18 #include <QStringList>
19 #include <QCryptographicHash>
27 #include <sys/types.h>
33 #include <netinet/tcp.h>
44 #include "libmythbase/mythversion.h"
59 {
"gif" ,
"image/gif" },
60 {
"ico" ,
"image/x-icon" },
61 {
"jpeg",
"image/jpeg" },
62 {
"jpg" ,
"image/jpeg" },
63 {
"mng" ,
"image/x-mng" },
64 {
"png" ,
"image/png" },
65 {
"svg" ,
"image/svg+xml" },
66 {
"svgz",
"image/svg+xml" },
67 {
"tif" ,
"image/tiff" },
68 {
"tiff",
"image/tiff" },
70 {
"htm" ,
"text/html" },
71 {
"html",
"text/html" },
72 {
"qsp" ,
"text/html" },
73 {
"txt" ,
"text/plain" },
74 {
"xml" ,
"text/xml" },
75 {
"qxml",
"text/xml" },
76 {
"xslt",
"text/xml" },
77 {
"css" ,
"text/css" },
79 {
"crt" ,
"application/x-x509-ca-cert" },
80 {
"doc" ,
"application/vnd.ms-word" },
81 {
"gz" ,
"application/x-tar" },
82 {
"js" ,
"application/javascript" },
83 {
"m3u" ,
"application/x-mpegurl" },
84 {
"m3u8",
"application/x-mpegurl" },
85 {
"ogx" ,
"application/ogg" },
86 {
"pdf" ,
"application/pdf" },
87 {
"pem" ,
"application/x-x509-ca-cert" },
88 {
"qjs" ,
"application/javascript" },
89 {
"rm" ,
"application/vnd.rn-realmedia" },
90 {
"swf" ,
"application/x-shockwave-flash" },
91 {
"xls" ,
"application/vnd.ms-excel" },
92 {
"zip" ,
"application/x-tar" },
94 {
"aac" ,
"audio/mp4" },
95 {
"ac3" ,
"audio/vnd.dolby.dd-raw" },
96 {
"flac",
"audio/x-flac" },
97 {
"m4a" ,
"audio/x-m4a" },
98 {
"mid" ,
"audio/midi" },
99 {
"mka" ,
"audio/x-matroska" },
100 {
"mp3" ,
"audio/mpeg" },
101 {
"oga" ,
"audio/ogg" },
102 {
"ogg" ,
"audio/ogg" },
103 {
"wav" ,
"audio/wav" },
104 {
"wma" ,
"audio/x-ms-wma" },
106 {
"3gp" ,
"video/3gpp" },
107 {
"3g2" ,
"video/3gpp2" },
108 {
"asx" ,
"video/x-ms-asf" },
109 {
"asf" ,
"video/x-ms-asf" },
110 {
"avi" ,
"video/x-msvideo" },
111 {
"m2p" ,
"video/mp2p" },
112 {
"m4v" ,
"video/mp4" },
113 {
"mpeg",
"video/mp2p" },
114 {
"mpeg2",
"video/mp2p" },
115 {
"mpg" ,
"video/mp2p" },
116 {
"mpg2",
"video/mp2p" },
117 {
"mov" ,
"video/quicktime" },
118 {
"mp4" ,
"video/mp4" },
119 {
"mkv" ,
"video/x-matroska" },
120 {
"nuv" ,
"video/nupplevideo" },
121 {
"ogv" ,
"video/ogg" },
122 {
"ps" ,
"video/mp2p" },
123 {
"ts" ,
"video/mp2t" },
124 {
"vob" ,
"video/mpeg" },
125 {
"wmv" ,
"video/x-ms-wmv" },
127 {
"ttf" ,
"font/ttf" },
128 {
"woff" ,
"font/woff" },
129 {
"woff2",
"font/woff2" }
142 "<TITLE>Error %1</TITLE>"
143 "<META HTTP-EQUIV=\"Content-Type\" CONTENT=\"text/html; charset=ISO-8859-1\">"
145 "<BODY><H1>%2.</H1></BODY>"
157 if (!values.isEmpty())
158 return values.last();
182 LOG(VB_HTTP, LOG_INFO,
183 QString(
"HTTPRequest::SentRequestType( %1 ) - returning Unknown.")
