-const char filters_rcs[] = "$Id: filters.c,v 1.17 2001/06/09 10:55:28 jongfoster Exp $";
+const char filters_rcs[] = "$Id: filters.c,v 1.28 2001/09/10 10:18:51 oes Exp $";
/*********************************************************************
*
* File : $Source: /cvsroot/ijbswa/current/filters.c,v $
* `acl_addr', `add_stats', `block_acl', `block_imageurl',
* `block_url', `url_actions', `domaincmp', `dsplit',
* `filter_popups', `forward_url', 'redirect_url',
- * `ij_untrusted_url', `intercept_url', `re_process_buffer',
+ * `ij_untrusted_url', `intercept_url', `pcrs_filter_respose',
* `show_proxy_args', 'ijb_send_banner', and `trust_url'
*
* Copyright : Written by and Copyright (C) 2001 the SourceForge
*
* Revisions :
* $Log: filters.c,v $
+ * Revision 1.28 2001/09/10 10:18:51 oes
+ * Silenced compiler warnings
+ *
+ * Revision 1.27 2001/08/05 16:06:20 jongfoster
+ * Modifiying "struct map" so that there are now separate header and
+ * "map_entry" structures. This means that functions which modify a
+ * map no longer need to return a pointer to the modified map.
+ * Also, it no longer reverses the order of the entries (which may be
+ * important with some advanced template substitutions).
+ *
+ * Revision 1.26 2001/07/30 22:08:36 jongfoster
+ * Tidying up #defines:
+ * - All feature #defines are now of the form FEATURE_xxx
+ * - Permanently turned off WIN_GUI_EDIT
+ * - Permanently turned on WEBDAV and SPLIT_PROXY_ARGS
+ *
+ * Revision 1.25 2001/07/26 10:09:46 oes
+ * Made browser detection a little less naive
+ *
+ * Revision 1.24 2001/07/25 17:22:51 oes
+ * Added workaround for Netscape bug that prevents display of page when loading a component fails.
+ *
+ * Revision 1.23 2001/07/23 13:40:12 oes
+ * Fixed bug that caused document body to be dropped when pcrs joblist was empty.
+ *
+ * Revision 1.22 2001/07/18 12:29:34 oes
+ * - Made gif_deanimate_response respect
+ * csp->action->string[ACTION_STRING_DEANIMATE]
+ * - Logging cosmetics
+ *
+ * Revision 1.21 2001/07/13 13:59:53 oes
+ * - Introduced gif_deanimate_response which shares the
+ * generic content modification interface of pcrs_filter_response
+ * and acts as a wrapper to deanimate.c:gif_deanimate()
+ * - Renamed re_process_buffer to pcrs_filter_response
+ * - pcrs_filter_response now returns NULL on failiure
+ * - Removed all #ifdef PCRS
+ *
+ * Revision 1.20 2001/07/01 17:01:04 oes
+ * Added comments and missing return statement in is_untrusted_url()
+ *
+ * Revision 1.19 2001/06/29 21:45:41 oes
+ * Indentation, CRLF->LF, Tab-> Space
+ *
+ * Revision 1.18 2001/06/29 13:27:38 oes
+ * - Cleaned up, renamed and reorderd functions
+ * and improved comments
+ *
+ * - block_url:
+ * - Ported to CGI platform. Now delivers
+ * http_response or NULL
+ * - Unified HTML and GIF generation (moved image detection
+ * and GIF generation here from jcc.c:chat())
+ * - Fixed HTTP status to:
+ * - 403 (Forbidden) for the "blocked" HTML message
+ * - 200 (OK) for GIF answers
+ * - 302 (Redirect) for redirect to GIF
+ *
+ * - trust_url:
+ * - Ported to CGI platform. Now delivers
+ * http_response or NULL
+ * - Separated detection of untrusted URL into
+ * (bool)is_untrusted_url
+ * - Added enforcement of untrusted requests
+ *
+ * - Moved redirect_url() from cgi.c to here
+ * and ported it to the CGI platform
+ *
+ * - Removed logentry from cancelled commit
+ *
* Revision 1.17 2001/06/09 10:55:28 jongfoster
* Changing BUFSIZ ==> BUFFER_SIZE
*
#include "actions.h"
#include "cgi.h"
#include "list.h"
+#include "deanimate.h"
#ifdef _WIN32
#include "win32.h"
