HttpRequest.cpp 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273
  1. /*
  2. * Copyright (c) 2018-2020, Andreas Kling <kling@serenityos.org>
  3. * Copyright (c) 2022, the SerenityOS developers.
  4. *
  5. * SPDX-License-Identifier: BSD-2-Clause
  6. */
  7. #include <AK/Base64.h>
  8. #include <AK/StringBuilder.h>
  9. #include <LibHTTP/HttpRequest.h>
  10. #include <LibHTTP/Job.h>
  11. namespace HTTP {
  12. DeprecatedString to_deprecated_string(HttpRequest::Method method)
  13. {
  14. switch (method) {
  15. case HttpRequest::Method::GET:
  16. return "GET";
  17. case HttpRequest::Method::HEAD:
  18. return "HEAD";
  19. case HttpRequest::Method::POST:
  20. return "POST";
  21. case HttpRequest::Method::DELETE:
  22. return "DELETE";
  23. case HttpRequest::Method::PATCH:
  24. return "PATCH";
  25. case HttpRequest::Method::OPTIONS:
  26. return "OPTIONS";
  27. case HttpRequest::Method::TRACE:
  28. return "TRACE";
  29. case HttpRequest::Method::CONNECT:
  30. return "CONNECT";
  31. case HttpRequest::Method::PUT:
  32. return "PUT";
  33. default:
  34. VERIFY_NOT_REACHED();
  35. }
  36. }
  37. DeprecatedString HttpRequest::method_name() const
  38. {
  39. return to_deprecated_string(m_method);
  40. }
  41. ErrorOr<ByteBuffer> HttpRequest::to_raw_request() const
  42. {
  43. StringBuilder builder;
  44. TRY(builder.try_append(method_name()));
  45. TRY(builder.try_append(' '));
  46. // NOTE: The percent_encode is so that e.g. spaces are properly encoded.
  47. auto path = m_url.path();
  48. VERIFY(!path.is_empty());
  49. TRY(builder.try_append(URL::percent_encode(m_url.path(), URL::PercentEncodeSet::EncodeURI)));
  50. if (!m_url.query().is_empty()) {
  51. TRY(builder.try_append('?'));
  52. TRY(builder.try_append(m_url.query()));
  53. }
  54. TRY(builder.try_append(" HTTP/1.1\r\nHost: "sv));
  55. TRY(builder.try_append(m_url.host()));
  56. if (m_url.port().has_value())
  57. TRY(builder.try_appendff(":{}", *m_url.port()));
  58. TRY(builder.try_append("\r\n"sv));
  59. for (auto& header : m_headers) {
  60. TRY(builder.try_append(header.name));
  61. TRY(builder.try_append(": "sv));
  62. TRY(builder.try_append(header.value));
  63. TRY(builder.try_append("\r\n"sv));
  64. }
  65. if (!m_body.is_empty() || method() == Method::POST) {
  66. TRY(builder.try_appendff("Content-Length: {}\r\n\r\n", m_body.size()));
  67. TRY(builder.try_append((char const*)m_body.data(), m_body.size()));
  68. }
  69. TRY(builder.try_append("\r\n"sv));
  70. return builder.to_byte_buffer();
  71. }
  72. Optional<HttpRequest> HttpRequest::from_raw_request(ReadonlyBytes raw_request)
  73. {
  74. enum class State {
  75. InMethod,
  76. InResource,
  77. InProtocol,
  78. InHeaderName,
  79. InHeaderValue,
  80. InBody,
  81. };
  82. State state { State::InMethod };
  83. size_t index = 0;
  84. auto peek = [&](int offset = 0) -> u8 {
  85. if (index + offset >= raw_request.size())
  86. return 0;
  87. return raw_request[index + offset];
  88. };
  89. auto consume = [&]() -> u8 {
  90. VERIFY(index < raw_request.size());
  91. return raw_request[index++];
  92. };
  93. Vector<u8, 256> buffer;
  94. DeprecatedString method;
  95. DeprecatedString resource;
  96. DeprecatedString protocol;
  97. Vector<Header> headers;
  98. Header current_header;
  99. ByteBuffer body;
  100. auto commit_and_advance_to = [&](auto& output, State new_state) {
  101. output = DeprecatedString::copy(buffer);
  102. buffer.clear();
  103. state = new_state;
  104. };
  105. while (index < raw_request.size()) {
  106. // FIXME: Figure out what the appropriate limitations should be.
