1649 return regex;
1650 }();
1651
1652 regmatch_t match;
1653 size_t offset = 0;
1654 std::string redacted;
1655 const char *const text = input.c_str();
1656
1657 while (regexec(&auth_regex, text + offset, 1, &match, 0) == 0) {
1658 redacted.append(text + offset, match.rm_eo).append("REDACTED");
1659
1660 offset += match.rm_eo;
1661
1662 while (offset < input.size() && is_token_character(input[offset]))
1663 ++offset;
1664 }
1665
1666 return redacted.append(text + offset);
1667}
static bool is_token_character(int c)

References is_token_character(), and obfuscateAuth().

Referenced by XrdPfc::Cache::Attach(), XrdClHttp::HeaderBuilder::Build(), XrdPosixXrootd::Close(), XrdPosixFile::DelayedDestroy(), XrdPosixFile::DelayedDestroy(), XrdPosixPrepIO::Disable(), XrdPssSys::FSctl(), XrdPssCks::Get(), XrdCl::URL::GetObfuscatedURL(), XrdCl::Utils::LogPropertyList(), main(), XrdPssSys::Mkdir(), obfuscateAuth(), XrdPssFile::Open(), XrdPssDir::Opendir(), XrdCl::CopyProcess::Prepare(), XrdHttpProtocol::Process(), XrdHttpReq::ProcessHTTPReq(), XrdPssSys::Remdir(), XrdPssSys::Rename(), XrdCl::Message::SetDescription(), XrdPssSys::Stat(), XrdPssSys::Truncate(), and XrdPssSys::Unlink().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ splitHostCgi()

void splitHostCgi ( std::string_view target,
std::string & host,
std::string & cgi )

Split a "host[?cgi]" string at its first '?'.

Parameters
targetthe "host[?cgi]" string to split
hostoutput: the portion before the first '?', or the whole string when target contains no '?'
cgioutput: the first '?' and everything after it (so it begins with '?'), or empty when target contains no '?'

Definition at line 1778 of file XrdOucUtils.cc.

1780{
1781 const size_t q = target.find('?');
1782 if (q == std::string::npos) {host.assign(target); cgi.clear();}
1783 else {host.assign(target.data(), q);
1784 cgi.assign(target.data() + q, target.size() - q);
1785 }
1786}

References splitHostCgi().

Referenced by XrdXrootdRedirHelper::Redirect(), and splitHostCgi().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ stripCgi() [1/2]

void stripCgi ( std::string & url,
const std::unordered_set< std::string > & cgiKeys )

Strip selected CGI elements (e.g. "authz=...") from a string/URL. The function removes occurrences of "<key>=<token>" for each key in cgiKeys

Parameters
urlthe string/URL to sanitize (modified in-place)
cgiKeysCGI parameter names to remove (without the trailing '=')

Strip selected CGI elements (e.g. "authz=...") from a string/URL.

Parameters
urlthe string/URL to sanitize
cgiKeysCGI parameter names to remove (without the trailing '=')

Definition at line 1744 of file XrdOucUtils.cc.

1745{
1746 for (const auto &key : cgiKeys) {
1747 if (key.empty())
1748 continue;
1749
1750 const std::string needle = key + "=";
1751 size_t spos = 0, epos = 0;
1752
1753 while ((spos = url.find(needle, spos)) != std::string::npos) {
1754 epos = spos;
1755 while (epos < url.size() && is_token_character(url[epos]))
1756 ++epos;
1757 url.erase(spos, epos - spos);
1758 }
1759 }
1760
1761 // If a stripped CGI was the first element, remove the extra &
1762 size_t spos = 0;
1763 if ((spos = url.find("?&")) != std::string::npos)
1764 url.erase(spos + 1, 1);
1765
1766 // If stripping removed the only query parameter, remove the dangling ?
1767 if (!url.empty() && url.back() == '?')
1768 url.pop_back();
1769}

References is_token_character(), and stripCgi().

Referenced by XrdHttpReq::Redir(), stripCgi(), and stripCgi().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ stripCgi() [2/2]

void stripCgi ( XrdOucString & url,
const std::unordered_set< std::string > & cgiKeys )

Definition at line 1771 of file XrdOucUtils.cc.

1772{
1773 std::string tmp = url.c_str();
1774 stripCgi(tmp, cgiKeys);
1775 url = tmp.c_str();
1776}
void stripCgi(std::string &url, const std::unordered_set< std::string > &cgiKeys)
const char * c_str() const

References XrdOucString::c_str(), and stripCgi().

Here is the call graph for this function: