bcb4e51a409d94ae670de96afb8483a4f7855294Stephan Bosch/* Copyright (c) 2013-2018 Dovecot authors, see the included COPYING file */
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch * Test: valid requests
1faa520084b901b15d83d3d68baaee2535051defStephan Boschstatic const struct http_request_valid_parse_test
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "GET / HTTP/1.1\r\n"
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "OPTIONS * HTTP/1.0\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "Connection: Keep-Alive\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .format = HTTP_REQUEST_TARGET_FORMAT_ASTERISK,
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "CONNECT example.com:443 HTTP/1.2\r\n"
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "Host: example.com:443\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .format = HTTP_REQUEST_TARGET_FORMAT_AUTHORITY,
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "GET https://www.example.com:443 HTTP/1.1\r\n"
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "Host: www.example.com:80\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .format = HTTP_REQUEST_TARGET_FORMAT_ABSOLUTE,
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "POST http://api.example.com:8080/commit?user=dirk HTTP/1.1\r\n"
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "Host: api.example.com:8080\r\n"
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "Content-Length: 10\r\n"
10962368c30afde135743fd9796122e88a708e87Stephan Bosch "Content!\r\n",
10962368c30afde135743fd9796122e88a708e87Stephan Bosch .target_raw = "http://api.example.com:8080/commit?user=dirk",
10962368c30afde135743fd9796122e88a708e87Stephan Bosch .format = HTTP_REQUEST_TARGET_FORMAT_ABSOLUTE,
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET http://www.example.com/index.php?seq=1 HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "Connection: close\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .target_raw = "http://www.example.com/index.php?seq=1",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .format = HTTP_REQUEST_TARGET_FORMAT_ABSOLUTE,
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET http://www.example.com/index.html HTTP/1.0\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .target_raw = "http://www.example.com/index.html",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .format = HTTP_REQUEST_TARGET_FORMAT_ABSOLUTE,
f74dbd3ff682fea040f60383e001620d1f1b09d3Stephan Bosch .url = { .host = { .name = "www.example.com" } }
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET http://www.example.com/index.html HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "Expect: 100-continue\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .target_raw = "http://www.example.com/index.html",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .format = HTTP_REQUEST_TARGET_FORMAT_ABSOLUTE,
f74dbd3ff682fea040f60383e001620d1f1b09d3Stephan Bosch .url = { .host = { .name = "www.example.com" } }
d577bb9027e4ceb19ada88d6884265efa5e16b15Stephan Bosch "GET / HTTP/1.1\r\n"
d577bb9027e4ceb19ada88d6884265efa5e16b15Stephan Bosch "Date: Mon, 09 Kul 2018 02:24:29 GMT\r\n"
6e62aa36a3190ef7193bd86158a4245da49132f0Stephan Bosch "GET / HTTP/1.1\r\n"
6e62aa36a3190ef7193bd86158a4245da49132f0Stephan Bosch "Date: Sun, 07 Oct 2012 19:52:03 GMT\r\n"
6e62aa36a3190ef7193bd86158a4245da49132f0Stephan Bosch "Date: Sun, 13 Oct 2013 13:13:13 GMT\r\n"
ba592dc74a004ad47dfe58edcfc1ca7297551e39Phil Carmodystatic const unsigned int valid_request_parse_test_count =
10962368c30afde135743fd9796122e88a708e87Stephan Boschstatic const char *
10962368c30afde135743fd9796122e88a708e87Stephan Bosch_request_target_format(enum http_request_target_format target_format)
10962368c30afde135743fd9796122e88a708e87Stephan Bosch return "origin";
10962368c30afde135743fd9796122e88a708e87Stephan Bosch return "absolute";
10962368c30afde135743fd9796122e88a708e87Stephan Bosch return "authority";
10962368c30afde135743fd9796122e88a708e87Stephan Bosch return "asterisk";
10962368c30afde135743fd9796122e88a708e87Stephan Bosch return t_strdup_printf("<<UNKNOWN: %u>>", target_format);
10962368c30afde135743fd9796122e88a708e87Stephan Boschstatic void test_http_request_parse_valid(void)
10962368c30afde135743fd9796122e88a708e87Stephan Bosch unsigned int i;
10962368c30afde135743fd9796122e88a708e87Stephan Bosch buffer_t *payload_buffer = buffer_create_dynamic(default_pool, 1024);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch for (i = 0; i < valid_request_parse_test_count; i++) T_BEGIN {
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch const struct http_request_valid_parse_test *test;
10962368c30afde135743fd9796122e88a708e87Stephan Bosch input = test_istream_create_data(request_text, request_text_len);
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch parser = http_request_parser_init(input, NULL, test->flags);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch test_begin(t_strdup_printf("http request valid [%d]", i));
10962368c30afde135743fd9796122e88a708e87Stephan Bosch for (pos = 0; pos <= request_text_len && ret == 0; pos++) {
b9ee73a064b38d8aeec754b964cc34b23487387aTimo Sirainen (parser, NULL, &request_parsed, &error_code, &error);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch test_istream_set_size(input, request_text_len);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch while (ret > 0) {
10962368c30afde135743fd9796122e88a708e87Stephan Bosch output = o_stream_create_buffer(payload_buffer);
378e6cb162b355d6f103526505bc00b9a78962e7Timo Sirainen o_stream_send_istream(output, request.payload) == OSTREAM_SEND_ISTREAM_RESULT_FINISHED);