#define ijb_isdigit(__X) isdigit((int)(unsigned char)(__X))
-#ifdef ACL_FILES
+#ifdef FEATURE_ACL
/*********************************************************************
*
* Function : block_acl
* Returns : 0 = FALSE (don't block) and 1 = TRUE (do block)
*
*********************************************************************/
-int block_acl(struct access_control_addr *dst,
- struct client_state *csp)
+int block_acl(struct access_control_addr *dst, struct client_state *csp)
{
struct access_control_list *acl = csp->config->acl;
return(0);
}
-#endif /* def ACL_FILES */
+#endif /* def FEATURE_ACL */
/*********************************************************************
*********************************************************************/
struct http_response *block_url(struct client_state *csp)
{
+#ifdef FEATURE_IMAGE_BLOCKING
char *p;
- struct http_response *rsp;
- struct map *exports = NULL;
+#endif /* def FEATURE_IMAGE_BLOCKING */
+ struct http_response *rsp;
/*
* If it's not blocked, don't block it ;-)
* If it's an image-url, send back an image or redirect
* as specified by the relevant +image action
*/
-#ifdef IMAGE_BLOCKING
- if (((csp->action->flags & ACTION_IMAGE_BLOCKER) != 0)
+#ifdef FEATURE_IMAGE_BLOCKING
+ if (((csp->action->flags & ACTION_IMAGE_BLOCKER) != 0)
&& is_imageurl(csp))
- {
- /* determine HOW images should be blocked */
+ {
+ /* determine HOW images should be blocked */
p = csp->action->string[ACTION_STRING_IMAGE_BLOCKER];
/* and handle accordingly: */
if ((p == NULL) || (0 == strcmpic(p, "logo")))
{
- rsp->body = bindup(JBGIF, sizeof(JBGIF));
- rsp->content_length = sizeof(JBGIF);
+ rsp->body = bindup(image_junkbuster_gif_data, image_junkbuster_gif_length);
+ rsp->content_length = image_junkbuster_gif_length;
enlist_unique_header(rsp->headers, "Content-Type", "image/gif");
}
else if (0 == strcmpic(p, "blank"))
{
- rsp->body = bindup(BLANKGIF, sizeof(BLANKGIF));
- rsp->content_length = sizeof(BLANKGIF);
+ rsp->body = bindup(image_blank_gif_data, image_blank_gif_length);
+ rsp->content_length = image_blank_gif_length;
enlist_unique_header(rsp->headers, "Content-Type", "image/gif");
}
}
}
else
-#endif /* def IMAGE_BLOCKING */
+#endif /* def FEATURE_IMAGE_BLOCKING */
/*
* Else, generate an HTML "blocked" message:
*/
{
-
- exports = default_exports(csp, NULL);
-#ifdef FORCE_LOAD
- exports = map(exports, "force-prefix", 1, FORCE_PREFIX, 1);
-#else
- exports = map_block_killer(exports, "force-support");
-#endif /* ndef FORCE_LOAD */
-
- exports = map(exports, "hostport", 1, csp->http->hostport, 1);
- exports = map(exports, "hostport-html", 1, html_encode(csp->http->hostport), 0);
- exports = map(exports, "path", 1, csp->http->path, 1);
- exports = map(exports, "path-html", 1, html_encode(csp->http->path), 0);
+ struct map * exports = default_exports(csp, NULL);
+#ifdef FEATURE_FORCE_LOAD
+ map(exports, "force-prefix", 1, FORCE_PREFIX, 1);
+#else /* ifndef FEATURE_FORCE_LOAD */
+ map_block_killer(exports, "force-support");
+#endif /* ndef FEATURE_FORCE_LOAD */
+
+ map(exports, "hostport", 1, csp->http->hostport, 1);
+ map(exports, "hostport-html", 1, html_encode(csp->http->hostport), 0);
+ map(exports, "path", 1, csp->http->path, 1);
+ map(exports, "path-html", 1, html_encode(csp->http->path), 0);
rsp->body = fill_template(csp, "blocked", exports);
free_map(exports);
- rsp->status = strdup("403 Request for blocked URL");
+ /*
+ * Workaround for stupid Netscape bug which prevents
+ * pages from being displayed if loading a referenced
+ * JavaScript or style sheet fails. So make it appear
+ * as if it succeeded.
