1
0

httplib.h 679 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592
  1. //
  2. // httplib.h
  3. //
  4. // Copyright (c) 2026 Yuji Hirose. All rights reserved.
  5. // MIT License
  6. //
  7. #ifndef CPPHTTPLIB_HTTPLIB_H
  8. #define CPPHTTPLIB_HTTPLIB_H
  9. #define CPPHTTPLIB_VERSION "0.47.0"
  10. #define CPPHTTPLIB_VERSION_NUM "0x002f00"
  11. #ifdef _WIN32
  12. #if defined(_WIN32_WINNT) && _WIN32_WINNT < 0x0A00
  13. #error \
  14. "cpp-httplib doesn't support Windows 8 or lower. Please use Windows 10 or later."
  15. #endif
  16. #endif
  17. /*
  18. * Configuration
  19. */
  20. #ifndef CPPHTTPLIB_KEEPALIVE_TIMEOUT_SECOND
  21. #define CPPHTTPLIB_KEEPALIVE_TIMEOUT_SECOND 5
  22. #endif
  23. #ifndef CPPHTTPLIB_KEEPALIVE_TIMEOUT_CHECK_INTERVAL_USECOND
  24. #define CPPHTTPLIB_KEEPALIVE_TIMEOUT_CHECK_INTERVAL_USECOND 10000
  25. #endif
  26. #ifndef CPPHTTPLIB_KEEPALIVE_MAX_COUNT
  27. #define CPPHTTPLIB_KEEPALIVE_MAX_COUNT 100
  28. #endif
  29. #ifndef CPPHTTPLIB_CONNECTION_TIMEOUT_SECOND
  30. #define CPPHTTPLIB_CONNECTION_TIMEOUT_SECOND 300
  31. #endif
  32. #ifndef CPPHTTPLIB_CONNECTION_TIMEOUT_USECOND
  33. #define CPPHTTPLIB_CONNECTION_TIMEOUT_USECOND 0
  34. #endif
  35. #ifndef CPPHTTPLIB_SERVER_READ_TIMEOUT_SECOND
  36. #define CPPHTTPLIB_SERVER_READ_TIMEOUT_SECOND 5
  37. #endif
  38. #ifndef CPPHTTPLIB_SERVER_READ_TIMEOUT_USECOND
  39. #define CPPHTTPLIB_SERVER_READ_TIMEOUT_USECOND 0
  40. #endif
  41. #ifndef CPPHTTPLIB_SERVER_WRITE_TIMEOUT_SECOND
  42. #define CPPHTTPLIB_SERVER_WRITE_TIMEOUT_SECOND 5
  43. #endif
  44. #ifndef CPPHTTPLIB_SERVER_WRITE_TIMEOUT_USECOND
  45. #define CPPHTTPLIB_SERVER_WRITE_TIMEOUT_USECOND 0
  46. #endif
  47. #ifndef CPPHTTPLIB_CLIENT_READ_TIMEOUT_SECOND
  48. #define CPPHTTPLIB_CLIENT_READ_TIMEOUT_SECOND 300
  49. #endif
  50. #ifndef CPPHTTPLIB_CLIENT_READ_TIMEOUT_USECOND
  51. #define CPPHTTPLIB_CLIENT_READ_TIMEOUT_USECOND 0
  52. #endif
  53. #ifndef CPPHTTPLIB_CLIENT_WRITE_TIMEOUT_SECOND
  54. #define CPPHTTPLIB_CLIENT_WRITE_TIMEOUT_SECOND 5
  55. #endif
  56. #ifndef CPPHTTPLIB_CLIENT_WRITE_TIMEOUT_USECOND
  57. #define CPPHTTPLIB_CLIENT_WRITE_TIMEOUT_USECOND 0
  58. #endif
  59. #ifndef CPPHTTPLIB_CLIENT_MAX_TIMEOUT_MSECOND
  60. #define CPPHTTPLIB_CLIENT_MAX_TIMEOUT_MSECOND 0
  61. #endif
  62. #ifndef CPPHTTPLIB_EXPECT_100_THRESHOLD
  63. #define CPPHTTPLIB_EXPECT_100_THRESHOLD 1024
  64. #endif
  65. #ifndef CPPHTTPLIB_EXPECT_100_TIMEOUT_MSECOND
  66. #define CPPHTTPLIB_EXPECT_100_TIMEOUT_MSECOND 1000
  67. #endif
  68. #ifndef CPPHTTPLIB_WAIT_EARLY_SERVER_RESPONSE_THRESHOLD
  69. #define CPPHTTPLIB_WAIT_EARLY_SERVER_RESPONSE_THRESHOLD (1024 * 1024)
  70. #endif
  71. #ifndef CPPHTTPLIB_WAIT_EARLY_SERVER_RESPONSE_TIMEOUT_MSECOND
  72. #define CPPHTTPLIB_WAIT_EARLY_SERVER_RESPONSE_TIMEOUT_MSECOND 50
  73. #endif
  74. #ifndef CPPHTTPLIB_IDLE_INTERVAL_SECOND
  75. #define CPPHTTPLIB_IDLE_INTERVAL_SECOND 0
  76. #endif
  77. #ifndef CPPHTTPLIB_IDLE_INTERVAL_USECOND
  78. #ifdef _WIN32
  79. #define CPPHTTPLIB_IDLE_INTERVAL_USECOND 1000
  80. #else
  81. #define CPPHTTPLIB_IDLE_INTERVAL_USECOND 0
  82. #endif
  83. #endif
  84. #ifndef CPPHTTPLIB_REQUEST_URI_MAX_LENGTH
  85. #define CPPHTTPLIB_REQUEST_URI_MAX_LENGTH 8192
  86. #endif
  87. #ifndef CPPHTTPLIB_HEADER_MAX_LENGTH
  88. #define CPPHTTPLIB_HEADER_MAX_LENGTH 8192
  89. #endif
  90. #ifndef CPPHTTPLIB_HEADER_MAX_COUNT
  91. #define CPPHTTPLIB_HEADER_MAX_COUNT 100
  92. #endif
  93. #ifndef CPPHTTPLIB_REDIRECT_MAX_COUNT
  94. #define CPPHTTPLIB_REDIRECT_MAX_COUNT 20
  95. #endif
  96. #ifndef CPPHTTPLIB_MULTIPART_FORM_DATA_FILE_MAX_COUNT
  97. #define CPPHTTPLIB_MULTIPART_FORM_DATA_FILE_MAX_COUNT 1024
  98. #endif
  99. #ifndef CPPHTTPLIB_PAYLOAD_MAX_LENGTH
  100. #define CPPHTTPLIB_PAYLOAD_MAX_LENGTH (100 * 1024 * 1024) // 100MB
  101. #endif
  102. #ifndef CPPHTTPLIB_FORM_URL_ENCODED_PAYLOAD_MAX_LENGTH
  103. #define CPPHTTPLIB_FORM_URL_ENCODED_PAYLOAD_MAX_LENGTH 8192
  104. #endif
  105. #ifndef CPPHTTPLIB_RANGE_MAX_COUNT
  106. #define CPPHTTPLIB_RANGE_MAX_COUNT 1024
  107. #endif
  108. #ifndef CPPHTTPLIB_TCP_NODELAY
  109. #define CPPHTTPLIB_TCP_NODELAY false
  110. #endif
  111. #ifndef CPPHTTPLIB_IPV6_V6ONLY
  112. #define CPPHTTPLIB_IPV6_V6ONLY false
  113. #endif
  114. #ifndef CPPHTTPLIB_RECV_BUFSIZ
  115. #define CPPHTTPLIB_RECV_BUFSIZ size_t(16384u)
  116. #endif
  117. #ifndef CPPHTTPLIB_SEND_BUFSIZ
  118. #define CPPHTTPLIB_SEND_BUFSIZ size_t(16384u)
  119. #endif
  120. #ifndef CPPHTTPLIB_COMPRESSION_BUFSIZ
  121. #define CPPHTTPLIB_COMPRESSION_BUFSIZ size_t(16384u)
  122. #endif
  123. #ifndef CPPHTTPLIB_THREAD_POOL_COUNT
  124. #define CPPHTTPLIB_THREAD_POOL_COUNT \
  125. ((std::max)(8u, std::thread::hardware_concurrency() > 0 \
  126. ? std::thread::hardware_concurrency() - 1 \
  127. : 0))
  128. #endif
  129. #ifndef CPPHTTPLIB_THREAD_POOL_MAX_COUNT
  130. #define CPPHTTPLIB_THREAD_POOL_MAX_COUNT (CPPHTTPLIB_THREAD_POOL_COUNT * 4)
  131. #endif
  132. #ifndef CPPHTTPLIB_THREAD_POOL_IDLE_TIMEOUT
  133. #define CPPHTTPLIB_THREAD_POOL_IDLE_TIMEOUT 3 // seconds
  134. #endif
  135. #ifndef CPPHTTPLIB_RECV_FLAGS
  136. #define CPPHTTPLIB_RECV_FLAGS 0
  137. #endif
  138. #ifndef CPPHTTPLIB_SEND_FLAGS
  139. #define CPPHTTPLIB_SEND_FLAGS 0
  140. #endif
  141. #ifndef CPPHTTPLIB_LISTEN_BACKLOG
  142. #define CPPHTTPLIB_LISTEN_BACKLOG 5
  143. #endif
  144. #ifndef CPPHTTPLIB_MAX_LINE_LENGTH
  145. #define CPPHTTPLIB_MAX_LINE_LENGTH 32768
  146. #endif
  147. #ifndef CPPHTTPLIB_WEBSOCKET_MAX_PAYLOAD_LENGTH
  148. #define CPPHTTPLIB_WEBSOCKET_MAX_PAYLOAD_LENGTH 16777216
  149. #endif
  150. #ifndef CPPHTTPLIB_WEBSOCKET_READ_TIMEOUT_SECOND
  151. #define CPPHTTPLIB_WEBSOCKET_READ_TIMEOUT_SECOND 300
  152. #endif
  153. #ifndef CPPHTTPLIB_WEBSOCKET_CLOSE_TIMEOUT_SECOND
  154. #define CPPHTTPLIB_WEBSOCKET_CLOSE_TIMEOUT_SECOND 5
  155. #endif
  156. #ifndef CPPHTTPLIB_WEBSOCKET_PING_INTERVAL_SECOND
  157. #define CPPHTTPLIB_WEBSOCKET_PING_INTERVAL_SECOND 30
  158. #endif
  159. #ifndef CPPHTTPLIB_WEBSOCKET_MAX_MISSED_PONGS
  160. #define CPPHTTPLIB_WEBSOCKET_MAX_MISSED_PONGS 0
  161. #endif
  162. /*
  163. * Headers
  164. */
  165. #ifdef _WIN32
  166. #ifndef _CRT_SECURE_NO_WARNINGS
  167. #define _CRT_SECURE_NO_WARNINGS
  168. #endif //_CRT_SECURE_NO_WARNINGS
  169. #ifndef _CRT_NONSTDC_NO_DEPRECATE
  170. #define _CRT_NONSTDC_NO_DEPRECATE
  171. #endif //_CRT_NONSTDC_NO_DEPRECATE
  172. #if defined(_MSC_VER)
  173. #if _MSC_VER < 1900
  174. #error Sorry, Visual Studio versions prior to 2015 are not supported
  175. #endif
  176. #pragma comment(lib, "ws2_32.lib")
  177. #ifndef _SSIZE_T_DEFINED
  178. using ssize_t = __int64;
  179. #define _SSIZE_T_DEFINED
  180. #endif
  181. #endif // _MSC_VER
  182. #ifndef S_ISREG
  183. #define S_ISREG(m) (((m) & S_IFREG) == S_IFREG)
  184. #endif // S_ISREG
  185. #ifndef S_ISDIR
  186. #define S_ISDIR(m) (((m) & S_IFDIR) == S_IFDIR)
  187. #endif // S_ISDIR
  188. #ifndef NOMINMAX
  189. #define NOMINMAX
  190. #endif // NOMINMAX
  191. #include <io.h>
  192. #include <winsock2.h>
  193. #include <ws2tcpip.h>
  194. #if defined(__has_include)
  195. #if __has_include(<afunix.h>)
  196. // afunix.h uses types declared in winsock2.h, so has to be included after it.
  197. #include <afunix.h>
  198. #define CPPHTTPLIB_HAVE_AFUNIX_H 1
  199. #endif
  200. #endif
  201. #ifndef WSA_FLAG_NO_HANDLE_INHERIT
  202. #define WSA_FLAG_NO_HANDLE_INHERIT 0x80
  203. #endif
  204. using nfds_t = unsigned long;
  205. using socket_t = SOCKET;
  206. using socklen_t = int;
  207. #else // not _WIN32
  208. #include <arpa/inet.h>
  209. #if !defined(_AIX) && !defined(__MVS__)
  210. #include <ifaddrs.h>
  211. #endif
  212. #ifdef __MVS__
  213. #include <strings.h>
  214. #ifndef NI_MAXHOST
  215. #define NI_MAXHOST 1025
  216. #endif
  217. #endif
  218. #include <net/if.h>
  219. #include <netdb.h>
  220. #include <netinet/in.h>
  221. #ifdef __linux__
  222. #include <resolv.h>
  223. #undef _res // Undefine _res macro to avoid conflicts with user code (#2278)
  224. #endif
  225. #include <csignal>
  226. #include <netinet/tcp.h>
  227. #include <poll.h>
  228. #include <pthread.h>
  229. #include <sys/mman.h>
  230. #include <sys/socket.h>
  231. #include <sys/un.h>
  232. #include <unistd.h>
  233. using socket_t = int;
  234. #ifndef INVALID_SOCKET
  235. #define INVALID_SOCKET (-1)
  236. #endif
  237. #endif //_WIN32
  238. #if defined(__APPLE__)
  239. #include <TargetConditionals.h>
  240. #endif
  241. #include <algorithm>
  242. #include <array>
  243. #include <atomic>
  244. #include <cassert>
  245. #include <cctype>
  246. #include <chrono>
  247. #include <climits>
  248. #include <condition_variable>
  249. #include <cstdlib>
  250. #include <cstring>
  251. #include <errno.h>
  252. #include <exception>
  253. #include <fcntl.h>
  254. #include <fstream>
  255. #include <functional>
  256. #include <iomanip>
  257. #include <iostream>
  258. #include <list>
  259. #include <map>
  260. #include <memory>
  261. #include <mutex>
  262. #include <random>
  263. #include <regex>
  264. #include <set>
  265. #include <sstream>
  266. #include <string>
  267. #include <sys/stat.h>
  268. #include <system_error>
  269. #include <thread>
  270. #include <unordered_map>
  271. #include <unordered_set>
  272. #include <utility>
  273. // On macOS with a TLS backend, enable Keychain root certificates by default
  274. // unless the user explicitly opts out. Not enabled on iOS/tvOS/watchOS since
  275. // the SecTrustSettings APIs used to enumerate anchor certificates are macOS
  276. // only; on those platforms the user must provide a CA bundle explicitly.
  277. #if defined(__APPLE__) && defined(__clang__) && \
  278. !defined(CPPHTTPLIB_DISABLE_MACOSX_AUTOMATIC_ROOT_CERTIFICATES) && \
  279. (defined(CPPHTTPLIB_OPENSSL_SUPPORT) || \
  280. defined(CPPHTTPLIB_MBEDTLS_SUPPORT) || \
  281. defined(CPPHTTPLIB_WOLFSSL_SUPPORT))
  282. #if TARGET_OS_OSX
  283. #ifndef CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN
  284. #define CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN
  285. #endif
  286. #endif
  287. #endif
  288. #if defined(CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN) && \
  289. defined(__APPLE__) && !TARGET_OS_OSX
  290. #error \
  291. "CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN is only supported on macOS. On iOS/tvOS/watchOS, supply a CA bundle via set_ca_cert_path()."
  292. #endif
  293. // On Windows, enable Schannel certificate verification by default
  294. // unless the user explicitly opts out.
  295. #if defined(_WIN32) && \
  296. !defined(CPPHTTPLIB_DISABLE_WINDOWS_AUTOMATIC_ROOT_CERTIFICATES_UPDATE)
  297. #define CPPHTTPLIB_WINDOWS_AUTOMATIC_ROOT_CERTIFICATES_UPDATE
  298. #endif
  299. #if defined(CPPHTTPLIB_USE_NON_BLOCKING_GETADDRINFO) || \
  300. defined(CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN)
  301. #if TARGET_OS_MAC && defined(__clang__)
  302. #include <CFNetwork/CFHost.h>
  303. #include <CoreFoundation/CoreFoundation.h>
  304. #endif
  305. #endif
  306. #ifdef CPPHTTPLIB_OPENSSL_SUPPORT
  307. #ifdef _WIN32
  308. #include <wincrypt.h>
  309. // these are defined in wincrypt.h and it breaks compilation if BoringSSL is
  310. // used
  311. #undef X509_NAME
  312. #undef X509_CERT_PAIR
  313. #undef X509_EXTENSIONS
  314. #undef PKCS7_SIGNER_INFO
  315. #ifdef _MSC_VER
  316. #pragma comment(lib, "crypt32.lib")
  317. #endif
  318. #endif // _WIN32
  319. #ifdef CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN
  320. #if TARGET_OS_OSX
  321. #include <Security/Security.h>
  322. #endif
  323. #endif
  324. #include <openssl/err.h>
  325. #include <openssl/evp.h>
  326. #include <openssl/ssl.h>
  327. #include <openssl/x509v3.h>
  328. #if defined(_WIN32) && defined(OPENSSL_USE_APPLINK)
  329. #include <openssl/applink.c>
  330. #endif
  331. #include <iostream>
  332. #include <sstream>
  333. #if defined(OPENSSL_IS_BORINGSSL) || defined(LIBRESSL_VERSION_NUMBER)
  334. #if OPENSSL_VERSION_NUMBER < 0x1010107f
  335. #error Please use OpenSSL or a current version of BoringSSL
  336. #endif
  337. #define SSL_get1_peer_certificate SSL_get_peer_certificate
  338. #elif OPENSSL_VERSION_NUMBER < 0x30000000L
  339. #error Sorry, OpenSSL versions prior to 3.0.0 are not supported
  340. #endif
  341. #endif // CPPHTTPLIB_OPENSSL_SUPPORT
  342. #ifdef CPPHTTPLIB_MBEDTLS_SUPPORT
  343. #include <mbedtls/ctr_drbg.h>
  344. #include <mbedtls/entropy.h>
  345. #include <mbedtls/error.h>
  346. #include <mbedtls/md5.h>
  347. #include <mbedtls/net_sockets.h>
  348. #include <mbedtls/oid.h>
  349. #include <mbedtls/pk.h>
  350. #include <mbedtls/sha1.h>
  351. #include <mbedtls/sha256.h>
  352. #include <mbedtls/sha512.h>
  353. #include <mbedtls/ssl.h>
  354. #include <mbedtls/x509_crt.h>
  355. #ifdef _WIN32
  356. #include <wincrypt.h>
  357. #ifdef _MSC_VER
  358. #pragma comment(lib, "crypt32.lib")
  359. #endif
  360. #endif // _WIN32
  361. #ifdef CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN
  362. #if TARGET_OS_OSX
  363. #include <Security/Security.h>
  364. #endif
  365. #endif
  366. // Mbed TLS 3.x API compatibility
  367. #if MBEDTLS_VERSION_MAJOR >= 3
  368. #define CPPHTTPLIB_MBEDTLS_V3
  369. #endif
  370. #endif // CPPHTTPLIB_MBEDTLS_SUPPORT
  371. #ifdef CPPHTTPLIB_WOLFSSL_SUPPORT
  372. #include <wolfssl/options.h>
  373. #include <wolfssl/openssl/x509v3.h>
  374. // Fallback definitions for older wolfSSL versions (e.g., 5.6.6)
  375. #ifndef WOLFSSL_GEN_EMAIL
  376. #define WOLFSSL_GEN_EMAIL 1
  377. #endif
  378. #ifndef WOLFSSL_GEN_DNS
  379. #define WOLFSSL_GEN_DNS 2
  380. #endif
  381. #ifndef WOLFSSL_GEN_URI
  382. #define WOLFSSL_GEN_URI 6
  383. #endif
  384. #ifndef WOLFSSL_GEN_IPADD
  385. #define WOLFSSL_GEN_IPADD 7
  386. #endif
  387. #include <wolfssl/ssl.h>
  388. #include <wolfssl/wolfcrypt/hash.h>
  389. #include <wolfssl/wolfcrypt/md5.h>
  390. #include <wolfssl/wolfcrypt/sha256.h>
  391. #include <wolfssl/wolfcrypt/sha512.h>
  392. #ifdef _WIN32
  393. #include <wincrypt.h>
  394. #ifdef _MSC_VER
  395. #pragma comment(lib, "crypt32.lib")
  396. #endif
  397. #endif // _WIN32
  398. #ifdef CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN
  399. #if TARGET_OS_OSX
  400. #include <Security/Security.h>
  401. #endif
  402. #endif
  403. #endif // CPPHTTPLIB_WOLFSSL_SUPPORT
  404. // Define CPPHTTPLIB_SSL_ENABLED if any SSL backend is available
  405. #if defined(CPPHTTPLIB_OPENSSL_SUPPORT) || \
  406. defined(CPPHTTPLIB_MBEDTLS_SUPPORT) || defined(CPPHTTPLIB_WOLFSSL_SUPPORT)
  407. #define CPPHTTPLIB_SSL_ENABLED
  408. #endif
  409. #ifdef CPPHTTPLIB_ZLIB_SUPPORT
  410. #include <zlib.h>
  411. #endif
  412. #ifdef CPPHTTPLIB_BROTLI_SUPPORT
  413. #include <brotli/decode.h>
  414. #include <brotli/encode.h>
  415. #endif
  416. #ifdef CPPHTTPLIB_ZSTD_SUPPORT
  417. #include <zstd.h>
  418. #endif
  419. /*
  420. * Declaration
  421. */
  422. namespace httplib {
  423. namespace ws {
  424. class WebSocket;
  425. } // namespace ws
  426. namespace detail {
  427. /*
  428. * Backport std::make_unique from C++14.
  429. *
  430. * NOTE: This code came up with the following stackoverflow post:
  431. * https://stackoverflow.com/questions/10149840/c-arrays-and-make-unique
  432. *
  433. */
  434. template <class T, class... Args>
  435. typename std::enable_if<!std::is_array<T>::value, std::unique_ptr<T>>::type
  436. make_unique(Args &&...args) {
  437. return std::unique_ptr<T>(new T(std::forward<Args>(args)...));
  438. }
  439. template <class T>
  440. typename std::enable_if<std::is_array<T>::value, std::unique_ptr<T>>::type
  441. make_unique(std::size_t n) {
  442. typedef typename std::remove_extent<T>::type RT;
  443. return std::unique_ptr<T>(new RT[n]);
  444. }
  445. namespace case_ignore {
  446. inline unsigned char to_lower(int c) {
  447. const static unsigned char table[256] = {
  448. 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14,
  449. 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29,
  450. 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44,
  451. 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 56, 57, 58, 59,
  452. 60, 61, 62, 63, 64, 97, 98, 99, 100, 101, 102, 103, 104, 105, 106,
  453. 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121,
  454. 122, 91, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 103, 104,
  455. 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119,
  456. 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134,
  457. 135, 136, 137, 138, 139, 140, 141, 142, 143, 144, 145, 146, 147, 148, 149,
  458. 150, 151, 152, 153, 154, 155, 156, 157, 158, 159, 160, 161, 162, 163, 164,
  459. 165, 166, 167, 168, 169, 170, 171, 172, 173, 174, 175, 176, 177, 178, 179,
  460. 180, 181, 182, 183, 184, 185, 186, 187, 188, 189, 190, 191, 224, 225, 226,
  461. 227, 228, 229, 230, 231, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241,
  462. 242, 243, 244, 245, 246, 215, 248, 249, 250, 251, 252, 253, 254, 223, 224,
  463. 225, 226, 227, 228, 229, 230, 231, 232, 233, 234, 235, 236, 237, 238, 239,
  464. 240, 241, 242, 243, 244, 245, 246, 247, 248, 249, 250, 251, 252, 253, 254,
  465. 255,
  466. };
  467. return table[(unsigned char)(char)c];
  468. }
  469. inline std::string to_lower(const std::string &s) {
  470. std::string result = s;
  471. std::transform(
  472. result.begin(), result.end(), result.begin(),
  473. [](unsigned char c) { return static_cast<char>(to_lower(c)); });
  474. return result;
  475. }
  476. inline bool equal(const std::string &a, const std::string &b) {
  477. return a.size() == b.size() &&
  478. std::equal(a.begin(), a.end(), b.begin(), [](char ca, char cb) {
  479. return to_lower(ca) == to_lower(cb);
  480. });
  481. }
  482. struct equal_to {
  483. bool operator()(const std::string &a, const std::string &b) const {
  484. return equal(a, b);
  485. }
  486. };
  487. struct hash {
  488. size_t operator()(const std::string &key) const {
  489. return hash_core(key.data(), key.size(), 0);
  490. }
  491. size_t hash_core(const char *s, size_t l, size_t h) const {
  492. return (l == 0) ? h
  493. : hash_core(s + 1, l - 1,
  494. // Unsets the 6 high bits of h, therefore no
  495. // overflow happens
  496. (((std::numeric_limits<size_t>::max)() >> 6) &
  497. h * 33) ^
  498. static_cast<unsigned char>(to_lower(*s)));
  499. }
  500. };
  501. template <typename T>
  502. using unordered_set = std::unordered_set<T, detail::case_ignore::hash,
  503. detail::case_ignore::equal_to>;
  504. } // namespace case_ignore
  505. // This is based on
  506. // "http://www.open-std.org/jtc1/sc22/wg21/docs/papers/2014/n4189".
  507. struct scope_exit {
  508. explicit scope_exit(std::function<void(void)> &&f)
  509. : exit_function(std::move(f)), execute_on_destruction{true} {}
  510. scope_exit(scope_exit &&rhs) noexcept
  511. : exit_function(std::move(rhs.exit_function)),
  512. execute_on_destruction{rhs.execute_on_destruction} {
  513. rhs.release();
  514. }
  515. ~scope_exit() {
  516. if (execute_on_destruction) { this->exit_function(); }
  517. }
  518. void release() { this->execute_on_destruction = false; }
  519. private:
  520. scope_exit(const scope_exit &) = delete;
  521. void operator=(const scope_exit &) = delete;
  522. scope_exit &operator=(scope_exit &&) = delete;
  523. std::function<void(void)> exit_function;
  524. bool execute_on_destruction;
  525. };
  526. // Simple from_chars implementation for integer and double types (C++17
  527. // substitute)
  528. template <typename T> struct from_chars_result {
  529. const char *ptr;
  530. std::errc ec;
  531. };
  532. template <typename T>
  533. inline from_chars_result<T> from_chars(const char *first, const char *last,
  534. T &value, int base = 10) {
  535. value = 0;
  536. const char *p = first;
  537. bool negative = false;
  538. if (p != last && *p == '-') {
  539. negative = true;
  540. ++p;
  541. }
  542. if (p == last) { return {first, std::errc::invalid_argument}; }
  543. T result = 0;
  544. for (; p != last; ++p) {
  545. char c = *p;
  546. int digit = -1;
  547. if ('0' <= c && c <= '9') {
  548. digit = c - '0';
  549. } else if ('a' <= c && c <= 'z') {
  550. digit = c - 'a' + 10;
  551. } else if ('A' <= c && c <= 'Z') {
  552. digit = c - 'A' + 10;
  553. } else {
  554. break;
  555. }
  556. if (digit < 0 || digit >= base) { break; }
  557. if (result > ((std::numeric_limits<T>::max)() - digit) / base) {
  558. return {p, std::errc::result_out_of_range};
  559. }
  560. result = result * base + digit;
  561. }
  562. if (p == first || (negative && p == first + 1)) {
  563. return {first, std::errc::invalid_argument};
  564. }
  565. value = negative ? -result : result;
  566. return {p, std::errc{}};
  567. }
  568. // from_chars for double (simple wrapper for strtod)
  569. inline from_chars_result<double> from_chars(const char *first, const char *last,
  570. double &value) {
  571. std::string s(first, last);
  572. char *endptr = nullptr;
  573. errno = 0;
  574. value = std::strtod(s.c_str(), &endptr);
  575. if (endptr == s.c_str()) { return {first, std::errc::invalid_argument}; }
  576. if (errno == ERANGE) {
  577. return {first + (endptr - s.c_str()), std::errc::result_out_of_range};
  578. }
  579. return {first + (endptr - s.c_str()), std::errc{}};
  580. }
  581. inline bool parse_port(const char *s, size_t len, int &port) {
  582. int val = 0;
  583. auto r = from_chars(s, s + len, val);
  584. if (r.ec != std::errc{} || val < 1 || val > 65535) { return false; }
  585. port = val;
  586. return true;
  587. }
  588. inline bool parse_port(const std::string &s, int &port) {
  589. return parse_port(s.data(), s.size(), port);
  590. }
  591. struct UrlComponents {
  592. std::string scheme;
  593. std::string host;
  594. std::string port;
  595. std::string path;
  596. std::string query;
  597. };
  598. inline bool parse_url(const std::string &url, UrlComponents &uc) {
  599. uc = {};
  600. size_t pos = 0;
  601. auto sep = url.find("://");
  602. if (sep != std::string::npos) {
  603. uc.scheme = url.substr(0, sep);
  604. // Scheme must be [a-z]+ only
  605. if (uc.scheme.empty()) { return false; }
  606. for (auto c : uc.scheme) {
  607. if (c < 'a' || c > 'z') { return false; }
  608. }
  609. pos = sep + 3;
  610. } else if (url.compare(0, 2, "//") == 0) {
  611. pos = 2;
  612. }
  613. auto has_authority_prefix = pos > 0;
  614. auto has_authority = has_authority_prefix || (!url.empty() && url[0] != '/' &&
  615. url[0] != '?' && url[0] != '#');
  616. if (has_authority) {
  617. if (pos < url.size() && url[pos] == '[') {
  618. auto close = url.find(']', pos);
  619. if (close == std::string::npos) { return false; }
  620. uc.host = url.substr(pos + 1, close - pos - 1);
  621. // IPv6 host must be [a-fA-F0-9:]+ only
  622. if (uc.host.empty()) { return false; }
  623. for (auto c : uc.host) {
  624. if (!((c >= 'a' && c <= 'f') || (c >= 'A' && c <= 'F') ||
  625. (c >= '0' && c <= '9') || c == ':')) {
  626. return false;
  627. }
  628. }
  629. pos = close + 1;
  630. } else {
  631. auto end = url.find_first_of(":/?#", pos);
  632. if (end == std::string::npos) { end = url.size(); }
  633. uc.host = url.substr(pos, end - pos);
  634. pos = end;
  635. }
  636. if (pos < url.size() && url[pos] == ':') {
  637. ++pos;
  638. auto end = url.find_first_of("/?#", pos);
  639. if (end == std::string::npos) { end = url.size(); }
  640. uc.port = url.substr(pos, end - pos);
  641. pos = end;
  642. }
  643. // Without :// or //, the entire input must be consumed as host[:port].
  644. // If there is leftover (path, query, etc.), this is not a valid
  645. // host[:port] string — clear and reparse as a plain path.
  646. if (!has_authority_prefix && pos < url.size()) {
  647. uc.host.clear();
  648. uc.port.clear();
  649. pos = 0;
  650. }
  651. }
  652. if (pos < url.size() && url[pos] != '?' && url[pos] != '#') {
  653. auto end = url.find_first_of("?#", pos);
  654. if (end == std::string::npos) { end = url.size(); }
  655. uc.path = url.substr(pos, end - pos);
  656. pos = end;
  657. }
  658. if (pos < url.size() && url[pos] == '?') {
  659. auto end = url.find('#', pos);
  660. if (end == std::string::npos) { end = url.size(); }
  661. uc.query = url.substr(pos, end - pos);
  662. }
  663. return true;
  664. }
  665. } // namespace detail
  666. enum class SSLVerifierResponse {
  667. // no decision has been made, use the built-in certificate verifier
  668. NoDecisionMade,
  669. // connection certificate is verified and accepted
  670. CertificateAccepted,
  671. // connection certificate was processed but is rejected
  672. CertificateRejected
  673. };
  674. // System CA loading policy for SSL clients. Auto (the default) loads system
  675. // CA certs only when no custom CA is configured; enable_system_ca() switches
  676. // to an explicit policy.
  677. enum class SystemCAMode { Auto, Enabled, Disabled };
  678. enum StatusCode {
  679. // Information responses
  680. Continue_100 = 100,
  681. SwitchingProtocol_101 = 101,
  682. Processing_102 = 102,
  683. EarlyHints_103 = 103,
  684. // Successful responses
  685. OK_200 = 200,
  686. Created_201 = 201,
  687. Accepted_202 = 202,
  688. NonAuthoritativeInformation_203 = 203,
  689. NoContent_204 = 204,
  690. ResetContent_205 = 205,
  691. PartialContent_206 = 206,
  692. MultiStatus_207 = 207,
  693. AlreadyReported_208 = 208,
  694. IMUsed_226 = 226,
  695. // Redirection messages
  696. MultipleChoices_300 = 300,
  697. MovedPermanently_301 = 301,
  698. Found_302 = 302,
  699. SeeOther_303 = 303,
  700. NotModified_304 = 304,
  701. UseProxy_305 = 305,
  702. unused_306 = 306,
  703. TemporaryRedirect_307 = 307,
  704. PermanentRedirect_308 = 308,
  705. // Client error responses
  706. BadRequest_400 = 400,
  707. Unauthorized_401 = 401,
  708. PaymentRequired_402 = 402,
  709. Forbidden_403 = 403,
  710. NotFound_404 = 404,
  711. MethodNotAllowed_405 = 405,
  712. NotAcceptable_406 = 406,
  713. ProxyAuthenticationRequired_407 = 407,
  714. RequestTimeout_408 = 408,
  715. Conflict_409 = 409,
  716. Gone_410 = 410,
  717. LengthRequired_411 = 411,
  718. PreconditionFailed_412 = 412,
  719. PayloadTooLarge_413 = 413,
  720. UriTooLong_414 = 414,
  721. UnsupportedMediaType_415 = 415,
  722. RangeNotSatisfiable_416 = 416,
  723. ExpectationFailed_417 = 417,
  724. ImATeapot_418 = 418,
  725. MisdirectedRequest_421 = 421,
  726. UnprocessableContent_422 = 422,
  727. Locked_423 = 423,
  728. FailedDependency_424 = 424,
  729. TooEarly_425 = 425,
  730. UpgradeRequired_426 = 426,
  731. PreconditionRequired_428 = 428,
  732. TooManyRequests_429 = 429,
  733. RequestHeaderFieldsTooLarge_431 = 431,
  734. UnavailableForLegalReasons_451 = 451,
  735. // Server error responses
  736. InternalServerError_500 = 500,
  737. NotImplemented_501 = 501,
  738. BadGateway_502 = 502,
  739. ServiceUnavailable_503 = 503,
  740. GatewayTimeout_504 = 504,
  741. HttpVersionNotSupported_505 = 505,
  742. VariantAlsoNegotiates_506 = 506,
  743. InsufficientStorage_507 = 507,
  744. LoopDetected_508 = 508,
  745. NotExtended_510 = 510,
  746. NetworkAuthenticationRequired_511 = 511,
  747. };
  748. using Headers =
  749. std::unordered_multimap<std::string, std::string, detail::case_ignore::hash,
  750. detail::case_ignore::equal_to>;
  751. using Params = std::multimap<std::string, std::string>;
  752. using Match = std::smatch;
  753. using DownloadProgress = std::function<bool(size_t current, size_t total)>;
  754. using UploadProgress = std::function<bool(size_t current, size_t total)>;
  755. /*
  756. * detail: type-erased storage used by UserData.
  757. * ABI-stable regardless of C++ standard — always uses this custom
  758. * implementation instead of std::any.
  759. */
  760. namespace detail {
  761. using any_type_id = const void *;
  762. template <typename T> any_type_id any_typeid() noexcept {
  763. static const char id = 0;
  764. return &id;
  765. }
  766. struct any_storage {
  767. virtual ~any_storage() = default;
  768. virtual std::unique_ptr<any_storage> clone() const = 0;
  769. virtual any_type_id type_id() const noexcept = 0;
  770. };
  771. template <typename T> struct any_value final : any_storage {
  772. T value;
  773. template <typename U> explicit any_value(U &&v) : value(std::forward<U>(v)) {}
  774. std::unique_ptr<any_storage> clone() const override {
  775. return std::unique_ptr<any_storage>(new any_value<T>(value));
  776. }
  777. any_type_id type_id() const noexcept override { return any_typeid<T>(); }
  778. };
  779. } // namespace detail
  780. class UserData {
  781. public:
  782. UserData() = default;
  783. UserData(UserData &&) noexcept = default;
  784. UserData &operator=(UserData &&) noexcept = default;
  785. UserData(const UserData &o) {
  786. for (const auto &e : o.entries_) {
  787. if (e.second) { entries_[e.first] = e.second->clone(); }
  788. }
  789. }
  790. UserData &operator=(const UserData &o) {
  791. if (this != &o) {
  792. entries_.clear();
  793. for (const auto &e : o.entries_) {
  794. if (e.second) { entries_[e.first] = e.second->clone(); }
  795. }
  796. }
  797. return *this;
  798. }
  799. template <typename T> void set(const std::string &key, T &&value) {
  800. using D = typename std::decay<T>::type;
  801. entries_[key].reset(new detail::any_value<D>(std::forward<T>(value)));
  802. }
  803. template <typename T> T *get(const std::string &key) noexcept {
  804. auto it = entries_.find(key);
  805. if (it == entries_.end() || !it->second) { return nullptr; }
  806. if (it->second->type_id() != detail::any_typeid<T>()) { return nullptr; }
  807. return &static_cast<detail::any_value<T> *>(it->second.get())->value;
  808. }
  809. template <typename T> const T *get(const std::string &key) const noexcept {
  810. auto it = entries_.find(key);
  811. if (it == entries_.end() || !it->second) { return nullptr; }
  812. if (it->second->type_id() != detail::any_typeid<T>()) { return nullptr; }
  813. return &static_cast<const detail::any_value<T> *>(it->second.get())->value;
  814. }
  815. bool has(const std::string &key) const noexcept {
  816. return entries_.find(key) != entries_.end();
  817. }
  818. void erase(const std::string &key) { entries_.erase(key); }
  819. void clear() noexcept { entries_.clear(); }
  820. private:
  821. std::unordered_map<std::string, std::unique_ptr<detail::any_storage>>
  822. entries_;
  823. };
  824. struct Response;
  825. using ResponseHandler = std::function<bool(const Response &response)>;
  826. struct FormData {
  827. std::string name;
  828. std::string content;
  829. std::string filename;
  830. std::string content_type;
  831. Headers headers;
  832. };
  833. struct FormField {
  834. std::string name;
  835. std::string content;
  836. Headers headers;
  837. };
  838. using FormFields = std::multimap<std::string, FormField>;
  839. using FormFiles = std::multimap<std::string, FormData>;
  840. struct MultipartFormData {
  841. FormFields fields; // Text fields from multipart
  842. FormFiles files; // Files from multipart
  843. // Text field access
  844. std::string get_field(const std::string &key, size_t id = 0) const;
  845. std::vector<std::string> get_fields(const std::string &key) const;
  846. bool has_field(const std::string &key) const;
  847. size_t get_field_count(const std::string &key) const;
  848. // File access
  849. FormData get_file(const std::string &key, size_t id = 0) const;
  850. std::vector<FormData> get_files(const std::string &key) const;
  851. bool has_file(const std::string &key) const;
  852. size_t get_file_count(const std::string &key) const;
  853. };
  854. struct UploadFormData {
  855. std::string name;
  856. std::string content;
  857. std::string filename;
  858. std::string content_type;
  859. };
  860. using UploadFormDataItems = std::vector<UploadFormData>;
  861. class DataSink {
  862. public:
  863. DataSink() : os(&sb_), sb_(*this) {}
  864. DataSink(const DataSink &) = delete;
  865. DataSink &operator=(const DataSink &) = delete;
  866. DataSink(DataSink &&) = delete;
  867. DataSink &operator=(DataSink &&) = delete;
  868. std::function<bool(const char *data, size_t data_len)> write;
  869. std::function<bool()> is_writable;
  870. std::function<void()> done;
  871. std::function<void(const Headers &trailer)> done_with_trailer;
  872. std::ostream os;
  873. private:
  874. class data_sink_streambuf final : public std::streambuf {
  875. public:
  876. explicit data_sink_streambuf(DataSink &sink) : sink_(sink) {}
  877. protected:
  878. std::streamsize xsputn(const char *s, std::streamsize n) override {
  879. if (sink_.write(s, static_cast<size_t>(n))) { return n; }
  880. return 0;
  881. }
  882. private:
  883. DataSink &sink_;
  884. };
  885. data_sink_streambuf sb_;
  886. };
  887. using ContentProvider =
  888. std::function<bool(size_t offset, size_t length, DataSink &sink)>;
  889. using ContentProviderWithoutLength =
  890. std::function<bool(size_t offset, DataSink &sink)>;
  891. using ContentProviderResourceReleaser = std::function<void(bool success)>;
  892. struct FormDataProvider {
  893. std::string name;
  894. ContentProviderWithoutLength provider;
  895. std::string filename;
  896. std::string content_type;
  897. };
  898. using FormDataProviderItems = std::vector<FormDataProvider>;
  899. inline FormDataProvider
  900. make_file_provider(const std::string &name, const std::string &filepath,
  901. const std::string &filename = std::string(),
  902. const std::string &content_type = std::string()) {
  903. FormDataProvider fdp;
  904. fdp.name = name;
  905. fdp.filename = filename.empty() ? filepath : filename;
  906. fdp.content_type = content_type;
  907. fdp.provider = [filepath](size_t offset, DataSink &sink) -> bool {
  908. std::ifstream f(filepath, std::ios::binary);
  909. if (!f) { return false; }
  910. if (offset > 0) {
  911. f.seekg(static_cast<std::streamoff>(offset));
  912. if (!f.good()) {
  913. sink.done();
  914. return true;
  915. }
  916. }
  917. char buf[8192];
  918. f.read(buf, sizeof(buf));
  919. auto n = static_cast<size_t>(f.gcount());
  920. if (n > 0) { return sink.write(buf, n); }
  921. sink.done(); // EOF
  922. return true;
  923. };
  924. return fdp;
  925. }
  926. inline std::pair<size_t, ContentProvider>
  927. make_file_body(const std::string &filepath) {
  928. size_t size = 0;
  929. {
  930. std::ifstream f(filepath, std::ios::binary | std::ios::ate);
  931. if (!f) { return {0, ContentProvider{}}; }
  932. size = static_cast<size_t>(f.tellg());
  933. }
  934. ContentProvider provider = [filepath](size_t offset, size_t length,
  935. DataSink &sink) -> bool {
  936. std::ifstream f(filepath, std::ios::binary);
  937. if (!f) { return false; }
  938. f.seekg(static_cast<std::streamoff>(offset));
  939. if (!f.good()) { return false; }
  940. char buf[8192];
  941. while (length > 0) {
  942. auto to_read = (std::min)(sizeof(buf), length);
  943. f.read(buf, static_cast<std::streamsize>(to_read));
  944. auto n = static_cast<size_t>(f.gcount());
  945. if (n == 0) { break; }
  946. if (!sink.write(buf, n)) { return false; }
  947. length -= n;
  948. }
  949. return true;
  950. };
  951. return {size, std::move(provider)};
  952. }
  953. using ContentReceiverWithProgress = std::function<bool(
  954. const char *data, size_t data_length, size_t offset, size_t total_length)>;
  955. using ContentReceiver =
  956. std::function<bool(const char *data, size_t data_length)>;
  957. using FormDataHeader = std::function<bool(const FormData &file)>;
  958. class ContentReader {
  959. public:
  960. using Reader = std::function<bool(ContentReceiver receiver)>;
  961. using FormDataReader =
  962. std::function<bool(FormDataHeader header, ContentReceiver receiver)>;
  963. ContentReader(Reader reader, FormDataReader multipart_reader)
  964. : reader_(std::move(reader)),
  965. formdata_reader_(std::move(multipart_reader)) {}
  966. bool operator()(FormDataHeader header, ContentReceiver receiver) const {
  967. return formdata_reader_(std::move(header), std::move(receiver));
  968. }
  969. bool operator()(ContentReceiver receiver) const {
  970. return reader_(std::move(receiver));
  971. }
  972. Reader reader_;
  973. FormDataReader formdata_reader_;
  974. };
  975. using Range = std::pair<ssize_t, ssize_t>;
  976. using Ranges = std::vector<Range>;
  977. #ifdef CPPHTTPLIB_SSL_ENABLED
  978. // TLS abstraction layer - public type definitions and API
  979. namespace tls {
  980. // Opaque handles (defined as void* for abstraction)
  981. using ctx_t = void *;
  982. using session_t = void *;
  983. using const_session_t = const void *; // For read-only session access
  984. using cert_t = void *;
  985. using ca_store_t = void *;
  986. // TLS versions
  987. enum class Version {
  988. TLS1_2 = 0x0303,
  989. TLS1_3 = 0x0304,
  990. };
  991. // Subject Alternative Names (SAN) entry types
  992. enum class SanType { DNS, IP, EMAIL, URI, OTHER };
  993. // SAN entry structure
  994. struct SanEntry {
  995. SanType type;
  996. std::string value;
  997. };
  998. // Verification context for certificate verification callback
  999. struct VerifyContext {
  1000. session_t session; // TLS session handle
  1001. cert_t cert; // Current certificate being verified
  1002. int depth; // Certificate chain depth (0 = leaf)
  1003. bool preverify_ok; // OpenSSL/Mbed TLS pre-verification result
  1004. long error_code; // Backend-specific error code (0 = no error)
  1005. const char *error_string; // Human-readable error description
  1006. // Certificate introspection methods
  1007. std::string subject_cn() const;
  1008. std::string issuer_name() const;
  1009. bool check_hostname(const char *hostname) const;
  1010. std::vector<SanEntry> sans() const;
  1011. bool validity(time_t &not_before, time_t &not_after) const;
  1012. std::string serial() const;
  1013. };
  1014. using VerifyCallback = std::function<bool(const VerifyContext &ctx)>;
  1015. // TlsError codes for TLS operations (backend-independent)
  1016. enum class ErrorCode : int {
  1017. Success = 0,
  1018. WantRead, // Non-blocking: need to wait for read
  1019. WantWrite, // Non-blocking: need to wait for write
  1020. PeerClosed, // Peer closed the connection
  1021. Fatal, // Unrecoverable error
  1022. SyscallError, // System call error (check sys_errno)
  1023. CertVerifyFailed, // Certificate verification failed
  1024. HostnameMismatch, // Hostname verification failed
  1025. };
  1026. // TLS error information
  1027. struct TlsError {
  1028. ErrorCode code = ErrorCode::Fatal;
  1029. uint64_t backend_code = 0; // OpenSSL: ERR_get_error(), mbedTLS: return value
  1030. int sys_errno = 0; // errno when SyscallError
  1031. // Convert verification error code to human-readable string
  1032. static std::string verify_error_to_string(long error_code);
  1033. };
  1034. // RAII wrapper for peer certificate
  1035. class PeerCert {
  1036. public:
  1037. PeerCert();
  1038. PeerCert(PeerCert &&other) noexcept;
  1039. PeerCert &operator=(PeerCert &&other) noexcept;
  1040. ~PeerCert();
  1041. PeerCert(const PeerCert &) = delete;
  1042. PeerCert &operator=(const PeerCert &) = delete;
  1043. explicit operator bool() const;
  1044. std::string subject_cn() const;
  1045. std::string issuer_name() const;
  1046. bool check_hostname(const char *hostname) const;
  1047. std::vector<SanEntry> sans() const;
  1048. bool validity(time_t &not_before, time_t &not_after) const;
  1049. std::string serial() const;
  1050. private:
  1051. explicit PeerCert(cert_t cert);
  1052. cert_t cert_ = nullptr;
  1053. friend PeerCert get_peer_cert_from_session(const_session_t session);
  1054. };
  1055. // Callback for TLS context setup (used by SSLServer constructor)
  1056. using ContextSetupCallback = std::function<bool(ctx_t ctx)>;
  1057. } // namespace tls
  1058. #endif
  1059. struct Request {
  1060. std::string method;
  1061. std::string path;
  1062. std::string matched_route;
  1063. Params params;
  1064. Headers headers;
  1065. Headers trailers;
  1066. std::string body;
  1067. std::string remote_addr;
  1068. int remote_port = -1;
  1069. std::string local_addr;
  1070. int local_port = -1;
  1071. // for server
  1072. std::string version;
  1073. std::string target;
  1074. MultipartFormData form;
  1075. Ranges ranges;
  1076. Match matches;
  1077. std::unordered_map<std::string, std::string> path_params;
  1078. std::function<bool()> is_connection_closed = []() { return true; };
  1079. // for client
  1080. std::vector<std::string> accept_content_types;
  1081. ResponseHandler response_handler;
  1082. ContentReceiverWithProgress content_receiver;
  1083. DownloadProgress download_progress;
  1084. UploadProgress upload_progress;
  1085. bool has_header(const std::string &key) const;
  1086. std::string get_header_value(const std::string &key, const char *def = "",
  1087. size_t id = 0) const;
  1088. size_t get_header_value_u64(const std::string &key, size_t def = 0,
  1089. size_t id = 0) const;
  1090. size_t get_header_value_count(const std::string &key) const;
  1091. void set_header(const std::string &key, const std::string &val);
  1092. bool has_trailer(const std::string &key) const;
  1093. std::string get_trailer_value(const std::string &key, size_t id = 0) const;
  1094. size_t get_trailer_value_count(const std::string &key) const;
  1095. bool has_param(const std::string &key) const;
  1096. std::string get_param_value(const std::string &key, size_t id = 0) const;
  1097. std::vector<std::string> get_param_values(const std::string &key) const;
  1098. size_t get_param_value_count(const std::string &key) const;
  1099. bool is_multipart_form_data() const;
  1100. // private members...
  1101. bool body_consumed_ = false;
  1102. size_t redirect_count_ = CPPHTTPLIB_REDIRECT_MAX_COUNT;
  1103. size_t content_length_ = 0;
  1104. ContentProvider content_provider_;
  1105. bool is_chunked_content_provider_ = false;
  1106. size_t authorization_count_ = 0;
  1107. std::chrono::time_point<std::chrono::steady_clock> start_time_ =
  1108. (std::chrono::steady_clock::time_point::min)();
  1109. #ifdef CPPHTTPLIB_SSL_ENABLED
  1110. tls::const_session_t ssl = nullptr;
  1111. tls::PeerCert peer_cert() const;
  1112. std::string sni() const;
  1113. #endif
  1114. };
  1115. struct Response {
  1116. std::string version;
  1117. int status = -1;
  1118. std::string reason;
  1119. Headers headers;
  1120. Headers trailers;
  1121. std::string body;
  1122. std::string location; // Redirect location
  1123. // User-defined context — set by pre-routing/pre-request handlers and read
  1124. // by route handlers to pass arbitrary data (e.g. decoded auth tokens).
  1125. UserData user_data;
  1126. bool has_header(const std::string &key) const;
  1127. std::string get_header_value(const std::string &key, const char *def = "",
  1128. size_t id = 0) const;
  1129. size_t get_header_value_u64(const std::string &key, size_t def = 0,
  1130. size_t id = 0) const;
  1131. size_t get_header_value_count(const std::string &key) const;
  1132. void set_header(const std::string &key, const std::string &val);
  1133. bool has_trailer(const std::string &key) const;
  1134. std::string get_trailer_value(const std::string &key, size_t id = 0) const;
  1135. size_t get_trailer_value_count(const std::string &key) const;
  1136. void set_redirect(const std::string &url, int status = StatusCode::Found_302);
  1137. void set_content(const char *s, size_t n, const std::string &content_type);
  1138. void set_content(const std::string &s, const std::string &content_type);
  1139. void set_content(std::string &&s, const std::string &content_type);
  1140. void set_content_provider(
  1141. size_t length, const std::string &content_type, ContentProvider provider,
  1142. ContentProviderResourceReleaser resource_releaser = nullptr);
  1143. void set_content_provider(
  1144. const std::string &content_type, ContentProviderWithoutLength provider,
  1145. ContentProviderResourceReleaser resource_releaser = nullptr);
  1146. void set_chunked_content_provider(
  1147. const std::string &content_type, ContentProviderWithoutLength provider,
  1148. ContentProviderResourceReleaser resource_releaser = nullptr);
  1149. void set_file_content(const std::string &path,
  1150. const std::string &content_type);
  1151. void set_file_content(const std::string &path);
  1152. Response() = default;
  1153. Response(const Response &) = default;
  1154. Response &operator=(const Response &) = default;
  1155. Response(Response &&) = default;
  1156. Response &operator=(Response &&) = default;
  1157. ~Response() {
  1158. if (content_provider_resource_releaser_) {
  1159. content_provider_resource_releaser_(content_provider_success_);
  1160. }
  1161. }
  1162. // private members...
  1163. size_t content_length_ = 0;
  1164. ContentProvider content_provider_;
  1165. ContentProviderResourceReleaser content_provider_resource_releaser_;
  1166. bool is_chunked_content_provider_ = false;
  1167. bool content_provider_success_ = false;
  1168. std::string file_content_path_;
  1169. std::string file_content_content_type_;
  1170. };
  1171. enum class Error {
  1172. Success = 0,
  1173. Unknown,
  1174. Connection,
  1175. BindIPAddress,
  1176. Read,
  1177. Write,
  1178. ExceedRedirectCount,
  1179. Canceled,
  1180. SSLConnection,
  1181. SSLLoadingCerts,
  1182. SSLServerVerification,
  1183. SSLServerHostnameVerification,
  1184. UnsupportedMultipartBoundaryChars,
  1185. Compression,
  1186. ConnectionTimeout,
  1187. ProxyConnection,
  1188. ConnectionClosed,
  1189. Timeout,
  1190. ResourceExhaustion,
  1191. TooManyFormDataFiles,
  1192. ExceedMaxPayloadSize,
  1193. ExceedUriMaxLength,
  1194. ExceedMaxSocketDescriptorCount,
  1195. InvalidRequestLine,
  1196. InvalidHTTPMethod,
  1197. InvalidHTTPVersion,
  1198. InvalidHeaders,
  1199. MultipartParsing,
  1200. OpenFile,
  1201. Listen,
  1202. GetSockName,
  1203. UnsupportedAddressFamily,
  1204. HTTPParsing,
  1205. InvalidRangeHeader,
  1206. // For internal use only
  1207. SSLPeerCouldBeClosed_,
  1208. };
  1209. std::string to_string(Error error);
  1210. std::ostream &operator<<(std::ostream &os, const Error &obj);
  1211. class Stream {
  1212. public:
  1213. virtual ~Stream() = default;
  1214. virtual bool is_readable() const = 0;
  1215. virtual bool wait_readable() const = 0;
  1216. virtual bool wait_writable() const = 0;
  1217. virtual bool is_peer_alive() const { return wait_writable(); }
  1218. virtual ssize_t read(char *ptr, size_t size) = 0;
  1219. virtual ssize_t write(const char *ptr, size_t size) = 0;
  1220. virtual void get_remote_ip_and_port(std::string &ip, int &port) const = 0;
  1221. virtual void get_local_ip_and_port(std::string &ip, int &port) const = 0;
  1222. virtual socket_t socket() const = 0;
  1223. virtual time_t duration() const = 0;
  1224. virtual void set_read_timeout(time_t sec, time_t usec = 0) {
  1225. (void)sec;
  1226. (void)usec;
  1227. }
  1228. ssize_t write(const char *ptr);
  1229. ssize_t write(const std::string &s);
  1230. Error get_error() const { return error_; }
  1231. protected:
  1232. Error error_ = Error::Success;
  1233. };
  1234. class TaskQueue {
  1235. public:
  1236. TaskQueue() = default;
  1237. virtual ~TaskQueue() = default;
  1238. virtual bool enqueue(std::function<void()> fn) = 0;
  1239. virtual void shutdown() = 0;
  1240. virtual void on_idle() {}
  1241. };
  1242. class ThreadPool final : public TaskQueue {
  1243. public:
  1244. explicit ThreadPool(size_t n, size_t max_n = 0, size_t mqr = 0);
  1245. ThreadPool(const ThreadPool &) = delete;
  1246. ~ThreadPool() override = default;
  1247. bool enqueue(std::function<void()> fn) override;
  1248. void shutdown() override;
  1249. private:
  1250. void worker(bool is_dynamic);
  1251. void move_to_finished(std::thread::id id);
  1252. void cleanup_finished_threads();
  1253. size_t base_thread_count_;
  1254. size_t max_thread_count_;
  1255. size_t max_queued_requests_;
  1256. size_t idle_thread_count_;
  1257. bool shutdown_;
  1258. std::list<std::function<void()>> jobs_;
  1259. std::vector<std::thread> threads_; // base threads
  1260. std::list<std::thread> dynamic_threads_; // dynamic threads
  1261. std::vector<std::thread>
  1262. finished_threads_; // exited dynamic threads awaiting join
  1263. std::condition_variable cond_;
  1264. std::mutex mutex_;
  1265. };
  1266. using Logger = std::function<void(const Request &, const Response &)>;
  1267. // Forward declaration for Error type
  1268. enum class Error;
  1269. using ErrorLogger = std::function<void(const Error &, const Request *)>;
  1270. using SocketOptions = std::function<void(socket_t sock)>;
  1271. void default_socket_options(socket_t sock);
  1272. bool set_socket_opt(socket_t sock, int level, int optname, int optval);
  1273. const char *status_message(int status);
  1274. std::string to_string(Error error);
  1275. std::ostream &operator<<(std::ostream &os, const Error &obj);
  1276. std::string get_bearer_token_auth(const Request &req);
  1277. namespace detail {
  1278. class MatcherBase {
  1279. public:
  1280. MatcherBase(std::string pattern) : pattern_(std::move(pattern)) {}
  1281. virtual ~MatcherBase() = default;
  1282. const std::string &pattern() const { return pattern_; }
  1283. // Match request path and populate its matches and
  1284. virtual bool match(Request &request) const = 0;
  1285. private:
  1286. std::string pattern_;
  1287. };
  1288. /**
  1289. * Captures parameters in request path and stores them in Request::path_params
  1290. *
  1291. * Capture name is a substring of a pattern from : to /.
  1292. * The rest of the pattern is matched against the request path directly
  1293. * Parameters are captured starting from the next character after
  1294. * the end of the last matched static pattern fragment until the next /.
  1295. *
  1296. * Example pattern:
  1297. * "/path/fragments/:capture/more/fragments/:second_capture"
  1298. * Static fragments:
  1299. * "/path/fragments/", "more/fragments/"
  1300. *
  1301. * Given the following request path:
  1302. * "/path/fragments/:1/more/fragments/:2"
  1303. * the resulting capture will be
  1304. * {{"capture", "1"}, {"second_capture", "2"}}
  1305. */
  1306. class PathParamsMatcher final : public MatcherBase {
  1307. public:
  1308. PathParamsMatcher(const std::string &pattern);
  1309. bool match(Request &request) const override;
  1310. private:
  1311. // Treat segment separators as the end of path parameter capture
  1312. // Does not need to handle query parameters as they are parsed before path
  1313. // matching
  1314. static constexpr char separator = '/';
  1315. // Contains static path fragments to match against, excluding the '/' after
  1316. // path params
  1317. // Fragments are separated by path params
  1318. std::vector<std::string> static_fragments_;
  1319. // Stores the names of the path parameters to be used as keys in the
  1320. // Request::path_params map
  1321. std::vector<std::string> param_names_;
  1322. };
  1323. /**
  1324. * Performs std::regex_match on request path
  1325. * and stores the result in Request::matches
  1326. *
  1327. * Note that regex match is performed directly on the whole request.
  1328. * This means that wildcard patterns may match multiple path segments with /:
  1329. * "/begin/(.*)/end" will match both "/begin/middle/end" and "/begin/1/2/end".
  1330. */
  1331. class RegexMatcher final : public MatcherBase {
  1332. public:
  1333. RegexMatcher(const std::string &pattern)
  1334. : MatcherBase(pattern), regex_(pattern) {}
  1335. bool match(Request &request) const override;
  1336. private:
  1337. std::regex regex_;
  1338. };
  1339. int close_socket(socket_t sock) noexcept;
  1340. ssize_t write_headers(Stream &strm, const Headers &headers);
  1341. bool set_socket_opt_time(socket_t sock, int level, int optname, time_t sec,
  1342. time_t usec);
  1343. size_t get_multipart_content_length(const UploadFormDataItems &items,
  1344. const std::string &boundary);
  1345. ContentProvider
  1346. make_multipart_content_provider(const UploadFormDataItems &items,
  1347. const std::string &boundary);
  1348. } // namespace detail
  1349. class Server {
  1350. public:
  1351. using Handler = std::function<void(const Request &, Response &)>;
  1352. using ExceptionHandler =
  1353. std::function<void(const Request &, Response &, std::exception_ptr ep)>;
  1354. enum class HandlerResponse {
  1355. Handled,
  1356. Unhandled,
  1357. };
  1358. using HandlerWithResponse =
  1359. std::function<HandlerResponse(const Request &, Response &)>;
  1360. using HandlerWithContentReader = std::function<void(
  1361. const Request &, Response &, const ContentReader &content_reader)>;
  1362. using Expect100ContinueHandler =
  1363. std::function<int(const Request &, Response &)>;
  1364. using StartHandler = std::function<void()>;
  1365. using WebSocketHandler =
  1366. std::function<void(const Request &, ws::WebSocket &)>;
  1367. using SubProtocolSelector =
  1368. std::function<std::string(const std::vector<std::string> &protocols)>;
  1369. Server();
  1370. virtual ~Server();
  1371. virtual bool is_valid() const;
  1372. Server &Get(const std::string &pattern, Handler handler);
  1373. Server &Post(const std::string &pattern, Handler handler);
  1374. Server &Post(const std::string &pattern, HandlerWithContentReader handler);
  1375. Server &Put(const std::string &pattern, Handler handler);
  1376. Server &Put(const std::string &pattern, HandlerWithContentReader handler);
  1377. Server &Patch(const std::string &pattern, Handler handler);
  1378. Server &Patch(const std::string &pattern, HandlerWithContentReader handler);
  1379. Server &Delete(const std::string &pattern, Handler handler);
  1380. Server &Delete(const std::string &pattern, HandlerWithContentReader handler);
  1381. Server &Options(const std::string &pattern, Handler handler);
  1382. Server &WebSocket(const std::string &pattern, WebSocketHandler handler);
  1383. Server &WebSocket(const std::string &pattern, WebSocketHandler handler,
  1384. SubProtocolSelector sub_protocol_selector);
  1385. bool set_base_dir(const std::string &dir,
  1386. const std::string &mount_point = std::string());
  1387. bool set_mount_point(const std::string &mount_point, const std::string &dir,
  1388. Headers headers = Headers());
  1389. bool remove_mount_point(const std::string &mount_point);
  1390. Server &set_file_extension_and_mimetype_mapping(const std::string &ext,
  1391. const std::string &mime);
  1392. Server &set_default_file_mimetype(const std::string &mime);
  1393. Server &set_file_request_handler(Handler handler);
  1394. template <class ErrorHandlerFunc>
  1395. Server &set_error_handler(ErrorHandlerFunc &&handler) {
  1396. return set_error_handler_core(
  1397. std::forward<ErrorHandlerFunc>(handler),
  1398. std::is_convertible<ErrorHandlerFunc, HandlerWithResponse>{});
  1399. }
  1400. Server &set_exception_handler(ExceptionHandler handler);
  1401. Server &set_pre_routing_handler(HandlerWithResponse handler);
  1402. Server &set_post_routing_handler(Handler handler);
  1403. Server &set_pre_request_handler(HandlerWithResponse handler);
  1404. Server &set_expect_100_continue_handler(Expect100ContinueHandler handler);
  1405. Server &set_start_handler(StartHandler handler);
  1406. Server &set_logger(Logger logger);
  1407. Server &set_pre_compression_logger(Logger logger);
  1408. Server &set_error_logger(ErrorLogger error_logger);
  1409. Server &set_address_family(int family);
  1410. Server &set_tcp_nodelay(bool on);
  1411. Server &set_ipv6_v6only(bool on);
  1412. Server &set_socket_options(SocketOptions socket_options);
  1413. Server &set_default_headers(Headers headers);
  1414. Server &
  1415. set_header_writer(std::function<ssize_t(Stream &, Headers &)> const &writer);
  1416. Server &set_trusted_proxies(const std::vector<std::string> &proxies);
  1417. Server &set_keep_alive_max_count(size_t count);
  1418. Server &set_keep_alive_timeout(time_t sec);
  1419. template <class Rep, class Period>
  1420. Server &
  1421. set_keep_alive_timeout(const std::chrono::duration<Rep, Period> &duration);
  1422. Server &set_read_timeout(time_t sec, time_t usec = 0);
  1423. template <class Rep, class Period>
  1424. Server &set_read_timeout(const std::chrono::duration<Rep, Period> &duration);
  1425. Server &set_write_timeout(time_t sec, time_t usec = 0);
  1426. template <class Rep, class Period>
  1427. Server &set_write_timeout(const std::chrono::duration<Rep, Period> &duration);
  1428. Server &set_idle_interval(time_t sec, time_t usec = 0);
  1429. template <class Rep, class Period>
  1430. Server &set_idle_interval(const std::chrono::duration<Rep, Period> &duration);
  1431. Server &set_payload_max_length(size_t length);
  1432. Server &set_websocket_ping_interval(time_t sec);
  1433. template <class Rep, class Period>
  1434. Server &set_websocket_ping_interval(
  1435. const std::chrono::duration<Rep, Period> &duration);
  1436. Server &set_websocket_max_missed_pongs(int count);
  1437. bool bind_to_port(const std::string &host, int port, int socket_flags = 0);
  1438. int bind_to_any_port(const std::string &host, int socket_flags = 0);
  1439. bool listen_after_bind();
  1440. bool listen(const std::string &host, int port, int socket_flags = 0);
  1441. bool is_running() const;
  1442. void wait_until_ready() const;
  1443. void stop() noexcept;
  1444. void decommission();
  1445. std::function<TaskQueue *(void)> new_task_queue;
  1446. protected:
  1447. bool process_request(Stream &strm, const std::string &remote_addr,
  1448. int remote_port, const std::string &local_addr,
  1449. int local_port, bool close_connection,
  1450. bool &connection_closed,
  1451. const std::function<void(Request &)> &setup_request,
  1452. bool *websocket_upgraded = nullptr);
  1453. std::atomic<socket_t> svr_sock_{INVALID_SOCKET};
  1454. std::vector<std::string> trusted_proxies_;
  1455. size_t keep_alive_max_count_ = CPPHTTPLIB_KEEPALIVE_MAX_COUNT;
  1456. time_t keep_alive_timeout_sec_ = CPPHTTPLIB_KEEPALIVE_TIMEOUT_SECOND;
  1457. time_t read_timeout_sec_ = CPPHTTPLIB_SERVER_READ_TIMEOUT_SECOND;
  1458. time_t read_timeout_usec_ = CPPHTTPLIB_SERVER_READ_TIMEOUT_USECOND;
  1459. time_t write_timeout_sec_ = CPPHTTPLIB_SERVER_WRITE_TIMEOUT_SECOND;
  1460. time_t write_timeout_usec_ = CPPHTTPLIB_SERVER_WRITE_TIMEOUT_USECOND;
  1461. time_t idle_interval_sec_ = CPPHTTPLIB_IDLE_INTERVAL_SECOND;
  1462. time_t idle_interval_usec_ = CPPHTTPLIB_IDLE_INTERVAL_USECOND;
  1463. size_t payload_max_length_ = CPPHTTPLIB_PAYLOAD_MAX_LENGTH;
  1464. time_t websocket_ping_interval_sec_ =
  1465. CPPHTTPLIB_WEBSOCKET_PING_INTERVAL_SECOND;
  1466. int websocket_max_missed_pongs_ = CPPHTTPLIB_WEBSOCKET_MAX_MISSED_PONGS;
  1467. private:
  1468. using Handlers =
  1469. std::vector<std::pair<std::unique_ptr<detail::MatcherBase>, Handler>>;
  1470. using HandlersForContentReader =
  1471. std::vector<std::pair<std::unique_ptr<detail::MatcherBase>,
  1472. HandlerWithContentReader>>;
  1473. static std::unique_ptr<detail::MatcherBase>
  1474. make_matcher(const std::string &pattern);
  1475. template <typename H>
  1476. Server &add_handler(
  1477. std::vector<std::pair<std::unique_ptr<detail::MatcherBase>, H>> &handlers,
  1478. const std::string &pattern, H handler) {
  1479. handlers.emplace_back(make_matcher(pattern), std::move(handler));
  1480. return *this;
  1481. }
  1482. Server &set_error_handler_core(HandlerWithResponse handler, std::true_type);
  1483. Server &set_error_handler_core(Handler handler, std::false_type);
  1484. socket_t create_server_socket(const std::string &host, int port,
  1485. int socket_flags,
  1486. SocketOptions socket_options) const;
  1487. int bind_internal(const std::string &host, int port, int socket_flags);
  1488. bool listen_internal();
  1489. bool routing(Request &req, Response &res, Stream &strm);
  1490. bool handle_file_request(Request &req, Response &res);
  1491. bool check_if_not_modified(const Request &req, Response &res,
  1492. const std::string &etag, time_t mtime) const;
  1493. bool check_if_range(Request &req, const std::string &etag,
  1494. time_t mtime) const;
  1495. bool dispatch_request(Request &req, Response &res, const Handlers &handlers,
  1496. Stream &strm);
  1497. bool dispatch_request_for_content_reader(
  1498. Request &req, Response &res, ContentReader content_reader,
  1499. const HandlersForContentReader &handlers) const;
  1500. bool parse_request_line(const char *s, Request &req) const;
  1501. void apply_ranges(const Request &req, Response &res,
  1502. std::string &content_type, std::string &boundary) const;
  1503. bool write_response(Stream &strm, bool close_connection, Request &req,
  1504. Response &res);
  1505. bool write_response_with_content(Stream &strm, bool close_connection,
  1506. const Request &req, Response &res);
  1507. bool write_response_core(Stream &strm, bool close_connection,
  1508. const Request &req, Response &res,
  1509. bool need_apply_ranges);
  1510. bool write_content_with_provider(Stream &strm, const Request &req,
  1511. Response &res, const std::string &boundary,
  1512. const std::string &content_type);
  1513. bool read_content(Stream &strm, Request &req, Response &res);
  1514. bool read_content_with_content_receiver(Stream &strm, Request &req,
  1515. Response &res,
  1516. ContentReceiver receiver,
  1517. FormDataHeader multipart_header,
  1518. ContentReceiver multipart_receiver);
  1519. bool read_content_core(Stream &strm, Request &req, Response &res,
  1520. ContentReceiver receiver,
  1521. FormDataHeader multipart_header,
  1522. ContentReceiver multipart_receiver) const;
  1523. virtual bool process_and_close_socket(socket_t sock);
  1524. void output_log(const Request &req, const Response &res) const;
  1525. void output_pre_compression_log(const Request &req,
  1526. const Response &res) const;
  1527. void output_error_log(const Error &err, const Request *req) const;
  1528. std::atomic<bool> is_running_{false};
  1529. std::atomic<bool> is_decommissioned{false};
  1530. struct MountPointEntry {
  1531. std::string mount_point;
  1532. std::string base_dir;
  1533. std::string resolved_base_dir;
  1534. Headers headers;
  1535. };
  1536. std::vector<MountPointEntry> base_dirs_;
  1537. std::map<std::string, std::string> file_extension_and_mimetype_map_;
  1538. std::string default_file_mimetype_ = "application/octet-stream";
  1539. Handler file_request_handler_;
  1540. Handlers get_handlers_;
  1541. Handlers post_handlers_;
  1542. HandlersForContentReader post_handlers_for_content_reader_;
  1543. Handlers put_handlers_;
  1544. HandlersForContentReader put_handlers_for_content_reader_;
  1545. Handlers patch_handlers_;
  1546. HandlersForContentReader patch_handlers_for_content_reader_;
  1547. Handlers delete_handlers_;
  1548. HandlersForContentReader delete_handlers_for_content_reader_;
  1549. Handlers options_handlers_;
  1550. struct WebSocketHandlerEntry {
  1551. std::unique_ptr<detail::MatcherBase> matcher;
  1552. WebSocketHandler handler;
  1553. SubProtocolSelector sub_protocol_selector;
  1554. };
  1555. using WebSocketHandlers = std::vector<WebSocketHandlerEntry>;
  1556. WebSocketHandlers websocket_handlers_;
  1557. HandlerWithResponse error_handler_;
  1558. ExceptionHandler exception_handler_;
  1559. HandlerWithResponse pre_routing_handler_;
  1560. Handler post_routing_handler_;
  1561. HandlerWithResponse pre_request_handler_;
  1562. Expect100ContinueHandler expect_100_continue_handler_;
  1563. StartHandler start_handler_;
  1564. mutable std::mutex logger_mutex_;
  1565. Logger logger_;
  1566. Logger pre_compression_logger_;
  1567. ErrorLogger error_logger_;
  1568. int address_family_ = AF_UNSPEC;
  1569. bool tcp_nodelay_ = CPPHTTPLIB_TCP_NODELAY;
  1570. bool ipv6_v6only_ = CPPHTTPLIB_IPV6_V6ONLY;
  1571. SocketOptions socket_options_ = default_socket_options;
  1572. Headers default_headers_;
  1573. std::function<ssize_t(Stream &, Headers &)> header_writer_ =
  1574. detail::write_headers;
  1575. };
  1576. class Result {
  1577. public:
  1578. Result() = default;
  1579. Result(std::unique_ptr<Response> &&res, Error err,
  1580. Headers &&request_headers = Headers{})
  1581. : res_(std::move(res)), err_(err),
  1582. request_headers_(std::move(request_headers)) {}
  1583. // Response
  1584. operator bool() const { return res_ != nullptr; }
  1585. bool operator==(std::nullptr_t) const { return res_ == nullptr; }
  1586. bool operator!=(std::nullptr_t) const { return res_ != nullptr; }
  1587. const Response &value() const { return *res_; }
  1588. Response &value() { return *res_; }
  1589. const Response &operator*() const { return *res_; }
  1590. Response &operator*() { return *res_; }
  1591. const Response *operator->() const { return res_.get(); }
  1592. Response *operator->() { return res_.get(); }
  1593. // Error
  1594. Error error() const { return err_; }
  1595. // Request Headers
  1596. bool has_request_header(const std::string &key) const;
  1597. std::string get_request_header_value(const std::string &key,
  1598. const char *def = "",
  1599. size_t id = 0) const;
  1600. size_t get_request_header_value_u64(const std::string &key, size_t def = 0,
  1601. size_t id = 0) const;
  1602. size_t get_request_header_value_count(const std::string &key) const;
  1603. private:
  1604. std::unique_ptr<Response> res_;
  1605. Error err_ = Error::Unknown;
  1606. Headers request_headers_;
  1607. #ifdef CPPHTTPLIB_SSL_ENABLED
  1608. public:
  1609. Result(std::unique_ptr<Response> &&res, Error err, Headers &&request_headers,
  1610. int ssl_error)
  1611. : res_(std::move(res)), err_(err),
  1612. request_headers_(std::move(request_headers)), ssl_error_(ssl_error) {}
  1613. Result(std::unique_ptr<Response> &&res, Error err, Headers &&request_headers,
  1614. int ssl_error, uint64_t ssl_backend_error)
  1615. : res_(std::move(res)), err_(err),
  1616. request_headers_(std::move(request_headers)), ssl_error_(ssl_error),
  1617. ssl_backend_error_(ssl_backend_error) {}
  1618. int ssl_error() const { return ssl_error_; }
  1619. uint64_t ssl_backend_error() const { return ssl_backend_error_; }
  1620. private:
  1621. int ssl_error_ = 0;
  1622. uint64_t ssl_backend_error_ = 0;
  1623. #endif
  1624. };
  1625. struct ClientConnection {
  1626. socket_t sock = INVALID_SOCKET;
  1627. bool is_open() const { return sock != INVALID_SOCKET; }
  1628. ClientConnection() = default;
  1629. ~ClientConnection();
  1630. ClientConnection(const ClientConnection &) = delete;
  1631. ClientConnection &operator=(const ClientConnection &) = delete;
  1632. ClientConnection(ClientConnection &&other) noexcept
  1633. : sock(other.sock)
  1634. #ifdef CPPHTTPLIB_SSL_ENABLED
  1635. ,
  1636. session(other.session)
  1637. #endif
  1638. {
  1639. other.sock = INVALID_SOCKET;
  1640. #ifdef CPPHTTPLIB_SSL_ENABLED
  1641. other.session = nullptr;
  1642. #endif
  1643. }
  1644. ClientConnection &operator=(ClientConnection &&other) noexcept {
  1645. if (this != &other) {
  1646. sock = other.sock;
  1647. other.sock = INVALID_SOCKET;
  1648. #ifdef CPPHTTPLIB_SSL_ENABLED
  1649. session = other.session;
  1650. other.session = nullptr;
  1651. #endif
  1652. }
  1653. return *this;
  1654. }
  1655. #ifdef CPPHTTPLIB_SSL_ENABLED
  1656. tls::session_t session = nullptr;
  1657. #endif
  1658. };
  1659. namespace detail {
  1660. struct ChunkedDecoder;
  1661. struct BodyReader {
  1662. Stream *stream = nullptr;
  1663. bool has_content_length = false;
  1664. size_t content_length = 0;
  1665. size_t payload_max_length = CPPHTTPLIB_PAYLOAD_MAX_LENGTH;
  1666. size_t bytes_read = 0;
  1667. bool chunked = false;
  1668. bool eof = false;
  1669. std::unique_ptr<ChunkedDecoder> chunked_decoder;
  1670. Error last_error = Error::Success;
  1671. ssize_t read(char *buf, size_t len);
  1672. bool has_error() const { return last_error != Error::Success; }
  1673. };
  1674. inline ssize_t read_body_content(Stream *stream, BodyReader &br, char *buf,
  1675. size_t len) {
  1676. (void)stream;
  1677. return br.read(buf, len);
  1678. }
  1679. class decompressor;
  1680. enum class NoProxyKind {
  1681. Wildcard, // "*"
  1682. HostnameSuffix, // "example.com" or ".example.com"
  1683. IPv4Cidr, // "10.0.0.0/8" (or single IP, treated as /32)
  1684. IPv6Cidr, // "fe80::/10" (or single IP, treated as /128)
  1685. };
  1686. // Unified 16-byte buffer holding either a v4 (first 4 bytes) or v6 address.
  1687. // Lets one CIDR matcher cover both families.
  1688. using IPBytes = std::array<uint8_t, 16>;
  1689. struct NoProxyEntry {
  1690. NoProxyKind kind = NoProxyKind::Wildcard;
  1691. std::string hostname_pattern; // lowercased, leading/trailing dot stripped
  1692. IPBytes net{};
  1693. int prefix_bits = 0;
  1694. };
  1695. struct NormalizedTarget {
  1696. std::string hostname; // lowercase; brackets and trailing dot removed
  1697. bool is_ipv4 = false;
  1698. bool is_ipv6 = false;
  1699. IPBytes ip{};
  1700. };
  1701. } // namespace detail
  1702. class ClientImpl {
  1703. public:
  1704. explicit ClientImpl(const std::string &host);
  1705. explicit ClientImpl(const std::string &host, int port);
  1706. explicit ClientImpl(const std::string &host, int port,
  1707. const std::string &client_cert_path,
  1708. const std::string &client_key_path);
  1709. virtual ~ClientImpl();
  1710. virtual bool is_valid() const;
  1711. struct StreamHandle {
  1712. std::unique_ptr<Response> response;
  1713. Error error = Error::Success;
  1714. StreamHandle() = default;
  1715. StreamHandle(const StreamHandle &) = delete;
  1716. StreamHandle &operator=(const StreamHandle &) = delete;
  1717. StreamHandle(StreamHandle &&) = default;
  1718. StreamHandle &operator=(StreamHandle &&) = default;
  1719. ~StreamHandle() = default;
  1720. bool is_valid() const {
  1721. return response != nullptr && error == Error::Success;
  1722. }
  1723. ssize_t read(char *buf, size_t len);
  1724. void parse_trailers_if_needed();
  1725. Error get_read_error() const { return body_reader_.last_error; }
  1726. bool has_read_error() const { return body_reader_.has_error(); }
  1727. bool trailers_parsed_ = false;
  1728. private:
  1729. friend class ClientImpl;
  1730. ssize_t read_with_decompression(char *buf, size_t len);
  1731. std::unique_ptr<ClientConnection> connection_;
  1732. std::unique_ptr<Stream> socket_stream_;
  1733. Stream *stream_ = nullptr;
  1734. detail::BodyReader body_reader_;
  1735. std::unique_ptr<detail::decompressor> decompressor_;
  1736. std::string decompress_buffer_;
  1737. size_t decompress_offset_ = 0;
  1738. size_t decompressed_bytes_read_ = 0;
  1739. };
  1740. // clang-format off
  1741. Result Get(const std::string &path, DownloadProgress progress = nullptr);
  1742. Result Get(const std::string &path, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1743. Result Get(const std::string &path, ResponseHandler response_handler, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1744. Result Get(const std::string &path, const Headers &headers, DownloadProgress progress = nullptr);
  1745. Result Get(const std::string &path, const Headers &headers, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1746. Result Get(const std::string &path, const Headers &headers, ResponseHandler response_handler, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1747. Result Get(const std::string &path, const Params &params, const Headers &headers, DownloadProgress progress = nullptr);
  1748. Result Get(const std::string &path, const Params &params, const Headers &headers, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1749. Result Get(const std::string &path, const Params &params, const Headers &headers, ResponseHandler response_handler, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1750. Result Head(const std::string &path);
  1751. Result Head(const std::string &path, const Headers &headers);
  1752. Result Post(const std::string &path);
  1753. Result Post(const std::string &path, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  1754. Result Post(const std::string &path, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  1755. Result Post(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1756. Result Post(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1757. Result Post(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1758. Result Post(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1759. Result Post(const std::string &path, const Params &params);
  1760. Result Post(const std::string &path, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  1761. Result Post(const std::string &path, const Headers &headers);
  1762. Result Post(const std::string &path, const Headers &headers, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  1763. Result Post(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  1764. Result Post(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1765. Result Post(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1766. Result Post(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1767. Result Post(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1768. Result Post(const std::string &path, const Headers &headers, const Params &params);
  1769. Result Post(const std::string &path, const Headers &headers, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  1770. Result Post(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const std::string &boundary, UploadProgress progress = nullptr);
  1771. Result Post(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const FormDataProviderItems &provider_items, UploadProgress progress = nullptr);
  1772. Result Post(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1773. Result Put(const std::string &path);
  1774. Result Put(const std::string &path, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  1775. Result Put(const std::string &path, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  1776. Result Put(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1777. Result Put(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1778. Result Put(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1779. Result Put(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1780. Result Put(const std::string &path, const Params &params);
  1781. Result Put(const std::string &path, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  1782. Result Put(const std::string &path, const Headers &headers);
  1783. Result Put(const std::string &path, const Headers &headers, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  1784. Result Put(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  1785. Result Put(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1786. Result Put(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1787. Result Put(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1788. Result Put(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1789. Result Put(const std::string &path, const Headers &headers, const Params &params);
  1790. Result Put(const std::string &path, const Headers &headers, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  1791. Result Put(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const std::string &boundary, UploadProgress progress = nullptr);
  1792. Result Put(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const FormDataProviderItems &provider_items, UploadProgress progress = nullptr);
  1793. Result Put(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1794. Result Patch(const std::string &path);
  1795. Result Patch(const std::string &path, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  1796. Result Patch(const std::string &path, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  1797. Result Patch(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1798. Result Patch(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1799. Result Patch(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1800. Result Patch(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1801. Result Patch(const std::string &path, const Params &params);
  1802. Result Patch(const std::string &path, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  1803. Result Patch(const std::string &path, const Headers &headers, UploadProgress progress = nullptr);
  1804. Result Patch(const std::string &path, const Headers &headers, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  1805. Result Patch(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  1806. Result Patch(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1807. Result Patch(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1808. Result Patch(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  1809. Result Patch(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  1810. Result Patch(const std::string &path, const Headers &headers, const Params &params);
  1811. Result Patch(const std::string &path, const Headers &headers, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  1812. Result Patch(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const std::string &boundary, UploadProgress progress = nullptr);
  1813. Result Patch(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const FormDataProviderItems &provider_items, UploadProgress progress = nullptr);
  1814. Result Patch(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  1815. Result Delete(const std::string &path, DownloadProgress progress = nullptr);
  1816. Result Delete(const std::string &path, const char *body, size_t content_length, const std::string &content_type, DownloadProgress progress = nullptr);
  1817. Result Delete(const std::string &path, const std::string &body, const std::string &content_type, DownloadProgress progress = nullptr);
  1818. Result Delete(const std::string &path, const Params &params, DownloadProgress progress = nullptr);
  1819. Result Delete(const std::string &path, const Headers &headers, DownloadProgress progress = nullptr);
  1820. Result Delete(const std::string &path, const Headers &headers, const char *body, size_t content_length, const std::string &content_type, DownloadProgress progress = nullptr);
  1821. Result Delete(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, DownloadProgress progress = nullptr);
  1822. Result Delete(const std::string &path, const Headers &headers, const Params &params, DownloadProgress progress = nullptr);
  1823. Result Options(const std::string &path);
  1824. Result Options(const std::string &path, const Headers &headers);
  1825. // clang-format on
  1826. // Streaming API: Open a stream for reading response body incrementally
  1827. // Socket ownership is transferred to StreamHandle for true streaming
  1828. // Supports all HTTP methods (GET, POST, PUT, PATCH, DELETE, etc.)
  1829. StreamHandle open_stream(const std::string &method, const std::string &path,
  1830. const Params &params = {},
  1831. const Headers &headers = {},
  1832. const std::string &body = {},
  1833. const std::string &content_type = {});
  1834. bool send(Request &req, Response &res, Error &error);
  1835. Result send(const Request &req);
  1836. void stop();
  1837. std::string host() const;
  1838. int port() const;
  1839. size_t is_socket_open() const;
  1840. socket_t socket() const;
  1841. void set_hostname_addr_map(std::map<std::string, std::string> addr_map);
  1842. void set_default_headers(Headers headers);
  1843. void
  1844. set_header_writer(std::function<ssize_t(Stream &, Headers &)> const &writer);
  1845. void set_address_family(int family);
  1846. void set_tcp_nodelay(bool on);
  1847. void set_ipv6_v6only(bool on);
  1848. void set_socket_options(SocketOptions socket_options);
  1849. void set_connection_timeout(time_t sec, time_t usec = 0);
  1850. template <class Rep, class Period>
  1851. void
  1852. set_connection_timeout(const std::chrono::duration<Rep, Period> &duration);
  1853. void set_read_timeout(time_t sec, time_t usec = 0);
  1854. template <class Rep, class Period>
  1855. void set_read_timeout(const std::chrono::duration<Rep, Period> &duration);
  1856. void set_write_timeout(time_t sec, time_t usec = 0);
  1857. template <class Rep, class Period>
  1858. void set_write_timeout(const std::chrono::duration<Rep, Period> &duration);
  1859. void set_max_timeout(time_t msec);
  1860. template <class Rep, class Period>
  1861. void set_max_timeout(const std::chrono::duration<Rep, Period> &duration);
  1862. void set_basic_auth(const std::string &username, const std::string &password);
  1863. void set_bearer_token_auth(const std::string &token);
  1864. void set_keep_alive(bool on);
  1865. void set_follow_location(bool on);
  1866. void set_path_encode(bool on);
  1867. void set_compress(bool on);
  1868. void set_decompress(bool on);
  1869. void set_payload_max_length(size_t length);
  1870. void set_interface(const std::string &intf);
  1871. void set_proxy(const std::string &host, int port);
  1872. void set_proxy_basic_auth(const std::string &username,
  1873. const std::string &password);
  1874. void set_proxy_bearer_token_auth(const std::string &token);
  1875. void set_no_proxy(const std::vector<std::string> &patterns);
  1876. void set_logger(Logger logger);
  1877. void set_error_logger(ErrorLogger error_logger);
  1878. protected:
  1879. struct Socket {
  1880. socket_t sock = INVALID_SOCKET;
  1881. // For Mbed TLS compatibility: start_time for request timeout tracking
  1882. std::chrono::time_point<std::chrono::steady_clock> start_time_;
  1883. bool is_open() const { return sock != INVALID_SOCKET; }
  1884. #ifdef CPPHTTPLIB_SSL_ENABLED
  1885. tls::session_t ssl = nullptr;
  1886. #endif
  1887. };
  1888. virtual bool create_and_connect_socket(Socket &socket, Error &error);
  1889. virtual bool ensure_socket_connection(Socket &socket, Error &error);
  1890. virtual bool setup_proxy_connection(
  1891. Socket &socket,
  1892. std::chrono::time_point<std::chrono::steady_clock> start_time,
  1893. Response &res, bool &success, Error &error);
  1894. bool is_proxy_enabled_for_host(const std::string &host) const;
  1895. // All of:
  1896. // shutdown_ssl
  1897. // shutdown_socket
  1898. // close_socket
  1899. // disconnect
  1900. // should ONLY be called when socket_mutex_ is locked, and only when
  1901. // no other thread is using the socket.
