URL.cpp 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437
  1. /*
  2. * Copyright (c) 2018-2020, Andreas Kling <kling@serenityos.org>
  3. * Copyright (c) 2021, Max Wipfli <mail@maxwipfli.ch>
  4. *
  5. * SPDX-License-Identifier: BSD-2-Clause
  6. */
  7. #include <AK/CharacterTypes.h>
  8. #include <AK/Debug.h>
  9. #include <AK/LexicalPath.h>
  10. #include <AK/StringBuilder.h>
  11. #include <AK/URL.h>
  12. #include <AK/URLParser.h>
  13. #include <AK/Utf8View.h>
  14. namespace AK {
  15. // FIXME: It could make sense to force users of URL to use URLParser::parse() explicitly instead of using a constructor.
  16. URL::URL(StringView string)
  17. : URL(URLParser::parse(string))
  18. {
  19. if constexpr (URL_PARSER_DEBUG) {
  20. if (m_valid)
  21. dbgln("URL constructor: Parsed URL to be '{}'.", serialize());
  22. else
  23. dbgln("URL constructor: Parsed URL to be invalid.");
  24. }
  25. }
  26. String URL::path() const
  27. {
  28. if (cannot_be_a_base_url())
  29. return paths()[0];
  30. StringBuilder builder;
  31. for (auto& path : m_paths) {
  32. builder.append('/');
  33. builder.append(path);
  34. }
  35. return builder.to_string();
  36. }
  37. URL URL::complete_url(String const& string) const
  38. {
  39. if (!is_valid())
  40. return {};
  41. return URLParser::parse(string, this);
  42. }
  43. void URL::set_scheme(String scheme)
  44. {
  45. m_scheme = move(scheme);
  46. m_valid = compute_validity();
  47. }
  48. void URL::set_username(String username)
  49. {
  50. m_username = move(username);
  51. m_valid = compute_validity();
  52. }
  53. void URL::set_password(String password)
  54. {
  55. m_password = move(password);
  56. m_valid = compute_validity();
  57. }
  58. void URL::set_host(String host)
  59. {
  60. m_host = move(host);
  61. m_valid = compute_validity();
  62. }
  63. void URL::set_port(Optional<u16> port)
  64. {
  65. if (port == default_port_for_scheme(m_scheme)) {
  66. m_port = {};
  67. return;
  68. }
  69. m_port = move(port);
  70. m_valid = compute_validity();
  71. }
  72. void URL::set_paths(Vector<String> paths)
  73. {
  74. m_paths = move(paths);
  75. m_valid = compute_validity();
  76. }
  77. void URL::set_query(String query)
  78. {
  79. m_query = move(query);
  80. }
  81. void URL::set_fragment(String fragment)
  82. {
  83. m_fragment = move(fragment);
  84. }
  85. // FIXME: This is by no means complete.
  86. // NOTE: This relies on some assumptions about how the spec-defined URL parser works that may turn out to be wrong.
  87. bool URL::compute_validity() const
  88. {
  89. if (m_scheme.is_empty())
  90. return false;
  91. if (m_scheme == "data") {
  92. if (m_data_mime_type.is_empty())
  93. return false;
  94. if (m_data_payload_is_base64) {
  95. if (m_data_payload.length() % 4 != 0)
  96. return false;
  97. for (auto character : m_data_payload) {
  98. if (!is_ascii_alphanumeric(character) || character == '+' || character == '/' || character == '=')
  99. return false;
  100. }
  101. }
  102. } else if (m_cannot_be_a_base_url) {
  103. if (m_paths.size() != 1)
  104. return false;
  105. if (m_paths[0].is_empty())
  106. return false;
  107. } else {
  108. if (m_scheme.is_one_of("about", "mailto"))
  109. return false;
  110. // NOTE: Maybe it is allowed to have a zero-segment path.
  111. if (m_paths.size() == 0)
  112. return false;
  113. }
  114. // NOTE: A file URL's host should be the empty string for localhost, not null.
