Infer filename from content-disposition or URL

The Content-Disposition inferring is probably a bad idea security wise,
so I am going to remove it.
This commit is contained in:
William Wennerström
2020-07-05 17:21:20 +02:00
parent 9499df6585
commit eebf54c859
9 changed files with 512 additions and 137 deletions

View File

@@ -0,0 +1,119 @@
#include <stdarg.h>
#include <stddef.h>
#include <setjmp.h>
#include <cmocka.h>
#include <stdlib.h>
#include <string.h>
#include <glib.h>
#include "config.h"
#include "tools/http_download.h"
typedef struct {
char *url;
char *filename;
} url_test_t;
typedef struct {
char *header;
char *filename;
} header_test_t;
void http_filename_from_url_td(void **state) {
int num_tests = 5;
url_test_t tests[] = {
(url_test_t){
.url = "https://host.test/image.jpeg",
.filename = "image.jpeg",
},
(url_test_t){
.url = "https://host.test/images/",
.filename = "images",
},
(url_test_t){
.url = "https://host.test/",
.filename = "index.html",
},
(url_test_t){
.url = "https://host.test",
.filename = "index.html",
},
(url_test_t){
.url = "aesgcm://host.test",
.filename = "index.html",
},
};
char *filename;
for(int i = 0; i < num_tests; i++) {
filename = http_filename_from_url(tests[i].url);
assert_string_equal(filename, tests[i].filename);
}
}
void http_filename_from_header_td(void **state) {
int num_tests = 11;
header_test_t tests[] = {
(header_test_t){
.header = "Content-Disposition: filename=image.jpeg",
.filename = "image.jpeg",
},
(header_test_t){
.header = "Content-Disposition:filename=image.jpeg",
.filename = "image.jpeg",
},
(header_test_t){
.header = "CoNteNt-DiSpoSItioN: filename=image.jpeg",
.filename = "image.jpeg",
},
(header_test_t){
.header = "Content-Disposition: attachment; filename=image.jpeg",
.filename = "image.jpeg",
},
(header_test_t){
.header = "Content-Disposition: filename=",
.filename = NULL,
},
(header_test_t){
.header = "Content-Disposition: filename=;",
.filename = NULL,
},
(header_test_t){
.header = "Content-Disposition: inline",
.filename = NULL,
},
(header_test_t){
.header = "Content-Disposition:",
.filename = NULL,
},
(header_test_t){
.header = "Last-Modified: Wed, 21 Oct 2015 07:28:00 GMT ",
.filename = NULL,
},
(header_test_t){
.header = "",
.filename = NULL,
},
(header_test_t){
.header = NULL,
.filename = NULL,
},
};
char *got_filename;
char *exp_filename;
char *header;
for(int i = 0; i < num_tests; i++) {
header = tests[i].header;
exp_filename = tests[i].filename;
got_filename = http_filename_from_header(header);
if (exp_filename == NULL) {
assert_null(got_filename);
} else {
assert_string_equal(got_filename, exp_filename);
}
}
}

View File

@@ -0,0 +1,2 @@
void http_filename_from_url_td(void **state);
void http_filename_from_header_td(void **state);

View File

@@ -0,0 +1,28 @@
#ifndef TOOLS_HTTP_DOWNLOAD_H
#define TOOLS_HTTP_DOWNLOAD_H
#include <curl/curl.h>
#include <pthread.h>
typedef struct prof_win_t ProfWin;
typedef struct http_download_t {
char *url;
char *filename;
char *directory;
FILE *filehandle;
curl_off_t bytes_received;
ProfWin *window;
pthread_t worker;
int cancel;
} HTTPDownload;
void* http_file_get(void *userdata);
void http_download_cancel_processes(ProfWin *window);
void http_download_add_download(HTTPDownload *download);
char *http_filename_from_url(const char *url);
#endif

