-const char cgisimple_rcs[] = "$Id: cgisimple.c,v 1.69 2008/04/17 14:40:48 fabiankeil Exp $";
+const char cgisimple_rcs[] = "$Id: cgisimple.c,v 1.93 2009/05/16 13:27:20 fabiankeil Exp $";
/*********************************************************************
*
* File : $Source: /cvsroot/ijbswa/current/cgisimple.c,v $
* or write to the Free Software Foundation, Inc., 59
* Temple Place - Suite 330, Boston, MA 02111-1307, USA.
*
- * Revisions :
- * $Log: cgisimple.c,v $
- * Revision 1.69 2008/04/17 14:40:48 fabiankeil
- * Provide get_http_time() with the buffer size so it doesn't
- * have to blindly assume that the buffer is big enough.
- *
- * Revision 1.68 2008/03/27 18:27:21 fabiankeil
- * Remove kill-popups action.
- *
- * Revision 1.67 2008/03/27 17:00:05 fabiankeil
- * Turn the favicon blobs into locals.
- *
- * Revision 1.66 2008/02/23 16:57:12 fabiankeil
- * Rename url_actions() to get_url_actions() and let it
- * use the standard parameter ordering.
- *
- * Revision 1.65 2008/02/23 16:33:43 fabiankeil
- * Let forward_url() use the standard parameter ordering
- * and mark its second parameter immutable.
- *
- * Revision 1.64 2008/02/03 13:56:07 fabiankeil
- * Add SOCKS5 support for show-url-info CGI page.
- *
- * Revision 1.63 2008/02/01 06:04:31 fabiankeil
- * If edit buttons on the show-url-info CGI page are hidden, explain why.
- *
- * Revision 1.62 2008/02/01 05:52:40 fabiankeil
- * Hide edit buttons on the show-url-info CGI page if enable-edit-action
- * is disabled. Patch by Lee with additional white space adjustments.
- *
- * Revision 1.61 2008/01/26 11:13:25 fabiankeil
- * If enable-edit-actions is disabled, hide the edit buttons and explain why.
- *
- * Revision 1.60 2007/10/27 13:12:13 fabiankeil
- * Finish 1.49 and check write access before
- * showing edit buttons on show-url-info page.
- *
- * Revision 1.59 2007/10/19 16:42:36 fabiankeil
- * Plug memory leak I introduced five months ago.
- * Yay Valgrind and Privoxy-Regression-Test.
- *
- * Revision 1.58 2007/07/21 12:19:50 fabiankeil
- * If show-url-info is called with an URL that Privoxy
- * would reject as invalid, don't show unresolved forwarding
- * variables, "final matches" or claim the site's secure.
- *
- * Revision 1.57 2007/06/01 16:53:05 fabiankeil
- * Adjust cgi_show_url_info() to show what forward-override{}
- * would do with the requested URL (instead of showing how the
- * request for the CGI page would be forwarded if it wasn't a
- * CGI request).
- *
- * Revision 1.56 2007/05/21 10:50:35 fabiankeil
- * - Use strlcpy() instead of strcpy().
- * - Stop treating actions files special. Expect a complete file name
- * (with or without path) like it's done for the rest of the files.
- * Closes FR#588084.
- * - Don't rerun sed() in cgi_show_request().
- *
- * Revision 1.55 2007/04/13 13:36:46 fabiankeil
- * Reference action files in CGI URLs by id instead
- * of using the first part of the file name.
- * Fixes BR 1694250 and BR 1590556.
- *
- * Revision 1.54 2007/04/09 18:11:35 fabiankeil
- * Don't mistake VC++'s _snprintf() for a snprintf() replacement.
- *
- * Revision 1.53 2007/04/08 13:21:04 fabiankeil
- * Reference action files in CGI URLs by id instead
- * of using the first part of the file name.
- * Fixes BR 1694250 and BR 1590556.
- *
- * Revision 1.52 2007/02/13 15:10:26 fabiankeil
- * Apparently fopen()ing in "binary" mode doesn't require
- * #ifdefs, it's already done without them in cgiedit.c.
- *
- * Revision 1.51 2007/02/10 16:55:22 fabiankeil
- * - Show forwarding settings on the show-url-info page
- * - Fix some HTML syntax errors.
- *
- * Revision 1.50 2007/01/23 15:51:17 fabiankeil
- * Add favicon delivery functions.
