XRootD
XrdHttpUtils.cc
Go to the documentation of this file.
1 //------------------------------------------------------------------------------
2 // This file is part of XrdHTTP: A pragmatic implementation of the
3 // HTTP/WebDAV protocol for the Xrootd framework
4 //
5 // Copyright (c) 2013 by European Organization for Nuclear Research (CERN)
6 // Author: Fabrizio Furano <furano@cern.ch>
7 // File Date: Apr 2013
8 //------------------------------------------------------------------------------
9 // XRootD is free software: you can redistribute it and/or modify
10 // it under the terms of the GNU Lesser General Public License as published by
11 // the Free Software Foundation, either version 3 of the License, or
12 // (at your option) any later version.
13 //
14 // XRootD is distributed in the hope that it will be useful,
15 // but WITHOUT ANY WARRANTY; without even the implied warranty of
16 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 // GNU General Public License for more details.
18 //
19 // You should have received a copy of the GNU Lesser General Public License
20 // along with XRootD. If not, see <http://www.gnu.org/licenses/>.
21 //------------------------------------------------------------------------------
22 
23 
24 
25 
26 
27 
28 
29 
40 #include "XrdHttpUtils.hh"
41 
42 #include <cstring>
43 #include <openssl/hmac.h>
44 #include <openssl/bio.h>
45 #include <openssl/buffer.h>
46 #include <openssl/err.h>
47 #include <openssl/ssl.h>
48 # include "sys/param.h"
49 
50 #include <pthread.h>
51 #include <memory>
52 #include <vector>
53 #include <algorithm>
54 
55 #include "XrdSec/XrdSecEntity.hh"
56 #include "XrdOuc/XrdOucString.hh"
57 
58 #if OPENSSL_VERSION_NUMBER < 0x10100000L
59 static HMAC_CTX* HMAC_CTX_new() {
60  HMAC_CTX *ctx = (HMAC_CTX *)OPENSSL_malloc(sizeof(HMAC_CTX));
61  if (ctx) HMAC_CTX_init(ctx);
62  return ctx;
63 }
64 
65 static void HMAC_CTX_free(HMAC_CTX *ctx) {
66  if (ctx) {
67  HMAC_CTX_cleanup(ctx);
68  OPENSSL_free(ctx);
69  }
70 }
71 #endif
72 
73 
74 // GetHost from URL
75 // Parse an URL and extract the host name and port
76 // Return 0 if OK
77 int parseURL(char *url, char *host, int &port, char **path) {
78  // http://x.y.z.w:p/path
79 
80  *path = 0;
81 
82  // look for the second slash
83  char *p = strstr(url, "//");
84  if (!p) return -1;
85 
86 
87  p += 2;
88 
89  // look for the end of the host:port
90  char *p2 = strchr(p, '/');
91  if (!p2) return -1;
92 
93  *path = p2;
94 
95  char buf[256];
96  int l = std::min((int)(p2 - p), (int)sizeof (buf) - 1);
97  strncpy(buf, p, l);
98  buf[l] = '\0';
99 
100  // Now look for :
101  p = strchr(buf, ':');
102  if (p) {
103  int l = std::min((int)(p - buf), (int)sizeof (buf) - 1);
104  strncpy(host, buf, l);
105  host[l] = '\0';
106 
107  port = atoi(p + 1);
108  } else {
109  port = 0;
110 
111 
112  strcpy(host, buf);
113  }
114 
115  return 0;
116 }
117 
118 
119 // Encode an array of bytes to base64
120 
121 void Tobase64(const unsigned char *input, int length, char *out) {
122  BIO *bmem, *b64;
123  BUF_MEM *bptr;
124 
125  if (!out) return;
126 
127  out[0] = '\0';
128 
129  b64 = BIO_new(BIO_f_base64());
130  BIO_set_flags(b64, BIO_FLAGS_BASE64_NO_NL);
131  bmem = BIO_new(BIO_s_mem());
132  BIO_push(b64, bmem);
133  BIO_write(b64, input, length);
134 
135  if (BIO_flush(b64) <= 0) {
136  BIO_free_all(b64);
137  return;
138  }
139 
140  BIO_get_mem_ptr(b64, &bptr);
141 
142 
143  memcpy(out, bptr->data, bptr->length);
144  out[bptr->length] = '\0';
145 
146  BIO_free_all(b64);
147 
148  return;
149 }
150 
151 
152 static int
154 {
155  if (isdigit(c)) {
156  return c - '0';
157  } else {
158  c = tolower(c);
159  if (c >= 'a' && c <= 'f') {
160  return c - 'a' + 10;
161  }
162  return -1;
163  }
164 }
165 
166 
167 // Decode a hex digest array to raw bytes.