b9ee73a064b38d8aeec754b964cc34b23487387aTimo Sirainen (parser, NULL, &request_parsed, &error_code, &error);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch test_out_reason("parse success", ret == 0, error);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch /* verify last request only */
10962368c30afde135743fd9796122e88a708e87Stephan Bosch if (request.method == NULL || test->method == NULL) {
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch test_out(t_strdup_printf("request->method = %s", request.method),
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch test_out(t_strdup_printf("request->method = %s", request.method),
10962368c30afde135743fd9796122e88a708e87Stephan Bosch if (request.target_raw == NULL || test->target_raw == NULL) {
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch ("request->target_raw = %s", request.target_raw),
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch ("request->target_raw = %s", request.target_raw),
10962368c30afde135743fd9796122e88a708e87Stephan Bosch strcmp(request.target_raw, test->target_raw) == 0);
f74dbd3ff682fea040f60383e001620d1f1b09d3Stephan Bosch test->target.url.host.name == NULL && test->target.url.port == 0);
f74dbd3ff682fea040f60383e001620d1f1b09d3Stephan Bosch test_out(t_strdup_printf("request->target.url->host.name = %s",
f74dbd3ff682fea040f60383e001620d1f1b09d3Stephan Bosch request.target.url->host.name == test->target.url.host.name);
f74dbd3ff682fea040f60383e001620d1f1b09d3Stephan Bosch test_out(t_strdup_printf("request->target.url->host.name = %s",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch test_out("request->target.url->port = (unspecified)",
f883bf3eff62f5d27df5ee9ee664edc38a77937fStephan Bosch request.target.url->port == test->target.url.port);
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch ("request->target.url->port = %u", request.target.url->port),
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch request.target.url->port == test->target.url.port);
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch test_out(t_strdup_printf("request->target.url->have_ssl = %s",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch (request.target.url->have_ssl ? "yes" : "no")),
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch request.target.url->have_ssl == test->target.url.have_ssl);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch test_out(t_strdup_printf("request->target_format = %s",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch _request_target_format(request.target.format)),
10962368c30afde135743fd9796122e88a708e87Stephan Bosch request.target.format == test->target.format);
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch test_out(t_strdup_printf("request->version = %u.%u",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch request.version_major, request.version_minor),
10962368c30afde135743fd9796122e88a708e87Stephan Bosch request.version_major == test->version_major &&
10962368c30afde135743fd9796122e88a708e87Stephan Bosch request.version_minor == test->version_minor);
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch test_out(t_strdup_printf("request->connection_close = %s",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch request.connection_close == test->connection_close);
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch test_out(t_strdup_printf("request->expect_100_continue = %s",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch (request.expect_100_continue ? "yes" : "no")),
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch request.expect_100_continue == test->expect_100_continue);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch if (payload == NULL || test->payload == NULL) {
10962368c30afde135743fd9796122e88a708e87Stephan Bosch test_out(t_strdup_printf("request->payload = %s",
10962368c30afde135743fd9796122e88a708e87Stephan Bosch test_out(t_strdup_printf("request->payload = %s",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch * Test: invalid requests
ba592dc74a004ad47dfe58edcfc1ca7297551e39Phil Carmodystatic const struct http_request_invalid_parse_test
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET: / HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BROKEN_REQUEST
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET % HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BAD_REQUEST
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET /frop\" HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BAD_REQUEST
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET / HTCPCP/1.0\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BROKEN_REQUEST
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET / HTTP/1.0.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BROKEN_REQUEST
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET / HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "Host: \"example.com\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BAD_REQUEST
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET / HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BAD_REQUEST
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET / HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "Transfer-Encoding: gzip\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BROKEN_REQUEST
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET / HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "Expect: payment\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_EXPECTATION_FAILED
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "GET / HTTP/1.1\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch "Transfer-Encoding: cuneiform, chunked\r\n"