  1902. virtual void shutdown_ssl(Socket &socket, bool shutdown_gracefully);
  1903. void shutdown_socket(Socket &socket) const;
  1904. void close_socket(Socket &socket);
  1905. void disconnect(bool gracefully);
  1906. bool process_request(Stream &strm, Request &req, Response &res,
  1907. bool close_connection, Error &error);
  1908. bool write_content_with_provider(Stream &strm, const Request &req,
  1909. Error &error) const;
  1910. void copy_settings(const ClientImpl &rhs);
  1911. void output_log(const Request &req, const Response &res) const;
  1912. void output_error_log(const Error &err, const Request *req) const;
  1913. // Socket endpoint information
  1914. const std::string host_;
  1915. const int port_;
  1916. // Current open socket
  1917. Socket socket_;
  1918. mutable std::mutex socket_mutex_;
  1919. std::recursive_mutex request_mutex_;
  1920. // These are all protected under socket_mutex
  1921. size_t socket_requests_in_flight_ = 0;
  1922. std::thread::id socket_requests_are_from_thread_ = std::thread::id();
  1923. bool socket_should_be_closed_when_request_is_done_ = false;
  1924. // Hostname-IP map
  1925. std::map<std::string, std::string> addr_map_;
  1926. // Default headers
  1927. Headers default_headers_;
  1928. // Header writer
  1929. std::function<ssize_t(Stream &, Headers &)> header_writer_ =
  1930. detail::write_headers;
  1931. // Settings
  1932. std::string client_cert_path_;
  1933. std::string client_key_path_;
  1934. time_t connection_timeout_sec_ = CPPHTTPLIB_CONNECTION_TIMEOUT_SECOND;
  1935. time_t connection_timeout_usec_ = CPPHTTPLIB_CONNECTION_TIMEOUT_USECOND;
  1936. time_t read_timeout_sec_ = CPPHTTPLIB_CLIENT_READ_TIMEOUT_SECOND;
  1937. time_t read_timeout_usec_ = CPPHTTPLIB_CLIENT_READ_TIMEOUT_USECOND;
  1938. time_t write_timeout_sec_ = CPPHTTPLIB_CLIENT_WRITE_TIMEOUT_SECOND;
  1939. time_t write_timeout_usec_ = CPPHTTPLIB_CLIENT_WRITE_TIMEOUT_USECOND;
  1940. time_t max_timeout_msec_ = CPPHTTPLIB_CLIENT_MAX_TIMEOUT_MSECOND;
  1941. std::string basic_auth_username_;
  1942. std::string basic_auth_password_;
  1943. std::string bearer_token_auth_token_;
  1944. bool keep_alive_ = false;
  1945. bool follow_location_ = false;
  1946. bool path_encode_ = true;
  1947. int address_family_ = AF_UNSPEC;
  1948. bool tcp_nodelay_ = CPPHTTPLIB_TCP_NODELAY;
  1949. bool ipv6_v6only_ = CPPHTTPLIB_IPV6_V6ONLY;
  1950. SocketOptions socket_options_ = nullptr;
  1951. bool compress_ = false;
  1952. bool decompress_ = true;
  1953. size_t payload_max_length_ = CPPHTTPLIB_PAYLOAD_MAX_LENGTH;
  1954. bool has_payload_max_length_ = false;
  1955. std::string interface_;
  1956. std::string proxy_host_;
  1957. int proxy_port_ = -1;
  1958. std::string proxy_basic_auth_username_;
  1959. std::string proxy_basic_auth_password_;
  1960. std::string proxy_bearer_token_auth_token_;
  1961. std::vector<detail::NoProxyEntry> no_proxy_entries_;
  1962. mutable detail::NormalizedTarget host_normalized_;
  1963. mutable bool host_normalized_valid_ = false;
  1964. mutable std::mutex logger_mutex_;
  1965. Logger logger_;
  1966. ErrorLogger error_logger_;
  1967. private:
  1968. bool send_(Request &req, Response &res, Error &error);
  1969. Result send_(Request &&req);
  1970. socket_t create_client_socket(Error &error) const;
  1971. bool read_response_line(Stream &strm, const Request &req, Response &res,
  1972. bool skip_100_continue = true) const;
  1973. bool write_request(Stream &strm, Request &req, bool close_connection,
  1974. Error &error, bool skip_body = false);
  1975. bool write_request_body(Stream &strm, Request &req, Error &error);
  1976. void prepare_default_headers(Request &r, bool for_stream,
  1977. const std::string &ct);
  1978. bool redirect(Request &req, Response &res, Error &error);
  1979. bool create_redirect_client(const std::string &scheme,
  1980. const std::string &host, int port, Request &req,
  1981. Response &res, const std::string &path,
  1982. const std::string &location, Error &error);
  1983. template <typename ClientType> void setup_redirect_client(ClientType &client);
  1984. bool handle_request(Stream &strm, Request &req, Response &res,
  1985. bool close_connection, Error &error);
  1986. std::unique_ptr<Response> send_with_content_provider_and_receiver(
  1987. Request &req, const char *body, size_t content_length,
  1988. ContentProvider content_provider,
  1989. ContentProviderWithoutLength content_provider_without_length,
  1990. const std::string &content_type, ContentReceiver content_receiver,
  1991. Error &error);
  1992. Result send_with_content_provider_and_receiver(
  1993. const std::string &method, const std::string &path,
  1994. const Headers &headers, const char *body, size_t content_length,
  1995. ContentProvider content_provider,
  1996. ContentProviderWithoutLength content_provider_without_length,
  1997. const std::string &content_type, ContentReceiver content_receiver,
  1998. UploadProgress progress);
  1999. ContentProviderWithoutLength get_multipart_content_provider(
  2000. const std::string &boundary, const UploadFormDataItems &items,
  2001. const FormDataProviderItems &provider_items) const;
  2002. virtual bool
  2003. process_socket(const Socket &socket,
  2004. std::chrono::time_point<std::chrono::steady_clock> start_time,
  2005. std::function<bool(Stream &strm)> callback);
  2006. virtual bool is_ssl() const;
  2007. void transfer_socket_ownership_to_handle(StreamHandle &handle);
  2008. #ifdef CPPHTTPLIB_SSL_ENABLED
  2009. public:
  2010. void set_digest_auth(const std::string &username,
  2011. const std::string &password);
  2012. void set_proxy_digest_auth(const std::string &username,
  2013. const std::string &password);
  2014. void set_ca_cert_path(const std::string &ca_cert_file_path,
  2015. const std::string &ca_cert_dir_path = std::string());
  2016. void enable_server_certificate_verification(bool enabled);
  2017. void enable_server_hostname_verification(bool enabled);
  2018. void enable_system_ca(bool enabled);
  2019. protected:
  2020. std::string digest_auth_username_;
  2021. std::string digest_auth_password_;
  2022. std::string proxy_digest_auth_username_;
  2023. std::string proxy_digest_auth_password_;
  2024. std::string ca_cert_file_path_;
  2025. std::string ca_cert_dir_path_;
  2026. bool server_certificate_verification_ = true;
  2027. bool server_hostname_verification_ = true;
  2028. SystemCAMode system_ca_mode_ = SystemCAMode::Auto;
  2029. std::string ca_cert_pem_; // Store CA cert PEM for redirect transfer
  2030. int last_ssl_error_ = 0;
  2031. uint64_t last_backend_error_ = 0;
  2032. #endif
  2033. };
  2034. class Client {
  2035. public:
  2036. // Universal interface
  2037. explicit Client(const std::string &scheme_host_port);
  2038. explicit Client(const std::string &scheme_host_port,
  2039. const std::string &client_cert_path,
  2040. const std::string &client_key_path);
  2041. // HTTP only interface
  2042. explicit Client(const std::string &host, int port);
  2043. explicit Client(const std::string &host, int port,
  2044. const std::string &client_cert_path,
  2045. const std::string &client_key_path);
  2046. Client(Client &&) = default;
  2047. Client &operator=(Client &&) = default;
  2048. ~Client();
  2049. bool is_valid() const;
  2050. // clang-format off
  2051. Result Get(const std::string &path, DownloadProgress progress = nullptr);
  2052. Result Get(const std::string &path, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2053. Result Get(const std::string &path, ResponseHandler response_handler, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2054. Result Get(const std::string &path, const Headers &headers, DownloadProgress progress = nullptr);
  2055. Result Get(const std::string &path, const Headers &headers, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2056. Result Get(const std::string &path, const Headers &headers, ResponseHandler response_handler, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2057. Result Get(const std::string &path, const Params &params, const Headers &headers, DownloadProgress progress = nullptr);
  2058. Result Get(const std::string &path, const Params &params, const Headers &headers, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2059. Result Get(const std::string &path, const Params &params, const Headers &headers, ResponseHandler response_handler, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2060. Result Head(const std::string &path);
  2061. Result Head(const std::string &path, const Headers &headers);
  2062. Result Post(const std::string &path);
  2063. Result Post(const std::string &path, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  2064. Result Post(const std::string &path, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  2065. Result Post(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2066. Result Post(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2067. Result Post(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2068. Result Post(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2069. Result Post(const std::string &path, const Params &params);
  2070. Result Post(const std::string &path, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  2071. Result Post(const std::string &path, const Headers &headers);
  2072. Result Post(const std::string &path, const Headers &headers, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  2073. Result Post(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  2074. Result Post(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2075. Result Post(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2076. Result Post(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2077. Result Post(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2078. Result Post(const std::string &path, const Headers &headers, const Params &params);
  2079. Result Post(const std::string &path, const Headers &headers, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  2080. Result Post(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const std::string &boundary, UploadProgress progress = nullptr);
  2081. Result Post(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const FormDataProviderItems &provider_items, UploadProgress progress = nullptr);
  2082. Result Post(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2083. Result Put(const std::string &path);
  2084. Result Put(const std::string &path, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  2085. Result Put(const std::string &path, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  2086. Result Put(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2087. Result Put(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2088. Result Put(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2089. Result Put(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2090. Result Put(const std::string &path, const Params &params);
  2091. Result Put(const std::string &path, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  2092. Result Put(const std::string &path, const Headers &headers);
  2093. Result Put(const std::string &path, const Headers &headers, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  2094. Result Put(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  2095. Result Put(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2096. Result Put(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2097. Result Put(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2098. Result Put(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2099. Result Put(const std::string &path, const Headers &headers, const Params &params);
  2100. Result Put(const std::string &path, const Headers &headers, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  2101. Result Put(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const std::string &boundary, UploadProgress progress = nullptr);
  2102. Result Put(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const FormDataProviderItems &provider_items, UploadProgress progress = nullptr);
  2103. Result Put(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2104. Result Patch(const std::string &path);
  2105. Result Patch(const std::string &path, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  2106. Result Patch(const std::string &path, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  2107. Result Patch(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2108. Result Patch(const std::string &path, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2109. Result Patch(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2110. Result Patch(const std::string &path, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2111. Result Patch(const std::string &path, const Params &params);
  2112. Result Patch(const std::string &path, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  2113. Result Patch(const std::string &path, const Headers &headers);
  2114. Result Patch(const std::string &path, const Headers &headers, const char *body, size_t content_length, const std::string &content_type, UploadProgress progress = nullptr);
  2115. Result Patch(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, UploadProgress progress = nullptr);
  2116. Result Patch(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2117. Result Patch(const std::string &path, const Headers &headers, size_t content_length, ContentProvider content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2118. Result Patch(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, UploadProgress progress = nullptr);
  2119. Result Patch(const std::string &path, const Headers &headers, ContentProviderWithoutLength content_provider, const std::string &content_type, ContentReceiver content_receiver, UploadProgress progress = nullptr);
  2120. Result Patch(const std::string &path, const Headers &headers, const Params &params);
  2121. Result Patch(const std::string &path, const Headers &headers, const UploadFormDataItems &items, UploadProgress progress = nullptr);
  2122. Result Patch(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const std::string &boundary, UploadProgress progress = nullptr);
  2123. Result Patch(const std::string &path, const Headers &headers, const UploadFormDataItems &items, const FormDataProviderItems &provider_items, UploadProgress progress = nullptr);
  2124. Result Patch(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, ContentReceiver content_receiver, DownloadProgress progress = nullptr);
  2125. Result Delete(const std::string &path, DownloadProgress progress = nullptr);
  2126. Result Delete(const std::string &path, const char *body, size_t content_length, const std::string &content_type, DownloadProgress progress = nullptr);
  2127. Result Delete(const std::string &path, const std::string &body, const std::string &content_type, DownloadProgress progress = nullptr);
  2128. Result Delete(const std::string &path, const Params &params, DownloadProgress progress = nullptr);
  2129. Result Delete(const std::string &path, const Headers &headers, DownloadProgress progress = nullptr);
  2130. Result Delete(const std::string &path, const Headers &headers, const char *body, size_t content_length, const std::string &content_type, DownloadProgress progress = nullptr);
  2131. Result Delete(const std::string &path, const Headers &headers, const std::string &body, const std::string &content_type, DownloadProgress progress = nullptr);
  2132. Result Delete(const std::string &path, const Headers &headers, const Params &params, DownloadProgress progress = nullptr);
  2133. Result Options(const std::string &path);
  2134. Result Options(const std::string &path, const Headers &headers);
  2135. // clang-format on
  2136. // Streaming API: Open a stream for reading response body incrementally
  2137. // Socket ownership is transferred to StreamHandle for true streaming
  2138. // Supports all HTTP methods (GET, POST, PUT, PATCH, DELETE, etc.)
  2139. ClientImpl::StreamHandle open_stream(const std::string &method,
  2140. const std::string &path,
  2141. const Params &params = {},
  2142. const Headers &headers = {},
  2143. const std::string &body = {},
  2144. const std::string &content_type = {});
  2145. bool send(Request &req, Response &res, Error &error);
  2146. Result send(const Request &req);
  2147. void stop();
  2148. std::string host() const;
  2149. int port() const;
  2150. size_t is_socket_open() const;
  2151. socket_t socket() const;
  2152. void set_hostname_addr_map(std::map<std::string, std::string> addr_map);
  2153. void set_default_headers(Headers headers);
  2154. void
  2155. set_header_writer(std::function<ssize_t(Stream &, Headers &)> const &writer);
  2156. void set_address_family(int family);
  2157. void set_tcp_nodelay(bool on);
  2158. void set_socket_options(SocketOptions socket_options);
  2159. void set_connection_timeout(time_t sec, time_t usec = 0);
  2160. template <class Rep, class Period>
  2161. void
  2162. set_connection_timeout(const std::chrono::duration<Rep, Period> &duration);
  2163. void set_read_timeout(time_t sec, time_t usec = 0);
  2164. template <class Rep, class Period>
  2165. void set_read_timeout(const std::chrono::duration<Rep, Period> &duration);
  2166. void set_write_timeout(time_t sec, time_t usec = 0);
  2167. template <class Rep, class Period>
  2168. void set_write_timeout(const std::chrono::duration<Rep, Period> &duration);
  2169. void set_max_timeout(time_t msec);
  2170. template <class Rep, class Period>
  2171. void set_max_timeout(const std::chrono::duration<Rep, Period> &duration);
  2172. void set_basic_auth(const std::string &username, const std::string &password);
  2173. void set_bearer_token_auth(const std::string &token);
  2174. void set_keep_alive(bool on);
  2175. void set_follow_location(bool on);
  2176. void set_path_encode(bool on);
  2177. void set_compress(bool on);
  2178. void set_decompress(bool on);
  2179. void set_payload_max_length(size_t length);
  2180. void set_interface(const std::string &intf);
  2181. void set_proxy(const std::string &host, int port);
  2182. void set_proxy_basic_auth(const std::string &username,
  2183. const std::string &password);
  2184. void set_proxy_bearer_token_auth(const std::string &token);
  2185. void set_no_proxy(const std::vector<std::string> &patterns);
  2186. void set_logger(Logger logger);
  2187. void set_error_logger(ErrorLogger error_logger);
  2188. private:
  2189. std::unique_ptr<ClientImpl> cli_;
  2190. #ifdef CPPHTTPLIB_SSL_ENABLED
  2191. public:
  2192. void set_digest_auth(const std::string &username,
  2193. const std::string &password);
  2194. void set_proxy_digest_auth(const std::string &username,
  2195. const std::string &password);
  2196. void enable_server_certificate_verification(bool enabled);
  2197. void enable_server_hostname_verification(bool enabled);
  2198. void enable_system_ca(bool enabled);
  2199. void set_ca_cert_path(const std::string &ca_cert_file_path,
  2200. const std::string &ca_cert_dir_path = std::string());
  2201. void set_ca_cert_store(tls::ca_store_t ca_cert_store);
  2202. void load_ca_cert_store(const char *ca_cert, std::size_t size);
  2203. void set_server_certificate_verifier(tls::VerifyCallback verifier);
  2204. void set_session_verifier(
  2205. std::function<SSLVerifierResponse(tls::session_t)> verifier);
  2206. tls::ctx_t tls_context() const;
  2207. #ifdef CPPHTTPLIB_WINDOWS_AUTOMATIC_ROOT_CERTIFICATES_UPDATE
  2208. void enable_windows_certificate_verification(bool enabled);
  2209. #endif
  2210. private:
  2211. bool is_ssl_ = false;
  2212. #endif
  2213. };
  2214. #ifdef CPPHTTPLIB_SSL_ENABLED
  2215. class SSLServer : public Server {
  2216. public:
  2217. SSLServer(const char *cert_path, const char *private_key_path,
  2218. const char *client_ca_cert_file_path = nullptr,
  2219. const char *client_ca_cert_dir_path = nullptr,
  2220. const char *private_key_password = nullptr);
  2221. struct PemMemory {
  2222. const char *cert_pem;
  2223. size_t cert_pem_len;
  2224. const char *key_pem;
  2225. size_t key_pem_len;
  2226. const char *client_ca_pem;
  2227. size_t client_ca_pem_len;
  2228. const char *private_key_password;
  2229. };
  2230. explicit SSLServer(const PemMemory &pem);
  2231. // The callback receives the ctx_t handle which can be cast to the
  2232. // appropriate backend type (SSL_CTX* for OpenSSL,
  2233. // tls::impl::MbedTlsContext* for Mbed TLS)
  2234. explicit SSLServer(const tls::ContextSetupCallback &setup_callback);
  2235. ~SSLServer() override;
  2236. bool is_valid() const override;
  2237. bool update_certs_pem(const char *cert_pem, const char *key_pem,
  2238. const char *client_ca_pem = nullptr,
  2239. const char *password = nullptr);
  2240. tls::ctx_t tls_context() const { return ctx_; }
  2241. int ssl_last_error() const { return last_ssl_error_; }
  2242. private:
  2243. bool process_and_close_socket(socket_t sock) override;
  2244. tls::ctx_t ctx_ = nullptr;
  2245. std::mutex ctx_mutex_;
  2246. int last_ssl_error_ = 0;
  2247. };
  2248. class SSLClient final : public ClientImpl {
  2249. public:
  2250. explicit SSLClient(const std::string &host);
  2251. explicit SSLClient(const std::string &host, int port);
  2252. explicit SSLClient(const std::string &host, int port,
  2253. const std::string &client_cert_path,
  2254. const std::string &client_key_path,
  2255. const std::string &private_key_password = std::string());
  2256. struct PemMemory {
  2257. const char *cert_pem;
  2258. size_t cert_pem_len;
  2259. const char *key_pem;
  2260. size_t key_pem_len;
  2261. const char *private_key_password;
  2262. };
  2263. explicit SSLClient(const std::string &host, int port, const PemMemory &pem);
  2264. ~SSLClient() override;
  2265. bool is_valid() const override;
  2266. void set_ca_cert_store(tls::ca_store_t ca_cert_store);
  2267. void load_ca_cert_store(const char *ca_cert, std::size_t size);
  2268. void set_server_certificate_verifier(tls::VerifyCallback verifier);
  2269. // Post-handshake session verifier (backend-independent)
  2270. void set_session_verifier(
  2271. std::function<SSLVerifierResponse(tls::session_t)> verifier);
  2272. tls::ctx_t tls_context() const { return ctx_; }
  2273. #ifdef CPPHTTPLIB_WINDOWS_AUTOMATIC_ROOT_CERTIFICATES_UPDATE
  2274. void enable_windows_certificate_verification(bool enabled);
  2275. #endif
  2276. private:
  2277. bool create_and_connect_socket(Socket &socket, Error &error) override;
  2278. bool ensure_socket_connection(Socket &socket, Error &error) override;
  2279. void shutdown_ssl(Socket &socket, bool shutdown_gracefully) override;
  2280. void shutdown_ssl_impl(Socket &socket, bool shutdown_gracefully);
  2281. bool
  2282. process_socket(const Socket &socket,
  2283. std::chrono::time_point<std::chrono::steady_clock> start_time,
  2284. std::function<bool(Stream &strm)> callback) override;
  2285. bool is_ssl() const override;
  2286. bool setup_proxy_connection(
  2287. Socket &socket,
  2288. std::chrono::time_point<std::chrono::steady_clock> start_time,
  2289. Response &res, bool &success, Error &error) override;
  2290. bool connect_with_proxy(
  2291. Socket &sock,
  2292. std::chrono::time_point<std::chrono::steady_clock> start_time,
  2293. Response &res, bool &success, Error &error);
  2294. bool initialize_ssl(Socket &socket, Error &error);
  2295. void init_ctx();
  2296. void reset_ctx_on_error();
  2297. bool load_certs();
  2298. tls::ctx_t ctx_ = nullptr;
  2299. std::mutex ctx_mutex_;
  2300. std::once_flag initialize_cert_;
  2301. // Tracks whether a custom CA store was applied via set_ca_cert_store(),
  2302. // since the store handle itself is owned by ctx_ and leaves no other trace.
  2303. // Used to keep custom CA configuration exclusive with system CA loading.
  2304. bool ca_cert_store_set_ = false;
  2305. long verify_result_ = 0;
  2306. std::function<SSLVerifierResponse(tls::session_t)> session_verifier_;
  2307. #ifdef CPPHTTPLIB_WINDOWS_AUTOMATIC_ROOT_CERTIFICATES_UPDATE
  2308. bool enable_windows_cert_verification_ = true;
  2309. #endif
  2310. friend class ClientImpl;
  2311. #ifdef CPPHTTPLIB_OPENSSL_SUPPORT
  2312. private:
  2313. bool verify_host(X509 *server_cert) const;
  2314. bool verify_host_with_subject_alt_name(X509 *server_cert) const;
  2315. bool verify_host_with_common_name(X509 *server_cert) const;
  2316. #endif
  2317. };
  2318. #endif // CPPHTTPLIB_SSL_ENABLED
  2319. namespace detail {
  2320. template <typename T, typename U>
  2321. inline void duration_to_sec_and_usec(const T &duration, U callback) {
  2322. auto sec = std::chrono::duration_cast<std::chrono::seconds>(duration).count();
  2323. auto usec = std::chrono::duration_cast<std::chrono::microseconds>(
  2324. duration - std::chrono::seconds(sec))
  2325. .count();
  2326. callback(static_cast<time_t>(sec), static_cast<time_t>(usec));
  2327. }
  2328. template <size_t N> inline constexpr size_t str_len(const char (&)[N]) {
  2329. return N - 1;
  2330. }
  2331. inline bool is_numeric(const std::string &str) {
  2332. return !str.empty() &&
  2333. std::all_of(str.cbegin(), str.cend(),
  2334. [](unsigned char c) { return std::isdigit(c); });
  2335. }
  2336. inline size_t get_header_value_u64(const Headers &headers,
  2337. const std::string &key, size_t def,
  2338. size_t id, bool &is_invalid_value) {
  2339. is_invalid_value = false;
  2340. auto rng = headers.equal_range(key);
  2341. auto it = rng.first;
  2342. std::advance(it, static_cast<ssize_t>(id));
  2343. if (it != rng.second) {
  2344. if (is_numeric(it->second)) {
  2345. return static_cast<size_t>(std::strtoull(it->second.data(), nullptr, 10));
  2346. } else {
  2347. is_invalid_value = true;
  2348. }
  2349. }
  2350. return def;
  2351. }
  2352. inline size_t get_header_value_u64(const Headers &headers,
  2353. const std::string &key, size_t def,
  2354. size_t id) {
  2355. auto dummy = false;
  2356. return get_header_value_u64(headers, key, def, id, dummy);
  2357. }
  2358. } // namespace detail
  2359. template <class Rep, class Period>
  2360. inline Server &
  2361. Server::set_read_timeout(const std::chrono::duration<Rep, Period> &duration) {
  2362. detail::duration_to_sec_and_usec(
  2363. duration, [&](time_t sec, time_t usec) { set_read_timeout(sec, usec); });
  2364. return *this;
  2365. }
  2366. template <class Rep, class Period>
  2367. inline Server &
  2368. Server::set_write_timeout(const std::chrono::duration<Rep, Period> &duration) {
  2369. detail::duration_to_sec_and_usec(
  2370. duration, [&](time_t sec, time_t usec) { set_write_timeout(sec, usec); });
  2371. return *this;
  2372. }
  2373. template <class Rep, class Period>
  2374. inline Server &
  2375. Server::set_idle_interval(const std::chrono::duration<Rep, Period> &duration) {
  2376. detail::duration_to_sec_and_usec(
  2377. duration, [&](time_t sec, time_t usec) { set_idle_interval(sec, usec); });
  2378. return *this;
  2379. }
  2380. template <class Rep, class Period>
  2381. inline void ClientImpl::set_connection_timeout(
  2382. const std::chrono::duration<Rep, Period> &duration) {
  2383. detail::duration_to_sec_and_usec(duration, [&](time_t sec, time_t usec) {
  2384. set_connection_timeout(sec, usec);
  2385. });
  2386. }
  2387. template <class Rep, class Period>
  2388. inline void ClientImpl::set_read_timeout(
  2389. const std::chrono::duration<Rep, Period> &duration) {
  2390. detail::duration_to_sec_and_usec(
  2391. duration, [&](time_t sec, time_t usec) { set_read_timeout(sec, usec); });
  2392. }
  2393. template <class Rep, class Period>
  2394. inline void ClientImpl::set_write_timeout(
  2395. const std::chrono::duration<Rep, Period> &duration) {
  2396. detail::duration_to_sec_and_usec(
  2397. duration, [&](time_t sec, time_t usec) { set_write_timeout(sec, usec); });
  2398. }
  2399. template <class Rep, class Period>
  2400. inline void ClientImpl::set_max_timeout(
  2401. const std::chrono::duration<Rep, Period> &duration) {
  2402. auto msec =
  2403. std::chrono::duration_cast<std::chrono::milliseconds>(duration).count();
  2404. set_max_timeout(msec);
  2405. }
  2406. template <class Rep, class Period>
  2407. inline void Client::set_connection_timeout(
  2408. const std::chrono::duration<Rep, Period> &duration) {
  2409. cli_->set_connection_timeout(duration);
  2410. }
  2411. template <class Rep, class Period>
  2412. inline void
  2413. Client::set_read_timeout(const std::chrono::duration<Rep, Period> &duration) {
  2414. cli_->set_read_timeout(duration);
  2415. }
  2416. template <class Rep, class Period>
  2417. inline void
  2418. Client::set_write_timeout(const std::chrono::duration<Rep, Period> &duration) {
  2419. cli_->set_write_timeout(duration);
  2420. }
  2421. inline void Client::set_max_timeout(time_t msec) {
  2422. cli_->set_max_timeout(msec);
  2423. }
  2424. template <class Rep, class Period>
  2425. inline void
  2426. Client::set_max_timeout(const std::chrono::duration<Rep, Period> &duration) {
  2427. cli_->set_max_timeout(duration);
  2428. }
  2429. /*
  2430. * Forward declarations and types that will be part of the .h file if split into
  2431. * .h + .cc.
  2432. */
  2433. std::string hosted_at(const std::string &hostname);
  2434. void hosted_at(const std::string &hostname, std::vector<std::string> &addrs);
  2435. // JavaScript-style URL encoding/decoding functions
  2436. std::string encode_uri_component(const std::string &value);
  2437. std::string encode_uri(const std::string &value);
  2438. std::string decode_uri_component(const std::string &value);
  2439. std::string decode_uri(const std::string &value);
  2440. // RFC 3986 compliant URL component encoding/decoding functions
  2441. std::string encode_path_component(const std::string &component);
  2442. std::string decode_path_component(const std::string &component);
  2443. std::string encode_query_component(const std::string &component,
  2444. bool space_as_plus = true);
  2445. std::string decode_query_component(const std::string &component,
  2446. bool plus_as_space = true);
  2447. std::string sanitize_filename(const std::string &filename);
  2448. std::string append_query_params(const std::string &path, const Params &params);
  2449. std::pair<std::string, std::string> make_range_header(const Ranges &ranges);
  2450. std::pair<std::string, std::string>
  2451. make_basic_authentication_header(const std::string &username,
  2452. const std::string &password,
  2453. bool is_proxy = false);
  2454. namespace detail {
  2455. #if defined(_WIN32)
  2456. inline std::wstring u8string_to_wstring(const char *s) {
  2457. if (!s) { return std::wstring(); }
  2458. auto len = static_cast<int>(strlen(s));
  2459. if (!len) { return std::wstring(); }
  2460. auto wlen = ::MultiByteToWideChar(CP_UTF8, 0, s, len, nullptr, 0);
  2461. if (!wlen) { return std::wstring(); }
  2462. std::wstring ws;
  2463. ws.resize(wlen);
  2464. wlen = ::MultiByteToWideChar(
  2465. CP_UTF8, 0, s, len,
  2466. const_cast<LPWSTR>(reinterpret_cast<LPCWSTR>(ws.data())), wlen);
  2467. if (wlen != static_cast<int>(ws.size())) { ws.clear(); }
  2468. return ws;
  2469. }
  2470. #endif
  2471. struct FileStat {
  2472. FileStat(const std::string &path);
  2473. bool is_file() const;
  2474. bool is_dir() const;
  2475. time_t mtime() const;
  2476. size_t size() const;
  2477. private:
  2478. #if defined(_WIN32)
  2479. struct _stat st_;
  2480. #else
  2481. struct stat st_;
  2482. #endif
  2483. int ret_ = -1;
  2484. };
  2485. std::string make_host_and_port_string(const std::string &host, int port,
  2486. bool is_ssl);
  2487. std::string trim_copy(const std::string &s);
  2488. void divide(
  2489. const char *data, std::size_t size, char d,
  2490. std::function<void(const char *, std::size_t, const char *, std::size_t)>
  2491. fn);
  2492. void divide(
  2493. const std::string &str, char d,
  2494. std::function<void(const char *, std::size_t, const char *, std::size_t)>
  2495. fn);
  2496. void split(const char *b, const char *e, char d,
  2497. std::function<void(const char *, const char *)> fn);
  2498. void split(const char *b, const char *e, char d, size_t m,
  2499. std::function<void(const char *, const char *)> fn);
  2500. bool process_client_socket(
  2501. socket_t sock, time_t read_timeout_sec, time_t read_timeout_usec,
  2502. time_t write_timeout_sec, time_t write_timeout_usec,
  2503. time_t max_timeout_msec,
  2504. std::chrono::time_point<std::chrono::steady_clock> start_time,
  2505. std::function<bool(Stream &)> callback);
  2506. socket_t create_client_socket(const std::string &host, const std::string &ip,
  2507. int port, int address_family, bool tcp_nodelay,
  2508. bool ipv6_v6only, SocketOptions socket_options,
  2509. time_t connection_timeout_sec,
  2510. time_t connection_timeout_usec,
  2511. time_t read_timeout_sec, time_t read_timeout_usec,
  2512. time_t write_timeout_sec,
  2513. time_t write_timeout_usec,
  2514. const std::string &intf, Error &error);
  2515. const char *get_header_value(const Headers &headers, const std::string &key,
  2516. const char *def, size_t id);
  2517. std::string params_to_query_str(const Params &params);
  2518. void parse_query_text(const char *data, std::size_t size, Params &params);
  2519. void parse_query_text(const std::string &s, Params &params);
  2520. bool parse_multipart_boundary(const std::string &content_type,
  2521. std::string &boundary);
  2522. bool parse_range_header(const std::string &s, Ranges &ranges);
  2523. bool parse_accept_header(const std::string &s,
  2524. std::vector<std::string> &content_types);
  2525. ssize_t send_socket(socket_t sock, const void *ptr, size_t size, int flags);
  2526. ssize_t read_socket(socket_t sock, void *ptr, size_t size, int flags);
  2527. enum class EncodingType { None = 0, Gzip, Brotli, Zstd };
  2528. EncodingType encoding_type(const Request &req, const Response &res);
  2529. class BufferStream final : public Stream {
  2530. public:
  2531. BufferStream() = default;
  2532. ~BufferStream() override = default;
  2533. bool is_readable() const override;
  2534. bool wait_readable() const override;
  2535. bool wait_writable() const override;
  2536. ssize_t read(char *ptr, size_t size) override;
  2537. ssize_t write(const char *ptr, size_t size) override;
  2538. void get_remote_ip_and_port(std::string &ip, int &port) const override;
  2539. void get_local_ip_and_port(std::string &ip, int &port) const override;
  2540. socket_t socket() const override;
  2541. time_t duration() const override;
  2542. const std::string &get_buffer() const;
  2543. private:
  2544. std::string buffer;
  2545. size_t position = 0;
  2546. };
  2547. class compressor {
  2548. public:
  2549. virtual ~compressor() = default;
  2550. typedef std::function<bool(const char *data, size_t data_len)> Callback;
  2551. virtual bool compress(const char *data, size_t data_length, bool last,
  2552. Callback callback) = 0;
  2553. };
  2554. class decompressor {
  2555. public:
  2556. virtual ~decompressor() = default;
  2557. virtual bool is_valid() const = 0;
  2558. typedef std::function<bool(const char *data, size_t data_len)> Callback;
  2559. virtual bool decompress(const char *data, size_t data_length,
  2560. Callback callback) = 0;
  2561. };
  2562. class nocompressor final : public compressor {
  2563. public:
  2564. ~nocompressor() override = default;
  2565. bool compress(const char *data, size_t data_length, bool /*last*/,
  2566. Callback callback) override;
  2567. };
  2568. #ifdef CPPHTTPLIB_ZLIB_SUPPORT
  2569. class gzip_compressor final : public compressor {
  2570. public:
  2571. gzip_compressor();
  2572. ~gzip_compressor() override;
  2573. bool compress(const char *data, size_t data_length, bool last,
  2574. Callback callback) override;
  2575. private:
  2576. bool is_valid_ = false;
  2577. z_stream strm_;
  2578. };
  2579. class gzip_decompressor final : public decompressor {
  2580. public:
  2581. gzip_decompressor();
  2582. ~gzip_decompressor() override;
  2583. bool is_valid() const override;
  2584. bool decompress(const char *data, size_t data_length,
  2585. Callback callback) override;
  2586. private:
  2587. bool is_valid_ = false;
  2588. z_stream strm_;
  2589. };
  2590. #endif
  2591. #ifdef CPPHTTPLIB_BROTLI_SUPPORT
  2592. class brotli_compressor final : public compressor {
  2593. public:
  2594. brotli_compressor();
  2595. ~brotli_compressor();
  2596. bool compress(const char *data, size_t data_length, bool last,
  2597. Callback callback) override;
  2598. private:
  2599. BrotliEncoderState *state_ = nullptr;
  2600. };
  2601. class brotli_decompressor final : public decompressor {
  2602. public:
  2603. brotli_decompressor();
  2604. ~brotli_decompressor();
  2605. bool is_valid() const override;
  2606. bool decompress(const char *data, size_t data_length,
  2607. Callback callback) override;
  2608. private:
  2609. BrotliDecoderResult decoder_r;
  2610. BrotliDecoderState *decoder_s = nullptr;
  2611. };
  2612. #endif
  2613. #ifdef CPPHTTPLIB_ZSTD_SUPPORT
  2614. class zstd_compressor : public compressor {
  2615. public:
  2616. zstd_compressor();
  2617. ~zstd_compressor();
  2618. bool compress(const char *data, size_t data_length, bool last,
  2619. Callback callback) override;
  2620. private:
  2621. ZSTD_CCtx *ctx_ = nullptr;
  2622. };
  2623. class zstd_decompressor : public decompressor {
  2624. public:
  2625. zstd_decompressor();
  2626. ~zstd_decompressor();
  2627. bool is_valid() const override;
  2628. bool decompress(const char *data, size_t data_length,
  2629. Callback callback) override;
  2630. private:
  2631. ZSTD_DCtx *ctx_ = nullptr;
  2632. };
  2633. #endif
  2634. // NOTE: until the read size reaches `fixed_buffer_size`, use `fixed_buffer`
  2635. // to store data. The call can set memory on stack for performance.
  2636. class stream_line_reader {
  2637. public:
  2638. stream_line_reader(Stream &strm, char *fixed_buffer,
  2639. size_t fixed_buffer_size);
  2640. const char *ptr() const;
  2641. size_t size() const;
  2642. bool end_with_crlf() const;
  2643. bool getline();
  2644. private:
  2645. void append(char c);
  2646. Stream &strm_;
  2647. char *fixed_buffer_;
  2648. const size_t fixed_buffer_size_;
  2649. size_t fixed_buffer_used_size_ = 0;
  2650. std::string growable_buffer_;
  2651. };
  2652. bool parse_trailers(stream_line_reader &line_reader, Headers &dest,
  2653. const Headers &src_headers);
  2654. struct ChunkedDecoder {
  2655. Stream &strm;
  2656. size_t chunk_remaining = 0;
  2657. bool finished = false;
  2658. char line_buf[64];
  2659. size_t last_chunk_total = 0;
  2660. size_t last_chunk_offset = 0;
  2661. explicit ChunkedDecoder(Stream &s);
  2662. ssize_t read_payload(char *buf, size_t len, size_t &out_chunk_offset,
  2663. size_t &out_chunk_total);
  2664. bool parse_trailers_into(Headers &dest, const Headers &src_headers);
  2665. };
  2666. class mmap {
  2667. public:
  2668. mmap(const char *path);
  2669. ~mmap();
  2670. bool open(const char *path);
  2671. void close();
  2672. bool is_open() const;
  2673. size_t size() const;
  2674. const char *data() const;
  2675. private:
  2676. #if defined(_WIN32)
  2677. HANDLE hFile_ = NULL;
  2678. HANDLE hMapping_ = NULL;
  2679. #else
  2680. int fd_ = -1;
  2681. #endif
  2682. size_t size_ = 0;
  2683. void *addr_ = nullptr;
  2684. bool is_open_empty_file = false;
  2685. };
  2686. // NOTE: https://www.rfc-editor.org/rfc/rfc9110#section-5
  2687. namespace fields {
  2688. bool is_token_char(char c);
  2689. bool is_token(const std::string &s);
  2690. bool is_field_name(const std::string &s);
  2691. bool is_vchar(char c);
  2692. bool is_obs_text(char c);
  2693. bool is_field_vchar(char c);
  2694. bool is_field_content(const std::string &s);
  2695. bool is_field_value(const std::string &s);
  2696. } // namespace fields
  2697. } // namespace detail
  2698. /*
  2699. * TLS Abstraction Layer Declarations
  2700. */
  2701. #ifdef CPPHTTPLIB_SSL_ENABLED
  2702. // TLS abstraction layer - backend-specific type declarations
  2703. #ifdef CPPHTTPLIB_MBEDTLS_SUPPORT
  2704. namespace tls {
  2705. namespace impl {
  2706. // Mbed TLS context wrapper (holds config, entropy, DRBG, CA chain, own
  2707. // cert/key). This struct is accessible via tls::impl for use in SSL context
  2708. // setup callbacks (cast ctx_t to tls::impl::MbedTlsContext*).
  2709. struct MbedTlsContext {
  2710. mbedtls_ssl_config conf;
  2711. mbedtls_entropy_context entropy;
  2712. mbedtls_ctr_drbg_context ctr_drbg;
  2713. mbedtls_x509_crt ca_chain;
  2714. mbedtls_x509_crt own_cert;
  2715. mbedtls_pk_context own_key;
  2716. bool is_server = false;
  2717. bool verify_client = false;
  2718. bool has_verify_callback = false;
  2719. MbedTlsContext();
  2720. ~MbedTlsContext();
  2721. MbedTlsContext(const MbedTlsContext &) = delete;
  2722. MbedTlsContext &operator=(const MbedTlsContext &) = delete;
  2723. };
  2724. } // namespace impl
  2725. } // namespace tls
  2726. #endif
  2727. #ifdef CPPHTTPLIB_WOLFSSL_SUPPORT
  2728. namespace tls {
  2729. namespace impl {
  2730. // wolfSSL context wrapper (holds WOLFSSL_CTX and related state).
  2731. // This struct is accessible via tls::impl for use in SSL context
  2732. // setup callbacks (cast ctx_t to tls::impl::WolfSSLContext*).
  2733. struct WolfSSLContext {
  2734. WOLFSSL_CTX *ctx = nullptr;
  2735. bool is_server = false;
  2736. bool verify_client = false;
  2737. bool has_verify_callback = false;
  2738. std::string ca_pem_data_; // accumulated PEM for get_ca_names/get_ca_certs
  2739. WolfSSLContext();
  2740. ~WolfSSLContext();
  2741. WolfSSLContext(const WolfSSLContext &) = delete;
  2742. WolfSSLContext &operator=(const WolfSSLContext &) = delete;
  2743. };
  2744. // CA store for wolfSSL: holds raw PEM bytes to allow reloading into any ctx
  2745. struct WolfSSLCAStore {
  2746. std::string pem_data;
  2747. };
  2748. } // namespace impl
  2749. } // namespace tls
  2750. #endif
  2751. #endif // CPPHTTPLIB_SSL_ENABLED
  2752. namespace stream {
  2753. class Result {
  2754. public:
  2755. Result();
  2756. explicit Result(ClientImpl::StreamHandle &&handle, size_t chunk_size = 8192);
  2757. Result(Result &&other) noexcept;
  2758. Result &operator=(Result &&other) noexcept;
  2759. Result(const Result &) = delete;
  2760. Result &operator=(const Result &) = delete;
  2761. // Response info
  2762. bool is_valid() const;
  2763. explicit operator bool() const;
  2764. int status() const;
  2765. const Headers &headers() const;
  2766. std::string get_header_value(const std::string &key,
  2767. const char *def = "") const;
  2768. bool has_header(const std::string &key) const;
  2769. Error error() const;
  2770. Error read_error() const;
  2771. bool has_read_error() const;
  2772. // Stream reading
  2773. bool next();
  2774. const char *data() const;
  2775. size_t size() const;
  2776. std::string read_all();
  2777. private:
  2778. ClientImpl::StreamHandle handle_;
  2779. std::string buffer_;
  2780. size_t current_size_ = 0;
  2781. size_t chunk_size_;
  2782. bool finished_ = false;
  2783. };
  2784. // GET
  2785. template <typename ClientType>
  2786. inline Result Get(ClientType &cli, const std::string &path,
  2787. size_t chunk_size = 8192) {
  2788. return Result{cli.open_stream("GET", path), chunk_size};
  2789. }
  2790. template <typename ClientType>
  2791. inline Result Get(ClientType &cli, const std::string &path,
  2792. const Headers &headers, size_t chunk_size = 8192) {
  2793. return Result{cli.open_stream("GET", path, {}, headers), chunk_size};
  2794. }
  2795. template <typename ClientType>
  2796. inline Result Get(ClientType &cli, const std::string &path,
  2797. const Params &params, size_t chunk_size = 8192) {
  2798. return Result{cli.open_stream("GET", path, params), chunk_size};
  2799. }
  2800. template <typename ClientType>
  2801. inline Result Get(ClientType &cli, const std::string &path,
  2802. const Params &params, const Headers &headers,
  2803. size_t chunk_size = 8192) {
  2804. return Result{cli.open_stream("GET", path, params, headers), chunk_size};
  2805. }
  2806. // POST
  2807. template <typename ClientType>
  2808. inline Result Post(ClientType &cli, const std::string &path,
  2809. const std::string &body, const std::string &content_type,
  2810. size_t chunk_size = 8192) {
  2811. return Result{cli.open_stream("POST", path, {}, {}, body, content_type),
  2812. chunk_size};
  2813. }
  2814. template <typename ClientType>
  2815. inline Result Post(ClientType &cli, const std::string &path,
  2816. const Headers &headers, const std::string &body,
  2817. const std::string &content_type, size_t chunk_size = 8192) {
  2818. return Result{cli.open_stream("POST", path, {}, headers, body, content_type),
  2819. chunk_size};
  2820. }
  2821. template <typename ClientType>
  2822. inline Result Post(ClientType &cli, const std::string &path,
  2823. const Params &params, const std::string &body,
  2824. const std::string &content_type, size_t chunk_size = 8192) {
  2825. return Result{cli.open_stream("POST", path, params, {}, body, content_type),
  2826. chunk_size};
  2827. }
  2828. template <typename ClientType>
  2829. inline Result Post(ClientType &cli, const std::string &path,
  2830. const Params &params, const Headers &headers,
  2831. const std::string &body, const std::string &content_type,
  2832. size_t chunk_size = 8192) {
  2833. return Result{
  2834. cli.open_stream("POST", path, params, headers, body, content_type),
  2835. chunk_size};
  2836. }
  2837. // PUT
  2838. template <typename ClientType>
  2839. inline Result Put(ClientType &cli, const std::string &path,
  2840. const std::string &body, const std::string &content_type,
  2841. size_t chunk_size = 8192) {
  2842. return Result{cli.open_stream("PUT", path, {}, {}, body, content_type),
  2843. chunk_size};
  2844. }
  2845. template <typename ClientType>
  2846. inline Result Put(ClientType &cli, const std::string &path,
  2847. const Headers &headers, const std::string &body,
  2848. const std::string &content_type, size_t chunk_size = 8192) {
  2849. return Result{cli.open_stream("PUT", path, {}, headers, body, content_type),
  2850. chunk_size};
  2851. }
  2852. template <typename ClientType>
  2853. inline Result Put(ClientType &cli, const std::string &path,
  2854. const Params &params, const std::string &body,
  2855. const std::string &content_type, size_t chunk_size = 8192) {
  2856. return Result{cli.open_stream("PUT", path, params, {}, body, content_type),
  2857. chunk_size};
  2858. }
  2859. template <typename ClientType>
  2860. inline Result Put(ClientType &cli, const std::string &path,
  2861. const Params &params, const Headers &headers,
  2862. const std::string &body, const std::string &content_type,
  2863. size_t chunk_size = 8192) {
  2864. return Result{
  2865. cli.open_stream("PUT", path, params, headers, body, content_type),
  2866. chunk_size};
  2867. }
  2868. // PATCH
  2869. template <typename ClientType>
  2870. inline Result Patch(ClientType &cli, const std::string &path,
  2871. const std::string &body, const std::string &content_type,
  2872. size_t chunk_size = 8192) {
  2873. return Result{cli.open_stream("PATCH", path, {}, {}, body, content_type),
  2874. chunk_size};
  2875. }
  2876. template <typename ClientType>
  2877. inline Result Patch(ClientType &cli, const std::string &path,
  2878. const Headers &headers, const std::string &body,
  2879. const std::string &content_type, size_t chunk_size = 8192) {
  2880. return Result{cli.open_stream("PATCH", path, {}, headers, body, content_type),
  2881. chunk_size};
  2882. }
  2883. template <typename ClientType>
  2884. inline Result Patch(ClientType &cli, const std::string &path,
  2885. const Params &params, const std::string &body,
  2886. const std::string &content_type, size_t chunk_size = 8192) {
  2887. return Result{cli.open_stream("PATCH", path, params, {}, body, content_type),
  2888. chunk_size};
  2889. }
  2890. template <typename ClientType>
  2891. inline Result Patch(ClientType &cli, const std::string &path,
  2892. const Params &params, const Headers &headers,
  2893. const std::string &body, const std::string &content_type,
  2894. size_t chunk_size = 8192) {
  2895. return Result{
  2896. cli.open_stream("PATCH", path, params, headers, body, content_type),
  2897. chunk_size};
  2898. }
  2899. // DELETE
  2900. template <typename ClientType>
  2901. inline Result Delete(ClientType &cli, const std::string &path,
  2902. size_t chunk_size = 8192) {
  2903. return Result{cli.open_stream("DELETE", path), chunk_size};
  2904. }
  2905. template <typename ClientType>
  2906. inline Result Delete(ClientType &cli, const std::string &path,
  2907. const Headers &headers, size_t chunk_size = 8192) {
  2908. return Result{cli.open_stream("DELETE", path, {}, headers), chunk_size};
  2909. }
  2910. template <typename ClientType>
  2911. inline Result Delete(ClientType &cli, const std::string &path,
  2912. const std::string &body, const std::string &content_type,
  2913. size_t chunk_size = 8192) {
  2914. return Result{cli.open_stream("DELETE", path, {}, {}, body, content_type),
  2915. chunk_size};
  2916. }
  2917. template <typename ClientType>
  2918. inline Result Delete(ClientType &cli, const std::string &path,
  2919. const Headers &headers, const std::string &body,
  2920. const std::string &content_type,
  2921. size_t chunk_size = 8192) {
  2922. return Result{
  2923. cli.open_stream("DELETE", path, {}, headers, body, content_type),
  2924. chunk_size};
  2925. }
  2926. template <typename ClientType>
  2927. inline Result Delete(ClientType &cli, const std::string &path,
  2928. const Params &params, size_t chunk_size = 8192) {
  2929. return Result{cli.open_stream("DELETE", path, params), chunk_size};
  2930. }
  2931. template <typename ClientType>
  2932. inline Result Delete(ClientType &cli, const std::string &path,
  2933. const Params &params, const Headers &headers,
  2934. size_t chunk_size = 8192) {
  2935. return Result{cli.open_stream("DELETE", path, params, headers), chunk_size};
  2936. }
  2937. template <typename ClientType>
  2938. inline Result Delete(ClientType &cli, const std::string &path,
  2939. const Params &params, const std::string &body,
  2940. const std::string &content_type,
  2941. size_t chunk_size = 8192) {
  2942. return Result{cli.open_stream("DELETE", path, params, {}, body, content_type),
  2943. chunk_size};
  2944. }
  2945. template <typename ClientType>
  2946. inline Result Delete(ClientType &cli, const std::string &path,
  2947. const Params &params, const Headers &headers,
  2948. const std::string &body, const std::string &content_type,
  2949. size_t chunk_size = 8192) {
  2950. return Result{
  2951. cli.open_stream("DELETE", path, params, headers, body, content_type),
  2952. chunk_size};
  2953. }
  2954. // HEAD
  2955. template <typename ClientType>
  2956. inline Result Head(ClientType &cli, const std::string &path,
  2957. size_t chunk_size = 8192) {
  2958. return Result{cli.open_stream("HEAD", path), chunk_size};
  2959. }
  2960. template <typename ClientType>
  2961. inline Result Head(ClientType &cli, const std::string &path,
  2962. const Headers &headers, size_t chunk_size = 8192) {
  2963. return Result{cli.open_stream("HEAD", path, {}, headers), chunk_size};
  2964. }
  2965. template <typename ClientType>
  2966. inline Result Head(ClientType &cli, const std::string &path,
  2967. const Params &params, size_t chunk_size = 8192) {
  2968. return Result{cli.open_stream("HEAD", path, params), chunk_size};
  2969. }
  2970. template <typename ClientType>
  2971. inline Result Head(ClientType &cli, const std::string &path,
  2972. const Params &params, const Headers &headers,
  2973. size_t chunk_size = 8192) {
  2974. return Result{cli.open_stream("HEAD", path, params, headers), chunk_size};
  2975. }
  2976. // OPTIONS
  2977. template <typename ClientType>
  2978. inline Result Options(ClientType &cli, const std::string &path,
  2979. size_t chunk_size = 8192) {
  2980. return Result{cli.open_stream("OPTIONS", path), chunk_size};
  2981. }
  2982. template <typename ClientType>
  2983. inline Result Options(ClientType &cli, const std::string &path,
  2984. const Headers &headers, size_t chunk_size = 8192) {
  2985. return Result{cli.open_stream("OPTIONS", path, {}, headers), chunk_size};
  2986. }
  2987. template <typename ClientType>
  2988. inline Result Options(ClientType &cli, const std::string &path,
  2989. const Params &params, size_t chunk_size = 8192) {
  2990. return Result{cli.open_stream("OPTIONS", path, params), chunk_size};
  2991. }
  2992. template <typename ClientType>
  2993. inline Result Options(ClientType &cli, const std::string &path,
  2994. const Params &params, const Headers &headers,
  2995. size_t chunk_size = 8192) {
  2996. return Result{cli.open_stream("OPTIONS", path, params, headers), chunk_size};
  2997. }
  2998. } // namespace stream
  2999. namespace sse {
  3000. struct SSEMessage {
  3001. std::string event; // Event type (default: "message")
  3002. std::string data; // Event payload
  3003. std::string id; // Event ID for Last-Event-ID header
  3004. SSEMessage();
  3005. void clear();
  3006. };
  3007. class SSEClient {
  3008. public:
  3009. using MessageHandler = std::function<void(const SSEMessage &)>;
  3010. using ErrorHandler = std::function<void(Error)>;
  3011. using OpenHandler = std::function<void()>;
  3012. SSEClient(Client &client, const std::string &path);
  3013. SSEClient(Client &client, const std::string &path, const Headers &headers);
  3014. ~SSEClient();
  3015. SSEClient(const SSEClient &) = delete;
  3016. SSEClient &operator=(const SSEClient &) = delete;
  3017. // Event handlers
  3018. SSEClient &on_message(MessageHandler handler);
  3019. SSEClient &on_event(const std::string &type, MessageHandler handler);
  3020. SSEClient &on_open(OpenHandler handler);
  3021. SSEClient &on_error(ErrorHandler handler);
  3022. SSEClient &set_reconnect_interval(int ms);
  3023. SSEClient &set_max_reconnect_attempts(int n);
  3024. // Update headers (thread-safe)
  3025. SSEClient &set_headers(const Headers &headers);
  3026. // State accessors
  3027. bool is_connected() const;
  3028. const std::string &last_event_id() const;
  3029. // Blocking start - runs event loop with auto-reconnect
  3030. void start();
  3031. // Non-blocking start - runs in background thread
  3032. void start_async();
  3033. // Stop the client (thread-safe)
  3034. void stop();
  3035. private:
  3036. bool parse_sse_line(const std::string &line, SSEMessage &msg, int &retry_ms);
  3037. void run_event_loop();
  3038. void dispatch_event(const SSEMessage &msg);
  3039. bool should_reconnect(int count) const;
  3040. void wait_for_reconnect();
  3041. // Client and path
  3042. Client &client_;
  3043. std::string path_;
  3044. Headers headers_;
  3045. mutable std::mutex headers_mutex_;
  3046. // Callbacks
  3047. MessageHandler on_message_;
  3048. std::map<std::string, MessageHandler> event_handlers_;
  3049. OpenHandler on_open_;
  3050. ErrorHandler on_error_;
  3051. // Configuration
  3052. int reconnect_interval_ms_ = 3000;
  3053. int max_reconnect_attempts_ = 0; // 0 = unlimited
  3054. // State
  3055. std::atomic<bool> running_{false};
  3056. std::atomic<bool> connected_{false};
  3057. std::string last_event_id_;
  3058. // Async support
  3059. std::thread async_thread_;
  3060. };
  3061. } // namespace sse
  3062. namespace ws {
  3063. enum class Opcode : uint8_t {
  3064. Continuation = 0x0,
  3065. Text = 0x1,
  3066. Binary = 0x2,
  3067. Close = 0x8,
  3068. Ping = 0x9,
  3069. Pong = 0xA,
  3070. };
  3071. enum class CloseStatus : uint16_t {
  3072. Normal = 1000,
  3073. GoingAway = 1001,
  3074. ProtocolError = 1002,
  3075. UnsupportedData = 1003,
  3076. NoStatus = 1005,
  3077. Abnormal = 1006,
  3078. InvalidPayload = 1007,
  3079. PolicyViolation = 1008,
  3080. MessageTooBig = 1009,
  3081. MandatoryExtension = 1010,
  3082. InternalError = 1011,
  3083. };
  3084. enum ReadResult : int { Fail = 0, Text = 1, Binary = 2 };
  3085. class WebSocket {
  3086. public:
  3087. WebSocket(const WebSocket &) = delete;
  3088. WebSocket &operator=(const WebSocket &) = delete;
  3089. ~WebSocket();
  3090. ReadResult read(std::string &msg);
  3091. bool send(const std::string &data);
  3092. bool send(const char *data, size_t len);
  3093. void close(CloseStatus status = CloseStatus::Normal,
  3094. const std::string &reason = "");
  3095. const Request &request() const;
  3096. bool is_open() const;
  3097. private:
  3098. friend class httplib::Server;
  3099. friend class WebSocketClient;
  3100. WebSocket(
  3101. Stream &strm, const Request &req, bool is_server,
  3102. time_t ping_interval_sec = CPPHTTPLIB_WEBSOCKET_PING_INTERVAL_SECOND,
  3103. int max_missed_pongs = CPPHTTPLIB_WEBSOCKET_MAX_MISSED_PONGS)
  3104. : strm_(strm), req_(req), is_server_(is_server),
  3105. ping_interval_sec_(ping_interval_sec),
  3106. max_missed_pongs_(max_missed_pongs) {
  3107. start_heartbeat();
  3108. }
  3109. WebSocket(
  3110. std::unique_ptr<Stream> &&owned_strm, const Request &req, bool is_server,
  3111. time_t ping_interval_sec = CPPHTTPLIB_WEBSOCKET_PING_INTERVAL_SECOND,
  3112. int max_missed_pongs = CPPHTTPLIB_WEBSOCKET_MAX_MISSED_PONGS)
  3113. : strm_(*owned_strm), owned_strm_(std::move(owned_strm)), req_(req),
  3114. is_server_(is_server), ping_interval_sec_(ping_interval_sec),
  3115. max_missed_pongs_(max_missed_pongs) {
  3116. start_heartbeat();
  3117. }
  3118. void start_heartbeat();
  3119. bool send_frame(Opcode op, const char *data, size_t len, bool fin = true);
  3120. Stream &strm_;
  3121. std::unique_ptr<Stream> owned_strm_;
  3122. Request req_;
  3123. bool is_server_;
  3124. time_t ping_interval_sec_;
  3125. int max_missed_pongs_;
  3126. int unacked_pings_ = 0;
  3127. std::atomic<bool> closed_{false};
  3128. std::mutex write_mutex_;
  3129. std::thread ping_thread_;
  3130. std::mutex ping_mutex_;
  3131. std::condition_variable ping_cv_;
  3132. };
  3133. class WebSocketClient {
  3134. public:
  3135. explicit WebSocketClient(const std::string &scheme_host_port_path,
  3136. const Headers &headers = {});
  3137. ~WebSocketClient();
  3138. WebSocketClient(const WebSocketClient &) = delete;
  3139. WebSocketClient &operator=(const WebSocketClient &) = delete;
  3140. bool is_valid() const;
  3141. bool connect();
  3142. ReadResult read(std::string &msg);
  3143. bool send(const std::string &data);
  3144. bool send(const char *data, size_t len);
  3145. void close(CloseStatus status = CloseStatus::Normal,
  3146. const std::string &reason = "");
  3147. bool is_open() const;
  3148. const std::string &subprotocol() const;
  3149. void set_read_timeout(time_t sec, time_t usec = 0);
  3150. void set_write_timeout(time_t sec, time_t usec = 0);
  3151. void set_websocket_ping_interval(time_t sec);
  3152. void set_websocket_max_missed_pongs(int count);
  3153. void set_tcp_nodelay(bool on);
  3154. void set_address_family(int family);
  3155. void set_ipv6_v6only(bool on);
  3156. void set_socket_options(SocketOptions socket_options);
  3157. void set_connection_timeout(time_t sec, time_t usec = 0);
  3158. void set_interface(const std::string &intf);
  3159. void set_hostname_addr_map(std::map<std::string, std::string> addr_map);
  3160. #ifdef CPPHTTPLIB_SSL_ENABLED
  3161. void set_ca_cert_path(const std::string &path);
  3162. void set_ca_cert_store(tls::ca_store_t store);
  3163. void load_ca_cert_store(const char *ca_cert, std::size_t size);
  3164. void enable_server_certificate_verification(bool enabled);
  3165. void enable_system_ca(bool enabled);
  3166. #endif
  3167. private:
  3168. void shutdown_and_close();
  3169. bool create_stream(std::unique_ptr<Stream> &strm);
  3170. std::string host_;
  3171. int port_;
  3172. std::string path_;
  3173. Headers headers_;
  3174. std::string subprotocol_;
  3175. bool is_valid_ = false;
  3176. socket_t sock_ = INVALID_SOCKET;
  3177. std::unique_ptr<WebSocket> ws_;
  3178. time_t read_timeout_sec_ = CPPHTTPLIB_WEBSOCKET_READ_TIMEOUT_SECOND;
  3179. time_t read_timeout_usec_ = 0;
  3180. time_t write_timeout_sec_ = CPPHTTPLIB_CLIENT_WRITE_TIMEOUT_SECOND;
  3181. time_t write_timeout_usec_ = CPPHTTPLIB_CLIENT_WRITE_TIMEOUT_USECOND;
  3182. time_t websocket_ping_interval_sec_ =
  3183. CPPHTTPLIB_WEBSOCKET_PING_INTERVAL_SECOND;
  3184. int websocket_max_missed_pongs_ = CPPHTTPLIB_WEBSOCKET_MAX_MISSED_PONGS;
  3185. int address_family_ = AF_UNSPEC;
  3186. bool tcp_nodelay_ = CPPHTTPLIB_TCP_NODELAY;
  3187. bool ipv6_v6only_ = CPPHTTPLIB_IPV6_V6ONLY;
  3188. SocketOptions socket_options_ = nullptr;
  3189. time_t connection_timeout_sec_ = CPPHTTPLIB_CONNECTION_TIMEOUT_SECOND;
  3190. time_t connection_timeout_usec_ = CPPHTTPLIB_CONNECTION_TIMEOUT_USECOND;
  3191. std::string interface_;
  3192. // Hostname-IP map
  3193. std::map<std::string, std::string> addr_map_;
  3194. #ifdef CPPHTTPLIB_SSL_ENABLED
  3195. bool is_ssl_ = false;
  3196. tls::ctx_t tls_ctx_ = nullptr;
  3197. tls::session_t tls_session_ = nullptr;
  3198. std::string ca_cert_file_path_;
  3199. bool custom_ca_loaded_ = false;
  3200. bool certs_loaded_ = false;
  3201. SystemCAMode system_ca_mode_ = SystemCAMode::Auto;
  3202. bool server_certificate_verification_ = true;
  3203. #endif
  3204. };
  3205. namespace impl {
  3206. bool is_valid_utf8(const std::string &s);
  3207. bool read_websocket_frame(Stream &strm, Opcode &opcode, std::string &payload,
  3208. bool &fin, bool expect_masked, size_t max_len);
  3209. } // namespace impl
  3210. } // namespace ws
  3211. // ----------------------------------------------------------------------------
  3212. /*
  3213. * Implementation that will be part of the .cc file if split into .h + .cc.
  3214. */
  3215. namespace stream {
  3216. // stream::Result implementations
  3217. inline Result::Result() : chunk_size_(8192) {}
  3218. inline Result::Result(ClientImpl::StreamHandle &&handle, size_t chunk_size)
  3219. : handle_(std::move(handle)), chunk_size_(chunk_size) {}
  3220. inline Result::Result(Result &&other) noexcept
  3221. : handle_(std::move(other.handle_)), buffer_(std::move(other.buffer_)),
  3222. current_size_(other.current_size_), chunk_size_(other.chunk_size_),
  3223. finished_(other.finished_) {
  3224. other.current_size_ = 0;
  3225. other.finished_ = true;
  3226. }
  3227. inline Result &Result::operator=(Result &&other) noexcept {
  3228. if (this != &other) {
  3229. handle_ = std::move(other.handle_);
  3230. buffer_ = std::move(other.buffer_);
  3231. current_size_ = other.current_size_;
  3232. chunk_size_ = other.chunk_size_;
  3233. finished_ = other.finished_;
  3234. other.current_size_ = 0;
  3235. other.finished_ = true;
  3236. }
  3237. return *this;
  3238. }
  3239. inline bool Result::is_valid() const { return handle_.is_valid(); }
  3240. inline Result::operator bool() const { return is_valid(); }
  3241. inline int Result::status() const {
  3242. return handle_.response ? handle_.response->status : -1;
  3243. }
  3244. inline const Headers &Result::headers() const {
  3245. static const Headers empty_headers;
  3246. return handle_.response ? handle_.response->headers : empty_headers;
  3247. }
  3248. inline std::string Result::get_header_value(const std::string &key,
  3249. const char *def) const {
  3250. return handle_.response ? handle_.response->get_header_value(key, def) : def;
  3251. }
  3252. inline bool Result::has_header(const std::string &key) const {
  3253. return handle_.response ? handle_.response->has_header(key) : false;
  3254. }
  3255. inline Error Result::error() const { return handle_.error; }
  3256. inline Error Result::read_error() const { return handle_.get_read_error(); }
  3257. inline bool Result::has_read_error() const { return handle_.has_read_error(); }
  3258. inline bool Result::next() {
  3259. if (!handle_.is_valid() || finished_) { return false; }
  3260. if (buffer_.size() < chunk_size_) { buffer_.resize(chunk_size_); }
  3261. ssize_t n = handle_.read(&buffer_[0], chunk_size_);
  3262. if (n > 0) {
  3263. current_size_ = static_cast<size_t>(n);
  3264. return true;
  3265. }
  3266. current_size_ = 0;
  3267. finished_ = true;
  3268. return false;
  3269. }
  3270. inline const char *Result::data() const { return buffer_.data(); }
  3271. inline size_t Result::size() const { return current_size_; }
  3272. inline std::string Result::read_all() {
  3273. std::string result;
  3274. while (next()) {
  3275. result.append(data(), size());
  3276. }
  3277. return result;
  3278. }
  3279. } // namespace stream
  3280. namespace sse {
  3281. // SSEMessage implementations
  3282. inline SSEMessage::SSEMessage() : event("message") {}
  3283. inline void SSEMessage::clear() {
  3284. event = "message";
  3285. data.clear();
  3286. id.clear();
  3287. }
  3288. // SSEClient implementations
  3289. inline SSEClient::SSEClient(Client &client, const std::string &path)
  3290. : client_(client), path_(path) {}
  3291. inline SSEClient::SSEClient(Client &client, const std::string &path,
  3292. const Headers &headers)
  3293. : client_(client), path_(path), headers_(headers) {}
  3294. inline SSEClient::~SSEClient() { stop(); }
  3295. inline SSEClient &SSEClient::on_message(MessageHandler handler) {
  3296. on_message_ = std::move(handler);
  3297. return *this;
  3298. }
  3299. inline SSEClient &SSEClient::on_event(const std::string &type,
  3300. MessageHandler handler) {
  3301. event_handlers_[type] = std::move(handler);
  3302. return *this;
  3303. }
  3304. inline SSEClient &SSEClient::on_open(OpenHandler handler) {
  3305. on_open_ = std::move(handler);
  3306. return *this;
  3307. }
  3308. inline SSEClient &SSEClient::on_error(ErrorHandler handler) {
  3309. on_error_ = std::move(handler);
  3310. return *this;
  3311. }
  3312. inline SSEClient &SSEClient::set_reconnect_interval(int ms) {
  3313. reconnect_interval_ms_ = ms;
  3314. return *this;
  3315. }
  3316. inline SSEClient &SSEClient::set_max_reconnect_attempts(int n) {
  3317. max_reconnect_attempts_ = n;
  3318. return *this;
  3319. }
  3320. inline SSEClient &SSEClient::set_headers(const Headers &headers) {
  3321. std::lock_guard<std::mutex> lock(headers_mutex_);
  3322. headers_ = headers;
  3323. return *this;
  3324. }
  3325. inline bool SSEClient::is_connected() const { return connected_.load(); }
  3326. inline const std::string &SSEClient::last_event_id() const {
  3327. return last_event_id_;
  3328. }
  3329. inline void SSEClient::start() {
  3330. running_.store(true);
  3331. run_event_loop();
  3332. }
  3333. inline void SSEClient::start_async() {
  3334. running_.store(true);
  3335. async_thread_ = std::thread([this]() { run_event_loop(); });
  3336. }
  3337. inline void SSEClient::stop() {
  3338. running_.store(false);
  3339. client_.stop(); // Cancel any pending operations
  3340. if (async_thread_.joinable()) { async_thread_.join(); }
  3341. }
  3342. inline bool SSEClient::parse_sse_line(const std::string &line, SSEMessage &msg,
  3343. int &retry_ms) {
  3344. // Blank line signals end of event
  3345. if (line.empty() || line == "\r") { return true; }
  3346. // Lines starting with ':' are comments (ignored)
  3347. if (!line.empty() && line[0] == ':') { return false; }
  3348. // Find the colon separator
  3349. auto colon_pos = line.find(':');
  3350. if (colon_pos == std::string::npos) {
  3351. // Line with no colon is treated as field name with empty value
  3352. return false;
  3353. }
  3354. auto field = line.substr(0, colon_pos);
  3355. std::string value;
  3356. // Value starts after colon, skip optional single space
  3357. if (colon_pos + 1 < line.size()) {
  3358. auto value_start = colon_pos + 1;
  3359. if (line[value_start] == ' ') { value_start++; }
  3360. value = line.substr(value_start);
  3361. // Remove trailing \r if present
  3362. if (!value.empty() && value.back() == '\r') { value.pop_back(); }
  3363. }
  3364. // Handle known fields
  3365. if (field == "event") {
  3366. msg.event = value;
  3367. } else if (field == "data") {
  3368. // Multiple data lines are concatenated with newlines
  3369. if (!msg.data.empty()) { msg.data += "\n"; }
  3370. msg.data += value;
  3371. } else if (field == "id") {
  3372. // Empty id is valid (clears the last event ID)
  3373. msg.id = value;
  3374. } else if (field == "retry") {
  3375. // Parse retry interval in milliseconds
  3376. {
  3377. int v = 0;
  3378. auto res =
  3379. detail::from_chars(value.data(), value.data() + value.size(), v);
  3380. if (res.ec == std::errc{}) { retry_ms = v; }
  3381. }
  3382. }
  3383. // Unknown fields are ignored per SSE spec
  3384. return false;
  3385. }
  3386. inline void SSEClient::run_event_loop() {
  3387. auto reconnect_count = 0;
  3388. while (running_.load()) {
  3389. // Build headers, including Last-Event-ID if we have one
  3390. Headers request_headers;
  3391. {
  3392. std::lock_guard<std::mutex> lock(headers_mutex_);
  3393. request_headers = headers_;
  3394. }
  3395. if (!last_event_id_.empty()) {
  3396. request_headers.emplace("Last-Event-ID", last_event_id_);
  3397. }
  3398. // Open streaming connection
  3399. auto result = stream::Get(client_, path_, request_headers);
  3400. // Connection error handling
  3401. if (!result) {
  3402. connected_.store(false);
  3403. if (on_error_) { on_error_(result.error()); }
  3404. if (!should_reconnect(reconnect_count)) { break; }
  3405. wait_for_reconnect();
  3406. reconnect_count++;
  3407. continue;
  3408. }
  3409. if (result.status() != StatusCode::OK_200) {
  3410. connected_.store(false);
  3411. if (on_error_) { on_error_(Error::Connection); }
  3412. // For certain errors, don't reconnect.
  3413. // Note: 401 is intentionally absent so that handlers can refresh
  3414. // credentials via set_headers() and let the client reconnect.
  3415. if (result.status() == StatusCode::NoContent_204 ||
  3416. result.status() == StatusCode::NotFound_404 ||
  3417. result.status() == StatusCode::Forbidden_403) {
  3418. break;
  3419. }
  3420. if (!should_reconnect(reconnect_count)) { break; }
  3421. wait_for_reconnect();
  3422. reconnect_count++;
  3423. continue;
  3424. }
  3425. // Connection successful
  3426. connected_.store(true);
  3427. reconnect_count = 0;
  3428. if (on_open_) { on_open_(); }
  3429. // Event receiving loop
  3430. std::string buffer;
  3431. SSEMessage current_msg;
  3432. while (running_.load() && result.next()) {
  3433. buffer.append(result.data(), result.size());
  3434. // Process complete lines in the buffer
  3435. size_t line_start = 0;
  3436. size_t newline_pos;
  3437. while ((newline_pos = buffer.find('\n', line_start)) !=
  3438. std::string::npos) {
  3439. auto line = buffer.substr(line_start, newline_pos - line_start);
  3440. line_start = newline_pos + 1;
  3441. // Parse the line and check if event is complete
  3442. auto event_complete =
  3443. parse_sse_line(line, current_msg, reconnect_interval_ms_);
  3444. if (event_complete && !current_msg.data.empty()) {
  3445. // Update last_event_id for reconnection
  3446. if (!current_msg.id.empty()) { last_event_id_ = current_msg.id; }
  3447. // Dispatch event to appropriate handler
  3448. dispatch_event(current_msg);
  3449. current_msg.clear();
  3450. }
  3451. }
  3452. // Keep unprocessed data in buffer
  3453. buffer.erase(0, line_start);
  3454. }
  3455. // Connection ended
  3456. connected_.store(false);
  3457. if (!running_.load()) { break; }
  3458. // Check for read errors
  3459. if (result.has_read_error()) {
  3460. if (on_error_) { on_error_(result.read_error()); }
  3461. }
  3462. if (!should_reconnect(reconnect_count)) { break; }
  3463. wait_for_reconnect();
  3464. reconnect_count++;
  3465. }
  3466. connected_.store(false);
  3467. }
  3468. inline void SSEClient::dispatch_event(const SSEMessage &msg) {
  3469. // Check for specific event type handler first
  3470. auto it = event_handlers_.find(msg.event);
  3471. if (it != event_handlers_.end()) {
  3472. it->second(msg);
  3473. return;
  3474. }
  3475. // Fall back to generic message handler
  3476. if (on_message_) { on_message_(msg); }
  3477. }
  3478. inline bool SSEClient::should_reconnect(int count) const {
  3479. if (!running_.load()) { return false; }
  3480. if (max_reconnect_attempts_ == 0) { return true; } // unlimited
  3481. return count < max_reconnect_attempts_;
  3482. }
  3483. inline void SSEClient::wait_for_reconnect() {
  3484. // Use small increments to check running_ flag frequently
  3485. auto waited = 0;
  3486. while (running_.load() && waited < reconnect_interval_ms_) {
  3487. std::this_thread::sleep_for(std::chrono::milliseconds(100));
  3488. waited += 100;
  3489. }
  3490. }
  3491. } // namespace sse
  3492. #ifdef CPPHTTPLIB_SSL_ENABLED
  3493. /*
  3494. * TLS abstraction layer - internal function declarations
  3495. * These are implementation details and not part of the public API.
  3496. */
  3497. namespace tls {
  3498. // Client context
  3499. ctx_t create_client_context();
  3500. void free_context(ctx_t ctx);
  3501. bool set_min_version(ctx_t ctx, Version version);
  3502. bool load_ca_pem(ctx_t ctx, const char *pem, size_t len);
  3503. bool load_ca_file(ctx_t ctx, const char *file_path);
  3504. bool load_ca_dir(ctx_t ctx, const char *dir_path);
  3505. bool load_system_certs(ctx_t ctx);
  3506. bool set_client_cert_pem(ctx_t ctx, const char *cert, const char *key,
  3507. const char *password);
  3508. bool set_client_cert_file(ctx_t ctx, const char *cert_path,
  3509. const char *key_path, const char *password);
  3510. // Server context
  3511. ctx_t create_server_context();
  3512. bool set_server_cert_pem(ctx_t ctx, const char *cert, const char *key,
  3513. const char *password);
  3514. bool set_server_cert_file(ctx_t ctx, const char *cert_path,
  3515. const char *key_path, const char *password);
  3516. bool set_client_ca_file(ctx_t ctx, const char *ca_file, const char *ca_dir);
  3517. void set_verify_client(ctx_t ctx, bool require);
  3518. // Session management
  3519. session_t create_session(ctx_t ctx, socket_t sock);
  3520. void free_session(session_t session);
  3521. bool set_sni(session_t session, const char *hostname);
  3522. bool set_hostname(session_t session, const char *hostname);
  3523. // Handshake (non-blocking capable)
  3524. TlsError connect(session_t session);
  3525. TlsError accept(session_t session);
  3526. // Handshake with timeout (blocking until timeout)
  3527. bool connect_nonblocking(session_t session, socket_t sock, time_t timeout_sec,
  3528. time_t timeout_usec, TlsError *err);
  3529. bool accept_nonblocking(session_t session, socket_t sock, time_t timeout_sec,
  3530. time_t timeout_usec, TlsError *err);
  3531. // I/O (non-blocking capable)
  3532. ssize_t read(session_t session, void *buf, size_t len, TlsError &err);
  3533. ssize_t write(session_t session, const void *buf, size_t len, TlsError &err);
  3534. int pending(const_session_t session);
  3535. void shutdown(session_t session, bool graceful);
  3536. // Connection state
  3537. bool is_peer_closed(session_t session, socket_t sock);
  3538. // Certificate verification
  3539. cert_t get_peer_cert(const_session_t session);
  3540. void free_cert(cert_t cert);
  3541. bool verify_hostname(cert_t cert, const char *hostname);
  3542. uint64_t hostname_mismatch_code();
  3543. long get_verify_result(const_session_t session);
  3544. // Certificate introspection
  3545. std::string get_cert_subject_cn(cert_t cert);
  3546. std::string get_cert_issuer_name(cert_t cert);
  3547. bool get_cert_sans(cert_t cert, std::vector<SanEntry> &sans);
  3548. bool get_cert_validity(cert_t cert, time_t &not_before, time_t &not_after);
  3549. std::string get_cert_serial(cert_t cert);
  3550. bool get_cert_der(cert_t cert, std::vector<unsigned char> &der);
  3551. const char *get_sni(const_session_t session);
  3552. // CA store management
  3553. ca_store_t create_ca_store(const char *pem, size_t len);
  3554. void free_ca_store(ca_store_t store);
  3555. bool set_ca_store(ctx_t ctx, ca_store_t store);
  3556. size_t get_ca_certs(ctx_t ctx, std::vector<cert_t> &certs);
  3557. std::vector<std::string> get_ca_names(ctx_t ctx);
  3558. // Dynamic certificate update (for servers)
  3559. bool update_server_cert(ctx_t ctx, const char *cert_pem, const char *key_pem,
  3560. const char *password);
  3561. bool update_server_client_ca(ctx_t ctx, const char *ca_pem);
  3562. // Certificate verification callback
  3563. bool set_verify_callback(ctx_t ctx, VerifyCallback callback);
  3564. long get_verify_error(const_session_t session);
  3565. std::string verify_error_string(long error_code);
  3566. // TlsError information
  3567. uint64_t peek_error();
  3568. uint64_t get_error();
  3569. std::string error_string(uint64_t code);
  3570. } // namespace tls
  3571. #endif // CPPHTTPLIB_SSL_ENABLED
  3572. /*
  3573. * Group 1: detail namespace - Non-SSL utilities
  3574. */
  3575. namespace detail {
  3576. inline bool set_socket_opt_impl(socket_t sock, int level, int optname,
  3577. const void *optval, socklen_t optlen) {
  3578. return setsockopt(sock, level, optname,
  3579. #ifdef _WIN32
  3580. reinterpret_cast<const char *>(optval),
  3581. #else
  3582. optval,
  3583. #endif
  3584. optlen) == 0;
  3585. }
  3586. inline bool set_socket_opt_time(socket_t sock, int level, int optname,
  3587. time_t sec, time_t usec) {
  3588. #ifdef _WIN32
  3589. auto timeout = static_cast<uint32_t>(sec * 1000 + usec / 1000);
  3590. #else
  3591. timeval timeout;
  3592. timeout.tv_sec = static_cast<long>(sec);
  3593. timeout.tv_usec = static_cast<decltype(timeout.tv_usec)>(usec);
  3594. #endif
  3595. return set_socket_opt_impl(sock, level, optname, &timeout, sizeof(timeout));
  3596. }
  3597. inline bool is_hex(char c, int &v) {
  3598. if (isdigit(static_cast<unsigned char>(c))) {
  3599. v = c - '0';
  3600. return true;
  3601. } else if ('A' <= c && c <= 'F') {
  3602. v = c - 'A' + 10;
  3603. return true;
  3604. } else if ('a' <= c && c <= 'f') {
  3605. v = c - 'a' + 10;
  3606. return true;
  3607. }
  3608. return false;
  3609. }
  3610. inline bool from_hex_to_i(const std::string &s, size_t i, size_t cnt,
  3611. int &val) {
  3612. if (i >= s.size()) { return false; }
  3613. val = 0;
  3614. for (; cnt; i++, cnt--) {
  3615. if (!s[i]) { return false; }
  3616. auto v = 0;
  3617. if (is_hex(s[i], v)) {
  3618. val = val * 16 + v;
  3619. } else {
  3620. return false;
  3621. }
  3622. }
  3623. return true;
  3624. }
  3625. inline std::string from_i_to_hex(size_t n) {
  3626. static const auto charset = "0123456789abcdef";
  3627. std::string ret;
  3628. do {
  3629. ret = charset[n & 15] + ret;
  3630. n >>= 4;
  3631. } while (n > 0);
  3632. return ret;
  3633. }
  3634. inline std::string compute_etag(const FileStat &fs) {
  3635. if (!fs.is_file()) { return std::string(); }
  3636. // If mtime cannot be determined (negative value indicates an error
  3637. // or sentinel), do not generate an ETag. Returning a neutral / fixed
  3638. // value like 0 could collide with a real file that legitimately has
  3639. // mtime == 0 (epoch) and lead to misleading validators.
  3640. auto mtime_raw = fs.mtime();
  3641. if (mtime_raw < 0) { return std::string(); }
  3642. auto mtime = static_cast<size_t>(mtime_raw);
  3643. auto size = fs.size();
  3644. return std::string("W/\"") + from_i_to_hex(mtime) + "-" +
  3645. from_i_to_hex(size) + "\"";
  3646. }
  3647. // Format time_t as HTTP-date (RFC 9110 Section 5.6.7): "Sun, 06 Nov 1994
  3648. // 08:49:37 GMT" This implementation is defensive: it validates `mtime`, checks
  3649. // return values from `gmtime_r`/`gmtime_s`, and ensures `strftime` succeeds.
  3650. inline std::string file_mtime_to_http_date(time_t mtime) {
  3651. if (mtime < 0) { return std::string(); }
  3652. struct tm tm_buf;
  3653. #ifdef _WIN32
  3654. if (gmtime_s(&tm_buf, &mtime) != 0) { return std::string(); }
  3655. #else
  3656. if (gmtime_r(&mtime, &tm_buf) == nullptr) { return std::string(); }
  3657. #endif
  3658. char buf[64];
  3659. if (strftime(buf, sizeof(buf), "%a, %d %b %Y %H:%M:%S GMT", &tm_buf) == 0) {
  3660. return std::string();
  3661. }
  3662. return std::string(buf);
  3663. }
  3664. // Parse HTTP-date (RFC 9110 Section 5.6.7) to time_t. Returns -1 on failure.
  3665. inline time_t parse_http_date(const std::string &date_str) {
  3666. struct tm tm_buf;
  3667. // Create a classic locale object once for all parsing attempts
  3668. const std::locale classic_locale = std::locale::classic();
  3669. // Try to parse using std::get_time (C++11, cross-platform)
  3670. auto try_parse = [&](const char *fmt) -> bool {
  3671. std::istringstream ss(date_str);
  3672. ss.imbue(classic_locale);
  3673. memset(&tm_buf, 0, sizeof(tm_buf));
  3674. ss >> std::get_time(&tm_buf, fmt);
  3675. return !ss.fail();
  3676. };
  3677. // RFC 9110 preferred format (HTTP-date): "Sun, 06 Nov 1994 08:49:37 GMT"
  3678. if (!try_parse("%a, %d %b %Y %H:%M:%S")) {
  3679. // RFC 850 format: "Sunday, 06-Nov-94 08:49:37 GMT"
  3680. if (!try_parse("%A, %d-%b-%y %H:%M:%S")) {
  3681. // asctime format: "Sun Nov 6 08:49:37 1994"
  3682. if (!try_parse("%a %b %d %H:%M:%S %Y")) {
  3683. return static_cast<time_t>(-1);
  3684. }
  3685. }
  3686. }
  3687. #ifdef _WIN32
  3688. return _mkgmtime(&tm_buf);
  3689. #elif defined _AIX
  3690. return mktime(&tm_buf);
  3691. #else
  3692. return timegm(&tm_buf);
  3693. #endif
  3694. }
  3695. inline bool is_weak_etag(const std::string &s) {
  3696. // Check if the string is a weak ETag (starts with 'W/"')
  3697. return s.size() > 3 && s[0] == 'W' && s[1] == '/' && s[2] == '"';
  3698. }
  3699. inline bool is_strong_etag(const std::string &s) {
  3700. // Check if the string is a strong ETag (starts and ends with '"', at least 2
  3701. // chars)
  3702. return s.size() >= 2 && s[0] == '"' && s.back() == '"';
  3703. }
  3704. inline size_t to_utf8(int code, char *buff) {
  3705. if (code < 0x0080) {
  3706. buff[0] = static_cast<char>(code & 0x7F);
  3707. return 1;
  3708. } else if (code < 0x0800) {
  3709. buff[0] = static_cast<char>(0xC0 | ((code >> 6) & 0x1F));
  3710. buff[1] = static_cast<char>(0x80 | (code & 0x3F));
  3711. return 2;
  3712. } else if (code < 0xD800) {
  3713. buff[0] = static_cast<char>(0xE0 | ((code >> 12) & 0xF));
  3714. buff[1] = static_cast<char>(0x80 | ((code >> 6) & 0x3F));
  3715. buff[2] = static_cast<char>(0x80 | (code & 0x3F));
  3716. return 3;
  3717. } else if (code < 0xE000) { // D800 - DFFF is invalid...