- *
- * Revision 1.49 2007/01/20 16:29:38 fabiankeil
- * Suppress edit buttons for action files if Privoxy has
- * no write access. Suggested by Roland in PR 1564026.
- *
- * Revision 1.48 2007/01/20 15:31:31 fabiankeil
- * Display warning if show-url-info CGI page
- * is used while Privoxy is toggled off.
- *
- * Revision 1.47 2007/01/12 15:07:10 fabiankeil
- * Use zalloc in cgi_send_user_manual.
- *
- * Revision 1.46 2007/01/02 12:49:46 fabiankeil
- * Add FEATURE_ZLIB to the list of conditional
- * defines at the show-status page.
- *
- * Revision 1.45 2006/12/28 18:16:41 fabiankeil
- * Fixed gcc43 compiler warnings, zero out cgi_send_user_manual's
- * body memory before using it, replaced sprintf calls with snprintf.
- *
- * Revision 1.44 2006/12/22 14:19:27 fabiankeil
- * Removed checks whether or not AF_FILES have
- * data structures associated with them in cgi_show_status.
- * It doesn't matter as we're only interested in the file names.
- *
- * For the action files the checks were always true,
- * but they prevented empty filter files from being
- * listed. Fixes parts of BR 1619208.
- *
- * Revision 1.43 2006/12/17 17:57:56 fabiankeil
- * - Added FEATURE_GRACEFUL_TERMINATION to the
- * "conditional #defines" section
- * - Escaped ampersands in generated HTML.
- * - Renamed re-filter-filename to re-filter-filenames
- *
- * Revision 1.42 2006/11/21 15:43:12 fabiankeil
- * Add special treatment for WIN32 to make sure
- * cgi_send_user_manual opens the files in binary mode.
- * Fixes BR 1600411 and unbreaks image delivery.
- *
- * Remove outdated comment.
- *
- * Revision 1.41 2006/10/09 19:18:28 roro
- * Redirect http://p.p/user-manual (without trailing slash) to
- * http://p.p/user-manual/ (with trailing slash), otherwise links will be broken.
- *
- * Revision 1.40 2006/09/09 13:05:33 fabiankeil
- * Modified cgi_send_user_manual to serve binary
- * content without destroying it first. Should also be
- * faster now. Added ".jpg" check for Content-Type guessing.
- *
- * Revision 1.39 2006/09/08 09:49:23 fabiankeil
- * Deliver documents in the user-manual directory
- * with "Content-Type text/css" if their filename
- * ends with ".css".
- *
- * Revision 1.38 2006/09/06 18:45:03 fabiankeil
- * Incorporate modified version of Roland Rosenfeld's patch to
- * optionally access the user-manual via Privoxy. Closes patch 679075.
- *
- * Formatting changed to Privoxy style, added call to
- * cgi_error_no_template if the requested file doesn't
- * exist and modified check whether or not Privoxy itself
- * should serve the manual. Should work cross-platform now.
- *
- * Revision 1.37 2006/07/18 14:48:45 david__schmidt
- * Reorganizing the repository: swapping out what was HEAD (the old 3.1 branch)
- * with what was really the latest development (the v_3_0_branch branch)
- *
- * Revision 1.35.2.7 2006/01/29 23:10:56 david__schmidt
- * Multiple filter file support
- *
- * Revision 1.35.2.6 2005/07/04 03:13:43 david__schmidt
- * Undo some damaging memory leak patches
- *
- * Revision 1.35.2.5 2005/05/07 21:50:55 david__schmidt
- * A few memory leaks plugged (mostly on error paths)
- *
- * Revision 1.35.2.4 2005/04/04 02:21:24 david__schmidt
- * Another instance of:
- * Don't show "Edit" buttons #ifndef FEATURE_CGI_EDIT_ACTIONS
- * Thanks to Magnus Holmgren for the patch
- *
- * Revision 1.35.2.3 2003/12/17 16:34:15 oes
- * - Prevent line wrap beween "View/Edit" link buttons on status page
- * - Some (mostly irrelevant) fixes for Out-of-mem-case handling
- *
- * Revision 1.35.2.2 2003/04/03 13:48:28 oes
- * Don't show "Edit" buttons #ifndef FEATURE_CGI_EDIT_ACTIONS
- *
- * Revision 1.35.2.1 2002/07/04 15:02:38 oes
- * Added ability to send redirects to send-banner CGI, so that it can completely mimic the image blocking action if called with type=auto
- *
- * Revision 1.35.2.1 2002/07/01 17:32:04 morcego
- * Applying patch from Andreas as provided by Hal on the list.