256 if (sTransferMode.isEmpty())
260 sTransferMode =
"Streaming";
262 sTransferMode =
"Interactive";
265 if (sTransferMode ==
"Streaming")
267 else if (sTransferMode ==
"Background")
269 else if (sTransferMode ==
"Interactive")
274 SetResponseHeader(
"contentFeatures.dlna.org",
"DLNA.ORG_OP=01;DLNA.ORG_CI=0;DLNA.ORG_FLAGS=01500000000000000000000000000000");
278 for (
const auto & value : std::as_const(values))
281 if (qEnvironmentVariableIsSet(
"HTTPREQUEST_DEBUG"))
284 QMap<QString, QString>::iterator it;
287 LOG(VB_HTTP, LOG_INFO, QString(
"(Response Header) %1: %2").arg(it.key(), it.value()));
310 LOG(VB_HTTP, LOG_INFO,
311 QString(
"HTTPRequest::SendResponse( None ) :%1 -> %2:")
325 if (
file.exists() &&
file.size() < (2LL * 1024 * 1024) &&
326 file.open(QIODevice::ReadOnly | QIODevice::Text))
337 LOG(VB_HTTP, LOG_INFO,
338 QString(
"HTTPRequest::SendResponse( File ) :%1 -> %2:")
347 LOG(VB_HTTP, LOG_INFO,
348 QString(
"HTTPRequest::SendResponse(xml/html) (%1) :%2 -> %3: %4")
360 LOG(VB_HTTP, LOG_INFO,
361 QString(
"HTTPRequest::SendResponse(%1) - Cached")
373 int nContentLen =
m_response.buffer().length();
379 if (qEnvironmentVariableIsSet(
"HTTPREQUEST_DEBUG"))
380 std::cout <<
m_response.buffer().constData() << std::endl;
383 LOG(VB_HTTP, LOG_DEBUG, QString(
"Reponse Content Length: %1").arg(nContentLen));
392 bool gzip_found = std::any_of(values.cbegin(), values.cend(),
393 [](
const auto & value)
394 {return value.contains(
"gzip" ); });
396 if (( nContentLen > 0 ) && gzip_found)
399 compBuffer.setData( compressed );
401 if (!compBuffer.buffer().isEmpty())
403 pBuffer = &compBuffer;
406 LOG(VB_HTTP, LOG_DEBUG, QString(
"Reponse Compressed Content Length: %1").arg(compBuffer.buffer().length()));
414 nContentLen = pBuffer->buffer().length();
418 QByteArray sHeader = rHeader.toUtf8();
419 LOG(VB_HTTP, LOG_DEBUG, QString(
"Response header size: %1 bytes").arg(sHeader.length()));
420 nBytes =
WriteBlock( sHeader.constData(), sHeader.length() );
422 if (nBytes < sHeader.length())
424 LOG( VB_HTTP, LOG_ERR, QString(
"HttpRequest::SendResponse(): "
425 "Incomplete write of header, "
427 .arg(nBytes).arg(sHeader.length()));
437 qint64 bytesWritten =
SendData( pBuffer, 0, nContentLen );
440 if (bytesWritten != nContentLen)
441 LOG(VB_HTTP, LOG_ERR,
"HttpRequest::SendResponse(): Error occurred while writing response body.");
443 nBytes += bytesWritten;
456 long long llSize = 0;
457 long long llStart = 0;
460 LOG(VB_HTTP, LOG_INFO, QString(
"SendResponseFile ( %1 )").arg(sFileName));
465 QFile tmpFile( sFileName );
466 if (tmpFile.exists( ) && tmpFile.open( QIODevice::ReadOnly ))
475 llSize = llEnd = tmpFile.size( );
486 if (!sRange.isEmpty())
488 bRange =
ParseRange( sRange, llSize, &llStart, &llEnd );
495 if ((llSize > llStart) && (llSize > llEnd) && (llEnd > llStart))
504 llSize = (llEnd - llStart) + 1;
516 LOG(VB_HTTP, LOG_INFO,
517 QString(
"HTTPRequest::SendResponseFile(%1) - "
518 "invalid byte range %2-%3/%4")
519 .arg(sFileName) .arg(llStart) .arg(llEnd)
537 LOG(VB_HTTP, LOG_INFO,
538 QString(
"HTTPRequest::SendResponseFile(%1) - cannot find file!")