  3718. return 0;
  3719. } else if (code < 0x10000) {
  3720. buff[0] = static_cast<char>(0xE0 | ((code >> 12) & 0xF));
  3721. buff[1] = static_cast<char>(0x80 | ((code >> 6) & 0x3F));
  3722. buff[2] = static_cast<char>(0x80 | (code & 0x3F));
  3723. return 3;
  3724. } else if (code < 0x110000) {
  3725. buff[0] = static_cast<char>(0xF0 | ((code >> 18) & 0x7));
  3726. buff[1] = static_cast<char>(0x80 | ((code >> 12) & 0x3F));
  3727. buff[2] = static_cast<char>(0x80 | ((code >> 6) & 0x3F));
  3728. buff[3] = static_cast<char>(0x80 | (code & 0x3F));
  3729. return 4;
  3730. }
  3731. // NOTREACHED
  3732. return 0;
  3733. }
  3734. } // namespace detail
  3735. namespace ws {
  3736. namespace impl {
  3737. inline bool is_valid_utf8(const std::string &s) {
  3738. size_t i = 0;
  3739. auto n = s.size();
  3740. while (i < n) {
  3741. auto c = static_cast<unsigned char>(s[i]);
  3742. size_t len;
  3743. uint32_t cp;
  3744. if (c < 0x80) {
  3745. i++;
  3746. continue;
  3747. } else if ((c & 0xE0) == 0xC0) {
  3748. len = 2;
  3749. cp = c & 0x1F;
  3750. } else if ((c & 0xF0) == 0xE0) {
  3751. len = 3;
  3752. cp = c & 0x0F;
  3753. } else if ((c & 0xF8) == 0xF0) {
  3754. len = 4;
  3755. cp = c & 0x07;
  3756. } else {
  3757. return false;
  3758. }
  3759. if (i + len > n) { return false; }
  3760. for (size_t j = 1; j < len; j++) {
  3761. auto b = static_cast<unsigned char>(s[i + j]);
  3762. if ((b & 0xC0) != 0x80) { return false; }
  3763. cp = (cp << 6) | (b & 0x3F);
  3764. }
  3765. // Overlong encoding check
  3766. if (len == 2 && cp < 0x80) { return false; }
  3767. if (len == 3 && cp < 0x800) { return false; }
  3768. if (len == 4 && cp < 0x10000) { return false; }
  3769. // Surrogate halves (U+D800..U+DFFF) and beyond U+10FFFF are invalid
  3770. if (cp >= 0xD800 && cp <= 0xDFFF) { return false; }
  3771. if (cp > 0x10FFFF) { return false; }
  3772. i += len;
  3773. }
  3774. return true;
  3775. }
  3776. } // namespace impl
  3777. } // namespace ws
  3778. namespace detail {
  3779. // NOTE: This code came up with the following stackoverflow post:
  3780. // https://stackoverflow.com/questions/180947/base64-decode-snippet-in-c
  3781. inline std::string base64_encode(const std::string &in) {
  3782. static const auto lookup =
  3783. "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
  3784. std::string out;
  3785. out.reserve(in.size());
  3786. auto val = 0;
  3787. auto valb = -6;
  3788. for (auto c : in) {
  3789. val = (val << 8) + static_cast<uint8_t>(c);
  3790. valb += 8;
  3791. while (valb >= 0) {
  3792. out.push_back(lookup[(val >> valb) & 0x3F]);
  3793. valb -= 6;
  3794. }
  3795. }
  3796. if (valb > -6) { out.push_back(lookup[((val << 8) >> (valb + 8)) & 0x3F]); }
  3797. while (out.size() % 4) {
  3798. out.push_back('=');
  3799. }
  3800. return out;
  3801. }
  3802. inline std::string sha1(const std::string &input) {
  3803. // RFC 3174 SHA-1 implementation
  3804. auto left_rotate = [](uint32_t x, uint32_t n) -> uint32_t {
  3805. return (x << n) | (x >> (32 - n));
  3806. };
  3807. uint32_t h0 = 0x67452301;
  3808. uint32_t h1 = 0xEFCDAB89;
  3809. uint32_t h2 = 0x98BADCFE;
  3810. uint32_t h3 = 0x10325476;
  3811. uint32_t h4 = 0xC3D2E1F0;
  3812. // Pre-processing: adding padding bits
  3813. std::string msg = input;
  3814. uint64_t original_bit_len = static_cast<uint64_t>(msg.size()) * 8;
  3815. msg.push_back(static_cast<char>(0x80u));
  3816. while (msg.size() % 64 != 56) {
  3817. msg.push_back(0);
  3818. }
  3819. // Append original length in bits as 64-bit big-endian
  3820. for (int i = 56; i >= 0; i -= 8) {
  3821. msg.push_back(static_cast<char>((original_bit_len >> i) & 0xFF));
  3822. }
  3823. // Process each 512-bit chunk
  3824. for (size_t offset = 0; offset < msg.size(); offset += 64) {
  3825. uint32_t w[80];
  3826. for (size_t i = 0; i < 16; i++) {
  3827. w[i] =
  3828. (static_cast<uint32_t>(static_cast<uint8_t>(msg[offset + i * 4]))
  3829. << 24) |
  3830. (static_cast<uint32_t>(static_cast<uint8_t>(msg[offset + i * 4 + 1]))
  3831. << 16) |
  3832. (static_cast<uint32_t>(static_cast<uint8_t>(msg[offset + i * 4 + 2]))
  3833. << 8) |
  3834. (static_cast<uint32_t>(
  3835. static_cast<uint8_t>(msg[offset + i * 4 + 3])));
  3836. }
  3837. for (int i = 16; i < 80; i++) {
  3838. w[i] = left_rotate(w[i - 3] ^ w[i - 8] ^ w[i - 14] ^ w[i - 16], 1);
  3839. }
  3840. uint32_t a = h0, b = h1, c = h2, d = h3, e = h4;
  3841. for (int i = 0; i < 80; i++) {
  3842. uint32_t f, k;
  3843. if (i < 20) {
  3844. f = (b & c) | ((~b) & d);
  3845. k = 0x5A827999;
  3846. } else if (i < 40) {
  3847. f = b ^ c ^ d;
  3848. k = 0x6ED9EBA1;
  3849. } else if (i < 60) {
  3850. f = (b & c) | (b & d) | (c & d);
  3851. k = 0x8F1BBCDC;
  3852. } else {
  3853. f = b ^ c ^ d;
  3854. k = 0xCA62C1D6;
  3855. }
  3856. uint32_t temp = left_rotate(a, 5) + f + e + k + w[i];
  3857. e = d;
  3858. d = c;
  3859. c = left_rotate(b, 30);
  3860. b = a;
  3861. a = temp;
  3862. }
  3863. h0 += a;
  3864. h1 += b;
  3865. h2 += c;
  3866. h3 += d;
  3867. h4 += e;
  3868. }
  3869. // Produce the final hash as a 20-byte binary string
  3870. std::string hash(20, '\0');
  3871. for (size_t i = 0; i < 4; i++) {
  3872. hash[i] = static_cast<char>((h0 >> (24 - i * 8)) & 0xFF);
  3873. hash[4 + i] = static_cast<char>((h1 >> (24 - i * 8)) & 0xFF);
  3874. hash[8 + i] = static_cast<char>((h2 >> (24 - i * 8)) & 0xFF);
  3875. hash[12 + i] = static_cast<char>((h3 >> (24 - i * 8)) & 0xFF);
  3876. hash[16 + i] = static_cast<char>((h4 >> (24 - i * 8)) & 0xFF);
  3877. }
  3878. return hash;
  3879. }
  3880. inline std::string websocket_accept_key(const std::string &client_key) {
  3881. const std::string magic = "258EAFA5-E914-47DA-95CA-C5AB0DC85B11";
  3882. return base64_encode(sha1(client_key + magic));
  3883. }
  3884. inline bool is_websocket_upgrade(const Request &req) {
  3885. if (req.method != "GET") { return false; }
  3886. // Check Upgrade: websocket (case-insensitive)
  3887. auto upgrade_it = req.headers.find("Upgrade");
  3888. if (upgrade_it == req.headers.end()) { return false; }
  3889. auto upgrade_val = case_ignore::to_lower(upgrade_it->second);
  3890. if (upgrade_val != "websocket") { return false; }
  3891. // Check Connection header contains "Upgrade"
  3892. auto connection_it = req.headers.find("Connection");
  3893. if (connection_it == req.headers.end()) { return false; }
  3894. auto connection_val = case_ignore::to_lower(connection_it->second);
  3895. if (connection_val.find("upgrade") == std::string::npos) { return false; }
  3896. // Check Sec-WebSocket-Key is a valid base64-encoded 16-byte value (24 chars)
  3897. // RFC 6455 Section 4.2.1
  3898. auto ws_key = req.get_header_value("Sec-WebSocket-Key");
  3899. if (ws_key.size() != 24 || ws_key[22] != '=' || ws_key[23] != '=') {
  3900. return false;
  3901. }
  3902. static const std::string b64chars =
  3903. "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
  3904. for (size_t i = 0; i < 22; i++) {
  3905. if (b64chars.find(ws_key[i]) == std::string::npos) { return false; }
  3906. }
  3907. // Check Sec-WebSocket-Version: 13
  3908. auto version = req.get_header_value("Sec-WebSocket-Version");
  3909. if (version != "13") { return false; }
  3910. return true;
  3911. }
  3912. inline bool write_websocket_frame(Stream &strm, ws::Opcode opcode,
  3913. const char *data, size_t len, bool fin,
  3914. bool mask) {
  3915. // First byte: FIN + opcode
  3916. uint8_t header[2];
  3917. header[0] = static_cast<uint8_t>((fin ? 0x80 : 0x00) |
  3918. (static_cast<uint8_t>(opcode) & 0x0F));
  3919. // Second byte: MASK + payload length
  3920. if (len < 126) {
  3921. header[1] = static_cast<uint8_t>(len);
  3922. if (mask) { header[1] |= 0x80; }
  3923. if (strm.write(reinterpret_cast<char *>(header), 2) < 0) { return false; }
  3924. } else if (len <= 0xFFFF) {
  3925. header[1] = 126;
  3926. if (mask) { header[1] |= 0x80; }
  3927. if (strm.write(reinterpret_cast<char *>(header), 2) < 0) { return false; }
  3928. uint8_t ext[2];
  3929. ext[0] = static_cast<uint8_t>((len >> 8) & 0xFF);
  3930. ext[1] = static_cast<uint8_t>(len & 0xFF);
  3931. if (strm.write(reinterpret_cast<char *>(ext), 2) < 0) { return false; }
  3932. } else {
  3933. header[1] = 127;
  3934. if (mask) { header[1] |= 0x80; }
  3935. if (strm.write(reinterpret_cast<char *>(header), 2) < 0) { return false; }
  3936. uint8_t ext[8];
  3937. for (int i = 7; i >= 0; i--) {
  3938. ext[7 - i] =
  3939. static_cast<uint8_t>((static_cast<uint64_t>(len) >> (i * 8)) & 0xFF);
  3940. }
  3941. if (strm.write(reinterpret_cast<char *>(ext), 8) < 0) { return false; }
  3942. }
  3943. if (mask) {
  3944. // Generate random mask key
  3945. thread_local std::mt19937 rng(std::random_device{}());
  3946. uint8_t mask_key[4];
  3947. auto r = rng();
  3948. std::memcpy(mask_key, &r, 4);
  3949. if (strm.write(reinterpret_cast<char *>(mask_key), 4) < 0) { return false; }
  3950. // Write masked payload in chunks
  3951. const size_t chunk_size = 4096;
  3952. std::vector<char> buf((std::min)(len, chunk_size));
  3953. for (size_t offset = 0; offset < len; offset += chunk_size) {
  3954. size_t n = (std::min)(chunk_size, len - offset);
  3955. for (size_t i = 0; i < n; i++) {
  3956. buf[i] =
  3957. data[offset + i] ^ static_cast<char>(mask_key[(offset + i) % 4]);
  3958. }
  3959. if (strm.write(buf.data(), n) < 0) { return false; }
  3960. }
  3961. } else {
  3962. if (len > 0) {
  3963. if (strm.write(data, len) < 0) { return false; }
  3964. }
  3965. }
  3966. return true;
  3967. }
  3968. } // namespace detail
  3969. namespace ws {
  3970. namespace impl {
  3971. inline bool read_websocket_frame(Stream &strm, Opcode &opcode,
  3972. std::string &payload, bool &fin,
  3973. bool expect_masked, size_t max_len) {
  3974. // Read first 2 bytes
  3975. uint8_t header[2];
  3976. if (strm.read(reinterpret_cast<char *>(header), 2) != 2) { return false; }
  3977. fin = (header[0] & 0x80) != 0;
  3978. // RSV1, RSV2, RSV3 must be 0 when no extension is negotiated
  3979. if (header[0] & 0x70) { return false; }
  3980. opcode = static_cast<Opcode>(header[0] & 0x0F);
  3981. bool masked = (header[1] & 0x80) != 0;
  3982. uint64_t payload_len = header[1] & 0x7F;
  3983. // RFC 6455 Section 5.5: control frames MUST NOT be fragmented and
  3984. // MUST have a payload length of 125 bytes or less
  3985. bool is_control = (static_cast<uint8_t>(opcode) & 0x08) != 0;
  3986. if (is_control) {
  3987. if (!fin) { return false; }
  3988. if (payload_len > 125) { return false; }
  3989. }
  3990. if (masked != expect_masked) { return false; }
  3991. // Extended payload length
  3992. if (payload_len == 126) {
  3993. uint8_t ext[2];
  3994. if (strm.read(reinterpret_cast<char *>(ext), 2) != 2) { return false; }
  3995. payload_len = (static_cast<uint64_t>(ext[0]) << 8) | ext[1];
  3996. } else if (payload_len == 127) {
  3997. uint8_t ext[8];
  3998. if (strm.read(reinterpret_cast<char *>(ext), 8) != 8) { return false; }
  3999. // RFC 6455 Section 5.2: the most significant bit MUST be 0
  4000. if (ext[0] & 0x80) { return false; }
  4001. payload_len = 0;
  4002. for (int i = 0; i < 8; i++) {
  4003. payload_len = (payload_len << 8) | ext[i];
  4004. }
  4005. }
  4006. if (payload_len > max_len) { return false; }
  4007. // Read mask key if present
  4008. uint8_t mask_key[4] = {0};
  4009. if (masked) {
  4010. if (strm.read(reinterpret_cast<char *>(mask_key), 4) != 4) { return false; }
  4011. }
  4012. // Read payload
  4013. payload.resize(static_cast<size_t>(payload_len));
  4014. if (payload_len > 0) {
  4015. size_t total_read = 0;
  4016. while (total_read < payload_len) {
  4017. auto n = strm.read(&payload[total_read],
  4018. static_cast<size_t>(payload_len - total_read));
  4019. if (n <= 0) { return false; }
  4020. total_read += static_cast<size_t>(n);
  4021. }
  4022. }
  4023. // Unmask if needed
  4024. if (masked) {
  4025. for (size_t i = 0; i < payload.size(); i++) {
  4026. payload[i] ^= static_cast<char>(mask_key[i % 4]);
  4027. }
  4028. }
  4029. return true;
  4030. }
  4031. } // namespace impl
  4032. } // namespace ws
  4033. namespace detail {
  4034. inline bool is_valid_path(const std::string &path) {
  4035. size_t level = 0;
  4036. size_t i = 0;
  4037. // Skip slash
  4038. while (i < path.size() && path[i] == '/') {
  4039. i++;
  4040. }
  4041. while (i < path.size()) {
  4042. // Read component
  4043. auto beg = i;
  4044. while (i < path.size() && path[i] != '/') {
  4045. if (path[i] == '\0') {
  4046. return false;
  4047. } else if (path[i] == '\\') {
  4048. return false;
  4049. }
  4050. i++;
  4051. }
  4052. auto len = i - beg;
  4053. assert(len > 0);
  4054. if (!path.compare(beg, len, ".")) {
  4055. ;
  4056. } else if (!path.compare(beg, len, "..")) {
  4057. if (level == 0) { return false; }
  4058. level--;
  4059. } else {
  4060. level++;
  4061. }
  4062. // Skip slash
  4063. while (i < path.size() && path[i] == '/') {
  4064. i++;
  4065. }
  4066. }
  4067. return true;
  4068. }
  4069. inline bool canonicalize_path(const char *path, std::string &resolved) {
  4070. #if defined(_WIN32)
  4071. char buf[_MAX_PATH];
  4072. if (_fullpath(buf, path, _MAX_PATH) == nullptr) { return false; }
  4073. resolved = buf;
  4074. #elif defined(PATH_MAX)
  4075. char buf[PATH_MAX];
  4076. if (realpath(path, buf) == nullptr) { return false; }
  4077. resolved = buf;
  4078. #else
  4079. auto buf = realpath(path, nullptr);
  4080. auto guard = scope_exit([&]() { std::free(buf); });
  4081. if (buf == nullptr) { return false; }
  4082. resolved = buf;
  4083. #endif
  4084. return true;
  4085. }
  4086. inline bool is_path_within_base(const std::string &resolved_path,
  4087. const std::string &resolved_base) {
  4088. #if defined(_WIN32)
  4089. return _strnicmp(resolved_path.c_str(), resolved_base.c_str(),
  4090. resolved_base.size()) == 0;
  4091. #else
  4092. return strncmp(resolved_path.c_str(), resolved_base.c_str(),
  4093. resolved_base.size()) == 0;
  4094. #endif
  4095. }
  4096. inline FileStat::FileStat(const std::string &path) {
  4097. #if defined(_WIN32)
  4098. auto wpath = u8string_to_wstring(path.c_str());
  4099. ret_ = _wstat(wpath.c_str(), &st_);
  4100. #else
  4101. ret_ = stat(path.c_str(), &st_);
  4102. #endif
  4103. }
  4104. inline bool FileStat::is_file() const {
  4105. return ret_ >= 0 && S_ISREG(st_.st_mode);
  4106. }
  4107. inline bool FileStat::is_dir() const {
  4108. return ret_ >= 0 && S_ISDIR(st_.st_mode);
  4109. }
  4110. inline time_t FileStat::mtime() const {
  4111. return ret_ >= 0 ? static_cast<time_t>(st_.st_mtime)
  4112. : static_cast<time_t>(-1);
  4113. }
  4114. inline size_t FileStat::size() const {
  4115. return ret_ >= 0 ? static_cast<size_t>(st_.st_size) : 0;
  4116. }
  4117. inline std::string encode_path(const std::string &s) {
  4118. std::string result;
  4119. result.reserve(s.size());
  4120. for (size_t i = 0; s[i]; i++) {
  4121. switch (s[i]) {
  4122. case ' ': result += "%20"; break;
  4123. case '+': result += "%2B"; break;
  4124. case '\r': result += "%0D"; break;
  4125. case '\n': result += "%0A"; break;
  4126. case '\'': result += "%27"; break;
  4127. case ',': result += "%2C"; break;
  4128. // case ':': result += "%3A"; break; // ok? probably...
  4129. case ';': result += "%3B"; break;
  4130. default:
  4131. auto c = static_cast<uint8_t>(s[i]);
  4132. if (c >= 0x80) {
  4133. result += '%';
  4134. char hex[4];
  4135. auto len = snprintf(hex, sizeof(hex) - 1, "%02X", c);
  4136. assert(len == 2);
  4137. result.append(hex, static_cast<size_t>(len));
  4138. } else {
  4139. result += s[i];
  4140. }
  4141. break;
  4142. }
  4143. }
  4144. return result;
  4145. }
  4146. inline std::string file_extension(const std::string &path) {
  4147. std::smatch m;
  4148. thread_local auto re = std::regex("\\.([a-zA-Z0-9]+)$");
  4149. if (std::regex_search(path, m, re)) { return m[1].str(); }
  4150. return std::string();
  4151. }
  4152. inline bool is_space_or_tab(char c) { return c == ' ' || c == '\t'; }
  4153. template <typename T>
  4154. inline bool parse_header(const char *beg, const char *end, T fn);
  4155. template <typename T>
  4156. inline bool parse_header(const char *beg, const char *end, T fn) {
  4157. // Skip trailing spaces and tabs.
  4158. while (beg < end && is_space_or_tab(end[-1])) {
  4159. end--;
  4160. }
  4161. auto p = beg;
  4162. while (p < end && *p != ':') {
  4163. p++;
  4164. }
  4165. auto name = std::string(beg, p);
  4166. if (!detail::fields::is_field_name(name)) { return false; }
  4167. if (p == end) { return false; }
  4168. auto key_end = p;
  4169. if (*p++ != ':') { return false; }
  4170. while (p < end && is_space_or_tab(*p)) {
  4171. p++;
  4172. }
  4173. if (p <= end) {
  4174. auto key_len = key_end - beg;
  4175. if (!key_len) { return false; }
  4176. auto key = std::string(beg, key_end);
  4177. auto val = std::string(p, end);
  4178. if (!detail::fields::is_field_value(val)) { return false; }
  4179. // RFC 9110 §5.5: header field values are opaque octets and MUST NOT be
  4180. // percent-decoded by the recipient. Applications that need to interpret a
  4181. // value as a URI component should call httplib::decode_uri_component()
  4182. // (or decode_path_component()) explicitly.
  4183. fn(key, val);
  4184. return true;
  4185. }
  4186. return false;
  4187. }
  4188. inline bool parse_trailers(stream_line_reader &line_reader, Headers &dest,
  4189. const Headers &src_headers) {
  4190. // NOTE: In RFC 9112, '7.1 Chunked Transfer Coding' mentions "The chunked
  4191. // transfer coding is complete when a chunk with a chunk-size of zero is
  4192. // received, possibly followed by a trailer section, and finally terminated by
  4193. // an empty line". https://www.rfc-editor.org/rfc/rfc9112.html#section-7.1
  4194. //
  4195. // In '7.1.3. Decoding Chunked', however, the pseudo-code in the section
  4196. // doesn't care for the existence of the final CRLF. In other words, it seems
  4197. // to be ok whether the final CRLF exists or not in the chunked data.
  4198. // https://www.rfc-editor.org/rfc/rfc9112.html#section-7.1.3
  4199. //
  4200. // According to the reference code in RFC 9112, cpp-httplib now allows
  4201. // chunked transfer coding data without the final CRLF.
  4202. // RFC 7230 Section 4.1.2 - Headers prohibited in trailers
  4203. thread_local case_ignore::unordered_set<std::string> prohibited_trailers = {
  4204. "transfer-encoding",
  4205. "content-length",
  4206. "host",
  4207. "authorization",
  4208. "www-authenticate",
  4209. "proxy-authenticate",
  4210. "proxy-authorization",
  4211. "cookie",
  4212. "set-cookie",
  4213. "cache-control",
  4214. "expect",
  4215. "max-forwards",
  4216. "pragma",
  4217. "range",
  4218. "te",
  4219. "age",
  4220. "expires",
  4221. "date",
  4222. "location",
  4223. "retry-after",
  4224. "vary",
  4225. "warning",
  4226. "content-encoding",
  4227. "content-type",
  4228. "content-range",
  4229. "trailer"};
  4230. case_ignore::unordered_set<std::string> declared_trailers;
  4231. auto trailer_header = get_header_value(src_headers, "Trailer", "", 0);
  4232. if (trailer_header && std::strlen(trailer_header)) {
  4233. auto len = std::strlen(trailer_header);
  4234. split(trailer_header, trailer_header + len, ',',
  4235. [&](const char *b, const char *e) {
  4236. const char *kbeg = b;
  4237. const char *kend = e;
  4238. while (kbeg < kend && (*kbeg == ' ' || *kbeg == '\t')) {
  4239. ++kbeg;
  4240. }
  4241. while (kend > kbeg && (kend[-1] == ' ' || kend[-1] == '\t')) {
  4242. --kend;
  4243. }
  4244. std::string key(kbeg, static_cast<size_t>(kend - kbeg));
  4245. if (!key.empty() &&
  4246. prohibited_trailers.find(key) == prohibited_trailers.end()) {
  4247. declared_trailers.insert(key);
  4248. }
  4249. });
  4250. }
  4251. size_t trailer_header_count = 0;
  4252. while (strcmp(line_reader.ptr(), "\r\n") != 0) {
  4253. if (line_reader.size() > CPPHTTPLIB_HEADER_MAX_LENGTH) { return false; }
  4254. if (trailer_header_count >= CPPHTTPLIB_HEADER_MAX_COUNT) { return false; }
  4255. constexpr auto line_terminator_len = 2;
  4256. auto line_beg = line_reader.ptr();
  4257. auto line_end =
  4258. line_reader.ptr() + line_reader.size() - line_terminator_len;
  4259. if (!parse_header(line_beg, line_end,
  4260. [&](const std::string &key, const std::string &val) {
  4261. if (declared_trailers.find(key) !=
  4262. declared_trailers.end()) {
  4263. dest.emplace(key, val);
  4264. trailer_header_count++;
  4265. }
  4266. })) {
  4267. return false;
  4268. }
  4269. if (!line_reader.getline()) { return false; }
  4270. }
  4271. return true;
  4272. }
  4273. inline std::pair<size_t, size_t> trim(const char *b, const char *e, size_t left,
  4274. size_t right) {
  4275. while (b + left < e && is_space_or_tab(b[left])) {
  4276. left++;
  4277. }
  4278. while (right > 0 && is_space_or_tab(b[right - 1])) {
  4279. right--;
  4280. }
  4281. return std::make_pair(left, right);
  4282. }
  4283. inline std::string trim_copy(const std::string &s) {
  4284. auto r = trim(s.data(), s.data() + s.size(), 0, s.size());
  4285. return s.substr(r.first, r.second - r.first);
  4286. }
  4287. inline std::string trim_double_quotes_copy(const std::string &s) {
  4288. if (s.length() >= 2 && s.front() == '"' && s.back() == '"') {
  4289. return s.substr(1, s.size() - 2);
  4290. }
  4291. return s;
  4292. }
  4293. inline void
  4294. divide(const char *data, std::size_t size, char d,
  4295. std::function<void(const char *, std::size_t, const char *, std::size_t)>
  4296. fn) {
  4297. const auto it = std::find(data, data + size, d);
  4298. const auto found = static_cast<std::size_t>(it != data + size);
  4299. const auto lhs_data = data;
  4300. const auto lhs_size = static_cast<std::size_t>(it - data);
  4301. const auto rhs_data = it + found;
  4302. const auto rhs_size = size - lhs_size - found;
  4303. fn(lhs_data, lhs_size, rhs_data, rhs_size);
  4304. }
  4305. inline void
  4306. divide(const std::string &str, char d,
  4307. std::function<void(const char *, std::size_t, const char *, std::size_t)>
  4308. fn) {
  4309. divide(str.data(), str.size(), d, std::move(fn));
  4310. }
  4311. inline void split(const char *b, const char *e, char d,
  4312. std::function<void(const char *, const char *)> fn) {
  4313. return split(b, e, d, (std::numeric_limits<size_t>::max)(), std::move(fn));
  4314. }
  4315. inline void split(const char *b, const char *e, char d, size_t m,
  4316. std::function<void(const char *, const char *)> fn) {
  4317. size_t i = 0;
  4318. size_t beg = 0;
  4319. size_t count = 1;
  4320. while (e ? (b + i < e) : (b[i] != '\0')) {
  4321. if (b[i] == d && count < m) {
  4322. auto r = trim(b, e, beg, i);
  4323. if (r.first < r.second) { fn(&b[r.first], &b[r.second]); }
  4324. beg = i + 1;
  4325. count++;
  4326. }
  4327. i++;
  4328. }
  4329. if (i) {
  4330. auto r = trim(b, e, beg, i);
  4331. if (r.first < r.second) { fn(&b[r.first], &b[r.second]); }
  4332. }
  4333. }
  4334. inline bool split_find(const char *b, const char *e, char d, size_t m,
  4335. std::function<bool(const char *, const char *)> fn) {
  4336. size_t i = 0;
  4337. size_t beg = 0;
  4338. size_t count = 1;
  4339. while (e ? (b + i < e) : (b[i] != '\0')) {
  4340. if (b[i] == d && count < m) {
  4341. auto r = trim(b, e, beg, i);
  4342. if (r.first < r.second) {
  4343. auto found = fn(&b[r.first], &b[r.second]);
  4344. if (found) { return true; }
  4345. }
  4346. beg = i + 1;
  4347. count++;
  4348. }
  4349. i++;
  4350. }
  4351. if (i) {
  4352. auto r = trim(b, e, beg, i);
  4353. if (r.first < r.second) {
  4354. auto found = fn(&b[r.first], &b[r.second]);
  4355. if (found) { return true; }
  4356. }
  4357. }
  4358. return false;
  4359. }
  4360. inline bool split_find(const char *b, const char *e, char d,
  4361. std::function<bool(const char *, const char *)> fn) {
  4362. return split_find(b, e, d, (std::numeric_limits<size_t>::max)(),
  4363. std::move(fn));
  4364. }
  4365. inline stream_line_reader::stream_line_reader(Stream &strm, char *fixed_buffer,
  4366. size_t fixed_buffer_size)
  4367. : strm_(strm), fixed_buffer_(fixed_buffer),
  4368. fixed_buffer_size_(fixed_buffer_size) {}
  4369. inline const char *stream_line_reader::ptr() const {
  4370. if (growable_buffer_.empty()) {
  4371. return fixed_buffer_;
  4372. } else {
  4373. return growable_buffer_.data();
  4374. }
  4375. }
  4376. inline size_t stream_line_reader::size() const {
  4377. if (growable_buffer_.empty()) {
  4378. return fixed_buffer_used_size_;
  4379. } else {
  4380. return growable_buffer_.size();
  4381. }
  4382. }
  4383. inline bool stream_line_reader::end_with_crlf() const {
  4384. auto end = ptr() + size();
  4385. return size() >= 2 && end[-2] == '\r' && end[-1] == '\n';
  4386. }
  4387. inline bool stream_line_reader::getline() {
  4388. fixed_buffer_used_size_ = 0;
  4389. growable_buffer_.clear();
  4390. #ifndef CPPHTTPLIB_ALLOW_LF_AS_LINE_TERMINATOR
  4391. char prev_byte = 0;
  4392. #endif
  4393. for (size_t i = 0;; i++) {
  4394. if (size() >= CPPHTTPLIB_MAX_LINE_LENGTH) {
  4395. // Treat exceptionally long lines as an error to
  4396. // prevent infinite loops/memory exhaustion
  4397. return false;
  4398. }
  4399. char byte;
  4400. auto n = strm_.read(&byte, 1);
  4401. if (n < 0) {
  4402. return false;
  4403. } else if (n == 0) {
  4404. if (i == 0) {
  4405. return false;
  4406. } else {
  4407. break;
  4408. }
  4409. }
  4410. append(byte);
  4411. #ifdef CPPHTTPLIB_ALLOW_LF_AS_LINE_TERMINATOR
  4412. if (byte == '\n') { break; }
  4413. #else
  4414. if (prev_byte == '\r' && byte == '\n') { break; }
  4415. prev_byte = byte;
  4416. #endif
  4417. }
  4418. return true;
  4419. }
  4420. inline void stream_line_reader::append(char c) {
  4421. if (fixed_buffer_used_size_ < fixed_buffer_size_ - 1) {
  4422. fixed_buffer_[fixed_buffer_used_size_++] = c;
  4423. fixed_buffer_[fixed_buffer_used_size_] = '\0';
  4424. } else {
  4425. if (growable_buffer_.empty()) {
  4426. assert(fixed_buffer_[fixed_buffer_used_size_] == '\0');
  4427. growable_buffer_.assign(fixed_buffer_, fixed_buffer_used_size_);
  4428. }
  4429. growable_buffer_ += c;
  4430. }
  4431. }
  4432. inline mmap::mmap(const char *path) { open(path); }
  4433. inline mmap::~mmap() { close(); }
  4434. inline bool mmap::open(const char *path) {
  4435. close();
  4436. #if defined(_WIN32)
  4437. auto wpath = u8string_to_wstring(path);
  4438. if (wpath.empty()) { return false; }
  4439. hFile_ =
  4440. ::CreateFile2(wpath.c_str(), GENERIC_READ,
  4441. FILE_SHARE_READ | FILE_SHARE_WRITE, OPEN_EXISTING, NULL);
  4442. if (hFile_ == INVALID_HANDLE_VALUE) { return false; }
  4443. LARGE_INTEGER size{};
  4444. if (!::GetFileSizeEx(hFile_, &size)) { return false; }
  4445. // If the following line doesn't compile due to QuadPart, update Windows SDK.
  4446. // See:
  4447. // https://github.com/yhirose/cpp-httplib/issues/1903#issuecomment-2316520721
  4448. if (static_cast<ULONGLONG>(size.QuadPart) >
  4449. (std::numeric_limits<decltype(size_)>::max)()) {
  4450. // `size_t` might be 32-bits, on 32-bits Windows.
  4451. return false;
  4452. }
  4453. size_ = static_cast<size_t>(size.QuadPart);
  4454. hMapping_ =
  4455. ::CreateFileMappingFromApp(hFile_, NULL, PAGE_READONLY, size_, NULL);
  4456. // Special treatment for an empty file...
  4457. if (hMapping_ == NULL && size_ == 0) {
  4458. close();
  4459. is_open_empty_file = true;
  4460. return true;
  4461. }
  4462. if (hMapping_ == NULL) {
  4463. close();
  4464. return false;
  4465. }
  4466. addr_ = ::MapViewOfFileFromApp(hMapping_, FILE_MAP_READ, 0, 0);
  4467. if (addr_ == nullptr) {
  4468. close();
  4469. return false;
  4470. }
  4471. #else
  4472. fd_ = ::open(path, O_RDONLY);
  4473. if (fd_ == -1) { return false; }
  4474. struct stat sb;
  4475. if (fstat(fd_, &sb) == -1) {
  4476. close();
  4477. return false;
  4478. }
  4479. size_ = static_cast<size_t>(sb.st_size);
  4480. addr_ = ::mmap(NULL, size_, PROT_READ, MAP_PRIVATE, fd_, 0);
  4481. // Special treatment for an empty file...
  4482. if (addr_ == MAP_FAILED && size_ == 0) {
  4483. close();
  4484. is_open_empty_file = true;
  4485. return false;
  4486. }
  4487. #endif
  4488. return true;
  4489. }
  4490. inline bool mmap::is_open() const {
  4491. return is_open_empty_file ? true : addr_ != nullptr;
  4492. }
  4493. inline size_t mmap::size() const { return size_; }
  4494. inline const char *mmap::data() const {
  4495. return is_open_empty_file ? "" : static_cast<const char *>(addr_);
  4496. }
  4497. inline void mmap::close() {
  4498. #if defined(_WIN32)
  4499. if (addr_) {
  4500. ::UnmapViewOfFile(addr_);
  4501. addr_ = nullptr;
  4502. }
  4503. if (hMapping_) {
  4504. ::CloseHandle(hMapping_);
  4505. hMapping_ = NULL;
  4506. }
  4507. if (hFile_ != INVALID_HANDLE_VALUE) {
  4508. ::CloseHandle(hFile_);
  4509. hFile_ = INVALID_HANDLE_VALUE;
  4510. }
  4511. is_open_empty_file = false;
  4512. #else
  4513. if (addr_ != nullptr) {
  4514. munmap(addr_, size_);
  4515. addr_ = nullptr;
  4516. }
  4517. if (fd_ != -1) {
  4518. ::close(fd_);
  4519. fd_ = -1;
  4520. }
  4521. #endif
  4522. size_ = 0;
  4523. }
  4524. inline int close_socket(socket_t sock) noexcept {
  4525. #ifdef _WIN32
  4526. return closesocket(sock);
  4527. #else
  4528. return close(sock);
  4529. #endif
  4530. }
  4531. template <typename T> inline ssize_t handle_EINTR(T fn) {
  4532. ssize_t res = 0;
  4533. while (true) {
  4534. res = fn();
  4535. if (res < 0 && errno == EINTR) {
  4536. std::this_thread::sleep_for(std::chrono::microseconds{1});
  4537. continue;
  4538. }
  4539. break;
  4540. }
  4541. return res;
  4542. }
  4543. inline ssize_t read_socket(socket_t sock, void *ptr, size_t size, int flags) {
  4544. return handle_EINTR([&]() {
  4545. return recv(sock,
  4546. #ifdef _WIN32
  4547. static_cast<char *>(ptr), static_cast<int>(size),
  4548. #else
  4549. ptr, size,
  4550. #endif
  4551. flags);
  4552. });
  4553. }
  4554. inline ssize_t send_socket(socket_t sock, const void *ptr, size_t size,
  4555. int flags) {
  4556. return handle_EINTR([&]() {
  4557. return send(sock,
  4558. #ifdef _WIN32
  4559. static_cast<const char *>(ptr), static_cast<int>(size),
  4560. #else
  4561. ptr, size,
  4562. #endif
  4563. flags);
  4564. });
  4565. }
  4566. inline int poll_wrapper(struct pollfd *fds, nfds_t nfds, int timeout) {
  4567. #ifdef _WIN32
  4568. return ::WSAPoll(fds, nfds, timeout);
  4569. #else
  4570. return ::poll(fds, nfds, timeout);
  4571. #endif
  4572. }
  4573. inline ssize_t select_impl(socket_t sock, short events, time_t sec,
  4574. time_t usec) {
  4575. struct pollfd pfd;
  4576. pfd.fd = sock;
  4577. pfd.events = events;
  4578. pfd.revents = 0;
  4579. auto timeout = static_cast<int>(sec * 1000 + usec / 1000);
  4580. return handle_EINTR([&]() { return poll_wrapper(&pfd, 1, timeout); });
  4581. }
  4582. inline ssize_t select_read(socket_t sock, time_t sec, time_t usec) {
  4583. return select_impl(sock, POLLIN, sec, usec);
  4584. }
  4585. inline ssize_t select_write(socket_t sock, time_t sec, time_t usec) {
  4586. return select_impl(sock, POLLOUT, sec, usec);
  4587. }
  4588. inline Error wait_until_socket_is_ready(socket_t sock, time_t sec,
  4589. time_t usec) {
  4590. struct pollfd pfd_read;
  4591. pfd_read.fd = sock;
  4592. pfd_read.events = POLLIN | POLLOUT;
  4593. pfd_read.revents = 0;
  4594. auto timeout = static_cast<int>(sec * 1000 + usec / 1000);
  4595. auto poll_res =
  4596. handle_EINTR([&]() { return poll_wrapper(&pfd_read, 1, timeout); });
  4597. if (poll_res == 0) { return Error::ConnectionTimeout; }
  4598. if (poll_res > 0 && pfd_read.revents & (POLLIN | POLLOUT)) {
  4599. auto error = 0;
  4600. socklen_t len = sizeof(error);
  4601. auto res = getsockopt(sock, SOL_SOCKET, SO_ERROR,
  4602. reinterpret_cast<char *>(&error), &len);
  4603. auto successful = res >= 0 && !error;
  4604. return successful ? Error::Success : Error::Connection;
  4605. }
  4606. return Error::Connection;
  4607. }
  4608. inline bool is_socket_alive(socket_t sock) {
  4609. const auto val = detail::select_read(sock, 0, 0);
  4610. if (val == 0) {
  4611. return true;
  4612. } else if (val < 0 && errno == EBADF) {
  4613. return false;
  4614. }
  4615. char buf[1];
  4616. return detail::read_socket(sock, &buf[0], sizeof(buf), MSG_PEEK) > 0;
  4617. }
  4618. class SocketStream final : public Stream {
  4619. public:
  4620. SocketStream(socket_t sock, time_t read_timeout_sec, time_t read_timeout_usec,
  4621. time_t write_timeout_sec, time_t write_timeout_usec,
  4622. time_t max_timeout_msec = 0,
  4623. std::chrono::time_point<std::chrono::steady_clock> start_time =
  4624. (std::chrono::steady_clock::time_point::min)());
  4625. ~SocketStream() override;
  4626. bool is_readable() const override;
  4627. bool wait_readable() const override;
  4628. bool wait_writable() const override;
  4629. bool is_peer_alive() const override;
  4630. ssize_t read(char *ptr, size_t size) override;
  4631. ssize_t write(const char *ptr, size_t size) override;
  4632. void get_remote_ip_and_port(std::string &ip, int &port) const override;
  4633. void get_local_ip_and_port(std::string &ip, int &port) const override;
  4634. socket_t socket() const override;
  4635. time_t duration() const override;
  4636. void set_read_timeout(time_t sec, time_t usec = 0) override;
  4637. private:
  4638. socket_t sock_;
  4639. time_t read_timeout_sec_;
  4640. time_t read_timeout_usec_;
  4641. time_t write_timeout_sec_;
  4642. time_t write_timeout_usec_;
  4643. time_t max_timeout_msec_;
  4644. const std::chrono::time_point<std::chrono::steady_clock> start_time_;
  4645. std::vector<char> read_buff_;
  4646. size_t read_buff_off_ = 0;
  4647. size_t read_buff_content_size_ = 0;
  4648. static const size_t read_buff_size_ = 1024l * 4;
  4649. };
  4650. inline bool keep_alive(const std::atomic<socket_t> &svr_sock, socket_t sock,
  4651. time_t keep_alive_timeout_sec) {
  4652. using namespace std::chrono;
  4653. const auto interval_usec =
  4654. CPPHTTPLIB_KEEPALIVE_TIMEOUT_CHECK_INTERVAL_USECOND;
  4655. // Avoid expensive `steady_clock::now()` call for the first time
  4656. if (select_read(sock, 0, interval_usec) > 0) { return true; }
  4657. const auto start = steady_clock::now() - microseconds{interval_usec};
  4658. const auto timeout = seconds{keep_alive_timeout_sec};
  4659. while (true) {
  4660. if (svr_sock == INVALID_SOCKET) {
  4661. break; // Server socket is closed
  4662. }
  4663. auto val = select_read(sock, 0, interval_usec);
  4664. if (val < 0) {
  4665. break; // Ssocket error
  4666. } else if (val == 0) {
  4667. if (steady_clock::now() - start > timeout) {
  4668. break; // Timeout
  4669. }
  4670. } else {
  4671. return true; // Ready for read
  4672. }
  4673. }
  4674. return false;
  4675. }
  4676. template <typename T>
  4677. inline bool
  4678. process_server_socket_core(const std::atomic<socket_t> &svr_sock, socket_t sock,
  4679. size_t keep_alive_max_count,
  4680. time_t keep_alive_timeout_sec, T callback) {
  4681. assert(keep_alive_max_count > 0);
  4682. auto ret = false;
  4683. auto count = keep_alive_max_count;
  4684. while (count > 0 && keep_alive(svr_sock, sock, keep_alive_timeout_sec)) {
  4685. auto close_connection = count == 1;
  4686. auto connection_closed = false;
  4687. ret = callback(close_connection, connection_closed);
  4688. if (!ret || connection_closed) { break; }
  4689. count--;
  4690. }
  4691. return ret;
  4692. }
  4693. template <typename T>
  4694. inline bool
  4695. process_server_socket(const std::atomic<socket_t> &svr_sock, socket_t sock,
  4696. size_t keep_alive_max_count,
  4697. time_t keep_alive_timeout_sec, time_t read_timeout_sec,
  4698. time_t read_timeout_usec, time_t write_timeout_sec,
  4699. time_t write_timeout_usec, T callback) {
  4700. return process_server_socket_core(
  4701. svr_sock, sock, keep_alive_max_count, keep_alive_timeout_sec,
  4702. [&](bool close_connection, bool &connection_closed) {
  4703. SocketStream strm(sock, read_timeout_sec, read_timeout_usec,
  4704. write_timeout_sec, write_timeout_usec);
  4705. return callback(strm, close_connection, connection_closed);
  4706. });
  4707. }
  4708. inline bool process_client_socket(
  4709. socket_t sock, time_t read_timeout_sec, time_t read_timeout_usec,
  4710. time_t write_timeout_sec, time_t write_timeout_usec,
  4711. time_t max_timeout_msec,
  4712. std::chrono::time_point<std::chrono::steady_clock> start_time,
  4713. std::function<bool(Stream &)> callback) {
  4714. SocketStream strm(sock, read_timeout_sec, read_timeout_usec,
  4715. write_timeout_sec, write_timeout_usec, max_timeout_msec,
  4716. start_time);
  4717. return callback(strm);
  4718. }
  4719. inline int shutdown_socket(socket_t sock) noexcept {
  4720. #ifdef _WIN32
  4721. return shutdown(sock, SD_BOTH);
  4722. #else
  4723. return shutdown(sock, SHUT_RDWR);
  4724. #endif
  4725. }
  4726. inline std::string escape_abstract_namespace_unix_domain(const std::string &s) {
  4727. if (s.size() > 1 && s[0] == '\0') {
  4728. auto ret = s;
  4729. ret[0] = '@';
  4730. return ret;
  4731. }
  4732. return s;
  4733. }
  4734. inline std::string
  4735. unescape_abstract_namespace_unix_domain(const std::string &s) {
  4736. if (s.size() > 1 && s[0] == '@') {
  4737. auto ret = s;
  4738. ret[0] = '\0';
  4739. return ret;
  4740. }
  4741. return s;
  4742. }
  4743. inline int getaddrinfo_with_timeout(const char *node, const char *service,
  4744. const struct addrinfo *hints,
  4745. struct addrinfo **res, time_t timeout_sec) {
  4746. #ifdef CPPHTTPLIB_USE_NON_BLOCKING_GETADDRINFO
  4747. if (timeout_sec <= 0) {
  4748. // No timeout specified, use standard getaddrinfo
  4749. return getaddrinfo(node, service, hints, res);
  4750. }
  4751. #ifdef _WIN32
  4752. // Windows-specific implementation using GetAddrInfoEx with overlapped I/O
  4753. OVERLAPPED overlapped = {};
  4754. HANDLE event = CreateEventW(nullptr, TRUE, FALSE, nullptr);
  4755. if (!event) { return EAI_FAIL; }
  4756. overlapped.hEvent = event;
  4757. PADDRINFOEXW result_addrinfo = nullptr;
  4758. HANDLE cancel_handle = nullptr;
  4759. ADDRINFOEXW hints_ex = {};
  4760. if (hints) {
  4761. hints_ex.ai_flags = hints->ai_flags;
  4762. hints_ex.ai_family = hints->ai_family;
  4763. hints_ex.ai_socktype = hints->ai_socktype;
  4764. hints_ex.ai_protocol = hints->ai_protocol;
  4765. }
  4766. auto wnode = u8string_to_wstring(node);
  4767. auto wservice = u8string_to_wstring(service);
  4768. auto ret = ::GetAddrInfoExW(wnode.data(), wservice.data(), NS_DNS, nullptr,
  4769. hints ? &hints_ex : nullptr, &result_addrinfo,
  4770. nullptr, &overlapped, nullptr, &cancel_handle);
  4771. if (ret == WSA_IO_PENDING) {
  4772. auto wait_result =
  4773. ::WaitForSingleObject(event, static_cast<DWORD>(timeout_sec * 1000));
  4774. if (wait_result == WAIT_TIMEOUT) {
  4775. if (cancel_handle) { ::GetAddrInfoExCancel(&cancel_handle); }
  4776. ::CloseHandle(event);
  4777. return EAI_AGAIN;
  4778. }
  4779. DWORD bytes_returned;
  4780. if (!::GetOverlappedResult((HANDLE)INVALID_SOCKET, &overlapped,
  4781. &bytes_returned, FALSE)) {
  4782. ::CloseHandle(event);
  4783. return ::WSAGetLastError();
  4784. }
  4785. }
  4786. ::CloseHandle(event);
  4787. if (ret == NO_ERROR || ret == WSA_IO_PENDING) {
  4788. *res = reinterpret_cast<struct addrinfo *>(result_addrinfo);
  4789. return 0;
  4790. }
  4791. return ret;
  4792. #elif TARGET_OS_MAC && defined(__clang__)
  4793. if (!node) { return EAI_NONAME; }
  4794. // macOS implementation using CFHost API for asynchronous DNS resolution
  4795. CFStringRef hostname_ref = CFStringCreateWithCString(
  4796. kCFAllocatorDefault, node, kCFStringEncodingUTF8);
  4797. if (!hostname_ref) { return EAI_MEMORY; }
  4798. CFHostRef host_ref = CFHostCreateWithName(kCFAllocatorDefault, hostname_ref);
  4799. CFRelease(hostname_ref);
  4800. if (!host_ref) { return EAI_MEMORY; }
  4801. // Set up context for callback
  4802. struct CFHostContext {
  4803. bool completed = false;
  4804. bool success = false;
  4805. CFArrayRef addresses = nullptr;
  4806. std::mutex mutex;
  4807. std::condition_variable cv;
  4808. } context;
  4809. CFHostClientContext client_context;
  4810. memset(&client_context, 0, sizeof(client_context));
  4811. client_context.info = &context;
  4812. // Set callback
  4813. auto callback = [](CFHostRef theHost, CFHostInfoType /*typeInfo*/,
  4814. const CFStreamError *error, void *info) {
  4815. auto ctx = static_cast<CFHostContext *>(info);
  4816. std::lock_guard<std::mutex> lock(ctx->mutex);
  4817. if (error && error->error != 0) {
  4818. ctx->success = false;
  4819. } else {
  4820. Boolean hasBeenResolved;
  4821. ctx->addresses = CFHostGetAddressing(theHost, &hasBeenResolved);
  4822. if (ctx->addresses && hasBeenResolved) {
  4823. CFRetain(ctx->addresses);
  4824. ctx->success = true;
  4825. } else {
  4826. ctx->success = false;
  4827. }
  4828. }
  4829. ctx->completed = true;
  4830. ctx->cv.notify_one();
  4831. };
  4832. if (!CFHostSetClient(host_ref, callback, &client_context)) {
  4833. CFRelease(host_ref);
  4834. return EAI_SYSTEM;
  4835. }
  4836. // Schedule on run loop
  4837. CFRunLoopRef run_loop = CFRunLoopGetCurrent();
  4838. CFHostScheduleWithRunLoop(host_ref, run_loop, kCFRunLoopDefaultMode);
  4839. // Start resolution
  4840. CFStreamError stream_error;
  4841. if (!CFHostStartInfoResolution(host_ref, kCFHostAddresses, &stream_error)) {
  4842. CFHostUnscheduleFromRunLoop(host_ref, run_loop, kCFRunLoopDefaultMode);
  4843. CFRelease(host_ref);
  4844. return EAI_FAIL;
  4845. }
  4846. // Wait for completion with timeout
  4847. auto timeout_time =
  4848. std::chrono::steady_clock::now() + std::chrono::seconds(timeout_sec);
  4849. bool timed_out = false;
  4850. {
  4851. std::unique_lock<std::mutex> lock(context.mutex);
  4852. while (!context.completed) {
  4853. auto now = std::chrono::steady_clock::now();
  4854. if (now >= timeout_time) {
  4855. timed_out = true;
  4856. break;
  4857. }
  4858. // Run the runloop for a short time
  4859. lock.unlock();
  4860. CFRunLoopRunInMode(kCFRunLoopDefaultMode, 0.1, true);
  4861. lock.lock();
  4862. }
  4863. }
  4864. // Clean up
  4865. CFHostUnscheduleFromRunLoop(host_ref, run_loop, kCFRunLoopDefaultMode);
  4866. CFHostSetClient(host_ref, nullptr, nullptr);
  4867. if (timed_out || !context.completed) {
  4868. CFHostCancelInfoResolution(host_ref, kCFHostAddresses);
  4869. CFRelease(host_ref);
  4870. return EAI_AGAIN;
  4871. }
  4872. if (!context.success || !context.addresses) {
  4873. CFRelease(host_ref);
  4874. return EAI_NODATA;
  4875. }
  4876. // Convert CFArray to addrinfo
  4877. CFIndex count = CFArrayGetCount(context.addresses);
  4878. if (count == 0) {
  4879. CFRelease(context.addresses);
  4880. CFRelease(host_ref);
  4881. return EAI_NODATA;
  4882. }
  4883. struct addrinfo *result_addrinfo = nullptr;
  4884. struct addrinfo **current = &result_addrinfo;
  4885. for (CFIndex i = 0; i < count; i++) {
  4886. CFDataRef addr_data =
  4887. static_cast<CFDataRef>(CFArrayGetValueAtIndex(context.addresses, i));
  4888. if (!addr_data) continue;
  4889. const struct sockaddr *sockaddr_ptr =
  4890. reinterpret_cast<const struct sockaddr *>(CFDataGetBytePtr(addr_data));
  4891. socklen_t sockaddr_len = static_cast<socklen_t>(CFDataGetLength(addr_data));
  4892. // Allocate addrinfo structure
  4893. *current = static_cast<struct addrinfo *>(malloc(sizeof(struct addrinfo)));
  4894. if (!*current) {
  4895. freeaddrinfo(result_addrinfo);
  4896. CFRelease(context.addresses);
  4897. CFRelease(host_ref);
  4898. return EAI_MEMORY;
  4899. }
  4900. memset(*current, 0, sizeof(struct addrinfo));
  4901. // Set up addrinfo fields
  4902. (*current)->ai_family = sockaddr_ptr->sa_family;
  4903. (*current)->ai_socktype = hints ? hints->ai_socktype : SOCK_STREAM;
  4904. (*current)->ai_protocol = hints ? hints->ai_protocol : IPPROTO_TCP;
  4905. (*current)->ai_addrlen = sockaddr_len;
  4906. // Copy sockaddr
  4907. (*current)->ai_addr = static_cast<struct sockaddr *>(malloc(sockaddr_len));
  4908. if (!(*current)->ai_addr) {
  4909. freeaddrinfo(result_addrinfo);
  4910. CFRelease(context.addresses);
  4911. CFRelease(host_ref);
  4912. return EAI_MEMORY;
  4913. }
  4914. memcpy((*current)->ai_addr, sockaddr_ptr, sockaddr_len);
  4915. // Set port if service is specified
  4916. if (service && *service) {
  4917. int port = 0;
  4918. if (parse_port(service, strlen(service), port)) {
  4919. if (sockaddr_ptr->sa_family == AF_INET) {
  4920. reinterpret_cast<struct sockaddr_in *>((*current)->ai_addr)
  4921. ->sin_port = htons(static_cast<uint16_t>(port));
  4922. } else if (sockaddr_ptr->sa_family == AF_INET6) {
  4923. reinterpret_cast<struct sockaddr_in6 *>((*current)->ai_addr)
  4924. ->sin6_port = htons(static_cast<uint16_t>(port));
  4925. }
  4926. }
  4927. }
  4928. current = &((*current)->ai_next);
  4929. }
  4930. CFRelease(context.addresses);
  4931. CFRelease(host_ref);
  4932. *res = result_addrinfo;
  4933. return 0;
  4934. #elif defined(_GNU_SOURCE) && defined(__GLIBC__) && \
  4935. (__GLIBC__ > 2 || (__GLIBC__ == 2 && __GLIBC_MINOR__ >= 2))
  4936. // #2431: gai_cancel() is non-blocking and may return EAI_NOTCANCELED while
  4937. // the resolver worker still references the stack-local gaicb. The cancel
  4938. // path therefore waits (gai_suspend with no timeout) for the worker to
  4939. // actually finish before letting the stack frame go. The trade-off is that
  4940. // a wedged DNS server can hold this thread for the system resolver timeout
  4941. // (~30s by default) past the caller's connection timeout.
  4942. struct gaicb request {};
  4943. struct gaicb *requests[1] = {&request};
  4944. struct sigevent sevp {};
  4945. struct timespec timeout {
  4946. timeout_sec, 0
  4947. };
  4948. request.ar_name = node;
  4949. request.ar_service = service;
  4950. request.ar_request = hints;
  4951. sevp.sigev_notify = SIGEV_NONE;
  4952. int rc = getaddrinfo_a(GAI_NOWAIT, requests, 1, &sevp);
  4953. if (rc != 0) { return rc; }
  4954. auto cleanup = scope_exit([&] {
  4955. if (request.ar_result) { freeaddrinfo(request.ar_result); }
  4956. });
  4957. int wait_result = gai_suspend(requests, 1, &timeout);
  4958. if (wait_result == 0 || wait_result == EAI_ALLDONE) {
  4959. int gai_result = gai_error(&request);
  4960. if (gai_result == 0) {
  4961. *res = request.ar_result;
  4962. request.ar_result = nullptr;
  4963. return 0;
  4964. }
  4965. return gai_result;
  4966. }
  4967. gai_cancel(&request);
  4968. while (gai_error(&request) == EAI_INPROGRESS) {
  4969. gai_suspend(requests, 1, nullptr);
  4970. }
  4971. return wait_result;
  4972. #else
  4973. // Fallback implementation using thread-based timeout for other Unix systems.
  4974. struct GetAddrInfoState {
  4975. ~GetAddrInfoState() {
  4976. if (info) { freeaddrinfo(info); }
  4977. }
  4978. std::mutex mutex;
  4979. std::condition_variable result_cv;
  4980. bool completed = false;
  4981. int result = EAI_SYSTEM;
  4982. std::string node;
  4983. std::string service;
  4984. struct addrinfo hints;
  4985. struct addrinfo *info = nullptr;
  4986. };
  4987. // Allocate on the heap, so the resolver thread can keep using the data.
  4988. auto state = std::make_shared<GetAddrInfoState>();
  4989. if (node) { state->node = node; }
  4990. state->service = service;
  4991. state->hints = *hints;
  4992. std::thread resolve_thread([state]() {
  4993. auto thread_result =
  4994. getaddrinfo(state->node.c_str(), state->service.c_str(), &state->hints,
  4995. &state->info);
  4996. std::lock_guard<std::mutex> lock(state->mutex);
  4997. state->result = thread_result;
  4998. state->completed = true;
  4999. state->result_cv.notify_one();
  5000. });
  5001. // Wait for completion or timeout
  5002. std::unique_lock<std::mutex> lock(state->mutex);
  5003. auto finished =
  5004. state->result_cv.wait_for(lock, std::chrono::seconds(timeout_sec),
  5005. [&] { return state->completed; });
  5006. if (finished) {
  5007. // Operation completed within timeout
  5008. resolve_thread.join();
  5009. *res = state->info;
  5010. state->info = nullptr; // Pass ownership to caller
  5011. return state->result;
  5012. } else {
  5013. // Timeout occurred
  5014. resolve_thread.detach(); // Let the thread finish in background
  5015. return EAI_AGAIN; // Return timeout error
  5016. }
  5017. #endif
  5018. #else
  5019. (void)(timeout_sec); // Unused parameter for non-blocking getaddrinfo
  5020. return getaddrinfo(node, service, hints, res);
  5021. #endif
  5022. }
  5023. template <typename BindOrConnect>
  5024. socket_t create_socket(const std::string &host, const std::string &ip, int port,
  5025. int address_family, int socket_flags, bool tcp_nodelay,
  5026. bool ipv6_v6only, SocketOptions socket_options,
  5027. BindOrConnect bind_or_connect, time_t timeout_sec = 0) {
  5028. // Get address info
  5029. const char *node = nullptr;
  5030. struct addrinfo hints;
  5031. struct addrinfo *result;
  5032. memset(&hints, 0, sizeof(struct addrinfo));
  5033. hints.ai_socktype = SOCK_STREAM;
  5034. hints.ai_protocol = IPPROTO_IP;
  5035. if (!ip.empty()) {
  5036. node = ip.c_str();
  5037. // Ask getaddrinfo to convert IP in c-string to address
  5038. hints.ai_family = AF_UNSPEC;
  5039. hints.ai_flags = AI_NUMERICHOST;
  5040. } else {
  5041. if (!host.empty()) { node = host.c_str(); }
  5042. hints.ai_family = address_family;
  5043. hints.ai_flags = socket_flags;
  5044. }
  5045. #if !defined(_WIN32) || defined(CPPHTTPLIB_HAVE_AFUNIX_H)
  5046. if (hints.ai_family == AF_UNIX) {
  5047. const auto addrlen = host.length();
  5048. if (addrlen > sizeof(sockaddr_un::sun_path)) { return INVALID_SOCKET; }
  5049. #ifdef SOCK_CLOEXEC
  5050. auto sock = socket(hints.ai_family, hints.ai_socktype | SOCK_CLOEXEC,
  5051. hints.ai_protocol);
  5052. #else
  5053. auto sock = socket(hints.ai_family, hints.ai_socktype, hints.ai_protocol);
  5054. #endif
  5055. if (sock != INVALID_SOCKET) {
  5056. sockaddr_un addr{};
  5057. addr.sun_family = AF_UNIX;
  5058. auto unescaped_host = unescape_abstract_namespace_unix_domain(host);
  5059. std::copy(unescaped_host.begin(), unescaped_host.end(), addr.sun_path);
  5060. hints.ai_addr = reinterpret_cast<sockaddr *>(&addr);
  5061. hints.ai_addrlen = static_cast<socklen_t>(
  5062. sizeof(addr) - sizeof(addr.sun_path) + addrlen);
  5063. #ifndef SOCK_CLOEXEC
  5064. #ifndef _WIN32
  5065. fcntl(sock, F_SETFD, FD_CLOEXEC);
  5066. #endif
  5067. #endif
  5068. if (socket_options) { socket_options(sock); }
  5069. #ifdef _WIN32
  5070. // Setting SO_REUSEADDR seems not to work well with AF_UNIX on windows, so
  5071. // remove the option.
  5072. set_socket_opt(sock, SOL_SOCKET, SO_REUSEADDR, 0);
  5073. #endif
  5074. bool dummy;
  5075. if (!bind_or_connect(sock, hints, dummy)) {
  5076. close_socket(sock);
  5077. sock = INVALID_SOCKET;
  5078. }
  5079. }
  5080. return sock;
  5081. }
  5082. #endif
  5083. auto service = std::to_string(port);
  5084. if (getaddrinfo_with_timeout(node, service.c_str(), &hints, &result,
  5085. timeout_sec)) {
  5086. #if defined __linux__ && !defined __ANDROID__
  5087. res_init();
  5088. #endif
  5089. return INVALID_SOCKET;
  5090. }
  5091. auto se = detail::scope_exit([&] { freeaddrinfo(result); });
  5092. for (auto rp = result; rp; rp = rp->ai_next) {
  5093. // Create a socket
  5094. #ifdef _WIN32
  5095. auto sock =
  5096. WSASocketW(rp->ai_family, rp->ai_socktype, rp->ai_protocol, nullptr, 0,
  5097. WSA_FLAG_NO_HANDLE_INHERIT | WSA_FLAG_OVERLAPPED);
  5098. /**
  5099. * Since the WSA_FLAG_NO_HANDLE_INHERIT is only supported on Windows 7 SP1
  5100. * and above the socket creation fails on older Windows Systems.
  5101. *
  5102. * Let's try to create a socket the old way in this case.
  5103. *
  5104. * Reference:
  5105. * https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasocketa
  5106. *
  5107. * WSA_FLAG_NO_HANDLE_INHERIT:
  5108. * This flag is supported on Windows 7 with SP1, Windows Server 2008 R2 with
  5109. * SP1, and later
  5110. *
  5111. */
  5112. if (sock == INVALID_SOCKET) {
  5113. sock = socket(rp->ai_family, rp->ai_socktype, rp->ai_protocol);
  5114. }
  5115. #else
  5116. #ifdef SOCK_CLOEXEC
  5117. auto sock =
  5118. socket(rp->ai_family, rp->ai_socktype | SOCK_CLOEXEC, rp->ai_protocol);
  5119. #else
  5120. auto sock = socket(rp->ai_family, rp->ai_socktype, rp->ai_protocol);
  5121. #endif
  5122. #endif
  5123. if (sock == INVALID_SOCKET) { continue; }
  5124. #if !defined _WIN32 && !defined SOCK_CLOEXEC
  5125. if (fcntl(sock, F_SETFD, FD_CLOEXEC) == -1) {
  5126. close_socket(sock);
  5127. continue;
  5128. }
  5129. #endif
  5130. if (tcp_nodelay) { set_socket_opt(sock, IPPROTO_TCP, TCP_NODELAY, 1); }
  5131. if (rp->ai_family == AF_INET6) {
  5132. set_socket_opt(sock, IPPROTO_IPV6, IPV6_V6ONLY, ipv6_v6only ? 1 : 0);
  5133. }
  5134. if (socket_options) { socket_options(sock); }
  5135. // bind or connect
  5136. auto quit = false;
  5137. if (bind_or_connect(sock, *rp, quit)) { return sock; }
  5138. close_socket(sock);
  5139. if (quit) { break; }
  5140. }
  5141. return INVALID_SOCKET;
  5142. }
  5143. inline void set_nonblocking(socket_t sock, bool nonblocking) {
  5144. #ifdef _WIN32
  5145. auto flags = nonblocking ? 1UL : 0UL;
  5146. ioctlsocket(sock, FIONBIO, &flags);
  5147. #else
  5148. auto flags = fcntl(sock, F_GETFL, 0);
  5149. fcntl(sock, F_SETFL,
  5150. nonblocking ? (flags | O_NONBLOCK) : (flags & (~O_NONBLOCK)));
  5151. #endif
  5152. }
  5153. inline bool is_connection_error() {
  5154. #ifdef _WIN32
  5155. return WSAGetLastError() != WSAEWOULDBLOCK;
  5156. #else
  5157. return errno != EINPROGRESS;
  5158. #endif
  5159. }
  5160. inline bool bind_ip_address(socket_t sock, const std::string &host) {
  5161. struct addrinfo hints;
  5162. struct addrinfo *result;
  5163. memset(&hints, 0, sizeof(struct addrinfo));
  5164. hints.ai_family = AF_UNSPEC;
  5165. hints.ai_socktype = SOCK_STREAM;
  5166. hints.ai_protocol = 0;
  5167. if (getaddrinfo_with_timeout(host.c_str(), "0", &hints, &result, 0)) {
  5168. return false;
  5169. }
  5170. auto se = detail::scope_exit([&] { freeaddrinfo(result); });
  5171. auto ret = false;
  5172. for (auto rp = result; rp; rp = rp->ai_next) {
  5173. const auto &ai = *rp;
  5174. if (!::bind(sock, ai.ai_addr, static_cast<socklen_t>(ai.ai_addrlen))) {
  5175. ret = true;
  5176. break;
  5177. }
  5178. }
  5179. return ret;
  5180. }
  5181. #if !defined _WIN32 && !defined ANDROID && !defined _AIX && !defined __MVS__
  5182. #define USE_IF2IP
  5183. #endif
  5184. #ifdef USE_IF2IP
  5185. inline std::string if2ip(int address_family, const std::string &ifn) {
  5186. struct ifaddrs *ifap;
  5187. getifaddrs(&ifap);
  5188. auto se = detail::scope_exit([&] { freeifaddrs(ifap); });
  5189. std::string addr_candidate;
  5190. for (auto ifa = ifap; ifa; ifa = ifa->ifa_next) {
  5191. if (ifa->ifa_addr && ifn == ifa->ifa_name &&
  5192. (AF_UNSPEC == address_family ||
  5193. ifa->ifa_addr->sa_family == address_family)) {
  5194. if (ifa->ifa_addr->sa_family == AF_INET) {
  5195. auto sa = reinterpret_cast<struct sockaddr_in *>(ifa->ifa_addr);
  5196. char buf[INET_ADDRSTRLEN];
  5197. if (inet_ntop(AF_INET, &sa->sin_addr, buf, INET_ADDRSTRLEN)) {
  5198. return std::string(buf, INET_ADDRSTRLEN);
  5199. }
  5200. } else if (ifa->ifa_addr->sa_family == AF_INET6) {
  5201. auto sa = reinterpret_cast<struct sockaddr_in6 *>(ifa->ifa_addr);
  5202. if (!IN6_IS_ADDR_LINKLOCAL(&sa->sin6_addr)) {
  5203. char buf[INET6_ADDRSTRLEN] = {};
  5204. if (inet_ntop(AF_INET6, &sa->sin6_addr, buf, INET6_ADDRSTRLEN)) {
  5205. // equivalent to mac's IN6_IS_ADDR_UNIQUE_LOCAL
  5206. auto s6_addr_head = sa->sin6_addr.s6_addr[0];
  5207. if (s6_addr_head == 0xfc || s6_addr_head == 0xfd) {
  5208. addr_candidate = std::string(buf, INET6_ADDRSTRLEN);
  5209. } else {
  5210. return std::string(buf, INET6_ADDRSTRLEN);
  5211. }
  5212. }
  5213. }
  5214. }
  5215. }
  5216. }
  5217. return addr_candidate;
  5218. }
  5219. #endif
  5220. inline socket_t create_client_socket(
  5221. const std::string &host, const std::string &ip, int port,
  5222. int address_family, bool tcp_nodelay, bool ipv6_v6only,
  5223. SocketOptions socket_options, time_t connection_timeout_sec,
  5224. time_t connection_timeout_usec, time_t read_timeout_sec,
  5225. time_t read_timeout_usec, time_t write_timeout_sec,
  5226. time_t write_timeout_usec, const std::string &intf, Error &error) {
  5227. auto sock = create_socket(
  5228. host, ip, port, address_family, 0, tcp_nodelay, ipv6_v6only,
  5229. std::move(socket_options),
  5230. [&](socket_t sock2, struct addrinfo &ai, bool &quit) -> bool {
  5231. if (!intf.empty()) {
  5232. #ifdef USE_IF2IP
  5233. auto ip_from_if = if2ip(address_family, intf);
  5234. if (ip_from_if.empty()) { ip_from_if = intf; }
  5235. if (!bind_ip_address(sock2, ip_from_if)) {
  5236. error = Error::BindIPAddress;
  5237. return false;
  5238. }
  5239. #endif
  5240. }
  5241. set_nonblocking(sock2, true);
  5242. auto ret =
  5243. ::connect(sock2, ai.ai_addr, static_cast<socklen_t>(ai.ai_addrlen));
  5244. if (ret < 0) {
  5245. if (is_connection_error()) {
  5246. error = Error::Connection;
  5247. return false;
  5248. }
  5249. error = wait_until_socket_is_ready(sock2, connection_timeout_sec,
  5250. connection_timeout_usec);
  5251. if (error != Error::Success) {
  5252. if (error == Error::ConnectionTimeout) { quit = true; }
  5253. return false;
  5254. }
  5255. }
  5256. set_nonblocking(sock2, false);
  5257. set_socket_opt_time(sock2, SOL_SOCKET, SO_RCVTIMEO, read_timeout_sec,
  5258. read_timeout_usec);
  5259. set_socket_opt_time(sock2, SOL_SOCKET, SO_SNDTIMEO, write_timeout_sec,
  5260. write_timeout_usec);
  5261. error = Error::Success;
  5262. return true;
  5263. },
  5264. connection_timeout_sec); // Pass DNS timeout
  5265. if (sock != INVALID_SOCKET) {
  5266. error = Error::Success;
  5267. } else {
  5268. if (error == Error::Success) { error = Error::Connection; }
  5269. }
  5270. return sock;
  5271. }
  5272. inline bool get_ip_and_port(const struct sockaddr_storage &addr,
  5273. socklen_t addr_len, std::string &ip, int &port) {
  5274. if (addr.ss_family == AF_INET) {
  5275. port = ntohs(reinterpret_cast<const struct sockaddr_in *>(&addr)->sin_port);
  5276. } else if (addr.ss_family == AF_INET6) {
  5277. port =
  5278. ntohs(reinterpret_cast<const struct sockaddr_in6 *>(&addr)->sin6_port);
  5279. } else {
  5280. return false;
  5281. }
  5282. std::array<char, NI_MAXHOST> ipstr{};
  5283. if (getnameinfo(reinterpret_cast<const struct sockaddr *>(&addr), addr_len,
  5284. ipstr.data(), static_cast<socklen_t>(ipstr.size()), nullptr,
  5285. 0, NI_NUMERICHOST)) {
  5286. return false;
  5287. }
  5288. ip = ipstr.data();
  5289. return true;
  5290. }
  5291. inline void get_local_ip_and_port(socket_t sock, std::string &ip, int &port) {
  5292. struct sockaddr_storage addr;
  5293. socklen_t addr_len = sizeof(addr);
  5294. if (!getsockname(sock, reinterpret_cast<struct sockaddr *>(&addr),
  5295. &addr_len)) {
  5296. get_ip_and_port(addr, addr_len, ip, port);
  5297. }
  5298. }
  5299. inline void get_remote_ip_and_port(socket_t sock, std::string &ip, int &port) {
  5300. struct sockaddr_storage addr;
  5301. socklen_t addr_len = sizeof(addr);
  5302. if (!getpeername(sock, reinterpret_cast<struct sockaddr *>(&addr),
  5303. &addr_len)) {
  5304. #ifndef _WIN32
  5305. if (addr.ss_family == AF_UNIX) {
  5306. #if defined(__linux__)
  5307. struct ucred ucred;
  5308. socklen_t len = sizeof(ucred);
  5309. if (getsockopt(sock, SOL_SOCKET, SO_PEERCRED, &ucred, &len) == 0) {
  5310. port = ucred.pid;
  5311. }
  5312. #elif defined(SOL_LOCAL) && defined(SO_PEERPID)
  5313. pid_t pid;
  5314. socklen_t len = sizeof(pid);
  5315. if (getsockopt(sock, SOL_LOCAL, SO_PEERPID, &pid, &len) == 0) {
  5316. port = pid;
  5317. }
  5318. #endif
  5319. return;
  5320. }
  5321. #endif
  5322. get_ip_and_port(addr, addr_len, ip, port);
  5323. }
  5324. }
  5325. // Recursive form retained so operator""_t below can compute hashes for
  5326. // switch-case labels at compile time (C++11 constexpr forbids loops). Do not
  5327. // call from runtime paths with arbitrary-length inputs — use str2tag()
  5328. // instead, which is iterative and stack-safe.
  5329. inline constexpr unsigned int str2tag_core(const char *s, size_t l,
  5330. unsigned int h) {
  5331. return (l == 0)
  5332. ? h
  5333. : str2tag_core(
  5334. s + 1, l - 1,
  5335. // Unsets the 6 high bits of h, therefore no overflow happens
  5336. (((std::numeric_limits<unsigned int>::max)() >> 6) &
  5337. h * 33) ^
  5338. static_cast<unsigned char>(*s));
  5339. }
  5340. inline unsigned int str2tag(const std::string &s) {
  5341. // Iterative form of str2tag_core: the recursive constexpr version is kept
  5342. // for compile-time UDL evaluation of short string literals, but at runtime
  5343. // we may receive arbitrarily long inputs (e.g. fuzzed Content-Type) that
  5344. // would blow the stack with one frame per character.
  5345. unsigned int h = 0;
  5346. for (auto c : s) {
  5347. h = (((std::numeric_limits<unsigned int>::max)() >> 6) & h * 33) ^
  5348. static_cast<unsigned char>(c);
  5349. }
  5350. return h;
  5351. }
  5352. namespace udl {
  5353. inline constexpr unsigned int operator""_t(const char *s, size_t l) {
  5354. return str2tag_core(s, l, 0);
  5355. }
  5356. } // namespace udl
  5357. inline std::string
  5358. find_content_type(const std::string &path,
  5359. const std::map<std::string, std::string> &user_data,
  5360. const std::string &default_content_type) {
  5361. auto ext = file_extension(path);
  5362. auto it = user_data.find(ext);
  5363. if (it != user_data.end()) { return it->second; }
  5364. using udl::operator""_t;
  5365. switch (str2tag(ext)) {
  5366. default: return default_content_type;
  5367. case "css"_t: return "text/css";
  5368. case "csv"_t: return "text/csv";
  5369. case "htm"_t:
  5370. case "html"_t: return "text/html";
  5371. case "js"_t:
  5372. case "mjs"_t: return "text/javascript";
  5373. case "txt"_t: return "text/plain";
  5374. case "vtt"_t: return "text/vtt";
  5375. case "apng"_t: return "image/apng";
  5376. case "avif"_t: return "image/avif";
  5377. case "bmp"_t: return "image/bmp";
  5378. case "gif"_t: return "image/gif";
  5379. case "png"_t: return "image/png";
  5380. case "svg"_t: return "image/svg+xml";
  5381. case "webp"_t: return "image/webp";
  5382. case "ico"_t: return "image/x-icon";
  5383. case "tif"_t: return "image/tiff";
  5384. case "tiff"_t: return "image/tiff";
  5385. case "jpg"_t:
  5386. case "jpeg"_t: return "image/jpeg";
  5387. case "mp4"_t: return "video/mp4";
  5388. case "mpeg"_t: return "video/mpeg";
  5389. case "webm"_t: return "video/webm";
  5390. case "mp3"_t: return "audio/mp3";
  5391. case "mpga"_t: return "audio/mpeg";
  5392. case "weba"_t: return "audio/webm";
  5393. case "wav"_t: return "audio/wave";
  5394. case "otf"_t: return "font/otf";
  5395. case "ttf"_t: return "font/ttf";
  5396. case "woff"_t: return "font/woff";
  5397. case "woff2"_t: return "font/woff2";
  5398. case "7z"_t: return "application/x-7z-compressed";
  5399. case "atom"_t: return "application/atom+xml";
  5400. case "pdf"_t: return "application/pdf";
  5401. case "json"_t: return "application/json";
  5402. case "rss"_t: return "application/rss+xml";
  5403. case "tar"_t: return "application/x-tar";
  5404. case "xht"_t:
  5405. case "xhtml"_t: return "application/xhtml+xml";
  5406. case "xslt"_t: return "application/xslt+xml";
  5407. case "xml"_t: return "application/xml";
  5408. case "gz"_t: return "application/gzip";
  5409. case "zip"_t: return "application/zip";
  5410. case "wasm"_t: return "application/wasm";
  5411. }
  5412. }
  5413. inline std::string
  5414. extract_media_type(const std::string &content_type,
  5415. std::map<std::string, std::string> *params = nullptr) {
  5416. // Extract type/subtype from Content-Type value (RFC 2045)
  5417. // e.g. "application/json; charset=utf-8" -> "application/json"
  5418. auto media_type = content_type;
  5419. auto semicolon_pos = media_type.find(';');
  5420. if (semicolon_pos != std::string::npos) {
  5421. auto param_str = media_type.substr(semicolon_pos + 1);
  5422. media_type = media_type.substr(0, semicolon_pos);
  5423. if (params) {
  5424. // Parse parameters: key=value pairs separated by ';'
  5425. split(param_str.data(), param_str.data() + param_str.size(), ';',
  5426. [&](const char *b, const char *e) {
  5427. std::string key;
  5428. std::string val;
  5429. split(b, e, '=', [&](const char *b2, const char *e2) {
  5430. if (key.empty()) {
  5431. key.assign(b2, e2);
  5432. } else {
  5433. val.assign(b2, e2);
  5434. }
  5435. });
  5436. if (!key.empty()) {
  5437. params->emplace(trim_copy(key), trim_double_quotes_copy(val));
  5438. }
  5439. });
  5440. }
  5441. }
  5442. // Trim whitespace from media type
  5443. return trim_copy(media_type);
  5444. }
  5445. inline bool can_compress_content_type(const std::string &content_type) {
  5446. using udl::operator""_t;
  5447. auto mime_type = extract_media_type(content_type);
  5448. auto tag = str2tag(mime_type);
  5449. switch (tag) {
  5450. case "image/svg+xml"_t:
  5451. case "application/javascript"_t:
  5452. case "application/x-javascript"_t:
  5453. case "application/json"_t:
  5454. case "application/ld+json"_t:
  5455. case "application/xml"_t:
  5456. case "application/xhtml+xml"_t:
  5457. case "application/rss+xml"_t:
  5458. case "application/atom+xml"_t:
  5459. case "application/xslt+xml"_t:
  5460. case "application/protobuf"_t: return true;
  5461. case "text/event-stream"_t: return false;
  5462. default: return !mime_type.rfind("text/", 0);
  5463. }
  5464. }
  5465. inline bool parse_quality(const char *b, const char *e, std::string &token,
  5466. double &quality) {
  5467. quality = 1.0;
  5468. token.clear();
  5469. // Split on first ';': left = token name, right = parameters
  5470. const char *params_b = nullptr;
  5471. std::size_t params_len = 0;
  5472. divide(
  5473. b, static_cast<std::size_t>(e - b), ';',
  5474. [&](const char *lb, std::size_t llen, const char *rb, std::size_t rlen) {
  5475. auto r = trim(lb, lb + llen, 0, llen);
  5476. if (r.first < r.second) { token.assign(lb + r.first, lb + r.second); }
  5477. params_b = rb;
  5478. params_len = rlen;
  5479. });
  5480. if (token.empty()) { return false; }
  5481. if (params_len == 0) { return true; }
  5482. // Scan parameters for q= (stops on first match)
  5483. bool invalid = false;
  5484. split_find(params_b, params_b + params_len, ';',
  5485. (std::numeric_limits<size_t>::max)(),
  5486. [&](const char *pb, const char *pe) -> bool {
  5487. // Match exactly "q=" or "Q=" (not "query=" etc.)
  5488. auto len = static_cast<size_t>(pe - pb);
  5489. if (len < 2) { return false; }
  5490. if ((pb[0] != 'q' && pb[0] != 'Q') || pb[1] != '=') {
  5491. return false;
  5492. }
  5493. // Trim the value portion
  5494. auto r = trim(pb, pe, 2, len);
  5495. if (r.first >= r.second) {
  5496. invalid = true;
  5497. return true;
  5498. }
  5499. double v = 0.0;
  5500. auto res = from_chars(pb + r.first, pb + r.second, v);
  5501. if (res.ec != std::errc{} || v < 0.0 || v > 1.0) {
  5502. invalid = true;
  5503. return true;
  5504. }
  5505. quality = v;
  5506. return true;
  5507. });
  5508. return !invalid;
  5509. }
  5510. inline EncodingType encoding_type(const Request &req, const Response &res) {
  5511. if (!can_compress_content_type(res.get_header_value("Content-Type"))) {
  5512. return EncodingType::None;
  5513. }
  5514. const auto &s = req.get_header_value("Accept-Encoding");
  5515. if (s.empty()) { return EncodingType::None; }
  5516. // Single-pass: iterate tokens and track the best supported encoding.
  5517. // Server preference breaks ties (br > gzip > zstd).
  5518. EncodingType best = EncodingType::None;
  5519. double best_q = 0.0; // q=0 means "not acceptable"
  5520. // Server preference: Brotli > Gzip > Zstd (lower = more preferred)
  5521. auto priority = [](EncodingType t) -> int {
  5522. switch (t) {
  5523. case EncodingType::Brotli: return 0;
  5524. case EncodingType::Gzip: return 1;
  5525. case EncodingType::Zstd: return 2;
  5526. default: return 3;
  5527. }
  5528. };
  5529. std::string name;
  5530. split(s.data(), s.data() + s.size(), ',', [&](const char *b, const char *e) {
  5531. double quality = 1.0;
  5532. if (!parse_quality(b, e, name, quality)) { return; }
  5533. if (quality <= 0.0) { return; }
  5534. EncodingType type = EncodingType::None;
  5535. #ifdef CPPHTTPLIB_BROTLI_SUPPORT
  5536. if (case_ignore::equal(name, "br")) { type = EncodingType::Brotli; }
  5537. #endif
  5538. #ifdef CPPHTTPLIB_ZLIB_SUPPORT
  5539. if (type == EncodingType::None && case_ignore::equal(name, "gzip")) {
  5540. type = EncodingType::Gzip;
  5541. }
  5542. #endif
  5543. #ifdef CPPHTTPLIB_ZSTD_SUPPORT
  5544. if (type == EncodingType::None && case_ignore::equal(name, "zstd")) {
  5545. type = EncodingType::Zstd;
  5546. }
  5547. #endif
  5548. if (type == EncodingType::None) { return; }
  5549. // Higher q-value wins; for equal q, server preference breaks ties
  5550. if (quality > best_q ||
  5551. (quality == best_q && priority(type) < priority(best))) {
  5552. best_q = quality;
  5553. best = type;
  5554. }
  5555. });
  5556. return best;
  5557. }
  5558. inline std::unique_ptr<compressor> make_compressor(EncodingType type) {
  5559. #ifdef CPPHTTPLIB_ZLIB_SUPPORT
  5560. if (type == EncodingType::Gzip) {
  5561. return detail::make_unique<gzip_compressor>();
  5562. }
  5563. #endif
  5564. #ifdef CPPHTTPLIB_BROTLI_SUPPORT
  5565. if (type == EncodingType::Brotli) {
  5566. return detail::make_unique<brotli_compressor>();
  5567. }
  5568. #endif
  5569. #ifdef CPPHTTPLIB_ZSTD_SUPPORT
  5570. if (type == EncodingType::Zstd) {
  5571. return detail::make_unique<zstd_compressor>();
  5572. }
  5573. #endif
  5574. (void)type;
  5575. return nullptr;
  5576. }
  5577. inline const char *encoding_name(EncodingType type) {
  5578. switch (type) {
  5579. case EncodingType::Gzip: return "gzip";
  5580. case EncodingType::Brotli: return "br";
  5581. case EncodingType::Zstd: return "zstd";
  5582. default: return "";
  5583. }
  5584. }
  5585. inline bool nocompressor::compress(const char *data, size_t data_length,
  5586. bool /*last*/, Callback callback) {
  5587. if (!data_length) { return true; }
  5588. return callback(data, data_length);
  5589. }
  5590. #ifdef CPPHTTPLIB_ZLIB_SUPPORT
  5591. inline gzip_compressor::gzip_compressor() {
  5592. std::memset(&strm_, 0, sizeof(strm_));
  5593. strm_.zalloc = Z_NULL;
  5594. strm_.zfree = Z_NULL;
  5595. strm_.opaque = Z_NULL;
  5596. is_valid_ = deflateInit2(&strm_, Z_DEFAULT_COMPRESSION, Z_DEFLATED, 31, 8,
  5597. Z_DEFAULT_STRATEGY) == Z_OK;
  5598. }
  5599. inline gzip_compressor::~gzip_compressor() { deflateEnd(&strm_); }
  5600. inline bool gzip_compressor::compress(const char *data, size_t data_length,
  5601. bool last, Callback callback) {
  5602. assert(is_valid_);
  5603. do {
  5604. constexpr size_t max_avail_in =
  5605. (std::numeric_limits<decltype(strm_.avail_in)>::max)();
  5606. strm_.avail_in = static_cast<decltype(strm_.avail_in)>(
  5607. (std::min)(data_length, max_avail_in));
  5608. strm_.next_in = const_cast<Bytef *>(reinterpret_cast<const Bytef *>(data));
  5609. data_length -= strm_.avail_in;
  5610. data += strm_.avail_in;
  5611. auto flush = (last && data_length == 0) ? Z_FINISH : Z_NO_FLUSH;
  5612. auto ret = Z_OK;
  5613. std::array<char, CPPHTTPLIB_COMPRESSION_BUFSIZ> buff{};
  5614. do {
  5615. strm_.avail_out = static_cast<uInt>(buff.size());
  5616. strm_.next_out = reinterpret_cast<Bytef *>(buff.data());
  5617. ret = deflate(&strm_, flush);
  5618. if (ret == Z_STREAM_ERROR) { return false; }
  5619. if (!callback(buff.data(), buff.size() - strm_.avail_out)) {
  5620. return false;
  5621. }
  5622. } while (strm_.avail_out == 0);
  5623. assert((flush == Z_FINISH && ret == Z_STREAM_END) ||
  5624. (flush == Z_NO_FLUSH && ret == Z_OK));
  5625. assert(strm_.avail_in == 0);
  5626. } while (data_length > 0);
  5627. return true;
  5628. }
  5629. inline gzip_decompressor::gzip_decompressor() {
  5630. std::memset(&strm_, 0, sizeof(strm_));
  5631. strm_.zalloc = Z_NULL;
  5632. strm_.zfree = Z_NULL;
  5633. strm_.opaque = Z_NULL;
  5634. // 15 is the value of wbits, which should be at the maximum possible value
  5635. // to ensure that any gzip stream can be decoded. The offset of 32 specifies
  5636. // that the stream type should be automatically detected either gzip or
  5637. // deflate.