168 //
169 bool Fromhexdigest(const unsigned char *input, int length, unsigned char *out) {
170  for (int idx=0; idx < length; idx += 2) {
171  int upper = char_to_int(input[idx]);
172  int lower = char_to_int(input[idx+1]);
173  if ((upper < 0) || (lower < 0)) {
174  return false;
175  }
176  out[idx/2] = (upper << 4) + lower;
177  }
178  return true;
179 }
180 
181 
182 // Simple itoa function
183 std::string itos(long i) {
184  char buf[128];
185  sprintf(buf, "%ld", i);
186 
187  return buf;
188 }
189 
190 
191 
192 // Home made implementation of strchrnul
193 char *mystrchrnul(const char *s, int c) {
194  char *ptr = strchr((char *)s, c);
195 
196  if (!ptr)
197  return strchr((char *)s, '\0');
198 
199  return ptr;
200 }
201 
202 
203 
204 // Calculates the opaque arguments hash, needed for a secure redirection
205 //
206 // - hash is a string that will be filled with the hash
207 //
208 // - fn: the original filename that was requested
209 // - dhost: target redirection hostname
210 // - client: address:port of the client
211 // - tim: creation time of the url
212 // - tim_grace: validity time before and after creation time
213 //
214 // Input for the key (simple shared secret)
215 // - key
216 // - key length
217 //
218 
220  char *hash,
221 
222  const char *fn,
223 
224  kXR_int16 request,
225 
226  XrdSecEntity *secent,
227 
228  time_t tim,
229 
230  const char *key) {
231 
232 
233 #if OPENSSL_VERSION_NUMBER >= 0x30000000L
234  EVP_MAC *mac;
235  EVP_MAC_CTX *ctx;
236  size_t len;
237 #else
238  HMAC_CTX *ctx;
239  unsigned int len;
240 #endif
241  unsigned char mdbuf[EVP_MAX_MD_SIZE];
242  char buf[64];
243  struct tm tms;
244 
245 
246  if (!hash) {
247  return;
248  }
249  hash[0] = '\0';
250 
251  if (!key) {
252  return;
253  }
254 
255  if (!fn || !secent) {
256  return;
257  }
258 
259 #if OPENSSL_VERSION_NUMBER >= 0x30000000L
260 
261  if (!(mac = EVP_MAC_fetch(nullptr, "HMAC", nullptr))) {
262  return;
263  }
264 
265  if (!(ctx = EVP_MAC_CTX_new(mac))) {
266  EVP_MAC_free(mac);
267  return;
268  }
269 
270  OSSL_PARAM params[2] = {
271  OSSL_PARAM_construct_utf8_string("digest", (char*)"SHA256", 0),
272  OSSL_PARAM_construct_end()
273  };
274 
275  if (!EVP_MAC_init(ctx, (const unsigned char *) key, strlen(key), params)) {
276  EVP_MAC_CTX_free(ctx);
277  EVP_MAC_free(mac);
278  return;
279  }
280 
281  if (fn)
282  EVP_MAC_update(ctx, (const unsigned char *) fn,
283  strlen(fn) + 1);
284 
285  EVP_MAC_update(ctx, (const unsigned char *) &request,
286  sizeof (request));
287 
288  if (secent->name)
289  EVP_MAC_update(ctx, (const unsigned char *) secent->name,
290  strlen(secent->name) + 1);
291 
292  if (secent->vorg)
293  EVP_MAC_update(ctx, (const unsigned char *) secent->vorg,
294  strlen(secent->vorg) + 1);
295 
296  if (secent->host)
297  EVP_MAC_update(ctx, (const unsigned char *) secent->host,
298  strlen(secent->host) + 1);
299 
300  if (secent->moninfo)
301  EVP_MAC_update(ctx, (const unsigned char *) secent->moninfo,
302  strlen(secent->moninfo) + 1);
303 
304  localtime_r(&tim, &tms);
305  strftime(buf, sizeof (buf), "%s", &tms);
306  EVP_MAC_update(ctx, (const unsigned char *) buf,
307  strlen(buf) + 1);
308 
309  EVP_MAC_final(ctx, mdbuf, &len, EVP_MAX_MD_SIZE);
310 
311  EVP_MAC_CTX_free(ctx);