551 QByteArray sHeader = rHeader.toUtf8();
552 LOG(VB_HTTP, LOG_DEBUG, QString(
"Response header size: %1 bytes").arg(sHeader.length()));
553 nBytes =
WriteBlock( sHeader.constData(), sHeader.length() );
555 if (nBytes < sHeader.length())
557 LOG( VB_HTTP, LOG_ERR, QString(
"HttpRequest::SendResponseFile(): "
558 "Incomplete write of header, "
560 .arg(nBytes).arg(sHeader.length()));
568 LOG(VB_HTTP, LOG_DEBUG,
569 QString(
"SendResponseFile : size = %1, start = %2, end = %3")
570 .arg(llSize).arg(llStart).arg(llEnd));
574 long long sent =
SendFile( tmpFile, llStart, llSize );
578 LOG(VB_HTTP, LOG_INFO,
579 QString(
"SendResponseFile( %1 ) Error: %2 [%3]" )
580 .arg(sFileName) .arg(errno) .arg(strerror(errno)));
600 bool bShouldClose =
false;
603 if (!pDevice->isOpen())
605 pDevice->open( QIODevice::ReadOnly );
613 if ( !pDevice->seek( llStart ))
616 std::array<char,SENDFILE_BUFFER_SIZE> aBuffer {};
618 qint64 llBytesRemaining = llBytes;
619 qint64 llBytesToRead = 0;
620 qint64 llBytesRead = 0;
622 while ((sent < llBytes) && !pDevice->atEnd())
625 llBytesRead = pDevice->read( aBuffer.data(), llBytesToRead );
626 if ( llBytesRead != -1 )
628 if (
WriteBlock( aBuffer.data(), llBytesRead ) == -1)
634 llBytesRemaining -= llBytesRead;
650 qint64 sent =
SendData( (QIODevice *)(&
file), llStart, llBytes );
661 const QString &sFaultString,
662 const QString &sDetails )
669 stream << R
"(<?xml version="1.0" encoding="utf-8"?>)";
671 QString sWhere = ( bServerError ) ? "s:Server" :
"s:Client";
679 <<
"<faultcode>" << sWhere <<
"</faultcode>"
680 <<
"<faultstring>" << sFaultString <<
"</faultstring>";
683 if (!sDetails.isEmpty())
685 stream <<
"<detail>" << sDetails <<
"</detail>";
722 stream <<
"<?xml version=\"1.0\" encoding=\"utf-8\"?>\r\n";
729 <<
"<u:" <<
m_sMethod <<
"Response xmlns:u=\""
734 stream <<
"<" <<
m_sMethod <<
"Response>\r\n";
737 for (
const auto & arg : std::as_const(
args))
739 stream <<
"<" << arg.m_sName;
741 if (arg.m_pAttributes)
743 for (
const auto & attr : std::as_const(*arg.m_pAttributes))
745 stream <<
" " << attr.m_sName <<
"='"
746 <<
Encode( attr.m_sValue ) <<
"'";
753 stream <<
Encode( arg.m_sValue );
755 stream << arg.m_sValue;
757 stream <<
"</" << arg.m_sName <<
">\r\n";
762 stream <<
"</u:" <<
m_sMethod <<
"Response>\r\n"
767 stream <<
"</" <<
m_sMethod <<
"Response>\r\n";
800 #if QT_VERSION < QT_VERSION_CHECK(6,5,0)
801 ims.setTimeSpec(Qt::UTC);
803 ims.setTimeZone(QTimeZone(QTimeZone::UTC));
805 if (ims.isValid() && ims <=
file.lastModified())
826 LOG(VB_HTTP, LOG_INFO,
827 QString(
"HTTPRequest::FormatFileResponse('%1') - cannot find file")
838 m_sProtocol = sLine.section(
'/', 0, 0 ).trimmed();
839 QString sVersion = sLine.section(
'/', 1 ).trimmed();
841 m_nMajor = sVersion.section(
'.', 0, 0 ).toInt();
842 m_nMinor = sVersion.section(
'.', 1 ).toInt();
883 if ((sType ==
"application/x-www-form-urlencoded" ) ||
884 (sType.startsWith(
"application/x-www-form-urlencoded;")))
887 if ((sType ==
"text/xml" ) ||
888 (sType.startsWith(
"text/xml;") ))
891 if ((sType ==
"application/json") ||
892 sType.startsWith(
"application/json;"))
907 case 200:
return(
"200 OK" );
908 case 201:
return(
"201 Created" );
909 case 202:
return(
"202 Accepted" );
