Requests.h 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490
  1. /*
  2. * Copyright (c) 2022, Linus Groh <linusg@serenityos.org>
  3. *
  4. * SPDX-License-Identifier: BSD-2-Clause
  5. */
  6. #pragma once
  7. #include <AK/ByteBuffer.h>
  8. #include <AK/Error.h>
  9. #include <AK/Forward.h>
  10. #include <AK/Optional.h>
  11. #include <AK/String.h>
  12. #include <AK/URL.h>
  13. #include <AK/Variant.h>
  14. #include <AK/Vector.h>
  15. #include <LibJS/Forward.h>
  16. #include <LibJS/Heap/Cell.h>
  17. #include <LibWeb/Fetch/Infrastructure/HTTP/Bodies.h>
  18. #include <LibWeb/Fetch/Infrastructure/HTTP/Headers.h>
  19. #include <LibWeb/HTML/Origin.h>
  20. #include <LibWeb/HTML/PolicyContainers.h>
  21. #include <LibWeb/HTML/Scripting/Environments.h>
  22. namespace Web::Fetch::Infrastructure {
  23. // https://fetch.spec.whatwg.org/#concept-request
  24. class Request final : public JS::Cell {
  25. JS_CELL(Request, JS::Cell);
  26. public:
  27. enum class CacheMode {
  28. Default,
  29. NoStore,
  30. Reload,
  31. NoCache,
  32. ForceCache,
  33. OnlyIfCached,
  34. };
  35. enum class CredentialsMode {
  36. Omit,
  37. SameOrigin,
  38. Include,
  39. };
  40. enum class Destination {
  41. Audio,
  42. AudioWorklet,
  43. Document,
  44. Embed,
  45. Font,
  46. Frame,
  47. IFrame,
  48. Image,
  49. Manifest,
  50. Object,
  51. PaintWorklet,
  52. Report,
  53. Script,
  54. ServiceWorker,
  55. SharedWorker,
  56. Style,
  57. Track,
  58. Video,
  59. WebIdentity,
  60. Worker,
  61. XSLT,
  62. };
  63. enum class Initiator {
  64. Download,
  65. ImageSet,
  66. Manifest,
  67. Prefetch,
  68. Prerender,
  69. XSLT,
  70. };
  71. enum class InitiatorType {
  72. Audio,
  73. Beacon,
  74. Body,
  75. CSS,
  76. EarlyHint,
  77. Embed,
  78. Fetch,
  79. Font,
  80. Frame,
  81. IFrame,
  82. Image,
  83. IMG,
  84. Input,
  85. Link,
  86. Object,
  87. Ping,
  88. Script,
  89. Track,
  90. Video,
  91. XMLHttpRequest,
  92. Other,
  93. };
  94. enum class Mode {
  95. SameOrigin,
  96. CORS,
  97. NoCORS,
  98. Navigate,
  99. WebSocket,
  100. };
  101. enum class Origin {
  102. Client,
  103. };
  104. enum class ParserMetadata {
  105. ParserInserted,
  106. NotParserInserted,
  107. };
  108. enum class PolicyContainer {
  109. Client,
  110. };
  111. enum class RedirectMode {
  112. Follow,
  113. Error,
  114. Manual,
  115. };
  116. enum class Referrer {
  117. NoReferrer,
  118. Client,
  119. };
  120. enum class ResponseTainting {
  121. Basic,
  122. CORS,
  123. Opaque,
  124. };
  125. enum class ServiceWorkersMode {
  126. All,
  127. None,
  128. };
  129. enum class Window {
  130. NoWindow,
  131. Client,
  132. };
  133. // Members are implementation-defined
  134. struct Priority { };
  135. using BodyType = Variant<Empty, ByteBuffer, Body>;
  136. using OriginType = Variant<Origin, HTML::Origin>;
  137. using PolicyContainerType = Variant<PolicyContainer, HTML::PolicyContainer>;
  138. using ReferrerType = Variant<Referrer, AK::URL>;
  139. using ReservedClientType = Variant<Empty, HTML::Environment*, HTML::EnvironmentSettingsObject*>;
  140. using WindowType = Variant<Window, HTML::EnvironmentSettingsObject*>;
  141. [[nodiscard]] static JS::NonnullGCPtr<Request> create(JS::VM&);
  142. [[nodiscard]] ReadonlyBytes method() const { return m_method; }
  143. void set_method(ByteBuffer method) { m_method = move(method); }
  144. [[nodiscard]] bool local_urls_only() const { return m_local_urls_only; }
  145. void set_local_urls_only(bool local_urls_only) { m_local_urls_only = local_urls_only; }
  146. [[nodiscard]] JS::NonnullGCPtr<HeaderList> header_list() const { return m_header_list; }
  147. void set_header_list(JS::NonnullGCPtr<HeaderList> header_list) { m_header_list = header_list; }
  148. [[nodiscard]] bool unsafe_request() const { return m_unsafe_request; }
  149. void set_unsafe_request(bool unsafe_request) { m_unsafe_request = unsafe_request; }
  150. [[nodiscard]] BodyType const& body() const { return m_body; }
  151. [[nodiscard]] BodyType& body() { return m_body; }
  152. void set_body(BodyType body) { m_body = move(body); }
  153. [[nodiscard]] HTML::EnvironmentSettingsObject const* client() const { return m_client; }
  154. [[nodiscard]] HTML::EnvironmentSettingsObject* client() { return m_client; }
  155. void set_client(HTML::EnvironmentSettingsObject* client) { m_client = client; }
  156. [[nodiscard]] ReservedClientType const& reserved_client() const { return m_reserved_client; }
  157. [[nodiscard]] ReservedClientType& reserved_client() { return m_reserved_client; }
  158. void set_reserved_client(ReservedClientType reserved_client) { m_reserved_client = move(reserved_client); }
  159. [[nodiscard]] String const& replaces_client_id() const { return m_replaces_client_id; }
  160. void set_replaces_client_id(String replaces_client_id) { m_replaces_client_id = move(replaces_client_id); }
  161. [[nodiscard]] WindowType const& window() const { return m_window; }
  162. void set_window(WindowType window) { m_window = move(window); }
  163. [[nodiscard]] bool keepalive() const { return m_keepalive; }
  164. void set_keepalive(bool keepalive) { m_keepalive = keepalive; }
  165. [[nodiscard]] Optional<InitiatorType> const& initiator_type() const { return m_initiator_type; }
  166. void set_initiator_type(Optional<InitiatorType> initiator_type) { m_initiator_type = move(initiator_type); }
  167. [[nodiscard]] ServiceWorkersMode service_workers_mode() const { return m_service_workers_mode; }
  168. void set_service_workers_mode(ServiceWorkersMode service_workers_mode) { m_service_workers_mode = service_workers_mode; }
  169. [[nodiscard]] Optional<Initiator> const& initiator() const { return m_initiator; }
  170. void set_initiator(Optional<Initiator> initiator) { m_initiator = move(initiator); }
  171. [[nodiscard]] Optional<Destination> const& destination() const { return m_destination; }
  172. void set_destination(Optional<Destination> destination) { m_destination = move(destination); }
  173. [[nodiscard]] Optional<Priority> const& priority() const { return m_priority; }
  174. void set_priority(Optional<Priority> priority) { m_priority = move(priority); }
  175. [[nodiscard]] OriginType const& origin() const { return m_origin; }
  176. void set_origin(OriginType origin) { m_origin = move(origin); }
  177. [[nodiscard]] PolicyContainerType const& policy_container() const { return m_policy_container; }
  178. void set_policy_container(PolicyContainerType policy_container) { m_policy_container = move(policy_container); }
  179. [[nodiscard]] Mode mode() const { return m_mode; }
  180. void set_mode(Mode mode) { m_mode = mode; }
  181. [[nodiscard]] bool use_cors_preflight() const { return m_use_cors_preflight; }
  182. void set_use_cors_preflight(bool use_cors_preflight) { m_use_cors_preflight = use_cors_preflight; }
  183. [[nodiscard]] CredentialsMode credentials_mode() const { return m_credentials_mode; }
  184. void set_credentials_mode(CredentialsMode credentials_mode) { m_credentials_mode = credentials_mode; }
  185. [[nodiscard]] bool use_url_credentials() const { return m_use_url_credentials; }
  186. void set_use_url_credentials(bool use_url_credentials) { m_use_url_credentials = use_url_credentials; }
  187. [[nodiscard]] CacheMode cache_mode() const { return m_cache_mode; }
  188. void set_cache_mode(CacheMode cache_mode) { m_cache_mode = cache_mode; }
  189. [[nodiscard]] RedirectMode redirect_mode() const { return m_redirect_mode; }
  190. void set_redirect_mode(RedirectMode redirect_mode) { m_redirect_mode = redirect_mode; }
  191. [[nodiscard]] String const& integrity_metadata() const { return m_integrity_metadata; }
  192. void set_integrity_metadata(String integrity_metadata) { m_integrity_metadata = move(integrity_metadata); }
  193. [[nodiscard]] String const& cryptographic_nonce_metadata() const { return m_cryptographic_nonce_metadata; }
  194. void set_cryptographic_nonce_metadata(String cryptographic_nonce_metadata) { m_cryptographic_nonce_metadata = move(cryptographic_nonce_metadata); }
  195. [[nodiscard]] Optional<ParserMetadata> const& parser_metadata() const { return m_parser_metadata; }
  196. void set_parser_metadata(Optional<ParserMetadata> parser_metadata) { m_parser_metadata = move(parser_metadata); }
  197. [[nodiscard]] bool reload_navigation() const { return m_reload_navigation; }
  198. void set_reload_navigation(bool reload_navigation) { m_reload_navigation = reload_navigation; }
  199. [[nodiscard]] bool history_navigation() const { return m_history_navigation; }
  200. void set_history_navigation(bool history_navigation) { m_history_navigation = history_navigation; }
  201. [[nodiscard]] bool user_activation() const { return m_user_activation; }
  202. void set_user_activation(bool user_activation) { m_user_activation = user_activation; }
  203. [[nodiscard]] bool render_blocking() const { return m_render_blocking; }
  204. void set_render_blocking(bool render_blocking) { m_render_blocking = render_blocking; }
  205. [[nodiscard]] Vector<AK::URL> const& url_list() const { return m_url_list; }
  206. [[nodiscard]] Vector<AK::URL>& url_list() { return m_url_list; }
  207. void set_url_list(Vector<AK::URL> url_list) { m_url_list = move(url_list); }
  208. [[nodiscard]] u8 redirect_count() const { return m_redirect_count; }
  209. void set_redirect_count(u8 redirect_count) { m_redirect_count = redirect_count; }
  210. [[nodiscard]] ReferrerType const& referrer() const { return m_referrer; }
  211. void set_referrer(ReferrerType referrer) { m_referrer = move(referrer); }
  212. [[nodiscard]] Optional<ReferrerPolicy::ReferrerPolicy> const& referrer_policy() const { return m_referrer_policy; }
  213. void set_referrer_policy(Optional<ReferrerPolicy::ReferrerPolicy> referrer_policy) { m_referrer_policy = move(referrer_policy); }
  214. [[nodiscard]] ResponseTainting response_tainting() const { return m_response_tainting; }
  215. void set_response_tainting(ResponseTainting response_tainting) { m_response_tainting = response_tainting; }
  216. [[nodiscard]] bool prevent_no_cache_cache_control_header_modification() const { return m_prevent_no_cache_cache_control_header_modification; }
  217. void set_prevent_no_cache_cache_control_header_modification(bool prevent_no_cache_cache_control_header_modification) { m_prevent_no_cache_cache_control_header_modification = prevent_no_cache_cache_control_header_modification; }
  218. [[nodiscard]] bool done() const { return m_done; }
  219. void set_done(bool done) { m_done = done; }
  220. [[nodiscard]] bool timing_allow_failed() const { return m_timing_allow_failed; }
  221. void set_timing_allow_failed(bool timing_allow_failed) { m_timing_allow_failed = timing_allow_failed; }
  222. [[nodiscard]] AK::URL& url();
  223. [[nodiscard]] AK::URL const& url() const;
  224. [[nodiscard]] AK::URL& current_url();
  225. [[nodiscard]] AK::URL const& current_url() const;
  226. void set_url(AK::URL url);
  227. [[nodiscard]] bool destination_is_script_like() const;
  228. [[nodiscard]] bool is_subresource_request() const;
  229. [[nodiscard]] bool is_non_subresource_request() const;
  230. [[nodiscard]] bool is_navigation_request() const;
  231. [[nodiscard]] bool has_redirect_tainted_origin() const;
  232. [[nodiscard]] String serialize_origin() const;
  233. [[nodiscard]] ErrorOr<ByteBuffer> byte_serialize_origin() const;
  234. [[nodiscard]] WebIDL::ExceptionOr<JS::NonnullGCPtr<Request>> clone(JS::VM&) const;
  235. [[nodiscard]] ErrorOr<void> add_range_header(u64 first, Optional<u64> const& last);
  236. [[nodiscard]] bool cross_origin_embedder_policy_allows_credentials() const;
  237. private:
  238. explicit Request(JS::NonnullGCPtr<HeaderList>);
  239. virtual void visit_edges(JS::Cell::Visitor&) override;
  240. // https://fetch.spec.whatwg.org/#concept-request-method
  241. // A request has an associated method (a method). Unless stated otherwise it is `GET`.
  242. ByteBuffer m_method { ByteBuffer::copy("GET"sv.bytes()).release_value() };
  243. // https://fetch.spec.whatwg.org/#local-urls-only-flag
  244. // A request has an associated local-URLs-only flag. Unless stated otherwise it is unset.
  245. bool m_local_urls_only { false };
  246. // https://fetch.spec.whatwg.org/#concept-request-header-list
  247. // A request has an associated header list (a header list). Unless stated otherwise it is empty.
  248. JS::NonnullGCPtr<HeaderList> m_header_list;
  249. // https://fetch.spec.whatwg.org/#unsafe-request-flag
  250. // A request has an associated unsafe-request flag. Unless stated otherwise it is unset.
  251. bool m_unsafe_request { false };
  252. // https://fetch.spec.whatwg.org/#concept-request-body
  253. // A request has an associated body (null, a byte sequence, or a body). Unless stated otherwise it is null.
  254. BodyType m_body;
  255. // https://fetch.spec.whatwg.org/#concept-request-client
  256. // A request has an associated client (null or an environment settings object).
  257. HTML::EnvironmentSettingsObject* m_client { nullptr };
  258. // https://fetch.spec.whatwg.org/#concept-request-reserved-client
  259. // A request has an associated reserved client (null, an environment, or an environment settings object). Unless
  260. // stated otherwise it is null.
  261. ReservedClientType m_reserved_client;
  262. // https://fetch.spec.whatwg.org/#concept-request-replaces-client-id
  263. // A request has an associated replaces client id (a string). Unless stated otherwise it is the empty string.
  264. String m_replaces_client_id { String::empty() };
  265. // https://fetch.spec.whatwg.org/#concept-request-window
  266. // A request has an associated window ("no-window", "client", or an environment settings object whose global object
  267. // is a Window object). Unless stated otherwise it is "client".
  268. WindowType m_window { Window::Client };
  269. // https://fetch.spec.whatwg.org/#request-keepalive-flag
  270. // A request has an associated boolean keepalive. Unless stated otherwise it is false.
  271. bool m_keepalive { false };
  272. // https://fetch.spec.whatwg.org/#request-initiator-type
  273. // A request has an associated initiator type, which is null, "audio", "beacon", "body", "css", "early-hint",
  274. // "embed", "fetch", "font", "frame", "iframe", "image", "img", "input", "link", "object", "ping", "script",
  275. // "track", "video", "xmlhttprequest", or "other". Unless stated otherwise it is null. [RESOURCE-TIMING]
  276. Optional<InitiatorType> m_initiator_type;
  277. // https://fetch.spec.whatwg.org/#request-service-workers-mode
  278. // A request has an associated service-workers mode, that is "all" or "none". Unless stated otherwise it is "all".
  279. ServiceWorkersMode m_service_workers_mode { ServiceWorkersMode::All };
  280. // https://fetch.spec.whatwg.org/#concept-request-initiator
  281. // A request has an associated initiator, which is the empty string, "download", "imageset", "manifest",
  282. // "prefetch", "prerender", or "xslt". Unless stated otherwise it is the empty string.
  283. Optional<Initiator> m_initiator;
  284. // https://fetch.spec.whatwg.org/#concept-request-destination
  285. // A request has an associated destination, which is the empty string, "audio", "audioworklet", "document",
  286. // "embed", "font", "frame", "iframe", "image", "manifest", "object", "paintworklet", "report", "script",
  287. // "serviceworker", "sharedworker", "style", "track", "video", "webidentity", "worker", or "xslt". Unless stated
  288. // otherwise it is the empty string.
  289. // NOTE: These are reflected on RequestDestination except for "serviceworker" and "webidentity" as fetches with
  290. // those destinations skip service workers.
  291. Optional<Destination> m_destination;
  292. // https://fetch.spec.whatwg.org/#concept-request-priority
  293. // A request has an associated priority (null or a user-agent-defined object). Unless otherwise stated it is null.
  294. Optional<Priority> m_priority;
  295. // https://fetch.spec.whatwg.org/#concept-request-origin
  296. // A request has an associated origin, which is "client" or an origin. Unless stated otherwise it is "client".
  297. OriginType m_origin { Origin::Client };
  298. // https://fetch.spec.whatwg.org/#concept-request-policy-container
  299. // A request has an associated policy container, which is "client" or a policy container. Unless stated otherwise
  300. // it is "client".
  301. PolicyContainerType m_policy_container { PolicyContainer::Client };
  302. // https://fetch.spec.whatwg.org/#concept-request-referrer
  303. // A request has an associated referrer, which is "no-referrer", "client", or a URL. Unless stated otherwise it is
  304. // "client".
  305. ReferrerType m_referrer { Referrer::Client };
  306. // https://fetch.spec.whatwg.org/#concept-request-referrer-policy
  307. // A request has an associated referrer policy, which is a referrer policy. Unless stated otherwise it is the empty
  308. // string.
  309. Optional<ReferrerPolicy::ReferrerPolicy> m_referrer_policy;
  310. // https://fetch.spec.whatwg.org/#concept-request-mode
  311. // A request has an associated mode, which is "same-origin", "cors", "no-cors", "navigate", or "websocket". Unless
  312. // stated otherwise, it is "no-cors".
  313. Mode m_mode { Mode::NoCORS };
  314. // https://fetch.spec.whatwg.org/#use-cors-preflight-flag
  315. // A request has an associated use-CORS-preflight flag. Unless stated otherwise, it is unset.
  316. bool m_use_cors_preflight { false };
  317. // https://fetch.spec.whatwg.org/#concept-request-credentials-mode
  318. // A request has an associated credentials mode, which is "omit", "same-origin", or "include". Unless stated
  319. // otherwise, it is "same-origin".
  320. CredentialsMode m_credentials_mode { CredentialsMode::SameOrigin };
  321. // https://fetch.spec.whatwg.org/#concept-request-use-url-credentials-flag
  322. // A request has an associated use-URL-credentials flag. Unless stated otherwise, it is unset.
  323. // NOTE: When this flag is set, when a request’s URL has a username and password, and there is an available
  324. // authentication entry for the request, then the URL’s credentials are preferred over that of the
  325. // authentication entry. Modern specifications avoid setting this flag, since putting credentials in URLs is
  326. // discouraged, but some older features set it for compatibility reasons.
  327. bool m_use_url_credentials { false };
  328. // https://fetch.spec.whatwg.org/#concept-request-cache-mode
  329. // A request has an associated cache mode, which is "default", "no-store", "reload", "no-cache", "force-cache", or
  330. // "only-if-cached". Unless stated otherwise, it is "default".
  331. CacheMode m_cache_mode { CacheMode::Default };
  332. // https://fetch.spec.whatwg.org/#concept-request-redirect-mode
  333. // A request has an associated redirect mode, which is "follow", "error", or "manual". Unless stated otherwise, it
  334. // is "follow".
  335. RedirectMode m_redirect_mode { RedirectMode::Follow };
  336. // https://fetch.spec.whatwg.org/#concept-request-integrity-metadata
  337. // A request has associated integrity metadata (a string). Unless stated otherwise, it is the empty string.
  338. String m_integrity_metadata { String::empty() };
  339. // https://fetch.spec.whatwg.org/#concept-request-nonce-metadata
  340. // A request has associated cryptographic nonce metadata (a string). Unless stated otherwise, it is the empty
  341. // string.
  342. String m_cryptographic_nonce_metadata { String::empty() };
  343. // https://fetch.spec.whatwg.org/#concept-request-parser-metadata
  344. // A request has associated parser metadata which is the empty string, "parser-inserted", or
  345. // "not-parser-inserted". Unless otherwise stated, it is the empty string.
  346. Optional<ParserMetadata> m_parser_metadata;
  347. // https://fetch.spec.whatwg.org/#concept-request-reload-navigation-flag
  348. // A request has an associated reload-navigation flag. Unless stated otherwise, it is unset.
  349. bool m_reload_navigation { false };
  350. // https://fetch.spec.whatwg.org/#concept-request-history-navigation-flag
  351. // A request has an associated history-navigation flag. Unless stated otherwise, it is unset.
  352. bool m_history_navigation { false };
  353. // https://fetch.spec.whatwg.org/#request-user-activation
  354. // A request has an associated boolean user-activation. Unless stated otherwise, it is false.
  355. bool m_user_activation { false };
  356. // https://fetch.spec.whatwg.org/#request-render-blocking
  357. // A request has an associated boolean render-blocking. Unless stated otherwise, it is false.
  358. bool m_render_blocking { false };
  359. // https://fetch.spec.whatwg.org/#concept-request-url-list
  360. // A request has an associated URL list (a list of one or more URLs). Unless stated otherwise, it is a list
  361. // containing a copy of request’s URL.
  362. Vector<AK::URL> m_url_list;
  363. // https://fetch.spec.whatwg.org/#concept-request-redirect-count
  364. // A request has an associated redirect count. Unless stated otherwise, it is zero.
  365. // NOTE: '4.4. HTTP-redirect fetch' infers a limit of 20.
  366. u8 m_redirect_count { 0 };
  367. // https://fetch.spec.whatwg.org/#concept-request-response-tainting
  368. // A request has an associated response tainting, which is "basic", "cors", or "opaque". Unless stated otherwise,
  369. // it is "basic".
  370. ResponseTainting m_response_tainting { ResponseTainting::Basic };
  371. // https://fetch.spec.whatwg.org/#no-cache-prevent-cache-control
  372. // A request has an associated prevent no-cache cache-control header modification flag. Unless stated otherwise, it
  373. // is unset.
  374. bool m_prevent_no_cache_cache_control_header_modification { false };
  375. // https://fetch.spec.whatwg.org/#done-flag
  376. // A request has an associated done flag. Unless stated otherwise, it is unset.
  377. bool m_done { false };
  378. // https://fetch.spec.whatwg.org/#timing-allow-failed
  379. // A request has an associated timing allow failed flag. Unless stated otherwise, it is unset.
  380. bool m_timing_allow_failed { false };
  381. };
  382. }