  5638. is_valid_ = inflateInit2(&strm_, 32 + 15) == Z_OK;
  5639. }
  5640. inline gzip_decompressor::~gzip_decompressor() { inflateEnd(&strm_); }
  5641. inline bool gzip_decompressor::is_valid() const { return is_valid_; }
  5642. inline bool gzip_decompressor::decompress(const char *data, size_t data_length,
  5643. Callback callback) {
  5644. assert(is_valid_);
  5645. auto ret = Z_OK;
  5646. do {
  5647. constexpr size_t max_avail_in =
  5648. (std::numeric_limits<decltype(strm_.avail_in)>::max)();
  5649. strm_.avail_in = static_cast<decltype(strm_.avail_in)>(
  5650. (std::min)(data_length, max_avail_in));
  5651. strm_.next_in = const_cast<Bytef *>(reinterpret_cast<const Bytef *>(data));
  5652. data_length -= strm_.avail_in;
  5653. data += strm_.avail_in;
  5654. std::array<char, CPPHTTPLIB_COMPRESSION_BUFSIZ> buff{};
  5655. while (strm_.avail_in > 0 && ret == Z_OK) {
  5656. strm_.avail_out = static_cast<uInt>(buff.size());
  5657. strm_.next_out = reinterpret_cast<Bytef *>(buff.data());
  5658. ret = inflate(&strm_, Z_NO_FLUSH);
  5659. assert(ret != Z_STREAM_ERROR);
  5660. switch (ret) {
  5661. case Z_NEED_DICT:
  5662. case Z_DATA_ERROR:
  5663. case Z_MEM_ERROR: inflateEnd(&strm_); return false;
  5664. }
  5665. if (!callback(buff.data(), buff.size() - strm_.avail_out)) {
  5666. return false;
  5667. }
  5668. }
  5669. if (ret != Z_OK && ret != Z_STREAM_END) { return false; }
  5670. } while (data_length > 0);
  5671. return true;
  5672. }
  5673. #endif
  5674. #ifdef CPPHTTPLIB_BROTLI_SUPPORT
  5675. inline brotli_compressor::brotli_compressor() {
  5676. state_ = BrotliEncoderCreateInstance(nullptr, nullptr, nullptr);
  5677. }
  5678. inline brotli_compressor::~brotli_compressor() {
  5679. BrotliEncoderDestroyInstance(state_);
  5680. }
  5681. inline bool brotli_compressor::compress(const char *data, size_t data_length,
  5682. bool last, Callback callback) {
  5683. std::array<uint8_t, CPPHTTPLIB_COMPRESSION_BUFSIZ> buff{};
  5684. auto operation = last ? BROTLI_OPERATION_FINISH : BROTLI_OPERATION_PROCESS;
  5685. auto available_in = data_length;
  5686. auto next_in = reinterpret_cast<const uint8_t *>(data);
  5687. for (;;) {
  5688. if (last) {
  5689. if (BrotliEncoderIsFinished(state_)) { break; }
  5690. } else {
  5691. if (!available_in) { break; }
  5692. }
  5693. auto available_out = buff.size();
  5694. auto next_out = buff.data();
  5695. if (!BrotliEncoderCompressStream(state_, operation, &available_in, &next_in,
  5696. &available_out, &next_out, nullptr)) {
  5697. return false;
  5698. }
  5699. auto output_bytes = buff.size() - available_out;
  5700. if (output_bytes) {
  5701. callback(reinterpret_cast<const char *>(buff.data()), output_bytes);
  5702. }
  5703. }
  5704. return true;
  5705. }
  5706. inline brotli_decompressor::brotli_decompressor() {
  5707. decoder_s = BrotliDecoderCreateInstance(0, 0, 0);
  5708. decoder_r = decoder_s ? BROTLI_DECODER_RESULT_NEEDS_MORE_INPUT
  5709. : BROTLI_DECODER_RESULT_ERROR;
  5710. }
  5711. inline brotli_decompressor::~brotli_decompressor() {
  5712. if (decoder_s) { BrotliDecoderDestroyInstance(decoder_s); }
  5713. }
  5714. inline bool brotli_decompressor::is_valid() const { return decoder_s; }
  5715. inline bool brotli_decompressor::decompress(const char *data,
  5716. size_t data_length,
  5717. Callback callback) {
  5718. if (decoder_r == BROTLI_DECODER_RESULT_SUCCESS ||
  5719. decoder_r == BROTLI_DECODER_RESULT_ERROR) {
  5720. return 0;
  5721. }
  5722. auto next_in = reinterpret_cast<const uint8_t *>(data);
  5723. size_t avail_in = data_length;
  5724. size_t total_out;
  5725. decoder_r = BROTLI_DECODER_RESULT_NEEDS_MORE_OUTPUT;
  5726. std::array<char, CPPHTTPLIB_COMPRESSION_BUFSIZ> buff{};
  5727. while (decoder_r == BROTLI_DECODER_RESULT_NEEDS_MORE_OUTPUT) {
  5728. char *next_out = buff.data();
  5729. size_t avail_out = buff.size();
  5730. decoder_r = BrotliDecoderDecompressStream(
  5731. decoder_s, &avail_in, &next_in, &avail_out,
  5732. reinterpret_cast<uint8_t **>(&next_out), &total_out);
  5733. if (decoder_r == BROTLI_DECODER_RESULT_ERROR) { return false; }
  5734. if (!callback(buff.data(), buff.size() - avail_out)) { return false; }
  5735. }
  5736. return decoder_r == BROTLI_DECODER_RESULT_SUCCESS ||
  5737. decoder_r == BROTLI_DECODER_RESULT_NEEDS_MORE_INPUT;
  5738. }
  5739. #endif
  5740. #ifdef CPPHTTPLIB_ZSTD_SUPPORT
  5741. inline zstd_compressor::zstd_compressor() {
  5742. ctx_ = ZSTD_createCCtx();
  5743. ZSTD_CCtx_setParameter(ctx_, ZSTD_c_compressionLevel, ZSTD_fast);
  5744. }
  5745. inline zstd_compressor::~zstd_compressor() { ZSTD_freeCCtx(ctx_); }
  5746. inline bool zstd_compressor::compress(const char *data, size_t data_length,
  5747. bool last, Callback callback) {
  5748. std::array<char, CPPHTTPLIB_COMPRESSION_BUFSIZ> buff{};
  5749. ZSTD_EndDirective mode = last ? ZSTD_e_end : ZSTD_e_continue;
  5750. ZSTD_inBuffer input = {data, data_length, 0};
  5751. bool finished;
  5752. do {
  5753. ZSTD_outBuffer output = {buff.data(), CPPHTTPLIB_COMPRESSION_BUFSIZ, 0};
  5754. size_t const remaining = ZSTD_compressStream2(ctx_, &output, &input, mode);
  5755. if (ZSTD_isError(remaining)) { return false; }
  5756. if (!callback(buff.data(), output.pos)) { return false; }
  5757. finished = last ? (remaining == 0) : (input.pos == input.size);
  5758. } while (!finished);
  5759. return true;
  5760. }
  5761. inline zstd_decompressor::zstd_decompressor() { ctx_ = ZSTD_createDCtx(); }
  5762. inline zstd_decompressor::~zstd_decompressor() { ZSTD_freeDCtx(ctx_); }
  5763. inline bool zstd_decompressor::is_valid() const { return ctx_ != nullptr; }
  5764. inline bool zstd_decompressor::decompress(const char *data, size_t data_length,
  5765. Callback callback) {
  5766. std::array<char, CPPHTTPLIB_COMPRESSION_BUFSIZ> buff{};
  5767. ZSTD_inBuffer input = {data, data_length, 0};
  5768. while (input.pos < input.size) {
  5769. ZSTD_outBuffer output = {buff.data(), CPPHTTPLIB_COMPRESSION_BUFSIZ, 0};
  5770. size_t const remaining = ZSTD_decompressStream(ctx_, &output, &input);
  5771. if (ZSTD_isError(remaining)) { return false; }
  5772. if (!callback(buff.data(), output.pos)) { return false; }
  5773. }
  5774. return true;
  5775. }
  5776. #endif
  5777. inline std::unique_ptr<decompressor>
  5778. create_decompressor(const std::string &encoding) {
  5779. std::unique_ptr<decompressor> decompressor;
  5780. if (encoding == "gzip" || encoding == "deflate") {
  5781. #ifdef CPPHTTPLIB_ZLIB_SUPPORT
  5782. decompressor = detail::make_unique<gzip_decompressor>();
  5783. #endif
  5784. } else if (encoding.find("br") != std::string::npos) {
  5785. #ifdef CPPHTTPLIB_BROTLI_SUPPORT
  5786. decompressor = detail::make_unique<brotli_decompressor>();
  5787. #endif
  5788. } else if (encoding == "zstd" || encoding.find("zstd") != std::string::npos) {
  5789. #ifdef CPPHTTPLIB_ZSTD_SUPPORT
  5790. decompressor = detail::make_unique<zstd_decompressor>();
  5791. #endif
  5792. }
  5793. return decompressor;
  5794. }
  5795. // Returns the best available compressor and its Content-Encoding name.
  5796. // Priority: Brotli > Gzip > Zstd (matches server-side preference).
  5797. inline std::pair<std::unique_ptr<compressor>, const char *>
  5798. create_compressor() {
  5799. #ifdef CPPHTTPLIB_BROTLI_SUPPORT
  5800. return {detail::make_unique<brotli_compressor>(), "br"};
  5801. #elif defined(CPPHTTPLIB_ZLIB_SUPPORT)
  5802. return {detail::make_unique<gzip_compressor>(), "gzip"};
  5803. #elif defined(CPPHTTPLIB_ZSTD_SUPPORT)
  5804. return {detail::make_unique<zstd_compressor>(), "zstd"};
  5805. #else
  5806. return {nullptr, nullptr};
  5807. #endif
  5808. }
  5809. inline bool is_prohibited_header_name(const std::string &name) {
  5810. using udl::operator""_t;
  5811. switch (str2tag(name)) {
  5812. case "REMOTE_ADDR"_t:
  5813. case "REMOTE_PORT"_t:
  5814. case "LOCAL_ADDR"_t:
  5815. case "LOCAL_PORT"_t: return true;
  5816. default: return false;
  5817. }
  5818. }
  5819. inline bool has_header(const Headers &headers, const std::string &key) {
  5820. if (is_prohibited_header_name(key)) { return false; }
  5821. return headers.find(key) != headers.end();
  5822. }
  5823. inline const char *get_header_value(const Headers &headers,
  5824. const std::string &key, const char *def,
  5825. size_t id) {
  5826. if (is_prohibited_header_name(key)) {
  5827. #ifndef CPPHTTPLIB_NO_EXCEPTIONS
  5828. std::string msg = "Prohibited header name '" + key + "' is specified.";
  5829. throw std::invalid_argument(msg);
  5830. #else
  5831. return "";
  5832. #endif
  5833. }
  5834. auto rng = headers.equal_range(key);
  5835. auto it = rng.first;
  5836. std::advance(it, static_cast<ssize_t>(id));
  5837. if (it != rng.second) { return it->second.c_str(); }
  5838. return def;
  5839. }
  5840. inline size_t get_header_value_count(const Headers &headers,
  5841. const std::string &key) {
  5842. auto r = headers.equal_range(key);
  5843. return static_cast<size_t>(std::distance(r.first, r.second));
  5844. }
  5845. template <typename Map>
  5846. inline typename Map::mapped_type
  5847. get_multimap_value(const Map &m, const std::string &key, size_t id) {
  5848. auto rng = m.equal_range(key);
  5849. auto it = rng.first;
  5850. std::advance(it, static_cast<ssize_t>(id));
  5851. if (it != rng.second) { return it->second; }
  5852. return typename Map::mapped_type();
  5853. }
  5854. inline void set_header(Headers &headers, const std::string &key,
  5855. const std::string &val) {
  5856. if (fields::is_field_name(key) && fields::is_field_value(val)) {
  5857. headers.emplace(key, val);
  5858. }
  5859. }
  5860. inline bool read_headers(Stream &strm, Headers &headers) {
  5861. const auto bufsiz = 2048;
  5862. char buf[bufsiz];
  5863. stream_line_reader line_reader(strm, buf, bufsiz);
  5864. size_t header_count = 0;
  5865. for (;;) {
  5866. if (!line_reader.getline()) { return false; }
  5867. // Check if the line ends with CRLF.
  5868. auto line_terminator_len = 2;
  5869. if (line_reader.end_with_crlf()) {
  5870. // Blank line indicates end of headers.
  5871. if (line_reader.size() == 2) { break; }
  5872. } else {
  5873. #ifdef CPPHTTPLIB_ALLOW_LF_AS_LINE_TERMINATOR
  5874. // Blank line indicates end of headers.
  5875. if (line_reader.size() == 1) { break; }
  5876. line_terminator_len = 1;
  5877. #else
  5878. continue; // Skip invalid line.
  5879. #endif
  5880. }
  5881. if (line_reader.size() > CPPHTTPLIB_HEADER_MAX_LENGTH) { return false; }
  5882. // Check header count limit
  5883. if (header_count >= CPPHTTPLIB_HEADER_MAX_COUNT) { return false; }
  5884. // Exclude line terminator
  5885. auto end = line_reader.ptr() + line_reader.size() - line_terminator_len;
  5886. if (!parse_header(line_reader.ptr(), end,
  5887. [&](const std::string &key, const std::string &val) {
  5888. headers.emplace(key, val);
  5889. })) {
  5890. return false;
  5891. }
  5892. header_count++;
  5893. }
  5894. // RFC 9110 Section 8.6: Reject requests with multiple Content-Length
  5895. // headers that have different values to prevent request smuggling.
  5896. auto cl_range = headers.equal_range("Content-Length");
  5897. if (cl_range.first != cl_range.second) {
  5898. const auto &first_val = cl_range.first->second;
  5899. for (auto it = std::next(cl_range.first); it != cl_range.second; ++it) {
  5900. if (it->second != first_val) { return false; }
  5901. }
  5902. }
  5903. return true;
  5904. }
  5905. inline bool read_websocket_upgrade_response(Stream &strm,
  5906. const std::string &expected_accept,
  5907. std::string &selected_subprotocol) {
  5908. // Read status line
  5909. const auto bufsiz = 2048;
  5910. char buf[bufsiz];
  5911. stream_line_reader line_reader(strm, buf, bufsiz);
  5912. if (!line_reader.getline()) { return false; }
  5913. // Check for "HTTP/1.1 101"
  5914. auto line = std::string(line_reader.ptr(), line_reader.size());
  5915. if (line.find("HTTP/1.1 101") == std::string::npos) { return false; }
  5916. // Parse headers using existing read_headers
  5917. Headers headers;
  5918. if (!read_headers(strm, headers)) { return false; }
  5919. // Verify Upgrade: websocket (case-insensitive)
  5920. auto upgrade_it = headers.find("Upgrade");
  5921. if (upgrade_it == headers.end()) { return false; }
  5922. auto upgrade_val = case_ignore::to_lower(upgrade_it->second);
  5923. if (upgrade_val != "websocket") { return false; }
  5924. // Verify Connection header contains "Upgrade" (case-insensitive)
  5925. auto connection_it = headers.find("Connection");
  5926. if (connection_it == headers.end()) { return false; }
  5927. auto connection_val = case_ignore::to_lower(connection_it->second);
  5928. if (connection_val.find("upgrade") == std::string::npos) { return false; }
  5929. // Verify Sec-WebSocket-Accept header value
  5930. auto it = headers.find("Sec-WebSocket-Accept");
  5931. if (it == headers.end() || it->second != expected_accept) { return false; }
  5932. // Extract negotiated subprotocol
  5933. auto proto_it = headers.find("Sec-WebSocket-Protocol");
  5934. if (proto_it != headers.end()) { selected_subprotocol = proto_it->second; }
  5935. return true;
  5936. }
  5937. enum class ReadContentResult {
  5938. Success, // Successfully read the content
  5939. PayloadTooLarge, // The content exceeds the specified payload limit
  5940. Error // An error occurred while reading the content
  5941. };
  5942. inline ReadContentResult read_content_with_length(
  5943. Stream &strm, size_t len, DownloadProgress progress,
  5944. ContentReceiverWithProgress out,
  5945. size_t payload_max_length = (std::numeric_limits<size_t>::max)()) {
  5946. char buf[CPPHTTPLIB_RECV_BUFSIZ];
  5947. detail::BodyReader br;
  5948. br.stream = &strm;
  5949. br.has_content_length = true;
  5950. br.content_length = len;
  5951. br.payload_max_length = payload_max_length;
  5952. br.chunked = false;
  5953. br.bytes_read = 0;
  5954. br.last_error = Error::Success;
  5955. size_t r = 0;
  5956. while (r < len) {
  5957. auto read_len = static_cast<size_t>(len - r);
  5958. auto to_read = (std::min)(read_len, CPPHTTPLIB_RECV_BUFSIZ);
  5959. auto n = detail::read_body_content(&strm, br, buf, to_read);
  5960. if (n <= 0) {
  5961. // Check if it was a payload size error
  5962. if (br.last_error == Error::ExceedMaxPayloadSize) {
  5963. return ReadContentResult::PayloadTooLarge;
  5964. }
  5965. return ReadContentResult::Error;
  5966. }
  5967. if (!out(buf, static_cast<size_t>(n), r, len)) {
  5968. return ReadContentResult::Error;
  5969. }
  5970. r += static_cast<size_t>(n);
  5971. if (progress) {
  5972. if (!progress(r, len)) { return ReadContentResult::Error; }
  5973. }
  5974. }
  5975. return ReadContentResult::Success;
  5976. }
  5977. inline ReadContentResult
  5978. read_content_without_length(Stream &strm, size_t payload_max_length,
  5979. ContentReceiverWithProgress out) {
  5980. char buf[CPPHTTPLIB_RECV_BUFSIZ];
  5981. size_t r = 0;
  5982. for (;;) {
  5983. auto n = strm.read(buf, CPPHTTPLIB_RECV_BUFSIZ);
  5984. if (n == 0) { return ReadContentResult::Success; }
  5985. if (n < 0) { return ReadContentResult::Error; }
  5986. // Check if adding this data would exceed the payload limit
  5987. if (r > payload_max_length ||
  5988. payload_max_length - r < static_cast<size_t>(n)) {
  5989. return ReadContentResult::PayloadTooLarge;
  5990. }
  5991. if (!out(buf, static_cast<size_t>(n), r, 0)) {
  5992. return ReadContentResult::Error;
  5993. }
  5994. r += static_cast<size_t>(n);
  5995. }
  5996. return ReadContentResult::Success;
  5997. }
  5998. template <typename T>
  5999. inline ReadContentResult read_content_chunked(Stream &strm, T &x,
  6000. size_t payload_max_length,
  6001. ContentReceiverWithProgress out) {
  6002. detail::ChunkedDecoder dec(strm);
  6003. char buf[CPPHTTPLIB_RECV_BUFSIZ];
  6004. size_t total_len = 0;
  6005. for (;;) {
  6006. size_t chunk_offset = 0;
  6007. size_t chunk_total = 0;
  6008. auto n = dec.read_payload(buf, sizeof(buf), chunk_offset, chunk_total);
  6009. if (n < 0) { return ReadContentResult::Error; }
  6010. if (n == 0) {
  6011. if (!dec.parse_trailers_into(x.trailers, x.headers)) {
  6012. return ReadContentResult::Error;
  6013. }
  6014. return ReadContentResult::Success;
  6015. }
  6016. if (total_len > payload_max_length ||
  6017. payload_max_length - total_len < static_cast<size_t>(n)) {
  6018. return ReadContentResult::PayloadTooLarge;
  6019. }
  6020. if (!out(buf, static_cast<size_t>(n), chunk_offset, chunk_total)) {
  6021. return ReadContentResult::Error;
  6022. }
  6023. total_len += static_cast<size_t>(n);
  6024. }
  6025. }
  6026. inline bool is_chunked_transfer_encoding(const Headers &headers) {
  6027. return case_ignore::equal(
  6028. get_header_value(headers, "Transfer-Encoding", "", 0), "chunked");
  6029. }
  6030. template <typename T, typename U>
  6031. bool prepare_content_receiver(T &x, int &status,
  6032. ContentReceiverWithProgress receiver,
  6033. bool decompress, size_t payload_max_length,
  6034. bool &exceed_payload_max_length, U callback) {
  6035. if (decompress) {
  6036. std::string encoding = x.get_header_value("Content-Encoding");
  6037. std::unique_ptr<decompressor> decompressor;
  6038. if (!encoding.empty()) {
  6039. decompressor = detail::create_decompressor(encoding);
  6040. if (!decompressor) {
  6041. // Unsupported encoding or no support compiled in
  6042. status = StatusCode::UnsupportedMediaType_415;
  6043. return false;
  6044. }
  6045. }
  6046. if (decompressor) {
  6047. if (decompressor->is_valid()) {
  6048. size_t decompressed_size = 0;
  6049. ContentReceiverWithProgress out = [&](const char *buf, size_t n,
  6050. size_t off, size_t len) {
  6051. return decompressor->decompress(
  6052. buf, n, [&](const char *buf2, size_t n2) {
  6053. // Guard against zip-bomb: check
  6054. // decompressed size against limit.
  6055. if (payload_max_length > 0 &&
  6056. (decompressed_size >= payload_max_length ||
  6057. n2 > payload_max_length - decompressed_size)) {
  6058. exceed_payload_max_length = true;
  6059. return false;
  6060. }
  6061. decompressed_size += n2;
  6062. return receiver(buf2, n2, off, len);
  6063. });
  6064. };
  6065. return callback(std::move(out));
  6066. } else {
  6067. status = StatusCode::InternalServerError_500;
  6068. return false;
  6069. }
  6070. }
  6071. }
  6072. ContentReceiverWithProgress out = [&](const char *buf, size_t n, size_t off,
  6073. size_t len) {
  6074. return receiver(buf, n, off, len);
  6075. };
  6076. return callback(std::move(out));
  6077. }
  6078. template <typename T>
  6079. bool read_content(Stream &strm, T &x, size_t payload_max_length, int &status,
  6080. DownloadProgress progress,
  6081. ContentReceiverWithProgress receiver, bool decompress) {
  6082. bool exceed_payload_max_length = false;
  6083. return prepare_content_receiver(
  6084. x, status, std::move(receiver), decompress, payload_max_length,
  6085. exceed_payload_max_length, [&](const ContentReceiverWithProgress &out) {
  6086. auto ret = true;
  6087. // Note: exceed_payload_max_length may also be set by the decompressor
  6088. // wrapper in prepare_content_receiver when the decompressed payload
  6089. // size exceeds the limit.
  6090. if (is_chunked_transfer_encoding(x.headers)) {
  6091. auto result = read_content_chunked(strm, x, payload_max_length, out);
  6092. if (result == ReadContentResult::Success) {
  6093. ret = true;
  6094. } else if (result == ReadContentResult::PayloadTooLarge) {
  6095. exceed_payload_max_length = true;
  6096. ret = false;
  6097. } else {
  6098. ret = false;
  6099. }
  6100. } else if (!has_header(x.headers, "Content-Length")) {
  6101. auto result =
  6102. read_content_without_length(strm, payload_max_length, out);
  6103. if (result == ReadContentResult::Success) {
  6104. ret = true;
  6105. } else if (result == ReadContentResult::PayloadTooLarge) {
  6106. exceed_payload_max_length = true;
  6107. ret = false;
  6108. } else {
  6109. ret = false;
  6110. }
  6111. } else {
  6112. auto is_invalid_value = false;
  6113. auto len = get_header_value_u64(x.headers, "Content-Length",
  6114. (std::numeric_limits<size_t>::max)(),
  6115. 0, is_invalid_value);
  6116. if (is_invalid_value) {
  6117. ret = false;
  6118. } else if (len > 0) {
  6119. auto result = read_content_with_length(
  6120. strm, len, std::move(progress), out, payload_max_length);
  6121. ret = (result == ReadContentResult::Success);
  6122. if (result == ReadContentResult::PayloadTooLarge) {
  6123. exceed_payload_max_length = true;
  6124. }
  6125. }
  6126. }
  6127. if (!ret) {
  6128. status = exceed_payload_max_length ? StatusCode::PayloadTooLarge_413
  6129. : StatusCode::BadRequest_400;
  6130. }
  6131. return ret;
  6132. });
  6133. }
  6134. inline ssize_t write_request_line(Stream &strm, const std::string &method,
  6135. const std::string &path) {
  6136. std::string s = method;
  6137. s += ' ';
  6138. s += path;
  6139. s += " HTTP/1.1\r\n";
  6140. return strm.write(s.data(), s.size());
  6141. }
  6142. inline ssize_t write_response_line(Stream &strm, int status) {
  6143. std::string s = "HTTP/1.1 ";
  6144. s += std::to_string(status);
  6145. s += ' ';
  6146. s += httplib::status_message(status);
  6147. s += "\r\n";
  6148. return strm.write(s.data(), s.size());
  6149. }
  6150. inline ssize_t write_headers(Stream &strm, const Headers &headers) {
  6151. ssize_t write_len = 0;
  6152. for (const auto &x : headers) {
  6153. std::string s;
  6154. s = x.first;
  6155. s += ": ";
  6156. s += x.second;
  6157. s += "\r\n";
  6158. auto len = strm.write(s.data(), s.size());
  6159. if (len < 0) { return len; }
  6160. write_len += len;
  6161. }
  6162. auto len = strm.write("\r\n");
  6163. if (len < 0) { return len; }
  6164. write_len += len;
  6165. return write_len;
  6166. }
  6167. inline bool write_data(Stream &strm, const char *d, size_t l) {
  6168. size_t offset = 0;
  6169. while (offset < l) {
  6170. auto length = strm.write(d + offset, l - offset);
  6171. if (length < 0) { return false; }
  6172. offset += static_cast<size_t>(length);
  6173. }
  6174. return true;
  6175. }
  6176. template <typename T>
  6177. inline bool write_content_with_progress(Stream &strm,
  6178. const ContentProvider &content_provider,
  6179. size_t offset, size_t length,
  6180. T is_shutting_down,
  6181. const UploadProgress &upload_progress,
  6182. Error &error) {
  6183. size_t end_offset = offset + length;
  6184. size_t start_offset = offset;
  6185. auto ok = true;
  6186. DataSink data_sink;
  6187. data_sink.write = [&](const char *d, size_t l) -> bool {
  6188. if (ok) {
  6189. if (write_data(strm, d, l)) {
  6190. offset += l;
  6191. if (upload_progress && length > 0) {
  6192. size_t current_written = offset - start_offset;
  6193. if (!upload_progress(current_written, length)) {
  6194. ok = false;
  6195. return false;
  6196. }
  6197. }
  6198. } else {
  6199. ok = false;
  6200. }
  6201. }
  6202. return ok;
  6203. };
  6204. data_sink.is_writable = [&]() -> bool { return strm.is_peer_alive(); };
  6205. while (offset < end_offset && !is_shutting_down()) {
  6206. if (!strm.wait_writable() || !strm.is_peer_alive()) {
  6207. error = Error::Write;
  6208. return false;
  6209. } else if (!content_provider(offset, end_offset - offset, data_sink)) {
  6210. error = Error::Canceled;
  6211. return false;
  6212. } else if (!ok) {
  6213. error = Error::Write;
  6214. return false;
  6215. }
  6216. }
  6217. if (offset < end_offset) { // exited due to is_shutting_down(), not completion
  6218. error = Error::Write;
  6219. return false;
  6220. }
  6221. error = Error::Success;
  6222. return true;
  6223. }
  6224. template <typename T>
  6225. inline bool write_content(Stream &strm, const ContentProvider &content_provider,
  6226. size_t offset, size_t length, T is_shutting_down,
  6227. Error &error) {
  6228. return write_content_with_progress<T>(strm, content_provider, offset, length,
  6229. is_shutting_down, nullptr, error);
  6230. }
  6231. template <typename T>
  6232. inline bool write_content(Stream &strm, const ContentProvider &content_provider,
  6233. size_t offset, size_t length,
  6234. const T &is_shutting_down) {
  6235. auto error = Error::Success;
  6236. return write_content(strm, content_provider, offset, length, is_shutting_down,
  6237. error);
  6238. }
  6239. template <typename T>
  6240. inline bool
  6241. write_content_without_length(Stream &strm,
  6242. const ContentProvider &content_provider,
  6243. const T &is_shutting_down) {
  6244. size_t offset = 0;
  6245. auto data_available = true;
  6246. auto ok = true;
  6247. DataSink data_sink;
  6248. data_sink.write = [&](const char *d, size_t l) -> bool {
  6249. if (ok) {
  6250. offset += l;
  6251. if (!write_data(strm, d, l)) { ok = false; }
  6252. }
  6253. return ok;
  6254. };
  6255. data_sink.is_writable = [&]() -> bool { return strm.is_peer_alive(); };
  6256. data_sink.done = [&](void) { data_available = false; };
  6257. while (data_available && !is_shutting_down()) {
  6258. if (!strm.wait_writable() || !strm.is_peer_alive()) {
  6259. return false;
  6260. } else if (!content_provider(offset, 0, data_sink)) {
  6261. return false;
  6262. } else if (!ok) {
  6263. return false;
  6264. }
  6265. }
  6266. return !data_available; // true only if done() was called, false if shutting
  6267. // down
  6268. }
  6269. template <typename T, typename U>
  6270. inline bool
  6271. write_content_chunked(Stream &strm, const ContentProvider &content_provider,
  6272. const T &is_shutting_down, U &compressor, Error &error) {
  6273. size_t offset = 0;
  6274. auto data_available = true;
  6275. auto ok = true;
  6276. DataSink data_sink;
  6277. data_sink.write = [&](const char *d, size_t l) -> bool {
  6278. if (ok) {
  6279. data_available = l > 0;
  6280. offset += l;
  6281. std::string payload;
  6282. if (compressor.compress(d, l, false,
  6283. [&](const char *data, size_t data_len) {
  6284. payload.append(data, data_len);
  6285. return true;
  6286. })) {
  6287. if (!payload.empty()) {
  6288. // Emit chunked response header and footer for each chunk
  6289. auto chunk =
  6290. from_i_to_hex(payload.size()) + "\r\n" + payload + "\r\n";
  6291. if (!write_data(strm, chunk.data(), chunk.size())) { ok = false; }
  6292. }
  6293. } else {
  6294. ok = false;
  6295. }
  6296. }
  6297. return ok;
  6298. };
  6299. data_sink.is_writable = [&]() -> bool { return strm.is_peer_alive(); };
  6300. auto done_with_trailer = [&](const Headers *trailer) {
  6301. if (!ok) { return; }
  6302. data_available = false;
  6303. std::string payload;
  6304. if (!compressor.compress(nullptr, 0, true,
  6305. [&](const char *data, size_t data_len) {
  6306. payload.append(data, data_len);
  6307. return true;
  6308. })) {
  6309. ok = false;
  6310. return;
  6311. }
  6312. if (!payload.empty()) {
  6313. // Emit chunked response header and footer for each chunk
  6314. auto chunk = from_i_to_hex(payload.size()) + "\r\n" + payload + "\r\n";
  6315. if (!write_data(strm, chunk.data(), chunk.size())) {
  6316. ok = false;
  6317. return;
  6318. }
  6319. }
  6320. constexpr const char done_marker[] = "0\r\n";
  6321. if (!write_data(strm, done_marker, str_len(done_marker))) { ok = false; }
  6322. // Trailer
  6323. if (trailer) {
  6324. for (const auto &kv : *trailer) {
  6325. std::string field_line = kv.first + ": " + kv.second + "\r\n";
  6326. if (!write_data(strm, field_line.data(), field_line.size())) {
  6327. ok = false;
  6328. }
  6329. }
  6330. }
  6331. constexpr const char crlf[] = "\r\n";
  6332. if (!write_data(strm, crlf, str_len(crlf))) { ok = false; }
  6333. };
  6334. data_sink.done = [&](void) { done_with_trailer(nullptr); };
  6335. data_sink.done_with_trailer = [&](const Headers &trailer) {
  6336. done_with_trailer(&trailer);
  6337. };
  6338. while (data_available && !is_shutting_down()) {
  6339. if (!strm.wait_writable() || !strm.is_peer_alive()) {
  6340. error = Error::Write;
  6341. return false;
  6342. } else if (!content_provider(offset, 0, data_sink)) {
  6343. error = Error::Canceled;
  6344. return false;
  6345. } else if (!ok) {
  6346. error = Error::Write;
  6347. return false;
  6348. }
  6349. }
  6350. if (data_available) { // exited due to is_shutting_down(), not done()
  6351. error = Error::Write;
  6352. return false;
  6353. }
  6354. error = Error::Success;
  6355. return true;
  6356. }
  6357. template <typename T, typename U>
  6358. inline bool write_content_chunked(Stream &strm,
  6359. const ContentProvider &content_provider,
  6360. const T &is_shutting_down, U &compressor) {
  6361. auto error = Error::Success;
  6362. return write_content_chunked(strm, content_provider, is_shutting_down,
  6363. compressor, error);
  6364. }
  6365. template <typename T>
  6366. inline bool redirect(T &cli, Request &req, Response &res,
  6367. const std::string &path, const std::string &location,
  6368. Error &error) {
  6369. Request new_req = req;
  6370. new_req.path = path;
  6371. new_req.redirect_count_ -= 1;
  6372. if (res.status == StatusCode::SeeOther_303 &&
  6373. (req.method != "GET" && req.method != "HEAD")) {
  6374. new_req.method = "GET";
  6375. new_req.body.clear();
  6376. new_req.headers.clear();
  6377. }
  6378. Response new_res;
  6379. auto ret = cli.send(new_req, new_res, error);
  6380. if (ret) {
  6381. req = std::move(new_req);
  6382. res = std::move(new_res);
  6383. if (res.location.empty()) { res.location = location; }
  6384. }
  6385. return ret;
  6386. }
  6387. inline std::string params_to_query_str(const Params &params) {
  6388. std::string query;
  6389. for (auto it = params.begin(); it != params.end(); ++it) {
  6390. if (it != params.begin()) { query += '&'; }
  6391. query += encode_query_component(it->first);
  6392. query += '=';
  6393. query += encode_query_component(it->second);
  6394. }
  6395. return query;
  6396. }
  6397. inline void parse_query_text(const char *data, std::size_t size,
  6398. Params &params) {
  6399. std::set<std::string> cache;
  6400. split(data, data + size, '&', [&](const char *b, const char *e) {
  6401. std::string kv(b, e);
  6402. if (cache.find(kv) != cache.end()) { return; }
  6403. cache.insert(std::move(kv));
  6404. std::string key;
  6405. std::string val;
  6406. divide(b, static_cast<std::size_t>(e - b), '=',
  6407. [&](const char *lhs_data, std::size_t lhs_size, const char *rhs_data,
  6408. std::size_t rhs_size) {
  6409. key.assign(lhs_data, lhs_size);
  6410. val.assign(rhs_data, rhs_size);
  6411. });
  6412. if (!key.empty()) {
  6413. params.emplace(decode_query_component(key), decode_query_component(val));
  6414. }
  6415. });
  6416. }
  6417. inline void parse_query_text(const std::string &s, Params &params) {
  6418. parse_query_text(s.data(), s.size(), params);
  6419. }
  6420. // Normalize a query string by decoding and re-encoding each key/value pair
  6421. // while preserving the original parameter order. This avoids double-encoding
  6422. // and ensures consistent encoding without reordering (unlike Params which
  6423. // uses std::multimap and sorts keys).
  6424. inline std::string normalize_query_string(const std::string &query) {
  6425. std::string result;
  6426. split(query.data(), query.data() + query.size(), '&',
  6427. [&](const char *b, const char *e) {
  6428. std::string key;
  6429. std::string val;
  6430. divide(b, static_cast<std::size_t>(e - b), '=',
  6431. [&](const char *lhs_data, std::size_t lhs_size,
  6432. const char *rhs_data, std::size_t rhs_size) {
  6433. key.assign(lhs_data, lhs_size);
  6434. val.assign(rhs_data, rhs_size);
  6435. });
  6436. if (!key.empty()) {
  6437. auto dec_key = decode_query_component(key);
  6438. auto dec_val = decode_query_component(val);
  6439. if (!result.empty()) { result += '&'; }
  6440. result += encode_query_component(dec_key);
  6441. if (!val.empty() || std::find(b, e, '=') != e) {
  6442. result += '=';
  6443. result += encode_query_component(dec_val);
  6444. }
  6445. }
  6446. });
  6447. return result;
  6448. }
  6449. inline bool parse_multipart_boundary(const std::string &content_type,
  6450. std::string &boundary) {
  6451. std::map<std::string, std::string> params;
  6452. extract_media_type(content_type, &params);
  6453. auto it = params.find("boundary");
  6454. if (it == params.end()) { return false; }
  6455. boundary = it->second;
  6456. return !boundary.empty();
  6457. }
  6458. inline void parse_disposition_params(const std::string &s, Params &params) {
  6459. std::set<std::string> cache;
  6460. split(s.data(), s.data() + s.size(), ';', [&](const char *b, const char *e) {
  6461. std::string kv(b, e);
  6462. if (cache.find(kv) != cache.end()) { return; }
  6463. cache.insert(kv);
  6464. std::string key;
  6465. std::string val;
  6466. split(b, e, '=', [&](const char *b2, const char *e2) {
  6467. if (key.empty()) {
  6468. key.assign(b2, e2);
  6469. } else {
  6470. val.assign(b2, e2);
  6471. }
  6472. });
  6473. if (!key.empty()) {
  6474. params.emplace(trim_double_quotes_copy((key)),
  6475. trim_double_quotes_copy((val)));
  6476. }
  6477. });
  6478. }
  6479. #ifdef CPPHTTPLIB_NO_EXCEPTIONS
  6480. inline bool parse_range_header(const std::string &s, Ranges &ranges) {
  6481. #else
  6482. inline bool parse_range_header(const std::string &s, Ranges &ranges) try {
  6483. #endif
  6484. auto is_valid = [](const std::string &str) {
  6485. return std::all_of(str.cbegin(), str.cend(),
  6486. [](unsigned char c) { return std::isdigit(c); });
  6487. };
  6488. if (s.size() > 7 && s.compare(0, 6, "bytes=") == 0) {
  6489. const auto pos = static_cast<size_t>(6);
  6490. const auto len = static_cast<size_t>(s.size() - 6);
  6491. auto all_valid_ranges = true;
  6492. split(&s[pos], &s[pos + len], ',', [&](const char *b, const char *e) {
  6493. if (!all_valid_ranges) { return; }
  6494. const auto it = std::find(b, e, '-');
  6495. if (it == e) {
  6496. all_valid_ranges = false;
  6497. return;
  6498. }
  6499. const auto lhs = std::string(b, it);
  6500. const auto rhs = std::string(it + 1, e);
  6501. if (!is_valid(lhs) || !is_valid(rhs)) {
  6502. all_valid_ranges = false;
  6503. return;
  6504. }
  6505. ssize_t first = -1;
  6506. if (!lhs.empty()) {
  6507. ssize_t v;
  6508. auto res = detail::from_chars(lhs.data(), lhs.data() + lhs.size(), v);
  6509. if (res.ec == std::errc{}) { first = v; }
  6510. }
  6511. ssize_t last = -1;
  6512. if (!rhs.empty()) {
  6513. ssize_t v;
  6514. auto res = detail::from_chars(rhs.data(), rhs.data() + rhs.size(), v);
  6515. if (res.ec == std::errc{}) { last = v; }
  6516. }
  6517. if ((first == -1 && last == -1) ||
  6518. (first != -1 && last != -1 && first > last)) {
  6519. all_valid_ranges = false;
  6520. return;
  6521. }
  6522. ranges.emplace_back(first, last);
  6523. });
  6524. return all_valid_ranges && !ranges.empty();
  6525. }
  6526. return false;
  6527. #ifdef CPPHTTPLIB_NO_EXCEPTIONS
  6528. }
  6529. #else
  6530. } catch (...) { return false; }
  6531. #endif
  6532. inline bool parse_accept_header(const std::string &s,
  6533. std::vector<std::string> &content_types) {
  6534. content_types.clear();
  6535. // Empty string is considered valid (no preference)
  6536. if (s.empty()) { return true; }
  6537. // Check for invalid patterns: leading/trailing commas or consecutive commas
  6538. if (s.front() == ',' || s.back() == ',' ||
  6539. s.find(",,") != std::string::npos) {
  6540. return false;
  6541. }
  6542. struct AcceptEntry {
  6543. std::string media_type;
  6544. double quality;
  6545. int order;
  6546. };
  6547. std::vector<AcceptEntry> entries;
  6548. int order = 0;
  6549. bool has_invalid_entry = false;
  6550. // Split by comma and parse each entry
  6551. split(s.data(), s.data() + s.size(), ',', [&](const char *b, const char *e) {
  6552. std::string entry(b, e);
  6553. entry = trim_copy(entry);
  6554. if (entry.empty()) {
  6555. has_invalid_entry = true;
  6556. return;
  6557. }
  6558. AcceptEntry accept_entry;
  6559. accept_entry.order = order++;
  6560. if (!parse_quality(entry.data(), entry.data() + entry.size(),
  6561. accept_entry.media_type, accept_entry.quality)) {
  6562. has_invalid_entry = true;
  6563. return;
  6564. }
  6565. // Remove additional parameters from media type
  6566. accept_entry.media_type = extract_media_type(accept_entry.media_type);
  6567. // Basic validation of media type format
  6568. if (accept_entry.media_type.empty()) {
  6569. has_invalid_entry = true;
  6570. return;
  6571. }
  6572. // Check for basic media type format (should contain '/' or be '*')
  6573. if (accept_entry.media_type != "*" &&
  6574. accept_entry.media_type.find('/') == std::string::npos) {
  6575. has_invalid_entry = true;
  6576. return;
  6577. }
  6578. entries.push_back(std::move(accept_entry));
  6579. });
  6580. // Return false if any invalid entry was found
  6581. if (has_invalid_entry) { return false; }
  6582. // Sort by quality (descending), then by original order (ascending)
  6583. std::sort(entries.begin(), entries.end(),
  6584. [](const AcceptEntry &a, const AcceptEntry &b) {
  6585. if (a.quality != b.quality) {
  6586. return a.quality > b.quality; // Higher quality first
  6587. }
  6588. return a.order < b.order; // Earlier order first for same quality
  6589. });
  6590. // Extract sorted media types
  6591. content_types.reserve(entries.size());
  6592. for (auto &entry : entries) {
  6593. content_types.push_back(std::move(entry.media_type));
  6594. }
  6595. return true;
  6596. }
  6597. class FormDataParser {
  6598. public:
  6599. FormDataParser() = default;
  6600. void set_boundary(std::string &&boundary) {
  6601. boundary_ = std::move(boundary);
  6602. dash_boundary_crlf_ = dash_ + boundary_ + crlf_;
  6603. crlf_dash_boundary_ = crlf_ + dash_ + boundary_;
  6604. }
  6605. bool is_valid() const { return is_valid_; }
  6606. bool parse(const char *buf, size_t n, const FormDataHeader &header_callback,
  6607. const ContentReceiver &content_callback) {
  6608. buf_append(buf, n);
  6609. while (buf_size() > 0) {
  6610. switch (state_) {
  6611. case 0: { // Initial boundary
  6612. auto pos = buf_find(dash_boundary_crlf_);
  6613. if (pos == buf_size()) { return true; }
  6614. buf_erase(pos + dash_boundary_crlf_.size());
  6615. state_ = 1;
  6616. break;
  6617. }
  6618. case 1: { // New entry
  6619. clear_file_info();
  6620. state_ = 2;
  6621. break;
  6622. }
  6623. case 2: { // Headers
  6624. auto pos = buf_find(crlf_);
  6625. if (pos > CPPHTTPLIB_HEADER_MAX_LENGTH) { return false; }
  6626. while (pos < buf_size()) {
  6627. // Empty line
  6628. if (pos == 0) {
  6629. if (!header_callback(file_)) {
  6630. is_valid_ = false;
  6631. return false;
  6632. }
  6633. buf_erase(crlf_.size());
  6634. state_ = 3;
  6635. break;
  6636. }
  6637. const auto header = buf_head(pos);
  6638. if (!parse_header(header.data(), header.data() + header.size(),
  6639. [&](const std::string &, const std::string &) {})) {
  6640. is_valid_ = false;
  6641. return false;
  6642. }
  6643. // Parse and emplace space trimmed headers into a map
  6644. if (!parse_header(
  6645. header.data(), header.data() + header.size(),
  6646. [&](const std::string &key, const std::string &val) {
  6647. file_.headers.emplace(key, val);
  6648. })) {
  6649. is_valid_ = false;
  6650. return false;
  6651. }
  6652. constexpr const char header_content_type[] = "Content-Type:";
  6653. if (start_with_case_ignore(header, header_content_type)) {
  6654. file_.content_type =
  6655. trim_copy(header.substr(str_len(header_content_type)));
  6656. } else {
  6657. std::string disposition_params;
  6658. if (parse_content_disposition(header, disposition_params)) {
  6659. Params params;
  6660. parse_disposition_params(disposition_params, params);
  6661. auto it = params.find("name");
  6662. if (it != params.end()) {
  6663. file_.name = it->second;
  6664. } else {
  6665. is_valid_ = false;
  6666. return false;
  6667. }
  6668. it = params.find("filename");
  6669. if (it != params.end()) { file_.filename = it->second; }
  6670. it = params.find("filename*");
  6671. if (it != params.end()) {
  6672. // RFC 5987: only UTF-8 encoding is allowed
  6673. const auto &val = it->second;
  6674. constexpr const char utf8_prefix[] = "UTF-8''";
  6675. constexpr size_t prefix_len = str_len(utf8_prefix);
  6676. if (val.size() > prefix_len &&
  6677. start_with_case_ignore(val, utf8_prefix)) {
  6678. file_.filename = decode_path_component(
  6679. val.substr(prefix_len)); // override...
  6680. } else {
  6681. is_valid_ = false;
  6682. return false;
  6683. }
  6684. }
  6685. }
  6686. }
  6687. buf_erase(pos + crlf_.size());
  6688. pos = buf_find(crlf_);
  6689. }
  6690. if (state_ != 3) { return true; }
  6691. break;
  6692. }
  6693. case 3: { // Body
  6694. if (crlf_dash_boundary_.size() > buf_size()) { return true; }
  6695. auto pos = buf_find(crlf_dash_boundary_);
  6696. if (pos < buf_size()) {
  6697. if (!content_callback(buf_data(), pos)) {
  6698. is_valid_ = false;
  6699. return false;
  6700. }
  6701. buf_erase(pos + crlf_dash_boundary_.size());
  6702. state_ = 4;
  6703. } else {
  6704. auto len = buf_size() - crlf_dash_boundary_.size();
  6705. if (len > 0) {
  6706. if (!content_callback(buf_data(), len)) {
  6707. is_valid_ = false;
  6708. return false;
  6709. }
  6710. buf_erase(len);
  6711. }
  6712. return true;
  6713. }
  6714. break;
  6715. }
  6716. case 4: { // Boundary
  6717. if (crlf_.size() > buf_size()) { return true; }
  6718. if (buf_start_with(crlf_)) {
  6719. buf_erase(crlf_.size());
  6720. state_ = 1;
  6721. } else {
  6722. if (dash_.size() > buf_size()) { return true; }
  6723. if (buf_start_with(dash_)) {
  6724. buf_erase(dash_.size());
  6725. is_valid_ = true;
  6726. buf_erase(buf_size()); // Remove epilogue
  6727. } else {
  6728. return true;
  6729. }
  6730. }
  6731. break;
  6732. }
  6733. }
  6734. }
  6735. return true;
  6736. }
  6737. private:
  6738. void clear_file_info() {
  6739. file_.name.clear();
  6740. file_.filename.clear();
  6741. file_.content_type.clear();
  6742. file_.headers.clear();
  6743. }
  6744. bool start_with_case_ignore(const std::string &a, const char *b,
  6745. size_t offset = 0) const {
  6746. const auto b_len = strlen(b);
  6747. if (a.size() < offset + b_len) { return false; }
  6748. for (size_t i = 0; i < b_len; i++) {
  6749. if (case_ignore::to_lower(a[offset + i]) != case_ignore::to_lower(b[i])) {
  6750. return false;
  6751. }
  6752. }
  6753. return true;
  6754. }
  6755. // Parses "Content-Disposition: form-data; <params>" without std::regex.
  6756. // Returns true if header matches, with the params portion in `params_out`.
  6757. bool parse_content_disposition(const std::string &header,
  6758. std::string &params_out) const {
  6759. constexpr const char prefix[] = "Content-Disposition:";
  6760. constexpr size_t prefix_len = str_len(prefix);
  6761. if (!start_with_case_ignore(header, prefix)) { return false; }
  6762. // Skip whitespace after "Content-Disposition:"
  6763. auto pos = prefix_len;
  6764. while (pos < header.size() && (header[pos] == ' ' || header[pos] == '\t')) {
  6765. pos++;
  6766. }
  6767. // Match "form-data;" (case-insensitive)
  6768. constexpr const char form_data[] = "form-data;";
  6769. constexpr size_t form_data_len = str_len(form_data);
  6770. if (!start_with_case_ignore(header, form_data, pos)) { return false; }
  6771. pos += form_data_len;
  6772. // Skip whitespace after "form-data;"
  6773. while (pos < header.size() && (header[pos] == ' ' || header[pos] == '\t')) {
  6774. pos++;
  6775. }
  6776. params_out = header.substr(pos);
  6777. return true;
  6778. }
  6779. const std::string dash_ = "--";
  6780. const std::string crlf_ = "\r\n";
  6781. std::string boundary_;
  6782. std::string dash_boundary_crlf_;
  6783. std::string crlf_dash_boundary_;
  6784. size_t state_ = 0;
  6785. bool is_valid_ = false;
  6786. FormData file_;
  6787. // Buffer
  6788. bool start_with(const std::string &a, size_t spos, size_t epos,
  6789. const std::string &b) const {
  6790. if (epos - spos < b.size()) { return false; }
  6791. for (size_t i = 0; i < b.size(); i++) {
  6792. if (a[i + spos] != b[i]) { return false; }
  6793. }
  6794. return true;
  6795. }
  6796. size_t buf_size() const { return buf_epos_ - buf_spos_; }
  6797. const char *buf_data() const { return &buf_[buf_spos_]; }
  6798. std::string buf_head(size_t l) const { return buf_.substr(buf_spos_, l); }
  6799. bool buf_start_with(const std::string &s) const {
  6800. return start_with(buf_, buf_spos_, buf_epos_, s);
  6801. }
  6802. size_t buf_find(const std::string &s) const {
  6803. auto c = s.front();
  6804. size_t off = buf_spos_;
  6805. while (off < buf_epos_) {
  6806. auto pos = off;
  6807. while (true) {
  6808. if (pos == buf_epos_) { return buf_size(); }
  6809. if (buf_[pos] == c) { break; }
  6810. pos++;
  6811. }
  6812. auto remaining_size = buf_epos_ - pos;
  6813. if (s.size() > remaining_size) { return buf_size(); }
  6814. if (start_with(buf_, pos, buf_epos_, s)) { return pos - buf_spos_; }
  6815. off = pos + 1;
  6816. }
  6817. return buf_size();
  6818. }
  6819. void buf_append(const char *data, size_t n) {
  6820. auto remaining_size = buf_size();
  6821. if (remaining_size > 0 && buf_spos_ > 0) {
  6822. for (size_t i = 0; i < remaining_size; i++) {
  6823. buf_[i] = buf_[buf_spos_ + i];
  6824. }
  6825. }
  6826. buf_spos_ = 0;
  6827. buf_epos_ = remaining_size;
  6828. if (remaining_size + n > buf_.size()) { buf_.resize(remaining_size + n); }
  6829. for (size_t i = 0; i < n; i++) {
  6830. buf_[buf_epos_ + i] = data[i];
  6831. }
  6832. buf_epos_ += n;
  6833. }
  6834. void buf_erase(size_t size) { buf_spos_ += size; }
  6835. std::string buf_;
  6836. size_t buf_spos_ = 0;
  6837. size_t buf_epos_ = 0;
  6838. };
  6839. inline std::string random_string(size_t length) {
  6840. constexpr const char data[] =
  6841. "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
  6842. thread_local auto engine([]() {
  6843. // std::random_device might actually be deterministic on some
  6844. // platforms, but due to lack of support in the c++ standard library,
  6845. // doing better requires either some ugly hacks or breaking portability.
  6846. std::random_device seed_gen;
  6847. // Request 128 bits of entropy for initialization
  6848. std::seed_seq seed_sequence{seed_gen(), seed_gen(), seed_gen(), seed_gen()};
  6849. return std::mt19937(seed_sequence);
  6850. }());
  6851. std::string result;
  6852. for (size_t i = 0; i < length; i++) {
  6853. result += data[engine() % (sizeof(data) - 1)];
  6854. }
  6855. return result;
  6856. }
  6857. inline std::string make_multipart_data_boundary() {
  6858. return "--cpp-httplib-multipart-data-" + detail::random_string(16);
  6859. }
  6860. inline bool is_multipart_boundary_chars_valid(const std::string &boundary) {
  6861. auto valid = true;
  6862. for (size_t i = 0; i < boundary.size(); i++) {
  6863. auto c = boundary[i];
  6864. if (!std::isalnum(static_cast<unsigned char>(c)) && c != '-' && c != '_') {
  6865. valid = false;
  6866. break;
  6867. }
  6868. }
  6869. return valid;
  6870. }
  6871. template <typename T>
  6872. inline std::string
  6873. serialize_multipart_formdata_item_begin(const T &item,
  6874. const std::string &boundary) {
  6875. std::string body = "--" + boundary + "\r\n";
  6876. body += "Content-Disposition: form-data; name=\"" + item.name + "\"";
  6877. if (!item.filename.empty()) {
  6878. body += "; filename=\"" + item.filename + "\"";
  6879. }
  6880. body += "\r\n";
  6881. if (!item.content_type.empty()) {
  6882. body += "Content-Type: " + item.content_type + "\r\n";
  6883. }
  6884. body += "\r\n";
  6885. return body;
  6886. }
  6887. inline std::string serialize_multipart_formdata_item_end() { return "\r\n"; }
  6888. inline std::string
  6889. serialize_multipart_formdata_finish(const std::string &boundary) {
  6890. return "--" + boundary + "--\r\n";
  6891. }
  6892. inline std::string
  6893. serialize_multipart_formdata_get_content_type(const std::string &boundary) {
  6894. return "multipart/form-data; boundary=" + boundary;
  6895. }
  6896. inline std::string
  6897. serialize_multipart_formdata(const UploadFormDataItems &items,
  6898. const std::string &boundary, bool finish = true) {
  6899. std::string body;
  6900. for (const auto &item : items) {
  6901. body += serialize_multipart_formdata_item_begin(item, boundary);
  6902. body += item.content + serialize_multipart_formdata_item_end();
  6903. }
  6904. if (finish) { body += serialize_multipart_formdata_finish(boundary); }
  6905. return body;
  6906. }
  6907. inline size_t get_multipart_content_length(const UploadFormDataItems &items,
  6908. const std::string &boundary) {
  6909. size_t total = 0;
  6910. for (const auto &item : items) {
  6911. total += serialize_multipart_formdata_item_begin(item, boundary).size();
  6912. total += item.content.size();
  6913. total += serialize_multipart_formdata_item_end().size();
  6914. }
  6915. total += serialize_multipart_formdata_finish(boundary).size();
  6916. return total;
  6917. }
  6918. struct MultipartSegment {
  6919. const char *data;
  6920. size_t size;
  6921. };
  6922. // NOTE: items must outlive the returned ContentProvider
  6923. // (safe for synchronous use inside Post/Put/Patch)
  6924. inline ContentProvider
  6925. make_multipart_content_provider(const UploadFormDataItems &items,
  6926. const std::string &boundary) {
  6927. // Own the per-item header strings and the finish string
  6928. std::vector<std::string> owned;
  6929. owned.reserve(items.size() + 1);
  6930. for (const auto &item : items)
  6931. owned.push_back(serialize_multipart_formdata_item_begin(item, boundary));
  6932. owned.push_back(serialize_multipart_formdata_finish(boundary));
  6933. // Flat segment list: [header, content, "\r\n"] * N + [finish]
  6934. std::vector<MultipartSegment> segs;
  6935. segs.reserve(items.size() * 3 + 1);
  6936. static const char crlf[] = "\r\n";
  6937. for (size_t i = 0; i < items.size(); i++) {
  6938. segs.push_back({owned[i].data(), owned[i].size()});
  6939. segs.push_back({items[i].content.data(), items[i].content.size()});
  6940. segs.push_back({crlf, 2});
  6941. }
  6942. segs.push_back({owned.back().data(), owned.back().size()});
  6943. struct MultipartState {
  6944. std::vector<std::string> owned;
  6945. std::vector<MultipartSegment> segs;
  6946. std::vector<char> buf = std::vector<char>(CPPHTTPLIB_SEND_BUFSIZ);
  6947. };
  6948. auto state = std::make_shared<MultipartState>();
  6949. state->owned = std::move(owned);
  6950. // `segs` holds raw pointers into owned strings; std::string move preserves
  6951. // the data pointer, so these pointers remain valid after the move above.
  6952. state->segs = std::move(segs);
  6953. return [state](size_t offset, size_t length, DataSink &sink) -> bool {
  6954. // Buffer multiple small segments into fewer, larger writes to avoid
  6955. // excessive TCP packets when there are many form data items (#2410)
  6956. auto &buf = state->buf;
  6957. auto buf_size = buf.size();
  6958. size_t buf_len = 0;
  6959. size_t remaining = length;
  6960. // Find the first segment containing 'offset'
  6961. size_t pos = 0;
  6962. size_t seg_idx = 0;
  6963. for (; seg_idx < state->segs.size(); seg_idx++) {
  6964. const auto &seg = state->segs[seg_idx];
  6965. if (seg.size > 0 && offset - pos < seg.size) { break; }
  6966. pos += seg.size;
  6967. }
  6968. size_t seg_offset = (seg_idx < state->segs.size()) ? offset - pos : 0;
  6969. for (; seg_idx < state->segs.size() && remaining > 0; seg_idx++) {
  6970. const auto &seg = state->segs[seg_idx];
  6971. size_t available = seg.size - seg_offset;
  6972. size_t to_copy = (std::min)(available, remaining);
  6973. const char *src = seg.data + seg_offset;
  6974. seg_offset = 0; // only the first segment has a non-zero offset
  6975. while (to_copy > 0) {
  6976. size_t space = buf_size - buf_len;
  6977. size_t chunk = (std::min)(to_copy, space);
  6978. std::memcpy(buf.data() + buf_len, src, chunk);
  6979. buf_len += chunk;
  6980. src += chunk;
  6981. to_copy -= chunk;
  6982. remaining -= chunk;
  6983. if (buf_len == buf_size) {
  6984. if (!sink.write(buf.data(), buf_len)) { return false; }
  6985. buf_len = 0;
  6986. }
  6987. }
  6988. }
  6989. if (buf_len > 0) { return sink.write(buf.data(), buf_len); }
  6990. return true;
  6991. };
  6992. }
  6993. inline void coalesce_ranges(Ranges &ranges, size_t content_length) {
  6994. if (ranges.size() <= 1) return;
  6995. // Sort ranges by start position
  6996. std::sort(ranges.begin(), ranges.end(),
  6997. [](const Range &a, const Range &b) { return a.first < b.first; });
  6998. Ranges coalesced;
  6999. coalesced.reserve(ranges.size());
  7000. for (auto &r : ranges) {
  7001. auto first_pos = r.first;
  7002. auto last_pos = r.second;
  7003. // Handle special cases like in range_error
  7004. if (first_pos == -1 && last_pos == -1) {
  7005. first_pos = 0;
  7006. last_pos = static_cast<ssize_t>(content_length);
  7007. }
  7008. if (first_pos == -1) {
  7009. first_pos = static_cast<ssize_t>(content_length) - last_pos;
  7010. last_pos = static_cast<ssize_t>(content_length) - 1;
  7011. }
  7012. if (last_pos == -1 || last_pos >= static_cast<ssize_t>(content_length)) {
  7013. last_pos = static_cast<ssize_t>(content_length) - 1;
  7014. }
  7015. // Skip invalid ranges
  7016. if (!(0 <= first_pos && first_pos <= last_pos &&
  7017. last_pos < static_cast<ssize_t>(content_length))) {
  7018. continue;
  7019. }
  7020. // Coalesce with previous range if overlapping or adjacent (but not
  7021. // identical)
  7022. if (!coalesced.empty()) {
  7023. auto &prev = coalesced.back();
  7024. // Check if current range overlaps or is adjacent to previous range
  7025. // but don't coalesce identical ranges (allow duplicates)
  7026. if (first_pos <= prev.second + 1 &&
  7027. !(first_pos == prev.first && last_pos == prev.second)) {
  7028. // Extend the previous range
  7029. prev.second = (std::max)(prev.second, last_pos);
  7030. continue;
  7031. }
  7032. }
  7033. // Add new range
  7034. coalesced.emplace_back(first_pos, last_pos);
  7035. }
  7036. ranges = std::move(coalesced);
  7037. }
  7038. inline bool range_error(Request &req, Response &res) {
  7039. if (!req.ranges.empty() && 200 <= res.status && res.status < 300) {
  7040. if (res.body.empty() && res.content_provider_ && res.content_length_ == 0) {
  7041. req.ranges.clear();
  7042. if (res.status == StatusCode::PartialContent_206) {
  7043. res.status = StatusCode::OK_200;
  7044. }
  7045. return false;
  7046. }
  7047. ssize_t content_len = static_cast<ssize_t>(
  7048. res.content_length_ ? res.content_length_ : res.body.size());
  7049. std::vector<std::pair<ssize_t, ssize_t>> processed_ranges;
  7050. size_t overwrapping_count = 0;
  7051. // NOTE: The following Range check is based on '14.2. Range' in RFC 9110
  7052. // 'HTTP Semantics' to avoid potential denial-of-service attacks.
  7053. // https://www.rfc-editor.org/rfc/rfc9110#section-14.2
  7054. // Too many ranges
  7055. if (req.ranges.size() > CPPHTTPLIB_RANGE_MAX_COUNT) { return true; }
  7056. for (auto &r : req.ranges) {
  7057. auto &first_pos = r.first;
  7058. auto &last_pos = r.second;
  7059. if (first_pos == -1 && last_pos == -1) {
  7060. first_pos = 0;
  7061. last_pos = content_len;
  7062. }
  7063. if (first_pos == -1) {
  7064. first_pos = content_len - last_pos;
  7065. last_pos = content_len - 1;
  7066. }
  7067. // NOTE: RFC-9110 '14.1.2. Byte Ranges':
  7068. // A client can limit the number of bytes requested without knowing the
  7069. // size of the selected representation. If the last-pos value is absent,
  7070. // or if the value is greater than or equal to the current length of the
  7071. // representation data, the byte range is interpreted as the remainder of
  7072. // the representation (i.e., the server replaces the value of last-pos
  7073. // with a value that is one less than the current length of the selected
  7074. // representation).
  7075. // https://www.rfc-editor.org/rfc/rfc9110.html#section-14.1.2-6
  7076. if (last_pos == -1 || last_pos >= content_len) {
  7077. last_pos = content_len - 1;
  7078. }
  7079. // Range must be within content length
  7080. if (!(0 <= first_pos && first_pos <= last_pos &&
  7081. last_pos <= content_len - 1)) {
  7082. return true;
  7083. }
  7084. // Request must not have more than two overlapping ranges
  7085. for (const auto &processed_range : processed_ranges) {
  7086. if (!(last_pos < processed_range.first ||
  7087. first_pos > processed_range.second)) {
  7088. overwrapping_count++;
  7089. if (overwrapping_count > 2) { return true; }
  7090. break; // Only count once per range
  7091. }
  7092. }
  7093. processed_ranges.emplace_back(first_pos, last_pos);
  7094. }
  7095. // After validation, coalesce overlapping ranges as per RFC 9110
  7096. coalesce_ranges(req.ranges, static_cast<size_t>(content_len));
  7097. }
  7098. return false;
  7099. }
  7100. inline std::pair<size_t, size_t>
  7101. get_range_offset_and_length(Range r, size_t content_length) {
  7102. assert(r.first != -1 && r.second != -1);
  7103. assert(0 <= r.first && r.first < static_cast<ssize_t>(content_length));
  7104. assert(r.first <= r.second &&
  7105. r.second < static_cast<ssize_t>(content_length));
  7106. (void)(content_length);
  7107. return std::make_pair(static_cast<size_t>(r.first),
  7108. static_cast<size_t>(r.second - r.first) + 1);
  7109. }
  7110. inline std::string make_content_range_header_field(
  7111. const std::pair<size_t, size_t> &offset_and_length, size_t content_length) {
  7112. auto st = offset_and_length.first;
  7113. auto ed = st + offset_and_length.second - 1;
  7114. std::string field = "bytes ";
  7115. field += std::to_string(st);
  7116. field += '-';
  7117. field += std::to_string(ed);
  7118. field += '/';
  7119. field += std::to_string(content_length);
  7120. return field;
  7121. }
  7122. template <typename SToken, typename CToken, typename Content>
  7123. bool process_multipart_ranges_data(const Request &req,
  7124. const std::string &boundary,
  7125. const std::string &content_type,
  7126. size_t content_length, SToken stoken,
  7127. CToken ctoken, Content content) {
  7128. for (size_t i = 0; i < req.ranges.size(); i++) {
  7129. ctoken("--");
  7130. stoken(boundary);
  7131. ctoken("\r\n");
  7132. if (!content_type.empty()) {
  7133. ctoken("Content-Type: ");
  7134. stoken(content_type);
  7135. ctoken("\r\n");
  7136. }
  7137. auto offset_and_length =
  7138. get_range_offset_and_length(req.ranges[i], content_length);
  7139. ctoken("Content-Range: ");
  7140. stoken(make_content_range_header_field(offset_and_length, content_length));
  7141. ctoken("\r\n");
  7142. ctoken("\r\n");
  7143. if (!content(offset_and_length.first, offset_and_length.second)) {
  7144. return false;
  7145. }
  7146. ctoken("\r\n");
  7147. }
  7148. ctoken("--");
  7149. stoken(boundary);
  7150. ctoken("--");
  7151. return true;
  7152. }
  7153. inline void make_multipart_ranges_data(const Request &req, Response &res,
  7154. const std::string &boundary,
  7155. const std::string &content_type,
  7156. size_t content_length,
  7157. std::string &data) {
  7158. process_multipart_ranges_data(
  7159. req, boundary, content_type, content_length,
  7160. [&](const std::string &token) { data += token; },
  7161. [&](const std::string &token) { data += token; },
  7162. [&](size_t offset, size_t length) {
  7163. assert(offset + length <= content_length);
  7164. data += res.body.substr(offset, length);
  7165. return true;
  7166. });
  7167. }
  7168. inline size_t get_multipart_ranges_data_length(const Request &req,
  7169. const std::string &boundary,
  7170. const std::string &content_type,
  7171. size_t content_length) {
  7172. size_t data_length = 0;
  7173. process_multipart_ranges_data(
  7174. req, boundary, content_type, content_length,
  7175. [&](const std::string &token) { data_length += token.size(); },
  7176. [&](const std::string &token) { data_length += token.size(); },
  7177. [&](size_t /*offset*/, size_t length) {
  7178. data_length += length;
  7179. return true;
  7180. });
  7181. return data_length;
  7182. }
  7183. template <typename T>
  7184. inline bool
  7185. write_multipart_ranges_data(Stream &strm, const Request &req, Response &res,
  7186. const std::string &boundary,
  7187. const std::string &content_type,
  7188. size_t content_length, const T &is_shutting_down) {
  7189. return process_multipart_ranges_data(
  7190. req, boundary, content_type, content_length,
  7191. [&](const std::string &token) { strm.write(token); },
  7192. [&](const std::string &token) { strm.write(token); },
  7193. [&](size_t offset, size_t length) {
  7194. return write_content(strm, res.content_provider_, offset, length,
  7195. is_shutting_down);
  7196. });
  7197. }
  7198. inline bool has_framed_body(const Request &req) {
  7199. return is_chunked_transfer_encoding(req.headers) ||
  7200. req.get_header_value_u64("Content-Length") > 0;
  7201. }
  7202. inline bool is_connection_persistent(const Request &req) {
  7203. auto conn = req.get_header_value("Connection");
  7204. if (conn == "close") { return false; }
  7205. if (req.version == "HTTP/1.0" && conn != "Keep-Alive") { return false; }
  7206. return true;
  7207. }
  7208. inline bool expect_content(const Request &req) {
  7209. if (req.method == "POST" || req.method == "PUT" || req.method == "PATCH" ||
  7210. req.method == "DELETE") {
  7211. return true;
  7212. }
  7213. return has_framed_body(req);
  7214. }
  7215. #ifdef _WIN32
  7216. class WSInit {
  7217. public:
  7218. WSInit() {
  7219. WSADATA wsaData;
  7220. if (WSAStartup(0x0002, &wsaData) == 0) is_valid_ = true;
  7221. }
  7222. ~WSInit() {
  7223. if (is_valid_) WSACleanup();
  7224. }
  7225. bool is_valid_ = false;
  7226. };
  7227. static WSInit wsinit_;
  7228. #endif
  7229. inline bool parse_www_authenticate(const Response &res,
  7230. std::map<std::string, std::string> &auth,
  7231. bool is_proxy) {
  7232. auto auth_key = is_proxy ? "Proxy-Authenticate" : "WWW-Authenticate";
  7233. if (res.has_header(auth_key)) {
  7234. thread_local auto re =
  7235. std::regex(R"~((?:(?:,\s*)?(.+?)=(?:"(.*?)"|([^,]*))))~");
  7236. auto s = res.get_header_value(auth_key);
  7237. auto pos = s.find(' ');
  7238. if (pos != std::string::npos) {
  7239. auto type = s.substr(0, pos);
  7240. if (type == "Basic") {
  7241. return false;
  7242. } else if (type == "Digest") {
  7243. s = s.substr(pos + 1);
  7244. auto beg = std::sregex_iterator(s.begin(), s.end(), re);
  7245. for (auto i = beg; i != std::sregex_iterator(); ++i) {
  7246. const auto &m = *i;
  7247. auto key = s.substr(static_cast<size_t>(m.position(1)),
  7248. static_cast<size_t>(m.length(1)));
  7249. auto val = m.length(2) > 0
  7250. ? s.substr(static_cast<size_t>(m.position(2)),
  7251. static_cast<size_t>(m.length(2)))
  7252. : s.substr(static_cast<size_t>(m.position(3)),
  7253. static_cast<size_t>(m.length(3)));
  7254. auth[std::move(key)] = std::move(val);
  7255. }
  7256. return true;
  7257. }
  7258. }
  7259. }
  7260. return false;
  7261. }
  7262. class ContentProviderAdapter {
  7263. public:
  7264. explicit ContentProviderAdapter(
  7265. ContentProviderWithoutLength &&content_provider)
  7266. : content_provider_(std::move(content_provider)) {}
  7267. bool operator()(size_t offset, size_t, DataSink &sink) {
  7268. return content_provider_(offset, sink);
  7269. }
  7270. private:
  7271. ContentProviderWithoutLength content_provider_;
  7272. };
  7273. // NOTE: https://www.rfc-editor.org/rfc/rfc9110#section-5
  7274. namespace fields {
  7275. inline bool is_token_char(char c) {
  7276. return std::isalnum(static_cast<unsigned char>(c)) || c == '!' || c == '#' ||
  7277. c == '$' || c == '%' || c == '&' || c == '\'' || c == '*' ||
  7278. c == '+' || c == '-' || c == '.' || c == '^' || c == '_' || c == '`' ||
  7279. c == '|' || c == '~';
  7280. }
  7281. inline bool is_token(const std::string &s) {
  7282. if (s.empty()) { return false; }
  7283. for (auto c : s) {
  7284. if (!is_token_char(c)) { return false; }
  7285. }
  7286. return true;
  7287. }
  7288. inline bool is_field_name(const std::string &s) { return is_token(s); }
  7289. inline bool is_vchar(char c) { return c >= 33 && c <= 126; }
  7290. inline bool is_obs_text(char c) { return 128 <= static_cast<unsigned char>(c); }
  7291. inline bool is_field_vchar(char c) { return is_vchar(c) || is_obs_text(c); }
  7292. inline bool is_field_content(const std::string &s) {
  7293. if (s.empty()) { return true; }
  7294. if (s.size() == 1) {
  7295. return is_field_vchar(s[0]);
  7296. } else if (s.size() == 2) {
  7297. return is_field_vchar(s[0]) && is_field_vchar(s[1]);
  7298. } else {
  7299. size_t i = 0;
  7300. if (!is_field_vchar(s[i])) { return false; }
  7301. i++;
  7302. while (i < s.size() - 1) {
  7303. auto c = s[i++];
  7304. if (c == ' ' || c == '\t' || is_field_vchar(c)) {
  7305. } else {
  7306. return false;
  7307. }
  7308. }
  7309. return is_field_vchar(s[i]);
  7310. }
  7311. }
  7312. inline bool is_field_value(const std::string &s) { return is_field_content(s); }
  7313. } // namespace fields
  7314. inline bool perform_websocket_handshake(Stream &strm, const std::string &host,
  7315. int port, const std::string &path,
  7316. const Headers &headers,
  7317. std::string &selected_subprotocol) {
  7318. // Validate path and host
  7319. if (!fields::is_field_value(path) || !fields::is_field_value(host)) {
  7320. return false;
  7321. }
  7322. // Validate user-provided headers
  7323. for (const auto &h : headers) {
  7324. if (!fields::is_field_name(h.first) || !fields::is_field_value(h.second)) {
  7325. return false;
  7326. }
  7327. }
  7328. // Generate random Sec-WebSocket-Key
  7329. thread_local std::mt19937 rng(std::random_device{}());
  7330. std::string key_bytes(16, '\0');
  7331. for (size_t i = 0; i < 16; i += 4) {
  7332. auto r = rng();
  7333. std::memcpy(&key_bytes[i], &r, (std::min)(size_t(4), size_t(16 - i)));
  7334. }
  7335. auto client_key = base64_encode(key_bytes);
  7336. // Build upgrade request
  7337. std::string req_str = "GET " + path + " HTTP/1.1\r\n";
  7338. req_str += "Host: " + host + ":" + std::to_string(port) + "\r\n";
  7339. req_str += "Upgrade: websocket\r\n";
  7340. req_str += "Connection: Upgrade\r\n";
  7341. req_str += "Sec-WebSocket-Key: " + client_key + "\r\n";
  7342. req_str += "Sec-WebSocket-Version: 13\r\n";
  7343. for (const auto &h : headers) {
  7344. req_str += h.first + ": " + h.second + "\r\n";
  7345. }
  7346. req_str += "\r\n";
  7347. if (strm.write(req_str.data(), req_str.size()) < 0) { return false; }
  7348. // Verify 101 response and Sec-WebSocket-Accept header
  7349. auto expected_accept = websocket_accept_key(client_key);
  7350. return read_websocket_upgrade_response(strm, expected_accept,
  7351. selected_subprotocol);
  7352. }
  7353. } // namespace detail
  7354. /*
  7355. * Group 2: detail namespace - SSL common utilities
  7356. */
  7357. #ifdef CPPHTTPLIB_SSL_ENABLED
  7358. namespace detail {
  7359. class SSLSocketStream final : public Stream {
  7360. public:
  7361. SSLSocketStream(
  7362. socket_t sock, tls::session_t session, time_t read_timeout_sec,
  7363. time_t read_timeout_usec, time_t write_timeout_sec,
  7364. time_t write_timeout_usec, time_t max_timeout_msec = 0,
  7365. std::chrono::time_point<std::chrono::steady_clock> start_time =
  7366. (std::chrono::steady_clock::time_point::min)());
  7367. ~SSLSocketStream() override;
  7368. bool is_readable() const override;
  7369. bool wait_readable() const override;
  7370. bool wait_writable() const override;
  7371. bool is_peer_alive() const override;
  7372. ssize_t read(char *ptr, size_t size) override;
  7373. ssize_t write(const char *ptr, size_t size) override;
  7374. void get_remote_ip_and_port(std::string &ip, int &port) const override;
  7375. void get_local_ip_and_port(std::string &ip, int &port) const override;
  7376. socket_t socket() const override;
  7377. time_t duration() const override;
  7378. void set_read_timeout(time_t sec, time_t usec = 0) override;
  7379. private:
  7380. socket_t sock_;
  7381. tls::session_t session_;
  7382. time_t read_timeout_sec_;
  7383. time_t read_timeout_usec_;
  7384. time_t write_timeout_sec_;
  7385. time_t write_timeout_usec_;
  7386. time_t max_timeout_msec_;
  7387. const std::chrono::time_point<std::chrono::steady_clock> start_time_;
  7388. };
  7389. #ifdef CPPHTTPLIB_OPENSSL_SUPPORT
  7390. inline std::string message_digest(const std::string &s, const EVP_MD *algo) {
  7391. auto context = std::unique_ptr<EVP_MD_CTX, decltype(&EVP_MD_CTX_free)>(
  7392. EVP_MD_CTX_new(), EVP_MD_CTX_free);
  7393. unsigned int hash_length = 0;
  7394. unsigned char hash[EVP_MAX_MD_SIZE];
  7395. EVP_DigestInit_ex(context.get(), algo, nullptr);
  7396. EVP_DigestUpdate(context.get(), s.c_str(), s.size());
  7397. EVP_DigestFinal_ex(context.get(), hash, &hash_length);
  7398. std::stringstream ss;
  7399. for (auto i = 0u; i < hash_length; ++i) {
  7400. ss << std::hex << std::setw(2) << std::setfill('0')
  7401. << static_cast<unsigned int>(hash[i]);
  7402. }
  7403. return ss.str();
  7404. }
  7405. inline std::string MD5(const std::string &s) {
  7406. return message_digest(s, EVP_md5());
  7407. }
  7408. inline std::string SHA_256(const std::string &s) {
  7409. return message_digest(s, EVP_sha256());
  7410. }
  7411. inline std::string SHA_512(const std::string &s) {
  7412. return message_digest(s, EVP_sha512());
  7413. }
  7414. #elif defined(CPPHTTPLIB_MBEDTLS_SUPPORT)
  7415. namespace {
  7416. template <size_t N>
  7417. inline std::string hash_to_hex(const unsigned char (&hash)[N]) {
  7418. std::stringstream ss;
  7419. for (size_t i = 0; i < N; ++i) {
  7420. ss << std::hex << std::setw(2) << std::setfill('0')
  7421. << static_cast<unsigned int>(hash[i]);
  7422. }
  7423. return ss.str();
  7424. }
  7425. } // namespace
  7426. inline std::string MD5(const std::string &s) {
  7427. unsigned char hash[16];
  7428. #ifdef CPPHTTPLIB_MBEDTLS_V3
  7429. mbedtls_md5(reinterpret_cast<const unsigned char *>(s.c_str()), s.size(),
  7430. hash);
  7431. #else
  7432. mbedtls_md5_ret(reinterpret_cast<const unsigned char *>(s.c_str()), s.size(),
  7433. hash);
  7434. #endif
  7435. return hash_to_hex(hash);
  7436. }
  7437. inline std::string SHA_256(const std::string &s) {
  7438. unsigned char hash[32];
  7439. #ifdef CPPHTTPLIB_MBEDTLS_V3
  7440. mbedtls_sha256(reinterpret_cast<const unsigned char *>(s.c_str()), s.size(),
  7441. hash, 0);
  7442. #else
  7443. mbedtls_sha256_ret(reinterpret_cast<const unsigned char *>(s.c_str()),
  7444. s.size(), hash, 0);
  7445. #endif
  7446. return hash_to_hex(hash);
  7447. }
  7448. inline std::string SHA_512(const std::string &s) {
  7449. unsigned char hash[64];
  7450. #ifdef CPPHTTPLIB_MBEDTLS_V3
  7451. mbedtls_sha512(reinterpret_cast<const unsigned char *>(s.c_str()), s.size(),
  7452. hash, 0);
  7453. #else
  7454. mbedtls_sha512_ret(reinterpret_cast<const unsigned char *>(s.c_str()),
  7455. s.size(), hash, 0);
  7456. #endif
  7457. return hash_to_hex(hash);
  7458. }
  7459. #elif defined(CPPHTTPLIB_WOLFSSL_SUPPORT)
  7460. namespace {
  7461. template <size_t N>
  7462. inline std::string hash_to_hex(const unsigned char (&hash)[N]) {
  7463. std::stringstream ss;
  7464. for (size_t i = 0; i < N; ++i) {
  7465. ss << std::hex << std::setw(2) << std::setfill('0')
  7466. << static_cast<unsigned int>(hash[i]);
  7467. }
  7468. return ss.str();
  7469. }
  7470. } // namespace
  7471. inline std::string MD5(const std::string &s) {
  7472. unsigned char hash[WC_MD5_DIGEST_SIZE];
  7473. wc_Md5Hash(reinterpret_cast<const unsigned char *>(s.c_str()),
  7474. static_cast<word32>(s.size()), hash);
  7475. return hash_to_hex(hash);
  7476. }
  7477. inline std::string SHA_256(const std::string &s) {
  7478. unsigned char hash[WC_SHA256_DIGEST_SIZE];
  7479. wc_Sha256Hash(reinterpret_cast<const unsigned char *>(s.c_str()),
  7480. static_cast<word32>(s.size()), hash);
  7481. return hash_to_hex(hash);
  7482. }
  7483. inline std::string SHA_512(const std::string &s) {
  7484. unsigned char hash[WC_SHA512_DIGEST_SIZE];
  7485. wc_Sha512Hash(reinterpret_cast<const unsigned char *>(s.c_str()),
  7486. static_cast<word32>(s.size()), hash);
  7487. return hash_to_hex(hash);
  7488. }
  7489. #endif
  7490. inline bool is_ip_address(const std::string &host) {
  7491. struct in_addr addr4;
  7492. struct in6_addr addr6;
  7493. return inet_pton(AF_INET, host.c_str(), &addr4) == 1 ||
  7494. inet_pton(AF_INET6, host.c_str(), &addr6) == 1;
  7495. }
  7496. template <typename T>
  7497. inline bool process_server_socket_ssl(
  7498. const std::atomic<socket_t> &svr_sock, tls::session_t session,
  7499. socket_t sock, size_t keep_alive_max_count, time_t keep_alive_timeout_sec,
  7500. time_t read_timeout_sec, time_t read_timeout_usec, time_t write_timeout_sec,
  7501. time_t write_timeout_usec, T callback) {
  7502. return process_server_socket_core(
  7503. svr_sock, sock, keep_alive_max_count, keep_alive_timeout_sec,
  7504. [&](bool close_connection, bool &connection_closed) {
  7505. SSLSocketStream strm(sock, session, read_timeout_sec, read_timeout_usec,
  7506. write_timeout_sec, write_timeout_usec);
  7507. return callback(strm, close_connection, connection_closed);
  7508. });
  7509. }
  7510. template <typename T>
  7511. inline bool process_client_socket_ssl(
  7512. tls::session_t session, socket_t sock, time_t read_timeout_sec,
  7513. time_t read_timeout_usec, time_t write_timeout_sec,
  7514. time_t write_timeout_usec, time_t max_timeout_msec,
  7515. std::chrono::time_point<std::chrono::steady_clock> start_time, T callback) {
  7516. SSLSocketStream strm(sock, session, read_timeout_sec, read_timeout_usec,
  7517. write_timeout_sec, write_timeout_usec, max_timeout_msec,
  7518. start_time);
  7519. return callback(strm);
  7520. }
  7521. inline std::pair<std::string, std::string> make_digest_authentication_header(
  7522. const Request &req, const std::map<std::string, std::string> &auth,
  7523. size_t cnonce_count, const std::string &cnonce, const std::string &username,
  7524. const std::string &password, bool is_proxy = false) {
  7525. std::string nc;
  7526. {
  7527. std::stringstream ss;
  7528. ss << std::setfill('0') << std::setw(8) << std::hex << cnonce_count;
  7529. nc = ss.str();
  7530. }
  7531. std::string qop;
  7532. if (auth.find("qop") != auth.end()) {
  7533. qop = auth.at("qop");
  7534. if (qop.find("auth-int") != std::string::npos) {
  7535. qop = "auth-int";
  7536. } else if (qop.find("auth") != std::string::npos) {
  7537. qop = "auth";
  7538. } else {
  7539. qop.clear();
  7540. }
  7541. }
  7542. std::string algo = "MD5";
  7543. if (auth.find("algorithm") != auth.end()) { algo = auth.at("algorithm"); }
  7544. std::string response;
  7545. {
  7546. auto H = algo == "SHA-256" ? detail::SHA_256
  7547. : algo == "SHA-512" ? detail::SHA_512
  7548. : detail::MD5;
  7549. auto A1 = username + ":" + auth.at("realm") + ":" + password;
  7550. auto A2 = req.method + ":" + req.path;
  7551. if (qop == "auth-int") { A2 += ":" + H(req.body); }
  7552. if (qop.empty()) {
  7553. response = H(H(A1) + ":" + auth.at("nonce") + ":" + H(A2));
  7554. } else {
  7555. response = H(H(A1) + ":" + auth.at("nonce") + ":" + nc + ":" + cnonce +
  7556. ":" + qop + ":" + H(A2));
  7557. }
  7558. }
  7559. auto opaque = (auth.find("opaque") != auth.end()) ? auth.at("opaque") : "";
  7560. auto field = "Digest username=\"" + username + "\", realm=\"" +
  7561. auth.at("realm") + "\", nonce=\"" + auth.at("nonce") +
  7562. "\", uri=\"" + req.path + "\", algorithm=" + algo +
  7563. (qop.empty() ? ", response=\""
  7564. : ", qop=" + qop + ", nc=" + nc + ", cnonce=\"" +
  7565. cnonce + "\", response=\"") +
  7566. response + "\"" +
  7567. (opaque.empty() ? "" : ", opaque=\"" + opaque + "\"");
  7568. auto key = is_proxy ? "Proxy-Authorization" : "Authorization";
  7569. return std::make_pair(key, field);
  7570. }
  7571. inline bool match_hostname(const std::string &pattern,
  7572. const std::string &hostname) {
  7573. // Exact match (case-insensitive)
  7574. if (detail::case_ignore::equal(hostname, pattern)) { return true; }
  7575. // Split both pattern and hostname into components by '.'
  7576. std::vector<std::string> pattern_components;
  7577. if (!pattern.empty()) {
  7578. split(pattern.data(), pattern.data() + pattern.size(), '.',
  7579. [&](const char *b, const char *e) {
  7580. pattern_components.emplace_back(b, e);
  7581. });
  7582. }
  7583. std::vector<std::string> host_components;
  7584. if (!hostname.empty()) {
  7585. split(hostname.data(), hostname.data() + hostname.size(), '.',
  7586. [&](const char *b, const char *e) {
  7587. host_components.emplace_back(b, e);
  7588. });
  7589. }
  7590. // Component count must match
  7591. if (host_components.size() != pattern_components.size()) { return false; }
  7592. // Compare each component with wildcard support
  7593. // Supports: "*" (full wildcard), "prefix*" (partial wildcard)
  7594. // https://bugs.launchpad.net/ubuntu/+source/firefox-3.0/+bug/376484
  7595. auto itr = pattern_components.begin();
  7596. for (const auto &h : host_components) {
  7597. auto &p = *itr;
  7598. if (!detail::case_ignore::equal(p, h) && p != "*") {
  7599. bool partial_match = false;
  7600. if (!p.empty() && p[p.size() - 1] == '*') {
  7601. const auto prefix_length = p.size() - 1;
  7602. if (prefix_length == 0) {
  7603. partial_match = true;
  7604. } else if (h.size() >= prefix_length) {
  7605. partial_match =
  7606. std::equal(p.begin(),
  7607. p.begin() + static_cast<std::string::difference_type>(
  7608. prefix_length),
  7609. h.begin(), [](const char ca, const char cb) {
  7610. return detail::case_ignore::to_lower(ca) ==
  7611. detail::case_ignore::to_lower(cb);
  7612. });
  7613. }
  7614. }
  7615. if (!partial_match) { return false; }
  7616. }
  7617. ++itr;
  7618. }
  7619. return true;
  7620. }
  7621. #ifdef _WIN32
  7622. // Verify certificate using Windows CertGetCertificateChain API.