910 case 204:
return(
"204 No Content" );
911 case 205:
return(
"205 Reset Content" );
912 case 206:
return(
"206 Partial Content" );
913 case 300:
return(
"300 Multiple Choices" );
914 case 301:
return(
"301 Moved Permanently" );
915 case 302:
return(
"302 Found" );
916 case 303:
return(
"303 See Other" );
917 case 304:
return(
"304 Not Modified" );
918 case 305:
return(
"305 Use Proxy" );
919 case 307:
return(
"307 Temporary Redirect" );
920 case 308:
return(
"308 Permanent Redirect" );
921 case 400:
return(
"400 Bad Request" );
922 case 401:
return(
"401 Unauthorized" );
923 case 403:
return(
"403 Forbidden" );
924 case 404:
return(
"404 Not Found" );
925 case 405:
return(
"405 Method Not Allowed" );
926 case 406:
return(
"406 Not Acceptable" );
927 case 408:
return(
"408 Request Timeout" );
928 case 410:
return(
"410 Gone" );
929 case 411:
return(
"411 Length Required" );
930 case 412:
return(
"412 Precondition Failed" );
931 case 413:
return(
"413 Request Entity Too Large" );
932 case 414:
return(
"414 Request-URI Too Long" );
933 case 415:
return(
"415 Unsupported Media Type" );
934 case 416:
return(
"416 Requested Range Not Satisfiable" );
935 case 417:
return(
"417 Expectation Failed" );
937 case 428:
return(
"428 Precondition Required" );
938 case 429:
return(
"429 Too Many Requests" );
939 case 431:
return(
"431 Request Header Fields Too Large" );
940 case 500:
return(
"500 Internal Server Error" );
941 case 501:
return(
"501 Not Implemented" );
942 case 502:
return(
"502 Bad Gateway" );
943 case 503:
return(
"503 Service Unavailable" );
944 case 504:
return(
"504 Gateway Timeout" );
945 case 505:
return(
"505 HTTP Version Not Supported" );
946 case 510:
return(
"510 Not Extended" );
947 case 511:
return(
"511 Network Authentication Required" );
979 return(
"text/plain" );
992 ext =
type.pszExtension;
994 if ( sFileExtension.compare(ext, Qt::CaseInsensitive) == 0 )
995 return(
type.pszType );
998 return(
"text/plain" );
1007 QStringList mimeTypes;
1011 if (!mimeTypes.contains(
type.pszType ))
1012 mimeTypes.append(
type.pszType );
1024 QFileInfo
info( sFileName );
1025 QString sLOC =
"HTTPRequest::TestMimeType(" + sFileName +
") - ";
1026 QString sSuffix =
info.suffix().toLower();
1029 if ( sSuffix ==
"nuv" )
1032 QFile
file( sFileName );
1034 if (
file.open(QIODevice::ReadOnly | QIODevice::Text) )
1036 QByteArray head =
file.read(8);
1037 QString sHex = head.toHex();
1039 LOG(VB_HTTP, LOG_DEBUG, sLOC +
"file starts with " + sHex);
1041 if ( sHex ==
"000001ba44000400" )
1042 sMIME =
"video/mp2p";
1044 if ( head ==
"MythTVVi" )
1047 head =
file.read(4);
1049 if ( head ==
"DIVX" )
1051 LOG(VB_HTTP, LOG_DEBUG, sLOC +
"('MythTVVi...DIVXLAME')");
1052 sMIME =
"video/mp4";
1063 LOG(VB_GENERAL, LOG_ERR, sLOC +
"Could not read file");
1067 LOG(VB_HTTP, LOG_INFO, sLOC +
"type is " + sMIME);
1079 LOG(VB_HTTP, LOG_INFO, QString(
"sParams: '%1'").arg(sParams));
1084 sParams.replace(
"&",
"&" );
1086 if (!sParams.isEmpty())
1088 QStringList params = sParams.split(
'&', Qt::SkipEmptyParts);
1089 for (
const auto & param : std::as_const(params))
1091 QString sName = param.section(
'=', 0, 0 );
1092 QString sValue = param.section(
'=', 1 );
1093 sValue.replace(
"+",
" ");
