Files
cproof/src/tools/http_common.h
jabber.developer2 e05e0d58b3
Some checks failed
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 24s
CI Code / Linux (debian) (pull_request) Failing after 45s
CI Code / Linux (arch) (pull_request) Failing after 51s
CI Code / Linux (ubuntu) (pull_request) Failing after 3m57s
CI Code / Code Coverage (pull_request) Failing after 6m19s
security: E2EE and transport correctness (issue #147)
T04: promote security events to warnings — SASL auth failure, TLS
handshake failure, cert-failure details, see-other-host redirect;
DISABLE_TLS, TRUST_TLS and LEGACY_AUTH get a log warning plus a
console notice (REQ-LOG-01, REQ-LOG-02, REQ-AUTH-03)

T05: warn when a session ends up unencrypted without the user having
asked for it; refuse in-band registration on an unencrypted stream;
warn on each HTTP transfer with certificate verification disabled
(REQ-CRY-03, REQ-CFG-01)

T06: pin the update check to https with peer/host verification and no
redirects; strict N.N.N parser for the fetched version, which is
untrusted network input (REQ-VUL-02)

T09: no plaintext logging on failed MUC OMEMO sends; OTR opportunistic
first message passes allow_unencrypted_message(); get_random_string()
draws from a CSPRNG without modulo bias; guard the identity-key length
decrement against unsigned underflow (REQ-CRY-01, REQ-CRY-02,
REQ-CRY-07, REQ-MEM-05)

REQ-VUL-03 and REQ-CRY-09 are already satisfied on master and are
left unchanged.

The console warnings use cons_show_warning() from #87, so this needs
that change in master first.
2026-08-01 13:07:48 +03:00

23 lines
645 B
C

/*
* http_common.h
* vim: expandtab:ts=4:sts=4:sw=4
*
* Copyright (C) 2020 William Wennerström <william@wstrm.dev>
*
* SPDX-License-Identifier: GPL-3.0-or-later WITH OpenSSL-exception
*/
#ifndef TOOLS_HTTP_COMMON_H
#define TOOLS_HTTP_COMMON_H
#include <glib.h>
#include "ui/window.h"
G_GNUC_PRINTF(4, 5)
void http_print_transfer(ProfWin* window, char* id, theme_item_t theme_item, const char* fmt, ...);
G_GNUC_PRINTF(5, 6)
void http_print_transfer_update(ProfWin* window, char* id, theme_item_t theme_item, int flags, const char* fmt, ...);
void http_warn_insecure_transfer(ProfWin* window, char* id, const char* const url);
#endif