  7623. // This provides real-time certificate validation with Windows Update
  7624. // integration, independent of the TLS backend (OpenSSL or MbedTLS).
  7625. inline bool
  7626. verify_cert_with_windows_schannel(const std::vector<unsigned char> &der_cert,
  7627. const std::string &hostname,
  7628. bool verify_hostname, uint64_t &out_error) {
  7629. if (der_cert.empty()) { return false; }
  7630. out_error = 0;
  7631. // Create Windows certificate context from DER data
  7632. auto cert_context = CertCreateCertificateContext(
  7633. X509_ASN_ENCODING | PKCS_7_ASN_ENCODING, der_cert.data(),
  7634. static_cast<DWORD>(der_cert.size()));
  7635. if (!cert_context) {
  7636. out_error = GetLastError();
  7637. return false;
  7638. }
  7639. auto cert_guard =
  7640. scope_exit([&] { CertFreeCertificateContext(cert_context); });
  7641. // Setup chain parameters
  7642. CERT_CHAIN_PARA chain_para = {};
  7643. chain_para.cbSize = sizeof(chain_para);
  7644. // Build certificate chain with revocation checking
  7645. PCCERT_CHAIN_CONTEXT chain_context = nullptr;
  7646. auto chain_result = CertGetCertificateChain(
  7647. nullptr, cert_context, nullptr, cert_context->hCertStore, &chain_para,
  7648. CERT_CHAIN_CACHE_END_CERT | CERT_CHAIN_REVOCATION_CHECK_END_CERT |
  7649. CERT_CHAIN_REVOCATION_ACCUMULATIVE_TIMEOUT,
  7650. nullptr, &chain_context);
  7651. if (!chain_result || !chain_context) {
  7652. out_error = GetLastError();
  7653. return false;
  7654. }
  7655. auto chain_guard =
  7656. scope_exit([&] { CertFreeCertificateChain(chain_context); });
  7657. // Check if chain has errors
  7658. if (chain_context->TrustStatus.dwErrorStatus != CERT_TRUST_NO_ERROR) {
  7659. out_error = chain_context->TrustStatus.dwErrorStatus;
  7660. return false;
  7661. }
  7662. // Verify SSL policy
  7663. SSL_EXTRA_CERT_CHAIN_POLICY_PARA extra_policy_para = {};
  7664. extra_policy_para.cbSize = sizeof(extra_policy_para);
  7665. #ifdef AUTHTYPE_SERVER
  7666. extra_policy_para.dwAuthType = AUTHTYPE_SERVER;
  7667. #endif
  7668. std::wstring whost;
  7669. if (verify_hostname) {
  7670. whost = u8string_to_wstring(hostname.c_str());
  7671. extra_policy_para.pwszServerName = const_cast<wchar_t *>(whost.c_str());
  7672. }
  7673. CERT_CHAIN_POLICY_PARA policy_para = {};
  7674. policy_para.cbSize = sizeof(policy_para);
  7675. #ifdef CERT_CHAIN_POLICY_IGNORE_ALL_REV_UNKNOWN_FLAGS
  7676. policy_para.dwFlags = CERT_CHAIN_POLICY_IGNORE_ALL_REV_UNKNOWN_FLAGS;
  7677. #else
  7678. policy_para.dwFlags = 0;
  7679. #endif
  7680. policy_para.pvExtraPolicyPara = &extra_policy_para;
  7681. CERT_CHAIN_POLICY_STATUS policy_status = {};
  7682. policy_status.cbSize = sizeof(policy_status);
  7683. if (!CertVerifyCertificateChainPolicy(CERT_CHAIN_POLICY_SSL, chain_context,
  7684. &policy_para, &policy_status)) {
  7685. out_error = GetLastError();
  7686. return false;
  7687. }
  7688. if (policy_status.dwError != 0) {
  7689. out_error = policy_status.dwError;
  7690. return false;
  7691. }
  7692. return true;
  7693. }
  7694. #endif // _WIN32
  7695. // Loads CA file/dir configuration and applies the system CA policy to a
  7696. // client TLS context. PEM data and native stores are applied to the context
  7697. // directly at set time; has_custom_store reflects them for the Auto policy
  7698. // decision.
  7699. inline bool load_client_ca_config(tls::ctx_t ctx,
  7700. const std::string &ca_cert_file_path,
  7701. const std::string &ca_cert_dir_path,
  7702. bool has_custom_store, SystemCAMode mode,
  7703. uint64_t &backend_error) {
  7704. auto ret = true;
  7705. if (!ca_cert_file_path.empty()) {
  7706. if (!tls::load_ca_file(ctx, ca_cert_file_path.c_str())) {
  7707. backend_error = tls::get_error();
  7708. ret = false;
  7709. }
  7710. } else if (!ca_cert_dir_path.empty()) {
  7711. if (!tls::load_ca_dir(ctx, ca_cert_dir_path.c_str())) {
  7712. backend_error = tls::get_error();
  7713. ret = false;
  7714. }
  7715. }
  7716. auto has_custom_ca = !ca_cert_file_path.empty() ||
  7717. !ca_cert_dir_path.empty() || has_custom_store;
  7718. if (mode == SystemCAMode::Enabled ||
  7719. (mode == SystemCAMode::Auto && !has_custom_ca)) {
  7720. if (!tls::load_system_certs(ctx)) { backend_error = tls::get_error(); }
  7721. }
  7722. return ret;
  7723. }
  7724. inline bool setup_client_tls_session(const std::string &host, tls::ctx_t ctx,
  7725. tls::session_t &session, socket_t sock,
  7726. bool server_certificate_verification,
  7727. time_t timeout_sec, time_t timeout_usec) {
  7728. using namespace tls;
  7729. if (!ctx) { return false; }
  7730. bool is_ip = is_ip_address(host);
  7731. #if defined(CPPHTTPLIB_MBEDTLS_SUPPORT) || defined(CPPHTTPLIB_WOLFSSL_SUPPORT)
  7732. // Chain verification happens during the handshake even for IP hosts; the
  7733. // certificate identity is verified post-handshake via verify_hostname()
  7734. set_verify_client(ctx, server_certificate_verification);
  7735. #endif
  7736. session = create_session(ctx, sock);
  7737. if (!session) { return false; }
  7738. // RFC 6066: SNI must not be set for IP addresses. On Mbed TLS and wolfSSL
  7739. // set_hostname also sets SNI, so it must be skipped for IP hosts as well;
  7740. // their identity is checked post-handshake below instead.
  7741. if (!is_ip) {
  7742. if (server_certificate_verification) {
  7743. set_hostname(session, host.c_str());
  7744. } else {
  7745. set_sni(session, host.c_str());
  7746. }
  7747. }
  7748. if (!connect_nonblocking(session, sock, timeout_sec, timeout_usec, nullptr)) {
  7749. return false;
  7750. }
  7751. if (server_certificate_verification) {
  7752. if (get_verify_result(session) != 0) { return false; }
  7753. // Identity check against the peer certificate, post-handshake for all
  7754. // backends (same as SSLClient). For IP hosts this is the only identity
  7755. // verification since no hostname is bound during the handshake.
  7756. auto server_cert = get_peer_cert(session);
  7757. if (!server_cert) { return false; }
  7758. auto cert_guard = detail::scope_exit([&] { free_cert(server_cert); });
  7759. if (!verify_hostname(server_cert, host.c_str())) { return false; }
  7760. }
  7761. return true;
  7762. }
  7763. } // namespace detail
  7764. #endif // CPPHTTPLIB_SSL_ENABLED
  7765. /*
  7766. * Group 3: httplib namespace - Non-SSL public API implementations
  7767. */
  7768. inline void default_socket_options(socket_t sock) {
  7769. set_socket_opt(sock, SOL_SOCKET,
  7770. #ifdef SO_REUSEPORT
  7771. SO_REUSEPORT,
  7772. #else
  7773. SO_REUSEADDR,
  7774. #endif
  7775. 1);
  7776. }
  7777. inline bool set_socket_opt(socket_t sock, int level, int optname, int optval) {
  7778. return detail::set_socket_opt_impl(sock, level, optname, &optval,
  7779. sizeof(optval));
  7780. }
  7781. inline std::string get_bearer_token_auth(const Request &req) {
  7782. if (req.has_header("Authorization")) {
  7783. constexpr auto bearer_header_prefix_len = detail::str_len("Bearer ");
  7784. return req.get_header_value("Authorization")
  7785. .substr(bearer_header_prefix_len);
  7786. }
  7787. return "";
  7788. }
  7789. inline const char *status_message(int status) {
  7790. switch (status) {
  7791. case StatusCode::Continue_100: return "Continue";
  7792. case StatusCode::SwitchingProtocol_101: return "Switching Protocol";
  7793. case StatusCode::Processing_102: return "Processing";
  7794. case StatusCode::EarlyHints_103: return "Early Hints";
  7795. case StatusCode::OK_200: return "OK";
  7796. case StatusCode::Created_201: return "Created";
  7797. case StatusCode::Accepted_202: return "Accepted";
  7798. case StatusCode::NonAuthoritativeInformation_203:
  7799. return "Non-Authoritative Information";
  7800. case StatusCode::NoContent_204: return "No Content";
  7801. case StatusCode::ResetContent_205: return "Reset Content";
  7802. case StatusCode::PartialContent_206: return "Partial Content";
  7803. case StatusCode::MultiStatus_207: return "Multi-Status";
  7804. case StatusCode::AlreadyReported_208: return "Already Reported";
  7805. case StatusCode::IMUsed_226: return "IM Used";
  7806. case StatusCode::MultipleChoices_300: return "Multiple Choices";
  7807. case StatusCode::MovedPermanently_301: return "Moved Permanently";
  7808. case StatusCode::Found_302: return "Found";
  7809. case StatusCode::SeeOther_303: return "See Other";
  7810. case StatusCode::NotModified_304: return "Not Modified";
  7811. case StatusCode::UseProxy_305: return "Use Proxy";
  7812. case StatusCode::unused_306: return "unused";
  7813. case StatusCode::TemporaryRedirect_307: return "Temporary Redirect";
  7814. case StatusCode::PermanentRedirect_308: return "Permanent Redirect";
  7815. case StatusCode::BadRequest_400: return "Bad Request";
  7816. case StatusCode::Unauthorized_401: return "Unauthorized";
  7817. case StatusCode::PaymentRequired_402: return "Payment Required";
  7818. case StatusCode::Forbidden_403: return "Forbidden";
  7819. case StatusCode::NotFound_404: return "Not Found";
  7820. case StatusCode::MethodNotAllowed_405: return "Method Not Allowed";
  7821. case StatusCode::NotAcceptable_406: return "Not Acceptable";
  7822. case StatusCode::ProxyAuthenticationRequired_407:
  7823. return "Proxy Authentication Required";
  7824. case StatusCode::RequestTimeout_408: return "Request Timeout";
  7825. case StatusCode::Conflict_409: return "Conflict";
  7826. case StatusCode::Gone_410: return "Gone";
  7827. case StatusCode::LengthRequired_411: return "Length Required";
  7828. case StatusCode::PreconditionFailed_412: return "Precondition Failed";
  7829. case StatusCode::PayloadTooLarge_413: return "Payload Too Large";
  7830. case StatusCode::UriTooLong_414: return "URI Too Long";
  7831. case StatusCode::UnsupportedMediaType_415: return "Unsupported Media Type";
  7832. case StatusCode::RangeNotSatisfiable_416: return "Range Not Satisfiable";
  7833. case StatusCode::ExpectationFailed_417: return "Expectation Failed";
  7834. case StatusCode::ImATeapot_418: return "I'm a teapot";
  7835. case StatusCode::MisdirectedRequest_421: return "Misdirected Request";
  7836. case StatusCode::UnprocessableContent_422: return "Unprocessable Content";
  7837. case StatusCode::Locked_423: return "Locked";
  7838. case StatusCode::FailedDependency_424: return "Failed Dependency";
  7839. case StatusCode::TooEarly_425: return "Too Early";
  7840. case StatusCode::UpgradeRequired_426: return "Upgrade Required";
  7841. case StatusCode::PreconditionRequired_428: return "Precondition Required";
  7842. case StatusCode::TooManyRequests_429: return "Too Many Requests";
  7843. case StatusCode::RequestHeaderFieldsTooLarge_431:
  7844. return "Request Header Fields Too Large";
  7845. case StatusCode::UnavailableForLegalReasons_451:
  7846. return "Unavailable For Legal Reasons";
  7847. case StatusCode::NotImplemented_501: return "Not Implemented";
  7848. case StatusCode::BadGateway_502: return "Bad Gateway";
  7849. case StatusCode::ServiceUnavailable_503: return "Service Unavailable";
  7850. case StatusCode::GatewayTimeout_504: return "Gateway Timeout";
  7851. case StatusCode::HttpVersionNotSupported_505:
  7852. return "HTTP Version Not Supported";
  7853. case StatusCode::VariantAlsoNegotiates_506: return "Variant Also Negotiates";
  7854. case StatusCode::InsufficientStorage_507: return "Insufficient Storage";
  7855. case StatusCode::LoopDetected_508: return "Loop Detected";
  7856. case StatusCode::NotExtended_510: return "Not Extended";
  7857. case StatusCode::NetworkAuthenticationRequired_511:
  7858. return "Network Authentication Required";
  7859. default:
  7860. case StatusCode::InternalServerError_500: return "Internal Server Error";
  7861. }
  7862. }
  7863. inline std::string to_string(const Error error) {
  7864. switch (error) {
  7865. case Error::Success: return "Success (no error)";
  7866. case Error::Unknown: return "Unknown";
  7867. case Error::Connection: return "Could not establish connection";
  7868. case Error::BindIPAddress: return "Failed to bind IP address";
  7869. case Error::Read: return "Failed to read connection";
  7870. case Error::Write: return "Failed to write connection";
  7871. case Error::ExceedRedirectCount: return "Maximum redirect count exceeded";
  7872. case Error::Canceled: return "Connection handling canceled";
  7873. case Error::SSLConnection: return "SSL connection failed";
  7874. case Error::SSLLoadingCerts: return "SSL certificate loading failed";
  7875. case Error::SSLServerVerification: return "SSL server verification failed";
  7876. case Error::SSLServerHostnameVerification:
  7877. return "SSL server hostname verification failed";
  7878. case Error::UnsupportedMultipartBoundaryChars:
  7879. return "Unsupported HTTP multipart boundary characters";
  7880. case Error::Compression: return "Compression failed";
  7881. case Error::ConnectionTimeout: return "Connection timed out";
  7882. case Error::ProxyConnection: return "Proxy connection failed";
  7883. case Error::ConnectionClosed: return "Connection closed by server";
  7884. case Error::Timeout: return "Read timeout";
  7885. case Error::ResourceExhaustion: return "Resource exhaustion";
  7886. case Error::TooManyFormDataFiles: return "Too many form data files";
  7887. case Error::ExceedMaxPayloadSize: return "Exceeded maximum payload size";
  7888. case Error::ExceedUriMaxLength: return "Exceeded maximum URI length";
  7889. case Error::ExceedMaxSocketDescriptorCount:
  7890. return "Exceeded maximum socket descriptor count";
  7891. case Error::InvalidRequestLine: return "Invalid request line";
  7892. case Error::InvalidHTTPMethod: return "Invalid HTTP method";
  7893. case Error::InvalidHTTPVersion: return "Invalid HTTP version";
  7894. case Error::InvalidHeaders: return "Invalid headers";
  7895. case Error::MultipartParsing: return "Multipart parsing failed";
  7896. case Error::OpenFile: return "Failed to open file";
  7897. case Error::Listen: return "Failed to listen on socket";
  7898. case Error::GetSockName: return "Failed to get socket name";
  7899. case Error::UnsupportedAddressFamily: return "Unsupported address family";
  7900. case Error::HTTPParsing: return "HTTP parsing failed";
  7901. case Error::InvalidRangeHeader: return "Invalid Range header";
  7902. default: break;
  7903. }
  7904. return "Invalid";
  7905. }
  7906. inline std::ostream &operator<<(std::ostream &os, const Error &obj) {
  7907. os << to_string(obj);
  7908. os << " (" << static_cast<std::underlying_type<Error>::type>(obj) << ')';
  7909. return os;
  7910. }
  7911. inline std::string hosted_at(const std::string &hostname) {
  7912. std::vector<std::string> addrs;
  7913. hosted_at(hostname, addrs);
  7914. if (addrs.empty()) { return std::string(); }
  7915. return addrs[0];
  7916. }
  7917. inline void hosted_at(const std::string &hostname,
  7918. std::vector<std::string> &addrs) {
  7919. struct addrinfo hints;
  7920. struct addrinfo *result;
  7921. memset(&hints, 0, sizeof(struct addrinfo));
  7922. hints.ai_family = AF_UNSPEC;
  7923. hints.ai_socktype = SOCK_STREAM;
  7924. hints.ai_protocol = 0;
  7925. if (detail::getaddrinfo_with_timeout(hostname.c_str(), nullptr, &hints,
  7926. &result, 0)) {
  7927. #if defined __linux__ && !defined __ANDROID__
  7928. res_init();
  7929. #endif
  7930. return;
  7931. }
  7932. auto se = detail::scope_exit([&] { freeaddrinfo(result); });
  7933. for (auto rp = result; rp; rp = rp->ai_next) {
  7934. const auto &addr =
  7935. *reinterpret_cast<struct sockaddr_storage *>(rp->ai_addr);
  7936. std::string ip;
  7937. auto dummy = -1;
  7938. if (detail::get_ip_and_port(addr, sizeof(struct sockaddr_storage), ip,
  7939. dummy)) {
  7940. addrs.emplace_back(std::move(ip));
  7941. }
  7942. }
  7943. }
  7944. inline std::string encode_uri_component(const std::string &value) {
  7945. std::ostringstream escaped;
  7946. escaped.fill('0');
  7947. escaped << std::hex;
  7948. for (auto c : value) {
  7949. if (std::isalnum(static_cast<uint8_t>(c)) || c == '-' || c == '_' ||
  7950. c == '.' || c == '!' || c == '~' || c == '*' || c == '\'' || c == '(' ||
  7951. c == ')') {
  7952. escaped << c;
  7953. } else {
  7954. escaped << std::uppercase;
  7955. escaped << '%' << std::setw(2)
  7956. << static_cast<int>(static_cast<unsigned char>(c));
  7957. escaped << std::nouppercase;
  7958. }
  7959. }
  7960. return escaped.str();
  7961. }
  7962. inline std::string encode_uri(const std::string &value) {
  7963. std::ostringstream escaped;
  7964. escaped.fill('0');
  7965. escaped << std::hex;
  7966. for (auto c : value) {
  7967. if (std::isalnum(static_cast<uint8_t>(c)) || c == '-' || c == '_' ||
  7968. c == '.' || c == '!' || c == '~' || c == '*' || c == '\'' || c == '(' ||
  7969. c == ')' || c == ';' || c == '/' || c == '?' || c == ':' || c == '@' ||
  7970. c == '&' || c == '=' || c == '+' || c == '$' || c == ',' || c == '#') {
  7971. escaped << c;
  7972. } else {
  7973. escaped << std::uppercase;
  7974. escaped << '%' << std::setw(2)
  7975. << static_cast<int>(static_cast<unsigned char>(c));
  7976. escaped << std::nouppercase;
  7977. }
  7978. }
  7979. return escaped.str();
  7980. }
  7981. inline std::string decode_uri_component(const std::string &value) {
  7982. std::string result;
  7983. for (size_t i = 0; i < value.size(); i++) {
  7984. if (value[i] == '%' && i + 2 < value.size()) {
  7985. auto val = 0;
  7986. if (detail::from_hex_to_i(value, i + 1, 2, val)) {
  7987. result += static_cast<char>(val);
  7988. i += 2;
  7989. } else {
  7990. result += value[i];
  7991. }
  7992. } else {
  7993. result += value[i];
  7994. }
  7995. }
  7996. return result;
  7997. }
  7998. inline std::string decode_uri(const std::string &value) {
  7999. std::string result;
  8000. for (size_t i = 0; i < value.size(); i++) {
  8001. if (value[i] == '%' && i + 2 < value.size()) {
  8002. auto val = 0;
  8003. if (detail::from_hex_to_i(value, i + 1, 2, val)) {
  8004. result += static_cast<char>(val);
  8005. i += 2;
  8006. } else {
  8007. result += value[i];
  8008. }
  8009. } else {
  8010. result += value[i];
  8011. }
  8012. }
  8013. return result;
  8014. }
  8015. inline std::string encode_path_component(const std::string &component) {
  8016. std::string result;
  8017. result.reserve(component.size() * 3);
  8018. for (size_t i = 0; i < component.size(); i++) {
  8019. auto c = static_cast<unsigned char>(component[i]);
  8020. // Unreserved characters per RFC 3986: ALPHA / DIGIT / "-" / "." / "_" / "~"
  8021. if (std::isalnum(c) || c == '-' || c == '.' || c == '_' || c == '~') {
  8022. result += static_cast<char>(c);
  8023. }
  8024. // Path-safe sub-delimiters: "!" / "$" / "&" / "'" / "(" / ")" / "*" / "+" /
  8025. // "," / ";" / "="
  8026. else if (c == '!' || c == '$' || c == '&' || c == '\'' || c == '(' ||
  8027. c == ')' || c == '*' || c == '+' || c == ',' || c == ';' ||
  8028. c == '=') {
  8029. result += static_cast<char>(c);
  8030. }
  8031. // Colon is allowed in path segments except first segment
  8032. else if (c == ':') {
  8033. result += static_cast<char>(c);
  8034. }
  8035. // @ is allowed in path
  8036. else if (c == '@') {
  8037. result += static_cast<char>(c);
  8038. } else {
  8039. result += '%';
  8040. char hex[3];
  8041. snprintf(hex, sizeof(hex), "%02X", c);
  8042. result.append(hex, 2);
  8043. }
  8044. }
  8045. return result;
  8046. }
  8047. inline std::string decode_path_component(const std::string &component) {
  8048. std::string result;
  8049. result.reserve(component.size());
  8050. for (size_t i = 0; i < component.size(); i++) {
  8051. if (component[i] == '%' && i + 1 < component.size()) {
  8052. if (component[i + 1] == 'u') {
  8053. // Unicode %uXXXX encoding
  8054. auto val = 0;
  8055. if (detail::from_hex_to_i(component, i + 2, 4, val)) {
  8056. // 4 digits Unicode codes: val is 0x0000-0xFFFF (from 4 hex digits),
  8057. // so to_utf8 writes at most 3 bytes. buff[4] is safe.
  8058. char buff[4];
  8059. size_t len = detail::to_utf8(val, buff);
  8060. if (len > 0) { result.append(buff, len); }
  8061. i += 5; // 'u0000'
  8062. } else {
  8063. result += component[i];
  8064. }
  8065. } else {
  8066. // Standard %XX encoding
  8067. auto val = 0;
  8068. if (detail::from_hex_to_i(component, i + 1, 2, val)) {
  8069. // 2 digits hex codes
  8070. result += static_cast<char>(val);
  8071. i += 2; // 'XX'
  8072. } else {
  8073. result += component[i];
  8074. }
  8075. }
  8076. } else {
  8077. result += component[i];
  8078. }
  8079. }
  8080. return result;
  8081. }
  8082. inline std::string encode_query_component(const std::string &component,
  8083. bool space_as_plus) {
  8084. std::string result;
  8085. result.reserve(component.size() * 3);
  8086. for (size_t i = 0; i < component.size(); i++) {
  8087. auto c = static_cast<unsigned char>(component[i]);
  8088. // Unreserved characters per RFC 3986
  8089. if (std::isalnum(c) || c == '-' || c == '.' || c == '_' || c == '~') {
  8090. result += static_cast<char>(c);
  8091. }
  8092. // Space handling
  8093. else if (c == ' ') {
  8094. if (space_as_plus) {
  8095. result += '+';
  8096. } else {
  8097. result += "%20";
  8098. }
  8099. }
  8100. // Plus sign handling
  8101. else if (c == '+') {
  8102. if (space_as_plus) {
  8103. result += "%2B";
  8104. } else {
  8105. result += static_cast<char>(c);
  8106. }
  8107. }
  8108. // Query-safe sub-delimiters (excluding & and = which are query delimiters)
  8109. else if (c == '!' || c == '$' || c == '\'' || c == '(' || c == ')' ||
  8110. c == '*' || c == ',' || c == ';') {
  8111. result += static_cast<char>(c);
  8112. }
  8113. // Colon and @ are allowed in query
  8114. else if (c == ':' || c == '@') {
  8115. result += static_cast<char>(c);
  8116. }
  8117. // Forward slash is allowed in query values
  8118. else if (c == '/') {
  8119. result += static_cast<char>(c);
  8120. }
  8121. // Question mark is allowed in query values (after first ?)
  8122. else if (c == '?') {
  8123. result += static_cast<char>(c);
  8124. } else {
  8125. result += '%';
  8126. char hex[3];
  8127. snprintf(hex, sizeof(hex), "%02X", c);
  8128. result.append(hex, 2);
  8129. }
  8130. }
  8131. return result;
  8132. }
  8133. inline std::string decode_query_component(const std::string &component,
  8134. bool plus_as_space) {
  8135. std::string result;
  8136. result.reserve(component.size());
  8137. for (size_t i = 0; i < component.size(); i++) {
  8138. if (component[i] == '%' && i + 2 < component.size()) {
  8139. std::string hex = component.substr(i + 1, 2);
  8140. char *end;
  8141. unsigned long value = std::strtoul(hex.c_str(), &end, 16);
  8142. if (end == hex.c_str() + 2) {
  8143. result += static_cast<char>(value);
  8144. i += 2;
  8145. } else {
  8146. result += component[i];
  8147. }
  8148. } else if (component[i] == '+' && plus_as_space) {
  8149. result += ' '; // + becomes space in form-urlencoded
  8150. } else {
  8151. result += component[i];
  8152. }
  8153. }
  8154. return result;
  8155. }
  8156. inline std::string sanitize_filename(const std::string &filename) {
  8157. // Extract basename: find the last path separator (/ or \)
  8158. auto pos = filename.find_last_of("/\\");
  8159. auto result =
  8160. (pos != std::string::npos) ? filename.substr(pos + 1) : filename;
  8161. // Strip null bytes
  8162. result.erase(std::remove(result.begin(), result.end(), '\0'), result.end());
  8163. // Trim whitespace
  8164. {
  8165. auto start = result.find_first_not_of(" \t");
  8166. auto end = result.find_last_not_of(" \t");
  8167. result = (start == std::string::npos)
  8168. ? ""
  8169. : result.substr(start, end - start + 1);
  8170. }
  8171. // Reject . and ..
  8172. if (result == "." || result == "..") { return ""; }
  8173. return result;
  8174. }
  8175. inline std::string append_query_params(const std::string &path,
  8176. const Params &params) {
  8177. std::string path_with_query = path;
  8178. thread_local const std::regex re("[^?]+\\?.*");
  8179. auto delm = std::regex_match(path, re) ? '&' : '?';
  8180. path_with_query += delm + detail::params_to_query_str(params);
  8181. return path_with_query;
  8182. }
  8183. // Header utilities
  8184. inline std::pair<std::string, std::string>
  8185. make_range_header(const Ranges &ranges) {
  8186. std::string field = "bytes=";
  8187. auto i = 0;
  8188. for (const auto &r : ranges) {
  8189. if (i != 0) { field += ", "; }
  8190. if (r.first != -1) { field += std::to_string(r.first); }
  8191. field += '-';
  8192. if (r.second != -1) { field += std::to_string(r.second); }
  8193. i++;
  8194. }
  8195. return std::make_pair("Range", std::move(field));
  8196. }
  8197. inline std::pair<std::string, std::string>
  8198. make_basic_authentication_header(const std::string &username,
  8199. const std::string &password, bool is_proxy) {
  8200. auto field = "Basic " + detail::base64_encode(username + ":" + password);
  8201. auto key = is_proxy ? "Proxy-Authorization" : "Authorization";
  8202. return std::make_pair(key, std::move(field));
  8203. }
  8204. inline std::pair<std::string, std::string>
  8205. make_bearer_token_authentication_header(const std::string &token,
  8206. bool is_proxy = false) {
  8207. auto field = "Bearer " + token;
  8208. auto key = is_proxy ? "Proxy-Authorization" : "Authorization";
  8209. return std::make_pair(key, std::move(field));
  8210. }
  8211. // Request implementation
  8212. inline size_t Request::get_header_value_u64(const std::string &key, size_t def,
  8213. size_t id) const {
  8214. return detail::get_header_value_u64(headers, key, def, id);
  8215. }
  8216. inline bool Request::has_header(const std::string &key) const {
  8217. return detail::has_header(headers, key);
  8218. }
  8219. inline std::string Request::get_header_value(const std::string &key,
  8220. const char *def, size_t id) const {
  8221. return detail::get_header_value(headers, key, def, id);
  8222. }
  8223. inline size_t Request::get_header_value_count(const std::string &key) const {
  8224. return detail::get_header_value_count(headers, key);
  8225. }
  8226. inline void Request::set_header(const std::string &key,
  8227. const std::string &val) {
  8228. detail::set_header(headers, key, val);
  8229. }
  8230. inline bool Request::has_trailer(const std::string &key) const {
  8231. return trailers.find(key) != trailers.end();
  8232. }
  8233. inline std::string Request::get_trailer_value(const std::string &key,
  8234. size_t id) const {
  8235. return detail::get_multimap_value(trailers, key, id);
  8236. }
  8237. inline size_t Request::get_trailer_value_count(const std::string &key) const {
  8238. auto r = trailers.equal_range(key);
  8239. return static_cast<size_t>(std::distance(r.first, r.second));
  8240. }
  8241. inline bool Request::has_param(const std::string &key) const {
  8242. return params.find(key) != params.end();
  8243. }
  8244. inline std::string Request::get_param_value(const std::string &key,
  8245. size_t id) const {
  8246. return detail::get_multimap_value(params, key, id);
  8247. }
  8248. inline std::vector<std::string>
  8249. Request::get_param_values(const std::string &key) const {
  8250. auto rng = params.equal_range(key);
  8251. std::vector<std::string> values;
  8252. values.reserve(static_cast<size_t>(std::distance(rng.first, rng.second)));
  8253. for (auto it = rng.first; it != rng.second; ++it) {
  8254. values.push_back(it->second);
  8255. }
  8256. return values;
  8257. }
  8258. inline size_t Request::get_param_value_count(const std::string &key) const {
  8259. auto r = params.equal_range(key);
  8260. return static_cast<size_t>(std::distance(r.first, r.second));
  8261. }
  8262. inline bool Request::is_multipart_form_data() const {
  8263. const auto &content_type = get_header_value("Content-Type");
  8264. return detail::extract_media_type(content_type) == "multipart/form-data";
  8265. }
  8266. // Multipart FormData implementation
  8267. inline std::string MultipartFormData::get_field(const std::string &key,
  8268. size_t id) const {
  8269. auto rng = fields.equal_range(key);
  8270. auto it = rng.first;
  8271. std::advance(it, static_cast<ssize_t>(id));
  8272. if (it != rng.second) { return it->second.content; }
  8273. return std::string();
  8274. }
  8275. inline std::vector<std::string>
  8276. MultipartFormData::get_fields(const std::string &key) const {
  8277. std::vector<std::string> values;
  8278. auto rng = fields.equal_range(key);
  8279. for (auto it = rng.first; it != rng.second; it++) {
  8280. values.push_back(it->second.content);
  8281. }
  8282. return values;
  8283. }
  8284. inline bool MultipartFormData::has_field(const std::string &key) const {
  8285. return fields.find(key) != fields.end();
  8286. }
  8287. inline size_t MultipartFormData::get_field_count(const std::string &key) const {
  8288. auto r = fields.equal_range(key);
  8289. return static_cast<size_t>(std::distance(r.first, r.second));
  8290. }
  8291. inline FormData MultipartFormData::get_file(const std::string &key,
  8292. size_t id) const {
  8293. return detail::get_multimap_value(files, key, id);
  8294. }
  8295. inline std::vector<FormData>
  8296. MultipartFormData::get_files(const std::string &key) const {
  8297. std::vector<FormData> values;
  8298. auto rng = files.equal_range(key);
  8299. for (auto it = rng.first; it != rng.second; it++) {
  8300. values.push_back(it->second);
  8301. }
  8302. return values;
  8303. }
  8304. inline bool MultipartFormData::has_file(const std::string &key) const {
  8305. return files.find(key) != files.end();
  8306. }
  8307. inline size_t MultipartFormData::get_file_count(const std::string &key) const {
  8308. auto r = files.equal_range(key);
  8309. return static_cast<size_t>(std::distance(r.first, r.second));
  8310. }
  8311. // Response implementation
  8312. inline size_t Response::get_header_value_u64(const std::string &key, size_t def,
  8313. size_t id) const {
  8314. return detail::get_header_value_u64(headers, key, def, id);
  8315. }
  8316. inline bool Response::has_header(const std::string &key) const {
  8317. return headers.find(key) != headers.end();
  8318. }
  8319. inline std::string Response::get_header_value(const std::string &key,
  8320. const char *def,
  8321. size_t id) const {
  8322. return detail::get_header_value(headers, key, def, id);
  8323. }
  8324. inline size_t Response::get_header_value_count(const std::string &key) const {
  8325. return detail::get_header_value_count(headers, key);
  8326. }
  8327. inline void Response::set_header(const std::string &key,
  8328. const std::string &val) {
  8329. detail::set_header(headers, key, val);
  8330. }
  8331. inline bool Response::has_trailer(const std::string &key) const {
  8332. return trailers.find(key) != trailers.end();
  8333. }
  8334. inline std::string Response::get_trailer_value(const std::string &key,
  8335. size_t id) const {
  8336. return detail::get_multimap_value(trailers, key, id);
  8337. }
  8338. inline size_t Response::get_trailer_value_count(const std::string &key) const {
  8339. auto r = trailers.equal_range(key);
  8340. return static_cast<size_t>(std::distance(r.first, r.second));
  8341. }
  8342. inline void Response::set_redirect(const std::string &url, int stat) {
  8343. if (detail::fields::is_field_value(url)) {
  8344. set_header("Location", url);
  8345. if (300 <= stat && stat < 400) {
  8346. this->status = stat;
  8347. } else {
  8348. this->status = StatusCode::Found_302;
  8349. }
  8350. }
  8351. }
  8352. inline void Response::set_content(const char *s, size_t n,
  8353. const std::string &content_type) {
  8354. body.assign(s, n);
  8355. auto rng = headers.equal_range("Content-Type");
  8356. headers.erase(rng.first, rng.second);
  8357. set_header("Content-Type", content_type);
  8358. }
  8359. inline void Response::set_content(const std::string &s,
  8360. const std::string &content_type) {
  8361. set_content(s.data(), s.size(), content_type);
  8362. }
  8363. inline void Response::set_content(std::string &&s,
  8364. const std::string &content_type) {
  8365. body = std::move(s);
  8366. auto rng = headers.equal_range("Content-Type");
  8367. headers.erase(rng.first, rng.second);
  8368. set_header("Content-Type", content_type);
  8369. }
  8370. inline void Response::set_content_provider(
  8371. size_t in_length, const std::string &content_type, ContentProvider provider,
  8372. ContentProviderResourceReleaser resource_releaser) {
  8373. set_header("Content-Type", content_type);
  8374. content_length_ = in_length;
  8375. if (in_length > 0) { content_provider_ = std::move(provider); }
  8376. content_provider_resource_releaser_ = std::move(resource_releaser);
  8377. is_chunked_content_provider_ = false;
  8378. }
  8379. inline void Response::set_content_provider(
  8380. const std::string &content_type, ContentProviderWithoutLength provider,
  8381. ContentProviderResourceReleaser resource_releaser) {
  8382. set_header("Content-Type", content_type);
  8383. content_length_ = 0;
  8384. content_provider_ = detail::ContentProviderAdapter(std::move(provider));
  8385. content_provider_resource_releaser_ = std::move(resource_releaser);
  8386. is_chunked_content_provider_ = false;
  8387. }
  8388. inline void Response::set_chunked_content_provider(
  8389. const std::string &content_type, ContentProviderWithoutLength provider,
  8390. ContentProviderResourceReleaser resource_releaser) {
  8391. set_header("Content-Type", content_type);
  8392. content_length_ = 0;
  8393. content_provider_ = detail::ContentProviderAdapter(std::move(provider));
  8394. content_provider_resource_releaser_ = std::move(resource_releaser);
  8395. is_chunked_content_provider_ = true;
  8396. }
  8397. inline void Response::set_file_content(const std::string &path,
  8398. const std::string &content_type) {
  8399. file_content_path_ = path;
  8400. file_content_content_type_ = content_type;
  8401. }
  8402. inline void Response::set_file_content(const std::string &path) {
  8403. file_content_path_ = path;
  8404. }
  8405. // Result implementation
  8406. inline size_t Result::get_request_header_value_u64(const std::string &key,
  8407. size_t def,
  8408. size_t id) const {
  8409. return detail::get_header_value_u64(request_headers_, key, def, id);
  8410. }
  8411. inline bool Result::has_request_header(const std::string &key) const {
  8412. return request_headers_.find(key) != request_headers_.end();
  8413. }
  8414. inline std::string Result::get_request_header_value(const std::string &key,
  8415. const char *def,
  8416. size_t id) const {
  8417. return detail::get_header_value(request_headers_, key, def, id);
  8418. }
  8419. inline size_t
  8420. Result::get_request_header_value_count(const std::string &key) const {
  8421. auto r = request_headers_.equal_range(key);
  8422. return static_cast<size_t>(std::distance(r.first, r.second));
  8423. }
  8424. // Stream implementation
  8425. inline ssize_t Stream::write(const char *ptr) {
  8426. return write(ptr, strlen(ptr));
  8427. }
  8428. inline ssize_t Stream::write(const std::string &s) {
  8429. return write(s.data(), s.size());
  8430. }
  8431. // BodyReader implementation
  8432. inline ssize_t detail::BodyReader::read(char *buf, size_t len) {
  8433. if (!stream) {
  8434. last_error = Error::Connection;
  8435. return -1;
  8436. }
  8437. if (eof) { return 0; }
  8438. if (!chunked) {
  8439. // Content-Length based reading
  8440. if (has_content_length && bytes_read >= content_length) {
  8441. eof = true;
  8442. return 0;
  8443. }
  8444. auto to_read = len;
  8445. if (has_content_length) {
  8446. auto remaining = content_length - bytes_read;
  8447. to_read = (std::min)(len, remaining);
  8448. }
  8449. auto n = stream->read(buf, to_read);
  8450. if (n < 0) {
  8451. last_error = stream->get_error();
  8452. if (last_error == Error::Success) { last_error = Error::Read; }
  8453. eof = true;
  8454. return n;
  8455. }
  8456. if (n == 0) {
  8457. // Unexpected EOF before content_length
  8458. last_error = stream->get_error();
  8459. if (last_error == Error::Success) { last_error = Error::Read; }
  8460. eof = true;
  8461. return 0;
  8462. }
  8463. bytes_read += static_cast<size_t>(n);
  8464. if (has_content_length && bytes_read >= content_length) { eof = true; }
  8465. if (payload_max_length > 0 && bytes_read > payload_max_length) {
  8466. last_error = Error::ExceedMaxPayloadSize;
  8467. eof = true;
  8468. return -1;
  8469. }
  8470. return n;
  8471. }
  8472. // Chunked transfer encoding: delegate to shared decoder instance.
  8473. if (!chunked_decoder) { chunked_decoder.reset(new ChunkedDecoder(*stream)); }
  8474. size_t chunk_offset = 0;
  8475. size_t chunk_total = 0;
  8476. auto n = chunked_decoder->read_payload(buf, len, chunk_offset, chunk_total);
  8477. if (n < 0) {
  8478. last_error = stream->get_error();
  8479. if (last_error == Error::Success) { last_error = Error::Read; }
  8480. eof = true;
  8481. return n;
  8482. }
  8483. if (n == 0) {
  8484. // Final chunk observed. Leave trailer parsing to the caller (StreamHandle).
  8485. eof = true;
  8486. return 0;
  8487. }
  8488. bytes_read += static_cast<size_t>(n);
  8489. if (payload_max_length > 0 && bytes_read > payload_max_length) {
  8490. last_error = Error::ExceedMaxPayloadSize;
  8491. eof = true;
  8492. return -1;
  8493. }
  8494. return n;
  8495. }
  8496. // ThreadPool implementation
  8497. inline ThreadPool::ThreadPool(size_t n, size_t max_n, size_t mqr)
  8498. : base_thread_count_(n), max_queued_requests_(mqr), idle_thread_count_(0),
  8499. shutdown_(false) {
  8500. #ifndef CPPHTTPLIB_NO_EXCEPTIONS
  8501. if (max_n != 0 && max_n < n) {
  8502. std::string msg = "max_threads must be >= base_threads";
  8503. throw std::invalid_argument(msg);
  8504. }
  8505. #endif
  8506. max_thread_count_ = max_n == 0 ? n : max_n;
  8507. threads_.reserve(base_thread_count_);
  8508. #ifndef CPPHTTPLIB_NO_EXCEPTIONS
  8509. try {
  8510. #endif
  8511. for (size_t i = 0; i < base_thread_count_; i++) {
  8512. threads_.emplace_back(std::thread([this]() { worker(false); }));
  8513. }
  8514. #ifndef CPPHTTPLIB_NO_EXCEPTIONS
  8515. } catch (...) {
  8516. // If thread creation fails partway (e.g., pthread_create returns EAGAIN),
  8517. // signal the workers we already spawned to exit and join them so the
  8518. // vector destructor does not see joinable threads (which would call
  8519. // std::terminate). Then rethrow so the caller learns of the failure.
  8520. {
  8521. std::unique_lock<std::mutex> lock(mutex_);
  8522. shutdown_ = true;
  8523. }
  8524. cond_.notify_all();
  8525. for (auto &t : threads_) {
  8526. if (t.joinable()) { t.join(); }
  8527. }
  8528. throw;
  8529. }
  8530. #endif
  8531. }
  8532. inline bool ThreadPool::enqueue(std::function<void()> fn) {
  8533. {
  8534. std::unique_lock<std::mutex> lock(mutex_);
  8535. if (shutdown_) { return false; }
  8536. if (max_queued_requests_ > 0 && jobs_.size() >= max_queued_requests_) {
  8537. return false;
  8538. }
  8539. jobs_.push_back(std::move(fn));
  8540. // Spawn a dynamic thread if no idle threads and under max
  8541. if (idle_thread_count_ == 0 &&
  8542. threads_.size() + dynamic_threads_.size() < max_thread_count_) {
  8543. cleanup_finished_threads();
  8544. dynamic_threads_.emplace_back(std::thread([this]() { worker(true); }));
  8545. }
  8546. }
  8547. cond_.notify_one();
  8548. return true;
  8549. }
  8550. inline void ThreadPool::shutdown() {
  8551. {
  8552. std::unique_lock<std::mutex> lock(mutex_);
  8553. shutdown_ = true;
  8554. }
  8555. cond_.notify_all();
  8556. for (auto &t : threads_) {
  8557. if (t.joinable()) { t.join(); }
  8558. }
  8559. // Move dynamic_threads_ to a local list under the lock to avoid racing
  8560. // with worker threads that call move_to_finished() concurrently.
  8561. std::list<std::thread> remaining_dynamic;
  8562. {
  8563. std::unique_lock<std::mutex> lock(mutex_);
  8564. remaining_dynamic = std::move(dynamic_threads_);
  8565. }
  8566. for (auto &t : remaining_dynamic) {
  8567. if (t.joinable()) { t.join(); }
  8568. }
  8569. std::unique_lock<std::mutex> lock(mutex_);
  8570. cleanup_finished_threads();
  8571. }
  8572. inline void ThreadPool::move_to_finished(std::thread::id id) {
  8573. // Must be called with mutex_ held
  8574. for (auto it = dynamic_threads_.begin(); it != dynamic_threads_.end(); ++it) {
  8575. if (it->get_id() == id) {
  8576. finished_threads_.push_back(std::move(*it));
  8577. dynamic_threads_.erase(it);
  8578. return;
  8579. }
  8580. }
  8581. }
  8582. inline void ThreadPool::cleanup_finished_threads() {
  8583. // Must be called with mutex_ held
  8584. for (auto &t : finished_threads_) {
  8585. if (t.joinable()) { t.join(); }
  8586. }
  8587. finished_threads_.clear();
  8588. }
  8589. inline void ThreadPool::worker(bool is_dynamic) {
  8590. for (;;) {
  8591. std::function<void()> fn;
  8592. {
  8593. std::unique_lock<std::mutex> lock(mutex_);
  8594. idle_thread_count_++;
  8595. if (is_dynamic) {
  8596. auto has_work = cond_.wait_for(
  8597. lock, std::chrono::seconds(CPPHTTPLIB_THREAD_POOL_IDLE_TIMEOUT),
  8598. [&] { return !jobs_.empty() || shutdown_; });
  8599. if (!has_work) {
  8600. // Timed out with no work - exit this dynamic thread
  8601. idle_thread_count_--;
  8602. move_to_finished(std::this_thread::get_id());
  8603. break;
  8604. }
  8605. } else {
  8606. cond_.wait(lock, [&] { return !jobs_.empty() || shutdown_; });
  8607. }
  8608. idle_thread_count_--;
  8609. if (shutdown_ && jobs_.empty()) { break; }
  8610. fn = std::move(jobs_.front());
  8611. jobs_.pop_front();
  8612. }
  8613. assert(true == static_cast<bool>(fn));
  8614. fn();
  8615. }
  8616. #if defined(CPPHTTPLIB_OPENSSL_SUPPORT) && !defined(OPENSSL_IS_BORINGSSL) && \
  8617. !defined(LIBRESSL_VERSION_NUMBER)
  8618. OPENSSL_thread_stop();
  8619. #endif
  8620. }
  8621. /*
  8622. * Group 1 (continued): detail namespace - Stream implementations
  8623. */
  8624. namespace detail {
  8625. inline void calc_actual_timeout(time_t max_timeout_msec, time_t duration_msec,
  8626. time_t timeout_sec, time_t timeout_usec,
  8627. time_t &actual_timeout_sec,
  8628. time_t &actual_timeout_usec) {
  8629. auto timeout_msec = (timeout_sec * 1000) + (timeout_usec / 1000);
  8630. auto actual_timeout_msec =
  8631. (std::min)(max_timeout_msec - duration_msec, timeout_msec);
  8632. if (actual_timeout_msec < 0) { actual_timeout_msec = 0; }
  8633. actual_timeout_sec = actual_timeout_msec / 1000;
  8634. actual_timeout_usec = (actual_timeout_msec % 1000) * 1000;
  8635. }
  8636. // Socket stream implementation
  8637. inline SocketStream::SocketStream(
  8638. socket_t sock, time_t read_timeout_sec, time_t read_timeout_usec,
  8639. time_t write_timeout_sec, time_t write_timeout_usec,
  8640. time_t max_timeout_msec,
  8641. std::chrono::time_point<std::chrono::steady_clock> start_time)
  8642. : sock_(sock), read_timeout_sec_(read_timeout_sec),
  8643. read_timeout_usec_(read_timeout_usec),
  8644. write_timeout_sec_(write_timeout_sec),
  8645. write_timeout_usec_(write_timeout_usec),
  8646. max_timeout_msec_(max_timeout_msec), start_time_(start_time),
  8647. read_buff_(read_buff_size_, 0) {}
  8648. inline SocketStream::~SocketStream() = default;
  8649. inline bool SocketStream::is_readable() const {
  8650. return read_buff_off_ < read_buff_content_size_;
  8651. }
  8652. inline bool SocketStream::wait_readable() const {
  8653. if (max_timeout_msec_ <= 0) {
  8654. return select_read(sock_, read_timeout_sec_, read_timeout_usec_) > 0;
  8655. }
  8656. time_t read_timeout_sec;
  8657. time_t read_timeout_usec;
  8658. calc_actual_timeout(max_timeout_msec_, duration(), read_timeout_sec_,
  8659. read_timeout_usec_, read_timeout_sec, read_timeout_usec);
  8660. return select_read(sock_, read_timeout_sec, read_timeout_usec) > 0;
  8661. }
  8662. inline bool SocketStream::wait_writable() const {
  8663. return select_write(sock_, write_timeout_sec_, write_timeout_usec_) > 0;
  8664. }
  8665. inline bool SocketStream::is_peer_alive() const {
  8666. return detail::is_socket_alive(sock_);
  8667. }
  8668. inline ssize_t SocketStream::read(char *ptr, size_t size) {
  8669. #ifdef _WIN32
  8670. size =
  8671. (std::min)(size, static_cast<size_t>((std::numeric_limits<int>::max)()));
  8672. #else
  8673. size = (std::min)(size,
  8674. static_cast<size_t>((std::numeric_limits<ssize_t>::max)()));
  8675. #endif
  8676. if (read_buff_off_ < read_buff_content_size_) {
  8677. auto remaining_size = read_buff_content_size_ - read_buff_off_;
  8678. if (size <= remaining_size) {
  8679. memcpy(ptr, read_buff_.data() + read_buff_off_, size);
  8680. read_buff_off_ += size;
  8681. return static_cast<ssize_t>(size);
  8682. } else {
  8683. memcpy(ptr, read_buff_.data() + read_buff_off_, remaining_size);
  8684. read_buff_off_ += remaining_size;
  8685. return static_cast<ssize_t>(remaining_size);
  8686. }
  8687. }
  8688. if (!wait_readable()) {
  8689. error_ = Error::Timeout;
  8690. return -1;
  8691. }
  8692. read_buff_off_ = 0;
  8693. read_buff_content_size_ = 0;
  8694. if (size < read_buff_size_) {
  8695. auto n = read_socket(sock_, read_buff_.data(), read_buff_size_,
  8696. CPPHTTPLIB_RECV_FLAGS);
  8697. if (n <= 0) {
  8698. if (n == 0) {
  8699. error_ = Error::ConnectionClosed;
  8700. } else {
  8701. error_ = Error::Read;
  8702. }
  8703. return n;
  8704. } else if (n <= static_cast<ssize_t>(size)) {
  8705. memcpy(ptr, read_buff_.data(), static_cast<size_t>(n));
  8706. return n;
  8707. } else {
  8708. memcpy(ptr, read_buff_.data(), size);
  8709. read_buff_off_ = size;
  8710. read_buff_content_size_ = static_cast<size_t>(n);
  8711. return static_cast<ssize_t>(size);
  8712. }
  8713. } else {
  8714. auto n = read_socket(sock_, ptr, size, CPPHTTPLIB_RECV_FLAGS);
  8715. if (n <= 0) {
  8716. if (n == 0) {
  8717. error_ = Error::ConnectionClosed;
  8718. } else {
  8719. error_ = Error::Read;
  8720. }
  8721. }
  8722. return n;
  8723. }
  8724. }
  8725. inline ssize_t SocketStream::write(const char *ptr, size_t size) {
  8726. if (!wait_writable()) { return -1; }
  8727. #if defined(_WIN32) && !defined(_WIN64)
  8728. size =
  8729. (std::min)(size, static_cast<size_t>((std::numeric_limits<int>::max)()));
  8730. #endif
  8731. return send_socket(sock_, ptr, size, CPPHTTPLIB_SEND_FLAGS);
  8732. }
  8733. inline void SocketStream::get_remote_ip_and_port(std::string &ip,
  8734. int &port) const {
  8735. return detail::get_remote_ip_and_port(sock_, ip, port);
  8736. }
  8737. inline void SocketStream::get_local_ip_and_port(std::string &ip,
  8738. int &port) const {
  8739. return detail::get_local_ip_and_port(sock_, ip, port);
  8740. }
  8741. inline socket_t SocketStream::socket() const { return sock_; }
  8742. inline time_t SocketStream::duration() const {
  8743. return std::chrono::duration_cast<std::chrono::milliseconds>(
  8744. std::chrono::steady_clock::now() - start_time_)
  8745. .count();
  8746. }
  8747. inline void SocketStream::set_read_timeout(time_t sec, time_t usec) {
  8748. read_timeout_sec_ = sec;
  8749. read_timeout_usec_ = usec;
  8750. }
  8751. // Buffer stream implementation
  8752. inline bool BufferStream::is_readable() const { return true; }
  8753. inline bool BufferStream::wait_readable() const { return true; }
  8754. inline bool BufferStream::wait_writable() const { return true; }
  8755. inline ssize_t BufferStream::read(char *ptr, size_t size) {
  8756. #if defined(_MSC_VER) && _MSC_VER < 1910
  8757. auto len_read = buffer._Copy_s(ptr, size, size, position);
  8758. #else
  8759. auto len_read = buffer.copy(ptr, size, position);
  8760. #endif
  8761. position += static_cast<size_t>(len_read);
  8762. return static_cast<ssize_t>(len_read);
  8763. }
  8764. inline ssize_t BufferStream::write(const char *ptr, size_t size) {
  8765. buffer.append(ptr, size);
  8766. return static_cast<ssize_t>(size);
  8767. }
  8768. inline void BufferStream::get_remote_ip_and_port(std::string & /*ip*/,
  8769. int & /*port*/) const {}
  8770. inline void BufferStream::get_local_ip_and_port(std::string & /*ip*/,
  8771. int & /*port*/) const {}
  8772. inline socket_t BufferStream::socket() const { return 0; }
  8773. inline time_t BufferStream::duration() const { return 0; }
  8774. inline const std::string &BufferStream::get_buffer() const { return buffer; }
  8775. inline PathParamsMatcher::PathParamsMatcher(const std::string &pattern)
  8776. : MatcherBase(pattern) {
  8777. constexpr const char marker[] = "/:";
  8778. // One past the last ending position of a path param substring
  8779. std::size_t last_param_end = 0;
  8780. #ifndef CPPHTTPLIB_NO_EXCEPTIONS
  8781. // Needed to ensure that parameter names are unique during matcher
  8782. // construction
  8783. // If exceptions are disabled, only last duplicate path
  8784. // parameter will be set
  8785. std::unordered_set<std::string> param_name_set;
  8786. #endif
  8787. while (true) {
  8788. const auto marker_pos = pattern.find(
  8789. marker, last_param_end == 0 ? last_param_end : last_param_end - 1);
  8790. if (marker_pos == std::string::npos) { break; }
  8791. static_fragments_.push_back(
  8792. pattern.substr(last_param_end, marker_pos - last_param_end + 1));
  8793. const auto param_name_start = marker_pos + str_len(marker);
  8794. auto sep_pos = pattern.find(separator, param_name_start);
  8795. if (sep_pos == std::string::npos) { sep_pos = pattern.length(); }
  8796. auto param_name =
  8797. pattern.substr(param_name_start, sep_pos - param_name_start);
  8798. #ifndef CPPHTTPLIB_NO_EXCEPTIONS
  8799. if (param_name_set.find(param_name) != param_name_set.cend()) {
  8800. std::string msg = "Encountered path parameter '" + param_name +
  8801. "' multiple times in route pattern '" + pattern + "'.";
  8802. throw std::invalid_argument(msg);
  8803. }
  8804. #endif
  8805. param_names_.push_back(std::move(param_name));
  8806. last_param_end = sep_pos + 1;
  8807. }
  8808. if (last_param_end < pattern.length()) {
  8809. static_fragments_.push_back(pattern.substr(last_param_end));
  8810. }
  8811. }
  8812. inline bool PathParamsMatcher::match(Request &request) const {
  8813. request.matches = std::smatch();
  8814. request.path_params.clear();
  8815. request.path_params.reserve(param_names_.size());
  8816. // One past the position at which the path matched the pattern last time
  8817. std::size_t starting_pos = 0;
  8818. for (size_t i = 0; i < static_fragments_.size(); ++i) {
  8819. const auto &fragment = static_fragments_[i];
  8820. if (starting_pos + fragment.length() > request.path.length()) {
  8821. return false;
  8822. }
  8823. // Avoid unnecessary allocation by using strncmp instead of substr +
  8824. // comparison
  8825. if (std::strncmp(request.path.c_str() + starting_pos, fragment.c_str(),
  8826. fragment.length()) != 0) {
  8827. return false;
  8828. }
  8829. starting_pos += fragment.length();
  8830. // Should only happen when we have a static fragment after a param
  8831. // Example: '/users/:id/subscriptions'
  8832. // The 'subscriptions' fragment here does not have a corresponding param
  8833. if (i >= param_names_.size()) { continue; }
  8834. auto sep_pos = request.path.find(separator, starting_pos);
  8835. if (sep_pos == std::string::npos) { sep_pos = request.path.length(); }
  8836. const auto &param_name = param_names_[i];
  8837. request.path_params.emplace(
  8838. param_name, request.path.substr(starting_pos, sep_pos - starting_pos));
  8839. // Mark everything up to '/' as matched
  8840. starting_pos = sep_pos + 1;
  8841. }
  8842. // Returns false if the path is longer than the pattern
  8843. return starting_pos >= request.path.length();
  8844. }
  8845. inline bool RegexMatcher::match(Request &request) const {
  8846. request.path_params.clear();
  8847. return std::regex_match(request.path, request.matches, regex_);
  8848. }
  8849. // Enclose IPv6 address in brackets if needed
  8850. inline std::string prepare_host_string(const std::string &host) {
  8851. // Enclose IPv6 address in brackets (but not if already enclosed)
  8852. if (host.find(':') == std::string::npos ||
  8853. (!host.empty() && host[0] == '[')) {
  8854. // IPv4, hostname, or already bracketed IPv6
  8855. return host;
  8856. } else {
  8857. // IPv6 address without brackets
  8858. return "[" + host + "]";
  8859. }
  8860. }
  8861. inline std::string make_host_and_port_string(const std::string &host, int port,
  8862. bool is_ssl) {
  8863. auto result = prepare_host_string(host);
  8864. // Append port if not default
  8865. if ((!is_ssl && port == 80) || (is_ssl && port == 443)) {
  8866. ; // do nothing
  8867. } else {
  8868. result += ":" + std::to_string(port);
  8869. }
  8870. return result;
  8871. }
  8872. // Create "host:port" string always including port number (for CONNECT method)
  8873. inline std::string
  8874. make_host_and_port_string_always_port(const std::string &host, int port) {
  8875. return prepare_host_string(host) + ":" + std::to_string(port);
  8876. }
  8877. bool parse_no_proxy_entry(const std::string &token, NoProxyEntry &out);
  8878. NormalizedTarget normalize_target(const std::string &host);
  8879. bool ip_in_cidr(const IPBytes &ip, const IPBytes &net, int prefix_bits);
  8880. bool host_matches_no_proxy(const NormalizedTarget &target,
  8881. const std::vector<NoProxyEntry> &entries);
  8882. inline bool ip_in_cidr(const IPBytes &ip, const IPBytes &net, int prefix_bits) {
  8883. if (prefix_bits < 0 || prefix_bits > 128) { return false; }
  8884. if (prefix_bits == 0) { return true; }
  8885. int full_bytes = prefix_bits / 8;
  8886. int rem_bits = prefix_bits % 8;
  8887. if (full_bytes > 0 && std::memcmp(ip.data(), net.data(),
  8888. static_cast<size_t>(full_bytes)) != 0) {
  8889. return false;
  8890. }
  8891. if (rem_bits == 0) { return true; }
  8892. auto i = static_cast<size_t>(full_bytes);
  8893. auto mask = static_cast<uint8_t>(0xFFu << (8 - rem_bits));
  8894. return (ip[i] & mask) == (net[i] & mask);
  8895. }
  8896. inline bool parse_no_proxy_entry(const std::string &token, NoProxyEntry &out) {
  8897. if (token.empty()) { return false; }
  8898. if (token == "*") {
  8899. out.kind = NoProxyKind::Wildcard;
  8900. return true;
  8901. }
  8902. auto slash = token.find('/');
  8903. std::string addr_part =
  8904. (slash == std::string::npos) ? token : token.substr(0, slash);
  8905. std::string prefix_part =
  8906. (slash == std::string::npos) ? std::string() : token.substr(slash + 1);
  8907. // A bare slash or trailing-slash CIDR like "10.0.0.0/" is malformed;
  8908. // don't silently treat it as a /32 (or /128).
  8909. if (slash != std::string::npos && prefix_part.empty()) { return false; }
  8910. // Accept the bracketed IPv6 form ("[::1]", "[fe80::]/10") as well as the
  8911. // bare form. Brackets have no meaning for IPv4, so skip the IPv4 attempt
  8912. // when brackets are present.
  8913. bool bracketed = addr_part.size() >= 2 && addr_part.front() == '[' &&
  8914. addr_part.back() == ']';
  8915. if (bracketed) { addr_part = addr_part.substr(1, addr_part.size() - 2); }
  8916. if (!bracketed) {
  8917. struct in_addr v4;
  8918. if (inet_pton(AF_INET, addr_part.c_str(), &v4) == 1) {
  8919. int prefix = 32;
  8920. if (!prefix_part.empty()) {
  8921. auto r = from_chars(prefix_part.data(),
  8922. prefix_part.data() + prefix_part.size(), prefix);
  8923. if (r.ec != std::errc{} ||
  8924. r.ptr != prefix_part.data() + prefix_part.size()) {
  8925. return false;
  8926. }
  8927. if (prefix < 0 || prefix > 32) { return false; }
  8928. }
  8929. out.kind = NoProxyKind::IPv4Cidr;
  8930. std::memcpy(out.net.data(), &v4, sizeof(v4));
  8931. out.prefix_bits = prefix;
  8932. return true;
  8933. }
  8934. }
  8935. struct in6_addr v6;
  8936. if (inet_pton(AF_INET6, addr_part.c_str(), &v6) == 1) {
  8937. int prefix = 128;
  8938. if (!prefix_part.empty()) {
  8939. auto r = from_chars(prefix_part.data(),
  8940. prefix_part.data() + prefix_part.size(), prefix);
  8941. if (r.ec != std::errc{} ||
  8942. r.ptr != prefix_part.data() + prefix_part.size()) {
  8943. return false;
  8944. }
  8945. if (prefix < 0 || prefix > 128) { return false; }
  8946. }
  8947. out.kind = NoProxyKind::IPv6Cidr;
  8948. std::memcpy(out.net.data(), &v6, sizeof(v6));
  8949. out.prefix_bits = prefix;
  8950. return true;
  8951. }
  8952. // Bracketed entries can only be IPv6. If the IPv6 parse above failed,
  8953. // the entry is malformed — don't fall through to the hostname branch.
  8954. if (bracketed) { return false; }
  8955. // A '/' on a non-IP token means a CIDR prefix without an address. Reject.
  8956. if (slash != std::string::npos) { return false; }
  8957. // Port-specific entries (host:port) are not supported.
  8958. if (token.find(':') != std::string::npos) { return false; }
  8959. std::string hostname = case_ignore::to_lower(token);
  8960. while (!hostname.empty() && hostname.front() == '.') {
  8961. hostname.erase(hostname.begin());
  8962. }
  8963. while (!hostname.empty() && hostname.back() == '.') {
  8964. hostname.pop_back();
  8965. }
  8966. if (hostname.empty()) { return false; }
  8967. out.kind = NoProxyKind::HostnameSuffix;
  8968. out.hostname_pattern = std::move(hostname);
  8969. return true;
  8970. }
  8971. inline NormalizedTarget normalize_target(const std::string &host) {
  8972. NormalizedTarget t;
  8973. std::string h = host;
  8974. if (h.size() >= 2 && h.front() == '[' && h.back() == ']') {
  8975. h = h.substr(1, h.size() - 2);
  8976. }
  8977. // Strip a single trailing dot so "example.com." canonicalizes to
  8978. // "example.com".
  8979. if (!h.empty() && h.back() == '.') { h.pop_back(); }
  8980. t.hostname = case_ignore::to_lower(h);
  8981. if (!t.hostname.empty()) {
  8982. struct in_addr v4;
  8983. struct in6_addr v6;
  8984. if (inet_pton(AF_INET, t.hostname.c_str(), &v4) == 1) {
  8985. t.is_ipv4 = true;
  8986. std::memcpy(t.ip.data(), &v4, sizeof(v4));
  8987. } else if (inet_pton(AF_INET6, t.hostname.c_str(), &v6) == 1) {
  8988. t.is_ipv6 = true;
  8989. std::memcpy(t.ip.data(), &v6, sizeof(v6));
  8990. }
  8991. }
  8992. return t;
  8993. }
  8994. inline bool host_matches_no_proxy(const NormalizedTarget &target,
  8995. const std::vector<NoProxyEntry> &entries) {
  8996. if (target.hostname.empty()) { return false; }
  8997. for (const auto &e : entries) {
  8998. switch (e.kind) {
  8999. case NoProxyKind::Wildcard: return true;
  9000. case NoProxyKind::IPv4Cidr:
  9001. if (target.is_ipv4 && ip_in_cidr(target.ip, e.net, e.prefix_bits)) {
  9002. return true;
  9003. }
  9004. break;
  9005. case NoProxyKind::IPv6Cidr:
  9006. if (target.is_ipv6 && ip_in_cidr(target.ip, e.net, e.prefix_bits)) {
  9007. return true;
  9008. }
  9009. break;
  9010. case NoProxyKind::HostnameSuffix:
  9011. if (target.is_ipv4 || target.is_ipv6) { break; }
  9012. if (target.hostname == e.hostname_pattern) { return true; }
  9013. // Dot-boundary suffix match: prevents "evilexample.com" from matching
  9014. // an entry of "example.com".
  9015. if (target.hostname.size() > e.hostname_pattern.size() + 1) {
  9016. auto offset = target.hostname.size() - e.hostname_pattern.size();
  9017. if (target.hostname[offset - 1] == '.' &&
  9018. target.hostname.compare(offset, e.hostname_pattern.size(),
  9019. e.hostname_pattern) == 0) {
  9020. return true;
  9021. }
  9022. }
  9023. break;
  9024. }
  9025. }
  9026. return false;
  9027. }
  9028. template <typename T>
  9029. inline bool check_and_write_headers(Stream &strm, Headers &headers,
  9030. T header_writer, Error &error) {
  9031. for (const auto &h : headers) {
  9032. if (!detail::fields::is_field_name(h.first) ||
  9033. !detail::fields::is_field_value(h.second)) {
  9034. error = Error::InvalidHeaders;
  9035. return false;
  9036. }
  9037. }
  9038. if (header_writer(strm, headers) <= 0) {
  9039. error = Error::Write;
  9040. return false;
  9041. }
  9042. return true;
  9043. }
  9044. } // namespace detail
  9045. /*
  9046. * Group 2 (continued): detail namespace - SSLSocketStream implementation
  9047. */
  9048. #ifdef CPPHTTPLIB_SSL_ENABLED
  9049. namespace detail {
  9050. // SSL socket stream implementation
  9051. inline SSLSocketStream::SSLSocketStream(
  9052. socket_t sock, tls::session_t session, time_t read_timeout_sec,
  9053. time_t read_timeout_usec, time_t write_timeout_sec,
  9054. time_t write_timeout_usec, time_t max_timeout_msec,
  9055. std::chrono::time_point<std::chrono::steady_clock> start_time)
  9056. : sock_(sock), session_(session), read_timeout_sec_(read_timeout_sec),
  9057. read_timeout_usec_(read_timeout_usec),
  9058. write_timeout_sec_(write_timeout_sec),
  9059. write_timeout_usec_(write_timeout_usec),
  9060. max_timeout_msec_(max_timeout_msec), start_time_(start_time) {
  9061. #ifdef CPPHTTPLIB_OPENSSL_SUPPORT
  9062. // Clear AUTO_RETRY for proper non-blocking I/O timeout handling
  9063. // Note: create_session() also clears this, but SSLClient currently
  9064. // uses ssl_new() which does not. Until full TLS API migration is complete,
  9065. // we need to ensure AUTO_RETRY is cleared here regardless of how the
  9066. // SSL session was created.
  9067. SSL_clear_mode(static_cast<SSL *>(session), SSL_MODE_AUTO_RETRY);
  9068. #endif
  9069. }
  9070. inline SSLSocketStream::~SSLSocketStream() = default;
  9071. inline bool SSLSocketStream::is_readable() const {
  9072. return tls::pending(session_) > 0;
  9073. }
  9074. inline bool SSLSocketStream::wait_readable() const {
  9075. if (max_timeout_msec_ <= 0) {
  9076. return select_read(sock_, read_timeout_sec_, read_timeout_usec_) > 0;
  9077. }
  9078. time_t read_timeout_sec;
  9079. time_t read_timeout_usec;
  9080. calc_actual_timeout(max_timeout_msec_, duration(), read_timeout_sec_,
  9081. read_timeout_usec_, read_timeout_sec, read_timeout_usec);
  9082. return select_read(sock_, read_timeout_sec, read_timeout_usec) > 0;
  9083. }
  9084. inline bool SSLSocketStream::wait_writable() const {
  9085. return select_write(sock_, write_timeout_sec_, write_timeout_usec_) > 0 &&
  9086. !tls::is_peer_closed(session_, sock_);
  9087. }
  9088. inline bool SSLSocketStream::is_peer_alive() const {
  9089. return !tls::is_peer_closed(session_, sock_);
  9090. }
  9091. inline ssize_t SSLSocketStream::read(char *ptr, size_t size) {
  9092. if (tls::pending(session_) > 0) {
  9093. tls::TlsError err;
  9094. auto ret = tls::read(session_, ptr, size, err);
  9095. if (ret == 0 || err.code == tls::ErrorCode::PeerClosed) {
  9096. error_ = Error::ConnectionClosed;
  9097. }
  9098. return ret;
  9099. } else if (wait_readable()) {
  9100. tls::TlsError err;
  9101. auto ret = tls::read(session_, ptr, size, err);
  9102. if (ret < 0) {
  9103. auto n = 1000;
  9104. #ifdef _WIN32
  9105. while (--n >= 0 && (err.code == tls::ErrorCode::WantRead ||
  9106. (err.code == tls::ErrorCode::SyscallError &&
  9107. WSAGetLastError() == WSAETIMEDOUT))) {
  9108. #else
  9109. while (--n >= 0 && err.code == tls::ErrorCode::WantRead) {
  9110. #endif
  9111. if (tls::pending(session_) > 0) {
  9112. return tls::read(session_, ptr, size, err);
  9113. } else if (wait_readable()) {
  9114. std::this_thread::sleep_for(std::chrono::microseconds{10});
  9115. ret = tls::read(session_, ptr, size, err);
  9116. if (ret >= 0) { return ret; }
  9117. } else {
  9118. break;
  9119. }
  9120. }
  9121. assert(ret < 0);
  9122. } else if (ret == 0 || err.code == tls::ErrorCode::PeerClosed) {
  9123. error_ = Error::ConnectionClosed;
  9124. }
  9125. return ret;
  9126. } else {
  9127. error_ = Error::Timeout;
  9128. return -1;
  9129. }
  9130. }
  9131. inline ssize_t SSLSocketStream::write(const char *ptr, size_t size) {
  9132. if (wait_writable()) {
  9133. auto handle_size =
  9134. std::min<size_t>(size, (std::numeric_limits<int>::max)());
  9135. tls::TlsError err;
  9136. auto ret = tls::write(session_, ptr, handle_size, err);
  9137. if (ret < 0) {
  9138. auto n = 1000;
  9139. #ifdef _WIN32
  9140. while (--n >= 0 && (err.code == tls::ErrorCode::WantWrite ||
  9141. (err.code == tls::ErrorCode::SyscallError &&
  9142. WSAGetLastError() == WSAETIMEDOUT))) {
  9143. #else
  9144. while (--n >= 0 && err.code == tls::ErrorCode::WantWrite) {
  9145. #endif
  9146. if (wait_writable()) {
  9147. std::this_thread::sleep_for(std::chrono::microseconds{10});
  9148. ret = tls::write(session_, ptr, handle_size, err);
  9149. if (ret >= 0) { return ret; }
  9150. } else {
  9151. break;
  9152. }
  9153. }
  9154. assert(ret < 0);
  9155. }
  9156. return ret;
  9157. }
  9158. return -1;
  9159. }
  9160. inline void SSLSocketStream::get_remote_ip_and_port(std::string &ip,
  9161. int &port) const {
  9162. detail::get_remote_ip_and_port(sock_, ip, port);
  9163. }
  9164. inline void SSLSocketStream::get_local_ip_and_port(std::string &ip,
  9165. int &port) const {
  9166. detail::get_local_ip_and_port(sock_, ip, port);
  9167. }
  9168. inline socket_t SSLSocketStream::socket() const { return sock_; }
  9169. inline time_t SSLSocketStream::duration() const {
  9170. return std::chrono::duration_cast<std::chrono::milliseconds>(
  9171. std::chrono::steady_clock::now() - start_time_)
  9172. .count();
  9173. }
  9174. inline void SSLSocketStream::set_read_timeout(time_t sec, time_t usec) {
  9175. read_timeout_sec_ = sec;
  9176. read_timeout_usec_ = usec;
  9177. }
  9178. } // namespace detail
  9179. #endif // CPPHTTPLIB_SSL_ENABLED
  9180. /*
  9181. * Group 4: Server implementation
  9182. */
  9183. // HTTP server implementation
  9184. inline Server::Server()
  9185. : new_task_queue([] {
  9186. return new ThreadPool(CPPHTTPLIB_THREAD_POOL_COUNT,
  9187. CPPHTTPLIB_THREAD_POOL_MAX_COUNT);
  9188. }) {
  9189. #ifndef _WIN32
  9190. signal(SIGPIPE, SIG_IGN);
  9191. #endif
  9192. }
  9193. inline Server::~Server() = default;
  9194. inline std::unique_ptr<detail::MatcherBase>
  9195. Server::make_matcher(const std::string &pattern) {
  9196. if (pattern.find("/:") != std::string::npos) {
  9197. return detail::make_unique<detail::PathParamsMatcher>(pattern);
  9198. } else {
  9199. return detail::make_unique<detail::RegexMatcher>(pattern);
  9200. }
  9201. }
  9202. inline Server &Server::Get(const std::string &pattern, Handler handler) {
  9203. return add_handler(get_handlers_, pattern, std::move(handler));
  9204. }
  9205. inline Server &Server::Post(const std::string &pattern, Handler handler) {
  9206. return add_handler(post_handlers_, pattern, std::move(handler));
  9207. }
  9208. inline Server &Server::Post(const std::string &pattern,
  9209. HandlerWithContentReader handler) {
  9210. return add_handler(post_handlers_for_content_reader_, pattern,
  9211. std::move(handler));
  9212. }
  9213. inline Server &Server::Put(const std::string &pattern, Handler handler) {
  9214. return add_handler(put_handlers_, pattern, std::move(handler));
  9215. }
  9216. inline Server &Server::Put(const std::string &pattern,
  9217. HandlerWithContentReader handler) {
  9218. return add_handler(put_handlers_for_content_reader_, pattern,
  9219. std::move(handler));
  9220. }
  9221. inline Server &Server::Patch(const std::string &pattern, Handler handler) {
  9222. return add_handler(patch_handlers_, pattern, std::move(handler));
  9223. }
  9224. inline Server &Server::Patch(const std::string &pattern,
  9225. HandlerWithContentReader handler) {
  9226. return add_handler(patch_handlers_for_content_reader_, pattern,
  9227. std::move(handler));
  9228. }
  9229. inline Server &Server::Delete(const std::string &pattern, Handler handler) {
  9230. return add_handler(delete_handlers_, pattern, std::move(handler));
  9231. }
  9232. inline Server &Server::Delete(const std::string &pattern,
  9233. HandlerWithContentReader handler) {
  9234. return add_handler(delete_handlers_for_content_reader_, pattern,
  9235. std::move(handler));
  9236. }
  9237. inline Server &Server::Options(const std::string &pattern, Handler handler) {
  9238. return add_handler(options_handlers_, pattern, std::move(handler));
  9239. }
  9240. inline Server &Server::WebSocket(const std::string &pattern,
  9241. WebSocketHandler handler) {
  9242. websocket_handlers_.push_back(
  9243. {make_matcher(pattern), std::move(handler), nullptr});
  9244. return *this;
  9245. }
  9246. inline Server &Server::WebSocket(const std::string &pattern,
  9247. WebSocketHandler handler,
  9248. SubProtocolSelector sub_protocol_selector) {
  9249. websocket_handlers_.push_back({make_matcher(pattern), std::move(handler),
  9250. std::move(sub_protocol_selector)});
  9251. return *this;
  9252. }
  9253. inline bool Server::set_base_dir(const std::string &dir,
  9254. const std::string &mount_point) {
  9255. return set_mount_point(mount_point, dir);
  9256. }
  9257. inline bool Server::set_mount_point(const std::string &mount_point,
  9258. const std::string &dir, Headers headers) {
  9259. detail::FileStat stat(dir);
  9260. if (stat.is_dir()) {
  9261. std::string mnt = !mount_point.empty() ? mount_point : "/";
  9262. if (!mnt.empty() && mnt[0] == '/') {
  9263. std::string resolved_base;
  9264. if (detail::canonicalize_path(dir.c_str(), resolved_base)) {
  9265. #if defined(_WIN32)
  9266. if (resolved_base.back() != '\\' && resolved_base.back() != '/') {
  9267. resolved_base += '\\';
  9268. }
  9269. #else
  9270. if (resolved_base.back() != '/') { resolved_base += '/'; }
  9271. #endif
  9272. }
  9273. base_dirs_.push_back(
  9274. {std::move(mnt), dir, std::move(resolved_base), std::move(headers)});
  9275. return true;
  9276. }
  9277. }
  9278. return false;
  9279. }
  9280. inline bool Server::remove_mount_point(const std::string &mount_point) {
  9281. for (auto it = base_dirs_.begin(); it != base_dirs_.end(); ++it) {
  9282. if (it->mount_point == mount_point) {
  9283. base_dirs_.erase(it);
  9284. return true;
  9285. }
  9286. }
  9287. return false;
  9288. }
  9289. inline Server &
  9290. Server::set_file_extension_and_mimetype_mapping(const std::string &ext,
  9291. const std::string &mime) {
  9292. file_extension_and_mimetype_map_[ext] = mime;
  9293. return *this;
  9294. }
  9295. inline Server &Server::set_default_file_mimetype(const std::string &mime) {
  9296. default_file_mimetype_ = mime;
  9297. return *this;
  9298. }
  9299. inline Server &Server::set_file_request_handler(Handler handler) {
  9300. file_request_handler_ = std::move(handler);
  9301. return *this;
  9302. }
  9303. inline Server &Server::set_error_handler_core(HandlerWithResponse handler,
  9304. std::true_type) {
  9305. error_handler_ = std::move(handler);
  9306. return *this;
  9307. }
  9308. inline Server &Server::set_error_handler_core(Handler handler,
  9309. std::false_type) {
  9310. error_handler_ = [handler](const Request &req, Response &res) {
  9311. handler(req, res);
  9312. return HandlerResponse::Handled;
  9313. };
  9314. return *this;
  9315. }
  9316. inline Server &Server::set_exception_handler(ExceptionHandler handler) {
  9317. exception_handler_ = std::move(handler);
  9318. return *this;
  9319. }
  9320. inline Server &Server::set_pre_routing_handler(HandlerWithResponse handler) {
  9321. pre_routing_handler_ = std::move(handler);
  9322. return *this;
  9323. }
  9324. inline Server &Server::set_post_routing_handler(Handler handler) {
  9325. post_routing_handler_ = std::move(handler);
  9326. return *this;
  9327. }
  9328. inline Server &Server::set_pre_request_handler(HandlerWithResponse handler) {
  9329. pre_request_handler_ = std::move(handler);
  9330. return *this;
  9331. }
  9332. inline Server &Server::set_logger(Logger logger) {
  9333. logger_ = std::move(logger);
  9334. return *this;
  9335. }
  9336. inline Server &Server::set_error_logger(ErrorLogger error_logger) {
  9337. error_logger_ = std::move(error_logger);
  9338. return *this;
  9339. }
  9340. inline Server &Server::set_pre_compression_logger(Logger logger) {
  9341. pre_compression_logger_ = std::move(logger);
  9342. return *this;
  9343. }
  9344. inline Server &
  9345. Server::set_expect_100_continue_handler(Expect100ContinueHandler handler) {
  9346. expect_100_continue_handler_ = std::move(handler);
  9347. return *this;
  9348. }
  9349. inline Server &Server::set_start_handler(StartHandler handler) {
  9350. start_handler_ = std::move(handler);
  9351. return *this;
  9352. }
  9353. inline Server &Server::set_address_family(int family) {
  9354. address_family_ = family;
  9355. return *this;
  9356. }
  9357. inline Server &Server::set_tcp_nodelay(bool on) {
  9358. tcp_nodelay_ = on;
  9359. return *this;
  9360. }
  9361. inline Server &Server::set_ipv6_v6only(bool on) {
  9362. ipv6_v6only_ = on;
  9363. return *this;
  9364. }
  9365. inline Server &Server::set_socket_options(SocketOptions socket_options) {
  9366. socket_options_ = std::move(socket_options);
  9367. return *this;
  9368. }
  9369. inline Server &Server::set_default_headers(Headers headers) {
  9370. default_headers_ = std::move(headers);
  9371. return *this;
  9372. }
  9373. inline Server &Server::set_header_writer(
  9374. std::function<ssize_t(Stream &, Headers &)> const &writer) {
  9375. header_writer_ = writer;
  9376. return *this;
  9377. }
  9378. inline Server &
  9379. Server::set_trusted_proxies(const std::vector<std::string> &proxies) {
  9380. trusted_proxies_ = proxies;
  9381. return *this;
  9382. }
  9383. inline Server &Server::set_keep_alive_max_count(size_t count) {
  9384. keep_alive_max_count_ = count;
  9385. return *this;
  9386. }
  9387. inline Server &Server::set_keep_alive_timeout(time_t sec) {
  9388. keep_alive_timeout_sec_ = sec;
  9389. return *this;
  9390. }
  9391. template <class Rep, class Period>
  9392. inline Server &Server::set_keep_alive_timeout(
  9393. const std::chrono::duration<Rep, Period> &duration) {
  9394. detail::duration_to_sec_and_usec(duration, [&](time_t sec, time_t /*usec*/) {
  9395. set_keep_alive_timeout(sec);
  9396. });
  9397. return *this;
  9398. }
  9399. inline Server &Server::set_read_timeout(time_t sec, time_t usec) {
  9400. read_timeout_sec_ = sec;
  9401. read_timeout_usec_ = usec;
  9402. return *this;
  9403. }
  9404. inline Server &Server::set_write_timeout(time_t sec, time_t usec) {
  9405. write_timeout_sec_ = sec;
  9406. write_timeout_usec_ = usec;
  9407. return *this;
  9408. }
  9409. inline Server &Server::set_idle_interval(time_t sec, time_t usec) {
  9410. idle_interval_sec_ = sec;
  9411. idle_interval_usec_ = usec;
  9412. return *this;
  9413. }
  9414. inline Server &Server::set_payload_max_length(size_t length) {
  9415. payload_max_length_ = length;
  9416. return *this;
  9417. }
  9418. inline Server &Server::set_websocket_max_missed_pongs(int count) {
  9419. websocket_max_missed_pongs_ = count;
  9420. return *this;
  9421. }
  9422. inline Server &Server::set_websocket_ping_interval(time_t sec) {
  9423. websocket_ping_interval_sec_ = sec;
  9424. return *this;
  9425. }
  9426. template <class Rep, class Period>
  9427. inline Server &Server::set_websocket_ping_interval(
  9428. const std::chrono::duration<Rep, Period> &duration) {
  9429. detail::duration_to_sec_and_usec(duration, [&](time_t sec, time_t /*usec*/) {
  9430. set_websocket_ping_interval(sec);
  9431. });
  9432. return *this;
  9433. }
  9434. inline bool Server::bind_to_port(const std::string &host, int port,
  9435. int socket_flags) {
  9436. auto ret = bind_internal(host, port, socket_flags);
  9437. if (ret == -1) { is_decommissioned = true; }
  9438. return ret >= 0;
  9439. }
  9440. inline int Server::bind_to_any_port(const std::string &host, int socket_flags) {
  9441. auto ret = bind_internal(host, 0, socket_flags);
  9442. if (ret == -1) { is_decommissioned = true; }
  9443. return ret;
  9444. }
  9445. inline bool Server::listen_after_bind() { return listen_internal(); }
  9446. inline bool Server::listen(const std::string &host, int port,
  9447. int socket_flags) {
  9448. return bind_to_port(host, port, socket_flags) && listen_internal();
  9449. }
  9450. inline bool Server::is_running() const { return is_running_; }
  9451. inline void Server::wait_until_ready() const {
  9452. while (!is_running_ && !is_decommissioned) {
  9453. std::this_thread::sleep_for(std::chrono::milliseconds{1});
  9454. }
  9455. }
  9456. inline void Server::stop() noexcept {
  9457. if (is_running_) {
  9458. assert(svr_sock_ != INVALID_SOCKET);
  9459. std::atomic<socket_t> sock(svr_sock_.exchange(INVALID_SOCKET));
  9460. detail::shutdown_socket(sock);
  9461. detail::close_socket(sock);
  9462. }
  9463. is_decommissioned = false;
  9464. }
  9465. inline void Server::decommission() { is_decommissioned = true; }
  9466. inline bool Server::parse_request_line(const char *s, Request &req) const {
  9467. auto len = strlen(s);
  9468. if (len < 2 || s[len - 2] != '\r' || s[len - 1] != '\n') { return false; }
  9469. len -= 2;
  9470. {
  9471. size_t count = 0;
  9472. detail::split(s, s + len, ' ', [&](const char *b, const char *e) {
  9473. switch (count) {
  9474. case 0: req.method = std::string(b, e); break;
  9475. case 1: req.target = std::string(b, e); break;
  9476. case 2: req.version = std::string(b, e); break;
  9477. default: break;
  9478. }
  9479. count++;
  9480. });
  9481. if (count != 3) { return false; }
  9482. }
  9483. thread_local const std::set<std::string> methods{
  9484. "GET", "HEAD", "POST", "PUT", "DELETE",
  9485. "CONNECT", "OPTIONS", "TRACE", "PATCH", "PRI"};
  9486. if (methods.find(req.method) == methods.end()) {
  9487. output_error_log(Error::InvalidHTTPMethod, &req);
  9488. return false;
  9489. }
  9490. if (req.version != "HTTP/1.1" && req.version != "HTTP/1.0") {
  9491. output_error_log(Error::InvalidHTTPVersion, &req);
  9492. return false;
  9493. }
  9494. {
  9495. // Skip URL fragment
  9496. for (size_t i = 0; i < req.target.size(); i++) {
  9497. if (req.target[i] == '#') {
  9498. req.target.erase(i);
  9499. break;
  9500. }
  9501. }
  9502. detail::divide(req.target, '?',
  9503. [&](const char *lhs_data, std::size_t lhs_size,
  9504. const char *rhs_data, std::size_t rhs_size) {
  9505. req.path =
  9506. decode_path_component(std::string(lhs_data, lhs_size));
  9507. detail::parse_query_text(rhs_data, rhs_size, req.params);
  9508. });
  9509. }
  9510. return true;
  9511. }
  9512. inline bool Server::write_response(Stream &strm, bool close_connection,
  9513. Request &req, Response &res) {
  9514. // NOTE: `req.ranges` should be empty, otherwise it will be applied
  9515. // incorrectly to the error content.
