Cleanup of the default_resource check that ensures that the request path is within the given web_root_path

This commit is contained in:
eidheim 2016-03-10 16:25:12 +01:00
commit 359bad9862
3 changed files with 70 additions and 75 deletions

View file

@ -84,17 +84,16 @@ int main() {
//Default file: index.html //Default file: index.html
//Can for instance be used to retrieve an HTML 5 client that uses REST-resources on this server //Can for instance be used to retrieve an HTML 5 client that uses REST-resources on this server
server.default_resource["GET"]=[](HttpServer::Response& response, shared_ptr<HttpServer::Request> request) { server.default_resource["GET"]=[](HttpServer::Response& response, shared_ptr<HttpServer::Request> request) {
boost::filesystem::path web_root_path("web"); string web_root_path=boost::filesystem::canonical("web").string();
if(!boost::filesystem::exists(web_root_path)) boost::filesystem::path path=web_root_path;
cerr << "Could not find web root." << endl; path/=request->path;
else {
auto path=web_root_path;
path+=request->path;
if(boost::filesystem::exists(path)) { if(boost::filesystem::exists(path)) {
if(boost::filesystem::canonical(web_root_path)<=boost::filesystem::canonical(path)) { auto path_str=boost::filesystem::canonical(path).string();
if(path_str.substr(0, web_root_path.size())==web_root_path) {
if(boost::filesystem::is_directory(path)) if(boost::filesystem::is_directory(path))
path+="/index.html"; path/="index.html";
if(boost::filesystem::exists(path) && boost::filesystem::is_regular_file(path)) { if(boost::filesystem::exists(path) && boost::filesystem::is_regular_file(path)) {
cout << "test" << endl;
ifstream ifs; ifstream ifs;
ifs.open(path.string(), ifstream::in | ios::binary); ifs.open(path.string(), ifstream::in | ios::binary);
@ -127,7 +126,6 @@ int main() {
} }
} }
} }
}
string content="Could not open path "+request->path; string content="Could not open path "+request->path;
response << "HTTP/1.1 400 Bad Request\r\nContent-Length: " << content.length() << "\r\n\r\n" << content; response << "HTTP/1.1 400 Bad Request\r\nContent-Length: " << content.length() << "\r\n\r\n" << content;
}; };

View file

@ -84,17 +84,16 @@ int main() {
//Default file: index.html //Default file: index.html
//Can for instance be used to retrieve an HTML 5 client that uses REST-resources on this server //Can for instance be used to retrieve an HTML 5 client that uses REST-resources on this server
server.default_resource["GET"]=[](HttpsServer::Response& response, shared_ptr<HttpsServer::Request> request) { server.default_resource["GET"]=[](HttpsServer::Response& response, shared_ptr<HttpsServer::Request> request) {
boost::filesystem::path web_root_path("web"); string web_root_path=boost::filesystem::canonical("web").string();
if(!boost::filesystem::exists(web_root_path)) boost::filesystem::path path=web_root_path;
cerr << "Could not find web root." << endl; path/=request->path;
else {
auto path=web_root_path;
path+=request->path;
if(boost::filesystem::exists(path)) { if(boost::filesystem::exists(path)) {
if(boost::filesystem::canonical(web_root_path)<=boost::filesystem::canonical(path)) { auto path_str=boost::filesystem::canonical(path).string();
if(path_str.substr(0, web_root_path.size())==web_root_path) {
if(boost::filesystem::is_directory(path)) if(boost::filesystem::is_directory(path))
path+="/index.html"; path/="index.html";
if(boost::filesystem::exists(path) && boost::filesystem::is_regular_file(path)) { if(boost::filesystem::exists(path) && boost::filesystem::is_regular_file(path)) {
cout << "test" << endl;
ifstream ifs; ifstream ifs;
ifs.open(path.string(), ifstream::in | ios::binary); ifs.open(path.string(), ifstream::in | ios::binary);
@ -127,7 +126,6 @@ int main() {
} }
} }
} }
}
string content="Could not open path "+request->path; string content="Could not open path "+request->path;
response << "HTTP/1.1 400 Bad Request\r\nContent-Length: " << content.length() << "\r\n\r\n" << content; response << "HTTP/1.1 400 Bad Request\r\nContent-Length: " << content.length() << "\r\n\r\n" << content;
}; };

View file

@ -312,7 +312,6 @@ namespace SimpleWeb {
else else
return false; return false;
getline(stream, line); getline(stream, line);
size_t param_end; size_t param_end;
while((param_end=line.find(':'))!=std::string::npos) { while((param_end=line.find(':'))!=std::string::npos) {