1095 if (!sName.isEmpty())
1097 sName = QUrl::fromPercentEncoding(sName.toUtf8());
1098 sValue = QUrl::fromPercentEncoding(sValue.toUtf8());
1100 mapParams.insert( sName.trimmed(), sValue );
1137 sHeader += it.key() +
": ";
1138 sHeader += *it +
"\r\n";
1154 bool bKeepAlive =
true;
1163 QString sConnection =
GetRequestHeader(
"connection",
"default" ).toLower();
1165 QStringList sValueList = sConnection.split(
",");
1167 if ( sValueList.contains(
"close") )
1169 LOG(VB_HTTP, LOG_DEBUG,
"Client requested the connection be closed");
1172 else if (sValueList.contains(
"keep-alive"))
1186 QStringList sCookieList =
m_mapHeaders.values(
"cookie");
1188 QStringList::iterator it;
1189 for (it = sCookieList.begin(); it != sCookieList.end(); ++it)
1191 QString key = (*it).section(
'=', 0, 0);
1192 QString value = (*it).section(
'=', 1);
1204 bool bSuccess =
false;
1209 QString sRequestLine =
ReadLine( 2s );
1211 if ( sRequestLine.isEmpty() )
1213 LOG(VB_GENERAL, LOG_ERR,
"Timeout reading first line of request." );
1245 while (( !sLine.isEmpty() ) && !bDone )
1247 if (sLine !=
"\r\n")
1249 QString sName = sLine.section(
':', 0, 0 ).trimmed();
1250 QString sValue = sLine.section(
':', 1 );
1252 sValue.truncate( sValue.length() - 2 );
1254 if (!sName.isEmpty() && !sValue.isEmpty())
1256 m_mapHeaders.insert(sName.toLower(), sValue.trimmed());
1270 LOG(VB_HTTP, LOG_INFO, QString(
"(Request Header) %1: %2")
1271 .arg(it.key(), *it));
1283 LOG(VB_GENERAL, LOG_INFO,
"Timeout waiting for request header." );
1337 long nPayloadSize =
GetLastHeader(
"content-length" ).toLong();
1339 if (nPayloadSize > 0)
1341 char *pszPayload =
new char[ nPayloadSize + 2 ];
1344 nBytes =
ReadBlock( pszPayload, nPayloadSize, 5s );
1345 if (nBytes == nPayloadSize )
1347 m_sPayload = QString::fromUtf8( pszPayload, nPayloadSize );
1357 LOG(VB_GENERAL, LOG_ERR,
1358 QString(
"Unable to read entire payload (read %1 of %2 bytes)")
1359 .arg( nBytes ) .arg( nPayloadSize ) );
1363 delete [] pszPayload;
1369 if (!sSOAPAction.isEmpty())
1376 LOG(VB_HTTP, LOG_DEBUG,
1377 QString(
"HTTPRequest::ParseRequest - Socket (%1) Base (%2) "
1378 "Method (%3) - Bytes in Socket Buffer (%4)")
1380 .arg(
m_sMethod) .arg(BytesAvailable()));
1385 LOG(VB_GENERAL, LOG_WARNING,
1386 "Unexpected exception in HTTPRequest::ParseRequest" );
1401 int nCount = tokens.count();
1405 if ( sLine.startsWith( QString(
"HTTP/") ))
1429 m_sRequestUrl = QUrl::fromPercentEncoding(tokens[1].toUtf8());
1435 QString sQueryStr = tokens[1].section(
'?', 1, 1 );
1437 if (!sQueryStr.isEmpty())
1465 long long *pllStart,
1473 if (sRange.isEmpty())
1485 sRange.remove( 0, nIdx );
1491 QStringList ranges = sRange.split(
',', Qt::SkipEmptyParts);
1492 if (ranges.count() == 0)
1499 QStringList parts = ranges[0].split(
'-');
1501 if (parts.count() != 2)
1504 if (parts[0].isEmpty() && parts[1].isEmpty())
1511 bool conv_ok =
false;
1512 if (parts[0].isEmpty())
1518 long long llValue = parts[1].toLongLong(&conv_ok);
1519 if (!conv_ok)
return false;
1521 *pllStart = llSize - llValue;
1522 *pllEnd = llSize - 1;
1524 else if (parts[1].isEmpty())
1530 *pllStart = parts[0].toLongLong(&conv_ok);
1535 *pllEnd = llSize - 1;
1543 *pllStart = parts[0].toLongLong(&conv_ok);