  9516. req.ranges.clear();
  9517. return write_response_core(strm, close_connection, req, res, false);
  9518. }
  9519. inline bool Server::write_response_with_content(Stream &strm,
  9520. bool close_connection,
  9521. const Request &req,
  9522. Response &res) {
  9523. return write_response_core(strm, close_connection, req, res, true);
  9524. }
  9525. inline bool Server::write_response_core(Stream &strm, bool close_connection,
  9526. const Request &req, Response &res,
  9527. bool need_apply_ranges) {
  9528. assert(res.status != -1);
  9529. if (400 <= res.status && error_handler_ &&
  9530. error_handler_(req, res) == HandlerResponse::Handled) {
  9531. need_apply_ranges = true;
  9532. }
  9533. std::string content_type;
  9534. std::string boundary;
  9535. if (need_apply_ranges) { apply_ranges(req, res, content_type, boundary); }
  9536. // Prepare additional headers
  9537. if (close_connection || req.get_header_value("Connection") == "close" ||
  9538. 400 <= res.status) { // Don't leave connections open after errors
  9539. res.set_header("Connection", "close");
  9540. } else {
  9541. std::string s = "timeout=";
  9542. s += std::to_string(keep_alive_timeout_sec_);
  9543. s += ", max=";
  9544. s += std::to_string(keep_alive_max_count_);
  9545. res.set_header("Keep-Alive", s);
  9546. }
  9547. if ((!res.body.empty() || res.content_length_ > 0 || res.content_provider_) &&
  9548. !res.has_header("Content-Type")) {
  9549. res.set_header("Content-Type", "text/plain");
  9550. }
  9551. if (res.body.empty() && !res.content_length_ && !res.content_provider_ &&
  9552. !res.has_header("Content-Length")) {
  9553. res.set_header("Content-Length", "0");
  9554. }
  9555. if (req.method == "HEAD" && !res.has_header("Accept-Ranges")) {
  9556. res.set_header("Accept-Ranges", "bytes");
  9557. }
  9558. if (post_routing_handler_) { post_routing_handler_(req, res); }
  9559. // Response line and headers
  9560. detail::BufferStream bstrm;
  9561. if (!detail::write_response_line(bstrm, res.status)) { return false; }
  9562. if (header_writer_(bstrm, res.headers) <= 0) { return false; }
  9563. // Combine small body with headers to reduce write syscalls
  9564. if (req.method != "HEAD" && !res.body.empty() && !res.content_provider_) {
  9565. bstrm.write(res.body.data(), res.body.size());
  9566. }
  9567. // Log before writing to avoid race condition with client-side code that
  9568. // accesses logger-captured data immediately after receiving the response.
  9569. output_log(req, res);
  9570. // Flush buffer
  9571. auto &data = bstrm.get_buffer();
  9572. if (!detail::write_data(strm, data.data(), data.size())) { return false; }
  9573. // Streaming body
  9574. auto ret = true;
  9575. if (req.method != "HEAD" && res.content_provider_) {
  9576. if (write_content_with_provider(strm, req, res, boundary, content_type)) {
  9577. res.content_provider_success_ = true;
  9578. } else {
  9579. ret = false;
  9580. }
  9581. }
  9582. return ret;
  9583. }
  9584. inline bool
  9585. Server::write_content_with_provider(Stream &strm, const Request &req,
  9586. Response &res, const std::string &boundary,
  9587. const std::string &content_type) {
  9588. auto is_shutting_down = [this]() {
  9589. return this->svr_sock_ == INVALID_SOCKET;
  9590. };
  9591. if (res.content_length_ > 0) {
  9592. if (req.ranges.empty()) {
  9593. return detail::write_content(strm, res.content_provider_, 0,
  9594. res.content_length_, is_shutting_down);
  9595. } else if (req.ranges.size() == 1) {
  9596. auto offset_and_length = detail::get_range_offset_and_length(
  9597. req.ranges[0], res.content_length_);
  9598. return detail::write_content(strm, res.content_provider_,
  9599. offset_and_length.first,
  9600. offset_and_length.second, is_shutting_down);
  9601. } else {
  9602. return detail::write_multipart_ranges_data(
  9603. strm, req, res, boundary, content_type, res.content_length_,
  9604. is_shutting_down);
  9605. }
  9606. } else {
  9607. if (res.is_chunked_content_provider_) {
  9608. auto type = detail::encoding_type(req, res);
  9609. auto compressor = detail::make_compressor(type);
  9610. if (!compressor) {
  9611. compressor = detail::make_unique<detail::nocompressor>();
  9612. }
  9613. return detail::write_content_chunked(strm, res.content_provider_,
  9614. is_shutting_down, *compressor);
  9615. } else {
  9616. return detail::write_content_without_length(strm, res.content_provider_,
  9617. is_shutting_down);
  9618. }
  9619. }
  9620. }
  9621. inline bool Server::read_content(Stream &strm, Request &req, Response &res) {
  9622. FormFields::iterator cur_field;
  9623. FormFiles::iterator cur_file;
  9624. auto is_text_field = false;
  9625. size_t count = 0;
  9626. if (read_content_core(
  9627. strm, req, res,
  9628. // Regular
  9629. [&](const char *buf, size_t n) {
  9630. // Prevent arithmetic overflow when checking sizes.
  9631. // Avoid computing (req.body.size() + n) directly because
  9632. // adding two unsigned `size_t` values can wrap around and
  9633. // produce a small result instead of indicating overflow.
  9634. // Instead, check using subtraction: ensure `n` does not
  9635. // exceed the remaining capacity `max_size() - size()`.
  9636. if (req.body.size() >= req.body.max_size() ||
  9637. n > req.body.max_size() - req.body.size()) {
  9638. return false;
  9639. }
  9640. // Limit decompressed body size to payload_max_length_ to protect
  9641. // against "zip bomb" attacks where a small compressed payload
  9642. // decompresses to a massive size.
  9643. if (payload_max_length_ > 0 &&
  9644. (req.body.size() >= payload_max_length_ ||
  9645. n > payload_max_length_ - req.body.size())) {
  9646. return false;
  9647. }
  9648. req.body.append(buf, n);
  9649. return true;
  9650. },
  9651. // Multipart FormData
  9652. [&](const FormData &file) {
  9653. if (count++ == CPPHTTPLIB_MULTIPART_FORM_DATA_FILE_MAX_COUNT) {
  9654. output_error_log(Error::TooManyFormDataFiles, &req);
  9655. return false;
  9656. }
  9657. if (file.filename.empty()) {
  9658. cur_field = req.form.fields.emplace(
  9659. file.name, FormField{file.name, file.content, file.headers});
  9660. is_text_field = true;
  9661. } else {
  9662. cur_file = req.form.files.emplace(file.name, file);
  9663. is_text_field = false;
  9664. }
  9665. return true;
  9666. },
  9667. [&](const char *buf, size_t n) {
  9668. if (is_text_field) {
  9669. auto &content = cur_field->second.content;
  9670. if (content.size() + n > content.max_size()) { return false; }
  9671. content.append(buf, n);
  9672. } else {
  9673. auto &content = cur_file->second.content;
  9674. if (content.size() + n > content.max_size()) { return false; }
  9675. content.append(buf, n);
  9676. }
  9677. return true;
  9678. })) {
  9679. const auto &content_type = req.get_header_value("Content-Type");
  9680. if (detail::extract_media_type(content_type) ==
  9681. "application/x-www-form-urlencoded") {
  9682. if (req.body.size() > CPPHTTPLIB_FORM_URL_ENCODED_PAYLOAD_MAX_LENGTH) {
  9683. res.status = StatusCode::PayloadTooLarge_413; // NOTE: should be 414?
  9684. output_error_log(Error::ExceedMaxPayloadSize, &req);
  9685. return false;
  9686. }
  9687. detail::parse_query_text(req.body, req.params);
  9688. }
  9689. return true;
  9690. }
  9691. return false;
  9692. }
  9693. inline bool Server::read_content_with_content_receiver(
  9694. Stream &strm, Request &req, Response &res, ContentReceiver receiver,
  9695. FormDataHeader multipart_header, ContentReceiver multipart_receiver) {
  9696. return read_content_core(strm, req, res, std::move(receiver),
  9697. std::move(multipart_header),
  9698. std::move(multipart_receiver));
  9699. }
  9700. inline bool Server::read_content_core(
  9701. Stream &strm, Request &req, Response &res, ContentReceiver receiver,
  9702. FormDataHeader multipart_header, ContentReceiver multipart_receiver) const {
  9703. detail::FormDataParser multipart_form_data_parser;
  9704. ContentReceiverWithProgress out;
  9705. if (req.is_multipart_form_data()) {
  9706. const auto &content_type = req.get_header_value("Content-Type");
  9707. std::string boundary;
  9708. if (!detail::parse_multipart_boundary(content_type, boundary)) {
  9709. res.status = StatusCode::BadRequest_400;
  9710. output_error_log(Error::MultipartParsing, &req);
  9711. return false;
  9712. }
  9713. multipart_form_data_parser.set_boundary(std::move(boundary));
  9714. out = [&](const char *buf, size_t n, size_t /*off*/, size_t /*len*/) {
  9715. return multipart_form_data_parser.parse(buf, n, multipart_header,
  9716. multipart_receiver);
  9717. };
  9718. } else {
  9719. out = [receiver](const char *buf, size_t n, size_t /*off*/,
  9720. size_t /*len*/) { return receiver(buf, n); };
  9721. }
  9722. // RFC 9112 §6: no Transfer-Encoding and no Content-Length means no body.
  9723. // For non-SSL builds we still scan non-persistent connections for stray
  9724. // body bytes so the payload limit is enforced (413). On keep-alive,
  9725. // pending bytes may be the next request (issue #2450), so skip.
  9726. #if !defined(CPPHTTPLIB_SSL_ENABLED)
  9727. if (!req.has_header("Content-Length") &&
  9728. !detail::is_chunked_transfer_encoding(req.headers)) {
  9729. if (!detail::is_connection_persistent(req) && payload_max_length_ > 0 &&
  9730. payload_max_length_ < (std::numeric_limits<size_t>::max)()) {
  9731. auto has_data = strm.is_readable();
  9732. if (!has_data) {
  9733. auto s = strm.socket();
  9734. if (s != INVALID_SOCKET) {
  9735. has_data = detail::select_read(s, 0, 0) > 0;
  9736. }
  9737. }
  9738. if (has_data) {
  9739. auto result =
  9740. detail::read_content_without_length(strm, payload_max_length_, out);
  9741. if (result == detail::ReadContentResult::PayloadTooLarge) {
  9742. res.status = StatusCode::PayloadTooLarge_413;
  9743. return false;
  9744. } else if (result != detail::ReadContentResult::Success) {
  9745. return false;
  9746. }
  9747. return true;
  9748. }
  9749. }
  9750. return true;
  9751. }
  9752. #else
  9753. if (!req.has_header("Content-Length") &&
  9754. !detail::is_chunked_transfer_encoding(req.headers)) {
  9755. return true;
  9756. }
  9757. #endif
  9758. if (!detail::read_content(strm, req, payload_max_length_, res.status, nullptr,
  9759. out, true)) {
  9760. return false;
  9761. }
  9762. req.body_consumed_ = true;
  9763. if (req.is_multipart_form_data()) {
  9764. if (!multipart_form_data_parser.is_valid()) {
  9765. res.status = StatusCode::BadRequest_400;
  9766. output_error_log(Error::MultipartParsing, &req);
  9767. return false;
  9768. }
  9769. }
  9770. return true;
  9771. }
  9772. inline bool Server::handle_file_request(Request &req, Response &res) {
  9773. for (const auto &entry : base_dirs_) {
  9774. // Prefix match
  9775. if (!req.path.compare(0, entry.mount_point.size(), entry.mount_point)) {
  9776. std::string sub_path = "/" + req.path.substr(entry.mount_point.size());
  9777. if (detail::is_valid_path(sub_path)) {
  9778. auto path = entry.base_dir + sub_path;
  9779. if (path.back() == '/') { path += "index.html"; }
  9780. // Defense-in-depth: is_valid_path blocks ".." traversal in the URL,
  9781. // but symlinks/junctions can still escape the base directory.
  9782. if (!entry.resolved_base_dir.empty()) {
  9783. std::string resolved_path;
  9784. if (detail::canonicalize_path(path.c_str(), resolved_path) &&
  9785. !detail::is_path_within_base(resolved_path,
  9786. entry.resolved_base_dir)) {
  9787. res.status = StatusCode::Forbidden_403;
  9788. return true;
  9789. }
  9790. }
  9791. detail::FileStat stat(path);
  9792. if (stat.is_dir()) {
  9793. res.set_redirect(sub_path + "/", StatusCode::MovedPermanently_301);
  9794. return true;
  9795. }
  9796. if (stat.is_file()) {
  9797. for (const auto &kv : entry.headers) {
  9798. res.set_header(kv.first, kv.second);
  9799. }
  9800. auto etag = detail::compute_etag(stat);
  9801. if (!etag.empty()) { res.set_header("ETag", etag); }
  9802. auto mtime = stat.mtime();
  9803. auto last_modified = detail::file_mtime_to_http_date(mtime);
  9804. if (!last_modified.empty()) {
  9805. res.set_header("Last-Modified", last_modified);
  9806. }
  9807. if (check_if_not_modified(req, res, etag, mtime)) { return true; }
  9808. check_if_range(req, etag, mtime);
  9809. auto mm = std::make_shared<detail::mmap>(path.c_str());
  9810. if (!mm->is_open()) {
  9811. output_error_log(Error::OpenFile, &req);
  9812. return false;
  9813. }
  9814. res.set_content_provider(
  9815. mm->size(),
  9816. detail::find_content_type(path, file_extension_and_mimetype_map_,
  9817. default_file_mimetype_),
  9818. [mm](size_t offset, size_t length, DataSink &sink) -> bool {
  9819. sink.write(mm->data() + offset, length);
  9820. return true;
  9821. });
  9822. if (req.method != "HEAD" && file_request_handler_) {
  9823. file_request_handler_(req, res);
  9824. }
  9825. return true;
  9826. } else {
  9827. output_error_log(Error::OpenFile, &req);
  9828. }
  9829. }
  9830. }
  9831. }
  9832. return false;
  9833. }
  9834. inline bool Server::check_if_not_modified(const Request &req, Response &res,
  9835. const std::string &etag,
  9836. time_t mtime) const {
  9837. // Handle conditional GET:
  9838. // 1. If-None-Match takes precedence (RFC 9110 Section 13.1.2)
  9839. // 2. If-Modified-Since is checked only when If-None-Match is absent
  9840. if (req.has_header("If-None-Match")) {
  9841. if (!etag.empty()) {
  9842. auto val = req.get_header_value("If-None-Match");
  9843. // NOTE: We use exact string matching here. This works correctly
  9844. // because our server always generates weak ETags (W/"..."), and
  9845. // clients typically send back the same ETag they received.
  9846. // RFC 9110 Section 8.8.3.2 allows weak comparison for
  9847. // If-None-Match, where W/"x" and "x" would match, but this
  9848. // simplified implementation requires exact matches.
  9849. auto ret = detail::split_find(val.data(), val.data() + val.size(), ',',
  9850. [&](const char *b, const char *e) {
  9851. auto seg_len = static_cast<size_t>(e - b);
  9852. return (seg_len == 1 && *b == '*') ||
  9853. (seg_len == etag.size() &&
  9854. std::equal(b, e, etag.begin()));
  9855. });
  9856. if (ret) {
  9857. res.status = StatusCode::NotModified_304;
  9858. return true;
  9859. }
  9860. }
  9861. } else if (req.has_header("If-Modified-Since")) {
  9862. auto val = req.get_header_value("If-Modified-Since");
  9863. auto t = detail::parse_http_date(val);
  9864. if (t != static_cast<time_t>(-1) && mtime <= t) {
  9865. res.status = StatusCode::NotModified_304;
  9866. return true;
  9867. }
  9868. }
  9869. return false;
  9870. }
  9871. inline bool Server::check_if_range(Request &req, const std::string &etag,
  9872. time_t mtime) const {
  9873. // Handle If-Range for partial content requests (RFC 9110
  9874. // Section 13.1.5). If-Range is only evaluated when Range header is
  9875. // present. If the validator matches, serve partial content; otherwise
  9876. // serve full content.
  9877. if (!req.ranges.empty() && req.has_header("If-Range")) {
  9878. auto val = req.get_header_value("If-Range");
  9879. auto is_valid_range = [&]() {
  9880. if (detail::is_strong_etag(val)) {
  9881. // RFC 9110 Section 13.1.5: If-Range requires strong ETag
  9882. // comparison.
  9883. return (!etag.empty() && val == etag);
  9884. } else if (detail::is_weak_etag(val)) {
  9885. // Weak ETags are not valid for If-Range (RFC 9110 Section 13.1.5)
  9886. return false;
  9887. } else {
  9888. // HTTP-date comparison
  9889. auto t = detail::parse_http_date(val);
  9890. return (t != static_cast<time_t>(-1) && mtime <= t);
  9891. }
  9892. };
  9893. if (!is_valid_range()) {
  9894. // Validator doesn't match: ignore Range and serve full content
  9895. req.ranges.clear();
  9896. return false;
  9897. }
  9898. }
  9899. return true;
  9900. }
  9901. inline socket_t
  9902. Server::create_server_socket(const std::string &host, int port,
  9903. int socket_flags,
  9904. SocketOptions socket_options) const {
  9905. return detail::create_socket(
  9906. host, std::string(), port, address_family_, socket_flags, tcp_nodelay_,
  9907. ipv6_v6only_, std::move(socket_options),
  9908. [&](socket_t sock, struct addrinfo &ai, bool & /*quit*/) -> bool {
  9909. if (::bind(sock, ai.ai_addr, static_cast<socklen_t>(ai.ai_addrlen))) {
  9910. output_error_log(Error::BindIPAddress, nullptr);
  9911. return false;
  9912. }
  9913. if (::listen(sock, CPPHTTPLIB_LISTEN_BACKLOG)) {
  9914. output_error_log(Error::Listen, nullptr);
  9915. return false;
  9916. }
  9917. return true;
  9918. });
  9919. }
  9920. inline int Server::bind_internal(const std::string &host, int port,
  9921. int socket_flags) {
  9922. if (is_decommissioned) { return -1; }
  9923. if (!is_valid()) { return -1; }
  9924. svr_sock_ = create_server_socket(host, port, socket_flags, socket_options_);
  9925. if (svr_sock_ == INVALID_SOCKET) { return -1; }
  9926. if (port == 0) {
  9927. struct sockaddr_storage addr;
  9928. socklen_t addr_len = sizeof(addr);
  9929. if (getsockname(svr_sock_, reinterpret_cast<struct sockaddr *>(&addr),
  9930. &addr_len) == -1) {
  9931. output_error_log(Error::GetSockName, nullptr);
  9932. return -1;
  9933. }
  9934. if (addr.ss_family == AF_INET) {
  9935. return ntohs(reinterpret_cast<struct sockaddr_in *>(&addr)->sin_port);
  9936. } else if (addr.ss_family == AF_INET6) {
  9937. return ntohs(reinterpret_cast<struct sockaddr_in6 *>(&addr)->sin6_port);
  9938. } else {
  9939. output_error_log(Error::UnsupportedAddressFamily, nullptr);
  9940. return -1;
  9941. }
  9942. } else {
  9943. return port;
  9944. }
  9945. }
  9946. inline bool Server::listen_internal() {
  9947. if (is_decommissioned) { return false; }
  9948. auto ret = true;
  9949. is_running_ = true;
  9950. auto se = detail::scope_exit([&]() { is_running_ = false; });
  9951. if (start_handler_) { start_handler_(); }
  9952. {
  9953. std::unique_ptr<TaskQueue> task_queue(new_task_queue());
  9954. while (svr_sock_ != INVALID_SOCKET) {
  9955. #ifndef _WIN32
  9956. if (idle_interval_sec_ > 0 || idle_interval_usec_ > 0) {
  9957. #endif
  9958. auto val = detail::select_read(svr_sock_, idle_interval_sec_,
  9959. idle_interval_usec_);
  9960. if (val == 0) { // Timeout
  9961. task_queue->on_idle();
  9962. continue;
  9963. }
  9964. #ifndef _WIN32
  9965. }
  9966. #endif
  9967. #if defined _WIN32
  9968. // sockets connected via WASAccept inherit flags NO_HANDLE_INHERIT,
  9969. // OVERLAPPED
  9970. socket_t sock = WSAAccept(svr_sock_, nullptr, nullptr, nullptr, 0);
  9971. #elif defined SOCK_CLOEXEC
  9972. socket_t sock = accept4(svr_sock_, nullptr, nullptr, SOCK_CLOEXEC);
  9973. #else
  9974. socket_t sock = accept(svr_sock_, nullptr, nullptr);
  9975. #endif
  9976. if (sock == INVALID_SOCKET) {
  9977. if (errno == EMFILE) {
  9978. // The per-process limit of open file descriptors has been reached.
  9979. // Try to accept new connections after a short sleep.
  9980. std::this_thread::sleep_for(std::chrono::microseconds{1});
  9981. continue;
  9982. } else if (errno == EINTR || errno == EAGAIN) {
  9983. continue;
  9984. }
  9985. if (svr_sock_ != INVALID_SOCKET) {
  9986. detail::close_socket(svr_sock_);
  9987. ret = false;
  9988. output_error_log(Error::Connection, nullptr);
  9989. } else {
  9990. ; // The server socket was closed by user.
  9991. }
  9992. break;
  9993. }
  9994. detail::set_socket_opt_time(sock, SOL_SOCKET, SO_RCVTIMEO,
  9995. read_timeout_sec_, read_timeout_usec_);
  9996. detail::set_socket_opt_time(sock, SOL_SOCKET, SO_SNDTIMEO,
  9997. write_timeout_sec_, write_timeout_usec_);
  9998. if (tcp_nodelay_) { set_socket_opt(sock, IPPROTO_TCP, TCP_NODELAY, 1); }
  9999. if (!task_queue->enqueue(
  10000. [this, sock]() { process_and_close_socket(sock); })) {
  10001. output_error_log(Error::ResourceExhaustion, nullptr);
  10002. detail::shutdown_socket(sock);
  10003. detail::close_socket(sock);
  10004. }
  10005. }
  10006. task_queue->shutdown();
  10007. }
  10008. is_decommissioned = !ret;
  10009. return ret;
  10010. }
  10011. inline bool Server::routing(Request &req, Response &res, Stream &strm) {
  10012. if (pre_routing_handler_ &&
  10013. pre_routing_handler_(req, res) == HandlerResponse::Handled) {
  10014. return true;
  10015. }
  10016. // File handler
  10017. if ((req.method == "GET" || req.method == "HEAD") &&
  10018. handle_file_request(req, res)) {
  10019. return true;
  10020. }
  10021. if (detail::expect_content(req)) {
  10022. // Content reader handler
  10023. {
  10024. // Track whether the ContentReader was aborted due to the decompressed
  10025. // payload exceeding `payload_max_length_`.
  10026. // The user handler runs after the lambda returns, so we must restore the
  10027. // 413 status if the handler overwrites it.
  10028. bool content_reader_payload_too_large = false;
  10029. ContentReader reader(
  10030. [&](ContentReceiver receiver) {
  10031. auto result = read_content_with_content_receiver(
  10032. strm, req, res, std::move(receiver), nullptr, nullptr);
  10033. if (!result) {
  10034. output_error_log(Error::Read, &req);
  10035. if (res.status == StatusCode::PayloadTooLarge_413) {
  10036. content_reader_payload_too_large = true;
  10037. }
  10038. }
  10039. return result;
  10040. },
  10041. [&](FormDataHeader header, ContentReceiver receiver) {
  10042. auto result = read_content_with_content_receiver(
  10043. strm, req, res, nullptr, std::move(header),
  10044. std::move(receiver));
  10045. if (!result) {
  10046. output_error_log(Error::Read, &req);
  10047. if (res.status == StatusCode::PayloadTooLarge_413) {
  10048. content_reader_payload_too_large = true;
  10049. }
  10050. }
  10051. return result;
  10052. });
  10053. bool dispatched = false;
  10054. if (req.method == "POST") {
  10055. dispatched = dispatch_request_for_content_reader(
  10056. req, res, std::move(reader), post_handlers_for_content_reader_);
  10057. } else if (req.method == "PUT") {
  10058. dispatched = dispatch_request_for_content_reader(
  10059. req, res, std::move(reader), put_handlers_for_content_reader_);
  10060. } else if (req.method == "PATCH") {
  10061. dispatched = dispatch_request_for_content_reader(
  10062. req, res, std::move(reader), patch_handlers_for_content_reader_);
  10063. } else if (req.method == "DELETE") {
  10064. dispatched = dispatch_request_for_content_reader(
  10065. req, res, std::move(reader), delete_handlers_for_content_reader_);
  10066. }
  10067. if (dispatched) {
  10068. if (content_reader_payload_too_large) {
  10069. // Enforce the limit: override any status the handler may have set
  10070. // and return false so the error path sends a plain 413 response.
  10071. res.status = StatusCode::PayloadTooLarge_413;
  10072. res.body.clear();
  10073. res.content_length_ = 0;
  10074. res.content_provider_ = nullptr;
  10075. return false;
  10076. }
  10077. return true;
  10078. }
  10079. }
  10080. // NOTE: `req.body` is not read here. For a regular handler the body is
  10081. // read inside dispatch_request(), after the route has matched and the
  10082. // pre-request handler has approved the request, so that a rejected
  10083. // request (e.g. failed authentication) never forces us to buffer a
  10084. // potentially large body.
  10085. }
  10086. // Regular handler
  10087. if (req.method == "GET" || req.method == "HEAD") {
  10088. return dispatch_request(req, res, get_handlers_, strm);
  10089. } else if (req.method == "POST") {
  10090. return dispatch_request(req, res, post_handlers_, strm);
  10091. } else if (req.method == "PUT") {
  10092. return dispatch_request(req, res, put_handlers_, strm);
  10093. } else if (req.method == "DELETE") {
  10094. return dispatch_request(req, res, delete_handlers_, strm);
  10095. } else if (req.method == "OPTIONS") {
  10096. return dispatch_request(req, res, options_handlers_, strm);
  10097. } else if (req.method == "PATCH") {
  10098. return dispatch_request(req, res, patch_handlers_, strm);
  10099. }
  10100. res.status = StatusCode::BadRequest_400;
  10101. return false;
  10102. }
  10103. inline bool Server::dispatch_request(Request &req, Response &res,
  10104. const Handlers &handlers, Stream &strm) {
  10105. for (const auto &x : handlers) {
  10106. const auto &matcher = x.first;
  10107. const auto &handler = x.second;
  10108. if (matcher->match(req)) {
  10109. req.matched_route = matcher->pattern();
  10110. // Run the pre-request handler before reading the body so a rejected
  10111. // request (e.g. failed authentication) never forces us to buffer a
  10112. // potentially large body. `req.matched_route` is available here.
  10113. if (pre_request_handler_ &&
  10114. pre_request_handler_(req, res) == HandlerResponse::Handled) {
  10115. return true;
  10116. }
  10117. // The route matched and the request was approved; read the body now.
  10118. if (detail::expect_content(req) && !read_content(strm, req, res)) {
  10119. output_error_log(Error::Read, &req);
  10120. return false;
  10121. }
  10122. handler(req, res);
  10123. return true;
  10124. }
  10125. }
  10126. return false;
  10127. }
  10128. inline void Server::apply_ranges(const Request &req, Response &res,
  10129. std::string &content_type,
  10130. std::string &boundary) const {
  10131. if (req.ranges.size() > 1 && res.status == StatusCode::PartialContent_206) {
  10132. auto it = res.headers.find("Content-Type");
  10133. if (it != res.headers.end()) {
  10134. content_type = it->second;
  10135. res.headers.erase(it);
  10136. }
  10137. boundary = detail::make_multipart_data_boundary();
  10138. res.set_header("Content-Type",
  10139. "multipart/byteranges; boundary=" + boundary);
  10140. }
  10141. auto type = detail::encoding_type(req, res);
  10142. if (res.body.empty()) {
  10143. if (res.content_length_ > 0) {
  10144. size_t length = 0;
  10145. if (req.ranges.empty() || res.status != StatusCode::PartialContent_206) {
  10146. length = res.content_length_;
  10147. } else if (req.ranges.size() == 1) {
  10148. auto offset_and_length = detail::get_range_offset_and_length(
  10149. req.ranges[0], res.content_length_);
  10150. length = offset_and_length.second;
  10151. auto content_range = detail::make_content_range_header_field(
  10152. offset_and_length, res.content_length_);
  10153. res.set_header("Content-Range", content_range);
  10154. } else {
  10155. length = detail::get_multipart_ranges_data_length(
  10156. req, boundary, content_type, res.content_length_);
  10157. }
  10158. res.set_header("Content-Length", std::to_string(length));
  10159. } else {
  10160. if (res.content_provider_) {
  10161. if (res.is_chunked_content_provider_) {
  10162. res.set_header("Transfer-Encoding", "chunked");
  10163. if (type != detail::EncodingType::None) {
  10164. res.set_header("Content-Encoding", detail::encoding_name(type));
  10165. res.set_header("Vary", "Accept-Encoding");
  10166. }
  10167. }
  10168. }
  10169. }
  10170. } else {
  10171. if (req.ranges.empty() || res.status != StatusCode::PartialContent_206) {
  10172. ;
  10173. } else if (req.ranges.size() == 1) {
  10174. auto offset_and_length =
  10175. detail::get_range_offset_and_length(req.ranges[0], res.body.size());
  10176. auto offset = offset_and_length.first;
  10177. auto length = offset_and_length.second;
  10178. auto content_range = detail::make_content_range_header_field(
  10179. offset_and_length, res.body.size());
  10180. res.set_header("Content-Range", content_range);
  10181. assert(offset + length <= res.body.size());
  10182. res.body = res.body.substr(offset, length);
  10183. } else {
  10184. std::string data;
  10185. detail::make_multipart_ranges_data(req, res, boundary, content_type,
  10186. res.body.size(), data);
  10187. res.body.swap(data);
  10188. }
  10189. if (type != detail::EncodingType::None) {
  10190. output_pre_compression_log(req, res);
  10191. if (auto compressor = detail::make_compressor(type)) {
  10192. std::string compressed;
  10193. if (compressor->compress(res.body.data(), res.body.size(), true,
  10194. [&](const char *data, size_t data_len) {
  10195. compressed.append(data, data_len);
  10196. return true;
  10197. })) {
  10198. res.body.swap(compressed);
  10199. res.set_header("Content-Encoding", detail::encoding_name(type));
  10200. res.set_header("Vary", "Accept-Encoding");
  10201. }
  10202. }
  10203. }
  10204. auto length = std::to_string(res.body.size());
  10205. res.set_header("Content-Length", length);
  10206. }
  10207. }
  10208. inline bool Server::dispatch_request_for_content_reader(
  10209. Request &req, Response &res, ContentReader content_reader,
  10210. const HandlersForContentReader &handlers) const {
  10211. for (const auto &x : handlers) {
  10212. const auto &matcher = x.first;
  10213. const auto &handler = x.second;
  10214. if (matcher->match(req)) {
  10215. req.matched_route = matcher->pattern();
  10216. if (!pre_request_handler_ ||
  10217. pre_request_handler_(req, res) != HandlerResponse::Handled) {
  10218. handler(req, res, content_reader);
  10219. }
  10220. return true;
  10221. }
  10222. }
  10223. return false;
  10224. }
  10225. inline std::string
  10226. get_client_ip(const std::string &x_forwarded_for,
  10227. const std::vector<std::string> &trusted_proxies) {
  10228. // X-Forwarded-For is a comma-separated list per RFC 7239
  10229. std::vector<std::string> ip_list;
  10230. detail::split(x_forwarded_for.data(),
  10231. x_forwarded_for.data() + x_forwarded_for.size(), ',',
  10232. [&](const char *b, const char *e) {
  10233. auto r = detail::trim(b, e, 0, static_cast<size_t>(e - b));
  10234. ip_list.emplace_back(std::string(b + r.first, b + r.second));
  10235. });
  10236. // A malformed X-Forwarded-For (empty, comma-only, whitespace-only) yields
  10237. // no segments. Signal "no client IP derived" with an empty string so the
  10238. // caller can fall back to the connection-level remote address.
  10239. if (ip_list.empty()) { return std::string(); }
  10240. for (size_t i = 0; i < ip_list.size(); ++i) {
  10241. auto ip = ip_list[i];
  10242. auto is_trusted_proxy =
  10243. std::any_of(trusted_proxies.begin(), trusted_proxies.end(),
  10244. [&](const std::string &proxy) { return ip == proxy; });
  10245. if (is_trusted_proxy) {
  10246. if (i == 0) {
  10247. // If the trusted proxy is the first IP, there's no preceding client IP
  10248. return ip;
  10249. } else {
  10250. // Return the IP immediately before the trusted proxy
  10251. return ip_list[i - 1];
  10252. }
  10253. }
  10254. }
  10255. // If no trusted proxy is found, return the first IP in the list
  10256. return ip_list.front();
  10257. }
  10258. inline bool
  10259. Server::process_request(Stream &strm, const std::string &remote_addr,
  10260. int remote_port, const std::string &local_addr,
  10261. int local_port, bool close_connection,
  10262. bool &connection_closed,
  10263. const std::function<void(Request &)> &setup_request,
  10264. bool *websocket_upgraded) {
  10265. std::array<char, 2048> buf{};
  10266. detail::stream_line_reader line_reader(strm, buf.data(), buf.size());
  10267. // Connection has been closed on client
  10268. if (!line_reader.getline()) { return false; }
  10269. Request req;
  10270. req.start_time_ = std::chrono::steady_clock::now();
  10271. req.remote_addr = remote_addr;
  10272. req.remote_port = remote_port;
  10273. req.local_addr = local_addr;
  10274. req.local_port = local_port;
  10275. Response res;
  10276. res.version = "HTTP/1.1";
  10277. res.headers = default_headers_;
  10278. // Request line and headers
  10279. if (!parse_request_line(line_reader.ptr(), req)) {
  10280. res.status = StatusCode::BadRequest_400;
  10281. output_error_log(Error::InvalidRequestLine, &req);
  10282. return write_response(strm, close_connection, req, res);
  10283. }
  10284. // Request headers
  10285. if (!detail::read_headers(strm, req.headers)) {
  10286. res.status = StatusCode::BadRequest_400;
  10287. output_error_log(Error::InvalidHeaders, &req);
  10288. return write_response(strm, close_connection, req, res);
  10289. }
  10290. // RFC 9112 §6.3: Reject requests with both a non-zero Content-Length and
  10291. // any Transfer-Encoding to prevent request smuggling. Content-Length: 0 is
  10292. // tolerated for compatibility with existing clients.
  10293. if (req.get_header_value_u64("Content-Length") > 0 &&
  10294. req.has_header("Transfer-Encoding")) {
  10295. connection_closed = true;
  10296. res.status = StatusCode::BadRequest_400;
  10297. return write_response(strm, close_connection, req, res);
  10298. }
  10299. // Check if the request URI doesn't exceed the limit
  10300. if (req.target.size() > CPPHTTPLIB_REQUEST_URI_MAX_LENGTH) {
  10301. connection_closed = true;
  10302. res.status = StatusCode::UriTooLong_414;
  10303. output_error_log(Error::ExceedUriMaxLength, &req);
  10304. return write_response(strm, close_connection, req, res);
  10305. }
  10306. if (req.get_header_value("Connection") == "close") {
  10307. connection_closed = true;
  10308. }
  10309. if (req.version == "HTTP/1.0" &&
  10310. req.get_header_value("Connection") != "Keep-Alive") {
  10311. connection_closed = true;
  10312. }
  10313. if (!trusted_proxies_.empty() && req.has_header("X-Forwarded-For")) {
  10314. auto x_forwarded_for = req.get_header_value("X-Forwarded-For");
  10315. auto derived = get_client_ip(x_forwarded_for, trusted_proxies_);
  10316. req.remote_addr = derived.empty() ? remote_addr : derived;
  10317. } else {
  10318. req.remote_addr = remote_addr;
  10319. }
  10320. req.remote_port = remote_port;
  10321. req.local_addr = local_addr;
  10322. req.local_port = local_port;
  10323. if (req.has_header("Accept")) {
  10324. const auto &accept_header = req.get_header_value("Accept");
  10325. if (!detail::parse_accept_header(accept_header, req.accept_content_types)) {
  10326. connection_closed = true;
  10327. res.status = StatusCode::BadRequest_400;
  10328. output_error_log(Error::HTTPParsing, &req);
  10329. return write_response(strm, close_connection, req, res);
  10330. }
  10331. }
  10332. if (req.has_header("Range")) {
  10333. const auto &range_header_value = req.get_header_value("Range");
  10334. if (!detail::parse_range_header(range_header_value, req.ranges)) {
  10335. connection_closed = true;
  10336. res.status = StatusCode::RangeNotSatisfiable_416;
  10337. output_error_log(Error::InvalidRangeHeader, &req);
  10338. return write_response(strm, close_connection, req, res);
  10339. }
  10340. }
  10341. if (setup_request) { setup_request(req); }
  10342. if (req.get_header_value("Expect") == "100-continue") {
  10343. int status = StatusCode::Continue_100;
  10344. if (expect_100_continue_handler_) {
  10345. status = expect_100_continue_handler_(req, res);
  10346. }
  10347. switch (status) {
  10348. case StatusCode::Continue_100:
  10349. case StatusCode::ExpectationFailed_417:
  10350. detail::write_response_line(strm, status);
  10351. strm.write("\r\n");
  10352. break;
  10353. default:
  10354. connection_closed = true;
  10355. return write_response(strm, true, req, res);
  10356. }
  10357. }
  10358. // Setup `is_connection_closed` method
  10359. auto sock = strm.socket();
  10360. req.is_connection_closed = [sock]() {
  10361. return !detail::is_socket_alive(sock);
  10362. };
  10363. // WebSocket upgrade
  10364. // Check pre_routing_handler_ before upgrading so that authentication
  10365. // and other middleware can reject the request with an HTTP response
  10366. // (e.g., 401) before the protocol switches.
  10367. if (detail::is_websocket_upgrade(req)) {
  10368. if (pre_routing_handler_ &&
  10369. pre_routing_handler_(req, res) == HandlerResponse::Handled) {
  10370. if (res.status == -1) { res.status = StatusCode::OK_200; }
  10371. return write_response(strm, close_connection, req, res);
  10372. }
  10373. // Find matching WebSocket handler
  10374. for (const auto &entry : websocket_handlers_) {
  10375. if (entry.matcher->match(req)) {
  10376. // Compute accept key
  10377. auto client_key = req.get_header_value("Sec-WebSocket-Key");
  10378. auto accept_key = detail::websocket_accept_key(client_key);
  10379. // Negotiate subprotocol
  10380. std::string selected_subprotocol;
  10381. if (entry.sub_protocol_selector) {
  10382. auto protocol_header = req.get_header_value("Sec-WebSocket-Protocol");
  10383. if (!protocol_header.empty()) {
  10384. std::vector<std::string> protocols;
  10385. std::istringstream iss(protocol_header);
  10386. std::string token;
  10387. while (std::getline(iss, token, ',')) {
  10388. // Trim whitespace
  10389. auto start = token.find_first_not_of(' ');
  10390. auto end = token.find_last_not_of(' ');
  10391. if (start != std::string::npos) {
  10392. protocols.push_back(token.substr(start, end - start + 1));
  10393. }
  10394. }
  10395. selected_subprotocol = entry.sub_protocol_selector(protocols);
  10396. }
  10397. }
  10398. // Send 101 Switching Protocols
  10399. std::string handshake_response = "HTTP/1.1 101 Switching Protocols\r\n"
  10400. "Upgrade: websocket\r\n"
  10401. "Connection: Upgrade\r\n"
  10402. "Sec-WebSocket-Accept: " +
  10403. accept_key + "\r\n";
  10404. if (!selected_subprotocol.empty()) {
  10405. if (!detail::fields::is_field_value(selected_subprotocol)) {
  10406. return false;
  10407. }
  10408. handshake_response +=
  10409. "Sec-WebSocket-Protocol: " + selected_subprotocol + "\r\n";
  10410. }
  10411. handshake_response += "\r\n";
  10412. if (strm.write(handshake_response.data(), handshake_response.size()) <
  10413. 0) {
  10414. return false;
  10415. }
  10416. connection_closed = true;
  10417. if (websocket_upgraded) { *websocket_upgraded = true; }
  10418. {
  10419. // Use WebSocket-specific read timeout instead of HTTP timeout
  10420. strm.set_read_timeout(CPPHTTPLIB_WEBSOCKET_READ_TIMEOUT_SECOND, 0);
  10421. ws::WebSocket ws(strm, req, true, websocket_ping_interval_sec_,
  10422. websocket_max_missed_pongs_);
  10423. entry.handler(req, ws);
  10424. }
  10425. return true;
  10426. }
  10427. }
  10428. // No matching handler - fall through to 404
  10429. }
  10430. // Routing
  10431. auto routed = false;
  10432. #ifdef CPPHTTPLIB_NO_EXCEPTIONS
  10433. routed = routing(req, res, strm);
  10434. #else
  10435. try {
  10436. routed = routing(req, res, strm);
  10437. } catch (std::exception &) {
  10438. if (exception_handler_) {
  10439. auto ep = std::current_exception();
  10440. exception_handler_(req, res, ep);
  10441. routed = true;
  10442. } else {
  10443. res.status = StatusCode::InternalServerError_500;
  10444. }
  10445. } catch (...) {
  10446. if (exception_handler_) {
  10447. auto ep = std::current_exception();
  10448. exception_handler_(req, res, ep);
  10449. routed = true;
  10450. } else {
  10451. res.status = StatusCode::InternalServerError_500;
  10452. }
  10453. }
  10454. #endif
  10455. auto ret = false;
  10456. if (routed) {
  10457. if (res.status == -1) {
  10458. res.status = req.ranges.empty() ? StatusCode::OK_200
  10459. : StatusCode::PartialContent_206;
  10460. }
  10461. // Serve file content by using a content provider
  10462. auto file_open_error = false;
  10463. if (!res.file_content_path_.empty()) {
  10464. const auto &path = res.file_content_path_;
  10465. auto mm = std::make_shared<detail::mmap>(path.c_str());
  10466. if (!mm->is_open()) {
  10467. res.body.clear();
  10468. res.content_length_ = 0;
  10469. res.content_provider_ = nullptr;
  10470. res.status = StatusCode::NotFound_404;
  10471. output_error_log(Error::OpenFile, &req);
  10472. file_open_error = true;
  10473. } else {
  10474. auto content_type = res.file_content_content_type_;
  10475. if (content_type.empty()) {
  10476. content_type = detail::find_content_type(
  10477. path, file_extension_and_mimetype_map_, default_file_mimetype_);
  10478. }
  10479. res.set_content_provider(
  10480. mm->size(), content_type,
  10481. [mm](size_t offset, size_t length, DataSink &sink) -> bool {
  10482. sink.write(mm->data() + offset, length);
  10483. return true;
  10484. });
  10485. }
  10486. }
  10487. if (file_open_error) {
  10488. ret = write_response(strm, close_connection, req, res);
  10489. } else if (detail::range_error(req, res)) {
  10490. res.body.clear();
  10491. res.content_length_ = 0;
  10492. res.content_provider_ = nullptr;
  10493. res.status = StatusCode::RangeNotSatisfiable_416;
  10494. ret = write_response(strm, close_connection, req, res);
  10495. } else {
  10496. ret = write_response_with_content(strm, close_connection, req, res);
  10497. }
  10498. } else {
  10499. if (res.status == -1) { res.status = StatusCode::NotFound_404; }
  10500. ret = write_response(strm, close_connection, req, res);
  10501. }
  10502. // Drain any unconsumed framed body to prevent request smuggling on
  10503. // keep-alive. Without framing there is no body to drain — reading would
  10504. // consume the next request (issue #2450).
  10505. if (!req.body_consumed_ && detail::has_framed_body(req)) {
  10506. int dummy_status;
  10507. if (!detail::read_content(
  10508. strm, req, payload_max_length_, dummy_status, nullptr,
  10509. [](const char *, size_t, size_t, size_t) { return true; }, false)) {
  10510. connection_closed = true;
  10511. }
  10512. }
  10513. return ret;
  10514. }
  10515. inline bool Server::is_valid() const { return true; }
  10516. inline bool Server::process_and_close_socket(socket_t sock) {
  10517. std::string remote_addr;
  10518. int remote_port = 0;
  10519. detail::get_remote_ip_and_port(sock, remote_addr, remote_port);
  10520. std::string local_addr;
  10521. int local_port = 0;
  10522. detail::get_local_ip_and_port(sock, local_addr, local_port);
  10523. bool websocket_upgraded = false;
  10524. auto ret = detail::process_server_socket(
  10525. svr_sock_, sock, keep_alive_max_count_, keep_alive_timeout_sec_,
  10526. read_timeout_sec_, read_timeout_usec_, write_timeout_sec_,
  10527. write_timeout_usec_,
  10528. [&](Stream &strm, bool close_connection, bool &connection_closed) {
  10529. return process_request(strm, remote_addr, remote_port, local_addr,
  10530. local_port, close_connection, connection_closed,
  10531. nullptr, &websocket_upgraded);
  10532. });
  10533. detail::shutdown_socket(sock);
  10534. detail::close_socket(sock);
  10535. return ret;
  10536. }
  10537. inline void Server::output_log(const Request &req, const Response &res) const {
  10538. if (logger_) {
  10539. std::lock_guard<std::mutex> guard(logger_mutex_);
  10540. logger_(req, res);
  10541. }
  10542. }
  10543. inline void Server::output_pre_compression_log(const Request &req,
  10544. const Response &res) const {
  10545. if (pre_compression_logger_) {
  10546. std::lock_guard<std::mutex> guard(logger_mutex_);
  10547. pre_compression_logger_(req, res);
  10548. }
  10549. }
  10550. inline void Server::output_error_log(const Error &err,
  10551. const Request *req) const {
  10552. if (error_logger_) {
  10553. std::lock_guard<std::mutex> guard(logger_mutex_);
  10554. error_logger_(err, req);
  10555. }
  10556. }
  10557. /*
  10558. * Group 5: ClientImpl and Client (Universal) implementation
  10559. */
  10560. // HTTP client implementation
  10561. inline ClientImpl::ClientImpl(const std::string &host)
  10562. : ClientImpl(host, 80, std::string(), std::string()) {}
  10563. inline ClientImpl::ClientImpl(const std::string &host, int port)
  10564. : ClientImpl(host, port, std::string(), std::string()) {}
  10565. inline ClientImpl::ClientImpl(const std::string &host, int port,
  10566. const std::string &client_cert_path,
  10567. const std::string &client_key_path)
  10568. : host_(detail::escape_abstract_namespace_unix_domain(host)), port_(port),
  10569. client_cert_path_(client_cert_path), client_key_path_(client_key_path) {}
  10570. inline ClientImpl::~ClientImpl() {
  10571. // Wait until all the requests in flight are handled.
  10572. size_t retry_count = 10;
  10573. while (retry_count-- > 0) {
  10574. {
  10575. std::lock_guard<std::mutex> guard(socket_mutex_);
  10576. if (socket_requests_in_flight_ == 0) { break; }
  10577. }
  10578. std::this_thread::sleep_for(std::chrono::milliseconds{1});
  10579. }
  10580. std::lock_guard<std::mutex> guard(socket_mutex_);
  10581. shutdown_socket(socket_);
  10582. close_socket(socket_);
  10583. }
  10584. inline bool ClientImpl::is_valid() const { return true; }
  10585. inline void ClientImpl::copy_settings(const ClientImpl &rhs) {
  10586. client_cert_path_ = rhs.client_cert_path_;
  10587. client_key_path_ = rhs.client_key_path_;
  10588. connection_timeout_sec_ = rhs.connection_timeout_sec_;
  10589. read_timeout_sec_ = rhs.read_timeout_sec_;
  10590. read_timeout_usec_ = rhs.read_timeout_usec_;
  10591. write_timeout_sec_ = rhs.write_timeout_sec_;
  10592. write_timeout_usec_ = rhs.write_timeout_usec_;
  10593. max_timeout_msec_ = rhs.max_timeout_msec_;
  10594. basic_auth_username_ = rhs.basic_auth_username_;
  10595. basic_auth_password_ = rhs.basic_auth_password_;
  10596. bearer_token_auth_token_ = rhs.bearer_token_auth_token_;
  10597. keep_alive_ = rhs.keep_alive_;
  10598. follow_location_ = rhs.follow_location_;
  10599. path_encode_ = rhs.path_encode_;
  10600. address_family_ = rhs.address_family_;
  10601. tcp_nodelay_ = rhs.tcp_nodelay_;
  10602. ipv6_v6only_ = rhs.ipv6_v6only_;
  10603. socket_options_ = rhs.socket_options_;
  10604. compress_ = rhs.compress_;
  10605. decompress_ = rhs.decompress_;
  10606. payload_max_length_ = rhs.payload_max_length_;
  10607. has_payload_max_length_ = rhs.has_payload_max_length_;
  10608. interface_ = rhs.interface_;
  10609. proxy_host_ = rhs.proxy_host_;
  10610. proxy_port_ = rhs.proxy_port_;
  10611. proxy_basic_auth_username_ = rhs.proxy_basic_auth_username_;
  10612. proxy_basic_auth_password_ = rhs.proxy_basic_auth_password_;
  10613. proxy_bearer_token_auth_token_ = rhs.proxy_bearer_token_auth_token_;
  10614. no_proxy_entries_ = rhs.no_proxy_entries_;
  10615. logger_ = rhs.logger_;
  10616. error_logger_ = rhs.error_logger_;
  10617. #ifdef CPPHTTPLIB_SSL_ENABLED
  10618. digest_auth_username_ = rhs.digest_auth_username_;
  10619. digest_auth_password_ = rhs.digest_auth_password_;
  10620. proxy_digest_auth_username_ = rhs.proxy_digest_auth_username_;
  10621. proxy_digest_auth_password_ = rhs.proxy_digest_auth_password_;
  10622. ca_cert_file_path_ = rhs.ca_cert_file_path_;
  10623. ca_cert_dir_path_ = rhs.ca_cert_dir_path_;
  10624. server_certificate_verification_ = rhs.server_certificate_verification_;
  10625. server_hostname_verification_ = rhs.server_hostname_verification_;
  10626. system_ca_mode_ = rhs.system_ca_mode_;
  10627. #endif
  10628. }
  10629. inline bool
  10630. ClientImpl::is_proxy_enabled_for_host(const std::string &host) const {
  10631. if (proxy_host_.empty() || proxy_port_ == -1) { return false; }
  10632. if (no_proxy_entries_.empty()) { return true; }
  10633. // host_ is const so its normalized form is invariant; cache it. The
  10634. // cross-host path (setup_redirect_client passing next_host) re-normalizes.
  10635. if (host == host_) {
  10636. if (!host_normalized_valid_) {
  10637. host_normalized_ = detail::normalize_target(host_);
  10638. host_normalized_valid_ = true;
  10639. }
  10640. return !detail::host_matches_no_proxy(host_normalized_, no_proxy_entries_);
  10641. }
  10642. auto target = detail::normalize_target(host);
  10643. return !detail::host_matches_no_proxy(target, no_proxy_entries_);
  10644. }
  10645. inline socket_t ClientImpl::create_client_socket(Error &error) const {
  10646. if (is_proxy_enabled_for_host(host_)) {
  10647. return detail::create_client_socket(
  10648. proxy_host_, std::string(), proxy_port_, address_family_, tcp_nodelay_,
  10649. ipv6_v6only_, socket_options_, connection_timeout_sec_,
  10650. connection_timeout_usec_, read_timeout_sec_, read_timeout_usec_,
  10651. write_timeout_sec_, write_timeout_usec_, interface_, error);
  10652. }
  10653. // Check is custom IP specified for host_
  10654. std::string ip;
  10655. auto it = addr_map_.find(host_);
  10656. if (it != addr_map_.end()) { ip = it->second; }
  10657. return detail::create_client_socket(
  10658. host_, ip, port_, address_family_, tcp_nodelay_, ipv6_v6only_,
  10659. socket_options_, connection_timeout_sec_, connection_timeout_usec_,
  10660. read_timeout_sec_, read_timeout_usec_, write_timeout_sec_,
  10661. write_timeout_usec_, interface_, error);
  10662. }
  10663. inline bool ClientImpl::create_and_connect_socket(Socket &socket,
  10664. Error &error) {
  10665. auto sock = create_client_socket(error);
  10666. if (sock == INVALID_SOCKET) { return false; }
  10667. socket.sock = sock;
  10668. return true;
  10669. }
  10670. inline bool ClientImpl::ensure_socket_connection(Socket &socket, Error &error) {
  10671. return create_and_connect_socket(socket, error);
  10672. }
  10673. inline bool ClientImpl::setup_proxy_connection(
  10674. Socket & /*socket*/,
  10675. std::chrono::time_point<std::chrono::steady_clock> /*start_time*/,
  10676. Response & /*res*/, bool & /*success*/, Error & /*error*/) {
  10677. return true;
  10678. }
  10679. inline void ClientImpl::shutdown_ssl(Socket & /*socket*/,
  10680. bool /*shutdown_gracefully*/) {
  10681. // If there are any requests in flight from threads other than us, then it's
  10682. // a thread-unsafe race because individual ssl* objects are not thread-safe.
  10683. assert(socket_requests_in_flight_ == 0 ||
  10684. socket_requests_are_from_thread_ == std::this_thread::get_id());
  10685. }
  10686. inline void ClientImpl::shutdown_socket(Socket &socket) const {
  10687. if (socket.sock == INVALID_SOCKET) { return; }
  10688. detail::shutdown_socket(socket.sock);
  10689. }
  10690. inline void ClientImpl::close_socket(Socket &socket) {
  10691. // If there are requests in flight in another thread, usually closing
  10692. // the socket will be fine and they will simply receive an error when
  10693. // using the closed socket, but it is still a bug since rarely the OS
  10694. // may reassign the socket id to be used for a new socket, and then
  10695. // suddenly they will be operating on a live socket that is different
  10696. // than the one they intended!
  10697. assert(socket_requests_in_flight_ == 0 ||
  10698. socket_requests_are_from_thread_ == std::this_thread::get_id());
  10699. // It is also a bug if this happens while SSL is still active
  10700. #ifdef CPPHTTPLIB_SSL_ENABLED
  10701. assert(socket.ssl == nullptr);
  10702. #endif
  10703. if (socket.sock == INVALID_SOCKET) { return; }
  10704. detail::close_socket(socket.sock);
  10705. socket.sock = INVALID_SOCKET;
  10706. }
  10707. inline void ClientImpl::disconnect(bool gracefully) {
  10708. shutdown_ssl(socket_, gracefully);
  10709. shutdown_socket(socket_);
  10710. close_socket(socket_);
  10711. }
  10712. inline bool ClientImpl::read_response_line(Stream &strm, const Request &req,
  10713. Response &res,
  10714. bool skip_100_continue) const {
  10715. std::array<char, 2048> buf{};
  10716. detail::stream_line_reader line_reader(strm, buf.data(), buf.size());
  10717. if (!line_reader.getline()) { return false; }
  10718. #ifdef CPPHTTPLIB_ALLOW_LF_AS_LINE_TERMINATOR
  10719. thread_local const std::regex re("(HTTP/1\\.[01]) (\\d{3})(?: (.*?))?\r?\n");
  10720. #else
  10721. thread_local const std::regex re("(HTTP/1\\.[01]) (\\d{3})(?: (.*?))?\r\n");
  10722. #endif
  10723. std::cmatch m;
  10724. if (!std::regex_match(line_reader.ptr(), m, re)) {
  10725. return req.method == "CONNECT";
  10726. }
  10727. res.version = std::string(m[1]);
  10728. res.status = std::stoi(std::string(m[2]));
  10729. res.reason = std::string(m[3]);
  10730. // Ignore '100 Continue' (only when not using Expect: 100-continue explicitly)
  10731. while (skip_100_continue && res.status == StatusCode::Continue_100) {
  10732. if (!line_reader.getline()) { return false; } // CRLF
  10733. if (!line_reader.getline()) { return false; } // next response line
  10734. if (!std::regex_match(line_reader.ptr(), m, re)) { return false; }
  10735. res.version = std::string(m[1]);
  10736. res.status = std::stoi(std::string(m[2]));
  10737. res.reason = std::string(m[3]);
  10738. }
  10739. return true;
  10740. }
  10741. inline bool ClientImpl::send(Request &req, Response &res, Error &error) {
  10742. std::lock_guard<std::recursive_mutex> request_mutex_guard(request_mutex_);
  10743. auto ret = send_(req, res, error);
  10744. if (error == Error::SSLPeerCouldBeClosed_) {
  10745. assert(!ret);
  10746. ret = send_(req, res, error);
  10747. // If still failing with SSLPeerCouldBeClosed_, convert to Read error
  10748. if (error == Error::SSLPeerCouldBeClosed_) { error = Error::Read; }
  10749. }
  10750. return ret;
  10751. }
  10752. inline bool ClientImpl::send_(Request &req, Response &res, Error &error) {
  10753. {
  10754. std::lock_guard<std::mutex> guard(socket_mutex_);
  10755. // Set this to false immediately - if it ever gets set to true by the end
  10756. // of the request, we know another thread instructed us to close the
  10757. // socket.
  10758. socket_should_be_closed_when_request_is_done_ = false;
  10759. auto is_alive = false;
  10760. if (socket_.is_open()) {
  10761. is_alive = detail::is_socket_alive(socket_.sock);
  10762. #ifdef CPPHTTPLIB_SSL_ENABLED
  10763. if (is_alive && is_ssl()) {
  10764. if (tls::is_peer_closed(socket_.ssl, socket_.sock)) {
  10765. is_alive = false;
  10766. }
  10767. }
  10768. #endif
  10769. if (!is_alive) {
  10770. // Peer seems gone — non-graceful shutdown to avoid SIGPIPE.
  10771. disconnect(/*gracefully=*/false);
  10772. }
  10773. }
  10774. if (!is_alive) {
  10775. if (!ensure_socket_connection(socket_, error)) {
  10776. output_error_log(error, &req);
  10777. return false;
  10778. }
  10779. {
  10780. auto success = true;
  10781. if (!setup_proxy_connection(socket_, req.start_time_, res, success,
  10782. error)) {
  10783. if (!success) { output_error_log(error, &req); }
  10784. return success;
  10785. }
  10786. }
  10787. }
  10788. // Mark the current socket as being in use so that it cannot be closed by
  10789. // anyone else while this request is ongoing, even though we will be
  10790. // releasing the mutex.
  10791. if (socket_requests_in_flight_ > 1) {
  10792. assert(socket_requests_are_from_thread_ == std::this_thread::get_id());
  10793. }
  10794. socket_requests_in_flight_ += 1;
  10795. socket_requests_are_from_thread_ = std::this_thread::get_id();
  10796. }
  10797. for (const auto &header : default_headers_) {
  10798. if (req.headers.find(header.first) == req.headers.end()) {
  10799. req.headers.insert(header);
  10800. }
  10801. }
  10802. auto ret = false;
  10803. auto close_connection = !keep_alive_;
  10804. auto se = detail::scope_exit([&]() {
  10805. // Briefly lock mutex in order to mark that a request is no longer ongoing
  10806. std::lock_guard<std::mutex> guard(socket_mutex_);
  10807. socket_requests_in_flight_ -= 1;
  10808. if (socket_requests_in_flight_ <= 0) {
  10809. assert(socket_requests_in_flight_ == 0);
  10810. socket_requests_are_from_thread_ = std::thread::id();
  10811. }
  10812. if (socket_should_be_closed_when_request_is_done_ || close_connection ||
  10813. !ret) {
  10814. disconnect(/*gracefully=*/true);
  10815. }
  10816. });
  10817. ret = process_socket(socket_, req.start_time_, [&](Stream &strm) {
  10818. return handle_request(strm, req, res, close_connection, error);
  10819. });
  10820. if (!ret) {
  10821. if (error == Error::Success) {
  10822. error = Error::Unknown;
  10823. output_error_log(error, &req);
  10824. }
  10825. }
  10826. return ret;
  10827. }
  10828. inline Result ClientImpl::send(const Request &req) {
  10829. auto req2 = req;
  10830. return send_(std::move(req2));
  10831. }
  10832. inline Result ClientImpl::send_(Request &&req) {
  10833. auto res = detail::make_unique<Response>();
  10834. auto error = Error::Success;
  10835. auto ret = send(req, *res, error);
  10836. #ifdef CPPHTTPLIB_SSL_ENABLED
  10837. return Result{ret ? std::move(res) : nullptr, error, std::move(req.headers),
  10838. last_ssl_error_, last_backend_error_};
  10839. #else
  10840. return Result{ret ? std::move(res) : nullptr, error, std::move(req.headers)};
  10841. #endif
  10842. }
  10843. inline void ClientImpl::prepare_default_headers(Request &r, bool for_stream,
  10844. const std::string &ct) {
  10845. (void)for_stream;
  10846. for (const auto &header : default_headers_) {
  10847. if (!r.has_header(header.first)) { r.headers.insert(header); }
  10848. }
  10849. if (!r.has_header("Host")) {
  10850. if (address_family_ == AF_UNIX) {
  10851. r.headers.emplace("Host", "localhost");
  10852. } else {
  10853. r.headers.emplace(
  10854. "Host", detail::make_host_and_port_string(host_, port_, is_ssl()));
  10855. }
  10856. }
  10857. if (!r.has_header("Accept")) { r.headers.emplace("Accept", "*/*"); }
  10858. if (!r.content_receiver) {
  10859. if (!r.has_header("Accept-Encoding")) {
  10860. std::string accept_encoding;
  10861. #ifdef CPPHTTPLIB_BROTLI_SUPPORT
  10862. accept_encoding = "br";
  10863. #endif
  10864. #ifdef CPPHTTPLIB_ZLIB_SUPPORT
  10865. if (!accept_encoding.empty()) { accept_encoding += ", "; }
  10866. accept_encoding += "gzip, deflate";
  10867. #endif
  10868. #ifdef CPPHTTPLIB_ZSTD_SUPPORT
  10869. if (!accept_encoding.empty()) { accept_encoding += ", "; }
  10870. accept_encoding += "zstd";
  10871. #endif
  10872. r.set_header("Accept-Encoding", accept_encoding);
  10873. }
  10874. #ifndef CPPHTTPLIB_NO_DEFAULT_USER_AGENT
  10875. if (!r.has_header("User-Agent")) {
  10876. auto agent = std::string("cpp-httplib/") + CPPHTTPLIB_VERSION;
  10877. r.set_header("User-Agent", agent);
  10878. }
  10879. #endif
  10880. }
  10881. if (!r.body.empty()) {
  10882. if (!ct.empty() && !r.has_header("Content-Type")) {
  10883. r.headers.emplace("Content-Type", ct);
  10884. }
  10885. if (!r.has_header("Content-Length")) {
  10886. r.headers.emplace("Content-Length", std::to_string(r.body.size()));
  10887. }
  10888. }
  10889. }
  10890. inline ClientImpl::StreamHandle
  10891. ClientImpl::open_stream(const std::string &method, const std::string &path,
  10892. const Params &params, const Headers &headers,
  10893. const std::string &body,
  10894. const std::string &content_type) {
  10895. StreamHandle handle;
  10896. handle.response = detail::make_unique<Response>();
  10897. handle.error = Error::Success;
  10898. auto query_path = params.empty() ? path : append_query_params(path, params);
  10899. handle.connection_ = detail::make_unique<ClientConnection>();
  10900. {
  10901. std::lock_guard<std::mutex> guard(socket_mutex_);
  10902. auto is_alive = false;
  10903. if (socket_.is_open()) {
  10904. is_alive = detail::is_socket_alive(socket_.sock);
  10905. #ifdef CPPHTTPLIB_SSL_ENABLED
  10906. if (is_alive && is_ssl()) {
  10907. if (tls::is_peer_closed(socket_.ssl, socket_.sock)) {
  10908. is_alive = false;
  10909. }
  10910. }
  10911. #endif
  10912. if (!is_alive) { disconnect(/*gracefully=*/false); }
  10913. }
  10914. if (!is_alive) {
  10915. if (!ensure_socket_connection(socket_, handle.error)) {
  10916. handle.response.reset();
  10917. return handle;
  10918. }
  10919. {
  10920. auto success = true;
  10921. auto start_time = std::chrono::steady_clock::now();
  10922. if (!setup_proxy_connection(socket_, start_time, *handle.response,
  10923. success, handle.error)) {
  10924. if (!success) { handle.response.reset(); }
  10925. return handle;
  10926. }
  10927. }
  10928. }
  10929. transfer_socket_ownership_to_handle(handle);
  10930. }
  10931. #ifdef CPPHTTPLIB_SSL_ENABLED
  10932. if (is_ssl() && handle.connection_->session) {
  10933. handle.socket_stream_ = detail::make_unique<detail::SSLSocketStream>(
  10934. handle.connection_->sock, handle.connection_->session,
  10935. read_timeout_sec_, read_timeout_usec_, write_timeout_sec_,
  10936. write_timeout_usec_);
  10937. } else {
  10938. handle.socket_stream_ = detail::make_unique<detail::SocketStream>(
  10939. handle.connection_->sock, read_timeout_sec_, read_timeout_usec_,
  10940. write_timeout_sec_, write_timeout_usec_);
  10941. }
  10942. #else
  10943. handle.socket_stream_ = detail::make_unique<detail::SocketStream>(
  10944. handle.connection_->sock, read_timeout_sec_, read_timeout_usec_,
  10945. write_timeout_sec_, write_timeout_usec_);
  10946. #endif
  10947. handle.stream_ = handle.socket_stream_.get();
  10948. Request req;
  10949. req.method = method;
  10950. req.path = query_path;
  10951. req.headers = headers;
  10952. req.body = body;
  10953. prepare_default_headers(req, true, content_type);
  10954. auto &strm = *handle.stream_;
  10955. if (detail::write_request_line(strm, req.method, req.path) < 0) {
  10956. handle.error = Error::Write;
  10957. handle.response.reset();
  10958. return handle;
  10959. }
  10960. if (!detail::check_and_write_headers(strm, req.headers, header_writer_,
  10961. handle.error)) {
  10962. handle.response.reset();
  10963. return handle;
  10964. }
  10965. if (!body.empty()) {
  10966. if (strm.write(body.data(), body.size()) < 0) {
  10967. handle.error = Error::Write;
  10968. handle.response.reset();
  10969. return handle;
  10970. }
  10971. }
  10972. if (!read_response_line(strm, req, *handle.response) ||
  10973. !detail::read_headers(strm, handle.response->headers)) {
  10974. handle.error = Error::Read;
  10975. handle.response.reset();
  10976. return handle;
  10977. }
  10978. handle.body_reader_.stream = handle.stream_;
  10979. handle.body_reader_.payload_max_length = payload_max_length_;
  10980. if (handle.response->has_header("Content-Length")) {
  10981. bool is_invalid = false;
  10982. auto content_length = detail::get_header_value_u64(
  10983. handle.response->headers, "Content-Length", 0, 0, is_invalid);
  10984. if (is_invalid) {
  10985. handle.error = Error::Read;
  10986. handle.response.reset();
  10987. return handle;
  10988. }
  10989. handle.body_reader_.has_content_length = true;
  10990. handle.body_reader_.content_length = content_length;
  10991. }
  10992. auto transfer_encoding =
  10993. handle.response->get_header_value("Transfer-Encoding");
  10994. handle.body_reader_.chunked = (transfer_encoding == "chunked");
  10995. auto content_encoding = handle.response->get_header_value("Content-Encoding");
  10996. if (!content_encoding.empty()) {
  10997. handle.decompressor_ = detail::create_decompressor(content_encoding);
  10998. }
  10999. return handle;
  11000. }
  11001. inline ssize_t ClientImpl::StreamHandle::read(char *buf, size_t len) {
  11002. if (!is_valid() || !response) { return -1; }
  11003. if (decompressor_) { return read_with_decompression(buf, len); }
  11004. auto n = detail::read_body_content(stream_, body_reader_, buf, len);
  11005. if (n <= 0 && body_reader_.chunked && !trailers_parsed_ && stream_) {
  11006. trailers_parsed_ = true;
  11007. if (body_reader_.chunked_decoder) {
  11008. if (!body_reader_.chunked_decoder->parse_trailers_into(
  11009. response->trailers, response->headers)) {
  11010. return n;
  11011. }
  11012. } else {
  11013. detail::ChunkedDecoder dec(*stream_);
  11014. if (!dec.parse_trailers_into(response->trailers, response->headers)) {
  11015. return n;
  11016. }
  11017. }
  11018. }
  11019. return n;
  11020. }
  11021. inline ssize_t ClientImpl::StreamHandle::read_with_decompression(char *buf,
  11022. size_t len) {
  11023. if (decompress_offset_ < decompress_buffer_.size()) {
  11024. auto available = decompress_buffer_.size() - decompress_offset_;
  11025. auto to_copy = (std::min)(len, available);
  11026. std::memcpy(buf, decompress_buffer_.data() + decompress_offset_, to_copy);
  11027. decompress_offset_ += to_copy;
  11028. decompressed_bytes_read_ += to_copy;
  11029. return static_cast<ssize_t>(to_copy);
  11030. }
  11031. decompress_buffer_.clear();
  11032. decompress_offset_ = 0;
  11033. constexpr size_t kDecompressionBufferSize = 8192;
  11034. char compressed_buf[kDecompressionBufferSize];
  11035. while (true) {
  11036. auto n = detail::read_body_content(stream_, body_reader_, compressed_buf,
  11037. sizeof(compressed_buf));
  11038. if (n <= 0) { return n; }
  11039. bool decompress_ok = decompressor_->decompress(
  11040. compressed_buf, static_cast<size_t>(n),
  11041. [this](const char *data, size_t data_len) {
  11042. decompress_buffer_.append(data, data_len);
  11043. auto limit = body_reader_.payload_max_length;
  11044. if (decompressed_bytes_read_ + decompress_buffer_.size() > limit) {
  11045. return false;
  11046. }
  11047. return true;
  11048. });
  11049. if (!decompress_ok) {
  11050. body_reader_.last_error = Error::Read;
  11051. return -1;
  11052. }
  11053. if (!decompress_buffer_.empty()) { break; }
  11054. }
  11055. auto to_copy = (std::min)(len, decompress_buffer_.size());
  11056. std::memcpy(buf, decompress_buffer_.data(), to_copy);
  11057. decompress_offset_ = to_copy;
  11058. decompressed_bytes_read_ += to_copy;
  11059. return static_cast<ssize_t>(to_copy);
  11060. }
  11061. inline void ClientImpl::StreamHandle::parse_trailers_if_needed() {
  11062. if (!response || !stream_ || !body_reader_.chunked || trailers_parsed_) {
  11063. return;
  11064. }
  11065. trailers_parsed_ = true;
  11066. const auto bufsiz = 128;
  11067. char line_buf[bufsiz];
  11068. detail::stream_line_reader line_reader(*stream_, line_buf, bufsiz);
  11069. if (!line_reader.getline()) { return; }
  11070. if (!detail::parse_trailers(line_reader, response->trailers,
  11071. response->headers)) {
  11072. return;
  11073. }
  11074. }
  11075. namespace detail {
  11076. inline ChunkedDecoder::ChunkedDecoder(Stream &s) : strm(s) {}
  11077. inline ssize_t ChunkedDecoder::read_payload(char *buf, size_t len,
  11078. size_t &out_chunk_offset,
  11079. size_t &out_chunk_total) {
  11080. if (finished) { return 0; }
  11081. if (chunk_remaining == 0) {
  11082. stream_line_reader lr(strm, line_buf, sizeof(line_buf));
  11083. if (!lr.getline()) { return -1; }
  11084. // RFC 9112 §7.1: chunk-size = 1*HEXDIG
  11085. const char *p = lr.ptr();
  11086. int v = 0;
  11087. if (!is_hex(*p, v)) { return -1; }
  11088. size_t chunk_len = 0;
  11089. constexpr size_t chunk_len_max = (std::numeric_limits<size_t>::max)();
  11090. for (; is_hex(*p, v); ++p) {
  11091. if (chunk_len > (chunk_len_max >> 4)) { return -1; }
  11092. chunk_len = (chunk_len << 4) | static_cast<size_t>(v);
  11093. }
  11094. while (is_space_or_tab(*p)) {
  11095. ++p;
  11096. }
  11097. if (*p != '\0' && *p != ';' && *p != '\r' && *p != '\n') { return -1; }
  11098. if (chunk_len == 0) {
  11099. chunk_remaining = 0;
  11100. finished = true;
  11101. out_chunk_offset = 0;
  11102. out_chunk_total = 0;
  11103. return 0;
  11104. }
  11105. chunk_remaining = chunk_len;
  11106. last_chunk_total = chunk_remaining;
  11107. last_chunk_offset = 0;
  11108. }
  11109. auto to_read = (std::min)(chunk_remaining, len);
  11110. auto n = strm.read(buf, to_read);
  11111. if (n <= 0) { return -1; }
  11112. auto offset_before = last_chunk_offset;
  11113. last_chunk_offset += static_cast<size_t>(n);
  11114. chunk_remaining -= static_cast<size_t>(n);
  11115. out_chunk_offset = offset_before;
  11116. out_chunk_total = last_chunk_total;
  11117. if (chunk_remaining == 0) {
  11118. stream_line_reader lr(strm, line_buf, sizeof(line_buf));
  11119. if (!lr.getline()) { return -1; }
  11120. if (std::strcmp(lr.ptr(), "\r\n") != 0) { return -1; }
  11121. }
  11122. return n;
  11123. }
  11124. inline bool ChunkedDecoder::parse_trailers_into(Headers &dest,
  11125. const Headers &src_headers) {
  11126. stream_line_reader lr(strm, line_buf, sizeof(line_buf));
  11127. if (!lr.getline()) { return false; }
  11128. return parse_trailers(lr, dest, src_headers);
  11129. }
  11130. } // namespace detail
  11131. inline void
  11132. ClientImpl::transfer_socket_ownership_to_handle(StreamHandle &handle) {
  11133. handle.connection_->sock = socket_.sock;
  11134. #ifdef CPPHTTPLIB_SSL_ENABLED
  11135. handle.connection_->session = socket_.ssl;
  11136. socket_.ssl = nullptr;
  11137. #endif
  11138. socket_.sock = INVALID_SOCKET;
  11139. }
  11140. inline bool ClientImpl::handle_request(Stream &strm, Request &req,
  11141. Response &res, bool close_connection,
  11142. Error &error) {
  11143. if (req.path.empty()) {
  11144. error = Error::Connection;
  11145. output_error_log(error, &req);
  11146. return false;
  11147. }
  11148. auto req_save = req;
  11149. bool ret;
  11150. if (!is_ssl() && is_proxy_enabled_for_host(host_)) {
  11151. auto req2 = req;
  11152. req2.path = "http://" +
  11153. detail::make_host_and_port_string(host_, port_, false) +
  11154. req.path;
  11155. ret = process_request(strm, req2, res, close_connection, error);
  11156. req = std::move(req2);
  11157. req.path = req_save.path;
  11158. } else {
  11159. ret = process_request(strm, req, res, close_connection, error);
  11160. }
  11161. if (!ret) { return false; }
  11162. if (res.get_header_value("Connection") == "close" ||
  11163. (res.version == "HTTP/1.0" && res.reason != "Connection established")) {
  11164. // NOTE: this requires a not-entirely-obvious chain of calls to be correct
  11165. // for this to be safe.
  11166. // This is safe to call because handle_request is only called by send_
  11167. // which locks the request mutex during the process. It would be a bug
  11168. // to call it from a different thread since it's a thread-safety issue
  11169. // to do these things to the socket if another thread is using the socket.
  11170. std::lock_guard<std::mutex> guard(socket_mutex_);
  11171. disconnect(/*gracefully=*/true);
  11172. }
  11173. if (300 < res.status && res.status < 400 && follow_location_) {
  11174. req = std::move(req_save);
  11175. ret = redirect(req, res, error);
  11176. }
  11177. #ifdef CPPHTTPLIB_SSL_ENABLED
  11178. if ((res.status == StatusCode::Unauthorized_401 ||
  11179. res.status == StatusCode::ProxyAuthenticationRequired_407) &&
  11180. req.authorization_count_ < 5) {
  11181. auto is_proxy = res.status == StatusCode::ProxyAuthenticationRequired_407;
  11182. // Only retry when the 407 actually came from a proxy hop: plain HTTP
  11183. // through an enabled proxy. HTTPS via CONNECT tunnels the 407 from the
  11184. // origin (#2457); direct/bypassed origins have no proxy hop at all.
  11185. if (is_proxy && !(!is_ssl() && is_proxy_enabled_for_host(host_))) {
  11186. return ret;
  11187. }
  11188. const auto &username =
  11189. is_proxy ? proxy_digest_auth_username_ : digest_auth_username_;
  11190. const auto &password =
  11191. is_proxy ? proxy_digest_auth_password_ : digest_auth_password_;
  11192. if (!username.empty() && !password.empty()) {
  11193. std::map<std::string, std::string> auth;
  11194. if (detail::parse_www_authenticate(res, auth, is_proxy)) {
  11195. Request new_req = req;
  11196. new_req.authorization_count_ += 1;
  11197. new_req.headers.erase(is_proxy ? "Proxy-Authorization"
  11198. : "Authorization");
  11199. new_req.headers.insert(detail::make_digest_authentication_header(
  11200. req, auth, new_req.authorization_count_, detail::random_string(10),
  11201. username, password, is_proxy));
  11202. Response new_res;
  11203. ret = send(new_req, new_res, error);
  11204. if (ret) { res = std::move(new_res); }
  11205. }
  11206. }
  11207. }
  11208. #endif
  11209. return ret;
  11210. }
  11211. inline bool ClientImpl::redirect(Request &req, Response &res, Error &error) {
  11212. if (req.redirect_count_ == 0) {
  11213. error = Error::ExceedRedirectCount;
  11214. output_error_log(error, &req);
  11215. return false;
  11216. }
  11217. auto location = res.get_header_value("location");
  11218. if (location.empty()) { return false; }
  11219. detail::UrlComponents uc;
  11220. if (!detail::parse_url(location, uc)) { return false; }
  11221. // Only follow http/https redirects
  11222. if (!uc.scheme.empty() && uc.scheme != "http" && uc.scheme != "https") {
  11223. return false;
  11224. }
  11225. auto scheme = is_ssl() ? "https" : "http";
  11226. auto next_scheme = std::move(uc.scheme);
  11227. auto next_host = std::move(uc.host);
  11228. auto port_str = std::move(uc.port);
  11229. auto next_path = std::move(uc.path);
  11230. auto next_query = std::move(uc.query);
  11231. auto next_port = port_;
  11232. if (!port_str.empty()) {
  11233. if (!detail::parse_port(port_str, next_port)) { return false; }
  11234. } else if (!next_scheme.empty()) {
  11235. next_port = next_scheme == "https" ? 443 : 80;
  11236. }
  11237. if (next_scheme.empty()) { next_scheme = scheme; }
  11238. if (next_host.empty()) { next_host = host_; }
  11239. if (next_path.empty()) { next_path = "/"; }
  11240. auto path = decode_path_component(next_path) + next_query;
  11241. // Same host redirect - use current client
  11242. if (next_scheme == scheme && next_host == host_ && next_port == port_) {
  11243. return detail::redirect(*this, req, res, path, location, error);
  11244. }
  11245. // Cross-host/scheme redirect - create new client with robust setup
  11246. return create_redirect_client(next_scheme, next_host, next_port, req, res,
  11247. path, location, error);
  11248. }
  11249. // New method for robust redirect client creation
  11250. inline bool ClientImpl::create_redirect_client(
  11251. const std::string &scheme, const std::string &host, int port, Request &req,
  11252. Response &res, const std::string &path, const std::string &location,
  11253. Error &error) {
  11254. // Determine if we need SSL
  11255. auto need_ssl = (scheme == "https");
  11256. // Clean up request headers that are host/client specific
  11257. // Remove headers that should not be carried over to new host
  11258. auto headers_to_remove =
  11259. std::vector<std::string>{"Host", "Proxy-Authorization", "Authorization"};
  11260. for (const auto &header_name : headers_to_remove) {
  11261. auto it = req.headers.find(header_name);
  11262. while (it != req.headers.end()) {
  11263. it = req.headers.erase(it);
  11264. it = req.headers.find(header_name);
  11265. }
  11266. }
  11267. // Create appropriate client type and handle redirect
  11268. if (need_ssl) {
  11269. #ifdef CPPHTTPLIB_SSL_ENABLED
  11270. // Create SSL client for HTTPS redirect
  11271. SSLClient redirect_client(host, port);
  11272. // Setup basic client configuration first
  11273. setup_redirect_client(redirect_client);
  11274. redirect_client.enable_server_certificate_verification(
  11275. server_certificate_verification_);
  11276. redirect_client.enable_server_hostname_verification(
  11277. server_hostname_verification_);
  11278. redirect_client.system_ca_mode_ = system_ca_mode_;
  11279. // Transfer CA certificate to redirect client
  11280. if (!ca_cert_pem_.empty()) {
  11281. redirect_client.load_ca_cert_store(ca_cert_pem_.c_str(),
  11282. ca_cert_pem_.size());
  11283. }
  11284. if (!ca_cert_file_path_.empty()) {
  11285. redirect_client.set_ca_cert_path(ca_cert_file_path_, ca_cert_dir_path_);
  11286. }
  11287. // Client certificates are set through constructor for SSLClient
  11288. // NOTE: SSLClient constructor already takes client_cert_path and
  11289. // client_key_path so we need to create it properly if client certs are
  11290. // needed
  11291. // Execute the redirect
  11292. return detail::redirect(redirect_client, req, res, path, location, error);
  11293. #else
  11294. // SSL not supported - set appropriate error
  11295. error = Error::SSLConnection;
  11296. output_error_log(error, &req);
  11297. return false;
  11298. #endif
  11299. } else {
  11300. // HTTP redirect
  11301. ClientImpl redirect_client(host, port);
  11302. // Setup client with robust configuration
  11303. setup_redirect_client(redirect_client);
  11304. // Execute the redirect
  11305. return detail::redirect(redirect_client, req, res, path, location, error);
  11306. }
  11307. }
  11308. // New method for robust client setup (based on basic_manual_redirect.cpp
  11309. // logic)
  11310. template <typename ClientType>
  11311. inline void ClientImpl::setup_redirect_client(ClientType &client) {
  11312. // Copy basic settings first
  11313. client.set_connection_timeout(connection_timeout_sec_);
  11314. client.set_read_timeout(read_timeout_sec_, read_timeout_usec_);
  11315. client.set_write_timeout(write_timeout_sec_, write_timeout_usec_);
  11316. client.set_keep_alive(keep_alive_);
  11317. client.set_follow_location(
  11318. true); // Enable redirects to handle multi-step redirects
  11319. client.set_path_encode(path_encode_);
  11320. client.set_compress(compress_);
  11321. client.set_decompress(decompress_);
  11322. // NOTE: Authentication credentials (basic auth, bearer token, digest auth)
  11323. // are intentionally NOT copied to the redirect client. Per RFC 9110 Section
  11324. // 15.4, credentials must not be forwarded when redirecting to a different
  11325. // host. This function is only called for cross-host redirects; same-host
  11326. // redirects are handled directly in ClientImpl::redirect().
  11327. // Copy the proxy configuration unconditionally; the per-target bypass is
  11328. // re-evaluated at send time, so a later hop to a non-bypassed host can
  11329. // still use the proxy.
  11330. client.no_proxy_entries_ = no_proxy_entries_;
  11331. if (!proxy_host_.empty() && proxy_port_ != -1) {
  11332. client.set_proxy(proxy_host_, proxy_port_);
  11333. if (!proxy_basic_auth_username_.empty()) {
  11334. client.set_proxy_basic_auth(proxy_basic_auth_username_,
  11335. proxy_basic_auth_password_);
  11336. }
  11337. if (!proxy_bearer_token_auth_token_.empty()) {
  11338. client.set_proxy_bearer_token_auth(proxy_bearer_token_auth_token_);
  11339. }
  11340. #ifdef CPPHTTPLIB_SSL_ENABLED
  11341. if (!proxy_digest_auth_username_.empty()) {
  11342. client.set_proxy_digest_auth(proxy_digest_auth_username_,
  11343. proxy_digest_auth_password_);
  11344. }
  11345. #endif
  11346. }
  11347. // Copy network and socket settings
  11348. client.set_address_family(address_family_);
  11349. client.set_tcp_nodelay(tcp_nodelay_);
  11350. client.set_ipv6_v6only(ipv6_v6only_);
  11351. if (socket_options_) { client.set_socket_options(socket_options_); }
  11352. if (!interface_.empty()) { client.set_interface(interface_); }
  11353. // Copy logging and headers
  11354. if (logger_) { client.set_logger(logger_); }
  11355. if (error_logger_) { client.set_error_logger(error_logger_); }
  11356. // NOTE: DO NOT copy default_headers_ as they may contain stale Host headers
  11357. // Each new client should generate its own headers based on its target host
  11358. }
  11359. inline bool ClientImpl::write_content_with_provider(Stream &strm,
  11360. const Request &req,
  11361. Error &error) const {
  11362. auto is_shutting_down = []() { return false; };
  11363. if (req.is_chunked_content_provider_) {
  11364. auto compressor = compress_ ? detail::create_compressor().first
  11365. : std::unique_ptr<detail::compressor>();
  11366. if (!compressor) {
  11367. compressor = detail::make_unique<detail::nocompressor>();
  11368. }
  11369. return detail::write_content_chunked(strm, req.content_provider_,
  11370. is_shutting_down, *compressor, error);
  11371. } else {
  11372. return detail::write_content_with_progress(
  11373. strm, req.content_provider_, 0, req.content_length_, is_shutting_down,
  11374. req.upload_progress, error);
  11375. }
  11376. }
  11377. inline bool ClientImpl::write_request(Stream &strm, Request &req,
  11378. bool close_connection, Error &error,
  11379. bool skip_body) {
  11380. // Prepare additional headers
  11381. if (close_connection) {
  11382. if (!req.has_header("Connection")) {
  11383. req.set_header("Connection", "close");
  11384. }
  11385. }
  11386. std::string ct_for_defaults;
  11387. if (!req.has_header("Content-Type") && !req.body.empty()) {
  11388. ct_for_defaults = "text/plain";
  11389. }
  11390. prepare_default_headers(req, false, ct_for_defaults);
  11391. if (req.body.empty()) {
  11392. if (req.content_provider_) {
  11393. if (!req.is_chunked_content_provider_) {
  11394. if (!req.has_header("Content-Length")) {
  11395. auto length = std::to_string(req.content_length_);
  11396. req.set_header("Content-Length", length);
  11397. }
  11398. }
  11399. } else {
  11400. if (req.method == "POST" || req.method == "PUT" ||
  11401. req.method == "PATCH") {
  11402. req.set_header("Content-Length", "0");
  11403. }
  11404. }
  11405. }
  11406. if (!basic_auth_password_.empty() || !basic_auth_username_.empty()) {
  11407. if (!req.has_header("Authorization")) {
  11408. req.headers.insert(make_basic_authentication_header(
  11409. basic_auth_username_, basic_auth_password_, false));
  11410. }
  11411. }
  11412. if (!bearer_token_auth_token_.empty()) {
  11413. if (!req.has_header("Authorization")) {
  11414. req.headers.insert(make_bearer_token_authentication_header(
  11415. bearer_token_auth_token_, false));
  11416. }
  11417. }
  11418. // Proxy-Authorization is only sent when the proxy is actually used for
  11419. // this target — otherwise NO_PROXY-matched requests would leak proxy
  11420. // credentials directly to the destination server.
