mod_request.c revision e02cb8f5090d904c054633ff33dfd1111e16e404
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin/* Licensed to the Apache Software Foundation (ASF) under one or more
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * contributor license agreements. See the NOTICE file distributed with
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * this work for additional information regarding copyright ownership.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * The ASF licenses this file to You under the Apache License, Version 2.0
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * (the "License"); you may not use this file except in compliance with
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * the License. You may obtain a copy of the License at
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * Unless required by applicable law or agreed to in writing, software
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * distributed under the License is distributed on an "AS IS" BASIS,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * See the License for the specific language governing permissions and
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * limitations under the License.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * mod_request.c --- HTTP routines to set aside or process request bodies.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin#include "http_log.h" /* For errors detected in basic auth common
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * support code... */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin/* Handles for core filters */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrinAP_DECLARE_DATA ap_filter_rec_t *ap_keep_body_input_filter_handle;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrinAP_DECLARE_DATA ap_filter_rec_t *ap_kept_body_input_filter_handle;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrinstatic apr_status_t bail_out_on_error(apr_bucket_brigade *bb,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrintypedef struct keep_body_filter_ctx {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * This is the KEEP_BODY_INPUT filter for HTTP requests, for times when the
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * body should be set aside for future use by other modules.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrinAP_DECLARE(apr_status_t) ap_keep_body_filter(ap_filter_t *f, apr_bucket_brigade *b,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin const char *lenp;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin request_dir_conf *dconf = ap_get_module_config(f->r->per_dir_config,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* must we step out of the way? */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin return ap_get_brigade(f->next, b, mode, block, readbytes);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin f->ctx = ctx = apr_pcalloc(f->r->pool, sizeof(*ctx));
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* fail fast if the content length exceeds keep body */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin lenp = apr_table_get(f->r->headers_in, "Content-Length");
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* Protects against over/underflow, non-digit chars in the
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * string (excluding leading space) (the endstr checks)
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * and a negative number. */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin || endstr == lenp || *endstr || ctx->remaining < 0) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin "Invalid Content-Length");
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin return bail_out_on_error(b, f, HTTP_REQUEST_ENTITY_TOO_LARGE);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* If we have a limit in effect and we know the C-L ahead of
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * time, stop it here if it is invalid.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin " is larger than the configured limit"
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin " of %" APR_OFF_T_FMT, ctx->remaining, dconf->keep_body);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin return bail_out_on_error(b, f, HTTP_REQUEST_ENTITY_TOO_LARGE);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin f->r->kept_body = apr_brigade_create(f->r->pool, f->r->connection->bucket_alloc);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* get the brigade from upstream, and read it in to get its length */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin rv = ap_get_brigade(f->next, b, mode, block, readbytes);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* does the length take us over the limit? */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if (f->r->kept_body) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin " is larger than the configured limit"
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin return bail_out_on_error(b, f, HTTP_REQUEST_ENTITY_TOO_LARGE);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* pass any errors downstream */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if (f->r->kept_body) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* all is well, set aside the buckets */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrintypedef struct kept_body_filter_ctx {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * Initialisation of filter to handle a kept body on subrequests.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * If a body is to be reinserted into a subrequest, any chunking will have
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * been removed from the body during storage. We need to change the request
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * from Transfer-Encoding: chunked to an explicit Content-Length.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin apr_table_unset(r->headers_in, "Transfer-Encoding");
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin apr_table_setn(r->headers_in, "Content-Length", apr_off_t_toa(r->pool, length));
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * Filter to handle a kept body on subrequests.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * If a body has been previously kept by the request, and if a subrequest wants
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * to re-insert the body into the request, this input filter makes it happen.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrinAP_DECLARE(apr_status_t) ap_kept_body_filter(ap_filter_t *f, apr_bucket_brigade *b,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* just get out of the way of things we don't want. */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if (!kept_body || (mode != AP_MODE_READBYTES && mode != AP_MODE_GETLINE)) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin return ap_get_brigade(f->next, b, mode, block, readbytes);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* set up the context if it does not already exist */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin f->ctx = ctx = apr_palloc(f->r->pool, sizeof(*ctx));
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* kept_body is finished, send next filter */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin return ap_get_brigade(f->next, b, mode, block, readbytes);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* send all of the kept_body, but no more */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* send part of the kept_body */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if ((rv = apr_brigade_partition(kept_body, ctx->offset, &ec)) != APR_SUCCESS) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin "apr_brigade_partition() failed on kept_body at %" APR_OFF_T_FMT, ctx->offset);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if ((rv = apr_brigade_partition(kept_body, ctx->offset + readbytes, &e2)) != APR_SUCCESS) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin "apr_brigade_partition() failed on kept_body at %" APR_OFF_T_FMT, ctx->offset + readbytes);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin const char *str;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* As above; this should not fail since the bucket has
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * a known length, but just to be sure, this takes
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * care of uncopyable buckets that do somehow manage
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * to slip through. */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* XXX: check for failure? */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin/* form parsing stuff */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrintypedef enum {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * Read the body and parse any form found, which must be of the
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * Name/value pairs are returned in an array, with the names as
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * strings with a maximum length of HUGE_STRING_LEN, and the
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * values as bucket brigades. This allows values to be arbitrarily
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * All url-encoding is removed from both the names and the values
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * on the fly. The names are interpreted as strings, while the
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * values are interpreted as blocks of binary data, that may
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * contain the 0 character.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * In order to ensure that resource limits are not exceeded, a
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * maximum size must be provided. If the sum of the lengths of
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * the names and the values exceed this size, this function
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * will return HTTP_REQUEST_ENTITY_TOO_LARGE.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * An optional number of parameters can be provided, if the number
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * of parameters provided exceeds this amount, this function will
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * return HTTP_REQUEST_ENTITY_TOO_LARGE. If this value is negative,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * no limit is imposed, and the number of parameters is in turn
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * constrained by the size parameter above.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * This function honours any kept_body configuration, and the
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * original raw request body will be saved to the kept_body brigade
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * if so configured, just as ap_discard_request_body does.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * NOTE: File upload is not yet supported, but can be without change
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * to the function call.