+ */
+ if (csp->http->user_agent
+ && !strncmpic(csp->http->user_agent, "mozilla", 7)
+ && !strstr(csp->http->user_agent, "compatible")
+ && !strstr(csp->http->user_agent, "Opera"))
+ {
+ rsp->status = strdup("200 Request for blocked URL");
+ }
+ else
+ {
+ rsp->status = strdup("404 Request for blocked URL");
+ }
+
}
return(finish_http_response(rsp));
}
-#ifdef TRUST_FILES
+#ifdef FEATURE_TRUST
/*********************************************************************
*
* Function : trust_url FIXME: I should be called distrust_url
struct http_response *trust_url(struct client_state *csp)
{
struct http_response *rsp;
- struct map *exports = NULL;
+ struct map * exports;
char buf[BUFFER_SIZE], *p = NULL;
struct url_spec **tl, *t;
*/
if (!is_untrusted_url(csp))
{
- return NULL;
+ return NULL;
}
/*
{
return NULL;
}
+
exports = default_exports(csp, NULL);
/*
* Export the host, port, and referrer information
- */
- exports = map(exports, "hostport", 1, csp->http->hostport, 1);
- exports = map(exports, "path", 1, csp->http->path, 1);
- exports = map(exports, "hostport-html", 1, html_encode(csp->http->hostport), 0);
- exports = map(exports, "path-html", 1, html_encode(csp->http->path), 0);
+ */
+ map(exports, "hostport", 1, csp->http->hostport, 1);
+ map(exports, "path", 1, csp->http->path, 1);
+ map(exports, "hostport-html", 1, html_encode(csp->http->hostport), 0);
+ map(exports, "path-html", 1, html_encode(csp->http->path), 0);
if (csp->referrer && strlen(csp->referrer) > 9)
{
- exports = map(exports, "referrer", 1, csp->referrer + 9, 1);
- exports = map(exports, "referrer-html", 1, html_encode(csp->referrer + 9), 0);
+ map(exports, "referrer", 1, csp->referrer + 9, 1);
+ map(exports, "referrer-html", 1, html_encode(csp->referrer + 9), 0);
}
else
{
- exports = map(exports, "referrer", 1, "unknown", 1);
- exports = map(exports, "referrer-html", 1, "unknown", 1);
+ map(exports, "referrer", 1, "unknown", 1);
+ map(exports, "referrer-html", 1, "unknown", 1);
}
/*
sprintf(buf, "<li>%s</li>\n", t->spec);
p = strsav(p, buf);
}
- exports = map(exports, "trusted-referrers", 1, p, 0);
+ map(exports, "trusted-referrers", 1, p, 0);
p = NULL;
/*
for (l = csp->config->trust_info->next; l ; l = l->next)
{
- sprintf(buf,
- "<li> <a href=%s>%s</a><br>\n",
- l->str, l->str);
+ sprintf(buf, "<li> <a href=%s>%s</a><br>\n",l->str, l->str);
p = strsav(p, buf);
}
- exports = map(exports, "trust-info", 1, p, 0);
+ map(exports, "trust-info", 1, p, 0);
}
else
- {
- exports = map_block_killer(exports, "have-trust-info");
- }
+ {
+ map_block_killer(exports, "have-trust-info");
+ }
/*
* Export the force prefix or the force conditional block killer
*/
-#ifdef FORCE_LOAD
- exports = map(exports, "force-prefix", 1, FORCE_PREFIX, 1);
-#else
- exports = map_block_killer(exports, "force-support");
-#endif /* ndef FORCE_LOAD */
+#ifdef FEATURE_FORCE_LOAD