- * Message-ID: <20020701121218.V1606@feenix.burgiss.net>
- *
- * Revision 1.35 2002/05/12 21:44:44 jongfoster
- * Adding amiga.[ch] revision information, if on an amiga.
- *
- * Revision 1.34 2002/04/30 12:06:12 oes
- * Deleted unused code from default_cgi
- *
- * Revision 1.33 2002/04/30 11:14:52 oes
- * Made csp the first parameter in *action_to_html
- *
- * Revision 1.32 2002/04/26 18:29:13 jongfoster
- * Fixing this Visual C++ warning:
- * cgisimple.c(775) : warning C4018: '<' : signed/unsigned mismatch
- *
- * Revision 1.31 2002/04/26 12:54:36 oes
- * - Kill obsolete REDIRECT_URL code
- * - Error handling fixes
- * - Style sheet related HTML snipplet changes
- * - cgi_show_url_info:
- * - Matches now in table, actions on single lines,
- * linked to help
- * - standard.action suppressed
- * - Buttons to View and Edit AFs
- *
- * Revision 1.30 2002/04/24 02:18:08 oes
- * - show-status is now the starting point for editing
- * the actions files, generate list of all AFs with buttons
- * for viewing and editing, new look for file list (Jon:
- * buttons now aligned ;-P ), view mode now supports multiple
- * AFs, name changes, no view links for unspecified files,
- * no edit link for standard.action.
- *
- * - Jon's multiple AF patch: cgi_show_url_info now uses all
- * AFs and marks the output accordingly
- *
- * Revision 1.29 2002/04/10 13:38:35 oes
- * load_template signature changed
- *
- * Revision 1.28 2002/04/07 15:42:12 jongfoster
- * Fixing send-banner?type=auto when the image-blocker is
- * a redirect to send-banner
- *
- * Revision 1.27 2002/04/05 15:50:48 oes
- * added send-stylesheet CGI
- *
- * Revision 1.26 2002/04/04 00:36:36 gliptak
- * always use pcre for matching
- *
- * Revision 1.25 2002/04/03 22:28:03 gliptak
- * Removed references to gnu_regex
- *
- * Revision 1.24 2002/04/02 16:12:47 oes
- * Fix: moving misplaced lines into #ifdef FEATURE_FORCE
- *
- * Revision 1.23 2002/03/26 22:29:54 swa
- * we have a new homepage!
- *
- * Revision 1.22 2002/03/24 16:18:15 jongfoster
- * Removing old logo
- *
- * Revision 1.21 2002/03/24 15:23:33 jongfoster
- * Name changes
- *
- * Revision 1.20 2002/03/24 13:25:43 swa
- * name change related issues
- *
- * Revision 1.19 2002/03/16 23:54:06 jongfoster
- * Adding graceful termination feature, to help look for memory leaks.
- * If you enable this (which, by design, has to be done by hand
- * editing config.h) and then go to http://i.j.b/die, then the program
- * will exit cleanly after the *next* request. It should free all the
- * memory that was used.
- *
- * Revision 1.18 2002/03/12 01:44:49 oes
- * Changed default for "blocked" image from jb logo to checkboard pattern
- *
- * Revision 1.17 2002/03/08 16:43:18 oes
- * Added choice beween GIF and PNG built-in images
- *
- * Revision 1.16 2002/03/07 03:48:38 oes
- * - Changed built-in images from GIF to PNG
- * (with regard to Unisys patent issue)
- * - Added a 4x4 pattern PNG which is less intrusive
- * than the logo but also clearly marks the deleted banners
- *
- * Revision 1.15 2002/03/06 22:54:35 jongfoster
- * Automated function-comment nitpicking.
- *
- * Revision 1.14 2002/03/02 04:14:50 david__schmidt
- * Clean up a little CRLF unpleasantness that suddenly appeared
- *
- * Revision 1.13 2002/02/21 00:10:37 jongfoster
- * Adding send-banner?type=auto option
- *
- * Revision 1.12 2002/01/23 01:03:32 jongfoster
- * Fixing gcc [CygWin] compiler warnings
- *
- * Revision 1.11 2002/01/23 00:01:04 jongfoster
- * Adding cgi_transparent_gif() for http://i.j.b/t
- * Adding missing html_encode() to many CGI functions.
