1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
|
/*
This file is part of TALER
Copyright (C) 2019-2024 Taler Systems SA
TALER is free software; you can redistribute it and/or modify it
under the terms of the GNU General Public License as published
by the Free Software Foundation; either version 3, or (at your
option) any later version.
TALER is distributed in the hope that it will be useful, but
WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public
License along with TALER; see the file COPYING. If not, see
<http://www.gnu.org/licenses/>
*/
/**
* @file curl/curl.c
* @brief Helper routines for interactions with libcurl
* @author Christian Grothoff
*/
#include "platform.h"
#include "taler_curl_lib.h"
#if TALER_CURL_COMPRESS_BODIES
#include <zlib.h>
#endif
void
TALER_curl_set_secure_redirect_policy (CURL *eh,
const char *url)
{
GNUNET_assert (CURLE_OK ==
curl_easy_setopt (eh,
CURLOPT_FOLLOWLOCATION,
1L));
GNUNET_assert ( (0 == strncasecmp (url,
"https://",
strlen ("https://"))) ||
(0 == strncasecmp (url,
"http://",
strlen ("http://"))) );
#ifdef CURLOPT_REDIR_PROTOCOLS_STR
if (0 == strncasecmp (url,
"https://",
strlen ("https://")))
GNUNET_assert (CURLE_OK ==
curl_easy_setopt (eh,
CURLOPT_REDIR_PROTOCOLS_STR,
"https"));
else
GNUNET_assert (CURLE_OK ==
curl_easy_setopt (eh,
CURLOPT_REDIR_PROTOCOLS_STR,
"http,https"));
#else
#ifdef CURLOPT_REDIR_PROTOCOLS
if (0 == strncasecmp (url,
"https://",
strlen ("https://")))
GNUNET_assert (CURLE_OK ==
curl_easy_setopt (eh,
CURLOPT_REDIR_PROTOCOLS,
CURLPROTO_HTTPS));
else
GNUNET_assert (CURLE_OK ==
curl_easy_setopt (eh,
CURLOPT_REDIR_PROTOCOLS,
CURLPROTO_HTTP | CURLPROTO_HTTPS));
#endif
#endif
/* limit MAXREDIRS to 5 as a simple security measure against
a potential infinite loop caused by a malicious target */
GNUNET_assert (CURLE_OK ==
curl_easy_setopt (eh,
CURLOPT_MAXREDIRS,
5L));
}
enum GNUNET_GenericReturnValue
TALER_curl_easy_post (struct TALER_CURL_PostContext *ctx,
CURL *eh,
const json_t *body)
{
char *str;
size_t slen;
str = json_dumps (body,
JSON_COMPACT);
if (NULL == str)
{
GNUNET_break (0);
return GNUNET_SYSERR;
}
slen = strlen (str);
if (TALER_CURL_COMPRESS_BODIES &&
(! ctx->disable_compression) )
{
Bytef *cbuf;
uLongf cbuf_size;
int ret;
cbuf_size = compressBound (slen);
cbuf = GNUNET_malloc (cbuf_size);
ret = compress (cbuf,
&cbuf_size,
(const Bytef *) str,
slen);
if (Z_OK != ret)
{
/* compression failed!? */
GNUNET_break (0);
GNUNET_free (cbuf);
return GNUNET_SYSERR;
}
free (str);
slen = (size_t) cbuf_size;
ctx->json_enc = (char *) cbuf;
GNUNET_assert (
NULL !=
(ctx->headers = curl_slist_append (
ctx->headers,
"Content-Encoding: deflate")));
}
else
{
ctx->json_enc = str;
}
GNUNET_assert (
NULL !=
(ctx->headers = curl_slist_append (
ctx->headers,
"Content-Type: application/json")));
GNUNET_assert (CURLE_OK ==
curl_easy_setopt (eh,
CURLOPT_POSTFIELDS,
ctx->json_enc));
GNUNET_assert (CURLE_OK ==
curl_easy_setopt (eh,
CURLOPT_POSTFIELDSIZE,
slen));
return GNUNET_OK;
}
void
TALER_curl_easy_post_finished (struct TALER_CURL_PostContext *ctx)
{
curl_slist_free_all (ctx->headers);
ctx->headers = NULL;
GNUNET_free (ctx->json_enc);
ctx->json_enc = NULL;
}
|