  107. if (buffer.size() > 65536)
  108. return {};
  109. switch (state) {
  110. case State::InMethod:
  111. if (peek() == ' ') {
  112. consume();
  113. commit_and_advance_to(method, State::InResource);
  114. break;
  115. }
  116. buffer.append(consume());
  117. break;
  118. case State::InResource:
  119. if (peek() == ' ') {
  120. consume();
  121. commit_and_advance_to(resource, State::InProtocol);
  122. break;
  123. }
  124. buffer.append(consume());
  125. break;
  126. case State::InProtocol:
  127. if (peek(0) == '\r' && peek(1) == '\n') {
  128. consume();
  129. consume();
  130. commit_and_advance_to(protocol, State::InHeaderName);
  131. break;
  132. }
  133. buffer.append(consume());
  134. break;
  135. case State::InHeaderName:
  136. if (peek(0) == ':' && peek(1) == ' ') {
  137. consume();
  138. consume();
  139. commit_and_advance_to(current_header.name, State::InHeaderValue);
  140. break;
  141. }
  142. buffer.append(consume());
  143. break;
  144. case State::InHeaderValue:
  145. if (peek(0) == '\r' && peek(1) == '\n') {
  146. consume();
  147. consume();
  148. // Detect end of headers
  149. auto next_state = State::InHeaderName;
  150. if (peek(0) == '\r' && peek(1) == '\n') {
  151. consume();
  152. consume();
  153. next_state = State::InBody;
  154. }
  155. commit_and_advance_to(current_header.value, next_state);
  156. headers.append(move(current_header));
  157. break;
  158. }
  159. buffer.append(consume());
  160. break;
  161. case State::InBody:
  162. buffer.append(consume());
  163. if (index == raw_request.size()) {
  164. // End of data, so store the body
  165. auto maybe_body = ByteBuffer::copy(buffer);
  166. // FIXME: Propagate this error somehow.
  167. if (maybe_body.is_error())
  168. return {};
  169. body = maybe_body.release_value();
  170. buffer.clear();
  171. }
  172. break;
  173. }
  174. }
  175. HttpRequest request;
  176. if (method == "GET")
  177. request.m_method = Method::GET;
  178. else if (method == "HEAD")
  179. request.m_method = Method::HEAD;
  180. else if (method == "POST")
  181. request.m_method = Method::POST;
  182. else if (method == "DELETE")
  183. request.set_method(HTTP::HttpRequest::Method::DELETE);
  184. else if (method == "PATCH")
  185. request.set_method(HTTP::HttpRequest::Method::PATCH);
  186. else if (method == "OPTIONS")
  187. request.set_method(HTTP::HttpRequest::Method::OPTIONS);
  188. else if (method == "TRACE")
  189. request.set_method(HTTP::HttpRequest::Method::TRACE);
  190. else if (method == "CONNECT")
  191. request.set_method(HTTP::HttpRequest::Method::CONNECT);
  192. else if (method == "PUT")
  193. request.set_method(HTTP::HttpRequest::Method::PUT);
  194. else
  195. return {};
  196. request.m_headers = move(headers);
  197. auto url_parts = resource.split_limit('?', 2, SplitBehavior::KeepEmpty);
  198. request.m_url.set_cannot_be_a_base_url(true);
  199. if (url_parts.size() == 2) {
  200. request.m_resource = url_parts[0];
  201. request.m_url.set_paths({ url_parts[0] });
  202. request.m_url.set_query(url_parts[1]);
  203. } else {
  204. request.m_resource = resource;
  205. request.m_url.set_paths({ resource });
  206. }
  207. request.set_body(move(body));
  208. return request;
  209. }
  210. void HttpRequest::set_headers(HashMap<DeprecatedString, DeprecatedString> const& headers)
  211. {
  212. for (auto& it : headers)
  213. m_headers.append({ it.key, it.value });
  214. }
  215. Optional<HttpRequest::Header> HttpRequest::get_http_basic_authentication_header(URL const& url)
  216. {
  217. if (!url.includes_credentials())
  218. return {};
  219. StringBuilder builder;
  220. builder.append(url.username());
  221. builder.append(':');
  222. builder.append(url.password());
  223. // FIXME: change to TRY() and make method fallible
  224. auto token = MUST(encode_base64(MUST(builder.to_string()).bytes()));
  225. builder.clear();
  226. builder.append("Basic "sv);
  227. builder.append(token);
  228. return Header { "Authorization", builder.to_deprecated_string() };
  229. }
  230. Optional<HttpRequest::BasicAuthenticationCredentials> HttpRequest::parse_http_basic_authentication_header(DeprecatedString const& value)
  231. {
  232. if (!value.starts_with("Basic "sv, AK::CaseSensitivity::CaseInsensitive))
  233. return {};
  234. auto token = value.substring_view(6);
  235. if (token.is_empty())
  236. return {};
  237. auto decoded_token_bb = decode_base64(token);
  238. if (decoded_token_bb.is_error())
  239. return {};
  240. auto decoded_token = DeprecatedString::copy(decoded_token_bb.value());
  241. auto colon_index = decoded_token.find(':');
  242. if (!colon_index.has_value())
  243. return {};
  244. auto username = decoded_token.substring_view(0, colon_index.value());
  245. auto password = decoded_token.substring_view(colon_index.value() + 1);
  246. return BasicAuthenticationCredentials { username, password };
  247. }
  248. }