312  EVP_MAC_free(mac);
313 
314 #else
315 
316  ctx = HMAC_CTX_new();
317 
318  if (!ctx) {
319  return;
320  }
321 
322 
323 
324  HMAC_Init_ex(ctx, (const void *) key, strlen(key), EVP_sha256(), 0);
325 
326 
327  if (fn)
328  HMAC_Update(ctx, (const unsigned char *) fn,
329  strlen(fn) + 1);
330 
331  HMAC_Update(ctx, (const unsigned char *) &request,
332  sizeof (request));
333 
334  if (secent->name)
335  HMAC_Update(ctx, (const unsigned char *) secent->name,
336  strlen(secent->name) + 1);
337 
338  if (secent->vorg)
339  HMAC_Update(ctx, (const unsigned char *) secent->vorg,
340  strlen(secent->vorg) + 1);
341 
342  if (secent->host)
343  HMAC_Update(ctx, (const unsigned char *) secent->host,
344  strlen(secent->host) + 1);
345 
346  if (secent->moninfo)
347  HMAC_Update(ctx, (const unsigned char *) secent->moninfo,
348  strlen(secent->moninfo) + 1);
349 
350  localtime_r(&tim, &tms);
351  strftime(buf, sizeof (buf), "%s", &tms);
352  HMAC_Update(ctx, (const unsigned char *) buf,
353  strlen(buf) + 1);
354 
355  HMAC_Final(ctx, mdbuf, &len);
356 
357  HMAC_CTX_free(ctx);
358 
359 #endif
360 
361  Tobase64(mdbuf, len / 2, hash);
362 }
363 
365  const char *h1,
366  const char *h2) {
367 
368  if (h1 == h2) return 0;
369 
370  if (!h1 || !h2)
371  return 1;
372 
373  return strcmp(h1, h2);
374 
375 }
376 
377 // unquote a string and return a new one
378 
379 char *unquote(char *str) {
380  int l = strlen(str);
381  char *r = (char *) malloc(l + 1);
382  r[0] = '\0';
383  int i, j = 0;
384 
385  for (i = 0; i < l; i++) {
386  if (str[i] == '%') {
387  if (i + 3 > l) {
388  r[j] = '\0';
389  return r;
390  }
391  char savec = str[i + 3];
392  str[i + 3] = '\0';
393 
394  r[j] = strtol(str + i + 1, 0, 16);
395  str[i + 3] = savec;
396 
397  i += 2;
398  } else r[j] = str[i];
399 
400  j++;
401  }
402 
403  r[j] = '\0';
404 
405  return r;
406 
407 }
408 
409 // Quote a string and return a new one
410 
411 char *quote(const char *str) {
412  int l = strlen(str);
413  char *r = (char *) malloc(l*3 + 1);
414  r[0] = '\0';
415  int i, j = 0;
416 
417  for (i = 0; i < l; i++) {
418  char c = str[i];
419 
420  switch (c) {
421  case ' ':
422  strcpy(r + j, "%20");
423  j += 3;
424  break;
425  case '[':
426  strcpy(r + j, "%5B");
427  j += 3;
428  break;
429  case ']':
430  strcpy(r + j, "%5D");
431  j += 3;
432  break;
433  case ':':
434  strcpy(r + j, "%3A");
435  j += 3;
436  break;
437  // case '/':
438  // strcpy(r + j, "%2F");
439  // j += 3;
440  // break;
441  case '#':
442  strcpy(r + j, "%23");
443  j += 3;
444  break;
445  case '\n':
446  strcpy(r + j, "%0A");
447  j += 3;
448  break;
449  case '\r':
450  strcpy(r + j, "%0D");
451  j += 3;
452  break;
453  case '=':
454  strcpy(r + j, "%3D");
455  j += 3;
456  break;
457  default:
458  r[j++] = c;
459  }
460  }
461 
462  r[j] = '\0';
463 
464  return r;
465 }
466 
467 
468 // Escape a string and return a new one
469 
470 char *escapeXML(const char *str) {
471  int l = strlen(str);
472  char *r = (char *) malloc(l*6 + 1);
473  r[0] = '\0';
474  int i, j = 0;
475 
476  for (i = 0; i < l; i++) {
477  char c = str[i];
478 
479  switch (c) {
480  case '"':
481  strcpy(r + j, "&quot;");
482  j += 6;
483  break;
484  case '&':
485  strcpy(r + j, "&amp;");
486  j += 5;
487  break;
488  case '<':