  11421. if (is_proxy_enabled_for_host(host_)) {
  11422. if (!proxy_basic_auth_username_.empty() &&
  11423. !proxy_basic_auth_password_.empty() &&
  11424. !req.has_header("Proxy-Authorization")) {
  11425. req.headers.insert(make_basic_authentication_header(
  11426. proxy_basic_auth_username_, proxy_basic_auth_password_, true));
  11427. }
  11428. if (!proxy_bearer_token_auth_token_.empty() &&
  11429. !req.has_header("Proxy-Authorization")) {
  11430. req.headers.insert(make_bearer_token_authentication_header(
  11431. proxy_bearer_token_auth_token_, true));
  11432. }
  11433. }
  11434. // Request line and headers
  11435. {
  11436. detail::BufferStream bstrm;
  11437. // Extract path and query from req.path
  11438. std::string path_part, query_part;
  11439. auto query_pos = req.path.find('?');
  11440. if (query_pos != std::string::npos) {
  11441. path_part = req.path.substr(0, query_pos);
  11442. query_part = req.path.substr(query_pos + 1);
  11443. } else {
  11444. path_part = req.path;
  11445. query_part = "";
  11446. }
  11447. // Encode path part. If the original `req.path` already contained a
  11448. // query component, preserve its raw query string (including parameter
  11449. // order) instead of reparsing and reassembling it which may reorder
  11450. // parameters due to container ordering (e.g. `Params` uses
  11451. // `std::multimap`). When there is no query in `req.path`, fall back to
  11452. // building a query from `req.params` so existing callers that pass
  11453. // `Params` continue to work.
  11454. auto path_with_query =
  11455. path_encode_ ? detail::encode_path(path_part) : path_part;
  11456. if (!query_part.empty()) {
  11457. // Normalize the query string (decode then re-encode) while preserving
  11458. // the original parameter order.
  11459. auto normalized = detail::normalize_query_string(query_part);
  11460. if (!normalized.empty()) { path_with_query += '?' + normalized; }
  11461. // Still populate req.params for handlers/users who read them.
  11462. detail::parse_query_text(query_part, req.params);
  11463. } else {
  11464. // No query in path; parse any query_part (empty) and append params
  11465. // from `req.params` when present (preserves prior behavior for
  11466. // callers who provide Params separately).
  11467. detail::parse_query_text(query_part, req.params);
  11468. if (!req.params.empty()) {
  11469. path_with_query = append_query_params(path_with_query, req.params);
  11470. }
  11471. }
  11472. // Write request line and headers
  11473. detail::write_request_line(bstrm, req.method, path_with_query);
  11474. if (!detail::check_and_write_headers(bstrm, req.headers, header_writer_,
  11475. error)) {
  11476. output_error_log(error, &req);
  11477. return false;
  11478. }
  11479. // Flush buffer
  11480. auto &data = bstrm.get_buffer();
  11481. if (!detail::write_data(strm, data.data(), data.size())) {
  11482. error = Error::Write;
  11483. output_error_log(error, &req);
  11484. return false;
  11485. }
  11486. }
  11487. // After sending request line and headers, wait briefly for an early server
  11488. // response (e.g. 4xx) and avoid sending a potentially large request body
  11489. // unnecessarily. This workaround is only enabled on Windows because Unix
  11490. // platforms surface write errors (EPIPE) earlier; on Windows kernel send
  11491. // buffering can accept large writes even when the peer already responded.
  11492. // Check the stream first (which covers SSL via `is_readable()`), then
  11493. // fall back to select on the socket. Only perform the wait for very large
  11494. // request bodies to avoid interfering with normal small requests and
  11495. // reduce side-effects. Poll briefly (up to 50ms as default) for an early
  11496. // response. Skip this check when using Expect: 100-continue, as the protocol
  11497. // handles early responses properly.
  11498. #if defined(_WIN32)
  11499. if (!skip_body &&
  11500. req.body.size() > CPPHTTPLIB_WAIT_EARLY_SERVER_RESPONSE_THRESHOLD &&
  11501. req.path.size() > CPPHTTPLIB_REQUEST_URI_MAX_LENGTH) {
  11502. auto start = std::chrono::high_resolution_clock::now();
  11503. for (;;) {
  11504. // Prefer socket-level readiness to avoid SSL_pending() false-positives
  11505. // from SSL internals. If the underlying socket is readable, assume an
  11506. // early response may be present.
  11507. auto sock = strm.socket();
  11508. if (sock != INVALID_SOCKET && detail::select_read(sock, 0, 0) > 0) {
  11509. return false;
  11510. }
  11511. // Fallback to stream-level check for non-socket streams or when the
  11512. // socket isn't reporting readable. Avoid using `is_readable()` for
  11513. // SSL, since `SSL_pending()` may report buffered records that do not
  11514. // indicate a complete application-level response yet.
  11515. if (!is_ssl() && strm.is_readable()) { return false; }
  11516. auto now = std::chrono::high_resolution_clock::now();
  11517. auto elapsed =
  11518. std::chrono::duration_cast<std::chrono::milliseconds>(now - start)
  11519. .count();
  11520. if (elapsed >= CPPHTTPLIB_WAIT_EARLY_SERVER_RESPONSE_TIMEOUT_MSECOND) {
  11521. break;
  11522. }
  11523. std::this_thread::sleep_for(std::chrono::milliseconds(1));
  11524. }
  11525. }
  11526. #endif
  11527. // Body
  11528. if (skip_body) { return true; }
  11529. return write_request_body(strm, req, error);
  11530. }
  11531. inline bool ClientImpl::write_request_body(Stream &strm, Request &req,
  11532. Error &error) {
  11533. if (req.body.empty()) {
  11534. return write_content_with_provider(strm, req, error);
  11535. }
  11536. if (req.upload_progress) {
  11537. auto body_size = req.body.size();
  11538. size_t written = 0;
  11539. auto data = req.body.data();
  11540. while (written < body_size) {
  11541. size_t to_write = (std::min)(CPPHTTPLIB_SEND_BUFSIZ, body_size - written);
  11542. if (!detail::write_data(strm, data + written, to_write)) {
  11543. error = Error::Write;
  11544. output_error_log(error, &req);
  11545. return false;
  11546. }
  11547. written += to_write;
  11548. if (!req.upload_progress(written, body_size)) {
  11549. error = Error::Canceled;
  11550. output_error_log(error, &req);
  11551. return false;
  11552. }
  11553. }
  11554. } else {
  11555. if (!detail::write_data(strm, req.body.data(), req.body.size())) {
  11556. error = Error::Write;
  11557. output_error_log(error, &req);
  11558. return false;
  11559. }
  11560. }
  11561. return true;
  11562. }
  11563. inline std::unique_ptr<Response>
  11564. ClientImpl::send_with_content_provider_and_receiver(
  11565. Request &req, const char *body, size_t content_length,
  11566. ContentProvider content_provider,
  11567. ContentProviderWithoutLength content_provider_without_length,
  11568. const std::string &content_type, ContentReceiver content_receiver,
  11569. Error &error) {
  11570. if (!content_type.empty()) { req.set_header("Content-Type", content_type); }
  11571. auto enc = compress_
  11572. ? detail::create_compressor()
  11573. : std::pair<std::unique_ptr<detail::compressor>, const char *>(
  11574. nullptr, nullptr);
  11575. if (enc.second) { req.set_header("Content-Encoding", enc.second); }
  11576. if (enc.first && !content_provider_without_length) {
  11577. auto &compressor = enc.first;
  11578. if (content_provider) {
  11579. auto ok = true;
  11580. size_t offset = 0;
  11581. DataSink data_sink;
  11582. data_sink.write = [&](const char *data, size_t data_len) -> bool {
  11583. if (ok) {
  11584. auto last = offset + data_len == content_length;
  11585. auto ret = compressor->compress(
  11586. data, data_len, last,
  11587. [&](const char *compressed_data, size_t compressed_data_len) {
  11588. req.body.append(compressed_data, compressed_data_len);
  11589. return true;
  11590. });
  11591. if (ret) {
  11592. offset += data_len;
  11593. } else {
  11594. ok = false;
  11595. }
  11596. }
  11597. return ok;
  11598. };
  11599. while (ok && offset < content_length) {
  11600. if (!content_provider(offset, content_length - offset, data_sink)) {
  11601. error = Error::Canceled;
  11602. output_error_log(error, &req);
  11603. return nullptr;
  11604. }
  11605. }
  11606. } else {
  11607. if (!compressor->compress(body, content_length, true,
  11608. [&](const char *data, size_t data_len) {
  11609. req.body.append(data, data_len);
  11610. return true;
  11611. })) {
  11612. error = Error::Compression;
  11613. output_error_log(error, &req);
  11614. return nullptr;
  11615. }
  11616. }
  11617. } else {
  11618. if (content_provider) {
  11619. req.content_length_ = content_length;
  11620. req.content_provider_ = std::move(content_provider);
  11621. req.is_chunked_content_provider_ = false;
  11622. } else if (content_provider_without_length) {
  11623. req.content_length_ = 0;
  11624. req.content_provider_ = detail::ContentProviderAdapter(
  11625. std::move(content_provider_without_length));
  11626. req.is_chunked_content_provider_ = true;
  11627. req.set_header("Transfer-Encoding", "chunked");
  11628. } else {
  11629. req.body.assign(body, content_length);
  11630. }
  11631. }
  11632. if (content_receiver) {
  11633. req.content_receiver =
  11634. [content_receiver](const char *data, size_t data_length,
  11635. size_t /*offset*/, size_t /*total_length*/) {
  11636. return content_receiver(data, data_length);
  11637. };
  11638. }
  11639. auto res = detail::make_unique<Response>();
  11640. return send(req, *res, error) ? std::move(res) : nullptr;
  11641. }
  11642. inline Result ClientImpl::send_with_content_provider_and_receiver(
  11643. const std::string &method, const std::string &path, const Headers &headers,
  11644. const char *body, size_t content_length, ContentProvider content_provider,
  11645. ContentProviderWithoutLength content_provider_without_length,
  11646. const std::string &content_type, ContentReceiver content_receiver,
  11647. UploadProgress progress) {
  11648. Request req;
  11649. req.method = method;
  11650. req.headers = headers;
  11651. req.path = path;
  11652. req.upload_progress = std::move(progress);
  11653. if (max_timeout_msec_ > 0) {
  11654. req.start_time_ = std::chrono::steady_clock::now();
  11655. }
  11656. auto error = Error::Success;
  11657. auto res = send_with_content_provider_and_receiver(
  11658. req, body, content_length, std::move(content_provider),
  11659. std::move(content_provider_without_length), content_type,
  11660. std::move(content_receiver), error);
  11661. #ifdef CPPHTTPLIB_SSL_ENABLED
  11662. return Result{std::move(res), error, std::move(req.headers), last_ssl_error_,
  11663. last_backend_error_};
  11664. #else
  11665. return Result{std::move(res), error, std::move(req.headers)};
  11666. #endif
  11667. }
  11668. inline void ClientImpl::output_log(const Request &req,
  11669. const Response &res) const {
  11670. if (logger_) {
  11671. std::lock_guard<std::mutex> guard(logger_mutex_);
  11672. logger_(req, res);
  11673. }
  11674. }
  11675. inline void ClientImpl::output_error_log(const Error &err,
  11676. const Request *req) const {
  11677. if (error_logger_) {
  11678. std::lock_guard<std::mutex> guard(logger_mutex_);
  11679. error_logger_(err, req);
  11680. }
  11681. }
  11682. inline bool ClientImpl::process_request(Stream &strm, Request &req,
  11683. Response &res, bool close_connection,
  11684. Error &error) {
  11685. // Auto-add Expect: 100-continue for large bodies
  11686. if (CPPHTTPLIB_EXPECT_100_THRESHOLD > 0 && !req.has_header("Expect")) {
  11687. auto body_size = req.body.empty() ? req.content_length_ : req.body.size();
  11688. if (body_size >= CPPHTTPLIB_EXPECT_100_THRESHOLD) {
  11689. req.set_header("Expect", "100-continue");
  11690. }
  11691. }
  11692. // Check for Expect: 100-continue
  11693. auto expect_100_continue = req.get_header_value("Expect") == "100-continue";
  11694. // Send request (skip body if using Expect: 100-continue)
  11695. auto write_request_success =
  11696. write_request(strm, req, close_connection, error, expect_100_continue);
  11697. #ifdef CPPHTTPLIB_SSL_ENABLED
  11698. if (is_ssl() && !expect_100_continue) {
  11699. auto is_proxy_enabled = is_proxy_enabled_for_host(host_);
  11700. if (!is_proxy_enabled) {
  11701. if (tls::is_peer_closed(socket_.ssl, socket_.sock)) {
  11702. error = Error::SSLPeerCouldBeClosed_;
  11703. output_error_log(error, &req);
  11704. return false;
  11705. }
  11706. }
  11707. }
  11708. #endif
  11709. // Handle Expect: 100-continue.
  11710. //
  11711. // Wait for an interim/early response by attempting to read the status line
  11712. // under a short timeout, instead of trusting raw socket readability. Over
  11713. // TLS, post-handshake records (e.g. session tickets) make the socket
  11714. // readable without any HTTP response being available; relying on
  11715. // `select_read` there caused the body to be withheld forever and the
  11716. // request to fail with `Read` (#2458). If no status line arrives within the
  11717. // timeout, send the body anyway (matching curl's behavior).
  11718. auto status_line_read = false;
  11719. if (expect_100_continue && write_request_success) {
  11720. if (CPPHTTPLIB_EXPECT_100_TIMEOUT_MSECOND > 0) {
  11721. time_t sec = CPPHTTPLIB_EXPECT_100_TIMEOUT_MSECOND / 1000;
  11722. time_t usec = (CPPHTTPLIB_EXPECT_100_TIMEOUT_MSECOND % 1000) * 1000;
  11723. strm.set_read_timeout(sec, usec);
  11724. status_line_read = read_response_line(strm, req, res, false);
  11725. strm.set_read_timeout(read_timeout_sec_, read_timeout_usec_);
  11726. }
  11727. if (!status_line_read) {
  11728. // No interim response within the timeout: send the body and handle the
  11729. // response as usual.
  11730. if (!write_request_body(strm, req, error)) { return false; }
  11731. expect_100_continue = false; // Switch to normal response handling
  11732. }
  11733. }
  11734. // Receive response and headers
  11735. // When using Expect: 100-continue, don't auto-skip `100 Continue` response
  11736. if ((!status_line_read &&
  11737. !read_response_line(strm, req, res, !expect_100_continue)) ||
  11738. !detail::read_headers(strm, res.headers)) {
  11739. if (write_request_success) { error = Error::Read; }
  11740. output_error_log(error, &req);
  11741. return false;
  11742. }
  11743. if (!write_request_success) { return false; }
  11744. // Handle Expect: 100-continue response
  11745. if (expect_100_continue) {
  11746. if (res.status == StatusCode::Continue_100) {
  11747. // Server accepted, send the body
  11748. if (!write_request_body(strm, req, error)) { return false; }
  11749. // Read the actual response
  11750. res.headers.clear();
  11751. res.body.clear();
  11752. if (!read_response_line(strm, req, res) ||
  11753. !detail::read_headers(strm, res.headers)) {
  11754. error = Error::Read;
  11755. output_error_log(error, &req);
  11756. return false;
  11757. }
  11758. }
  11759. // If not 100 Continue, server returned an error; proceed with that response
  11760. }
  11761. // Body
  11762. if ((res.status != StatusCode::NoContent_204) && req.method != "HEAD" &&
  11763. req.method != "CONNECT") {
  11764. auto redirect = 300 < res.status && res.status < 400 &&
  11765. res.status != StatusCode::NotModified_304 &&
  11766. follow_location_;
  11767. if (req.response_handler && !redirect) {
  11768. if (!req.response_handler(res)) {
  11769. error = Error::Canceled;
  11770. output_error_log(error, &req);
  11771. return false;
  11772. }
  11773. }
  11774. auto out =
  11775. req.content_receiver
  11776. ? static_cast<ContentReceiverWithProgress>(
  11777. [&](const char *buf, size_t n, size_t off, size_t len) {
  11778. if (redirect) { return true; }
  11779. auto ret = req.content_receiver(buf, n, off, len);
  11780. if (!ret) {
  11781. error = Error::Canceled;
  11782. output_error_log(error, &req);
  11783. }
  11784. return ret;
  11785. })
  11786. : static_cast<ContentReceiverWithProgress>(
  11787. [&](const char *buf, size_t n, size_t /*off*/,
  11788. size_t /*len*/) {
  11789. assert(res.body.size() + n <= res.body.max_size());
  11790. if (payload_max_length_ > 0 &&
  11791. (res.body.size() >= payload_max_length_ ||
  11792. n > payload_max_length_ - res.body.size())) {
  11793. return false;
  11794. }
  11795. res.body.append(buf, n);
  11796. return true;
  11797. });
  11798. auto progress = [&](size_t current, size_t total) {
  11799. if (!req.download_progress || redirect) { return true; }
  11800. auto ret = req.download_progress(current, total);
  11801. if (!ret) {
  11802. error = Error::Canceled;
  11803. output_error_log(error, &req);
  11804. }
  11805. return ret;
  11806. };
  11807. if (res.has_header("Content-Length")) {
  11808. if (!req.content_receiver) {
  11809. auto len = res.get_header_value_u64("Content-Length");
  11810. if (len > res.body.max_size()) {
  11811. error = Error::Read;
  11812. output_error_log(error, &req);
  11813. return false;
  11814. }
  11815. // Cap the reservation by payload_max_length_ to avoid OOM when a
  11816. // hostile or malformed server sends an enormous Content-Length.
  11817. // The actual body read below is bounded by payload_max_length_,
  11818. // so reserving more than that is never useful.
  11819. auto reserve_len = static_cast<size_t>(len);
  11820. if (payload_max_length_ > 0 && reserve_len > payload_max_length_) {
  11821. reserve_len = payload_max_length_;
  11822. }
  11823. res.body.reserve(reserve_len);
  11824. }
  11825. }
  11826. if (res.status != StatusCode::NotModified_304) {
  11827. int dummy_status;
  11828. auto max_length = (!has_payload_max_length_ && req.content_receiver)
  11829. ? (std::numeric_limits<size_t>::max)()
  11830. : payload_max_length_;
  11831. if (!detail::read_content(strm, res, max_length, dummy_status,
  11832. std::move(progress), std::move(out),
  11833. decompress_)) {
  11834. if (error != Error::Canceled) { error = Error::Read; }
  11835. output_error_log(error, &req);
  11836. return false;
  11837. }
  11838. }
  11839. }
  11840. // Log
  11841. output_log(req, res);
  11842. return true;
  11843. }
  11844. inline ContentProviderWithoutLength ClientImpl::get_multipart_content_provider(
  11845. const std::string &boundary, const UploadFormDataItems &items,
  11846. const FormDataProviderItems &provider_items) const {
  11847. size_t cur_item = 0;
  11848. size_t cur_start = 0;
  11849. // cur_item and cur_start are copied to within the std::function and
  11850. // maintain state between successive calls
  11851. return [&, cur_item, cur_start](size_t offset,
  11852. DataSink &sink) mutable -> bool {
  11853. if (!offset && !items.empty()) {
  11854. sink.os << detail::serialize_multipart_formdata(items, boundary, false);
  11855. return true;
  11856. } else if (cur_item < provider_items.size()) {
  11857. if (!cur_start) {
  11858. const auto &begin = detail::serialize_multipart_formdata_item_begin(
  11859. provider_items[cur_item], boundary);
  11860. offset += begin.size();
  11861. cur_start = offset;
  11862. sink.os << begin;
  11863. }
  11864. DataSink cur_sink;
  11865. auto has_data = true;
  11866. cur_sink.write = sink.write;
  11867. cur_sink.done = [&]() { has_data = false; };
  11868. if (!provider_items[cur_item].provider(offset - cur_start, cur_sink)) {
  11869. return false;
  11870. }
  11871. if (!has_data) {
  11872. sink.os << detail::serialize_multipart_formdata_item_end();
  11873. cur_item++;
  11874. cur_start = 0;
  11875. }
  11876. return true;
  11877. } else {
  11878. sink.os << detail::serialize_multipart_formdata_finish(boundary);
  11879. sink.done();
  11880. return true;
  11881. }
  11882. };
  11883. }
  11884. inline bool ClientImpl::process_socket(
  11885. const Socket &socket,
  11886. std::chrono::time_point<std::chrono::steady_clock> start_time,
  11887. std::function<bool(Stream &strm)> callback) {
  11888. return detail::process_client_socket(
  11889. socket.sock, read_timeout_sec_, read_timeout_usec_, write_timeout_sec_,
  11890. write_timeout_usec_, max_timeout_msec_, start_time, std::move(callback));
  11891. }
  11892. inline bool ClientImpl::is_ssl() const { return false; }
  11893. inline Result ClientImpl::Get(const std::string &path,
  11894. DownloadProgress progress) {
  11895. return Get(path, Headers(), std::move(progress));
  11896. }
  11897. inline Result ClientImpl::Get(const std::string &path, const Params &params,
  11898. const Headers &headers,
  11899. DownloadProgress progress) {
  11900. if (params.empty()) { return Get(path, headers); }
  11901. std::string path_with_query = append_query_params(path, params);
  11902. return Get(path_with_query, headers, std::move(progress));
  11903. }
  11904. inline Result ClientImpl::Get(const std::string &path, const Headers &headers,
  11905. DownloadProgress progress) {
  11906. Request req;
  11907. req.method = "GET";
  11908. req.path = path;
  11909. req.headers = headers;
  11910. req.download_progress = std::move(progress);
  11911. if (max_timeout_msec_ > 0) {
  11912. req.start_time_ = std::chrono::steady_clock::now();
  11913. }
  11914. return send_(std::move(req));
  11915. }
  11916. inline Result ClientImpl::Get(const std::string &path,
  11917. ContentReceiver content_receiver,
  11918. DownloadProgress progress) {
  11919. return Get(path, Headers(), nullptr, std::move(content_receiver),
  11920. std::move(progress));
  11921. }
  11922. inline Result ClientImpl::Get(const std::string &path, const Headers &headers,
  11923. ContentReceiver content_receiver,
  11924. DownloadProgress progress) {
  11925. return Get(path, headers, nullptr, std::move(content_receiver),
  11926. std::move(progress));
  11927. }
  11928. inline Result ClientImpl::Get(const std::string &path,
  11929. ResponseHandler response_handler,
  11930. ContentReceiver content_receiver,
  11931. DownloadProgress progress) {
  11932. return Get(path, Headers(), std::move(response_handler),
  11933. std::move(content_receiver), std::move(progress));
  11934. }
  11935. inline Result ClientImpl::Get(const std::string &path, const Headers &headers,
  11936. ResponseHandler response_handler,
  11937. ContentReceiver content_receiver,
  11938. DownloadProgress progress) {
  11939. Request req;
  11940. req.method = "GET";
  11941. req.path = path;
  11942. req.headers = headers;
  11943. req.response_handler = std::move(response_handler);
  11944. req.content_receiver =
  11945. [content_receiver](const char *data, size_t data_length,
  11946. size_t /*offset*/, size_t /*total_length*/) {
  11947. return content_receiver(data, data_length);
  11948. };
  11949. req.download_progress = std::move(progress);
  11950. if (max_timeout_msec_ > 0) {
  11951. req.start_time_ = std::chrono::steady_clock::now();
  11952. }
  11953. return send_(std::move(req));
  11954. }
  11955. inline Result ClientImpl::Get(const std::string &path, const Params &params,
  11956. const Headers &headers,
  11957. ContentReceiver content_receiver,
  11958. DownloadProgress progress) {
  11959. return Get(path, params, headers, nullptr, std::move(content_receiver),
  11960. std::move(progress));
  11961. }
  11962. inline Result ClientImpl::Get(const std::string &path, const Params &params,
  11963. const Headers &headers,
  11964. ResponseHandler response_handler,
  11965. ContentReceiver content_receiver,
  11966. DownloadProgress progress) {
  11967. if (params.empty()) {
  11968. return Get(path, headers, std::move(response_handler),
  11969. std::move(content_receiver), std::move(progress));
  11970. }
  11971. std::string path_with_query = append_query_params(path, params);
  11972. return Get(path_with_query, headers, std::move(response_handler),
  11973. std::move(content_receiver), std::move(progress));
  11974. }
  11975. inline Result ClientImpl::Head(const std::string &path) {
  11976. return Head(path, Headers());
  11977. }
  11978. inline Result ClientImpl::Head(const std::string &path,
  11979. const Headers &headers) {
  11980. Request req;
  11981. req.method = "HEAD";
  11982. req.headers = headers;
  11983. req.path = path;
  11984. if (max_timeout_msec_ > 0) {
  11985. req.start_time_ = std::chrono::steady_clock::now();
  11986. }
  11987. return send_(std::move(req));
  11988. }
  11989. inline Result ClientImpl::Post(const std::string &path) {
  11990. return Post(path, std::string(), std::string());
  11991. }
  11992. inline Result ClientImpl::Post(const std::string &path,
  11993. const Headers &headers) {
  11994. return Post(path, headers, nullptr, 0, std::string());
  11995. }
  11996. inline Result ClientImpl::Post(const std::string &path, const char *body,
  11997. size_t content_length,
  11998. const std::string &content_type,
  11999. UploadProgress progress) {
  12000. return Post(path, Headers(), body, content_length, content_type, progress);
  12001. }
  12002. inline Result ClientImpl::Post(const std::string &path, const std::string &body,
  12003. const std::string &content_type,
  12004. UploadProgress progress) {
  12005. return Post(path, Headers(), body, content_type, progress);
  12006. }
  12007. inline Result ClientImpl::Post(const std::string &path, const Params &params) {
  12008. return Post(path, Headers(), params);
  12009. }
  12010. inline Result ClientImpl::Post(const std::string &path, size_t content_length,
  12011. ContentProvider content_provider,
  12012. const std::string &content_type,
  12013. UploadProgress progress) {
  12014. return Post(path, Headers(), content_length, std::move(content_provider),
  12015. content_type, progress);
  12016. }
  12017. inline Result ClientImpl::Post(const std::string &path, size_t content_length,
  12018. ContentProvider content_provider,
  12019. const std::string &content_type,
  12020. ContentReceiver content_receiver,
  12021. UploadProgress progress) {
  12022. return Post(path, Headers(), content_length, std::move(content_provider),
  12023. content_type, std::move(content_receiver), progress);
  12024. }
  12025. inline Result ClientImpl::Post(const std::string &path,
  12026. ContentProviderWithoutLength content_provider,
  12027. const std::string &content_type,
  12028. UploadProgress progress) {
  12029. return Post(path, Headers(), std::move(content_provider), content_type,
  12030. progress);
  12031. }
  12032. inline Result ClientImpl::Post(const std::string &path,
  12033. ContentProviderWithoutLength content_provider,
  12034. const std::string &content_type,
  12035. ContentReceiver content_receiver,
  12036. UploadProgress progress) {
  12037. return Post(path, Headers(), std::move(content_provider), content_type,
  12038. std::move(content_receiver), progress);
  12039. }
  12040. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12041. const Params &params) {
  12042. auto query = detail::params_to_query_str(params);
  12043. return Post(path, headers, query, "application/x-www-form-urlencoded");
  12044. }
  12045. inline Result ClientImpl::Post(const std::string &path,
  12046. const UploadFormDataItems &items,
  12047. UploadProgress progress) {
  12048. return Post(path, Headers(), items, progress);
  12049. }
  12050. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12051. const UploadFormDataItems &items,
  12052. UploadProgress progress) {
  12053. const auto &boundary = detail::make_multipart_data_boundary();
  12054. const auto &content_type =
  12055. detail::serialize_multipart_formdata_get_content_type(boundary);
  12056. auto content_length = detail::get_multipart_content_length(items, boundary);
  12057. return Post(path, headers, content_length,
  12058. detail::make_multipart_content_provider(items, boundary),
  12059. content_type, progress);
  12060. }
  12061. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12062. const UploadFormDataItems &items,
  12063. const std::string &boundary,
  12064. UploadProgress progress) {
  12065. if (!detail::is_multipart_boundary_chars_valid(boundary)) {
  12066. return Result{nullptr, Error::UnsupportedMultipartBoundaryChars};
  12067. }
  12068. const auto &content_type =
  12069. detail::serialize_multipart_formdata_get_content_type(boundary);
  12070. auto content_length = detail::get_multipart_content_length(items, boundary);
  12071. return Post(path, headers, content_length,
  12072. detail::make_multipart_content_provider(items, boundary),
  12073. content_type, progress);
  12074. }
  12075. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12076. const char *body, size_t content_length,
  12077. const std::string &content_type,
  12078. UploadProgress progress) {
  12079. return send_with_content_provider_and_receiver(
  12080. "POST", path, headers, body, content_length, nullptr, nullptr,
  12081. content_type, nullptr, progress);
  12082. }
  12083. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12084. const std::string &body,
  12085. const std::string &content_type,
  12086. UploadProgress progress) {
  12087. return send_with_content_provider_and_receiver(
  12088. "POST", path, headers, body.data(), body.size(), nullptr, nullptr,
  12089. content_type, nullptr, progress);
  12090. }
  12091. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12092. size_t content_length,
  12093. ContentProvider content_provider,
  12094. const std::string &content_type,
  12095. UploadProgress progress) {
  12096. return send_with_content_provider_and_receiver(
  12097. "POST", path, headers, nullptr, content_length,
  12098. std::move(content_provider), nullptr, content_type, nullptr, progress);
  12099. }
  12100. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12101. size_t content_length,
  12102. ContentProvider content_provider,
  12103. const std::string &content_type,
  12104. ContentReceiver content_receiver,
  12105. DownloadProgress progress) {
  12106. return send_with_content_provider_and_receiver(
  12107. "POST", path, headers, nullptr, content_length,
  12108. std::move(content_provider), nullptr, content_type,
  12109. std::move(content_receiver), std::move(progress));
  12110. }
  12111. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12112. ContentProviderWithoutLength content_provider,
  12113. const std::string &content_type,
  12114. UploadProgress progress) {
  12115. return send_with_content_provider_and_receiver(
  12116. "POST", path, headers, nullptr, 0, nullptr, std::move(content_provider),
  12117. content_type, nullptr, progress);
  12118. }
  12119. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12120. ContentProviderWithoutLength content_provider,
  12121. const std::string &content_type,
  12122. ContentReceiver content_receiver,
  12123. DownloadProgress progress) {
  12124. return send_with_content_provider_and_receiver(
  12125. "POST", path, headers, nullptr, 0, nullptr, std::move(content_provider),
  12126. content_type, std::move(content_receiver), std::move(progress));
  12127. }
  12128. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12129. const UploadFormDataItems &items,
  12130. const FormDataProviderItems &provider_items,
  12131. UploadProgress progress) {
  12132. const auto &boundary = detail::make_multipart_data_boundary();
  12133. const auto &content_type =
  12134. detail::serialize_multipart_formdata_get_content_type(boundary);
  12135. return send_with_content_provider_and_receiver(
  12136. "POST", path, headers, nullptr, 0, nullptr,
  12137. get_multipart_content_provider(boundary, items, provider_items),
  12138. content_type, nullptr, progress);
  12139. }
  12140. inline Result ClientImpl::Post(const std::string &path, const Headers &headers,
  12141. const std::string &body,
  12142. const std::string &content_type,
  12143. ContentReceiver content_receiver,
  12144. DownloadProgress progress) {
  12145. Request req;
  12146. req.method = "POST";
  12147. req.path = path;
  12148. req.headers = headers;
  12149. req.body = body;
  12150. req.content_receiver =
  12151. [content_receiver](const char *data, size_t data_length,
  12152. size_t /*offset*/, size_t /*total_length*/) {
  12153. return content_receiver(data, data_length);
  12154. };
  12155. req.download_progress = std::move(progress);
  12156. if (max_timeout_msec_ > 0) {
  12157. req.start_time_ = std::chrono::steady_clock::now();
  12158. }
  12159. if (!content_type.empty()) { req.set_header("Content-Type", content_type); }
  12160. return send_(std::move(req));
  12161. }
  12162. inline Result ClientImpl::Put(const std::string &path) {
  12163. return Put(path, std::string(), std::string());
  12164. }
  12165. inline Result ClientImpl::Put(const std::string &path, const Headers &headers) {
  12166. return Put(path, headers, nullptr, 0, std::string());
  12167. }
  12168. inline Result ClientImpl::Put(const std::string &path, const char *body,
  12169. size_t content_length,
  12170. const std::string &content_type,
  12171. UploadProgress progress) {
  12172. return Put(path, Headers(), body, content_length, content_type, progress);
  12173. }
  12174. inline Result ClientImpl::Put(const std::string &path, const std::string &body,
  12175. const std::string &content_type,
  12176. UploadProgress progress) {
  12177. return Put(path, Headers(), body, content_type, progress);
  12178. }
  12179. inline Result ClientImpl::Put(const std::string &path, const Params &params) {
  12180. return Put(path, Headers(), params);
  12181. }
  12182. inline Result ClientImpl::Put(const std::string &path, size_t content_length,
  12183. ContentProvider content_provider,
  12184. const std::string &content_type,
  12185. UploadProgress progress) {
  12186. return Put(path, Headers(), content_length, std::move(content_provider),
  12187. content_type, progress);
  12188. }
  12189. inline Result ClientImpl::Put(const std::string &path, size_t content_length,
  12190. ContentProvider content_provider,
  12191. const std::string &content_type,
  12192. ContentReceiver content_receiver,
  12193. UploadProgress progress) {
  12194. return Put(path, Headers(), content_length, std::move(content_provider),
  12195. content_type, std::move(content_receiver), progress);
  12196. }
  12197. inline Result ClientImpl::Put(const std::string &path,
  12198. ContentProviderWithoutLength content_provider,
  12199. const std::string &content_type,
  12200. UploadProgress progress) {
  12201. return Put(path, Headers(), std::move(content_provider), content_type,
  12202. progress);
  12203. }
  12204. inline Result ClientImpl::Put(const std::string &path,
  12205. ContentProviderWithoutLength content_provider,
  12206. const std::string &content_type,
  12207. ContentReceiver content_receiver,
  12208. UploadProgress progress) {
  12209. return Put(path, Headers(), std::move(content_provider), content_type,
  12210. std::move(content_receiver), progress);
  12211. }
  12212. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12213. const Params &params) {
  12214. auto query = detail::params_to_query_str(params);
  12215. return Put(path, headers, query, "application/x-www-form-urlencoded");
  12216. }
  12217. inline Result ClientImpl::Put(const std::string &path,
  12218. const UploadFormDataItems &items,
  12219. UploadProgress progress) {
  12220. return Put(path, Headers(), items, progress);
  12221. }
  12222. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12223. const UploadFormDataItems &items,
  12224. UploadProgress progress) {
  12225. const auto &boundary = detail::make_multipart_data_boundary();
  12226. const auto &content_type =
  12227. detail::serialize_multipart_formdata_get_content_type(boundary);
  12228. auto content_length = detail::get_multipart_content_length(items, boundary);
  12229. return Put(path, headers, content_length,
  12230. detail::make_multipart_content_provider(items, boundary),
  12231. content_type, progress);
  12232. }
  12233. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12234. const UploadFormDataItems &items,
  12235. const std::string &boundary,
  12236. UploadProgress progress) {
  12237. if (!detail::is_multipart_boundary_chars_valid(boundary)) {
  12238. return Result{nullptr, Error::UnsupportedMultipartBoundaryChars};
  12239. }
  12240. const auto &content_type =
  12241. detail::serialize_multipart_formdata_get_content_type(boundary);
  12242. auto content_length = detail::get_multipart_content_length(items, boundary);
  12243. return Put(path, headers, content_length,
  12244. detail::make_multipart_content_provider(items, boundary),
  12245. content_type, progress);
  12246. }
  12247. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12248. const char *body, size_t content_length,
  12249. const std::string &content_type,
  12250. UploadProgress progress) {
  12251. return send_with_content_provider_and_receiver(
  12252. "PUT", path, headers, body, content_length, nullptr, nullptr,
  12253. content_type, nullptr, progress);
  12254. }
  12255. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12256. const std::string &body,
  12257. const std::string &content_type,
  12258. UploadProgress progress) {
  12259. return send_with_content_provider_and_receiver(
  12260. "PUT", path, headers, body.data(), body.size(), nullptr, nullptr,
  12261. content_type, nullptr, progress);
  12262. }
  12263. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12264. size_t content_length,
  12265. ContentProvider content_provider,
  12266. const std::string &content_type,
  12267. UploadProgress progress) {
  12268. return send_with_content_provider_and_receiver(
  12269. "PUT", path, headers, nullptr, content_length,
  12270. std::move(content_provider), nullptr, content_type, nullptr, progress);
  12271. }
  12272. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12273. size_t content_length,
  12274. ContentProvider content_provider,
  12275. const std::string &content_type,
  12276. ContentReceiver content_receiver,
  12277. UploadProgress progress) {
  12278. return send_with_content_provider_and_receiver(
  12279. "PUT", path, headers, nullptr, content_length,
  12280. std::move(content_provider), nullptr, content_type,
  12281. std::move(content_receiver), progress);
  12282. }
  12283. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12284. ContentProviderWithoutLength content_provider,
  12285. const std::string &content_type,
  12286. UploadProgress progress) {
  12287. return send_with_content_provider_and_receiver(
  12288. "PUT", path, headers, nullptr, 0, nullptr, std::move(content_provider),
  12289. content_type, nullptr, progress);
  12290. }
  12291. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12292. ContentProviderWithoutLength content_provider,
  12293. const std::string &content_type,
  12294. ContentReceiver content_receiver,
  12295. UploadProgress progress) {
  12296. return send_with_content_provider_and_receiver(
  12297. "PUT", path, headers, nullptr, 0, nullptr, std::move(content_provider),
  12298. content_type, std::move(content_receiver), progress);
  12299. }
  12300. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12301. const UploadFormDataItems &items,
  12302. const FormDataProviderItems &provider_items,
  12303. UploadProgress progress) {
  12304. const auto &boundary = detail::make_multipart_data_boundary();
  12305. const auto &content_type =
  12306. detail::serialize_multipart_formdata_get_content_type(boundary);
  12307. return send_with_content_provider_and_receiver(
  12308. "PUT", path, headers, nullptr, 0, nullptr,
  12309. get_multipart_content_provider(boundary, items, provider_items),
  12310. content_type, nullptr, progress);
  12311. }
  12312. inline Result ClientImpl::Put(const std::string &path, const Headers &headers,
  12313. const std::string &body,
  12314. const std::string &content_type,
  12315. ContentReceiver content_receiver,
  12316. DownloadProgress progress) {
  12317. Request req;
  12318. req.method = "PUT";
  12319. req.path = path;
  12320. req.headers = headers;
  12321. req.body = body;
  12322. req.content_receiver =
  12323. [content_receiver](const char *data, size_t data_length,
  12324. size_t /*offset*/, size_t /*total_length*/) {
  12325. return content_receiver(data, data_length);
  12326. };
  12327. req.download_progress = std::move(progress);
  12328. if (max_timeout_msec_ > 0) {
  12329. req.start_time_ = std::chrono::steady_clock::now();
  12330. }
  12331. if (!content_type.empty()) { req.set_header("Content-Type", content_type); }
  12332. return send_(std::move(req));
  12333. }
  12334. inline Result ClientImpl::Patch(const std::string &path) {
  12335. return Patch(path, std::string(), std::string());
  12336. }
  12337. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12338. UploadProgress progress) {
  12339. return Patch(path, headers, nullptr, 0, std::string(), progress);
  12340. }
  12341. inline Result ClientImpl::Patch(const std::string &path, const char *body,
  12342. size_t content_length,
  12343. const std::string &content_type,
  12344. UploadProgress progress) {
  12345. return Patch(path, Headers(), body, content_length, content_type, progress);
  12346. }
  12347. inline Result ClientImpl::Patch(const std::string &path,
  12348. const std::string &body,
  12349. const std::string &content_type,
  12350. UploadProgress progress) {
  12351. return Patch(path, Headers(), body, content_type, progress);
  12352. }
  12353. inline Result ClientImpl::Patch(const std::string &path, const Params &params) {
  12354. return Patch(path, Headers(), params);
  12355. }
  12356. inline Result ClientImpl::Patch(const std::string &path, size_t content_length,
  12357. ContentProvider content_provider,
  12358. const std::string &content_type,
  12359. UploadProgress progress) {
  12360. return Patch(path, Headers(), content_length, std::move(content_provider),
  12361. content_type, progress);
  12362. }
  12363. inline Result ClientImpl::Patch(const std::string &path, size_t content_length,
  12364. ContentProvider content_provider,
  12365. const std::string &content_type,
  12366. ContentReceiver content_receiver,
  12367. UploadProgress progress) {
  12368. return Patch(path, Headers(), content_length, std::move(content_provider),
  12369. content_type, std::move(content_receiver), progress);
  12370. }
  12371. inline Result ClientImpl::Patch(const std::string &path,
  12372. ContentProviderWithoutLength content_provider,
  12373. const std::string &content_type,
  12374. UploadProgress progress) {
  12375. return Patch(path, Headers(), std::move(content_provider), content_type,
  12376. progress);
  12377. }
  12378. inline Result ClientImpl::Patch(const std::string &path,
  12379. ContentProviderWithoutLength content_provider,
  12380. const std::string &content_type,
  12381. ContentReceiver content_receiver,
  12382. UploadProgress progress) {
  12383. return Patch(path, Headers(), std::move(content_provider), content_type,
  12384. std::move(content_receiver), progress);
  12385. }
  12386. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12387. const Params &params) {
  12388. auto query = detail::params_to_query_str(params);
  12389. return Patch(path, headers, query, "application/x-www-form-urlencoded");
  12390. }
  12391. inline Result ClientImpl::Patch(const std::string &path,
  12392. const UploadFormDataItems &items,
  12393. UploadProgress progress) {
  12394. return Patch(path, Headers(), items, progress);
  12395. }
  12396. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12397. const UploadFormDataItems &items,
  12398. UploadProgress progress) {
  12399. const auto &boundary = detail::make_multipart_data_boundary();
  12400. const auto &content_type =
  12401. detail::serialize_multipart_formdata_get_content_type(boundary);
  12402. auto content_length = detail::get_multipart_content_length(items, boundary);
  12403. return Patch(path, headers, content_length,
  12404. detail::make_multipart_content_provider(items, boundary),
  12405. content_type, progress);
  12406. }
  12407. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12408. const UploadFormDataItems &items,
  12409. const std::string &boundary,
  12410. UploadProgress progress) {
  12411. if (!detail::is_multipart_boundary_chars_valid(boundary)) {
  12412. return Result{nullptr, Error::UnsupportedMultipartBoundaryChars};
  12413. }
  12414. const auto &content_type =
  12415. detail::serialize_multipart_formdata_get_content_type(boundary);
  12416. auto content_length = detail::get_multipart_content_length(items, boundary);
  12417. return Patch(path, headers, content_length,
  12418. detail::make_multipart_content_provider(items, boundary),
  12419. content_type, progress);
  12420. }
  12421. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12422. const char *body, size_t content_length,
  12423. const std::string &content_type,
  12424. UploadProgress progress) {
  12425. return send_with_content_provider_and_receiver(
  12426. "PATCH", path, headers, body, content_length, nullptr, nullptr,
  12427. content_type, nullptr, progress);
  12428. }
  12429. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12430. const std::string &body,
  12431. const std::string &content_type,
  12432. UploadProgress progress) {
  12433. return send_with_content_provider_and_receiver(
  12434. "PATCH", path, headers, body.data(), body.size(), nullptr, nullptr,
  12435. content_type, nullptr, progress);
  12436. }
  12437. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12438. size_t content_length,
  12439. ContentProvider content_provider,
  12440. const std::string &content_type,
  12441. UploadProgress progress) {
  12442. return send_with_content_provider_and_receiver(
  12443. "PATCH", path, headers, nullptr, content_length,
  12444. std::move(content_provider), nullptr, content_type, nullptr, progress);
  12445. }
  12446. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12447. size_t content_length,
  12448. ContentProvider content_provider,
  12449. const std::string &content_type,
  12450. ContentReceiver content_receiver,
  12451. UploadProgress progress) {
  12452. return send_with_content_provider_and_receiver(
  12453. "PATCH", path, headers, nullptr, content_length,
  12454. std::move(content_provider), nullptr, content_type,
  12455. std::move(content_receiver), progress);
  12456. }
  12457. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12458. ContentProviderWithoutLength content_provider,
  12459. const std::string &content_type,
  12460. UploadProgress progress) {
  12461. return send_with_content_provider_and_receiver(
  12462. "PATCH", path, headers, nullptr, 0, nullptr, std::move(content_provider),
  12463. content_type, nullptr, progress);
  12464. }
  12465. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12466. ContentProviderWithoutLength content_provider,
  12467. const std::string &content_type,
  12468. ContentReceiver content_receiver,
  12469. UploadProgress progress) {
  12470. return send_with_content_provider_and_receiver(
  12471. "PATCH", path, headers, nullptr, 0, nullptr, std::move(content_provider),
  12472. content_type, std::move(content_receiver), progress);
  12473. }
  12474. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12475. const UploadFormDataItems &items,
  12476. const FormDataProviderItems &provider_items,
  12477. UploadProgress progress) {
  12478. const auto &boundary = detail::make_multipart_data_boundary();
  12479. const auto &content_type =
  12480. detail::serialize_multipart_formdata_get_content_type(boundary);
  12481. return send_with_content_provider_and_receiver(
  12482. "PATCH", path, headers, nullptr, 0, nullptr,
  12483. get_multipart_content_provider(boundary, items, provider_items),
  12484. content_type, nullptr, progress);
  12485. }
  12486. inline Result ClientImpl::Patch(const std::string &path, const Headers &headers,
  12487. const std::string &body,
  12488. const std::string &content_type,
  12489. ContentReceiver content_receiver,
  12490. DownloadProgress progress) {
  12491. Request req;
  12492. req.method = "PATCH";
  12493. req.path = path;
  12494. req.headers = headers;
  12495. req.body = body;
  12496. req.content_receiver =
  12497. [content_receiver](const char *data, size_t data_length,
  12498. size_t /*offset*/, size_t /*total_length*/) {
  12499. return content_receiver(data, data_length);
  12500. };
  12501. req.download_progress = std::move(progress);
  12502. if (max_timeout_msec_ > 0) {
  12503. req.start_time_ = std::chrono::steady_clock::now();
  12504. }
  12505. if (!content_type.empty()) { req.set_header("Content-Type", content_type); }
  12506. return send_(std::move(req));
  12507. }
  12508. inline Result ClientImpl::Delete(const std::string &path,
  12509. DownloadProgress progress) {
  12510. return Delete(path, Headers(), std::string(), std::string(), progress);
  12511. }
  12512. inline Result ClientImpl::Delete(const std::string &path,
  12513. const Headers &headers,
  12514. DownloadProgress progress) {
  12515. return Delete(path, headers, std::string(), std::string(), progress);
  12516. }
  12517. inline Result ClientImpl::Delete(const std::string &path, const char *body,
  12518. size_t content_length,
  12519. const std::string &content_type,
  12520. DownloadProgress progress) {
  12521. return Delete(path, Headers(), body, content_length, content_type, progress);
  12522. }
  12523. inline Result ClientImpl::Delete(const std::string &path,
  12524. const std::string &body,
  12525. const std::string &content_type,
  12526. DownloadProgress progress) {
  12527. return Delete(path, Headers(), body.data(), body.size(), content_type,
  12528. progress);
  12529. }
  12530. inline Result ClientImpl::Delete(const std::string &path,
  12531. const Headers &headers,
  12532. const std::string &body,
  12533. const std::string &content_type,
  12534. DownloadProgress progress) {
  12535. return Delete(path, headers, body.data(), body.size(), content_type,
  12536. progress);
  12537. }
  12538. inline Result ClientImpl::Delete(const std::string &path, const Params &params,
  12539. DownloadProgress progress) {
  12540. return Delete(path, Headers(), params, progress);
  12541. }
  12542. inline Result ClientImpl::Delete(const std::string &path,
  12543. const Headers &headers, const Params &params,
  12544. DownloadProgress progress) {
  12545. auto query = detail::params_to_query_str(params);
  12546. return Delete(path, headers, query, "application/x-www-form-urlencoded",
  12547. progress);
  12548. }
  12549. inline Result ClientImpl::Delete(const std::string &path,
  12550. const Headers &headers, const char *body,
  12551. size_t content_length,
  12552. const std::string &content_type,
  12553. DownloadProgress progress) {
  12554. Request req;
  12555. req.method = "DELETE";
  12556. req.headers = headers;
  12557. req.path = path;
  12558. req.download_progress = std::move(progress);
  12559. if (max_timeout_msec_ > 0) {
  12560. req.start_time_ = std::chrono::steady_clock::now();
  12561. }
  12562. if (!content_type.empty()) { req.set_header("Content-Type", content_type); }
  12563. req.body.assign(body, content_length);
  12564. return send_(std::move(req));
  12565. }
  12566. inline Result ClientImpl::Options(const std::string &path) {
  12567. return Options(path, Headers());
  12568. }
  12569. inline Result ClientImpl::Options(const std::string &path,
  12570. const Headers &headers) {
  12571. Request req;
  12572. req.method = "OPTIONS";
  12573. req.headers = headers;
  12574. req.path = path;
  12575. if (max_timeout_msec_ > 0) {
  12576. req.start_time_ = std::chrono::steady_clock::now();
  12577. }
  12578. return send_(std::move(req));
  12579. }
  12580. inline void ClientImpl::stop() {
  12581. std::lock_guard<std::mutex> guard(socket_mutex_);
  12582. // If there is anything ongoing right now, the ONLY thread-safe thing we can
  12583. // do is to shutdown_socket, so that threads using this socket suddenly
  12584. // discover they can't read/write any more and error out. Everything else
  12585. // (closing the socket, shutting ssl down) is unsafe because these actions
  12586. // are not thread-safe.
  12587. if (socket_requests_in_flight_ > 0) {
  12588. shutdown_socket(socket_);
  12589. // Aside from that, we set a flag for the socket to be closed when we're
  12590. // done.
  12591. socket_should_be_closed_when_request_is_done_ = true;
  12592. return;
  12593. }
  12594. disconnect(/*gracefully=*/true);
  12595. }
  12596. inline std::string ClientImpl::host() const { return host_; }
  12597. inline int ClientImpl::port() const { return port_; }
  12598. inline size_t ClientImpl::is_socket_open() const {
  12599. std::lock_guard<std::mutex> guard(socket_mutex_);
  12600. return socket_.is_open();
  12601. }
  12602. inline socket_t ClientImpl::socket() const { return socket_.sock; }
  12603. inline void ClientImpl::set_connection_timeout(time_t sec, time_t usec) {
  12604. connection_timeout_sec_ = sec;
  12605. connection_timeout_usec_ = usec;
  12606. }
  12607. inline void ClientImpl::set_read_timeout(time_t sec, time_t usec) {
  12608. read_timeout_sec_ = sec;
  12609. read_timeout_usec_ = usec;
  12610. }
  12611. inline void ClientImpl::set_write_timeout(time_t sec, time_t usec) {
  12612. write_timeout_sec_ = sec;
  12613. write_timeout_usec_ = usec;
  12614. }
  12615. inline void ClientImpl::set_max_timeout(time_t msec) {
  12616. max_timeout_msec_ = msec;
  12617. }
  12618. inline void ClientImpl::set_basic_auth(const std::string &username,
  12619. const std::string &password) {
  12620. basic_auth_username_ = username;
  12621. basic_auth_password_ = password;
  12622. }
  12623. inline void ClientImpl::set_bearer_token_auth(const std::string &token) {
  12624. bearer_token_auth_token_ = token;
  12625. }
  12626. inline void ClientImpl::set_keep_alive(bool on) { keep_alive_ = on; }
  12627. inline void ClientImpl::set_follow_location(bool on) { follow_location_ = on; }
  12628. inline void ClientImpl::set_path_encode(bool on) { path_encode_ = on; }
  12629. inline void
  12630. ClientImpl::set_hostname_addr_map(std::map<std::string, std::string> addr_map) {
  12631. addr_map_ = std::move(addr_map);
  12632. }
  12633. inline void ClientImpl::set_default_headers(Headers headers) {
  12634. default_headers_ = std::move(headers);
  12635. }
  12636. inline void ClientImpl::set_header_writer(
  12637. std::function<ssize_t(Stream &, Headers &)> const &writer) {
  12638. header_writer_ = writer;
  12639. }
  12640. inline void ClientImpl::set_address_family(int family) {
  12641. address_family_ = family;
  12642. }
  12643. inline void ClientImpl::set_tcp_nodelay(bool on) { tcp_nodelay_ = on; }
  12644. inline void ClientImpl::set_ipv6_v6only(bool on) { ipv6_v6only_ = on; }
  12645. inline void ClientImpl::set_socket_options(SocketOptions socket_options) {
  12646. socket_options_ = std::move(socket_options);
  12647. }
  12648. inline void ClientImpl::set_compress(bool on) { compress_ = on; }
  12649. inline void ClientImpl::set_decompress(bool on) { decompress_ = on; }
  12650. inline void ClientImpl::set_payload_max_length(size_t length) {
  12651. payload_max_length_ = length;
  12652. has_payload_max_length_ = true;
  12653. }
  12654. inline void ClientImpl::set_interface(const std::string &intf) {
  12655. interface_ = intf;
  12656. }
  12657. inline void ClientImpl::set_proxy(const std::string &host, int port) {
  12658. proxy_host_ = host;
  12659. proxy_port_ = port;
  12660. std::lock_guard<std::mutex> guard(socket_mutex_);
  12661. disconnect(/*gracefully=*/true);
  12662. }
  12663. inline void ClientImpl::set_proxy_basic_auth(const std::string &username,
  12664. const std::string &password) {
  12665. proxy_basic_auth_username_ = username;
  12666. proxy_basic_auth_password_ = password;
  12667. }
  12668. inline void ClientImpl::set_proxy_bearer_token_auth(const std::string &token) {
  12669. proxy_bearer_token_auth_token_ = token;
  12670. }
  12671. inline void ClientImpl::set_no_proxy(const std::vector<std::string> &patterns) {
  12672. std::vector<detail::NoProxyEntry> parsed;
  12673. parsed.reserve(patterns.size());
  12674. for (const auto &p : patterns) {
  12675. auto trimmed = detail::trim_copy(p);
  12676. if (trimmed.empty()) { continue; }
  12677. detail::NoProxyEntry entry;
  12678. if (detail::parse_no_proxy_entry(trimmed, entry)) {
  12679. parsed.push_back(std::move(entry));
  12680. }
  12681. }
  12682. no_proxy_entries_ = std::move(parsed);
  12683. std::lock_guard<std::mutex> guard(socket_mutex_);
  12684. disconnect(/*gracefully=*/true);
  12685. }
  12686. #ifdef CPPHTTPLIB_SSL_ENABLED
  12687. inline void ClientImpl::set_digest_auth(const std::string &username,
  12688. const std::string &password) {
  12689. digest_auth_username_ = username;
  12690. digest_auth_password_ = password;
  12691. }
  12692. inline void ClientImpl::set_ca_cert_path(const std::string &ca_cert_file_path,
  12693. const std::string &ca_cert_dir_path) {
  12694. ca_cert_file_path_ = ca_cert_file_path;
  12695. ca_cert_dir_path_ = ca_cert_dir_path;
  12696. }
  12697. inline void ClientImpl::set_proxy_digest_auth(const std::string &username,
  12698. const std::string &password) {
  12699. proxy_digest_auth_username_ = username;
  12700. proxy_digest_auth_password_ = password;
  12701. }
  12702. inline void ClientImpl::enable_server_certificate_verification(bool enabled) {
  12703. server_certificate_verification_ = enabled;
  12704. }
  12705. inline void ClientImpl::enable_server_hostname_verification(bool enabled) {
  12706. server_hostname_verification_ = enabled;
  12707. }
  12708. inline void ClientImpl::enable_system_ca(bool enabled) {
  12709. system_ca_mode_ = enabled ? SystemCAMode::Enabled : SystemCAMode::Disabled;
  12710. }
  12711. #endif
  12712. inline void ClientImpl::set_logger(Logger logger) {
  12713. logger_ = std::move(logger);
  12714. }
  12715. inline void ClientImpl::set_error_logger(ErrorLogger error_logger) {
  12716. error_logger_ = std::move(error_logger);
  12717. }
  12718. /*
  12719. * SSL/TLS Common Implementation
  12720. */
  12721. inline ClientConnection::~ClientConnection() {
  12722. #ifdef CPPHTTPLIB_SSL_ENABLED
  12723. if (session) {
  12724. tls::shutdown(session, true);
  12725. tls::free_session(session);
  12726. session = nullptr;
  12727. }
  12728. #endif
  12729. if (sock != INVALID_SOCKET) {
  12730. detail::close_socket(sock);
  12731. sock = INVALID_SOCKET;
  12732. }
  12733. }
  12734. // Universal client implementation
  12735. inline Client::Client(const std::string &scheme_host_port)
  12736. : Client(scheme_host_port, std::string(), std::string()) {}
  12737. inline Client::Client(const std::string &scheme_host_port,
  12738. const std::string &client_cert_path,
  12739. const std::string &client_key_path) {
  12740. detail::UrlComponents uc;
  12741. if (detail::parse_url(scheme_host_port, uc) && !uc.host.empty()) {
  12742. auto &scheme = uc.scheme;
  12743. #ifdef CPPHTTPLIB_SSL_ENABLED
  12744. if (!scheme.empty() && (scheme != "http" && scheme != "https")) {
  12745. #else
  12746. if (!scheme.empty() && scheme != "http") {
  12747. #endif
  12748. #ifndef CPPHTTPLIB_NO_EXCEPTIONS
  12749. std::string msg = "'" + scheme + "' scheme is not supported.";
  12750. throw std::invalid_argument(msg);
  12751. #endif
  12752. return;
  12753. }
  12754. auto is_ssl = scheme == "https";
  12755. auto host = std::move(uc.host);
  12756. auto port = is_ssl ? 443 : 80;
  12757. if (!uc.port.empty() && !detail::parse_port(uc.port, port)) { return; }
  12758. if (is_ssl) {
  12759. #ifdef CPPHTTPLIB_SSL_ENABLED
  12760. cli_ = detail::make_unique<SSLClient>(host, port, client_cert_path,
  12761. client_key_path);
  12762. is_ssl_ = is_ssl;
  12763. #endif
  12764. } else {
  12765. cli_ = detail::make_unique<ClientImpl>(host, port, client_cert_path,
  12766. client_key_path);
  12767. }
  12768. } else {
  12769. // NOTE: Update TEST(UniversalClientImplTest, Ipv6LiteralAddress)
  12770. // if port param below changes.
  12771. cli_ = detail::make_unique<ClientImpl>(scheme_host_port, 80,
  12772. client_cert_path, client_key_path);
  12773. }
  12774. }
  12775. inline Client::Client(const std::string &host, int port)
  12776. : Client(host, port, std::string(), std::string()) {}
  12777. inline Client::Client(const std::string &host, int port,
  12778. const std::string &client_cert_path,
  12779. const std::string &client_key_path)
  12780. : cli_(detail::make_unique<ClientImpl>(host, port, client_cert_path,
  12781. client_key_path)) {}
  12782. inline Client::~Client() = default;
  12783. inline bool Client::is_valid() const {
  12784. return cli_ != nullptr && cli_->is_valid();
  12785. }
  12786. inline Result Client::Get(const std::string &path, DownloadProgress progress) {
  12787. return cli_->Get(path, std::move(progress));
  12788. }
  12789. inline Result Client::Get(const std::string &path, const Headers &headers,
  12790. DownloadProgress progress) {
  12791. return cli_->Get(path, headers, std::move(progress));
  12792. }
  12793. inline Result Client::Get(const std::string &path,
  12794. ContentReceiver content_receiver,
  12795. DownloadProgress progress) {
  12796. return cli_->Get(path, std::move(content_receiver), std::move(progress));
  12797. }
  12798. inline Result Client::Get(const std::string &path, const Headers &headers,
  12799. ContentReceiver content_receiver,
  12800. DownloadProgress progress) {
  12801. return cli_->Get(path, headers, std::move(content_receiver),
  12802. std::move(progress));
  12803. }
  12804. inline Result Client::Get(const std::string &path,
  12805. ResponseHandler response_handler,
  12806. ContentReceiver content_receiver,
  12807. DownloadProgress progress) {
  12808. return cli_->Get(path, std::move(response_handler),
  12809. std::move(content_receiver), std::move(progress));
  12810. }
  12811. inline Result Client::Get(const std::string &path, const Headers &headers,
  12812. ResponseHandler response_handler,
  12813. ContentReceiver content_receiver,
  12814. DownloadProgress progress) {
  12815. return cli_->Get(path, headers, std::move(response_handler),
  12816. std::move(content_receiver), std::move(progress));
  12817. }
  12818. inline Result Client::Get(const std::string &path, const Params &params,
  12819. const Headers &headers, DownloadProgress progress) {
  12820. return cli_->Get(path, params, headers, std::move(progress));
  12821. }
  12822. inline Result Client::Get(const std::string &path, const Params &params,
  12823. const Headers &headers,
  12824. ContentReceiver content_receiver,
  12825. DownloadProgress progress) {
  12826. return cli_->Get(path, params, headers, std::move(content_receiver),
  12827. std::move(progress));
  12828. }
  12829. inline Result Client::Get(const std::string &path, const Params &params,
  12830. const Headers &headers,
  12831. ResponseHandler response_handler,
  12832. ContentReceiver content_receiver,
  12833. DownloadProgress progress) {
  12834. return cli_->Get(path, params, headers, std::move(response_handler),
  12835. std::move(content_receiver), std::move(progress));
  12836. }
  12837. inline Result Client::Head(const std::string &path) { return cli_->Head(path); }
  12838. inline Result Client::Head(const std::string &path, const Headers &headers) {
  12839. return cli_->Head(path, headers);
  12840. }
  12841. inline Result Client::Post(const std::string &path) { return cli_->Post(path); }
  12842. inline Result Client::Post(const std::string &path, const Headers &headers) {
  12843. return cli_->Post(path, headers);
  12844. }
  12845. inline Result Client::Post(const std::string &path, const char *body,
  12846. size_t content_length,
  12847. const std::string &content_type,
  12848. UploadProgress progress) {
  12849. return cli_->Post(path, body, content_length, content_type, progress);
  12850. }
  12851. inline Result Client::Post(const std::string &path, const Headers &headers,
  12852. const char *body, size_t content_length,
  12853. const std::string &content_type,
  12854. UploadProgress progress) {
  12855. return cli_->Post(path, headers, body, content_length, content_type,
  12856. progress);
  12857. }
  12858. inline Result Client::Post(const std::string &path, const std::string &body,
  12859. const std::string &content_type,
  12860. UploadProgress progress) {
  12861. return cli_->Post(path, body, content_type, progress);
  12862. }
  12863. inline Result Client::Post(const std::string &path, const Headers &headers,
  12864. const std::string &body,
  12865. const std::string &content_type,
  12866. UploadProgress progress) {
  12867. return cli_->Post(path, headers, body, content_type, progress);
  12868. }
  12869. inline Result Client::Post(const std::string &path, size_t content_length,
  12870. ContentProvider content_provider,
  12871. const std::string &content_type,
  12872. UploadProgress progress) {
  12873. return cli_->Post(path, content_length, std::move(content_provider),
  12874. content_type, progress);
  12875. }
  12876. inline Result Client::Post(const std::string &path, size_t content_length,
  12877. ContentProvider content_provider,
  12878. const std::string &content_type,
  12879. ContentReceiver content_receiver,
  12880. UploadProgress progress) {
  12881. return cli_->Post(path, content_length, std::move(content_provider),
  12882. content_type, std::move(content_receiver), progress);
  12883. }
  12884. inline Result Client::Post(const std::string &path,
  12885. ContentProviderWithoutLength content_provider,
  12886. const std::string &content_type,
  12887. UploadProgress progress) {
  12888. return cli_->Post(path, std::move(content_provider), content_type, progress);
  12889. }
  12890. inline Result Client::Post(const std::string &path,
  12891. ContentProviderWithoutLength content_provider,
  12892. const std::string &content_type,
  12893. ContentReceiver content_receiver,
  12894. UploadProgress progress) {
  12895. return cli_->Post(path, std::move(content_provider), content_type,
  12896. std::move(content_receiver), progress);
  12897. }
  12898. inline Result Client::Post(const std::string &path, const Headers &headers,
  12899. size_t content_length,
  12900. ContentProvider content_provider,
  12901. const std::string &content_type,
  12902. UploadProgress progress) {
  12903. return cli_->Post(path, headers, content_length, std::move(content_provider),
  12904. content_type, progress);
  12905. }
  12906. inline Result Client::Post(const std::string &path, const Headers &headers,
  12907. size_t content_length,
  12908. ContentProvider content_provider,
  12909. const std::string &content_type,
  12910. ContentReceiver content_receiver,
  12911. DownloadProgress progress) {
  12912. return cli_->Post(path, headers, content_length, std::move(content_provider),
  12913. content_type, std::move(content_receiver), progress);
  12914. }
  12915. inline Result Client::Post(const std::string &path, const Headers &headers,
  12916. ContentProviderWithoutLength content_provider,
  12917. const std::string &content_type,
  12918. UploadProgress progress) {
  12919. return cli_->Post(path, headers, std::move(content_provider), content_type,
  12920. progress);
  12921. }
  12922. inline Result Client::Post(const std::string &path, const Headers &headers,
  12923. ContentProviderWithoutLength content_provider,
  12924. const std::string &content_type,
  12925. ContentReceiver content_receiver,
  12926. DownloadProgress progress) {
  12927. return cli_->Post(path, headers, std::move(content_provider), content_type,
  12928. std::move(content_receiver), progress);
  12929. }
  12930. inline Result Client::Post(const std::string &path, const Params &params) {
  12931. return cli_->Post(path, params);
  12932. }
  12933. inline Result Client::Post(const std::string &path, const Headers &headers,
  12934. const Params &params) {
  12935. return cli_->Post(path, headers, params);
  12936. }
  12937. inline Result Client::Post(const std::string &path,
  12938. const UploadFormDataItems &items,
  12939. UploadProgress progress) {
  12940. return cli_->Post(path, items, progress);
  12941. }
  12942. inline Result Client::Post(const std::string &path, const Headers &headers,
  12943. const UploadFormDataItems &items,
  12944. UploadProgress progress) {
  12945. return cli_->Post(path, headers, items, progress);
  12946. }
  12947. inline Result Client::Post(const std::string &path, const Headers &headers,
  12948. const UploadFormDataItems &items,
  12949. const std::string &boundary,
  12950. UploadProgress progress) {
  12951. return cli_->Post(path, headers, items, boundary, progress);
  12952. }
  12953. inline Result Client::Post(const std::string &path, const Headers &headers,
  12954. const UploadFormDataItems &items,
  12955. const FormDataProviderItems &provider_items,
  12956. UploadProgress progress) {
  12957. return cli_->Post(path, headers, items, provider_items, progress);
  12958. }
  12959. inline Result Client::Post(const std::string &path, const Headers &headers,
  12960. const std::string &body,
  12961. const std::string &content_type,
  12962. ContentReceiver content_receiver,
  12963. DownloadProgress progress) {
  12964. return cli_->Post(path, headers, body, content_type,
  12965. std::move(content_receiver), progress);
  12966. }
  12967. inline Result Client::Put(const std::string &path) { return cli_->Put(path); }
  12968. inline Result Client::Put(const std::string &path, const Headers &headers) {
  12969. return cli_->Put(path, headers);
  12970. }
  12971. inline Result Client::Put(const std::string &path, const char *body,
  12972. size_t content_length,
  12973. const std::string &content_type,
  12974. UploadProgress progress) {
  12975. return cli_->Put(path, body, content_length, content_type, progress);
  12976. }
  12977. inline Result Client::Put(const std::string &path, const Headers &headers,
  12978. const char *body, size_t content_length,
  12979. const std::string &content_type,
  12980. UploadProgress progress) {
  12981. return cli_->Put(path, headers, body, content_length, content_type, progress);
  12982. }
  12983. inline Result Client::Put(const std::string &path, const std::string &body,
  12984. const std::string &content_type,
  12985. UploadProgress progress) {
  12986. return cli_->Put(path, body, content_type, progress);
  12987. }
  12988. inline Result Client::Put(const std::string &path, const Headers &headers,
  12989. const std::string &body,
  12990. const std::string &content_type,
  12991. UploadProgress progress) {
  12992. return cli_->Put(path, headers, body, content_type, progress);
  12993. }
  12994. inline Result Client::Put(const std::string &path, size_t content_length,
  12995. ContentProvider content_provider,
  12996. const std::string &content_type,
  12997. UploadProgress progress) {
  12998. return cli_->Put(path, content_length, std::move(content_provider),
  12999. content_type, progress);
  13000. }
  13001. inline Result Client::Put(const std::string &path, size_t content_length,
  13002. ContentProvider content_provider,
  13003. const std::string &content_type,
  13004. ContentReceiver content_receiver,
  13005. UploadProgress progress) {
  13006. return cli_->Put(path, content_length, std::move(content_provider),
  13007. content_type, std::move(content_receiver), progress);
  13008. }
  13009. inline Result Client::Put(const std::string &path,
  13010. ContentProviderWithoutLength content_provider,
  13011. const std::string &content_type,
  13012. UploadProgress progress) {
  13013. return cli_->Put(path, std::move(content_provider), content_type, progress);
  13014. }
  13015. inline Result Client::Put(const std::string &path,
  13016. ContentProviderWithoutLength content_provider,
  13017. const std::string &content_type,
  13018. ContentReceiver content_receiver,
  13019. UploadProgress progress) {
  13020. return cli_->Put(path, std::move(content_provider), content_type,
  13021. std::move(content_receiver), progress);
  13022. }
  13023. inline Result Client::Put(const std::string &path, const Headers &headers,
  13024. size_t content_length,
  13025. ContentProvider content_provider,
  13026. const std::string &content_type,
  13027. UploadProgress progress) {
  13028. return cli_->Put(path, headers, content_length, std::move(content_provider),
  13029. content_type, progress);
  13030. }
  13031. inline Result Client::Put(const std::string &path, const Headers &headers,
  13032. size_t content_length,
  13033. ContentProvider content_provider,
  13034. const std::string &content_type,
  13035. ContentReceiver content_receiver,
  13036. UploadProgress progress) {
  13037. return cli_->Put(path, headers, content_length, std::move(content_provider),
  13038. content_type, std::move(content_receiver), progress);
  13039. }
  13040. inline Result Client::Put(const std::string &path, const Headers &headers,
  13041. ContentProviderWithoutLength content_provider,
  13042. const std::string &content_type,
  13043. UploadProgress progress) {
  13044. return cli_->Put(path, headers, std::move(content_provider), content_type,
  13045. progress);
  13046. }
  13047. inline Result Client::Put(const std::string &path, const Headers &headers,
  13048. ContentProviderWithoutLength content_provider,
  13049. const std::string &content_type,
  13050. ContentReceiver content_receiver,
  13051. UploadProgress progress) {
  13052. return cli_->Put(path, headers, std::move(content_provider), content_type,
  13053. std::move(content_receiver), progress);
  13054. }
  13055. inline Result Client::Put(const std::string &path, const Params &params) {
  13056. return cli_->Put(path, params);
  13057. }
  13058. inline Result Client::Put(const std::string &path, const Headers &headers,
  13059. const Params &params) {
  13060. return cli_->Put(path, headers, params);
  13061. }
  13062. inline Result Client::Put(const std::string &path,
  13063. const UploadFormDataItems &items,
  13064. UploadProgress progress) {
  13065. return cli_->Put(path, items, progress);
  13066. }
  13067. inline Result Client::Put(const std::string &path, const Headers &headers,
  13068. const UploadFormDataItems &items,
  13069. UploadProgress progress) {
  13070. return cli_->Put(path, headers, items, progress);
  13071. }
  13072. inline Result Client::Put(const std::string &path, const Headers &headers,
  13073. const UploadFormDataItems &items,
  13074. const std::string &boundary,
  13075. UploadProgress progress) {
  13076. return cli_->Put(path, headers, items, boundary, progress);
  13077. }
  13078. inline Result Client::Put(const std::string &path, const Headers &headers,
  13079. const UploadFormDataItems &items,
  13080. const FormDataProviderItems &provider_items,
  13081. UploadProgress progress) {
  13082. return cli_->Put(path, headers, items, provider_items, progress);
  13083. }
  13084. inline Result Client::Put(const std::string &path, const Headers &headers,
  13085. const std::string &body,
  13086. const std::string &content_type,
  13087. ContentReceiver content_receiver,
  13088. DownloadProgress progress) {
  13089. return cli_->Put(path, headers, body, content_type, content_receiver,
  13090. progress);
  13091. }
  13092. inline Result Client::Patch(const std::string &path) {
  13093. return cli_->Patch(path);
  13094. }
  13095. inline Result Client::Patch(const std::string &path, const Headers &headers) {
  13096. return cli_->Patch(path, headers);
  13097. }
  13098. inline Result Client::Patch(const std::string &path, const char *body,
  13099. size_t content_length,
  13100. const std::string &content_type,
  13101. UploadProgress progress) {
  13102. return cli_->Patch(path, body, content_length, content_type, progress);
  13103. }
  13104. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13105. const char *body, size_t content_length,
  13106. const std::string &content_type,
  13107. UploadProgress progress) {
  13108. return cli_->Patch(path, headers, body, content_length, content_type,
  13109. progress);
  13110. }
  13111. inline Result Client::Patch(const std::string &path, const std::string &body,
  13112. const std::string &content_type,
  13113. UploadProgress progress) {
  13114. return cli_->Patch(path, body, content_type, progress);
  13115. }
  13116. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13117. const std::string &body,
  13118. const std::string &content_type,
  13119. UploadProgress progress) {
  13120. return cli_->Patch(path, headers, body, content_type, progress);
  13121. }
  13122. inline Result Client::Patch(const std::string &path, size_t content_length,
  13123. ContentProvider content_provider,
  13124. const std::string &content_type,
  13125. UploadProgress progress) {
  13126. return cli_->Patch(path, content_length, std::move(content_provider),
  13127. content_type, progress);
  13128. }
  13129. inline Result Client::Patch(const std::string &path, size_t content_length,
  13130. ContentProvider content_provider,
  13131. const std::string &content_type,
  13132. ContentReceiver content_receiver,
  13133. UploadProgress progress) {
  13134. return cli_->Patch(path, content_length, std::move(content_provider),
  13135. content_type, std::move(content_receiver), progress);
  13136. }
  13137. inline Result Client::Patch(const std::string &path,
  13138. ContentProviderWithoutLength content_provider,
  13139. const std::string &content_type,
  13140. UploadProgress progress) {
  13141. return cli_->Patch(path, std::move(content_provider), content_type, progress);
  13142. }
  13143. inline Result Client::Patch(const std::string &path,
  13144. ContentProviderWithoutLength content_provider,
  13145. const std::string &content_type,
  13146. ContentReceiver content_receiver,
  13147. UploadProgress progress) {
  13148. return cli_->Patch(path, std::move(content_provider), content_type,
  13149. std::move(content_receiver), progress);
  13150. }
  13151. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13152. size_t content_length,
  13153. ContentProvider content_provider,
  13154. const std::string &content_type,
  13155. UploadProgress progress) {
  13156. return cli_->Patch(path, headers, content_length, std::move(content_provider),
  13157. content_type, progress);
  13158. }
  13159. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13160. size_t content_length,
  13161. ContentProvider content_provider,
  13162. const std::string &content_type,
  13163. ContentReceiver content_receiver,
  13164. UploadProgress progress) {
  13165. return cli_->Patch(path, headers, content_length, std::move(content_provider),
  13166. content_type, std::move(content_receiver), progress);
  13167. }
  13168. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13169. ContentProviderWithoutLength content_provider,
  13170. const std::string &content_type,
  13171. UploadProgress progress) {
  13172. return cli_->Patch(path, headers, std::move(content_provider), content_type,
  13173. progress);
  13174. }
  13175. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13176. ContentProviderWithoutLength content_provider,
  13177. const std::string &content_type,
  13178. ContentReceiver content_receiver,
  13179. UploadProgress progress) {
  13180. return cli_->Patch(path, headers, std::move(content_provider), content_type,
  13181. std::move(content_receiver), progress);
  13182. }
  13183. inline Result Client::Patch(const std::string &path, const Params &params) {
  13184. return cli_->Patch(path, params);
  13185. }
  13186. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13187. const Params &params) {
  13188. return cli_->Patch(path, headers, params);
  13189. }
  13190. inline Result Client::Patch(const std::string &path,
  13191. const UploadFormDataItems &items,
  13192. UploadProgress progress) {
  13193. return cli_->Patch(path, items, progress);
  13194. }
  13195. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13196. const UploadFormDataItems &items,
  13197. UploadProgress progress) {
  13198. return cli_->Patch(path, headers, items, progress);
  13199. }
  13200. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13201. const UploadFormDataItems &items,
  13202. const std::string &boundary,
  13203. UploadProgress progress) {
  13204. return cli_->Patch(path, headers, items, boundary, progress);
  13205. }
  13206. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13207. const UploadFormDataItems &items,
  13208. const FormDataProviderItems &provider_items,
  13209. UploadProgress progress) {
  13210. return cli_->Patch(path, headers, items, provider_items, progress);
  13211. }
  13212. inline Result Client::Patch(const std::string &path, const Headers &headers,
  13213. const std::string &body,
  13214. const std::string &content_type,
  13215. ContentReceiver content_receiver,
  13216. DownloadProgress progress) {
  13217. return cli_->Patch(path, headers, body, content_type, content_receiver,
  13218. progress);
  13219. }
  13220. inline Result Client::Delete(const std::string &path,
  13221. DownloadProgress progress) {
  13222. return cli_->Delete(path, progress);
  13223. }
  13224. inline Result Client::Delete(const std::string &path, const Headers &headers,
  13225. DownloadProgress progress) {
  13226. return cli_->Delete(path, headers, progress);
  13227. }
  13228. inline Result Client::Delete(const std::string &path, const char *body,
  13229. size_t content_length,
  13230. const std::string &content_type,
  13231. DownloadProgress progress) {
  13232. return cli_->Delete(path, body, content_length, content_type, progress);
  13233. }
  13234. inline Result Client::Delete(const std::string &path, const Headers &headers,
  13235. const char *body, size_t content_length,
  13236. const std::string &content_type,
  13237. DownloadProgress progress) {
  13238. return cli_->Delete(path, headers, body, content_length, content_type,
  13239. progress);
  13240. }
  13241. inline Result Client::Delete(const std::string &path, const std::string &body,
  13242. const std::string &content_type,
  13243. DownloadProgress progress) {
  13244. return cli_->Delete(path, body, content_type, progress);
  13245. }
  13246. inline Result Client::Delete(const std::string &path, const Headers &headers,
  13247. const std::string &body,
  13248. const std::string &content_type,
  13249. DownloadProgress progress) {
  13250. return cli_->Delete(path, headers, body, content_type, progress);
  13251. }
  13252. inline Result Client::Delete(const std::string &path, const Params &params,
  13253. DownloadProgress progress) {
  13254. return cli_->Delete(path, params, progress);
  13255. }
  13256. inline Result Client::Delete(const std::string &path, const Headers &headers,
  13257. const Params &params, DownloadProgress progress) {
  13258. return cli_->Delete(path, headers, params, progress);
  13259. }
  13260. inline Result Client::Options(const std::string &path) {
  13261. return cli_->Options(path);
  13262. }
  13263. inline Result Client::Options(const std::string &path, const Headers &headers) {
  13264. return cli_->Options(path, headers);
  13265. }
  13266. inline ClientImpl::StreamHandle
  13267. Client::open_stream(const std::string &method, const std::string &path,
  13268. const Params &params, const Headers &headers,
  13269. const std::string &body, const std::string &content_type) {
  13270. return cli_->open_stream(method, path, params, headers, body, content_type);
  13271. }
  13272. inline bool Client::send(Request &req, Response &res, Error &error) {
  13273. return cli_->send(req, res, error);
  13274. }
  13275. inline Result Client::send(const Request &req) { return cli_->send(req); }
  13276. inline void Client::stop() { cli_->stop(); }
  13277. inline std::string Client::host() const { return cli_->host(); }
  13278. inline int Client::port() const { return cli_->port(); }
  13279. inline size_t Client::is_socket_open() const { return cli_->is_socket_open(); }
  13280. inline socket_t Client::socket() const { return cli_->socket(); }
  13281. inline void
  13282. Client::set_hostname_addr_map(std::map<std::string, std::string> addr_map) {
  13283. cli_->set_hostname_addr_map(std::move(addr_map));
  13284. }
  13285. inline void Client::set_default_headers(Headers headers) {
  13286. cli_->set_default_headers(std::move(headers));
  13287. }
  13288. inline void Client::set_header_writer(
  13289. std::function<ssize_t(Stream &, Headers &)> const &writer) {
  13290. cli_->set_header_writer(writer);
  13291. }
  13292. inline void Client::set_address_family(int family) {
  13293. cli_->set_address_family(family);
  13294. }
  13295. inline void Client::set_tcp_nodelay(bool on) { cli_->set_tcp_nodelay(on); }
  13296. inline void Client::set_socket_options(SocketOptions socket_options) {
  13297. cli_->set_socket_options(std::move(socket_options));
  13298. }
  13299. inline void Client::set_connection_timeout(time_t sec, time_t usec) {
  13300. cli_->set_connection_timeout(sec, usec);
  13301. }
  13302. inline void Client::set_read_timeout(time_t sec, time_t usec) {
  13303. cli_->set_read_timeout(sec, usec);
  13304. }
  13305. inline void Client::set_write_timeout(time_t sec, time_t usec) {
  13306. cli_->set_write_timeout(sec, usec);
  13307. }
  13308. inline void Client::set_basic_auth(const std::string &username,
  13309. const std::string &password) {
  13310. cli_->set_basic_auth(username, password);
  13311. }
  13312. inline void Client::set_bearer_token_auth(const std::string &token) {
  13313. cli_->set_bearer_token_auth(token);
  13314. }
  13315. inline void Client::set_keep_alive(bool on) { cli_->set_keep_alive(on); }
  13316. inline void Client::set_follow_location(bool on) {
  13317. cli_->set_follow_location(on);
  13318. }
  13319. inline void Client::set_path_encode(bool on) { cli_->set_path_encode(on); }
  13320. inline void Client::set_compress(bool on) { cli_->set_compress(on); }
  13321. inline void Client::set_decompress(bool on) { cli_->set_decompress(on); }
  13322. inline void Client::set_payload_max_length(size_t length) {
  13323. cli_->set_payload_max_length(length);
  13324. }
  13325. inline void Client::set_interface(const std::string &intf) {
  13326. cli_->set_interface(intf);
  13327. }
  13328. inline void Client::set_proxy(const std::string &host, int port) {
  13329. cli_->set_proxy(host, port);
  13330. }
  13331. inline void Client::set_proxy_basic_auth(const std::string &username,
  13332. const std::string &password) {
  13333. cli_->set_proxy_basic_auth(username, password);
  13334. }
  13335. inline void Client::set_proxy_bearer_token_auth(const std::string &token) {
  13336. cli_->set_proxy_bearer_token_auth(token);
  13337. }
  13338. inline void Client::set_no_proxy(const std::vector<std::string> &patterns) {
  13339. cli_->set_no_proxy(patterns);
  13340. }
  13341. inline void Client::set_logger(Logger logger) {
  13342. cli_->set_logger(std::move(logger));
  13343. }
  13344. inline void Client::set_error_logger(ErrorLogger error_logger) {
  13345. cli_->set_error_logger(std::move(error_logger));
  13346. }
  13347. /*
  13348. * Group 6: SSL Server and Client implementation
  13349. */
  13350. #ifdef CPPHTTPLIB_SSL_ENABLED
  13351. // SSL HTTP server implementation
  13352. inline SSLServer::SSLServer(const char *cert_path, const char *private_key_path,
  13353. const char *client_ca_cert_file_path,
  13354. const char *client_ca_cert_dir_path,
  13355. const char *private_key_password) {
  13356. using namespace tls;
  13357. ctx_ = create_server_context();
  13358. if (!ctx_) { return; }
  13359. // Load server certificate and private key
  13360. if (!set_server_cert_file(ctx_, cert_path, private_key_path,
  13361. private_key_password)) {
  13362. last_ssl_error_ = static_cast<int>(get_error());
  13363. free_context(ctx_);
  13364. ctx_ = nullptr;
  13365. return;
  13366. }
  13367. // Load client CA certificates for client authentication
  13368. if (client_ca_cert_file_path || client_ca_cert_dir_path) {
  13369. if (!set_client_ca_file(ctx_, client_ca_cert_file_path,
  13370. client_ca_cert_dir_path)) {
  13371. last_ssl_error_ = static_cast<int>(get_error());
  13372. free_context(ctx_);
  13373. ctx_ = nullptr;
  13374. return;
  13375. }
  13376. // Enable client certificate verification
  13377. set_verify_client(ctx_, true);
  13378. }
  13379. }
  13380. inline SSLServer::SSLServer(const PemMemory &pem) {
  13381. using namespace tls;
  13382. ctx_ = create_server_context();
  13383. if (ctx_) {
  13384. if (!set_server_cert_pem(ctx_, pem.cert_pem, pem.key_pem,
  13385. pem.private_key_password)) {
  13386. last_ssl_error_ = static_cast<int>(get_error());
  13387. free_context(ctx_);
  13388. ctx_ = nullptr;
  13389. } else if (pem.client_ca_pem && pem.client_ca_pem_len > 0) {
  13390. if (!load_ca_pem(ctx_, pem.client_ca_pem, pem.client_ca_pem_len)) {
  13391. last_ssl_error_ = static_cast<int>(get_error());
  13392. free_context(ctx_);
  13393. ctx_ = nullptr;
  13394. } else {
  13395. set_verify_client(ctx_, true);
  13396. }
  13397. }
  13398. }
  13399. }
  13400. inline SSLServer::SSLServer(const tls::ContextSetupCallback &setup_callback) {
  13401. using namespace tls;
  13402. ctx_ = create_server_context();
  13403. if (ctx_) {
  13404. if (!setup_callback(ctx_)) {
  13405. free_context(ctx_);
  13406. ctx_ = nullptr;
  13407. }
  13408. }
  13409. }
  13410. inline SSLServer::~SSLServer() {
  13411. if (ctx_) { tls::free_context(ctx_); }
  13412. }
  13413. inline bool SSLServer::is_valid() const { return ctx_ != nullptr; }
  13414. inline bool SSLServer::process_and_close_socket(socket_t sock) {
  13415. using namespace tls;
  13416. // Create TLS session with mutex protection
  13417. session_t session = nullptr;
  13418. {
  13419. std::lock_guard<std::mutex> guard(ctx_mutex_);
  13420. session = create_session(static_cast<ctx_t>(ctx_), sock);
  13421. }
  13422. if (!session) {
  13423. last_ssl_error_ = static_cast<int>(get_error());
  13424. detail::shutdown_socket(sock);
  13425. detail::close_socket(sock);
  13426. return false;
  13427. }
  13428. // Use scope_exit to ensure cleanup on all paths (including exceptions)
  13429. bool handshake_done = false;
  13430. bool ret = false;
  13431. bool websocket_upgraded = false;
  13432. auto cleanup = detail::scope_exit([&] {
  13433. if (handshake_done) { shutdown(session, !websocket_upgraded && ret); }
  13434. free_session(session);
  13435. detail::shutdown_socket(sock);
  13436. detail::close_socket(sock);
  13437. });
  13438. // Perform TLS accept handshake with timeout
  13439. TlsError tls_err;
  13440. if (!accept_nonblocking(session, sock, read_timeout_sec_, read_timeout_usec_,
  13441. &tls_err)) {
  13442. #ifdef CPPHTTPLIB_OPENSSL_SUPPORT
  13443. // Map TlsError to legacy ssl_error for backward compatibility
  13444. if (tls_err.code == ErrorCode::WantRead) {
  13445. last_ssl_error_ = SSL_ERROR_WANT_READ;
  13446. } else if (tls_err.code == ErrorCode::WantWrite) {
  13447. last_ssl_error_ = SSL_ERROR_WANT_WRITE;
  13448. } else {
  13449. last_ssl_error_ = SSL_ERROR_SSL;
  13450. }
  13451. #else
  13452. last_ssl_error_ = static_cast<int>(get_error());
  13453. #endif
  13454. return false;
  13455. }
  13456. handshake_done = true;
  13457. std::string remote_addr;
  13458. int remote_port = 0;
  13459. detail::get_remote_ip_and_port(sock, remote_addr, remote_port);
  13460. std::string local_addr;
  13461. int local_port = 0;
  13462. detail::get_local_ip_and_port(sock, local_addr, local_port);
  13463. ret = detail::process_server_socket_ssl(
  13464. svr_sock_, session, sock, keep_alive_max_count_, keep_alive_timeout_sec_,
  13465. read_timeout_sec_, read_timeout_usec_, write_timeout_sec_,
  13466. write_timeout_usec_,
  13467. [&](Stream &strm, bool close_connection, bool &connection_closed) {
  13468. return process_request(
  13469. strm, remote_addr, remote_port, local_addr, local_port,
  13470. close_connection, connection_closed,
  13471. [&](Request &req) { req.ssl = session; }, &websocket_upgraded);
  13472. });
  13473. return ret;
  13474. }
  13475. inline bool SSLServer::update_certs_pem(const char *cert_pem,
  13476. const char *key_pem,
  13477. const char *client_ca_pem,
  13478. const char *password) {
  13479. if (!ctx_) { return false; }
  13480. std::lock_guard<std::mutex> guard(ctx_mutex_);
  13481. if (!tls::update_server_cert(ctx_, cert_pem, key_pem, password)) {
  13482. return false;
  13483. }
  13484. if (client_ca_pem) {
  13485. return tls::update_server_client_ca(ctx_, client_ca_pem);
  13486. }
  13487. return true;
  13488. }
  13489. // SSL HTTP client implementation
  13490. inline SSLClient::~SSLClient() {
  13491. if (ctx_) { tls::free_context(ctx_); }
  13492. // Make sure to shut down SSL since shutdown_ssl will resolve to the
  13493. // base function rather than the derived function once we get to the
  13494. // base class destructor, and won't free the SSL (causing a leak).