  115. if (m_scheme == "file" && m_host.is_null())
  116. return false;
  117. return true;
  118. }
  119. bool URL::scheme_requires_port(StringView scheme)
  120. {
  121. return (default_port_for_scheme(scheme) != 0);
  122. }
  123. u16 URL::default_port_for_scheme(StringView scheme)
  124. {
  125. if (scheme == "http")
  126. return 80;
  127. if (scheme == "https")
  128. return 443;
  129. if (scheme == "gemini")
  130. return 1965;
  131. if (scheme == "irc")
  132. return 6667;
  133. if (scheme == "ircs")
  134. return 6697;
  135. if (scheme == "ws")
  136. return 80;
  137. if (scheme == "wss")
  138. return 443;
  139. return 0;
  140. }
  141. URL URL::create_with_file_scheme(String const& path, String const& fragment, String const& hostname)
  142. {
  143. LexicalPath lexical_path(path);
  144. if (!lexical_path.is_absolute())
  145. return {};
  146. URL url;
  147. url.set_scheme("file");
  148. // NOTE: If the hostname is localhost (or null, which implies localhost), it should be set to the empty string.
  149. // This is because a file URL always needs a non-null hostname.
  150. url.set_host(hostname.is_null() || hostname == "localhost" ? String::empty() : hostname);
  151. url.set_paths(lexical_path.parts());
  152. // NOTE: To indicate that we want to end the path with a slash, we have to append an empty path segment.
  153. if (path.ends_with('/'))
  154. url.append_path("");
  155. url.set_fragment(fragment);
  156. return url;
  157. }
  158. URL URL::create_with_url_or_path(String const& url_or_path)
  159. {
  160. URL url = url_or_path;
  161. if (url.is_valid())
  162. return url;
  163. String path = LexicalPath::canonicalized_path(url_or_path);
  164. return URL::create_with_file_scheme(path);
  165. }
  166. // https://url.spec.whatwg.org/#special-scheme
  167. bool URL::is_special_scheme(StringView scheme)
  168. {
  169. return scheme.is_one_of("ftp", "file", "http", "https", "ws", "wss");
  170. }
  171. String URL::serialize_data_url() const
  172. {
  173. VERIFY(m_scheme == "data");
  174. VERIFY(!m_data_mime_type.is_null());
  175. VERIFY(!m_data_payload.is_null());
  176. StringBuilder builder;
  177. builder.append(m_scheme);
  178. builder.append(':');
  179. builder.append(m_data_mime_type);
  180. if (m_data_payload_is_base64)
  181. builder.append(";base64");
  182. builder.append(',');
  183. // NOTE: The specification does not say anything about encoding this, but we should encode at least control and non-ASCII
  184. // characters (since this is also a valid representation of the same data URL).
  185. builder.append(URL::percent_encode(m_data_payload, PercentEncodeSet::C0Control));
  186. return builder.to_string();
  187. }
  188. // https://url.spec.whatwg.org/#concept-url-serializer
  189. String URL::serialize(ExcludeFragment exclude_fragment) const
  190. {
  191. if (m_scheme == "data")
  192. return serialize_data_url();
  193. StringBuilder builder;
  194. builder.append(m_scheme);
  195. builder.append(':');
  196. if (!m_host.is_null()) {
  197. builder.append("//");
  198. if (includes_credentials()) {
  199. builder.append(percent_encode(m_username, PercentEncodeSet::Userinfo));
  200. if (!m_password.is_empty()) {
  201. builder.append(':');
  202. builder.append(percent_encode(m_password, PercentEncodeSet::Userinfo));
  203. }
  204. builder.append('@');
  205. }
  206. builder.append(m_host);
  207. if (m_port.has_value())
  208. builder.appendff(":{}", *m_port);
  209. }
  210. if (cannot_be_a_base_url()) {
  211. builder.append(percent_encode(m_paths[0], PercentEncodeSet::Path));
  212. } else {
  213. if (m_host.is_null() && m_paths.size() > 1 && m_paths[0].is_empty())
  214. builder.append("/.");
  215. for (auto& segment : m_paths) {
  216. builder.append('/');
  217. builder.append(percent_encode(segment, PercentEncodeSet::Path));
  218. }
  219. }
  220. if (!m_query.is_null()) {
  221. builder.append('?');
  222. builder.append(percent_encode(m_query, is_special() ? URL::PercentEncodeSet::SpecialQuery : URL::PercentEncodeSet::Query));
  223. }
  224. if (exclude_fragment == ExcludeFragment::No && !m_fragment.is_null()) {
  225. builder.append('#');
  226. builder.append(percent_encode(m_fragment, PercentEncodeSet::Fragment));
  227. }
  228. return builder.to_string();
  229. }
  230. // https://url.spec.whatwg.org/#url-rendering
  231. // NOTE: This does e.g. not display credentials.