- * Adding urlmatch.[ch] to http://i.j.b/show-version
- *
- * Revision 1.10 2002/01/17 21:10:37 jongfoster
- * Changes to cgi_show_url_info to use new matching code from urlmatch.c.
- * Also fixing a problem in the same function with improperly quoted URLs
- * in output HTML, and adding code to handle https:// URLs correctly.
- *
- * Revision 1.9 2001/11/30 23:09:15 jongfoster
- * Now reports on FEATURE_CGI_EDIT_ACTIONS
- * Removing FEATURE_DENY_GZIP from template
- *
- * Revision 1.8 2001/11/13 00:14:07 jongfoster
- * Fixing stupid bug now I've figured out what || means.
- * (It always returns 0 or 1, not one of it's paramaters.)
- *
- * Revision 1.7 2001/10/23 21:48:19 jongfoster
- * Cleaning up error handling in CGI functions - they now send back
- * a HTML error page and should never cause a FATAL error. (Fixes one
- * potential source of "denial of service" attacks).
- *
- * CGI actions file editor that works and is actually useful.
- *
- * Ability to toggle JunkBuster remotely using a CGI call.
- *
- * You can turn off both the above features in the main configuration
- * file, e.g. if you are running a multi-user proxy.
- *
- * Revision 1.6 2001/10/14 22:00:32 jongfoster
- * Adding support for a 404 error when an invalid CGI page is requested.
- *
- * Revision 1.5 2001/10/07 15:30:41 oes
- * Removed FEATURE_DENY_GZIP
- *
- * Revision 1.4 2001/10/02 15:31:12 oes
- * Introduced show-request cgi
- *
- * Revision 1.3 2001/09/22 16:34:44 jongfoster
- * Removing unneeded #includes
- *
- * Revision 1.2 2001/09/19 18:01:11 oes
- * Fixed comments; cosmetics
- *
- * Revision 1.1 2001/09/16 17:08:54 jongfoster
- * Moving simple CGI functions from cgi.c to new file cgisimple.c
- *
- *
**********************************************************************/
-\f
+
#include "config.h"
const char cgisimple_h_rcs[] = CGISIMPLE_H_VERSION;
-
static char *show_rcs(void);
static jb_err show_defines(struct map *exports);
+static jb_err cgi_show_file(struct client_state *csp,
+ struct http_response *rsp,
+ const struct map *parameters);
+static jb_err load_file(const char *filename, char **buffer, size_t *length);
/*********************************************************************
*
{
struct map *exports;
+ (void)parameters;
+
assert(csp);
assert(rsp);
struct http_response *rsp,
const struct map *parameters)
{
+ (void)csp;
+ (void)parameters;
+
rsp->body = bindup(image_blank_data, image_blank_length);
rsp->content_length = image_blank_length;
"\017\000\000";
static const size_t favicon_length = sizeof(default_favicon_data) - 1;
+ (void)csp;
+ (void)parameters;
+
rsp->body = bindup(default_favicon_data, favicon_length);
rsp->content_length = favicon_length;
"\017\000\000";
static const size_t favicon_length = sizeof(error_favicon_data) - 1;
+ (void)csp;
+ (void)parameters;
+
rsp->body = bindup(error_favicon_data, favicon_length);
rsp->content_length = favicon_length;
assert(csp);
assert(rsp);
+ (void)parameters;
+
err = template_load(csp, &rsp->body, "cgi-style.css", 0);
if (err == JB_ERR_FILE)
return JB_ERR_OK;
}
+
+
+/*********************************************************************
+ *
+ * Function : cgi_send_url_info_osd
+ *
+ * Description : CGI function that sends the OpenSearch Description
+ * template for the show-url-info page. It allows to
+ * access the page through "search engine plugins".
+ *
+ * Parameters :
+ * 1 : csp = Current client state (buffers, headers, etc...)
+ * 2 : rsp = http_response data structure for output
+ * 3 : parameters = map of cgi parameters
+ *
+ * CGI Parameters : None
+ *
+ * Returns : JB_ERR_OK on success
+ * JB_ERR_MEMORY on out-of-memory error.
