/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
/* Sets variable @name in table @dest from r->subprocess_env if *available,elsefromtheenvironment,elsefrom@fallbackif
* non-NULL. */ staticvoid env2env(apr_table_t *dest, request_rec *r, constchar *name, constchar *fallback)
{ constchar *val;
val = apr_table_get(r->subprocess_env, name); if (!val)
val = apr_pstrdup(r->pool, getenv(name)); if (!val)
val = apr_pstrdup(r->pool, fallback); if (val)
apr_table_addn(dest, name, val);
}
/* use a temporary apr_table_t which we'll overlap onto *r->subprocess_envlater *(exception:ifr->subprocess_envisemptyatthestart, *writedirectlyintoit)
*/ if (apr_is_empty_table(r->subprocess_env)) {
e = r->subprocess_env;
} else {
e = apr_table_make(r->pool, 25 + hdrs_arr->nelts);
}
/* First, add environment vars from headers... this is as per *CGIspecs,thoughothersortsofscriptinginterfacessee *thesamevars...
*/
for (i = 0; i < hdrs_arr->nelts; ++i) { if (!hdrs[i].key) { continue;
}
/* A few headers are special cased --- Authorization to prevent *roguescriptsfromcapturingpasswords;content-typeand-length *fornoparticularreason.
*/
if (!ap_cstr_casecmp(hdrs[i].key, "Content-type")) {
apr_table_addn(e, "CONTENT_TYPE", hdrs[i].val);
} elseif (!ap_cstr_casecmp(hdrs[i].key, "Content-length")) {
apr_table_addn(e, "CONTENT_LENGTH", hdrs[i].val);
} /* HTTP_PROXY collides with a popular envvar used to configure *proxies,don'tletclientsset/overrideit.But,ifyoumust...
*/ #ifndef SECURITY_HOLE_PASS_PROXY elseif (!ap_cstr_casecmp(hdrs[i].key, "Proxy")) {
;
} #endif /* *Youreallydon'twanttodisablethischeck,sinceitleavesyou *wideopentoCGIsstealingpasswordsandpeopleviewingthem *intheenvironmentwith"ps-e".But,ifyoumust...
*/ #ifndef SECURITY_HOLE_PASS_AUTHORIZATION elseif (!ap_cstr_casecmp(hdrs[i].key, "Authorization")
|| !ap_cstr_casecmp(hdrs[i].key, "Proxy-Authorization")) { if (conf->cgi_pass_auth == AP_CGI_PASS_AUTH_ON) {
add_unless_null(e, http2env(r, hdrs[i].key), hdrs[i].val);
}
} #endif else
add_unless_null(e, http2env(r, hdrs[i].key), hdrs[i].val);
}
while (back) { if (back->user) {
apr_table_addn(e, "REDIRECT_REMOTE_USER", back->user); break;
}
back = back->prev;
}
}
add_unless_null(e, "AUTH_TYPE", r->ap_auth_type);
env_temp = ap_get_remote_logname(r); if (env_temp) {
apr_table_addn(e, "REMOTE_IDENT", apr_pstrdup(r->pool, env_temp));
}
/* Apache custom error responses. If we have redirected set two new vars */
if (r->prev) { if (conf->qualify_redirect_url != AP_CORE_CONFIG_ON) {
add_unless_null(e, "REDIRECT_URL", r->prev->uri);
} else { /* PR#57785: reconstruct full URL here */
apr_uri_t *uri = &r->prev->parsed_uri; if (!uri->scheme) {
uri->scheme = (char*)ap_http_scheme(r->prev);
} if (!uri->port) {
uri->port = ap_get_server_port(r->prev);
uri->port_str = apr_psprintf(r->pool, "%u", uri->port);
} if (!uri->hostname) {
uri->hostname = (char*)ap_get_server_name_for_url(r->prev);
}
add_unless_null(e, "REDIRECT_URL",
apr_uri_unparse(r->pool, uri, 0));
}
add_unless_null(e, "REDIRECT_QUERY_STRING", r->prev->args);
}
if (e != r->subprocess_env) {
apr_table_overlap(r->subprocess_env, e, APR_OVERLAP_TABLES_SET);
}
}
/* This "cute" little function comes about because the path info on *filenamesandURLsaren'talwaysthesame.Sowetakethetwo, *andfindasmuchofthetwothatmatchaspossible.