View File

@@ -236,16 +236,97 @@ ui_contact_online(char* barejid, Resource* resource, GDateTime* last_activity)
check_expected(last_activity);
}
void
ui_contact_typing(const char* const barejid, const char* const resource)
{
}
void
chatwin_incoming_msg(ProfChatWin* chatwin, ProfMessage* message, gboolean win_created)
{
}
void
chatwin_receipt_received(ProfChatWin* chatwin, const char* const id)
void ui_contact_typing(const char * const barejid, const char * const resource) {}
void chatwin_incoming_msg(ProfChatWin *chatwin, ProfMessage *message, gboolean win_created) {}
void chatwin_receipt_received(ProfChatWin *chatwin, const char * const id) {}
void privwin_incoming_msg(ProfPrivateWin *privatewin, ProfMessage *message) {}
void ui_disconnected(void) {}
void chatwin_recipient_gone(ProfChatWin *chatwin) {}
void chatwin_outgoing_msg(ProfChatWin *chatwin, const char *const message, char *id, prof_enc_t enc_mode, gboolean request_receipt, const char *const replace_id) {}
void chatwin_outgoing_carbon(ProfChatWin *chatwin, ProfMessage *message) {}
void privwin_outgoing_msg(ProfPrivateWin *privwin, const char * const message) {}
void privwin_occupant_offline(ProfPrivateWin *privwin) {}
void privwin_occupant_kicked(ProfPrivateWin *privwin, const char *const actor, const char *const reason) {}
void privwin_occupant_banned(ProfPrivateWin *privwin, const char *const actor, const char *const reason) {}
void privwin_occupant_online(ProfPrivateWin *privwin) {}
void privwin_message_occupant_offline(ProfPrivateWin *privwin) {}
void privwin_message_left_room(ProfPrivateWin *privwin) {}
void ui_room_join(const char * const roomjid, gboolean focus) {}
void ui_switch_to_room(const char * const roomjid) {}
void mucwin_role_change(ProfMucWin *mucwin, const char * const role, const char * const actor,
const char * const reason) {}
void mucwin_affiliation_change(ProfMucWin *mucwin, const char * const affiliation, const char * const actor,
const char * const reason) {}
void mucwin_role_and_affiliation_change(ProfMucWin *mucwin, const char * const role,
const char * const affiliation, const char * const actor, const char * const reason) {}
void mucwin_occupant_role_change(ProfMucWin *mucwin, const char * const nick, const char * const role,
const char * const actor, const char * const reason) {}
void mucwin_occupant_affiliation_change(ProfMucWin *mucwin, const char * const nick, const char * const affiliation,
const char * const actor, const char * const reason) {}
void mucwin_occupant_role_and_affiliation_change(ProfMucWin *mucwin, const char * const nick, const char * const role,
const char * const affiliation, const char * const actor, const char * const reason) {}
void mucwin_roster(ProfMucWin *mucwin, GList *occupants, const char * const presence) {}
void mucwin_history(ProfMucWin *mucwin, const ProfMessage *const message) {}
void mucwin_incoming_msg(ProfMucWin *mucwin, const ProfMessage *const message, GSList *mentions, GList *triggers, gboolean filter_reflection) {}
void mucwin_outgoing_msg(ProfMucWin *mucwin, const char *const message, const char *const id, prof_enc_t enc_mode, const char *const replace_id) {}
void mucwin_subject(ProfMucWin *mucwin, const char * const nick, const char * const subject) {}
void mucwin_requires_config(ProfMucWin *mucwin) {}
void ui_room_destroy(const char * const roomjid) {}
void mucwin_info(ProfMucWin *mucwin) {}
void mucwin_show_role_list(ProfMucWin *mucwin, muc_role_t role) {}
void mucwin_show_affiliation_list(ProfMucWin *mucwin, muc_affiliation_t affiliation) {}
void mucwin_room_info_error(ProfMucWin *mucwin, const char * const error) {}
void mucwin_room_disco_info(ProfMucWin *mucwin, GSList *identities, GSList *features) {}
void ui_room_destroyed(const char * const roomjid, const char * const reason, const char * const new_jid,
const char * const password) {}
void ui_room_kicked(const char * const roomjid, const char * const actor, const char * const reason) {}
void mucwin_occupant_kicked(ProfMucWin *mucwin, const char * const nick, const char * const actor,
const char * const reason) {}
void ui_room_banned(const char * const roomjid, const char * const actor, const char * const reason) {}
void mucwin_occupant_banned(ProfMucWin *mucwin, const char * const nick, const char * const actor,
const char * const reason) {}
void ui_leave_room(const char * const roomjid) {}
void mucwin_broadcast(ProfMucWin *mucwin, const char * const message) {}
void mucwin_occupant_offline(ProfMucWin *mucwin, const char * const nick) {}
void mucwin_occupant_online(ProfMucWin *mucwin, const char * const nick, const char * const roles,
const char * const affiliation, const char * const show, const char * const status) {}
void mucwin_occupant_nick_change(ProfMucWin *mucwin, const char * const old_nick, const char * const nick) {}
void mucwin_nick_change(ProfMucWin *mucwin, const char * const nick) {}
void mucwin_occupant_presence(ProfMucWin *mucwin, const char * const nick, const char * const show,
const char * const status) {}
void mucwin_update_occupants(ProfMucWin *mucwin) {}
void mucwin_show_occupants(ProfMucWin *mucwin) {}
void mucwin_hide_occupants(ProfMucWin *mucwin) {}
void mucwin_set_enctext(ProfMucWin *mucwin, const char *const enctext) {}
void mucwin_unset_enctext(ProfMucWin *mucwin) {}
void mucwin_set_message_char(ProfMucWin *mucwin, const char *const ch) {}
void mucwin_unset_message_char(ProfMucWin *mucwin) {}
void win_update_entry_message(ProfWin *window, const char *const id, const char *const message) {};
void win_mark_received(ProfWin *window, const char *const id) {};
void win_print_http_transfer(ProfWin *window, const char *const message, char *url) {};
void ui_show_roster(void) {}
void ui_hide_roster(void) {}
void ui_roster_add(const char * const barejid, const char * const name) {}
void ui_roster_remove(const char * const barejid) {}
void ui_contact_already_in_group(const char * const contact, const char * const group) {}
void ui_contact_not_in_group(const char * const contact, const char * const group) {}
void ui_group_added(const char * const contact, const char * const group) {}
void ui_group_removed(const char * const contact, const char * const group) {}
void chatwin_contact_online(ProfChatWin *chatwin, Resource *resource, GDateTime *last_activity) {}
void chatwin_contact_offline(ProfChatWin *chatwin, char *resource, char *status) {}
void ui_contact_offline(char *barejid, char *resource, char *status) {}
void ui_handle_recipient_error(const char * const recipient, const char * const err_msg)
{
}

View File

@@ -38,6 +38,7 @@
#include "test_form.h"
#include "test_callbacks.h"
#include "test_plugins_disco.h"
#include "test_http_download.h"
int
main(int argc, char* argv[])
@@ -626,6 +627,9 @@ main(int argc, char* argv[])
unit_test(does_not_add_duplicate_feature),
unit_test(removes_plugin_features),
unit_test(does_not_remove_feature_when_more_than_one_reference),
unit_test(http_filename_from_url_td),
unit_test(http_filename_from_header_td),
};
return run_tests(all_tests);