Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 1 | /*************************************************************************** |
| 2 | * _ _ ____ _ |
| 3 | * Project ___| | | | _ \| | |
| 4 | * / __| | | | |_) | | |
| 5 | * | (__| |_| | _ <| |___ |
| 6 | * \___|\___/|_| \_\_____| |
| 7 | * |
Alex Deymo | d15eaac | 2016-06-28 14:49:26 -0700 | [diff] [blame] | 8 | * Copyright (C) 1998 - 2016, Daniel Stenberg, <daniel@haxx.se>, et al. |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 9 | * |
| 10 | * This software is licensed as described in the file COPYING, which |
| 11 | * you should have received as part of this distribution. The terms |
Alex Deymo | d15eaac | 2016-06-28 14:49:26 -0700 | [diff] [blame] | 12 | * are also available at https://curl.haxx.se/docs/copyright.html. |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 13 | * |
| 14 | * You may opt to use, copy, modify, merge, publish, distribute and/or sell |
| 15 | * copies of the Software, and permit persons to whom the Software is |
| 16 | * furnished to do so, under the terms of the COPYING file. |
| 17 | * |
| 18 | * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY |
| 19 | * KIND, either express or implied. |
| 20 | * |
| 21 | ***************************************************************************/ |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 22 | |
| 23 | #include "curl_setup.h" |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 24 | |
| 25 | #if !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_CRYPTO_AUTH) |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 26 | |
| 27 | #include "urldata.h" |
Elliott Hughes | cee0338 | 2017-06-23 12:17:18 -0700 | [diff] [blame] | 28 | #include "strcase.h" |
Alex Deymo | d15eaac | 2016-06-28 14:49:26 -0700 | [diff] [blame] | 29 | #include "vauth/vauth.h" |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 30 | #include "http_digest.h" |
Alex Deymo | d15eaac | 2016-06-28 14:49:26 -0700 | [diff] [blame] | 31 | /* The last 3 #include files should be in this order */ |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 32 | #include "curl_printf.h" |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 33 | #include "curl_memory.h" |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 34 | #include "memdebug.h" |
| 35 | |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 36 | /* Test example headers: |
| 37 | |
| 38 | WWW-Authenticate: Digest realm="testrealm", nonce="1053604598" |
| 39 | Proxy-Authenticate: Digest realm="testrealm", nonce="1053604598" |
| 40 | |
| 41 | */ |
| 42 | |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 43 | CURLcode Curl_input_digest(struct connectdata *conn, |
| 44 | bool proxy, |
| 45 | const char *header) /* rest of the *-authenticate: |
| 46 | header */ |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 47 | { |
Alex Deymo | e3149cc | 2016-10-05 11:18:42 -0700 | [diff] [blame] | 48 | struct Curl_easy *data = conn->data; |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 49 | |
| 50 | /* Point to the correct struct with this */ |
| 51 | struct digestdata *digest; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 52 | |
| 53 | if(proxy) { |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 54 | digest = &data->state.proxydigest; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 55 | } |
| 56 | else { |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 57 | digest = &data->state.digest; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 58 | } |
| 59 | |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 60 | if(!checkprefix("Digest", header)) |
| 61 | return CURLE_BAD_CONTENT_ENCODING; |
| 62 | |
| 63 | header += strlen("Digest"); |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 64 | while(*header && ISSPACE(*header)) |
| 65 | header++; |
| 66 | |
Alex Deymo | d15eaac | 2016-06-28 14:49:26 -0700 | [diff] [blame] | 67 | return Curl_auth_decode_digest_http_message(header, digest); |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 68 | } |
| 69 | |
| 70 | CURLcode Curl_output_digest(struct connectdata *conn, |
| 71 | bool proxy, |
| 72 | const unsigned char *request, |
| 73 | const unsigned char *uripath) |
| 74 | { |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 75 | CURLcode result; |
Alex Deymo | e3149cc | 2016-10-05 11:18:42 -0700 | [diff] [blame] | 76 | struct Curl_easy *data = conn->data; |
Elliott Hughes | 82be86d | 2017-09-20 17:00:17 -0700 | [diff] [blame] | 77 | unsigned char *path = NULL; |
| 78 | char *tmp = NULL; |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 79 | char *response; |
| 80 | size_t len; |
| 81 | bool have_chlg; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 82 | |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 83 | /* Point to the address of the pointer that holds the string to send to the |
| 84 | server, which is for a plain host or for a HTTP proxy */ |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 85 | char **allocuserpwd; |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 86 | |
| 87 | /* Point to the name and password for this */ |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 88 | const char *userp; |
