Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(670)

Side by Side Diff: net/server/web_socket.cc

Issue 1340523002: Fix WebSocketServer extension parser. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@ws-constructor-fix
Patch Set: Created 5 years, 3 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "net/server/web_socket.h" 5 #include "net/server/web_socket.h"
6 6
7 #include <vector>
8
7 #include "base/base64.h" 9 #include "base/base64.h"
8 #include "base/logging.h" 10 #include "base/logging.h"
9 #include "base/sha1.h" 11 #include "base/sha1.h"
10 #include "base/strings/string_number_conversions.h" 12 #include "base/strings/string_number_conversions.h"
11 #include "base/strings/stringprintf.h" 13 #include "base/strings/stringprintf.h"
12 #include "base/sys_byteorder.h" 14 #include "base/sys_byteorder.h"
13 #include "net/server/http_connection.h" 15 #include "net/server/http_connection.h"
14 #include "net/server/http_server.h" 16 #include "net/server/http_server.h"
15 #include "net/server/http_server_request_info.h" 17 #include "net/server/http_server_request_info.h"
16 #include "net/server/http_server_response_info.h" 18 #include "net/server/http_server_response_info.h"
17 #include "net/server/web_socket_encoder.h" 19 #include "net/server/web_socket_encoder.h"
20 #include "net/websockets/websocket_deflate_parameters.h"
21 #include "net/websockets/websocket_extension.h"
22 #include "net/websockets/websocket_handshake_constants.h"
18 23
19 namespace net { 24 namespace net {
20 25
21 WebSocket::WebSocket(HttpServer* server, 26 namespace {
22 HttpConnection* connection, 27
23 const HttpServerRequestInfo& request) 28 std::string ExtensionsHeaderString(
24 : server_(server), connection_(connection), closed_(false) { 29 const std::vector<WebSocketExtension>& extensions) {
25 std::string request_extensions = 30 if (extensions.empty())
26 request.GetHeaderValue("sec-websocket-extensions"); 31 return std::string();
27 encoder_.reset(WebSocketEncoder::CreateServer(request_extensions, 32
28 &response_extensions_)); 33 std::string result = "Sec-WebSocket-Extensions: " + extensions[0].ToString();
29 if (!response_extensions_.empty()) { 34 for (size_t i = 1; i < extensions.size(); ++i)
30 response_extensions_ = 35 result += ", " + extensions[i].ToString();
31 "Sec-WebSocket-Extensions: " + response_extensions_ + "\r\n"; 36 return result + "\r\n";
32 }
33 } 37 }
34 38
39 std::string ValidResponseString(
40 const std::string& accept_hash,
41 const std::vector<WebSocketExtension> extensions) {
42 return base::StringPrintf(
43 "HTTP/1.1 101 WebSocket Protocol Handshake\r\n"
44 "Upgrade: WebSocket\r\n"
45 "Connection: Upgrade\r\n"
46 "Sec-WebSocket-Accept: %s\r\n"
47 "%s"
48 "\r\n",
49 accept_hash.c_str(), ExtensionsHeaderString(extensions).c_str());
50 }
51
52 } // namespace
53
54 WebSocket::WebSocket(HttpServer* server, HttpConnection* connection)
55 : server_(server), connection_(connection), closed_(false) {}
56
35 WebSocket::~WebSocket() {} 57 WebSocket::~WebSocket() {}
36 58
37 WebSocket* WebSocket::CreateWebSocket(HttpServer* server, 59 void WebSocket::Accept(const HttpServerRequestInfo& request) {
38 HttpConnection* connection,
39 const HttpServerRequestInfo& request) {
40 std::string version = request.GetHeaderValue("sec-websocket-version"); 60 std::string version = request.GetHeaderValue("sec-websocket-version");
41 if (version != "8" && version != "13") { 61 if (version != "8" && version != "13") {
42 server->SendResponse( 62 SendErrorResponse("Invalid request format. The version is not valid.");
43 connection->id(), 63 return;
44 HttpServerResponseInfo::CreateFor500(
45 "Invalid request format. The version is not valid."));
46 return nullptr;
47 } 64 }
48 65
49 std::string key = request.GetHeaderValue("sec-websocket-key"); 66 std::string key = request.GetHeaderValue("sec-websocket-key");