+ *
+ *********************************************************************/
+jb_err cgi_send_url_info_osd(struct client_state *csp,
+ struct http_response *rsp,
+ const struct map *parameters)
+{
+ jb_err err = JB_ERR_MEMORY;
+ struct map *exports = default_exports(csp, NULL);
+
+ (void)csp;
+ (void)parameters;
+
+ if (NULL != exports)
+ {
+ err = template_fill_for_cgi(csp, "url-info-osd.xml", exports, rsp);
+ if (JB_ERR_OK == err)
+ {
+ err = enlist(rsp->headers,
+ "Content-Type: application/opensearchdescription+xml");
+ }
+ }
+
+ return err;
+
+}
+
+
/*********************************************************************
*
* Function : cgi_send_user_manual
{
const char * filename;
char *full_path;
- FILE *fp;
jb_err err = JB_ERR_OK;
size_t length;
return JB_ERR_MEMORY;
}
- /* Open user-manual file */
- if (NULL == (fp = fopen(full_path, "rb")))
+ err = load_file(full_path, &rsp->body, &rsp->content_length);
+ if (JB_ERR_OK != err)
{
- log_error(LOG_LEVEL_ERROR, "Cannot open user-manual file %s: %E", full_path);
- err = cgi_error_no_template(csp, rsp, full_path);
- free(full_path);
+ assert((JB_ERR_FILE == err) || (JB_ERR_MEMORY == err));
+ if (JB_ERR_FILE == err)
+ {
+ err = cgi_error_no_template(csp, rsp, full_path);
+ }
+ freez(full_path);
return err;
}
-
- /* Get file length */
- fseek(fp, 0, SEEK_END);
- length = (size_t)ftell(fp);
- fseek(fp, 0, SEEK_SET);
-
- /* Allocate memory and load the file directly into the body */
- rsp->body = (char *)zalloc(length+1);
- if (!rsp->body)
- {
- fclose(fp);
- free(full_path);
- return JB_ERR_MEMORY;
- }
- if (!fread(rsp->body, length, 1, fp))
- {
- /*
- * May happen if the file size changes between fseek() and fread().
- * If it does, we just log it and serve what we got.
- */
- log_error(LOG_LEVEL_ERROR, "Couldn't completely read user-manual file %s.", full_path);
- }
- fclose(fp);
- free(full_path);
-
- rsp->content_length = length;
+ freez(full_path);
/* Guess correct Content-Type based on the filename's ending */
if (filename)
return template_fill_for_cgi(csp, "show-version", exports, rsp);
}
-
+
/*********************************************************************
*
* Function : cgi_show_status
* CGI Parameters :
* file : Which file to show. Only first letter is checked,
* valid values are:
- * - "p"ermissions (actions) file
+ * - "a"ction file
* - "r"egex
* - "t"rust
* Default is to show menu and other information.
unsigned i;
int j;
- FILE * fp;
char buf[BUFFER_SIZE];
- const char * filename = NULL;
- char * file_description = NULL;
#ifdef FEATURE_STATISTICS
float perc_rej; /* Percentage of http requests rejected */
int local_urls_read;
assert(rsp);
assert(parameters);
- if (NULL == (exports = default_exports(csp, "show-status")))
+ if ('\0' != *(lookup(parameters, "file")))
{
- return JB_ERR_MEMORY;
+ return cgi_show_file(csp, rsp, parameters);
}
- switch (*(lookup(parameters, "file")))
- {
- case 'a':
- if (!get_number_param(csp, parameters, "index", &i) && i < MAX_AF_FILES && csp->actions_list[i])
- {
- filename = csp->actions_list[i]->filename;
- file_description = "Actions File";
- }
- break;
-
- case 'f':
- if (!get_number_param(csp, parameters, "index", &i) && i < MAX_AF_FILES && csp->rlist[i])
- {
- filename = csp->rlist[i]->filename;
- file_description = "Filter File";
- }
- break;
-
-#ifdef FEATURE_TRUST
- case 't':
- if (csp->tlist)
- {
- filename = csp->tlist->filename;
- file_description = "Trust File";
- }
- break;
-#endif /* def FEATURE_TRUST */
- }
-
- if (NULL != filename)
+ if (NULL == (exports = default_exports(csp, "show-status")))
{
- if ( map(exports, "file-description", 1, file_description, 1)
- || map(exports, "filepath", 1, html_encode(filename), 0) )
- {
- free_map(exports);
- return JB_ERR_MEMORY;
- }
-
- if ((fp = fopen(filename, "rb")) == NULL)
- {
- if (map(exports, "content", 1, "<h1>ERROR OPENING FILE!</h1>", 1))
- {
- free_map(exports);
- return JB_ERR_MEMORY;
- }
- }
- else
- {
- /*
- * XXX: this code is "quite similar" to the one
- * in cgi_send_user_manual() and should be refactored.
