XRootD
Loading...
Searching...
No Matches
XrdClHttp::HeaderBuilder Namespace Reference

Typedefs

using HeaderList = std::vector<std::pair<std::string, std::string>>

Functions

void AppendMissing (const HeaderList &extra, HeaderList &headers)
bool Build (const std::string_view spec, HeaderList &headers)
bool CompareIgnoreCase (const std::string_view lhs, const std::string_view rhs)
bool IsForbiddenHeader (const std::string_view name)

Typedef Documentation

◆ HeaderList

using XrdClHttp::HeaderBuilder::HeaderList = std::vector<std::pair<std::string, std::string>>

Definition at line 16 of file XrdClHttpHeaderBuilder.hh.

Function Documentation

◆ AppendMissing()

void XrdClHttp::HeaderBuilder::AppendMissing ( const HeaderList & extra,
HeaderList & headers )

Definition at line 101 of file XrdClHttpHeaderBuilder.cc.

102{
103 for (const auto &header : extra) {
104 const auto present = std::any_of(headers.cbegin(), headers.cend(),
105 [&header](const auto &existing) {
106 return CompareIgnoreCase(existing.first, header.first);
107 });
108 if (!present) {
109 headers.emplace_back(header);
110 }
111 }
112}
int extra
Definition XrdAccTest.cc:63

References AppendMissing(), and extra.

Referenced by AppendMissing(), and XrdClHttp::CurlOperation::FinishSetup().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ Build()

bool XrdClHttp::HeaderBuilder::Build ( const std::string_view spec,
HeaderList & headers )
nodiscard

Definition at line 115 of file XrdClHttpHeaderBuilder.cc.

116{
118
119 headers.clear();
120
121 // Walk the newline separated entries, reporting every unusable one so a user
122 // who wrote several mistakes sees them all at once.
123 // An empty specification simply yields no headers.
124 HeaderList requested;
125 bool usable = true;
126 for (auto pos = spec.begin(); pos != spec.end(); ) {
127 const auto eol = std::find(pos, spec.end(), '\n');
128
129 // A CRLF separator leaves the CR behind; drop it along with any padding.
130 const auto entry = trim(spec.substr(pos - spec.begin(), eol - pos), " \t\r");
131 pos = (eol == spec.end() ? eol : std::next(eol));
132
133 // Tolerate blank entries so a trailing newline is not an error.
134 if (entry.empty()) {
135 continue;
136 }
137
138 // The value may itself contain colons, so split on the first one only.
139 // Without a colon the entry carries no value, so the log can show the
140 // whole entry without showing a value the user keeps private.
141 const auto colon = entry.find(':');
142 if (colon == std::string_view::npos) {
143 log->Error(kLogXrdClHttp, "Requested header %s holds no colon; each header must read \"<name>: <value>\"",
144 obfuscateAuth(std::string(entry)).c_str());
145 usable = false;
146 continue;
147 }
148
149 // The name must be a non-empty RFC 7230 token.
150 const std::string name(trim(entry.substr(0, colon), ows));
151 if (name.empty()) {
152 log->Error(kLogXrdClHttp, "Requested header holds no name before its colon");
153 usable = false;
154 continue;
155 }
156 if (!std::all_of(name.begin(), name.end(), [](const char c) {
157 return tchar.find(c) != std::string_view::npos;
158 }))
159 {
160 log->Error(kLogXrdClHttp, "Requested header %s holds a name that is not an HTTP token", name.c_str());
161 usable = false;
162 continue;
163 }
164 if (IsForbiddenHeader(name)) {
165 log->Error(kLogXrdClHttp, "Requested header %s must not be set by the client", name.c_str());
166 usable = false;
167 continue;
168 }
169
170 // A newline separates entries and so cannot occur in a value, but an
171 // embedded carriage return would let one forge part of the request.
172 const auto value = trim(entry.substr(colon + 1), ows);
173 if (value.empty()) {
174 log->Error(kLogXrdClHttp, "Requested header %s holds no value", name.c_str());
175 usable = false;
176 continue;
177 }
178 if (value.find('\r') != std::string_view::npos) {
179 log->Error(kLogXrdClHttp, "Requested header %s holds a carriage return in its value", name.c_str());
180 usable = false;
181 continue;
182 }
183
184 requested.emplace_back(name, value);
185 }
186
187 if (!usable) {
188 return false;
189 }
190
191 if (requested.empty()) {
192 return true;
193 }
194
195 // Name the headers but never their values, which the user fills with whatever
196 // the endpoint understands.
197 std::string names;
198 for (const auto &header : requested) {
199 if (!names.empty()) names += ", ";
200 names += header.first;
201 }
202 log->Debug(kLogXrdClHttp, "Requested headers %s", names.c_str());
203
204 headers = std::move(requested);
205 return true;
206}
void trim(std::string &str)
Definition XrdHttpReq.cc:78
std::string obfuscateAuth(const std::string &input)
static Log * GetLog()
Get default log.
Handle diagnostics.
Definition XrdClLog.hh:101
void Error(uint64_t topic, const char *format,...)
Report an error.
Definition XrdClLog.cc:231
void Debug(uint64_t topic, const char *format,...)
Print a debug message.
Definition XrdClLog.cc:282
bool IsForbiddenHeader(const std::string_view name)
std::vector< std::pair< std::string, std::string > > HeaderList
const uint64_t kLogXrdClHttp

References Build(), XrdCl::Log::Debug(), XrdCl::Log::Error(), XrdCl::DefaultEnv::GetLog(), IsForbiddenHeader(), XrdClHttp::kLogXrdClHttp, obfuscateAuth(), and trim().

Referenced by Build(), and XrdClHttp::CurlOperation::FinishSetup().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ CompareIgnoreCase()

bool XrdClHttp::HeaderBuilder::CompareIgnoreCase ( const std::string_view lhs,
const std::string_view rhs )
nodiscard

Definition at line 88 of file XrdClHttpHeaderBuilder.cc.

89{
90 const auto to_ascii_lower = [](const unsigned char c) {
91 return (c >= 'A' && c <= 'Z') ? static_cast<unsigned char>(c - 'A' + 'a') : c;
92 };
93
94 return std::equal(lhs.begin(), lhs.end(), rhs.begin(), rhs.end(),
95 [to_ascii_lower](const unsigned char a, const unsigned char b) {
96 return to_ascii_lower(a) == to_ascii_lower(b);
97 });
98}

References CompareIgnoreCase().

Referenced by CompareIgnoreCase(), XrdClHttp::CurlOperation::FinishSetup(), and IsForbiddenHeader().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ IsForbiddenHeader()

bool XrdClHttp::HeaderBuilder::IsForbiddenHeader ( const std::string_view name)
nodiscard

Definition at line 72 of file XrdClHttpHeaderBuilder.cc.

73{
74 // A forbidden header stays forbidden when the TransferHeader prefix aims it
75 // at the far server of a third party copy, however often the prefix repeats.
76 std::string_view bare(name);
77 while (CompareIgnoreCase(bare.substr(0, transfer_header_prefix.size()), transfer_header_prefix)) {
78 bare.remove_prefix(transfer_header_prefix.size());
79 }
80
81 return std::find_if(forbidden_headers.begin(), forbidden_headers.end(), [bare](auto _sv) {
82 return CompareIgnoreCase(bare, _sv);
83 })
84 != forbidden_headers.end();
85}
bool CompareIgnoreCase(const std::string_view lhs, const std::string_view rhs)

References CompareIgnoreCase(), and IsForbiddenHeader().

Referenced by Build(), and IsForbiddenHeader().

Here is the call graph for this function:
Here is the caller graph for this function: