HttpRequest.cpp 9.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308
  1. /*
  2. * Copyright (c) 2018-2020, Andreas Kling <kling@serenityos.org>
  3. * Copyright (c) 2022, the SerenityOS developers.
  4. *
  5. * SPDX-License-Identifier: BSD-2-Clause
  6. */
  7. #include <AK/Base64.h>
  8. #include <AK/StringBuilder.h>
  9. #include <AK/URLParser.h>
  10. #include <LibHTTP/HttpRequest.h>
  11. #include <LibHTTP/Job.h>
  12. namespace HTTP {
  13. StringView to_string_view(HttpRequest::Method method)
  14. {
  15. switch (method) {
  16. case HttpRequest::Method::GET:
  17. return "GET"sv;
  18. case HttpRequest::Method::HEAD:
  19. return "HEAD"sv;
  20. case HttpRequest::Method::POST:
  21. return "POST"sv;
  22. case HttpRequest::Method::DELETE:
  23. return "DELETE"sv;
  24. case HttpRequest::Method::PATCH:
  25. return "PATCH"sv;
  26. case HttpRequest::Method::OPTIONS:
  27. return "OPTIONS"sv;
  28. case HttpRequest::Method::TRACE:
  29. return "TRACE"sv;
  30. case HttpRequest::Method::CONNECT:
  31. return "CONNECT"sv;
  32. case HttpRequest::Method::PUT:
  33. return "PUT"sv;
  34. default:
  35. VERIFY_NOT_REACHED();
  36. }
  37. }
  38. StringView HttpRequest::method_name() const
  39. {
  40. return to_string_view(m_method);
  41. }
  42. ErrorOr<ByteBuffer> HttpRequest::to_raw_request() const
  43. {
  44. StringBuilder builder;
  45. TRY(builder.try_append(method_name()));
  46. TRY(builder.try_append(' '));
  47. // NOTE: The percent_encode is so that e.g. spaces are properly encoded.
  48. auto path = m_url.serialize_path();
  49. VERIFY(!path.is_empty());
  50. TRY(builder.try_append(URL::percent_encode(path, URL::PercentEncodeSet::EncodeURI)));
  51. if (m_url.query().has_value()) {
  52. TRY(builder.try_append('?'));
  53. TRY(builder.try_append(*m_url.query()));
  54. }
  55. TRY(builder.try_append(" HTTP/1.1\r\nHost: "sv));
  56. TRY(builder.try_append(TRY(m_url.serialized_host())));
  57. if (m_url.port().has_value())
  58. TRY(builder.try_appendff(":{}", *m_url.port()));
  59. TRY(builder.try_append("\r\n"sv));
  60. // Start headers.
  61. bool has_content_length = false;
  62. for (auto& header : m_headers) {
  63. if (header.name.equals_ignoring_ascii_case("Content-Length"sv))
  64. has_content_length = true;
  65. TRY(builder.try_append(header.name));
  66. TRY(builder.try_append(": "sv));
  67. TRY(builder.try_append(header.value));
  68. TRY(builder.try_append("\r\n"sv));
  69. }
  70. if (!m_body.is_empty() || method() == Method::POST) {
  71. // Add Content-Length header if it's not already present.
  72. if (!has_content_length) {
  73. TRY(builder.try_appendff("Content-Length: {}\r\n", m_body.size()));
  74. }
  75. // Finish headers.
  76. TRY(builder.try_append("\r\n"sv));
  77. TRY(builder.try_append((char const*)m_body.data(), m_body.size()));
  78. } else {
  79. // Finish headers.
  80. TRY(builder.try_append("\r\n"sv));
  81. }
  82. return builder.to_byte_buffer();
  83. }
  84. ErrorOr<HttpRequest, HttpRequest::ParseError> HttpRequest::from_raw_request(ReadonlyBytes raw_request)
  85. {
  86. enum class State {
  87. InMethod,
  88. InResource,
  89. InProtocol,
  90. InHeaderName,
  91. InHeaderValue,
  92. InBody,
  93. };
  94. State state { State::InMethod };
  95. size_t index = 0;
  96. auto peek = [&](int offset = 0) -> u8 {
  97. if (index + offset >= raw_request.size())
  98. return 0;
  99. return raw_request[index + offset];
  100. };
  101. auto consume = [&]() -> u8 {
  102. VERIFY(index < raw_request.size());
  103. return raw_request[index++];
  104. };
  105. Vector<u8, 256> buffer;
  106. Optional<unsigned> content_length;
  107. ByteString method;
  108. ByteString resource;
  109. ByteString protocol;
  110. Vector<Header> headers;
  111. Header current_header;
  112. ByteBuffer body;
  113. auto commit_and_advance_to = [&](auto& output, State new_state) {
  114. output = ByteString::copy(buffer);
  115. buffer.clear();
  116. state = new_state;
  117. };
  118. while (index < raw_request.size()) {
  119. // FIXME: Figure out what the appropriate limitations should be.
  120. if (buffer.size() > 65536)
  121. return ParseError::RequestTooLarge;
  122. switch (state) {
  123. case State::InMethod:
  124. if (peek() == ' ') {
  125. consume();
  126. commit_and_advance_to(method, State::InResource);
  127. break;
  128. }
  129. buffer.append(consume());
  130. break;
  131. case State::InResource:
  132. if (peek() == ' ') {
  133. consume();
  134. commit_and_advance_to(resource, State::InProtocol);
  135. break;
  136. }
  137. buffer.append(consume());
  138. break;
  139. case State::InProtocol:
  140. if (peek(0) == '\r' && peek(1) == '\n') {
  141. consume();
  142. consume();
  143. commit_and_advance_to(protocol, State::InHeaderName);
  144. break;
  145. }
  146. buffer.append(consume());
  147. break;
  148. case State::InHeaderName:
  149. if (peek(0) == ':' && peek(1) == ' ') {
  150. consume();
  151. consume();
  152. commit_and_advance_to(current_header.name, State::InHeaderValue);
  153. break;
  154. }
  155. buffer.append(consume());
  156. break;
  157. case State::InHeaderValue:
  158. if (peek(0) == '\r' && peek(1) == '\n') {
  159. consume();
  160. consume();
  161. // Detect end of headers
  162. auto next_state = State::InHeaderName;
  163. if (peek(0) == '\r' && peek(1) == '\n') {
  164. consume();
  165. consume();
  166. next_state = State::InBody;
  167. }
  168. commit_and_advance_to(current_header.value, next_state);
  169. if (current_header.name.equals_ignoring_ascii_case("Content-Length"sv))
  170. content_length = current_header.value.to_number<unsigned>();
  171. headers.append(move(current_header));
  172. break;
  173. }
  174. buffer.append(consume());
  175. break;
  176. case State::InBody:
  177. buffer.append(consume());
  178. if (index == raw_request.size()) {
  179. // End of data, so store the body
  180. auto maybe_body = ByteBuffer::copy(buffer);
  181. if (maybe_body.is_error()) {
  182. VERIFY(maybe_body.error().code() == ENOMEM);
  183. return ParseError::OutOfMemory;
  184. }
  185. body = maybe_body.release_value();
  186. buffer.clear();
  187. }
  188. break;
  189. }
  190. }
  191. if (state != State::InBody)
  192. return ParseError::RequestIncomplete;
  193. if (content_length.has_value() && content_length.value() != body.size())
  194. return ParseError::RequestIncomplete;
  195. HttpRequest request;
  196. if (method == "GET")
  197. request.m_method = Method::GET;
  198. else if (method == "HEAD")
  199. request.m_method = Method::HEAD;
  200. else if (method == "POST")
  201. request.m_method = Method::POST;
  202. else if (method == "DELETE")
  203. request.set_method(HTTP::HttpRequest::Method::DELETE);
  204. else if (method == "PATCH")
  205. request.set_method(HTTP::HttpRequest::Method::PATCH);
  206. else if (method == "OPTIONS")
  207. request.set_method(HTTP::HttpRequest::Method::OPTIONS);
  208. else if (method == "TRACE")
  209. request.set_method(HTTP::HttpRequest::Method::TRACE);
  210. else if (method == "CONNECT")
  211. request.set_method(HTTP::HttpRequest::Method::CONNECT);
  212. else if (method == "PUT")
  213. request.set_method(HTTP::HttpRequest::Method::PUT);
  214. else
  215. return ParseError::UnsupportedMethod;
  216. request.m_headers = move(headers);
  217. auto url_parts = resource.split_limit('?', 2, SplitBehavior::KeepEmpty);
  218. auto url_part_to_string = [](ByteString const& url_part) -> ErrorOr<String, ParseError> {
  219. auto query_string_or_error = String::from_byte_string(url_part);
  220. if (!query_string_or_error.is_error())
  221. return query_string_or_error.release_value();
  222. if (query_string_or_error.error().code() == ENOMEM)
  223. return ParseError::OutOfMemory;
  224. return ParseError::InvalidURL;
  225. };
  226. request.m_url.set_cannot_be_a_base_url(true);
  227. if (url_parts.size() == 2) {
  228. request.m_resource = url_parts[0];
  229. request.m_url.set_paths({ url_parts[0] });
  230. request.m_url.set_query(TRY(url_part_to_string(url_parts[1])));
  231. } else {
  232. request.m_resource = resource;
  233. request.m_url.set_paths({ resource });
  234. }
  235. request.set_body(move(body));
  236. return request;
  237. }
  238. void HttpRequest::set_headers(HashMap<ByteString, ByteString> const& headers)
  239. {
  240. for (auto& it : headers)
  241. m_headers.append({ it.key, it.value });
  242. }
  243. Optional<HttpRequest::Header> HttpRequest::get_http_basic_authentication_header(URL const& url)
  244. {
  245. if (!url.includes_credentials())
  246. return {};
  247. StringBuilder builder;
  248. builder.append(url.username().release_value_but_fixme_should_propagate_errors());
  249. builder.append(':');
  250. builder.append(url.password().release_value_but_fixme_should_propagate_errors());
  251. // FIXME: change to TRY() and make method fallible
  252. auto token = MUST(encode_base64(MUST(builder.to_string()).bytes()));
  253. builder.clear();
  254. builder.append("Basic "sv);
  255. builder.append(token);
  256. return Header { "Authorization", builder.to_byte_string() };
  257. }
  258. Optional<HttpRequest::BasicAuthenticationCredentials> HttpRequest::parse_http_basic_authentication_header(ByteString const& value)
  259. {
  260. if (!value.starts_with("Basic "sv, AK::CaseSensitivity::CaseInsensitive))
  261. return {};
  262. auto token = value.substring_view(6);
  263. if (token.is_empty())
  264. return {};
  265. auto decoded_token_bb = decode_base64(token);
  266. if (decoded_token_bb.is_error())
  267. return {};
  268. auto decoded_token = ByteString::copy(decoded_token_bb.value());
  269. auto colon_index = decoded_token.find(':');
  270. if (!colon_index.has_value())
  271. return {};
  272. auto username = decoded_token.substring_view(0, colon_index.value());
  273. auto password = decoded_token.substring_view(colon_index.value() + 1);
  274. return BasicAuthenticationCredentials { username, password };
  275. }
  276. }