- * While at it, the return codes for ftell() and fseek
- * should be verified.
- */
- size_t length;
- /* Get file length */
- fseek(fp, 0, SEEK_END);
- length = (size_t)ftell(fp);
- fseek(fp, 0, SEEK_SET);
-
- s = (char *)zalloc(length+1);
- if (NULL == s)
- {
- fclose(fp);
- return JB_ERR_MEMORY;
- }
- if (!fread(s, length, 1, fp))
- {
- /*
- * May happen if the file size changes between fseek() and fread().
- * If it does, we just log it and serve what we got.
- */
- log_error(LOG_LEVEL_ERROR, "Couldn't completely read file %s.", filename);
- }
- fclose(fp);
-
- s = html_encode_and_free_original(s);
- if (NULL == s)
- {
- return JB_ERR_MEMORY;
- }
-
- if (map(exports, "contents", 1, s, 0))
- {
- free_map(exports);
- return JB_ERR_MEMORY;
- }
- }
-
- return template_fill_for_cgi(csp, "show-status-file", exports, rsp);
+ return JB_ERR_MEMORY;
}
s = strdup("");
if (!err) err = string_append(&s, "<tr><td>");
if (!err) err = string_join(&s, html_encode(csp->actions_list[i]->filename));
snprintf(buf, sizeof(buf),
- "</td><td class=\"buttons\"><a href=\"/show-status?file=actions&index=%d\">View</a>", i);
+ "</td><td class=\"buttons\"><a href=\"/show-status?file=actions&index=%u\">View</a>", i);
if (!err) err = string_append(&s, buf);
#ifdef FEATURE_CGI_EDIT_ACTIONS
if (access(csp->config->actions_file[i], W_OK) == 0)
{
#endif /* def HAVE_ACCESS */
- snprintf(buf, sizeof(buf), " <a href=\"/edit-actions-list?f=%d\">Edit</a>", i);
+ snprintf(buf, sizeof(buf), " <a href=\"/edit-actions-list?f=%u\">Edit</a>", i);
if (!err) err = string_append(&s, buf);
#ifdef HAVE_ACCESS
}
{
if (!err) err = string_append(&s, "<tr><td>");
if (!err) err = string_join(&s, html_encode(csp->rlist[i]->filename));
- snprintf(buf, 100,
- "</td><td class=\"buttons\"><a href=\"/show-status?file=filter&index=%d\">View</a>", i);
+ snprintf(buf, sizeof(buf),
+ "</td><td class=\"buttons\"><a href=\"/show-status?file=filter&index=%u\">View</a>", i);
if (!err) err = string_append(&s, buf);
if (!err) err = string_append(&s, "</td></tr>\n");
}
url_param[0] = '\0';
}
}
- else if (url_param[0] != '\0')
+ else if ((url_param[0] != '\0') && (NULL == strstr(url_param, "://")))
{
- /*
- * Unknown prefix - assume http://
- */
- const size_t url_param_prefixed_size = 7 + 1 + strlen(url_param);
- char * url_param_prefixed = malloc(url_param_prefixed_size);
- if (NULL == url_param_prefixed)
+ /* No prefix - assume http:// */
+ char *url_param_prefixed = strdup("http://");
+
+ if (JB_ERR_OK != string_join(&url_param_prefixed, url_param))
{
- free(url_param);
free_map(exports);
return JB_ERR_MEMORY;
}
- strlcpy(url_param_prefixed, "http://", url_param_prefixed_size);
- strlcat(url_param_prefixed, url_param, url_param_prefixed_size);
- free(url_param);
url_param = url_param_prefixed;
}
return JB_ERR_MEMORY;
}
- err = parse_http_url(url_param, url_to_query, csp);
+ memset(url_to_query, '\0', sizeof(url_to_query));
+ err = parse_http_url(url_param, url_to_query, REQUIRE_PROTOCOL);
+ assert((err != JB_ERR_OK) || (url_to_query->ssl == !strncmpic(url_param, "https://", 8)));
free(url_param);
}
#endif /* FEATURE_CGI_EDIT_ACTIONS */
+ /*
+ * If zlib support is available, if no content filters
+ * are enabled or if the prevent-compression action is enabled,
+ * suppress the "compression could prevent filtering" warning.