489  strcpy(r + j, "&lt;");
490  j += 4;
491  break;
492  case '>':
493  strcpy(r + j, "&gt;");
494  j += 4;
495  break;
496  case '\'':
497  strcpy(r + j, "&apos;");
498  j += 6;
499  break;
500 
501  default:
502  r[j++] = c;
503  }
504  }
505 
506  r[j] = '\0';
507 
508  return r;
509 }
510 
512 
513  int errNo = XProtocol::toErrno(xrdError);
514  return mapErrNoToHttp(errNo);
515 
516 }
517 
518 int mapErrNoToHttp(int errNo) {
519 
520  switch (errNo) {
521 
522  case EACCES:
523  case EROFS:
524  case EPERM:
525  return HTTP_FORBIDDEN;
526 
527  case EAUTH:
528  return HTTP_UNAUTHORIZED;
529 
530  case ENOENT:
531  return HTTP_NOT_FOUND;
532 
533  case EEXIST:
534  case EISDIR:
535  case ENOTDIR:
536  case ENOTEMPTY:
537  return HTTP_CONFLICT;
538 
539  case EXDEV:
541 
542  case ENAMETOOLONG:
543  return HTTP_URI_TOO_LONG;
544 
545  case ELOOP:
546  return HTTP_LOOP_DETECTED;
547 
548  case ENOSPC:
549  case EDQUOT:
551 
552  case EFBIG:
553  return HTTP_PAYLOAD_TOO_LARGE;
554 
555  case EINVAL:
556  case EBADF:
557  case EFAULT:
558  case ENXIO:
559  case ESPIPE:
560  case EOVERFLOW:
561  return HTTP_BAD_REQUEST;
562 
563  case ENOTSUP: // EOPNOTSUPP
564  return HTTP_NOT_IMPLEMENTED;
565 
566  case EBUSY:
567  case EAGAIN:
568  case EINTR:
569  case ENOMEM:
570  case EMFILE:
571  case ENFILE:
572  case ETXTBSY:
574 
575  case ETIMEDOUT:
576  return HTTP_GATEWAY_TIMEOUT;
577 
578  case ECONNREFUSED:
579  case ECONNRESET:
580  case ENETDOWN:
581  case ENETUNREACH:
582  case EHOSTUNREACH:
583  case EPIPE:
584  return HTTP_BAD_GATEWAY;
585 
586  default:
588  }
589 }
590 
591 std::string httpStatusToString(int status) {
592  switch (status) {
593  // 1xx Informational
594  case 100: return "Continue";
595  case 101: return "Switching Protocols";
596  case 102: return "Processing";
597  case 103: return "Early Hints";
598 
599  // 2xx Success
600  case 200: return "OK";
601  case 201: return "Created";
602  case 202: return "Accepted";
603  case 203: return "Non-Authoritative Information";
604  case 204: return "No Content";
605  case 205: return "Reset Content";
606  case 206: return "Partial Content";
607  case 207: return "Multi-Status";
608  case 208: return "Already Reported";
609  case 226: return "IM Used";
610 
611  // 3xx Redirection
612  case 300: return "Multiple Choices";
613  case 301: return "Moved Permanently";
614  case 302: return "Found";
615  case 303: return "See Other";
616  case 304: return "Not Modified";
617  case 305: return "Use Proxy";
618  case 307: return "Temporary Redirect";
619  case 308: return "Permanent Redirect";
620 
621  // 4xx Client Errors
622  case 400: return "Bad Request";
623  case 401: return "Unauthorized";
624  case 402: return "Payment Required";
625  case 403: return "Forbidden";
626  case 404: return "Not Found";
627  case 405: return "Method Not Allowed";
628  case 406: return "Not Acceptable";
629  case 407: return "Proxy Authentication Required";
630  case 408: return "Request Timeout";
631  case 409: return "Conflict";
632  case 410: return "Gone";
633  case 411: return "Length Required";
634  case 412: return "Precondition Failed";
635  case 413: return "Payload Too Large";
636  case 414: return "URI Too Long";
637  case 415: return "Unsupported Media Type";
638  case 416: return "Range Not Satisfiable";
