1 /* Parser of HTTP headers */
11 #include "protocol/header.h"
12 #include "util/conv.h"
13 #include "util/error.h"
14 #include "util/memory.h"
15 #include "util/string.h"
18 * RFC 2616 HTTP/1.1 June 1999
21 * OCTET = <any 8-bit sequence of data>
22 * CHAR = <any US-ASCII character (octets 0 - 127)>
23 * UPALPHA = <any US-ASCII uppercase letter "A".."Z">
24 * LOALPHA = <any US-ASCII lowercase letter "a".."z">
25 * ALPHA = UPALPHA | LOALPHA
26 * DIGIT = <any US-ASCII digit "0".."9">
27 * CTL = <any US-ASCII control character
28 * (octets 0 - 31) and DEL (127)>
29 * CR = <US-ASCII CR, carriage return (13)>
30 * LF = <US-ASCII LF, linefeed (10)>
31 * SP = <US-ASCII SP, space (32)>
32 * HT = <US-ASCII HT, horizontal-tab (9)>
33 * <"> = <US-ASCII double-quote mark (34)>
35 * HTTP/1.1 defines the sequence CR LF as the end-of-line marker for all
36 * protocol elements except the entity-body (see appendix 19.3 for
37 * tolerant applications). The end-of-line marker within an entity-body
38 * is defined by its associated media type, as described in section 3.7.
42 * HTTP/1.1 header field values can be folded onto multiple lines if the
43 * continuation line begins with a space or horizontal tab. All linear
44 * white space, including folding, has the same semantics as SP. A
45 * recipient MAY replace any linear white space with a single SP before
46 * interpreting the field value or forwarding the message downstream.
48 * LWS = [CRLF] 1*( SP | HT )
50 * The TEXT rule is only used for descriptive field contents and values
51 * that are not intended to be interpreted by the message parser. Words
52 * of *TEXT MAY contain characters from character sets other than ISO-
53 * 8859-1 [22] only when encoded according to the rules of RFC 2047
56 * TEXT = <any OCTET except CTLs,
59 * A CRLF is allowed in the definition of TEXT only as part of a header
60 * field continuation. It is expected that the folding LWS will be
61 * replaced with a single SP before interpretation of the TEXT value.
63 * Hexadecimal numeric characters are used in several protocol elements.
65 * HEX = "A" | "B" | "C" | "D" | "E" | "F"
66 * | "a" | "b" | "c" | "d" | "e" | "f" | DIGIT
68 * Many HTTP/1.1 header field values consist of words separated by LWS
69 * or special characters. These special characters MUST be in a quoted
70 * string to be used within a parameter value (as defined in section
73 * token = 1*<any CHAR except CTLs or separators>
74 * separators = "(" | ")" | "<" | ">" | "@"
75 * | "," | ";" | ":" | "\" | <">
76 * | "/" | "[" | "]" | "?" | "="
77 * | "{" | "}" | SP | HT
79 * Comments can be included in some HTTP header fields by surrounding
80 * the comment text with parentheses. Comments are only allowed in
81 * fields containing "comment" as part of their field value definition.
82 * In all other fields, parentheses are considered part of the field
85 * comment = "(" *( ctext | quoted-pair | comment ) ")"
86 * ctext = <any TEXT excluding "(" and ")">
88 * A string of text is parsed as a single word if it is quoted using
91 * quoted-string = ( <"> *(qdtext | quoted-pair ) <"> )
92 * qdtext = <any TEXT except <">>
94 * The backslash character ("\") MAY be used as a single-character
95 * quoting mechanism only within quoted-string and comment constructs.
97 * quoted-pair = "\" CHAR
102 * HTTP/1.1 header continuation lines are not honoured.
103 * DEL char is accepted in TEXT part.
104 * HT char is not accepted in TEXT part.
105 * LF alone do not mark end of line, CRLF is the correct termination.
106 * CR or LF are invalid in header line.