+ */
+#ifndef FEATURE_ZLIB
+ if (!content_filters_enabled(action) ||
+ (action->flags & ACTION_NO_COMPRESSION))
+#endif
+ {
+ if (!err) err = map_block_killer(exports, "filters-might-be-ineffective");
+ }
+
if (err || map(exports, "matches", 1, matches , 0))
{
free_current_action(action);
char buf[100];
jb_err err;
+ (void)csp;
+ (void)parameters;
+
rsp->body = strdup(
"# This is the Privoxy control interface.\n"
"# It isn't very useful to index it, and you're likely to break stuff.\n"
#ifdef FEATURE_CGI_EDIT_ACTIONS
if (!err) err = map_conditional(exports, "FEATURE_CGI_EDIT_ACTIONS", 1);
-#else /* ifndef FEATURE_COOKIE_JAR */
+#else /* ifndef FEATURE_CGI_EDIT_ACTIONS */
if (!err) err = map_conditional(exports, "FEATURE_CGI_EDIT_ACTIONS", 0);
-#endif /* ndef FEATURE_COOKIE_JAR */
+#endif /* ndef FEATURE_CGI_EDIT_ACTIONS */
-#ifdef FEATURE_COOKIE_JAR
- if (!err) err = map_conditional(exports, "FEATURE_COOKIE_JAR", 1);
-#else /* ifndef FEATURE_COOKIE_JAR */
- if (!err) err = map_conditional(exports, "FEATURE_COOKIE_JAR", 0);
-#endif /* ndef FEATURE_COOKIE_JAR */
+#ifdef FEATURE_CONNECTION_KEEP_ALIVE
+ if (!err) err = map_conditional(exports, "FEATURE_CONNECTION_KEEP_ALIVE", 1);
+#else /* ifndef FEATURE_CONNECTION_KEEP_ALIVE */
+ if (!err) err = map_conditional(exports, "FEATURE_CONNECTION_KEEP_ALIVE", 0);
+#endif /* ndef FEATURE_CONNECTION_KEEP_ALIVE */
#ifdef FEATURE_FAST_REDIRECTS
if (!err) err = map_conditional(exports, "FEATURE_FAST_REDIRECTS", 1);
if (!err) err = map_conditional(exports, "FEATURE_IMAGE_DETECT_MSIE", 0);
#endif /* ndef FEATURE_IMAGE_DETECT_MSIE */
+#ifdef HAVE_RFC2553
+ if (!err) err = map_conditional(exports, "FEATURE_IPV6_SUPPORT", 1);
+#else /* ifndef HAVE_RFC2553 */
+ if (!err) err = map_conditional(exports, "FEATURE_IPV6_SUPPORT", 0);
+#endif /* ndef HAVE_RFC2553 */
+
#ifdef FEATURE_NO_GIFS
if (!err) err = map_conditional(exports, "FEATURE_NO_GIFS", 1);
#else /* ifndef FEATURE_NO_GIFS */
}
+/*********************************************************************
+ *
+ * Function : cgi_show_file
+ *
+ * Description : CGI function that shows the content of a
+ * configuration file.
+ *
+ * Parameters :
+ * 1 : csp = Current client state (buffers, headers, etc...)
+ * 2 : rsp = http_response data structure for output
+ * 3 : parameters = map of cgi parameters
+ *
+ * CGI Parameters :
+ * file : Which file to show. Only first letter is checked,
+ * valid values are:
+ * - "a"ction file
+ * - "r"egex
+ * - "t"rust
+ * Default is to show menu and other information.
+ *
+ * Returns : JB_ERR_OK on success
+ * JB_ERR_MEMORY on out-of-memory error.