639  case 417: return "Expectation Failed";
640  case 418: return "I'm a teapot";
641  case 421: return "Misdirected Request";
642  case 422: return "Unprocessable Entity";
643  case 423: return "Locked";
644  case 424: return "Failed Dependency";
645  case 425: return "Too Early";
646  case 426: return "Upgrade Required";
647  case 428: return "Precondition Required";
648  case 429: return "Too Many Requests";
649  case 431: return "Request Header Fields Too Large";
650  case 451: return "Unavailable For Legal Reasons";
651 
652  // 5xx Server Errors
653  case 500: return "Internal Server Error";
654  case 501: return "Not Implemented";
655  case 502: return "Bad Gateway";
656  case 503: return "Service Unavailable";
657  case 504: return "Gateway Timeout";
658  case 505: return "HTTP Version Not Supported";
659  case 506: return "Variant Also Negotiates";
660  case 507: return "Insufficient Storage";
661  case 508: return "Loop Detected";
662  case 510: return "Not Extended";
663  case 511: return "Network Authentication Required";
664 
665  default:
666  switch (status) {
667  case 100 ... 199: return "Informational";
668  case 200 ... 299: return "Success";
669  case 300 ... 399: return "Redirection";
670  case 400 ... 499: return "Client Error";
671  case 500 ... 599: return "Server Error";
672  default: return "Unknown";
673  }
674  }
675 }
XErrorCode
Definition: XProtocol.hh:989
#define EAUTH
Definition: XProtocol.hh:1351
short kXR_int16
Definition: XPtypes.hh:66
void BIO_set_flags(BIO *bio, int flags)
int parseURL(char *url, char *host, int &port, char **path)
Definition: XrdHttpUtils.cc:77
std::string itos(long i)
void Tobase64(const unsigned char *input, int length, char *out)
int compareHash(const char *h1, const char *h2)
char * unquote(char *str)
bool Fromhexdigest(const unsigned char *input, int length, unsigned char *out)
int mapXrdErrToHttp(XErrorCode xrdError)
static int char_to_int(int c)
int mapErrNoToHttp(int errNo)
static void HMAC_CTX_free(HMAC_CTX *ctx)
Definition: XrdHttpUtils.cc:65
static HMAC_CTX * HMAC_CTX_new()
Definition: XrdHttpUtils.cc:59
void calcHashes(char *hash, const char *fn, kXR_int16 request, XrdSecEntity *secent, time_t tim, const char *key)
char * escapeXML(const char *str)
char * mystrchrnul(const char *s, int c)
std::string httpStatusToString(int status)
char * quote(const char *str)
Utility functions for XrdHTTP.
@ HTTP_INSUFFICIENT_STORAGE
@ HTTP_BAD_REQUEST
Definition: XrdHttpUtils.hh:81
@ HTTP_LOOP_DETECTED
@ HTTP_SERVICE_UNAVAILABLE
@ HTTP_URI_TOO_LONG
Definition: XrdHttpUtils.hh:95
@ HTTP_UNAUTHORIZED
Definition: XrdHttpUtils.hh:82
@ HTTP_NOT_FOUND
Definition: XrdHttpUtils.hh:85
@ HTTP_FORBIDDEN
Definition: XrdHttpUtils.hh:84
@ HTTP_BAD_GATEWAY
@ HTTP_GATEWAY_TIMEOUT
@ HTTP_INTERNAL_SERVER_ERROR
@ HTTP_PAYLOAD_TOO_LARGE
Definition: XrdHttpUtils.hh:94
@ HTTP_NOT_IMPLEMENTED
@ HTTP_UNPROCESSABLE_ENTITY
@ HTTP_CONFLICT
Definition: XrdHttpUtils.hh:90
static int toErrno(int xerr)
Definition: XProtocol.hh:1411
char * vorg
Entity's virtual organization(s)
Definition: XrdSecEntity.hh:71
char * name
Entity's name.
Definition: XrdSecEntity.hh:69
char * moninfo
Information for monitoring.
Definition: XrdSecEntity.hh:76
char * host
Entity's host name dnr dependent.
Definition: XrdSecEntity.hh:70