e02cb8f5090d904c054633ff33dfd1111e16e404minfrinAP_DECLARE(int) ap_parse_request_form(request_rec * r, ap_filter_t * f,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin const char *ct;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin ap_form_type_t state = FORM_NAME, percent = FORM_NORMAL;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin apr_array_header_t *pairs = apr_array_make(r->pool, 4, sizeof(ap_form_pair_t));
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin /* sanity check - we only support forms for now */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if (!ct || strcmp("application/x-www-form-urlencoded", ct)) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin bb = apr_brigade_create(r->pool, r->connection->bucket_alloc);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin return (rv == AP_FILTER_ERROR) ? rv : HTTP_BAD_REQUEST;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin const char *data;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin rv = apr_bucket_read(bucket, &data, &len, APR_BLOCK_READ);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin while (state != FORM_ABORT && slide-- > 0 && size >= 0 && num != 0) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin char c = *data++;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if ('+' == c) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin else if ('&' == c) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if ('%' == c) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if (c >= 'a') {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin else if (c >= 'A') {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin else if (c >= '0') {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if (c >= 'a') {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin else if (c >= 'A') {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin else if (c >= '0') {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin const char *tmp = apr_pmemdup(r->pool, buffer, offset);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin apr_bucket *b = apr_bucket_pool_create(tmp, offset, r->pool, r->connection->bucket_alloc);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if ('=' == c) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin pair->value = apr_brigade_create(r->pool, r->connection->bucket_alloc);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin const char *tmp = apr_pmemdup(r->pool, buffer, offset);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin apr_bucket *b = apr_bucket_pool_create(tmp, offset, r->pool, r->connection->bucket_alloc);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin else if (FORM_VALUE == state && pair && offset > 0) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin const char *tmp = apr_pmemdup(r->pool, buffer, offset);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin apr_bucket *b = apr_bucket_pool_create(tmp, offset, r->pool, r->connection->bucket_alloc);
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin * Check whether this filter is not already present.
e02cb8f5090d904c054633ff33dfd1111e16e404minfrinstatic int request_is_filter_present(request_rec * r, ap_filter_rec_t *fn)
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin while (f) {
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin * Insert filter hook.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * Add the KEEP_BODY filter to the request, if the admin wants to keep
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * the body using the KeptBodySize directive.
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin * As a precaution, any pre-existing instances of either the kept_body or
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin * keep_body filters will be removed before the filter is added.
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin * @param r The request
e02cb8f5090d904c054633ff33dfd1111e16e404minfrinAP_DECLARE(void) ap_request_insert_filter(request_rec * r)
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin request_dir_conf *conf = ap_get_module_config(r->per_dir_config,
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin if (!request_is_filter_present(r, ap_kept_body_input_filter_handle)) {
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin ap_add_input_filter_handle(ap_kept_body_input_filter_handle,
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin if (!request_is_filter_present(r, ap_kept_body_input_filter_handle)) {
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin ap_add_input_filter_handle(ap_keep_body_input_filter_handle,
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin * Remove the kept_body and keep body filters from this specific request.
e02cb8f5090d904c054633ff33dfd1111e16e404minfrinAP_DECLARE(void) ap_request_remove_filter(request_rec * r)
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin while (f) {
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin if (f->frec->filter_func.in_func == ap_kept_body_filter ||
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin f->frec->filter_func.in_func == ap_keep_body_filter) {
82632a19f2f9c346fee2b28a65920ba9737b3973minfrinstatic void *create_request_dir_config(apr_pool_t *p, char *dummy)
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin (request_dir_conf *) apr_pcalloc(p, sizeof(request_dir_conf));
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin return (void *) new;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrinstatic void *merge_request_dir_config(apr_pool_t *p, void *basev, void *addv)
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin request_dir_conf *new = (request_dir_conf *) apr_pcalloc(p, sizeof(request_dir_conf));
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin request_dir_conf *base = (request_dir_conf *) basev;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin new->keep_body = (add->keep_body_set == 0) ? base->keep_body : add->keep_body;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin new->keep_body_set = add->keep_body_set || base->keep_body_set;
82632a19f2f9c346fee2b28a65920ba9737b3973minfrinstatic const char *set_kept_body_size(cmd_parms *cmd, void *dconf,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin const char *arg)
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin if (APR_SUCCESS != apr_strtoff(&(conf->keep_body), arg, NULL, 0)
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin return "KeptBodySize must be a size in bytes, or zero.";
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin AP_INIT_TAKE1("KeptBodySize", set_kept_body_size, NULL, ACCESS_CONF,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin "Maximum size of request bodies kept aside for use by filters"),
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin ap_register_input_filter(KEEP_BODY_FILTER, ap_keep_body_filter,
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin ap_register_input_filter(KEPT_BODY_FILTER, ap_kept_body_filter,
e02cb8f5090d904c054633ff33dfd1111e16e404minfrin ap_hook_insert_filter(ap_request_insert_filter, NULL, NULL, APR_HOOK_LAST);
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin create_request_dir_config, /* create per-directory config structure */
82632a19f2f9c346fee2b28a65920ba9737b3973minfrin merge_request_dir_config, /* merge per-directory config structures */