+ map(exports, "force-prefix", 1, FORCE_PREFIX, 1);
+#else /* ifndef FEATURE_FORCE_LOAD */
+ map_block_killer(exports, "force-support");
+#endif /* ndef FEATURE_FORCE_LOAD */
/*
* Build the response
return(finish_http_response(rsp));
}
-#endif /* def TRUST_FILES */
+#endif /* def FEATURE_TRUST */
-#ifdef FAST_REDIRECTS
+#ifdef FEATURE_FAST_REDIRECTS
/*********************************************************************
*
* Function : redirect_url
/*
* find the last URL encoded in the request
*/
- while (p = strstr(p, "http://"))
+ while ((p = strstr(p, "http://")))
{
q = p++;
}
}
}
-#endif /* def FAST_REDIRECTS */
+#endif /* def FEATURE_FAST_REDIRECTS */
-#ifdef IMAGE_BLOCKING
+#ifdef FEATURE_IMAGE_BLOCKING
/*********************************************************************
*
* Function : is_imageurl
*
* Description : Given a URL, decide whether it is an image or not,
* using either the info from a previous +image action
- * or, #ifdef DETECT_MSIE_IMAGES, the info from the
- * browser's accept header.
+ * or, #ifdef FEATURE_IMAGE_DETECT_MSIE, the info from
+ * the browser's accept header.
*
* Parameters :
* 1 : csp = Current client state (buffers, headers, etc...)
*********************************************************************/
int is_imageurl(struct client_state *csp)
{
-#ifdef DETECT_MSIE_IMAGES
+#ifdef FEATURE_IMAGE_DETECT_MSIE
if ((csp->accept_types
& (ACCEPT_TYPE_IS_MSIE|ACCEPT_TYPE_MSIE_IMAGE|ACCEPT_TYPE_MSIE_HTML))
== (ACCEPT_TYPE_IS_MSIE|ACCEPT_TYPE_MSIE_IMAGE))
{
return 0;
}
-#endif
+#endif /* def FEATURE_IMAGE_DETECT_MSIE */
return ((csp->action->flags & ACTION_IMAGE) != 0);
}
-#endif /* def IMAGE_BLOCKING */
+#endif /* def FEATURE_IMAGE_BLOCKING */
-#ifdef TRUST_FILES
+#ifdef FEATURE_COOKIE_JAR
/*********************************************************************
*
* Function : is_untrusted_url
struct http_request rhttp[1];
char *p, *h;
+ /*
+ * If we don't have a trustlist, we trust everybody
+ */
if (((fl = csp->tlist) == NULL) || ((b = fl->f) == NULL))
{
return(0);
}
+
+ /*
+ * Do we trust the request URL itself?
+ */
*url = dsplit(csp->http->host);
/* if splitting the domain fails, punt */
if ((csp->referrer == NULL)|| (strlen(csp->referrer) <= 9))
{
/* no referrer was supplied */
- return(1);
+ return(1);
}
/* forge a URL from the referrer so we can use
return(1);
}
+
+ /*
+ * If not, do we maybe trust its referrer?
+ */
*url = dsplit(rhttp->host);
/* if splitting the domain fails, punt */
}
}
}
-
+ return(1);
}
-#endif /* def TRUST_FILES */
+#endif /* def FEATURE_COOKIE_JAR */
-#ifdef PCRS
/*********************************************************************
*
- * Function : re_process_buffer
+ * Function : pcrs_filter_response
*
* Description : Apply all the pcrs jobs from the joblist (re_filterfile)
* to the text buffer that's been accumulated in
* 1 : csp = Current client state (buffers, headers, etc...)