50 if (key.empty()) { 67 if (key.empty()) {
51 server->SendResponse( 68 SendErrorResponse(
52 connection->id(), 69 "Invalid request format. Sec-WebSocket-Key is empty or isn't "
53 HttpServerResponseInfo::CreateFor500( 70 "specified.");
54 "Invalid request format. Sec-WebSocket-Key is empty or isn't " 71 return;
55 "specified."));
56 return nullptr;
57 } 72 }
58 return new WebSocket(server, connection, request); 73 std::string encoded_hash;
59 } 74 base::Base64Encode(base::SHA1HashString(key + websockets::kWebSocketGuid),
75 &encoded_hash);
60 76
61 void WebSocket::Accept(const HttpServerRequestInfo& request) { 77 std::vector<WebSocketExtension> response_extensions;
62 static const char* const kWebSocketGuid = 78 auto i = request.headers.find("sec-websocket-extensions");
63 "258EAFA5-E914-47DA-95CA-C5AB0DC85B11"; 79 if (i == request.headers.end()) {
64 std::string key = request.GetHeaderValue("sec-websocket-key"); 80 encoder_ = WebSocketEncoder::CreateServer();
65 std::string data = base::StringPrintf("%s%s", key.c_str(), kWebSocketGuid); 81 } else {
66 std::string encoded_hash; 82 WebSocketDeflateParameters params;
67 base::Base64Encode(base::SHA1HashString(data), &encoded_hash); 83 encoder_ = WebSocketEncoder::CreateServer(i->second, &params);
68 84 if (!encoder_) {
69 server_->SendRaw( 85 Fail();
70 connection_->id(), 86 return;
71 base::StringPrintf("HTTP/1.1 101 WebSocket Protocol Handshake\r\n" 87 }
72 "Upgrade: WebSocket\r\n" 88 if (encoder_->deflate_enabled()) {
73 "Connection: Upgrade\r\n" 89 DCHECK(params.IsValidAsResponse());
74 "Sec-WebSocket-Accept: %s\r\n" 90 response_extensions.push_back(params.AsExtension());
75 "%s" 91 }
76 "\r\n", 92 }
77 encoded_hash.c_str(), response_extensions_.c_str())); 93 server_->SendRaw(connection_->id(),
94 ValidResponseString(encoded_hash, response_extensions));
78 } 95 }
79 96
80 WebSocket::ParseResult WebSocket::Read(std::string* message) { 97 WebSocket::ParseResult WebSocket::Read(std::string* message) {
98 if (closed_)
99 return FRAME_CLOSE;
100
81 HttpConnection::ReadIOBuffer* read_buf = connection_->read_buf(); 101 HttpConnection::ReadIOBuffer* read_buf = connection_->read_buf();
82 base::StringPiece frame(read_buf->StartOfBuffer(), read_buf->GetSize()); 102 base::StringPiece frame(read_buf->StartOfBuffer(), read_buf->GetSize());
83 int bytes_consumed = 0; 103 int bytes_consumed = 0;
84 ParseResult result = encoder_->DecodeFrame(frame, &bytes_consumed, message); 104 ParseResult result = encoder_->DecodeFrame(frame, &bytes_consumed, message);
85 if (result == FRAME_OK) 105 if (result == FRAME_OK)
86 read_buf->DidConsume(bytes_consumed); 106 read_buf->DidConsume(bytes_consumed);
87 if (result == FRAME_CLOSE) 107 if (result == FRAME_CLOSE)
88 closed_ = true; 108 closed_ = true;
89 return result; 109 return result;
90 } 110 }
91 111
92 void WebSocket::Send(const std::string& message) { 112 void WebSocket::Send(const std::string& message) {
93 if (closed_) 113 if (closed_)
94 return; 114 return;
95 std::string encoded; 115 std::string encoded;
96 encoder_->EncodeFrame(message, 0, &encoded); 116 encoder_->EncodeFrame(message, 0, &encoded);
97 server_->SendRaw(connection_->id(), encoded); 117 server_->SendRaw(connection_->id(), encoded);
98 } 118 }
99 119
120 void WebSocket::Fail() {
121 closed_ = true;
122 // TODO(yhirano): The server SHOULD log the problem.
123 server_->Close(connection_->id());
124 }
125
126 void WebSocket::SendErrorResponse(const std::string& message) {
127 if (closed_)
128 return;
129 closed_ = true;
130 server_->Send500(connection_->id(), message);
davidben 2015/09/22 19:44:01 Why do some codepaths call Close and others not?
yhirano 2015/09/28 03:17:06 (extensions negotiation) https://tools.ietf.org/ht
131 }
132
100 } // namespace net 133 } // namespace net
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698