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_NOT_IMPLEMENTED
d577bb9027e4ceb19ada88d6884265efa5e16b15Stephan Bosch "GET / HTTP/1.1\r\n"
d577bb9027e4ceb19ada88d6884265efa5e16b15Stephan Bosch "Date: Mon, 09 Kul 2018 02:24:29 GMT\r\n"
d577bb9027e4ceb19ada88d6884265efa5e16b15Stephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BROKEN_REQUEST
6e62aa36a3190ef7193bd86158a4245da49132f0Stephan Bosch "GET / HTTP/1.1\r\n"
6e62aa36a3190ef7193bd86158a4245da49132f0Stephan Bosch "Date: Sun, 07 Oct 2012 19:52:03 GMT\r\n"
6e62aa36a3190ef7193bd86158a4245da49132f0Stephan Bosch "Date: Sun, 13 Oct 2013 13:13:13 GMT\r\n"
6e62aa36a3190ef7193bd86158a4245da49132f0Stephan Bosch .error_code = HTTP_REQUEST_PARSE_ERROR_BROKEN_REQUEST
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch // FIXME: test request limits
ba592dc74a004ad47dfe58edcfc1ca7297551e39Phil Carmodystatic unsigned int invalid_request_parse_test_count =
1faa520084b901b15d83d3d68baaee2535051defStephan Boschstatic const char *
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch_request_parse_error(enum http_request_parse_error error)
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return "none?!";
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return "broken stream";
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return "broken request";
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return "bad request";
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch case HTTP_REQUEST_PARSE_ERROR_NOT_IMPLEMENTED:
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return "not implemented";
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch case HTTP_REQUEST_PARSE_ERROR_EXPECTATION_FAILED:
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return "expectation failed";
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch case HTTP_REQUEST_PARSE_ERROR_METHOD_TOO_LONG:
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return "method too long";
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch case HTTP_REQUEST_PARSE_ERROR_TARGET_TOO_LONG:
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return "target too long";
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch case HTTP_REQUEST_PARSE_ERROR_PAYLOAD_TOO_LARGE:
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return "payload too large";
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch return t_strdup_printf("<<UNKNOWN: %u>>", error);
10962368c30afde135743fd9796122e88a708e87Stephan Boschstatic void test_http_request_parse_invalid(void)
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch const struct http_request_invalid_parse_test *test;
10962368c30afde135743fd9796122e88a708e87Stephan Bosch unsigned int i;
10962368c30afde135743fd9796122e88a708e87Stephan Bosch for (i = 0; i < invalid_request_parse_test_count; i++) T_BEGIN {
10962368c30afde135743fd9796122e88a708e87Stephan Bosch input = i_stream_create_from_data(request_text, strlen(request_text));
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch parser = http_request_parser_init(input, NULL, test->flags);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch test_begin(t_strdup_printf("http request invalid [%d]", i));
ba592dc74a004ad47dfe58edcfc1ca7297551e39Phil Carmody (parser, NULL, &request, &error_code, &error)) > 0);
10962368c30afde135743fd9796122e88a708e87Stephan Bosch test_out_reason("parse failure", ret < 0, error);
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch test_out(t_strdup_printf("parse error code = %s",
1faa520084b901b15d83d3d68baaee2535051defStephan Bosch _request_parse_error(error_code)), error_code == test->error_code);
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch * Bad request tests
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Boschstatic const unsigned char bad_request_with_nuls[] =
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch "GET / HTTP/1.1\r\n"
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch "User-Agent: text\0client\r\n"
10962368c30afde135743fd9796122e88a708e87Stephan Bosch /* parse failure guarantees http_request_header.size equals
10962368c30afde135743fd9796122e88a708e87Stephan Bosch strlen(http_request_header.value) */
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch test_begin("http request with NULs (strict)");
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch input = i_stream_create_from_data(bad_request_with_nuls,
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch parser = http_request_parser_init(input, NULL,
ba592dc74a004ad47dfe58edcfc1ca7297551e39Phil Carmody (parser, NULL, &request, &error_code, &error)) > 0);
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch /* even when lenient, bad characters like NUL must not be returned */
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch test_begin("http request with NULs (lenient)");
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch input = i_stream_create_from_data(bad_request_with_nuls,
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch parser = http_request_parser_init(input, NULL, 0);
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch (parser, NULL, &request, &error_code, &error);
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch header = http_request_header_get(&request, "user-agent");
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch test_out(t_strdup_printf("header User-Agent: %s", header),
7ebcb054e0d3cc4be54038cbf763ec4189d9725bStephan Bosch (parser, NULL, &request, &error_code, &error);
baf3e87e186453fda13bd21f7cbcb2efc8492e8bTimo Sirainen static void (*const test_functions[])(void) = {