*/
AP_DECLARE(int) ap_find_path_info(constchar *uri, constchar *path_info)
{ int lu = strlen(uri); int lp = strlen(path_info);
while (lu-- && lp-- && uri[lu] == path_info[lp]) { if (path_info[lp] == '/') { while (lu && uri[lu-1] == '/') lu--;
}
}
/* Obtain the Request-URI from the original request-line, returning *anewstringfromtherequestpoolcontainingtheURIor"".
*/ staticchar *original_uri(request_rec *r)
{ char *first, *last;
/* Note that the code below special-cases scripts run from includes, *becauseit"knows"thatthesub_requesthasbeenhackedtohavethe *argsandpath_infooftheoriginalrequest,andnotanythatmayhave *comewiththescriptURIintheincludecommand.Ugh.
*/
if (pa_req->filename) { char *pt = apr_pstrcat(r->pool, pa_req->filename, pa_req->path_info,
NULL); #ifdef WIN32 /* We need to make this a real Windows path name */
apr_filepath_merge(&pt, "", pt, APR_FILEPATH_NATIVE, r->pool); #endif
apr_table_setn(e, "PATH_TRANSLATED", pt);
}
ap_destroy_sub_req(pa_req);
}
}
/* PR#38070: This fails because it gets confused when a *CGIStatusheaderoverridesap_meets_conditions. * *Wecanfixthatbydroppingap_meets_conditionswhen *Statushasbeenset.Sincethisistheonlyplace *cgi_statusgetsused,let'stestitexplicitly. * *ThealternativewouldbetoignoreCGIStatuswhen *ap_meets_conditionsreturnsanythinginteresting. *ThatwouldbesaferwrtHTTP,butwouldbreakCGI.
*/ if ((cgi_status == HTTP_UNSET) && (r->method_number == M_GET)) {
cond_status = ap_meets_conditions(r);
}
apr_table_overlap(r->err_headers_out, merge,
APR_OVERLAP_TABLES_MERGE); if (!apr_is_empty_table(cookie_table)) { /* the cookies have already been copied to the cookie_table */
apr_table_unset(r->err_headers_out, "Set-Cookie");
r->err_headers_out = apr_table_overlay(r->pool,
r->err_headers_out, cookie_table);
} return cond_status;
}
if (trace_log) { if (first_header)
ap_log_rerror(SCRIPT_LOG_MARK, APLOG_TRACE4, 0, r, "Headers from script '%s':",
apr_filepath_name_get(r->filename));
ap_log_rerror(SCRIPT_LOG_MARK, APLOG_TRACE4, 0, r, " %s", w);
}
/* if we see a bogus header don't ignore it. Shout and scream */
#if APR_CHARSET_EBCDIC /* Chances are that we received an ASCII header text instead of *theexpectedEBCDICheaderlines.Trytoauto-detect:
*/ if (!(l = strchr(w, ':'))) { int maybeASCII = 0, maybeEBCDIC = 0; unsignedchar *cp, native;
apr_size_t inbytes_left, outbytes_left;
for (cp = w; *cp != '\0'; ++cp) {
native = apr_xlate_conv_byte(ap_hdrs_from_ascii, *cp); if (apr_isprint(*cp) && !apr_isprint(native))
++maybeEBCDIC; if (!apr_isprint(*cp) && apr_isprint(native))
++maybeASCII;
} if (maybeASCII > maybeEBCDIC) {
ap_log_error(SCRIPT_LOG_MARK, APLOG_ERR, 0, r->server,
APLOGNO(02660) "CGI Interface Error: " "Script headers apparently ASCII: (CGI = %s)",
r->filename);
inbytes_left = outbytes_left = cp - w;
apr_xlate_conv_buffer(ap_hdrs_from_ascii,
w, &inbytes_left, w, &outbytes_left);
}
} #endif/*APR_CHARSET_EBCDIC*/ if (!(l = strchr(w, ':'))) { if (!buffer) { /* Soak up all the script output - may save an outright kill */ while ((*getsfunc)(w, MAX_STRING_LEN - 1, getsfunc_data) > 0) { continue;
}
}
/* Intentional no APLOGNO */
ap_log_rerror(SCRIPT_LOG_MARK, APLOG_ERR|APLOG_TOCLIENT, 0, r, "malformed header from script '%s': Bad header: %.30s",
apr_filepath_name_get(r->filename), w); return HTTP_INTERNAL_SERVER_ERROR;
}
*l++ = '\0'; while (apr_isspace(*l)) {
++l;
}
if (!ap_cstr_casecmp(w, "Content-type")) { char *tmp;
/* Nuke trailing whitespace */
char *endp = l + strlen(l) - 1; while (endp > l && apr_isspace(*endp)) {
*endp-- = '\0';
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.