1544 if (!conv_ok)
return false;
1545 *pllEnd = parts[1].toLongLong(&conv_ok);
1546 if (!conv_ok)
return false;
1548 if (*pllStart > *pllEnd)
1552 LOG(VB_HTTP, LOG_DEBUG, QString(
"%1 Range Requested %2 - %3")
1567 static const QRegularExpression re {
"^http[s]?://.*?/"};
1570 QStringList sList =
m_sBaseUrl.split(
'/', Qt::SkipEmptyParts);
1573 if (!sList.isEmpty())
1580 LOG(VB_HTTP, LOG_INFO, QString(
"ExtractMethodFromURL(end) : %1 : %2")
1590 bool bSuccess =
false;
1596 LOG(VB_HTTP, LOG_INFO,
1597 QString(
"HTTPRequest::ProcessSOAPPayload : %1 : ").arg(sSOAPAction));
1598 QDomDocument doc (
"request" );
1600 #if QT_VERSION < QT_VERSION_CHECK(6,5,0)
1605 if (!doc.setContent(
m_sPayload,
true, &sErrMsg, &nErrLine, &nErrCol ))
1607 LOG(VB_GENERAL, LOG_ERR,
1608 QString(
"Error parsing request at line: %1 column: %2 : %3" )
1609 .arg(nErrLine) .arg(nErrCol) .arg(sErrMsg));
1613 auto parseResult =doc.setContent(
m_sPayload,
1614 QDomDocument::ParseOption::UseNamespaceProcessing );
1617 LOG(VB_GENERAL, LOG_ERR,
1618 QString(
"Error parsing request at line: %1 column: %2 : %3" )
1619 .arg(parseResult.errorLine).arg(parseResult.errorColumn)
1620 .arg(parseResult.errorMessage));
1631 if (sSOAPAction.contains(
'#' ))
1633 m_sNameSpace = sSOAPAction.section(
'#', 0, 0).remove( 0, 1);
1634 m_sMethod = sSOAPAction.section(
'#', 1 );
1639 if (sSOAPAction.contains(
'/' ))
1641 int nPos = sSOAPAction.lastIndexOf(
'/' );
1644 sSOAPAction.length() - nPos - 2);
1661 if (oNodeList.count() == 0)
1664 doc.elementsByTagNameNS(
"http://schemas.xmlsoap.org/soap/envelope/",
1668 if (oNodeList.count() > 0)
1670 QDomNode oMethod = oNodeList.item(0);
1672 if (!oMethod.isNull())
1676 for ( QDomNode oNode = oMethod.firstChild(); !oNode.isNull();
1677 oNode = oNode.nextSibling() )
1679 QDomElement e = oNode.toElement();
1683 QString sName = e.tagName();
1684 QString sValue =
"";
1686 QDomText oText = oNode.firstChild().toText();
1688 if (!oText.isNull())
1689 sValue = oText.nodeValue();
1691 sName = QUrl::fromPercentEncoding(sName.toUtf8());
1692 sValue = QUrl::fromPercentEncoding(sValue.toUtf8());
1694 m_mapParams.insert( sName.trimmed().toLower(), sValue );
1722 if (sAccept.contains(
"application/json", Qt::CaseInsensitive ) ||
1723 sAccept.contains(
"text/javascript", Qt::CaseInsensitive ))
1728 else if (sAccept.contains(
"text/x-apple-plist+xml", Qt::CaseInsensitive ))
1736 if (pSerializer ==
nullptr)
1750 LOG(VB_HTTP, LOG_DEBUG,
1751 QString(
"HTTPRequest::Encode Input : %1").arg(sStr));
1753 sStr.replace(
'&',
"&" );
1754 sStr.replace(
'<',
"<" );
1755 sStr.replace(
'>',
">" );
1756 sStr.replace(
'"',
""");
1757 sStr.replace(
"'",
"'");
1760 LOG(VB_HTTP, LOG_DEBUG,
1761 QString(
"HTTPRequest::Encode Output : %1").arg(sStr));
1773 sStr.replace(
"&",
"&");
1774 sStr.replace(
"<",
"<");
1775 sStr.replace(
">",
">");
1776 sStr.replace(
""",
"\"");
1777 sStr.replace(
"'",
"'");
1788 QByteArray hash = QCryptographicHash::hash( data.data(), QCryptographicHash::Sha1);
1790 return (
"\"" + hash.toHex() +
"\"");
1801 QStringList oList = sProtected.split(
';' );
1803 for(
int nIdx = 0; nIdx < oList.count(); nIdx++)
1805 if (sBaseUrl.startsWith( oList[nIdx], Qt::CaseInsensitive ))
1821 QString realm =
"MythTV";