| 89 | const char *passwdp; |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 90 | |
| 91 | /* Point to the correct struct with this */ |
| 92 | struct digestdata *digest; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 93 | struct auth *authp; |
| 94 | |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 95 | if(proxy) { |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 96 | digest = &data->state.proxydigest; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 97 | allocuserpwd = &conn->allocptr.proxyuserpwd; |
Elliott Hughes | cee0338 | 2017-06-23 12:17:18 -0700 | [diff] [blame] | 98 | userp = conn->http_proxy.user; |
| 99 | passwdp = conn->http_proxy.passwd; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 100 | authp = &data->state.authproxy; |
| 101 | } |
| 102 | else { |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 103 | digest = &data->state.digest; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 104 | allocuserpwd = &conn->allocptr.userpwd; |
| 105 | userp = conn->user; |
| 106 | passwdp = conn->passwd; |
| 107 | authp = &data->state.authhost; |
| 108 | } |
| 109 | |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 110 | Curl_safefree(*allocuserpwd); |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 111 | |
| 112 | /* not set means empty */ |
| 113 | if(!userp) |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 114 | userp = ""; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 115 | |
| 116 | if(!passwdp) |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 117 | passwdp = ""; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 118 | |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 119 | #if defined(USE_WINDOWS_SSPI) |
| 120 | have_chlg = digest->input_token ? TRUE : FALSE; |
| 121 | #else |
| 122 | have_chlg = digest->nonce ? TRUE : FALSE; |
| 123 | #endif |
| 124 | |
| 125 | if(!have_chlg) { |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 126 | authp->done = FALSE; |
| 127 | return CURLE_OK; |
| 128 | } |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 129 | |
| 130 | /* So IE browsers < v7 cut off the URI part at the query part when they |
| 131 | evaluate the MD5 and some (IIS?) servers work with them so we may need to |
| 132 | do the Digest IE-style. Note that the different ways cause different MD5 |
| 133 | sums to get sent. |
| 134 | |
| 135 | Apache servers can be set to do the Digest IE-style automatically using |
| 136 | the BrowserMatch feature: |
Alex Deymo | d15eaac | 2016-06-28 14:49:26 -0700 | [diff] [blame] | 137 | https://httpd.apache.org/docs/2.2/mod/mod_auth_digest.html#msie |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 138 | |
| 139 | Further details on Digest implementation differences: |
| 140 | http://www.fngtps.com/2006/09/http-authentication |
| 141 | */ |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 142 | |
Elliott Hughes | 82be86d | 2017-09-20 17:00:17 -0700 | [diff] [blame] | 143 | if(authp->iestyle) { |
| 144 | tmp = strchr((char *)uripath, '?'); |
| 145 | if(tmp) { |
| 146 | size_t urilen = tmp - (char *)uripath; |
| 147 | path = (unsigned char *) aprintf("%.*s", urilen, uripath); |
| 148 | } |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 149 | } |
Elliott Hughes | 82be86d | 2017-09-20 17:00:17 -0700 | [diff] [blame] | 150 | if(!tmp) |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 151 | path = (unsigned char *) strdup((char *) uripath); |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 152 | |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 153 | if(!path) |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 154 | return CURLE_OUT_OF_MEMORY; |
| 155 | |
Alex Deymo | d15eaac | 2016-06-28 14:49:26 -0700 | [diff] [blame] | 156 | result = Curl_auth_create_digest_http_message(data, userp, passwdp, request, |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 157 | path, digest, &response, &len); |
| 158 | free(path); |
| 159 | if(result) |
| 160 | return result; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 161 | |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 162 | *allocuserpwd = aprintf("%sAuthorization: Digest %s\r\n", |
| 163 | proxy ? "Proxy-" : "", |
| 164 | response); |
| 165 | free(response); |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 166 | if(!*allocuserpwd) |
| 167 | return CURLE_OUT_OF_MEMORY; |
| 168 | |
Bertrand SIMONNET | e6cd738 | 2015-07-01 15:39:44 -0700 | [diff] [blame] | 169 | authp->done = TRUE; |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 170 | |
| 171 | return CURLE_OK; |
| 172 | } |
| 173 | |
Alex Deymo | e3149cc | 2016-10-05 11:18:42 -0700 | [diff] [blame] | 174 | void Curl_digest_cleanup(struct Curl_easy *data) |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 175 | { |
Alex Deymo | d15eaac | 2016-06-28 14:49:26 -0700 | [diff] [blame] | 176 | Curl_auth_digest_cleanup(&data->state.digest); |
| 177 | Curl_auth_digest_cleanup(&data->state.proxydigest); |
Kristian Monsen | 5ab5018 | 2010-05-14 18:53:44 +0100 | [diff] [blame] | 178 | } |
| 179 | |
| 180 | #endif |