  232. // FIXME: Parts of the URL other than the host should have their sequences of percent-encoded bytes replaced with code points
  233. // resulting from percent-decoding those sequences converted to bytes, unless that renders those sequences invisible.
  234. String URL::serialize_for_display() const
  235. {
  236. VERIFY(m_valid);
  237. if (m_scheme == "data")
  238. return serialize_data_url();
  239. StringBuilder builder;
  240. builder.append(m_scheme);
  241. builder.append(':');
  242. if (!m_host.is_null()) {
  243. builder.append("//");
  244. builder.append(m_host);
  245. if (m_port.has_value())
  246. builder.appendff(":{}", *m_port);
  247. }
  248. if (cannot_be_a_base_url()) {
  249. builder.append(percent_encode(m_paths[0], PercentEncodeSet::Path));
  250. } else {
  251. if (m_host.is_null() && m_paths.size() > 1 && m_paths[0].is_empty())
  252. builder.append("/.");
  253. for (auto& segment : m_paths) {
  254. builder.append('/');
  255. builder.append(percent_encode(segment, PercentEncodeSet::Path));
  256. }
  257. }
  258. if (!m_query.is_null()) {
  259. builder.append('?');
  260. builder.append(percent_encode(m_query, is_special() ? URL::PercentEncodeSet::SpecialQuery : URL::PercentEncodeSet::Query));
  261. }
  262. if (!m_fragment.is_null()) {
  263. builder.append('#');
  264. builder.append(percent_encode(m_fragment, PercentEncodeSet::Fragment));
  265. }
  266. return builder.to_string();
  267. }
  268. // https://html.spec.whatwg.org/multipage/origin.html#ascii-serialisation-of-an-origin
  269. // https://url.spec.whatwg.org/#concept-url-origin
  270. String URL::serialize_origin() const
  271. {
  272. VERIFY(m_valid);
  273. if (m_scheme == "blob"sv) {
  274. // TODO: 1. If URL’s blob URL entry is non-null, then return URL’s blob URL entry’s environment’s origin.
  275. // 2. Let url be the result of parsing URL’s path[0].
  276. VERIFY(!m_paths.is_empty());
  277. URL url = m_paths[0];
  278. // 3. Return a new opaque origin, if url is failure, and url’s origin otherwise.
  279. if (!url.is_valid())
  280. return "null";
  281. return url.serialize_origin();
  282. } else if (!m_scheme.is_one_of("ftp"sv, "http"sv, "https"sv, "ws"sv, "wss"sv)) { // file: "Unfortunate as it is, this is left as an exercise to the reader. When in doubt, return a new opaque origin."
  283. return "null";
  284. }
  285. StringBuilder builder;
  286. builder.append(m_scheme);
  287. builder.append("://"sv);
  288. builder.append(m_host);
  289. if (m_port.has_value())
  290. builder.append(":{}", *m_port);
  291. return builder.build();
  292. }
  293. bool URL::equals(URL const& other, ExcludeFragment exclude_fragments) const
  294. {
  295. if (this == &other)
  296. return true;
  297. if (!m_valid || !other.m_valid)
  298. return false;
  299. return serialize(exclude_fragments) == other.serialize(exclude_fragments);
  300. }
  301. String URL::basename() const
  302. {
  303. if (!m_valid)
  304. return {};
  305. if (m_paths.is_empty())
  306. return {};
  307. return m_paths.last();
  308. }
  309. void URL::append_percent_encoded(StringBuilder& builder, u32 code_point)
  310. {
  311. if (code_point <= 0x7f)
  312. builder.appendff("%{:02X}", code_point);
  313. else if (code_point <= 0x07ff)
  314. builder.appendff("%{:02X}%{:02X}", ((code_point >> 6) & 0x1f) | 0xc0, (code_point & 0x3f) | 0x80);
  315. else if (code_point <= 0xffff)
  316. builder.appendff("%{:02X}%{:02X}%{:02X}", ((code_point >> 12) & 0x0f) | 0xe0, ((code_point >> 6) & 0x3f) | 0x80, (code_point & 0x3f) | 0x80);