1829 QString stale = isStale ?
"true" :
"false";
1830 authHeader = QString(
"Digest realm=\"%1\",nonce=\"%2\","
1831 "qop=\"auth\",stale=\"%3\",algorithm=\"MD5\"")
1832 .arg(realm, nonce, stale);
1836 authHeader = QString(
"Basic realm=\"%1\"").arg(realm);
1849 QString hash = QCryptographicHash::hash( uniqueID.toLatin1(), QCryptographicHash::Sha1).toHex();
1850 QString nonce = QString(
"%1%2").arg(timeStamp, hash);
1860 LOG(VB_HTTP, LOG_NOTICE,
"Attempting HTTP Basic Authentication");
1861 QStringList oList =
GetLastHeader(
"authorization" ).split(
' ' );
1865 LOG(VB_GENERAL, LOG_WARNING,
"Basic authentication is only allowed for HTTP 1.0");
1869 QString sCredentials = QByteArray::fromBase64( oList[1].toUtf8() );
1871 oList = sCredentials.split(
':' );
1873 if (oList.count() < 2)
1875 LOG(VB_GENERAL, LOG_WARNING,
"Authorization attempt with invalid number of tokens");
1879 QString sUsername = oList[0];
1880 QString sPassword = oList[1];
1882 if (sUsername ==
"nouser")
1888 LOG(VB_GENERAL, LOG_WARNING,
"Authorization attempt with invalid username");
1892 QString client = QString(
"WebFrontend_%1").arg(
GetPeerAddress());
1898 LOG(VB_GENERAL, LOG_WARNING,
"Authorization attempt with invalid password");
1902 LOG(VB_HTTP, LOG_NOTICE,
"Valid Authorization received");
1919 LOG(VB_HTTP, LOG_NOTICE,
"Attempting HTTP Digest Authentication");
1920 QString realm =
"MythTV";
1922 QString authMethod =
GetLastHeader(
"authorization" ).section(
' ', 0, 0).toLower();
1924 if (authMethod !=
"digest")
1926 LOG(VB_GENERAL, LOG_WARNING,
"Invalid method in Authorization header");
1930 QString parameterStr =
GetLastHeader(
"authorization" ).section(
' ', 1);
1932 QMap<QString, QString> paramMap;
1933 QStringList paramList = parameterStr.split(
',');
1934 QStringList::iterator it;
1935 for (it = paramList.begin(); it != paramList.end(); ++it)
1937 QString key = (*it).section(
'=', 0, 0).toLower().trimmed();
1939 QString value = (*it).section(
'=', 1).trimmed();
1942 paramMap[key] = value;
1945 if (paramMap.size() < 8)
1947 LOG(VB_GENERAL, LOG_WARNING,
"Invalid number of parameters in Authorization header");
1951 if (paramMap[
"nonce"].isEmpty() || paramMap[
"username"].isEmpty() ||
1952 paramMap[
"realm"].isEmpty() || paramMap[
"uri"].isEmpty() ||
1953 paramMap[
"response"].isEmpty() || paramMap[
"qop"].isEmpty() ||
1954 paramMap[
"cnonce"].isEmpty() || paramMap[
"nc"].isEmpty())
1956 LOG(VB_GENERAL, LOG_WARNING,
"Missing required parameters in Authorization header");
1960 if (paramMap[
"username"] ==
"nouser")
1965 LOG(VB_GENERAL, LOG_WARNING,
"Authorization URI doesn't match the "
1971 if (paramMap[
"realm"] != realm)
1973 LOG(VB_GENERAL, LOG_WARNING,
"Authorization realm doesn't match the "
1974 "realm of the requested content");
1978 QByteArray nonce = paramMap[
"nonce"].toLatin1();
1979 if (nonce.length() < 20)
1981 LOG(VB_GENERAL, LOG_WARNING,
"Authorization nonce is too short");
1985 QString nonceTimeStampStr = nonce.left(20);
1988 LOG(VB_GENERAL, LOG_WARNING,
"Authorization nonce doesn't match reference");
1989 LOG(VB_HTTP, LOG_DEBUG, QString(
"%1 vs %2").arg(QString(nonce),
1994 constexpr std::chrono::seconds AUTH_TIMEOUT { 2min };
1996 if (!nonceTimeStamp.isValid())
1998 LOG(VB_GENERAL, LOG_WARNING,
"Authorization nonce timestamp is invalid.");
1999 LOG(VB_HTTP, LOG_DEBUG, QString(
"Timestamp was '%1'").arg(nonceTimeStampStr));
2005 LOG(VB_HTTP, LOG_NOTICE,
"Authorization nonce timestamp is invalid or too old.");
2016 LOG(VB_GENERAL, LOG_WARNING,
"Authorization attempt with invalid username");
2020 if (paramMap[
"response"].length() != 32)
2022 LOG(VB_GENERAL, LOG_WARNING,
"Authorization response field is invalid length");
2030 QString methodDigest = QString(
"%1:%2").arg(
GetRequestType(), paramMap[
"uri"]);
2031 QByteArray a2 = QCryptographicHash::hash(methodDigest.toLatin1(),
2032 QCryptographicHash::Md5).toHex();
2034 QString responseDigest = QString(
"%1:%2:%3:%4:%5:%6").arg(a1,
2040 QByteArray kd = QCryptographicHash::hash(responseDigest.toLatin1(),
2041 QCryptographicHash::Md5).toHex();
2043 if (paramMap[
"response"].toLatin1() == kd)
2045 LOG(VB_HTTP, LOG_NOTICE,
"Valid Authorization received");
2046 QString client = QString(
"WebFrontend_%1").arg(
GetPeerAddress());
2052 LOG(VB_GENERAL, LOG_ERR,
"Valid Authorization received, but we "
2053 "failed to create a valid session");
2066 LOG(VB_GENERAL, LOG_WARNING,
"Authorization attempt with invalid password digest");
2067 LOG(VB_HTTP, LOG_DEBUG, QString(
"Received hash was '%1', calculated hash was '%2'")
2068 .arg(paramMap[
"response"], QString(kd)));
2083 QStringList oList =
GetLastHeader(
"authorization" ).split(
' ' );
2085 if (oList.count() < 2)
2088 if (oList[0].compare(
"basic", Qt::CaseInsensitive ) == 0)
2090 if (oList[0].compare(
"digest", Qt::CaseInsensitive ) == 0)
2114 const QDateTime &expiryDate,
bool secure)
2118 LOG(VB_GENERAL, LOG_WARNING, QString(
"HTTPRequest::SetCookie(%1=%2): "
2119 "A secure cookie cannot be set on an unencrypted connection.")