+ *
+ *********************************************************************/
+static jb_err cgi_show_file(struct client_state *csp,
+ struct http_response *rsp,
+ const struct map *parameters)
+{
+ unsigned i;
+ const char * filename = NULL;
+ char * file_description = NULL;
+
+ assert(csp);
+ assert(rsp);
+ assert(parameters);
+
+ switch (*(lookup(parameters, "file")))
+ {
+ case 'a':
+ if (!get_number_param(csp, parameters, "index", &i) && i < MAX_AF_FILES && csp->actions_list[i])
+ {
+ filename = csp->actions_list[i]->filename;
+ file_description = "Actions File";
+ }
+ break;
+
+ case 'f':
+ if (!get_number_param(csp, parameters, "index", &i) && i < MAX_AF_FILES && csp->rlist[i])
+ {
+ filename = csp->rlist[i]->filename;
+ file_description = "Filter File";
+ }
+ break;
+
+#ifdef FEATURE_TRUST
+ case 't':
+ if (csp->tlist)
+ {
+ filename = csp->tlist->filename;
+ file_description = "Trust File";
+ }
+ break;
+#endif /* def FEATURE_TRUST */
+ }
+
+ if (NULL != filename)
+ {
+ struct map *exports;
+ char *s;
+ jb_err err;
+ size_t length;
+
+ exports = default_exports(csp, "show-status");
+ if (NULL == exports)
+ {
+ return JB_ERR_MEMORY;
+ }
+
+ if ( map(exports, "file-description", 1, file_description, 1)
+ || map(exports, "filepath", 1, html_encode(filename), 0) )
+ {
+ free_map(exports);
+ return JB_ERR_MEMORY;
+ }
+
+ err = load_file(filename, &s, &length);
+ if (JB_ERR_OK != err)
+ {
+ if (map(exports, "contents", 1, "<h1>ERROR OPENING FILE!</h1>", 1))
+ {
+ free_map(exports);
+ return JB_ERR_MEMORY;
+ }
+ }
+ else
+ {
+ s = html_encode_and_free_original(s);
+ if (NULL == s)
+ {
+ return JB_ERR_MEMORY;
+ }
+
+ if (map(exports, "contents", 1, s, 0))
+ {
+ free_map(exports);
+ return JB_ERR_MEMORY;
+ }
+ }
+
+ return template_fill_for_cgi(csp, "show-status-file", exports, rsp);
+ }
+
+ return JB_ERR_CGI_PARAMS;
+}
+
+
+/*********************************************************************
+ *
+ * Function : load_file
+ *
+ * Description : Loads a file into a buffer.
+ *
+ * Parameters :
+ * 1 : filename = Name of the file to be loaded.
+ * 2 : buffer = Used to return the file's content.
+ * 3 : length = Used to return the size of the file.
+ *
+ * Returns : JB_ERR_OK in case of success,
+ * JB_ERR_FILE in case of ordinary file loading errors
+ * (fseek() and ftell() errors are fatal)
+ * JB_ERR_MEMORY in case of out-of-memory.
+ *
+ *********************************************************************/
+static jb_err load_file(const char *filename, char **buffer, size_t *length)
+{
+ FILE *fp;
+ long ret;
+ jb_err err = JB_ERR_OK;
+
+ fp = fopen(filename, "rb");
+ if (NULL == fp)
+ {
+ return JB_ERR_FILE;
+ }
+
+ /* Get file length */
+ if (fseek(fp, 0, SEEK_END))
+ {
+ log_error(LOG_LEVEL_FATAL,
+ "Unexpected error while fseek()ing to the end of %s: %E",
+ filename);
+ }
+ ret = ftell(fp);
+ if (-1 == ret)
+ {
+ log_error(LOG_LEVEL_FATAL,
+ "Unexpected ftell() error while loading %s: %E",
+ filename);
+ }
+ *length = (size_t)ret;
+
+ /* Go back to the beginning. */
+ if (fseek(fp, 0, SEEK_SET))
+ {
+ log_error(LOG_LEVEL_FATAL,
+ "Unexpected error while fseek()ing to the beginning of %s: %E",
+ filename);
+ }
+
+ *buffer = (char *)zalloc(*length + 1);
+ if (NULL == *buffer)
+ {
+ err = JB_ERR_MEMORY;
+ }
+ else if (!fread(*buffer, *length, 1, fp))
+ {
+ /*
+ * May happen if the file size changes between fseek() and
+ * fread(). If it does, we just log it and serve what we got.
+ */
+ log_error(LOG_LEVEL_ERROR,
+ "Couldn't completely read file %s.", filename);
+ err = JB_ERR_FILE;
+ }
+
+ fclose(fp);
+
+ return err;
+
+}
+
+
/*
Local Variables:
tab-width: 3