108 * Mozilla, IE, NS tolerate header value separator different from ':'
116 #define LWS(c) ((c) == ' ' || (c) == ASCII_TAB)
119 parse_header(unsigned char *head
, unsigned char *item
, unsigned char **ptr
)
121 unsigned char *pos
= head
;
123 if (!pos
) return NULL
;
126 unsigned char *end
, *itempos
, *value
;
129 /* Go for a newline. */
130 while (*pos
&& *pos
!= ASCII_LF
) pos
++;
132 pos
++; /* Start of line now. */
134 /* Does item match header line ? */
135 for (itempos
= item
; *itempos
&& *pos
; itempos
++, pos
++)
136 if (toupper(*itempos
) != toupper(*pos
))
139 if (!*pos
) break; /* Nothing left to parse. */
140 if (*itempos
) continue; /* Do not match. */
142 /* Be tolerant: we accept headers with
143 * weird syntax, since most browsers does it
148 * name[TAB]:[TAB]value */
152 /* Skip leading whitespaces if any. */
153 while (LWS(*pos
)) pos
++;
154 if (!*pos
) break; /* Nothing left to parse. */
156 /* Eat ':' or '=' if any. */
157 if (*pos
== ':' || *pos
== '=') pos
++;
158 if (!*pos
) break; /* Nothing left to parse. */
160 /* Skip whitespaces after separator if any. */
161 while (LWS(*pos
)) pos
++;
162 if (!*pos
) break; /* Nothing left to parse. */
164 if (pos
== end
) continue; /* Not an exact match (substring). */
166 /* Find the end of line/string.
167 * We fail on control chars and DEL char. */
169 while (*end
!= ASCII_DEL
&& (*end
> ' ' || LWS(*end
))) end
++;
170 if (!*end
) break; /* No end of line, nothing left to parse. */
172 /* Ignore line if we encountered an unexpected char. */
173 if (*end
!= ASCII_CR
&& *end
!= ASCII_LF
) continue;
175 /* Strip trailing whitespaces. */
176 while (end
> pos
&& LWS(end
[-1])) end
--;
180 if_assert_failed
break;
182 if (!len
) continue; /* Empty value. */
184 value
= memacpy(pos
, len
);
185 if (!value
) break; /* Allocation failure, stop here. */
194 /* Extract the value of name part of the value of attribute content.
195 * Ie. @name = "charset" and @str = "text/html; charset=iso-8859-1"
196 * will return allocated string containing "iso-8859-1".
197 * It supposes that separator is ';' and ignore first element in the
198 * list. (ie. '1' is ignored in "1; URL=xxx") */
200 parse_header_param(unsigned char *str
, unsigned char *name
)
202 unsigned char *p
= str
;
203 int namelen
, plen
= 0;
205 assert(str
&& name
&& *name
);
206 if_assert_failed
return NULL
;
208 /* Returns now if string @str is empty. */
209 if (!*p
) return NULL
;
211 namelen
= strlen(name
);
216 while (*p
&& (*p
== ';' || *p
<= ' ')) p
++;
217 if (strlen(p
) < namelen
) return NULL
;
218 } while (strncasecmp(p
, name
, namelen
));
222 while (*p
&& (*p
<= ' ' || *p
== '=')) p
++;
223 if (!*p
) return stracpy("");
225 while ((p
[plen
] > ' ' || LWS(p
[plen
])) && p
[plen
] != ';') plen
++;
227 /* Trim ending spaces */
228 while (plen
> 0 && LWS(p
[plen
- 1])) plen
--;
230 /* XXX: Drop enclosing single quotes if there's some.
232 * Some websites like newsnow.co.uk are using single quotes around url
233 * in URL field in meta tag content attribute like this:
234 * <meta http-equiv="Refresh" content="0; URL='http://www.site.com/path/xxx.htm'">
236 * This is an attempt to handle that, but it may break something else.
237 * We drop all pair of enclosing quotes found (eg. '''url''' => url).
238 * Please report any issue related to this. --Zas */
239 while (plen
> 1 && *p
== '\'' && p
[plen
- 1] == '\'') {
244 return memacpy(p
, plen
);
247 /* Parse string param="value", return value as new string or NULL if any
250 get_header_param(unsigned char *e
, unsigned char *name
)
252 unsigned char *n
, *start
;
255 while (*e
&& toupper(*e
++) != toupper(*name
));
256 if (!*e
) return NULL
;
259 while (*n
&& toupper(*e
) == toupper(*n
)) e
++, n
++;
263 if (*e
++ != '=') return NULL
;
271 unsigned char uu
= *e
++;
275 if (!*e
) return NULL
;
280 while (start
< e
&& *start
== ' ') start
++;
281 while (start
< e
&& *(e
- 1) == ' ') e
--;
282 if (start
== e
) return NULL
;
284 n
= mem_alloc(e
- start
+ 1);
289 n
[i
++] = (*start
< ' ') ? '.' : *start
;