2120 .arg(sKey, sValue));
2124 QStringList cookieAttributes;
2127 cookieAttributes.append(QString(
"%1=%2").arg(sKey, sValue));
2133 cookieAttributes.append(
"Path=/");
2137 cookieAttributes.append(QString(
"Expires=%1").arg(expires));
2142 cookieAttributes.append(
"Secure");
2145 cookieAttributes.append(
"HttpOnly");
2167 return hostname.section(
"]:", 0 , 0);
2171 return hostname.section(
":", 0 , 0);
2210 type =
"UNSUBSCRIBE";
2248 QStringList allowedOrigins;
2252 serverStatusPort + 10);
2254 QString masterAddrPort = QString(
"%1:%2")
2256 .arg(serverStatusPort);
2257 QString masterTLSAddrPort = QString(
"%1:%2")
2259 .arg(backendSSLPort);
2261 allowedOrigins << QString(
"http://%1").arg(masterAddrPort);
2262 allowedOrigins << QString(
"https://%2").arg(masterTLSAddrPort);
2264 QString localhostname = QHostInfo::localHostName();
2265 if (!localhostname.isEmpty())
2267 allowedOrigins << QString(
"http://%1:%2")
2268 .arg(localhostname).arg(serverStatusPort);
2269 allowedOrigins << QString(
"https://%1:%2")
2270 .arg(localhostname).arg(backendSSLPort);
2273 QStringList allowedOriginsList =
2275 "https://chromecast.mythtv.org")).split(
",");
2277 for (
const auto & origin : std::as_const(allowedOriginsList))
2279 if (origin.isEmpty())
2282 if (origin ==
"*" || (!origin.startsWith(
"http://") &&
2283 !origin.startsWith(
"https://")))
2285 LOG(VB_GENERAL, LOG_ERR, QString(
"Illegal AllowedOriginsList"
2286 " entry '%1'. Must start with http[s]:// and not be *")
2291 allowedOrigins << origin;
2297 for (
const auto & origin : std::as_const(allowedOrigins))
2298 LOG(VB_HTTP, LOG_DEBUG, QString(
"Will allow Origin: %1").arg(origin));
2301 if (allowedOrigins.contains(sOrigin))
2306 LOG(VB_HTTP, LOG_DEBUG, QString(
"Allow-Origin: %1)").arg(sOrigin));
2310 LOG(VB_GENERAL, LOG_CRIT, QString(
"HTTPRequest: Cross-origin request "
2311 "received with origin (%1)")
2329 m_pSocket->state() == QAbstractSocket::ConnectedState)
2338 if ( timer.
elapsed() >= msecs )
2341 LOG(VB_HTTP, LOG_INFO,
"BufferedSocketDeviceRequest::ReadLine() - Exceeded Total Elapsed Wait Time." );
2357 std::chrono::milliseconds msecs)
2360 m_pSocket->state() == QAbstractSocket::ConnectedState)
2363 return(
m_pSocket->read( pData, nMaxLen ));
2365 bool bTimeout =
false;
2368 while ( (
m_pSocket->bytesAvailable() < (
int)nMaxLen) && !bTimeout )
2370 bTimeout = !(
m_pSocket->waitForReadyRead( msecs.count() ));
2372 if ( timer.
elapsed() >= msecs )
2375 LOG(VB_HTTP, LOG_INFO,
"BufferedSocketDeviceRequest::ReadBlock() - Exceeded Total Elapsed Wait Time." );
2381 return(
m_pSocket->read( pData, nMaxLen ));
2393 qint64 bytesWritten = -1;
2395 m_pSocket->state() == QAbstractSocket::ConnectedState)
2397 bytesWritten =
m_pSocket->write( pData, nLen );
2401 return( bytesWritten );
2410 return(
m_pSocket->localAddress().toString() );
2429 return(
m_pSocket->peerAddress().toString() );