  317. else if (code_point <= 0x10ffff)
  318. builder.appendff("%{:02X}%{:02X}%{:02X}%{:02X}", ((code_point >> 18) & 0x07) | 0xf0, ((code_point >> 12) & 0x3f) | 0x80, ((code_point >> 6) & 0x3f) | 0x80, (code_point & 0x3f) | 0x80);
  319. else
  320. VERIFY_NOT_REACHED();
  321. }
  322. // https://url.spec.whatwg.org/#c0-control-percent-encode-set
  323. constexpr bool code_point_is_in_percent_encode_set(u32 code_point, URL::PercentEncodeSet set)
  324. {
  325. switch (set) {
  326. case URL::PercentEncodeSet::C0Control:
  327. return code_point < 0x20 || code_point > 0x7E;
  328. case URL::PercentEncodeSet::Fragment:
  329. return code_point_is_in_percent_encode_set(code_point, URL::PercentEncodeSet::C0Control) || " \"<>`"sv.contains(code_point);
  330. case URL::PercentEncodeSet::Query:
  331. return code_point_is_in_percent_encode_set(code_point, URL::PercentEncodeSet::C0Control) || " \"#<>"sv.contains(code_point);
  332. case URL::PercentEncodeSet::SpecialQuery:
  333. return code_point_is_in_percent_encode_set(code_point, URL::PercentEncodeSet::Query) || code_point == '\'';
  334. case URL::PercentEncodeSet::Path:
  335. return code_point_is_in_percent_encode_set(code_point, URL::PercentEncodeSet::Query) || "?`{}"sv.contains(code_point);
  336. case URL::PercentEncodeSet::Userinfo:
  337. return code_point_is_in_percent_encode_set(code_point, URL::PercentEncodeSet::Path) || "/:;=@[\\]^|"sv.contains(code_point);
  338. case URL::PercentEncodeSet::Component:
  339. return code_point_is_in_percent_encode_set(code_point, URL::PercentEncodeSet::Userinfo) || "$%&+,"sv.contains(code_point);
  340. case URL::PercentEncodeSet::ApplicationXWWWFormUrlencoded:
  341. return code_point >= 0x7E || !(is_ascii_alphanumeric(code_point) || "!'()~"sv.contains(code_point));
  342. case URL::PercentEncodeSet::EncodeURI:
  343. // NOTE: This is the same percent encode set that JS encodeURI() uses.
  344. // https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/encodeURI
  345. return code_point >= 0x7E || (!is_ascii_alphanumeric(code_point) && !";,/?:@&=+$-_.!~*'()#"sv.contains(code_point));
  346. default:
  347. VERIFY_NOT_REACHED();
  348. }
  349. }
  350. void URL::append_percent_encoded_if_necessary(StringBuilder& builder, u32 code_point, URL::PercentEncodeSet set)
  351. {
  352. if (code_point_is_in_percent_encode_set(code_point, set))
  353. append_percent_encoded(builder, code_point);
  354. else
  355. builder.append_code_point(code_point);
  356. }
  357. String URL::percent_encode(StringView input, URL::PercentEncodeSet set)
  358. {
  359. StringBuilder builder;
  360. for (auto code_point : Utf8View(input)) {
  361. append_percent_encoded_if_necessary(builder, code_point, set);
  362. }
  363. return builder.to_string();
  364. }
  365. String URL::percent_decode(StringView input)
  366. {
  367. if (!input.contains('%'))
  368. return input;
  369. StringBuilder builder;
  370. Utf8View utf8_view(input);
  371. for (auto it = utf8_view.begin(); !it.done(); ++it) {
  372. if (*it != '%') {
  373. builder.append_code_point(*it);
  374. } else if (!is_ascii_hex_digit(it.peek(1).value_or(0)) || !is_ascii_hex_digit(it.peek(2).value_or(0))) {
  375. builder.append_code_point(*it);
  376. } else {
  377. ++it;
  378. u8 byte = parse_ascii_hex_digit(*it) << 4;
  379. ++it;
  380. byte += parse_ascii_hex_digit(*it);
  381. builder.append(byte);
  382. }
  383. }
  384. return builder.to_string();
  385. }
  386. }