*
* Returns : a pointer to the (newly allocated) modified buffer.
- * or an empty string in case something went wrong
+ * or NULL in case something went wrong
*
*********************************************************************/
-char *re_process_buffer(struct client_state *csp)
+char *pcrs_filter_response(struct client_state *csp)
{
int hits=0;
int size = csp->iob->eod - csp->iob->cur;
/* Sanity first ;-) */
if (size <= 0)
{
- return(strdup(""));
+ return(NULL);
}
if ( ( NULL == (fl = csp->rlist) ) || ( NULL == (b = fl->f) ) )
{
log_error(LOG_LEVEL_ERROR, "Unable to get current state of regexp filtering.");
- return(strdup(""));
+ return(NULL);
+ }
+
+ if ( NULL == b->joblist )
+ {
+ log_error(LOG_LEVEL_RE_FILTER, "Empty joblist. Nothing to do.");
+ return(NULL);
}
log_error(LOG_LEVEL_RE_FILTER, "re_filtering %s%s (size %d) ...",
return(new);
}
-#endif /* def PCRS */
+
+
+/*********************************************************************
+ *
+ * Function : gif_deanimate_response
+ *
+ * Description : Deanimate the GIF image that has been accumulated in
+ * csp->iob->buf and set csp->content_length to the modified
+ * size.
+ *
+ * Parameters :
+ * 1 : csp = Current client state (buffers, headers, etc...)
+ *
+ * Returns : a pointer to the (newly allocated) modified buffer.
+ * or NULL in case something went wrong.
+ *
+ *********************************************************************/
+char *gif_deanimate_response(struct client_state *csp)
+{
+ struct binbuffer *in, *out;
+ char *p;
+ int size = csp->iob->eod - csp->iob->cur;
+
+ if ( (NULL == (in = (struct binbuffer *)zalloc(sizeof *in )))
+ || (NULL == (out = (struct binbuffer *)zalloc(sizeof *out))) )
+ {
+ log_error(LOG_LEVEL_DEANIMATE, "failed! (no mem)");
+ return NULL;
+ }
+
+ in->buffer = csp->iob->cur;
+ in->size = size;
+
+ if (gif_deanimate(in, out, strncmp("last", csp->action->string[ACTION_STRING_DEANIMATE], 4)))
+ {
+ log_error(LOG_LEVEL_DEANIMATE, "failed! (gif parsing)");
+ free(in);
+ buf_free(out);
+ return(NULL);
+ }
+ else
+ {
+ log_error(LOG_LEVEL_DEANIMATE, "Success! GIF shrunk from %d bytes to %d.", size, out->offset);
+ csp->content_length = out->offset;
+ p = out->buffer;
+ free(in);
+ free(out);
+ return(p);
+ }
+
+}
/*********************************************************************
}
apply_url_actions(csp->action, http, b);
+
}
const struct forward_spec * forward_url(struct http_request *http,
struct client_state *csp)
{
- static const struct forward_spec fwd_default[1] = { 0 }; /* All zeroes */
+ static const struct forward_spec fwd_default[1] = { FORWARD_SPEC_INITIALIZER };
struct forward_spec *fwd = csp->config->forward;
struct url_spec url[1];
if (domain[strlen(domain) - 1] == '.')
{
- ret->unanchored |= ANCHOR_RIGHT;
- }
- if (domain[0] == '.')
+ ret->unanchored |= ANCHOR_RIGHT;
+ }
+
+ if (domain[0] == '.')
{
- ret->unanchored |= ANCHOR_LEFT;
- }
+ ret->unanchored |= ANCHOR_LEFT;
+ }
ret->dbuf = strdup(domain);
memcpy(ret->dvec, v, size);
}
-
return(*ret);
}
}
return 0;
+
}
}
return 1;
}
-}
+}
/*