2021-03-28 14:54:21 +00:00
|
|
|
/*-*- mode:c;indent-tabs-mode:nil;c-basic-offset:2;tab-width:8;coding:utf-8 -*-│
|
|
|
|
│vi: set net ft=c ts=2 sts=2 sw=2 fenc=utf-8 :vi│
|
|
|
|
╞══════════════════════════════════════════════════════════════════════════════╡
|
|
|
|
│ Copyright 2021 Justine Alexandra Roberts Tunney │
|
|
|
|
│ │
|
|
|
|
│ Permission to use, copy, modify, and/or distribute this software for │
|
|
|
|
│ any purpose with or without fee is hereby granted, provided that the │
|
|
|
|
│ above copyright notice and this permission notice appear in all copies. │
|
|
|
|
│ │
|
|
|
|
│ THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL │
|
|
|
|
│ WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED │
|
|
|
|
│ WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE │
|
|
|
|
│ AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL │
|
|
|
|
│ DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR │
|
|
|
|
│ PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER │
|
|
|
|
│ TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR │
|
|
|
|
│ PERFORMANCE OF THIS SOFTWARE. │
|
|
|
|
╚─────────────────────────────────────────────────────────────────────────────*/
|
2021-04-18 18:34:59 +00:00
|
|
|
#include "libc/str/str.h"
|
2021-03-28 14:54:21 +00:00
|
|
|
#include "libc/str/thompike.h"
|
|
|
|
#include "net/http/http.h"
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Returns true if request path seems legit.
|
|
|
|
*
|
2021-04-18 18:34:59 +00:00
|
|
|
* 1. The substring "//" is disallowed.
|
|
|
|
* 2. We won't serve hidden files (segment starts with '.').
|
|
|
|
* 3. We won't serve paths with segments equal to "." or "..".
|
2021-03-28 14:54:21 +00:00
|
|
|
*
|
|
|
|
* It is assumed that the URI parser already took care of percent
|
|
|
|
* escape decoding as well as ISO-8859-1 decoding. The input needs
|
|
|
|
* to be a UTF-8 string.
|
2021-04-18 18:34:59 +00:00
|
|
|
*
|
|
|
|
* @param size if -1 implies strlen
|
2021-03-28 14:54:21 +00:00
|
|
|
*/
|
2021-04-18 18:34:59 +00:00
|
|
|
bool IsAcceptablePath(const char *data, size_t size) {
|
2021-03-28 14:54:21 +00:00
|
|
|
const char *p, *e;
|
2021-04-18 18:34:59 +00:00
|
|
|
int x, y, a, b, t, i, n;
|
|
|
|
if (size == -1) size = data ? strlen(data) : 0;
|
2021-03-28 14:54:21 +00:00
|
|
|
t = 0;
|
2021-04-18 18:34:59 +00:00
|
|
|
y = '/';
|
2021-03-28 14:54:21 +00:00
|
|
|
p = data;
|
|
|
|
e = p + size;
|
|
|
|
while (p < e) {
|
|
|
|
x = *p++ & 0xff;
|
|
|
|
if (x >= 0300) {
|
|
|
|
a = ThomPikeByte(x);
|
|
|
|
n = ThomPikeLen(x) - 1;
|
|
|
|
if (p + n <= e) {
|
|
|
|
for (i = 0;;) {
|
|
|
|
b = p[i] & 0xff;
|
|
|
|
if (!ThomPikeCont(b)) break;
|
|
|
|
a = ThomPikeMerge(a, b);
|
|
|
|
if (++i == n) {
|
|
|
|
x = a;
|
|
|
|
p += i;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if (x == '\\') {
|
|
|
|
x = '/';
|
|
|
|
}
|
2021-04-18 18:34:59 +00:00
|
|
|
if (y == '/') {
|
|
|
|
if (x == '.') return false;
|
|
|
|
if (x == '/' && t) return false;
|
2021-03-28 14:54:21 +00:00
|
|
|
}
|
|
|
|
y = x;
|
2021-04-18 18:34:59 +00:00
|
|
|
t = 1;
|
2021-03-28 14:54:21 +00:00
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|