  13495. shutdown_ssl_impl(socket_, true);
  13496. }
  13497. inline bool SSLClient::is_valid() const { return ctx_ != nullptr; }
  13498. inline void SSLClient::shutdown_ssl(Socket &socket, bool shutdown_gracefully) {
  13499. shutdown_ssl_impl(socket, shutdown_gracefully);
  13500. }
  13501. inline void SSLClient::shutdown_ssl_impl(Socket &socket,
  13502. bool shutdown_gracefully) {
  13503. if (socket.sock == INVALID_SOCKET) {
  13504. assert(socket.ssl == nullptr);
  13505. return;
  13506. }
  13507. if (socket.ssl) {
  13508. tls::shutdown(socket.ssl, shutdown_gracefully);
  13509. {
  13510. std::lock_guard<std::mutex> guard(ctx_mutex_);
  13511. tls::free_session(socket.ssl);
  13512. }
  13513. socket.ssl = nullptr;
  13514. }
  13515. assert(socket.ssl == nullptr);
  13516. }
  13517. inline bool SSLClient::process_socket(
  13518. const Socket &socket,
  13519. std::chrono::time_point<std::chrono::steady_clock> start_time,
  13520. std::function<bool(Stream &strm)> callback) {
  13521. assert(socket.ssl);
  13522. return detail::process_client_socket_ssl(
  13523. socket.ssl, socket.sock, read_timeout_sec_, read_timeout_usec_,
  13524. write_timeout_sec_, write_timeout_usec_, max_timeout_msec_, start_time,
  13525. std::move(callback));
  13526. }
  13527. inline bool SSLClient::is_ssl() const { return true; }
  13528. inline bool SSLClient::create_and_connect_socket(Socket &socket, Error &error) {
  13529. if (!is_valid()) {
  13530. error = Error::SSLConnection;
  13531. return false;
  13532. }
  13533. return ClientImpl::create_and_connect_socket(socket, error);
  13534. }
  13535. inline bool SSLClient::setup_proxy_connection(
  13536. Socket &socket,
  13537. std::chrono::time_point<std::chrono::steady_clock> start_time,
  13538. Response &res, bool &success, Error &error) {
  13539. if (!is_proxy_enabled_for_host(host_)) { return true; }
  13540. if (!connect_with_proxy(socket, start_time, res, success, error)) {
  13541. return false;
  13542. }
  13543. if (!initialize_ssl(socket, error)) {
  13544. success = false;
  13545. return false;
  13546. }
  13547. return true;
  13548. }
  13549. // Assumes that socket_mutex_ is locked and that there are no requests in
  13550. // flight
  13551. inline bool SSLClient::connect_with_proxy(
  13552. Socket &socket,
  13553. std::chrono::time_point<std::chrono::steady_clock> start_time,
  13554. Response &res, bool &success, Error &error) {
  13555. success = true;
  13556. Response proxy_res;
  13557. if (!detail::process_client_socket(
  13558. socket.sock, read_timeout_sec_, read_timeout_usec_,
  13559. write_timeout_sec_, write_timeout_usec_, max_timeout_msec_,
  13560. start_time, [&](Stream &strm) {
  13561. Request req2;
  13562. req2.method = "CONNECT";
  13563. req2.path =
  13564. detail::make_host_and_port_string_always_port(host_, port_);
  13565. if (max_timeout_msec_ > 0) {
  13566. req2.start_time_ = std::chrono::steady_clock::now();
  13567. }
  13568. return process_request(strm, req2, proxy_res, false, error);
  13569. })) {
  13570. // Thread-safe to close everything because we are assuming there are no
  13571. // requests in flight
  13572. shutdown_ssl(socket, true);
  13573. shutdown_socket(socket);
  13574. close_socket(socket);
  13575. success = false;
  13576. return false;
  13577. }
  13578. if (proxy_res.status == StatusCode::ProxyAuthenticationRequired_407) {
  13579. if (!proxy_digest_auth_username_.empty() &&
  13580. !proxy_digest_auth_password_.empty()) {
  13581. std::map<std::string, std::string> auth;
  13582. if (detail::parse_www_authenticate(proxy_res, auth, true)) {
  13583. // Close the current socket and create a new one for the authenticated
  13584. // request
  13585. shutdown_ssl(socket, true);
  13586. shutdown_socket(socket);
  13587. close_socket(socket);
  13588. // Create a new socket for the authenticated CONNECT request
  13589. if (!ensure_socket_connection(socket, error)) {
  13590. success = false;
  13591. output_error_log(error, nullptr);
  13592. return false;
  13593. }
  13594. proxy_res = Response();
  13595. if (!detail::process_client_socket(
  13596. socket.sock, read_timeout_sec_, read_timeout_usec_,
  13597. write_timeout_sec_, write_timeout_usec_, max_timeout_msec_,
  13598. start_time, [&](Stream &strm) {
  13599. Request req3;
  13600. req3.method = "CONNECT";
  13601. req3.path = detail::make_host_and_port_string_always_port(
  13602. host_, port_);
  13603. req3.headers.insert(detail::make_digest_authentication_header(
  13604. req3, auth, 1, detail::random_string(10),
  13605. proxy_digest_auth_username_, proxy_digest_auth_password_,
  13606. true));
  13607. if (max_timeout_msec_ > 0) {
  13608. req3.start_time_ = std::chrono::steady_clock::now();
  13609. }
  13610. return process_request(strm, req3, proxy_res, false, error);
  13611. })) {
  13612. // Thread-safe to close everything because we are assuming there are
  13613. // no requests in flight
  13614. shutdown_ssl(socket, true);
  13615. shutdown_socket(socket);
  13616. close_socket(socket);
  13617. success = false;
  13618. return false;
  13619. }
  13620. }
  13621. }
  13622. }
  13623. // If status code is not 200, proxy request is failed.
  13624. // Set error to ProxyConnection and return proxy response
  13625. // as the response of the request
  13626. if (proxy_res.status != StatusCode::OK_200) {
  13627. error = Error::ProxyConnection;
  13628. output_error_log(error, nullptr);
  13629. res = std::move(proxy_res);
  13630. // Thread-safe to close everything because we are assuming there are
  13631. // no requests in flight
  13632. shutdown_ssl(socket, true);
  13633. shutdown_socket(socket);
  13634. close_socket(socket);
  13635. return false;
  13636. }
  13637. return true;
  13638. }
  13639. inline bool SSLClient::ensure_socket_connection(Socket &socket, Error &error) {
  13640. if (!ClientImpl::ensure_socket_connection(socket, error)) { return false; }
  13641. if (is_proxy_enabled_for_host(host_)) { return true; }
  13642. if (!initialize_ssl(socket, error)) {
  13643. shutdown_socket(socket);
  13644. close_socket(socket);
  13645. return false;
  13646. }
  13647. return true;
  13648. }
  13649. // SSL HTTP client implementation
  13650. inline SSLClient::SSLClient(const std::string &host)
  13651. : SSLClient(host, 443, std::string(), std::string()) {}
  13652. inline SSLClient::SSLClient(const std::string &host, int port)
  13653. : SSLClient(host, port, std::string(), std::string()) {}
  13654. inline void SSLClient::init_ctx() {
  13655. ctx_ = tls::create_client_context();
  13656. if (ctx_) { tls::set_min_version(ctx_, tls::Version::TLS1_2); }
  13657. }
  13658. inline void SSLClient::reset_ctx_on_error() {
  13659. last_backend_error_ = tls::get_error();
  13660. tls::free_context(ctx_);
  13661. ctx_ = nullptr;
  13662. }
  13663. inline SSLClient::SSLClient(const std::string &host, int port,
  13664. const std::string &client_cert_path,
  13665. const std::string &client_key_path,
  13666. const std::string &private_key_password)
  13667. : ClientImpl(host, port, client_cert_path, client_key_path) {
  13668. init_ctx();
  13669. if (!ctx_) { return; }
  13670. if (!client_cert_path.empty() && !client_key_path.empty()) {
  13671. const char *password =
  13672. private_key_password.empty() ? nullptr : private_key_password.c_str();
  13673. if (!tls::set_client_cert_file(ctx_, client_cert_path.c_str(),
  13674. client_key_path.c_str(), password)) {
  13675. reset_ctx_on_error();
  13676. }
  13677. }
  13678. }
  13679. inline SSLClient::SSLClient(const std::string &host, int port,
  13680. const PemMemory &pem)
  13681. : ClientImpl(host, port) {
  13682. init_ctx();
  13683. if (!ctx_) { return; }
  13684. if (pem.cert_pem && pem.key_pem) {
  13685. if (!tls::set_client_cert_pem(ctx_, pem.cert_pem, pem.key_pem,
  13686. pem.private_key_password)) {
  13687. reset_ctx_on_error();
  13688. }
  13689. }
  13690. }
  13691. inline void SSLClient::set_ca_cert_store(tls::ca_store_t ca_cert_store) {
  13692. if (ca_cert_store && ctx_) {
  13693. // set_ca_store takes ownership of ca_cert_store
  13694. tls::set_ca_store(ctx_, ca_cert_store);
  13695. ca_cert_store_set_ = true;
  13696. } else if (ca_cert_store) {
  13697. tls::free_ca_store(ca_cert_store);
  13698. }
  13699. }
  13700. inline void
  13701. SSLClient::set_server_certificate_verifier(tls::VerifyCallback verifier) {
  13702. if (!ctx_) { return; }
  13703. tls::set_verify_callback(ctx_, verifier);
  13704. }
  13705. inline void SSLClient::set_session_verifier(
  13706. std::function<SSLVerifierResponse(tls::session_t)> verifier) {
  13707. session_verifier_ = std::move(verifier);
  13708. }
  13709. #ifdef CPPHTTPLIB_WINDOWS_AUTOMATIC_ROOT_CERTIFICATES_UPDATE
  13710. inline void SSLClient::enable_windows_certificate_verification(bool enabled) {
  13711. enable_windows_cert_verification_ = enabled;
  13712. }
  13713. #endif
  13714. inline void SSLClient::load_ca_cert_store(const char *ca_cert,
  13715. std::size_t size) {
  13716. if (ctx_ && ca_cert && size > 0) {
  13717. ca_cert_pem_.assign(ca_cert, size); // Store for redirect transfer
  13718. tls::load_ca_pem(ctx_, ca_cert, size);
  13719. }
  13720. }
  13721. inline bool SSLClient::load_certs() {
  13722. auto ret = true;
  13723. std::call_once(initialize_cert_, [&]() {
  13724. std::lock_guard<std::mutex> guard(ctx_mutex_);
  13725. ret = detail::load_client_ca_config(
  13726. ctx_, ca_cert_file_path_, ca_cert_dir_path_,
  13727. !ca_cert_pem_.empty() || ca_cert_store_set_, system_ca_mode_,
  13728. last_backend_error_);
  13729. });
  13730. return ret;
  13731. }
  13732. inline bool SSLClient::initialize_ssl(Socket &socket, Error &error) {
  13733. using namespace tls;
  13734. // Load CA certificates if server verification is enabled
  13735. if (server_certificate_verification_) {
  13736. if (!load_certs()) {
  13737. error = Error::SSLLoadingCerts;
  13738. output_error_log(error, nullptr);
  13739. return false;
  13740. }
  13741. }
  13742. bool is_ip = detail::is_ip_address(host_);
  13743. #if defined(CPPHTTPLIB_MBEDTLS_SUPPORT) || defined(CPPHTTPLIB_WOLFSSL_SUPPORT)
  13744. // MbedTLS/wolfSSL need explicit verification mode (OpenSSL uses
  13745. // SSL_VERIFY_NONE by default and performs all verification post-handshake).
  13746. // Chain verification happens during the handshake even for IP hosts; the
  13747. // certificate identity is verified post-handshake via verify_hostname().
  13748. set_verify_client(ctx_, server_certificate_verification_);
  13749. #endif
  13750. // Create TLS session
  13751. session_t session = nullptr;
  13752. {
  13753. std::lock_guard<std::mutex> guard(ctx_mutex_);
  13754. session = create_session(ctx_, socket.sock);
  13755. }
  13756. if (!session) {
  13757. error = Error::SSLConnection;
  13758. last_backend_error_ = get_error();
  13759. return false;
  13760. }
  13761. // Use scope_exit to ensure session is freed on error paths
  13762. bool success = false;
  13763. auto session_guard = detail::scope_exit([&] {
  13764. if (!success) { free_session(session); }
  13765. });
  13766. // Set SNI extension (skip for IP addresses per RFC 6066).
  13767. // On MbedTLS, set_sni also enables hostname verification internally.
  13768. // On OpenSSL, set_sni only sets SNI; verification is done post-handshake.
  13769. if (!is_ip) {
  13770. if (!set_sni(session, host_.c_str())) {
  13771. error = Error::SSLConnection;
  13772. last_backend_error_ = get_error();
  13773. return false;
  13774. }
  13775. }
  13776. // Perform non-blocking TLS handshake with timeout
  13777. TlsError tls_err;
  13778. if (!connect_nonblocking(session, socket.sock, connection_timeout_sec_,
  13779. connection_timeout_usec_, &tls_err)) {
  13780. last_ssl_error_ = static_cast<int>(tls_err.code);
  13781. last_backend_error_ = tls_err.backend_code;
  13782. if (tls_err.code == ErrorCode::CertVerifyFailed) {
  13783. error = Error::SSLServerVerification;
  13784. } else if (tls_err.code == ErrorCode::HostnameMismatch) {
  13785. error = Error::SSLServerHostnameVerification;
  13786. } else {
  13787. error = Error::SSLConnection;
  13788. }
  13789. output_error_log(error, nullptr);
  13790. return false;
  13791. }
  13792. // Post-handshake session verifier callback
  13793. auto verification_status = SSLVerifierResponse::NoDecisionMade;
  13794. if (session_verifier_) { verification_status = session_verifier_(session); }
  13795. if (verification_status == SSLVerifierResponse::CertificateRejected) {
  13796. last_backend_error_ = get_error();
  13797. error = Error::SSLServerVerification;
  13798. output_error_log(error, nullptr);
  13799. return false;
  13800. }
  13801. // Default server certificate verification
  13802. if (verification_status == SSLVerifierResponse::NoDecisionMade &&
  13803. server_certificate_verification_) {
  13804. verify_result_ = tls::get_verify_result(session);
  13805. if (verify_result_ != 0) {
  13806. last_backend_error_ = static_cast<uint64_t>(verify_result_);
  13807. error = Error::SSLServerVerification;
  13808. output_error_log(error, nullptr);
  13809. return false;
  13810. }
  13811. auto server_cert = get_peer_cert(session);
  13812. if (!server_cert) {
  13813. last_backend_error_ = get_error();
  13814. error = Error::SSLServerVerification;
  13815. output_error_log(error, nullptr);
  13816. return false;
  13817. }
  13818. auto cert_guard = detail::scope_exit([&] { free_cert(server_cert); });
  13819. // Hostname verification (post-handshake for all cases).
  13820. // On OpenSSL, verification is always post-handshake (SSL_VERIFY_NONE).
  13821. // On MbedTLS, set_sni already enabled hostname verification during
  13822. // handshake for non-IP hosts, but this check is still needed for IP
  13823. // addresses where SNI is not set.
  13824. if (server_hostname_verification_) {
  13825. if (!verify_hostname(server_cert, host_.c_str())) {
  13826. last_backend_error_ = hostname_mismatch_code();
  13827. error = Error::SSLServerHostnameVerification;
  13828. output_error_log(error, nullptr);
  13829. return false;
  13830. }
  13831. }
  13832. #ifdef CPPHTTPLIB_WINDOWS_AUTOMATIC_ROOT_CERTIFICATES_UPDATE
  13833. // Additional Windows Schannel verification.
  13834. // This provides real-time certificate validation with Windows Update
  13835. // integration, working with both OpenSSL and MbedTLS backends.
  13836. // Skip when a custom CA cert is specified, as the Windows certificate
  13837. // store would not know about user-provided CA certificates. Also skip
  13838. // when system CA trust is explicitly disabled.
  13839. if (enable_windows_cert_verification_ &&
  13840. system_ca_mode_ != SystemCAMode::Disabled &&
  13841. ca_cert_file_path_.empty() && ca_cert_dir_path_.empty() &&
  13842. ca_cert_pem_.empty() && !ca_cert_store_set_) {
  13843. std::vector<unsigned char> der;
  13844. if (get_cert_der(server_cert, der)) {
  13845. uint64_t wincrypt_error = 0;
  13846. if (!detail::verify_cert_with_windows_schannel(
  13847. der, host_, server_hostname_verification_, wincrypt_error)) {
  13848. last_backend_error_ = wincrypt_error;
  13849. error = Error::SSLServerVerification;
  13850. output_error_log(error, nullptr);
  13851. return false;
  13852. }
  13853. }
  13854. }
  13855. #endif
  13856. }
  13857. success = true;
  13858. socket.ssl = session;
  13859. return true;
  13860. }
  13861. inline void Client::set_digest_auth(const std::string &username,
  13862. const std::string &password) {
  13863. cli_->set_digest_auth(username, password);
  13864. }
  13865. inline void Client::set_proxy_digest_auth(const std::string &username,
  13866. const std::string &password) {
  13867. cli_->set_proxy_digest_auth(username, password);
  13868. }
  13869. inline void Client::enable_server_certificate_verification(bool enabled) {
  13870. cli_->enable_server_certificate_verification(enabled);
  13871. }
  13872. inline void Client::enable_server_hostname_verification(bool enabled) {
  13873. cli_->enable_server_hostname_verification(enabled);
  13874. }
  13875. inline void Client::enable_system_ca(bool enabled) {
  13876. cli_->enable_system_ca(enabled);
  13877. }
  13878. #ifdef CPPHTTPLIB_WINDOWS_AUTOMATIC_ROOT_CERTIFICATES_UPDATE
  13879. inline void Client::enable_windows_certificate_verification(bool enabled) {
  13880. if (is_ssl_) {
  13881. static_cast<SSLClient &>(*cli_).enable_windows_certificate_verification(
  13882. enabled);
  13883. }
  13884. }
  13885. #endif
  13886. inline void Client::set_ca_cert_path(const std::string &ca_cert_file_path,
  13887. const std::string &ca_cert_dir_path) {
  13888. cli_->set_ca_cert_path(ca_cert_file_path, ca_cert_dir_path);
  13889. }
  13890. inline void Client::set_ca_cert_store(tls::ca_store_t ca_cert_store) {
  13891. if (is_ssl_) {
  13892. static_cast<SSLClient &>(*cli_).set_ca_cert_store(ca_cert_store);
  13893. } else if (ca_cert_store) {
  13894. tls::free_ca_store(ca_cert_store);
  13895. }
  13896. }
  13897. inline void Client::load_ca_cert_store(const char *ca_cert, std::size_t size) {
  13898. if (is_ssl_) {
  13899. // Use the PEM-based path so the CA data is retained for redirect transfer
  13900. static_cast<SSLClient &>(*cli_).load_ca_cert_store(ca_cert, size);
  13901. }
  13902. }
  13903. inline void
  13904. Client::set_server_certificate_verifier(tls::VerifyCallback verifier) {
  13905. if (is_ssl_) {
  13906. static_cast<SSLClient &>(*cli_).set_server_certificate_verifier(
  13907. std::move(verifier));
  13908. }
  13909. }
  13910. inline void Client::set_session_verifier(
  13911. std::function<SSLVerifierResponse(tls::session_t)> verifier) {
  13912. if (is_ssl_) {
  13913. static_cast<SSLClient &>(*cli_).set_session_verifier(std::move(verifier));
  13914. }
  13915. }
  13916. inline tls::ctx_t Client::tls_context() const {
  13917. if (is_ssl_) { return static_cast<SSLClient &>(*cli_).tls_context(); }
  13918. return nullptr;
  13919. }
  13920. #endif // CPPHTTPLIB_SSL_ENABLED
  13921. /*
  13922. * Group 7: TLS abstraction layer - Common API
  13923. */
  13924. #ifdef CPPHTTPLIB_SSL_ENABLED
  13925. namespace tls {
  13926. // Helper for PeerCert construction
  13927. inline PeerCert get_peer_cert_from_session(const_session_t session) {
  13928. return PeerCert(get_peer_cert(session));
  13929. }
  13930. namespace impl {
  13931. inline VerifyCallback &get_verify_callback() {
  13932. static thread_local VerifyCallback callback;
  13933. return callback;
  13934. }
  13935. inline VerifyCallback &get_mbedtls_verify_callback() {
  13936. static thread_local VerifyCallback callback;
  13937. return callback;
  13938. }
  13939. // Check if a string is an IPv4 address
  13940. inline bool is_ipv4_address(const std::string &str) {
  13941. int dots = 0;
  13942. for (char c : str) {
  13943. if (c == '.') {
  13944. dots++;
  13945. } else if (!isdigit(static_cast<unsigned char>(c))) {
  13946. return false;
  13947. }
  13948. }
  13949. return dots == 3;
  13950. }
  13951. // Parse IPv4 address string to bytes
  13952. inline bool parse_ipv4(const std::string &str, unsigned char *out) {
  13953. const char *p = str.c_str();
  13954. for (int i = 0; i < 4; i++) {
  13955. if (i > 0) {
  13956. if (*p != '.') { return false; }
  13957. p++;
  13958. }
  13959. int val = 0;
  13960. int digits = 0;
  13961. while (*p >= '0' && *p <= '9') {
  13962. val = val * 10 + (*p - '0');
  13963. if (val > 255) { return false; }
  13964. p++;
  13965. digits++;
  13966. }
  13967. if (digits == 0) { return false; }
  13968. // Reject leading zeros (e.g., "01.002.03.04") to prevent ambiguity
  13969. if (digits > 1 && *(p - digits) == '0') { return false; }
  13970. out[i] = static_cast<unsigned char>(val);
  13971. }
  13972. return *p == '\0';
  13973. }
  13974. #ifdef _WIN32
  13975. // Enumerate Windows system certificates and call callback with DER data
  13976. template <typename Callback>
  13977. inline bool enumerate_windows_system_certs(Callback cb) {
  13978. bool loaded = false;
  13979. static const wchar_t *store_names[] = {L"ROOT", L"CA"};
  13980. for (auto store_name : store_names) {
  13981. HCERTSTORE hStore = CertOpenSystemStoreW(0, store_name);
  13982. if (hStore) {
  13983. PCCERT_CONTEXT pContext = nullptr;
  13984. while ((pContext = CertEnumCertificatesInStore(hStore, pContext)) !=
  13985. nullptr) {
  13986. if (cb(pContext->pbCertEncoded, pContext->cbCertEncoded)) {
  13987. loaded = true;
  13988. }
  13989. }
  13990. CertCloseStore(hStore, 0);
  13991. }
  13992. }
  13993. return loaded;
  13994. }
  13995. #endif
  13996. #ifdef CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN
  13997. // Enumerate macOS Keychain certificates and call callback with DER data
  13998. template <typename Callback>
  13999. inline bool enumerate_macos_keychain_certs(Callback cb) {
  14000. bool loaded = false;
  14001. const SecTrustSettingsDomain domains[] = {
  14002. kSecTrustSettingsDomainSystem,
  14003. kSecTrustSettingsDomainAdmin,
  14004. kSecTrustSettingsDomainUser,
  14005. };
  14006. for (auto domain : domains) {
  14007. CFArrayRef certs = nullptr;
  14008. OSStatus status = SecTrustSettingsCopyCertificates(domain, &certs);
  14009. if (status != errSecSuccess || !certs) {
  14010. if (certs) CFRelease(certs);
  14011. continue;
  14012. }
  14013. CFIndex count = CFArrayGetCount(certs);
  14014. for (CFIndex i = 0; i < count; i++) {
  14015. SecCertificateRef cert =
  14016. (SecCertificateRef)CFArrayGetValueAtIndex(certs, i);
  14017. CFDataRef data = SecCertificateCopyData(cert);
  14018. if (data) {
  14019. if (cb(CFDataGetBytePtr(data),
  14020. static_cast<size_t>(CFDataGetLength(data)))) {
  14021. loaded = true;
  14022. }
  14023. CFRelease(data);
  14024. }
  14025. }
  14026. CFRelease(certs);
  14027. }
  14028. return loaded;
  14029. }
  14030. #endif
  14031. #if !defined(_WIN32) && !(defined(__APPLE__) && \
  14032. defined(CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN))
  14033. // Common CA certificate file paths on Linux/Unix
  14034. inline const char **system_ca_paths() {
  14035. static const char *paths[] = {
  14036. "/etc/ssl/certs/ca-certificates.crt", // Debian/Ubuntu
  14037. "/etc/pki/tls/certs/ca-bundle.crt", // RHEL/CentOS
  14038. "/etc/ssl/ca-bundle.pem", // OpenSUSE
  14039. "/etc/pki/tls/cacert.pem", // OpenELEC
  14040. "/etc/ssl/cert.pem", // Alpine, FreeBSD
  14041. nullptr};
  14042. return paths;
  14043. }
  14044. // Common CA certificate directory paths on Linux/Unix
  14045. inline const char **system_ca_dirs() {
  14046. static const char *dirs[] = {"/etc/ssl/certs", // Debian/Ubuntu
  14047. "/etc/pki/tls/certs", // RHEL/CentOS
  14048. "/usr/share/ca-certificates", // Other
  14049. nullptr};
  14050. return dirs;
  14051. }
  14052. #endif
  14053. } // namespace impl
  14054. inline bool set_client_ca_file(ctx_t ctx, const char *ca_file,
  14055. const char *ca_dir) {
  14056. if (!ctx) { return false; }
  14057. bool success = true;
  14058. if (ca_file && *ca_file) {
  14059. if (!load_ca_file(ctx, ca_file)) { success = false; }
  14060. }
  14061. if (ca_dir && *ca_dir) {
  14062. if (!load_ca_dir(ctx, ca_dir)) { success = false; }
  14063. }
  14064. #ifdef CPPHTTPLIB_OPENSSL_SUPPORT
  14065. // Set CA list for client certificate request (CertificateRequest message)
  14066. if (ca_file && *ca_file) {
  14067. auto list = SSL_load_client_CA_file(ca_file);
  14068. if (list) { SSL_CTX_set_client_CA_list(static_cast<SSL_CTX *>(ctx), list); }
  14069. }
  14070. #endif
  14071. return success;
  14072. }
  14073. inline bool set_server_cert_pem(ctx_t ctx, const char *cert, const char *key,
  14074. const char *password) {
  14075. return set_client_cert_pem(ctx, cert, key, password);
  14076. }
  14077. inline bool set_server_cert_file(ctx_t ctx, const char *cert_path,
  14078. const char *key_path, const char *password) {
  14079. return set_client_cert_file(ctx, cert_path, key_path, password);
  14080. }
  14081. // PeerCert implementation
  14082. inline PeerCert::PeerCert() = default;
  14083. inline PeerCert::PeerCert(cert_t cert) : cert_(cert) {}
  14084. inline PeerCert::PeerCert(PeerCert &&other) noexcept : cert_(other.cert_) {
  14085. other.cert_ = nullptr;
  14086. }
  14087. inline PeerCert &PeerCert::operator=(PeerCert &&other) noexcept {
  14088. if (this != &other) {
  14089. if (cert_) { free_cert(cert_); }
  14090. cert_ = other.cert_;
  14091. other.cert_ = nullptr;
  14092. }
  14093. return *this;
  14094. }
  14095. inline PeerCert::~PeerCert() {
  14096. if (cert_) { free_cert(cert_); }
  14097. }
  14098. inline PeerCert::operator bool() const { return cert_ != nullptr; }
  14099. inline std::string PeerCert::subject_cn() const {
  14100. return cert_ ? get_cert_subject_cn(cert_) : std::string();
  14101. }
  14102. inline std::string PeerCert::issuer_name() const {
  14103. return cert_ ? get_cert_issuer_name(cert_) : std::string();
  14104. }
  14105. inline bool PeerCert::check_hostname(const char *hostname) const {
  14106. return cert_ ? verify_hostname(cert_, hostname) : false;
  14107. }
  14108. inline std::vector<SanEntry> PeerCert::sans() const {
  14109. std::vector<SanEntry> result;
  14110. if (cert_) { get_cert_sans(cert_, result); }
  14111. return result;
  14112. }
  14113. inline bool PeerCert::validity(time_t &not_before, time_t &not_after) const {
  14114. return cert_ ? get_cert_validity(cert_, not_before, not_after) : false;
  14115. }
  14116. inline std::string PeerCert::serial() const {
  14117. return cert_ ? get_cert_serial(cert_) : std::string();
  14118. }
  14119. // VerifyContext method implementations
  14120. inline std::string VerifyContext::subject_cn() const {
  14121. return cert ? get_cert_subject_cn(cert) : std::string();
  14122. }
  14123. inline std::string VerifyContext::issuer_name() const {
  14124. return cert ? get_cert_issuer_name(cert) : std::string();
  14125. }
  14126. inline bool VerifyContext::check_hostname(const char *hostname) const {
  14127. return cert ? verify_hostname(cert, hostname) : false;
  14128. }
  14129. inline std::vector<SanEntry> VerifyContext::sans() const {
  14130. std::vector<SanEntry> result;
  14131. if (cert) { get_cert_sans(cert, result); }
  14132. return result;
  14133. }
  14134. inline bool VerifyContext::validity(time_t &not_before,
  14135. time_t &not_after) const {
  14136. return cert ? get_cert_validity(cert, not_before, not_after) : false;
  14137. }
  14138. inline std::string VerifyContext::serial() const {
  14139. return cert ? get_cert_serial(cert) : std::string();
  14140. }
  14141. // TlsError static method implementation
  14142. inline std::string TlsError::verify_error_to_string(long error_code) {
  14143. return verify_error_string(error_code);
  14144. }
  14145. } // namespace tls
  14146. // Request::peer_cert() implementation
  14147. inline tls::PeerCert Request::peer_cert() const {
  14148. return tls::get_peer_cert_from_session(ssl);
  14149. }
  14150. // Request::sni() implementation
  14151. inline std::string Request::sni() const {
  14152. if (!ssl) { return std::string(); }
  14153. const char *s = tls::get_sni(ssl);
  14154. return s ? std::string(s) : std::string();
  14155. }
  14156. #endif // CPPHTTPLIB_SSL_ENABLED
  14157. /*
  14158. * Group 8: TLS abstraction layer - OpenSSL backend
  14159. */
  14160. /*
  14161. * OpenSSL Backend Implementation
  14162. */
  14163. #ifdef CPPHTTPLIB_OPENSSL_SUPPORT
  14164. namespace tls {
  14165. namespace impl {
  14166. // Helper to map OpenSSL SSL_get_error to ErrorCode
  14167. inline ErrorCode map_ssl_error(int ssl_error, int &out_errno) {
  14168. switch (ssl_error) {
  14169. case SSL_ERROR_NONE: return ErrorCode::Success;
  14170. case SSL_ERROR_WANT_READ: return ErrorCode::WantRead;
  14171. case SSL_ERROR_WANT_WRITE: return ErrorCode::WantWrite;
  14172. case SSL_ERROR_ZERO_RETURN: return ErrorCode::PeerClosed;
  14173. case SSL_ERROR_SYSCALL: out_errno = errno; return ErrorCode::SyscallError;
  14174. case SSL_ERROR_SSL:
  14175. default: return ErrorCode::Fatal;
  14176. }
  14177. }
  14178. // Helper: Create client CA list from PEM string
  14179. // Returns a new STACK_OF(X509_NAME)* or nullptr on failure
  14180. // Caller takes ownership of returned list
  14181. inline STACK_OF(X509_NAME) *
  14182. create_client_ca_list_from_pem(const char *ca_pem) {
  14183. if (!ca_pem) { return nullptr; }
  14184. auto ca_list = sk_X509_NAME_new_null();
  14185. if (!ca_list) { return nullptr; }
  14186. BIO *bio = BIO_new_mem_buf(ca_pem, -1);
  14187. if (!bio) {
  14188. sk_X509_NAME_pop_free(ca_list, X509_NAME_free);
  14189. return nullptr;
  14190. }
  14191. X509 *cert = nullptr;
  14192. while ((cert = PEM_read_bio_X509(bio, nullptr, nullptr, nullptr)) !=
  14193. nullptr) {
  14194. const X509_NAME *name = X509_get_subject_name(cert);
  14195. if (name) {
  14196. sk_X509_NAME_push(ca_list, X509_NAME_dup(const_cast<X509_NAME *>(name)));
  14197. }
  14198. X509_free(cert);
  14199. }
  14200. BIO_free(bio);
  14201. return ca_list;
  14202. }
  14203. // OpenSSL verify callback wrapper
  14204. inline int openssl_verify_callback(int preverify_ok, X509_STORE_CTX *ctx) {
  14205. auto &callback = get_verify_callback();
  14206. if (!callback) { return preverify_ok; }
  14207. // Get SSL object from X509_STORE_CTX
  14208. auto ssl = static_cast<SSL *>(
  14209. X509_STORE_CTX_get_ex_data(ctx, SSL_get_ex_data_X509_STORE_CTX_idx()));
  14210. if (!ssl) { return preverify_ok; }
  14211. // Get current certificate and depth
  14212. auto cert = X509_STORE_CTX_get_current_cert(ctx);
  14213. int depth = X509_STORE_CTX_get_error_depth(ctx);
  14214. int error = X509_STORE_CTX_get_error(ctx);
  14215. // Build context
  14216. VerifyContext verify_ctx;
  14217. verify_ctx.session = static_cast<session_t>(ssl);
  14218. verify_ctx.cert = static_cast<cert_t>(cert);
  14219. verify_ctx.depth = depth;
  14220. verify_ctx.preverify_ok = (preverify_ok != 0);
  14221. verify_ctx.error_code = error;
  14222. verify_ctx.error_string =
  14223. (error != X509_V_OK) ? X509_verify_cert_error_string(error) : nullptr;
  14224. return callback(verify_ctx) ? 1 : 0;
  14225. }
  14226. } // namespace impl
  14227. inline ctx_t create_client_context() {
  14228. SSL_CTX *ctx = SSL_CTX_new(TLS_client_method());
  14229. if (ctx) {
  14230. // Disable auto-retry to properly handle non-blocking I/O
  14231. SSL_CTX_clear_mode(ctx, SSL_MODE_AUTO_RETRY);
  14232. // Set minimum TLS version
  14233. SSL_CTX_set_min_proto_version(ctx, TLS1_2_VERSION);
  14234. }
  14235. return static_cast<ctx_t>(ctx);
  14236. }
  14237. inline void free_context(ctx_t ctx) {
  14238. if (ctx) { SSL_CTX_free(static_cast<SSL_CTX *>(ctx)); }
  14239. }
  14240. inline bool set_min_version(ctx_t ctx, Version version) {
  14241. if (!ctx) return false;
  14242. return SSL_CTX_set_min_proto_version(static_cast<SSL_CTX *>(ctx),
  14243. static_cast<int>(version)) == 1;
  14244. }
  14245. inline bool load_ca_pem(ctx_t ctx, const char *pem, size_t len) {
  14246. if (!ctx || !pem || len == 0) return false;
  14247. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14248. auto store = SSL_CTX_get_cert_store(ssl_ctx);
  14249. if (!store) return false;
  14250. auto bio = BIO_new_mem_buf(pem, static_cast<int>(len));
  14251. if (!bio) return false;
  14252. bool ok = true;
  14253. X509 *cert = nullptr;
  14254. while ((cert = PEM_read_bio_X509(bio, nullptr, nullptr, nullptr)) !=
  14255. nullptr) {
  14256. if (X509_STORE_add_cert(store, cert) != 1) {
  14257. // Ignore duplicate errors
  14258. auto err = ERR_peek_last_error();
  14259. if (ERR_GET_REASON(err) != X509_R_CERT_ALREADY_IN_HASH_TABLE) {
  14260. ok = false;
  14261. }
  14262. }
  14263. X509_free(cert);
  14264. if (!ok) break;
  14265. }
  14266. BIO_free(bio);
  14267. // Clear any "no more certificates" errors
  14268. ERR_clear_error();
  14269. return ok;
  14270. }
  14271. inline bool load_ca_file(ctx_t ctx, const char *file_path) {
  14272. if (!ctx || !file_path) return false;
  14273. return SSL_CTX_load_verify_locations(static_cast<SSL_CTX *>(ctx), file_path,
  14274. nullptr) == 1;
  14275. }
  14276. inline bool load_ca_dir(ctx_t ctx, const char *dir_path) {
  14277. if (!ctx || !dir_path) return false;
  14278. return SSL_CTX_load_verify_locations(static_cast<SSL_CTX *>(ctx), nullptr,
  14279. dir_path) == 1;
  14280. }
  14281. inline bool load_system_certs(ctx_t ctx) {
  14282. if (!ctx) return false;
  14283. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14284. #ifdef _WIN32
  14285. // Windows: Load from system certificate store (ROOT and CA)
  14286. auto store = SSL_CTX_get_cert_store(ssl_ctx);
  14287. if (!store) return false;
  14288. bool loaded_any = false;
  14289. static const wchar_t *store_names[] = {L"ROOT", L"CA"};
  14290. for (auto store_name : store_names) {
  14291. auto hStore = CertOpenSystemStoreW(NULL, store_name);
  14292. if (!hStore) continue;
  14293. PCCERT_CONTEXT pContext = nullptr;
  14294. while ((pContext = CertEnumCertificatesInStore(hStore, pContext)) !=
  14295. nullptr) {
  14296. const unsigned char *data = pContext->pbCertEncoded;
  14297. auto x509 = d2i_X509(nullptr, &data, pContext->cbCertEncoded);
  14298. if (x509) {
  14299. if (X509_STORE_add_cert(store, x509) == 1) { loaded_any = true; }
  14300. X509_free(x509);
  14301. }
  14302. }
  14303. CertCloseStore(hStore, 0);
  14304. }
  14305. return loaded_any;
  14306. #elif defined(__APPLE__)
  14307. #ifdef CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN
  14308. // macOS: Load from Keychain
  14309. auto store = SSL_CTX_get_cert_store(ssl_ctx);
  14310. if (!store) return false;
  14311. bool loaded_any = false;
  14312. const SecTrustSettingsDomain domains[] = {
  14313. kSecTrustSettingsDomainSystem,
  14314. kSecTrustSettingsDomainAdmin,
  14315. kSecTrustSettingsDomainUser,
  14316. };
  14317. for (auto domain : domains) {
  14318. CFArrayRef certs = nullptr;
  14319. if (SecTrustSettingsCopyCertificates(domain, &certs) != errSecSuccess ||
  14320. !certs) {
  14321. if (certs) CFRelease(certs);
  14322. continue;
  14323. }
  14324. auto count = CFArrayGetCount(certs);
  14325. for (CFIndex i = 0; i < count; i++) {
  14326. auto cert = reinterpret_cast<SecCertificateRef>(
  14327. const_cast<void *>(CFArrayGetValueAtIndex(certs, i)));
  14328. CFDataRef der = SecCertificateCopyData(cert);
  14329. if (der) {
  14330. const unsigned char *data = CFDataGetBytePtr(der);
  14331. auto x509 = d2i_X509(nullptr, &data, CFDataGetLength(der));
  14332. if (x509) {
  14333. if (X509_STORE_add_cert(store, x509) == 1) { loaded_any = true; }
  14334. X509_free(x509);
  14335. }
  14336. CFRelease(der);
  14337. }
  14338. }
  14339. CFRelease(certs);
  14340. }
  14341. return loaded_any || SSL_CTX_set_default_verify_paths(ssl_ctx) == 1;
  14342. #else
  14343. return SSL_CTX_set_default_verify_paths(ssl_ctx) == 1;
  14344. #endif
  14345. #else
  14346. // Other Unix: use default verify paths
  14347. return SSL_CTX_set_default_verify_paths(ssl_ctx) == 1;
  14348. #endif
  14349. }
  14350. inline bool set_client_cert_pem(ctx_t ctx, const char *cert, const char *key,
  14351. const char *password) {
  14352. if (!ctx || !cert || !key) return false;
  14353. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14354. // Load certificate
  14355. auto cert_bio = BIO_new_mem_buf(cert, -1);
  14356. if (!cert_bio) return false;
  14357. auto x509 = PEM_read_bio_X509(cert_bio, nullptr, nullptr, nullptr);
  14358. BIO_free(cert_bio);
  14359. if (!x509) return false;
  14360. auto cert_ok = SSL_CTX_use_certificate(ssl_ctx, x509) == 1;
  14361. X509_free(x509);
  14362. if (!cert_ok) return false;
  14363. // Load private key
  14364. auto key_bio = BIO_new_mem_buf(key, -1);
  14365. if (!key_bio) return false;
  14366. auto pkey = PEM_read_bio_PrivateKey(key_bio, nullptr, nullptr,
  14367. password ? const_cast<char *>(password)
  14368. : nullptr);
  14369. BIO_free(key_bio);
  14370. if (!pkey) return false;
  14371. auto key_ok = SSL_CTX_use_PrivateKey(ssl_ctx, pkey) == 1;
  14372. EVP_PKEY_free(pkey);
  14373. return key_ok && SSL_CTX_check_private_key(ssl_ctx) == 1;
  14374. }
  14375. inline bool set_client_cert_file(ctx_t ctx, const char *cert_path,
  14376. const char *key_path, const char *password) {
  14377. if (!ctx || !cert_path || !key_path) return false;
  14378. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14379. if (password && password[0] != '\0') {
  14380. SSL_CTX_set_default_passwd_cb_userdata(
  14381. ssl_ctx, reinterpret_cast<void *>(const_cast<char *>(password)));
  14382. }
  14383. return SSL_CTX_use_certificate_chain_file(ssl_ctx, cert_path) == 1 &&
  14384. SSL_CTX_use_PrivateKey_file(ssl_ctx, key_path, SSL_FILETYPE_PEM) == 1;
  14385. }
  14386. inline ctx_t create_server_context() {
  14387. SSL_CTX *ctx = SSL_CTX_new(TLS_server_method());
  14388. if (ctx) {
  14389. SSL_CTX_set_options(ctx, SSL_OP_NO_COMPRESSION |
  14390. SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION);
  14391. SSL_CTX_set_min_proto_version(ctx, TLS1_2_VERSION);
  14392. }
  14393. return static_cast<ctx_t>(ctx);
  14394. }
  14395. inline void set_verify_client(ctx_t ctx, bool require) {
  14396. if (!ctx) return;
  14397. SSL_CTX_set_verify(static_cast<SSL_CTX *>(ctx),
  14398. require
  14399. ? (SSL_VERIFY_PEER | SSL_VERIFY_FAIL_IF_NO_PEER_CERT)
  14400. : SSL_VERIFY_NONE,
  14401. nullptr);
  14402. }
  14403. inline session_t create_session(ctx_t ctx, socket_t sock) {
  14404. if (!ctx || sock == INVALID_SOCKET) return nullptr;
  14405. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14406. SSL *ssl = SSL_new(ssl_ctx);
  14407. if (!ssl) return nullptr;
  14408. // Disable auto-retry for proper non-blocking I/O handling
  14409. SSL_clear_mode(ssl, SSL_MODE_AUTO_RETRY);
  14410. auto bio = BIO_new_socket(static_cast<int>(sock), BIO_NOCLOSE);
  14411. if (!bio) {
  14412. SSL_free(ssl);
  14413. return nullptr;
  14414. }
  14415. SSL_set_bio(ssl, bio, bio);
  14416. return static_cast<session_t>(ssl);
  14417. }
  14418. inline void free_session(session_t session) {
  14419. if (session) { SSL_free(static_cast<SSL *>(session)); }
  14420. }
  14421. inline bool set_sni(session_t session, const char *hostname) {
  14422. if (!session || !hostname) return false;
  14423. auto ssl = static_cast<SSL *>(session);
  14424. // Set SNI (Server Name Indication) only - does not enable verification
  14425. #if defined(OPENSSL_IS_BORINGSSL)
  14426. return SSL_set_tlsext_host_name(ssl, hostname) == 1;
  14427. #else
  14428. // Direct call instead of macro to suppress -Wold-style-cast warning
  14429. return SSL_ctrl(ssl, SSL_CTRL_SET_TLSEXT_HOSTNAME, TLSEXT_NAMETYPE_host_name,
  14430. static_cast<void *>(const_cast<char *>(hostname))) == 1;
  14431. #endif
  14432. }
  14433. inline bool set_hostname(session_t session, const char *hostname) {
  14434. if (!session || !hostname) return false;
  14435. auto ssl = static_cast<SSL *>(session);
  14436. // Enable hostname verification
  14437. auto param = SSL_get0_param(ssl);
  14438. if (!param) return false;
  14439. if (detail::is_ip_address(hostname)) {
  14440. // RFC 6066: SNI must not be set for IP addresses; verify against the
  14441. // certificate's IP SANs instead of its DNS names
  14442. if (X509_VERIFY_PARAM_set1_ip_asc(param, hostname) != 1) { return false; }
  14443. } else {
  14444. // Set SNI (Server Name Indication)
  14445. if (!set_sni(session, hostname)) { return false; }
  14446. X509_VERIFY_PARAM_set_hostflags(param,
  14447. X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS);
  14448. if (X509_VERIFY_PARAM_set1_host(param, hostname, 0) != 1) { return false; }
  14449. }
  14450. SSL_set_verify(ssl, SSL_VERIFY_PEER, nullptr);
  14451. return true;
  14452. }
  14453. inline TlsError connect(session_t session) {
  14454. if (!session) { return TlsError(); }
  14455. auto ssl = static_cast<SSL *>(session);
  14456. auto ret = SSL_connect(ssl);
  14457. TlsError err;
  14458. if (ret == 1) {
  14459. err.code = ErrorCode::Success;
  14460. } else {
  14461. auto ssl_err = SSL_get_error(ssl, ret);
  14462. err.code = impl::map_ssl_error(ssl_err, err.sys_errno);
  14463. err.backend_code = ERR_get_error();
  14464. }
  14465. return err;
  14466. }
  14467. inline TlsError accept(session_t session) {
  14468. if (!session) { return TlsError(); }
  14469. auto ssl = static_cast<SSL *>(session);
  14470. auto ret = SSL_accept(ssl);
  14471. TlsError err;
  14472. if (ret == 1) {
  14473. err.code = ErrorCode::Success;
  14474. } else {
  14475. auto ssl_err = SSL_get_error(ssl, ret);
  14476. err.code = impl::map_ssl_error(ssl_err, err.sys_errno);
  14477. err.backend_code = ERR_get_error();
  14478. }
  14479. return err;
  14480. }
  14481. inline bool connect_nonblocking(session_t session, socket_t sock,
  14482. time_t timeout_sec, time_t timeout_usec,
  14483. TlsError *err) {
  14484. if (!session) {
  14485. if (err) { err->code = ErrorCode::Fatal; }
  14486. return false;
  14487. }
  14488. auto ssl = static_cast<SSL *>(session);
  14489. auto bio = SSL_get_rbio(ssl);
  14490. // Set non-blocking mode for handshake
  14491. detail::set_nonblocking(sock, true);
  14492. if (bio) { BIO_set_nbio(bio, 1); }
  14493. auto cleanup = detail::scope_exit([&]() {
  14494. // Restore blocking mode after handshake
  14495. if (bio) { BIO_set_nbio(bio, 0); }
  14496. detail::set_nonblocking(sock, false);
  14497. });
  14498. auto res = 0;
  14499. while ((res = SSL_connect(ssl)) != 1) {
  14500. auto ssl_err = SSL_get_error(ssl, res);
  14501. switch (ssl_err) {
  14502. case SSL_ERROR_WANT_READ:
  14503. if (detail::select_read(sock, timeout_sec, timeout_usec) > 0) {
  14504. continue;
  14505. }
  14506. break;
  14507. case SSL_ERROR_WANT_WRITE:
  14508. if (detail::select_write(sock, timeout_sec, timeout_usec) > 0) {
  14509. continue;
  14510. }
  14511. break;
  14512. default: break;
  14513. }
  14514. if (err) {
  14515. err->code = impl::map_ssl_error(ssl_err, err->sys_errno);
  14516. err->backend_code = ERR_get_error();
  14517. }
  14518. return false;
  14519. }
  14520. if (err) { err->code = ErrorCode::Success; }
  14521. return true;
  14522. }
  14523. inline bool accept_nonblocking(session_t session, socket_t sock,
  14524. time_t timeout_sec, time_t timeout_usec,
  14525. TlsError *err) {
  14526. if (!session) {
  14527. if (err) { err->code = ErrorCode::Fatal; }
  14528. return false;
  14529. }
  14530. auto ssl = static_cast<SSL *>(session);
  14531. auto bio = SSL_get_rbio(ssl);
  14532. // Set non-blocking mode for handshake
  14533. detail::set_nonblocking(sock, true);
  14534. if (bio) { BIO_set_nbio(bio, 1); }
  14535. auto cleanup = detail::scope_exit([&]() {
  14536. // Restore blocking mode after handshake
  14537. if (bio) { BIO_set_nbio(bio, 0); }
  14538. detail::set_nonblocking(sock, false);
  14539. });
  14540. auto res = 0;
  14541. while ((res = SSL_accept(ssl)) != 1) {
  14542. auto ssl_err = SSL_get_error(ssl, res);
  14543. switch (ssl_err) {
  14544. case SSL_ERROR_WANT_READ:
  14545. if (detail::select_read(sock, timeout_sec, timeout_usec) > 0) {
  14546. continue;
  14547. }
  14548. break;
  14549. case SSL_ERROR_WANT_WRITE:
  14550. if (detail::select_write(sock, timeout_sec, timeout_usec) > 0) {
  14551. continue;
  14552. }
  14553. break;
  14554. default: break;
  14555. }
  14556. if (err) {
  14557. err->code = impl::map_ssl_error(ssl_err, err->sys_errno);
  14558. err->backend_code = ERR_get_error();
  14559. }
  14560. return false;
  14561. }
  14562. if (err) { err->code = ErrorCode::Success; }
  14563. return true;
  14564. }
  14565. inline ssize_t read(session_t session, void *buf, size_t len, TlsError &err) {
  14566. if (!session || !buf) {
  14567. err.code = ErrorCode::Fatal;
  14568. return -1;
  14569. }
  14570. auto ssl = static_cast<SSL *>(session);
  14571. constexpr auto max_len =
  14572. static_cast<size_t>((std::numeric_limits<int>::max)());
  14573. if (len > max_len) { len = max_len; }
  14574. auto ret = SSL_read(ssl, buf, static_cast<int>(len));
  14575. if (ret > 0) {
  14576. err.code = ErrorCode::Success;
  14577. return ret;
  14578. }
  14579. auto ssl_err = SSL_get_error(ssl, ret);
  14580. err.code = impl::map_ssl_error(ssl_err, err.sys_errno);
  14581. if (err.code == ErrorCode::PeerClosed) {
  14582. return 0;
  14583. } // Gracefully handle the peer closed state.
  14584. if (err.code == ErrorCode::Fatal) { err.backend_code = ERR_get_error(); }
  14585. return -1;
  14586. }
  14587. inline ssize_t write(session_t session, const void *buf, size_t len,
  14588. TlsError &err) {
  14589. if (!session || !buf) {
  14590. err.code = ErrorCode::Fatal;
  14591. return -1;
  14592. }
  14593. auto ssl = static_cast<SSL *>(session);
  14594. auto ret = SSL_write(ssl, buf, static_cast<int>(len));
  14595. if (ret > 0) {
  14596. err.code = ErrorCode::Success;
  14597. return ret;
  14598. }
  14599. auto ssl_err = SSL_get_error(ssl, ret);
  14600. err.code = impl::map_ssl_error(ssl_err, err.sys_errno);
  14601. if (err.code == ErrorCode::Fatal) { err.backend_code = ERR_get_error(); }
  14602. return -1;
  14603. }
  14604. inline int pending(const_session_t session) {
  14605. if (!session) return 0;
  14606. return SSL_pending(static_cast<SSL *>(const_cast<void *>(session)));
  14607. }
  14608. inline void shutdown(session_t session, bool graceful) {
  14609. if (!session) return;
  14610. auto ssl = static_cast<SSL *>(session);
  14611. if (graceful) {
  14612. // First call sends close_notify
  14613. if (SSL_shutdown(ssl) == 0) {
  14614. // Second call waits for peer's close_notify
  14615. SSL_shutdown(ssl);
  14616. }
  14617. }
  14618. }
  14619. inline bool is_peer_closed(session_t session, socket_t sock) {
  14620. if (!session) return true;
  14621. // Temporarily set socket to non-blocking to avoid blocking on SSL_peek
  14622. detail::set_nonblocking(sock, true);
  14623. auto se = detail::scope_exit([&]() { detail::set_nonblocking(sock, false); });
  14624. auto ssl = static_cast<SSL *>(session);
  14625. char buf;
  14626. auto ret = SSL_peek(ssl, &buf, 1);
  14627. if (ret > 0) return false;
  14628. auto err = SSL_get_error(ssl, ret);
  14629. return err == SSL_ERROR_ZERO_RETURN;
  14630. }
  14631. inline cert_t get_peer_cert(const_session_t session) {
  14632. if (!session) return nullptr;
  14633. return static_cast<cert_t>(SSL_get1_peer_certificate(
  14634. static_cast<SSL *>(const_cast<void *>(session))));
  14635. }
  14636. inline void free_cert(cert_t cert) {
  14637. if (cert) { X509_free(static_cast<X509 *>(cert)); }
  14638. }
  14639. inline bool verify_hostname(cert_t cert, const char *hostname) {
  14640. if (!cert || !hostname) return false;
  14641. auto x509 = static_cast<X509 *>(cert);
  14642. // Use X509_check_ip_asc for IP addresses, X509_check_host for DNS names
  14643. if (detail::is_ip_address(hostname)) {
  14644. return X509_check_ip_asc(x509, hostname, 0) == 1;
  14645. }
  14646. return X509_check_host(x509, hostname, strlen(hostname), 0, nullptr) == 1;
  14647. }
  14648. inline uint64_t hostname_mismatch_code() {
  14649. return static_cast<uint64_t>(X509_V_ERR_HOSTNAME_MISMATCH);
  14650. }
  14651. inline long get_verify_result(const_session_t session) {
  14652. if (!session) return X509_V_ERR_UNSPECIFIED;
  14653. return SSL_get_verify_result(static_cast<SSL *>(const_cast<void *>(session)));
  14654. }
  14655. inline std::string get_cert_subject_cn(cert_t cert) {
  14656. if (!cert) return "";
  14657. auto x509 = static_cast<X509 *>(cert);
  14658. auto subject_name = X509_get_subject_name(x509);
  14659. if (!subject_name) return "";
  14660. char buf[256];
  14661. auto len =
  14662. X509_NAME_get_text_by_NID(subject_name, NID_commonName, buf, sizeof(buf));
  14663. if (len < 0) return "";
  14664. return std::string(buf, static_cast<size_t>(len));
  14665. }
  14666. inline std::string get_cert_issuer_name(cert_t cert) {
  14667. if (!cert) return "";
  14668. auto x509 = static_cast<X509 *>(cert);
  14669. auto issuer_name = X509_get_issuer_name(x509);
  14670. if (!issuer_name) return "";
  14671. char buf[256];
  14672. X509_NAME_oneline(issuer_name, buf, sizeof(buf));
  14673. return std::string(buf);
  14674. }
  14675. inline bool get_cert_sans(cert_t cert, std::vector<SanEntry> &sans) {
  14676. sans.clear();
  14677. if (!cert) return false;
  14678. auto x509 = static_cast<X509 *>(cert);
  14679. auto names = static_cast<GENERAL_NAMES *>(
  14680. X509_get_ext_d2i(x509, NID_subject_alt_name, nullptr, nullptr));
  14681. if (!names) return true; // No SANs is valid
  14682. auto count = sk_GENERAL_NAME_num(names);
  14683. for (decltype(count) i = 0; i < count; i++) {
  14684. auto gen = sk_GENERAL_NAME_value(names, i);
  14685. if (!gen) continue;
  14686. SanEntry entry;
  14687. switch (gen->type) {
  14688. case GEN_DNS:
  14689. entry.type = SanType::DNS;
  14690. if (gen->d.dNSName) {
  14691. entry.value = std::string(
  14692. reinterpret_cast<const char *>(
  14693. ASN1_STRING_get0_data(gen->d.dNSName)),
  14694. static_cast<size_t>(ASN1_STRING_length(gen->d.dNSName)));
  14695. }
  14696. break;
  14697. case GEN_IPADD:
  14698. entry.type = SanType::IP;
  14699. if (gen->d.iPAddress) {
  14700. auto data = ASN1_STRING_get0_data(gen->d.iPAddress);
  14701. auto len = ASN1_STRING_length(gen->d.iPAddress);
  14702. if (len == 4) {
  14703. // IPv4
  14704. char buf[INET_ADDRSTRLEN];
  14705. inet_ntop(AF_INET, data, buf, sizeof(buf));
  14706. entry.value = buf;
  14707. } else if (len == 16) {
  14708. // IPv6
  14709. char buf[INET6_ADDRSTRLEN];
  14710. inet_ntop(AF_INET6, data, buf, sizeof(buf));
  14711. entry.value = buf;
  14712. }
  14713. }
  14714. break;
  14715. case GEN_EMAIL:
  14716. entry.type = SanType::EMAIL;
  14717. if (gen->d.rfc822Name) {
  14718. entry.value = std::string(
  14719. reinterpret_cast<const char *>(
  14720. ASN1_STRING_get0_data(gen->d.rfc822Name)),
  14721. static_cast<size_t>(ASN1_STRING_length(gen->d.rfc822Name)));
  14722. }
  14723. break;
  14724. case GEN_URI:
  14725. entry.type = SanType::URI;
  14726. if (gen->d.uniformResourceIdentifier) {
  14727. entry.value = std::string(
  14728. reinterpret_cast<const char *>(
  14729. ASN1_STRING_get0_data(gen->d.uniformResourceIdentifier)),
  14730. static_cast<size_t>(
  14731. ASN1_STRING_length(gen->d.uniformResourceIdentifier)));
  14732. }
  14733. break;
  14734. default: entry.type = SanType::OTHER; break;
  14735. }
  14736. if (!entry.value.empty()) { sans.push_back(std::move(entry)); }
  14737. }
  14738. GENERAL_NAMES_free(names);
  14739. return true;
  14740. }
  14741. inline bool get_cert_validity(cert_t cert, time_t &not_before,
  14742. time_t &not_after) {
  14743. if (!cert) return false;
  14744. auto x509 = static_cast<X509 *>(cert);
  14745. auto nb = X509_get0_notBefore(x509);
  14746. auto na = X509_get0_notAfter(x509);
  14747. if (!nb || !na) return false;
  14748. ASN1_TIME *epoch = ASN1_TIME_new();
  14749. if (!epoch) return false;
  14750. auto se = detail::scope_exit([&] { ASN1_TIME_free(epoch); });
  14751. if (!ASN1_TIME_set(epoch, 0)) return false;
  14752. int pday, psec;
  14753. if (!ASN1_TIME_diff(&pday, &psec, epoch, nb)) return false;
  14754. not_before = 86400 * (time_t)pday + psec;
  14755. if (!ASN1_TIME_diff(&pday, &psec, epoch, na)) return false;
  14756. not_after = 86400 * (time_t)pday + psec;
  14757. return true;
  14758. }
  14759. inline std::string get_cert_serial(cert_t cert) {
  14760. if (!cert) return "";
  14761. auto x509 = static_cast<X509 *>(cert);
  14762. auto serial = X509_get_serialNumber(x509);
  14763. if (!serial) return "";
  14764. auto bn = ASN1_INTEGER_to_BN(serial, nullptr);
  14765. if (!bn) return "";
  14766. auto hex = BN_bn2hex(bn);
  14767. BN_free(bn);
  14768. if (!hex) return "";
  14769. std::string result(hex);
  14770. OPENSSL_free(hex);
  14771. return result;
  14772. }
  14773. inline bool get_cert_der(cert_t cert, std::vector<unsigned char> &der) {
  14774. if (!cert) return false;
  14775. auto x509 = static_cast<X509 *>(cert);
  14776. auto len = i2d_X509(x509, nullptr);
  14777. if (len < 0) return false;
  14778. der.resize(static_cast<size_t>(len));
  14779. auto p = der.data();
  14780. i2d_X509(x509, &p);
  14781. return true;
  14782. }
  14783. inline const char *get_sni(const_session_t session) {
  14784. if (!session) return nullptr;
  14785. auto ssl = static_cast<SSL *>(const_cast<void *>(session));
  14786. return SSL_get_servername(ssl, TLSEXT_NAMETYPE_host_name);
  14787. }
  14788. inline uint64_t peek_error() { return ERR_peek_last_error(); }
  14789. inline uint64_t get_error() { return ERR_get_error(); }
  14790. inline std::string error_string(uint64_t code) {
  14791. char buf[256];
  14792. ERR_error_string_n(static_cast<unsigned long>(code), buf, sizeof(buf));
  14793. return std::string(buf);
  14794. }
  14795. inline ca_store_t create_ca_store(const char *pem, size_t len) {
  14796. auto mem = BIO_new_mem_buf(pem, static_cast<int>(len));
  14797. if (!mem) { return nullptr; }
  14798. auto mem_guard = detail::scope_exit([&] { BIO_free_all(mem); });
  14799. auto inf = PEM_X509_INFO_read_bio(mem, nullptr, nullptr, nullptr);
  14800. if (!inf) { return nullptr; }
  14801. auto store = X509_STORE_new();
  14802. if (store) {
  14803. for (auto i = 0; i < static_cast<int>(sk_X509_INFO_num(inf)); i++) {
  14804. auto itmp = sk_X509_INFO_value(inf, i);
  14805. if (!itmp) { continue; }
  14806. if (itmp->x509) { X509_STORE_add_cert(store, itmp->x509); }
  14807. if (itmp->crl) { X509_STORE_add_crl(store, itmp->crl); }
  14808. }
  14809. }
  14810. sk_X509_INFO_pop_free(inf, X509_INFO_free);
  14811. return static_cast<ca_store_t>(store);
  14812. }
  14813. inline void free_ca_store(ca_store_t store) {
  14814. if (store) { X509_STORE_free(static_cast<X509_STORE *>(store)); }
  14815. }
  14816. inline bool set_ca_store(ctx_t ctx, ca_store_t store) {
  14817. if (!ctx || !store) { return false; }
  14818. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14819. auto x509_store = static_cast<X509_STORE *>(store);
  14820. // Check if same store is already set
  14821. if (SSL_CTX_get_cert_store(ssl_ctx) == x509_store) { return true; }
  14822. // SSL_CTX_set_cert_store takes ownership and frees the old store
  14823. SSL_CTX_set_cert_store(ssl_ctx, x509_store);
  14824. return true;
  14825. }
  14826. inline size_t get_ca_certs(ctx_t ctx, std::vector<cert_t> &certs) {
  14827. certs.clear();
  14828. if (!ctx) { return 0; }
  14829. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14830. auto store = SSL_CTX_get_cert_store(ssl_ctx);
  14831. if (!store) { return 0; }
  14832. auto objs = X509_STORE_get0_objects(store);
  14833. if (!objs) { return 0; }
  14834. auto count = sk_X509_OBJECT_num(objs);
  14835. for (decltype(count) i = 0; i < count; i++) {
  14836. auto obj = sk_X509_OBJECT_value(objs, i);
  14837. if (!obj) { continue; }
  14838. if (X509_OBJECT_get_type(obj) == X509_LU_X509) {
  14839. auto x509 = X509_OBJECT_get0_X509(obj);
  14840. if (x509) {
  14841. // Increment reference count so caller can free it
  14842. X509_up_ref(x509);
  14843. certs.push_back(static_cast<cert_t>(x509));
  14844. }
  14845. }
  14846. }
  14847. return certs.size();
  14848. }
  14849. inline std::vector<std::string> get_ca_names(ctx_t ctx) {
  14850. std::vector<std::string> names;
  14851. if (!ctx) { return names; }
  14852. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14853. auto store = SSL_CTX_get_cert_store(ssl_ctx);
  14854. if (!store) { return names; }
  14855. auto objs = X509_STORE_get0_objects(store);
  14856. if (!objs) { return names; }
  14857. auto count = sk_X509_OBJECT_num(objs);
  14858. for (decltype(count) i = 0; i < count; i++) {
  14859. auto obj = sk_X509_OBJECT_value(objs, i);
  14860. if (!obj) { continue; }
  14861. if (X509_OBJECT_get_type(obj) == X509_LU_X509) {
  14862. auto x509 = X509_OBJECT_get0_X509(obj);
  14863. if (x509) {
  14864. auto subject = X509_get_subject_name(x509);
  14865. if (subject) {
  14866. char buf[512];
  14867. X509_NAME_oneline(subject, buf, sizeof(buf));
  14868. names.push_back(buf);
  14869. }
  14870. }
  14871. }
  14872. }
  14873. return names;
  14874. }
  14875. inline bool update_server_cert(ctx_t ctx, const char *cert_pem,
  14876. const char *key_pem, const char *password) {
  14877. if (!ctx || !cert_pem || !key_pem) { return false; }
  14878. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14879. // Load certificate from PEM
  14880. auto cert_bio = BIO_new_mem_buf(cert_pem, -1);
  14881. if (!cert_bio) { return false; }
  14882. auto cert = PEM_read_bio_X509(cert_bio, nullptr, nullptr, nullptr);
  14883. BIO_free(cert_bio);
  14884. if (!cert) { return false; }
  14885. // Load private key from PEM
  14886. auto key_bio = BIO_new_mem_buf(key_pem, -1);
  14887. if (!key_bio) {
  14888. X509_free(cert);
  14889. return false;
  14890. }
  14891. auto key = PEM_read_bio_PrivateKey(key_bio, nullptr, nullptr,
  14892. password ? const_cast<char *>(password)
  14893. : nullptr);
  14894. BIO_free(key_bio);
  14895. if (!key) {
  14896. X509_free(cert);
  14897. return false;
  14898. }
  14899. // Update certificate and key
  14900. auto ret = SSL_CTX_use_certificate(ssl_ctx, cert) == 1 &&
  14901. SSL_CTX_use_PrivateKey(ssl_ctx, key) == 1;
  14902. X509_free(cert);
  14903. EVP_PKEY_free(key);
  14904. return ret;
  14905. }
  14906. inline bool update_server_client_ca(ctx_t ctx, const char *ca_pem) {
  14907. if (!ctx || !ca_pem) { return false; }
  14908. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14909. // Create new X509_STORE from PEM
  14910. auto store = create_ca_store(ca_pem, strlen(ca_pem));
  14911. if (!store) { return false; }
  14912. // SSL_CTX_set_cert_store takes ownership
  14913. SSL_CTX_set_cert_store(ssl_ctx, static_cast<X509_STORE *>(store));
  14914. // Set client CA list for client certificate request
  14915. auto ca_list = impl::create_client_ca_list_from_pem(ca_pem);
  14916. if (ca_list) {
  14917. // SSL_CTX_set_client_CA_list takes ownership of ca_list
  14918. SSL_CTX_set_client_CA_list(ssl_ctx, ca_list);
  14919. }
  14920. return true;
  14921. }
  14922. inline bool set_verify_callback(ctx_t ctx, VerifyCallback callback) {
  14923. if (!ctx) { return false; }
  14924. auto ssl_ctx = static_cast<SSL_CTX *>(ctx);
  14925. impl::get_verify_callback() = std::move(callback);
  14926. if (impl::get_verify_callback()) {
  14927. SSL_CTX_set_verify(ssl_ctx, SSL_VERIFY_PEER, impl::openssl_verify_callback);
  14928. } else {
  14929. SSL_CTX_set_verify(ssl_ctx, SSL_VERIFY_PEER, nullptr);
  14930. }
  14931. return true;
  14932. }
  14933. inline long get_verify_error(const_session_t session) {
  14934. if (!session) { return -1; }
  14935. auto ssl = static_cast<SSL *>(const_cast<void *>(session));
  14936. return SSL_get_verify_result(ssl);
  14937. }
  14938. inline std::string verify_error_string(long error_code) {
  14939. if (error_code == X509_V_OK) { return ""; }
  14940. const char *str = X509_verify_cert_error_string(static_cast<int>(error_code));
  14941. return str ? str : "unknown error";
  14942. }
  14943. } // namespace tls
  14944. inline bool SSLClient::verify_host(X509 *server_cert) const {
  14945. /* Quote from RFC2818 section 3.1 "Server Identity"
  14946. If a subjectAltName extension of type dNSName is present, that MUST
  14947. be used as the identity. Otherwise, the (most specific) Common Name
  14948. field in the Subject field of the certificate MUST be used. Although
  14949. the use of the Common Name is existing practice, it is deprecated and
  14950. Certification Authorities are encouraged to use the dNSName instead.
  14951. Matching is performed using the matching rules specified by
  14952. [RFC2459]. If more than one identity of a given type is present in
  14953. the certificate (e.g., more than one dNSName name, a match in any one
  14954. of the set is considered acceptable.) Names may contain the wildcard
  14955. character * which is considered to match any single domain name
  14956. component or component fragment. E.g., *.a.com matches foo.a.com but
  14957. not bar.foo.a.com. f*.com matches foo.com but not bar.com.
  14958. In some cases, the URI is specified as an IP address rather than a
  14959. hostname. In this case, the iPAddress subjectAltName must be present
  14960. in the certificate and must exactly match the IP in the URI.
  14961. */
  14962. return verify_host_with_subject_alt_name(server_cert) ||
  14963. verify_host_with_common_name(server_cert);
  14964. }
  14965. inline bool
  14966. SSLClient::verify_host_with_subject_alt_name(X509 *server_cert) const {
  14967. auto ret = false;
  14968. auto type = GEN_DNS;
  14969. struct in6_addr addr6 = {};
  14970. struct in_addr addr = {};
  14971. size_t addr_len = 0;
  14972. #ifndef __MINGW32__
  14973. if (inet_pton(AF_INET6, host_.c_str(), &addr6)) {
  14974. type = GEN_IPADD;
  14975. addr_len = sizeof(struct in6_addr);
  14976. } else if (inet_pton(AF_INET, host_.c_str(), &addr)) {
  14977. type = GEN_IPADD;
  14978. addr_len = sizeof(struct in_addr);
  14979. }
  14980. #endif
  14981. auto alt_names = static_cast<const struct stack_st_GENERAL_NAME *>(
  14982. X509_get_ext_d2i(server_cert, NID_subject_alt_name, nullptr, nullptr));
  14983. if (alt_names) {
  14984. auto dsn_matched = false;
  14985. auto ip_matched = false;
  14986. auto count = sk_GENERAL_NAME_num(alt_names);
  14987. for (decltype(count) i = 0; i < count && !dsn_matched; i++) {
  14988. auto val = sk_GENERAL_NAME_value(alt_names, i);
  14989. if (!val || val->type != type) { continue; }
  14990. auto name =
  14991. reinterpret_cast<const char *>(ASN1_STRING_get0_data(val->d.ia5));
  14992. if (name == nullptr) { continue; }
  14993. auto name_len = static_cast<size_t>(ASN1_STRING_length(val->d.ia5));
  14994. switch (type) {
  14995. case GEN_DNS:
  14996. dsn_matched =
  14997. detail::match_hostname(std::string(name, name_len), host_);
  14998. break;
  14999. case GEN_IPADD:
  15000. if (!memcmp(&addr6, name, addr_len) || !memcmp(&addr, name, addr_len)) {
  15001. ip_matched = true;
  15002. }
  15003. break;
  15004. }
  15005. }
  15006. if (dsn_matched || ip_matched) { ret = true; }
  15007. }
  15008. GENERAL_NAMES_free(const_cast<STACK_OF(GENERAL_NAME) *>(
  15009. reinterpret_cast<const STACK_OF(GENERAL_NAME) *>(alt_names)));
  15010. return ret;
  15011. }
  15012. inline bool SSLClient::verify_host_with_common_name(X509 *server_cert) const {
  15013. const auto subject_name = X509_get_subject_name(server_cert);
  15014. if (subject_name != nullptr) {
  15015. char name[BUFSIZ];
  15016. auto name_len = X509_NAME_get_text_by_NID(subject_name, NID_commonName,
  15017. name, sizeof(name));
  15018. if (name_len != -1) {
  15019. return detail::match_hostname(
  15020. std::string(name, static_cast<size_t>(name_len)), host_);
  15021. }
  15022. }
  15023. return false;
  15024. }
  15025. #endif // CPPHTTPLIB_OPENSSL_SUPPORT
  15026. /*
  15027. * Group 9: TLS abstraction layer - Mbed TLS backend
  15028. */
  15029. /*
  15030. * Mbed TLS Backend Implementation
  15031. */
  15032. #ifdef CPPHTTPLIB_MBEDTLS_SUPPORT
  15033. namespace tls {
  15034. namespace impl {
  15035. // Mbed TLS session wrapper
  15036. struct MbedTlsSession {
  15037. mbedtls_ssl_context ssl;
  15038. socket_t sock = INVALID_SOCKET;
  15039. std::string hostname; // For client: set via set_sni
  15040. std::string sni_hostname; // For server: received from client via SNI callback
  15041. MbedTlsSession() { mbedtls_ssl_init(&ssl); }
  15042. ~MbedTlsSession() { mbedtls_ssl_free(&ssl); }
  15043. MbedTlsSession(const MbedTlsSession &) = delete;
  15044. MbedTlsSession &operator=(const MbedTlsSession &) = delete;
  15045. };
  15046. // Thread-local error code accessor for Mbed TLS (since it doesn't have an error
  15047. // queue)
  15048. inline int &mbedtls_last_error() {
  15049. static thread_local int err = 0;
  15050. return err;
  15051. }
  15052. // Helper to map Mbed TLS error to ErrorCode
  15053. inline ErrorCode map_mbedtls_error(int ret, int &out_errno) {
  15054. if (ret == 0) { return ErrorCode::Success; }
  15055. if (ret == MBEDTLS_ERR_SSL_WANT_READ) { return ErrorCode::WantRead; }
  15056. if (ret == MBEDTLS_ERR_SSL_WANT_WRITE) { return ErrorCode::WantWrite; }
  15057. if (ret == MBEDTLS_ERR_SSL_PEER_CLOSE_NOTIFY) {
  15058. return ErrorCode::PeerClosed;
  15059. }
  15060. if (ret == MBEDTLS_ERR_NET_CONN_RESET || ret == MBEDTLS_ERR_NET_SEND_FAILED ||
  15061. ret == MBEDTLS_ERR_NET_RECV_FAILED) {
  15062. out_errno = errno;
  15063. return ErrorCode::SyscallError;
  15064. }
  15065. if (ret == MBEDTLS_ERR_X509_CERT_VERIFY_FAILED) {
  15066. return ErrorCode::CertVerifyFailed;
  15067. }
  15068. return ErrorCode::Fatal;
  15069. }
  15070. // BIO-like send callback for Mbed TLS
  15071. inline int mbedtls_net_send_cb(void *ctx, const unsigned char *buf,
  15072. size_t len) {
  15073. auto sock = *static_cast<socket_t *>(ctx);
  15074. #ifdef _WIN32
  15075. auto ret =
  15076. send(sock, reinterpret_cast<const char *>(buf), static_cast<int>(len), 0);
  15077. if (ret == SOCKET_ERROR) {
  15078. int err = WSAGetLastError();
  15079. if (err == WSAEWOULDBLOCK) { return MBEDTLS_ERR_SSL_WANT_WRITE; }
  15080. return MBEDTLS_ERR_NET_SEND_FAILED;
  15081. }
  15082. #else
  15083. auto ret = send(sock, buf, len, 0);
  15084. if (ret < 0) {
  15085. if (errno == EAGAIN || errno == EWOULDBLOCK) {
  15086. return MBEDTLS_ERR_SSL_WANT_WRITE;
  15087. }
  15088. return MBEDTLS_ERR_NET_SEND_FAILED;
  15089. }
  15090. #endif
  15091. return static_cast<int>(ret);
  15092. }
  15093. // BIO-like recv callback for Mbed TLS
  15094. inline int mbedtls_net_recv_cb(void *ctx, unsigned char *buf, size_t len) {
  15095. auto sock = *static_cast<socket_t *>(ctx);
  15096. #ifdef _WIN32
  15097. auto ret =
  15098. recv(sock, reinterpret_cast<char *>(buf), static_cast<int>(len), 0);
  15099. if (ret == SOCKET_ERROR) {
  15100. int err = WSAGetLastError();
  15101. if (err == WSAEWOULDBLOCK) { return MBEDTLS_ERR_SSL_WANT_READ; }
  15102. return MBEDTLS_ERR_NET_RECV_FAILED;
  15103. }
  15104. #else
  15105. auto ret = recv(sock, buf, len, 0);
  15106. if (ret < 0) {
  15107. if (errno == EAGAIN || errno == EWOULDBLOCK) {
  15108. return MBEDTLS_ERR_SSL_WANT_READ;
  15109. }
  15110. return MBEDTLS_ERR_NET_RECV_FAILED;
  15111. }
  15112. #endif
  15113. if (ret == 0) { return MBEDTLS_ERR_SSL_PEER_CLOSE_NOTIFY; }
  15114. return static_cast<int>(ret);
  15115. }
  15116. // MbedTlsContext constructor/destructor implementations
  15117. inline MbedTlsContext::MbedTlsContext() {
  15118. mbedtls_ssl_config_init(&conf);
  15119. mbedtls_entropy_init(&entropy);
  15120. mbedtls_ctr_drbg_init(&ctr_drbg);
  15121. mbedtls_x509_crt_init(&ca_chain);
  15122. mbedtls_x509_crt_init(&own_cert);
  15123. mbedtls_pk_init(&own_key);
  15124. }
  15125. inline MbedTlsContext::~MbedTlsContext() {
  15126. mbedtls_pk_free(&own_key);
  15127. mbedtls_x509_crt_free(&own_cert);
  15128. mbedtls_x509_crt_free(&ca_chain);
  15129. mbedtls_ctr_drbg_free(&ctr_drbg);
  15130. mbedtls_entropy_free(&entropy);
  15131. mbedtls_ssl_config_free(&conf);
  15132. }
  15133. // Thread-local storage for SNI captured during handshake
  15134. // This is needed because the SNI callback doesn't have a way to pass
  15135. // session-specific data before the session is fully set up
  15136. inline std::string &mbedpending_sni() {
  15137. static thread_local std::string sni;
  15138. return sni;
  15139. }
  15140. // SNI callback for Mbed TLS server to capture client's SNI hostname
  15141. inline int mbedtls_sni_callback(void *p_ctx, mbedtls_ssl_context *ssl,
  15142. const unsigned char *name, size_t name_len) {
  15143. (void)p_ctx;
  15144. (void)ssl;
  15145. // Store SNI name in thread-local storage
  15146. // It will be retrieved and stored in the session after handshake
  15147. if (name && name_len > 0) {
  15148. mbedpending_sni().assign(reinterpret_cast<const char *>(name), name_len);
  15149. } else {
  15150. mbedpending_sni().clear();
  15151. }
  15152. return 0; // Accept any SNI
  15153. }
  15154. inline int mbedtls_verify_callback(void *data, mbedtls_x509_crt *crt,
  15155. int cert_depth, uint32_t *flags);
  15156. // MbedTLS verify callback wrapper
  15157. inline int mbedtls_verify_callback(void *data, mbedtls_x509_crt *crt,
  15158. int cert_depth, uint32_t *flags) {
  15159. auto &callback = get_verify_callback();
  15160. if (!callback) { return 0; } // Continue with default verification
  15161. // data points to the MbedTlsSession
  15162. auto *session = static_cast<MbedTlsSession *>(data);
  15163. // Build context
  15164. VerifyContext verify_ctx;
  15165. verify_ctx.session = static_cast<session_t>(session);
  15166. verify_ctx.cert = static_cast<cert_t>(crt);
  15167. verify_ctx.depth = cert_depth;
  15168. verify_ctx.preverify_ok = (*flags == 0);
  15169. verify_ctx.error_code = static_cast<long>(*flags);
  15170. // Convert Mbed TLS flags to error string
  15171. static thread_local char error_buf[256];
  15172. if (*flags != 0) {
  15173. mbedtls_x509_crt_verify_info(error_buf, sizeof(error_buf), "", *flags);
  15174. verify_ctx.error_string = error_buf;
  15175. } else {
  15176. verify_ctx.error_string = nullptr;
  15177. }
  15178. bool accepted = callback(verify_ctx);
  15179. if (accepted) {
  15180. *flags = 0; // Clear all error flags
  15181. return 0;
  15182. }
  15183. return MBEDTLS_ERR_X509_CERT_VERIFY_FAILED;
  15184. }
  15185. } // namespace impl
  15186. inline ctx_t create_client_context() {
  15187. auto ctx = new (std::nothrow) impl::MbedTlsContext();
  15188. if (!ctx) { return nullptr; }
  15189. ctx->is_server = false;
  15190. // Seed the random number generator
  15191. const char *pers = "httplib_client";
  15192. int ret = mbedtls_ctr_drbg_seed(
  15193. &ctx->ctr_drbg, mbedtls_entropy_func, &ctx->entropy,
  15194. reinterpret_cast<const unsigned char *>(pers), strlen(pers));
  15195. if (ret != 0) {
  15196. impl::mbedtls_last_error() = ret;
  15197. delete ctx;
  15198. return nullptr;
  15199. }
  15200. // Set up SSL config for client
  15201. ret = mbedtls_ssl_config_defaults(&ctx->conf, MBEDTLS_SSL_IS_CLIENT,
  15202. MBEDTLS_SSL_TRANSPORT_STREAM,
  15203. MBEDTLS_SSL_PRESET_DEFAULT);
  15204. if (ret != 0) {
  15205. impl::mbedtls_last_error() = ret;
  15206. delete ctx;
  15207. return nullptr;
  15208. }
  15209. // Set random number generator
  15210. mbedtls_ssl_conf_rng(&ctx->conf, mbedtls_ctr_drbg_random, &ctx->ctr_drbg);
  15211. // Default: verify peer certificate
  15212. mbedtls_ssl_conf_authmode(&ctx->conf, MBEDTLS_SSL_VERIFY_REQUIRED);
  15213. // Set minimum TLS version to 1.2
  15214. #ifdef CPPHTTPLIB_MBEDTLS_V3
  15215. mbedtls_ssl_conf_min_tls_version(&ctx->conf, MBEDTLS_SSL_VERSION_TLS1_2);
  15216. #else
  15217. mbedtls_ssl_conf_min_version(&ctx->conf, MBEDTLS_SSL_MAJOR_VERSION_3,
  15218. MBEDTLS_SSL_MINOR_VERSION_3);
  15219. #endif
  15220. return static_cast<ctx_t>(ctx);
  15221. }
  15222. inline ctx_t create_server_context() {
  15223. auto ctx = new (std::nothrow) impl::MbedTlsContext();
  15224. if (!ctx) { return nullptr; }
  15225. ctx->is_server = true;
  15226. // Seed the random number generator
  15227. const char *pers = "httplib_server";
  15228. int ret = mbedtls_ctr_drbg_seed(
  15229. &ctx->ctr_drbg, mbedtls_entropy_func, &ctx->entropy,
  15230. reinterpret_cast<const unsigned char *>(pers), strlen(pers));
  15231. if (ret != 0) {
  15232. impl::mbedtls_last_error() = ret;
  15233. delete ctx;
  15234. return nullptr;
  15235. }
  15236. // Set up SSL config for server
  15237. ret = mbedtls_ssl_config_defaults(&ctx->conf, MBEDTLS_SSL_IS_SERVER,
  15238. MBEDTLS_SSL_TRANSPORT_STREAM,
  15239. MBEDTLS_SSL_PRESET_DEFAULT);
  15240. if (ret != 0) {
  15241. impl::mbedtls_last_error() = ret;
  15242. delete ctx;
  15243. return nullptr;
  15244. }
  15245. // Set random number generator
  15246. mbedtls_ssl_conf_rng(&ctx->conf, mbedtls_ctr_drbg_random, &ctx->ctr_drbg);
  15247. // Default: don't verify client
  15248. mbedtls_ssl_conf_authmode(&ctx->conf, MBEDTLS_SSL_VERIFY_NONE);
  15249. // Set minimum TLS version to 1.2
  15250. #ifdef CPPHTTPLIB_MBEDTLS_V3
  15251. mbedtls_ssl_conf_min_tls_version(&ctx->conf, MBEDTLS_SSL_VERSION_TLS1_2);
  15252. #else
  15253. mbedtls_ssl_conf_min_version(&ctx->conf, MBEDTLS_SSL_MAJOR_VERSION_3,
  15254. MBEDTLS_SSL_MINOR_VERSION_3);
  15255. #endif
  15256. // Set SNI callback to capture client's SNI hostname
  15257. mbedtls_ssl_conf_sni(&ctx->conf, impl::mbedtls_sni_callback, nullptr);
  15258. return static_cast<ctx_t>(ctx);
  15259. }
  15260. inline void free_context(ctx_t ctx) {
  15261. if (ctx) { delete static_cast<impl::MbedTlsContext *>(ctx); }
  15262. }
  15263. inline bool set_min_version(ctx_t ctx, Version version) {
  15264. if (!ctx) { return false; }
  15265. auto mctx = static_cast<impl::MbedTlsContext *>(ctx);
  15266. #ifdef CPPHTTPLIB_MBEDTLS_V3
  15267. // Mbed TLS 3.x uses mbedtls_ssl_protocol_version enum
  15268. mbedtls_ssl_protocol_version min_ver = MBEDTLS_SSL_VERSION_TLS1_2;
  15269. if (version >= Version::TLS1_3) {
  15270. #if defined(MBEDTLS_SSL_PROTO_TLS1_3)
  15271. min_ver = MBEDTLS_SSL_VERSION_TLS1_3;
  15272. #endif
  15273. }
  15274. mbedtls_ssl_conf_min_tls_version(&mctx->conf, min_ver);
  15275. #else
  15276. // Mbed TLS 2.x uses major/minor version numbers
  15277. int major = MBEDTLS_SSL_MAJOR_VERSION_3;
  15278. int minor = MBEDTLS_SSL_MINOR_VERSION_3; // TLS 1.2
  15279. if (version >= Version::TLS1_3) {
  15280. #if defined(MBEDTLS_SSL_PROTO_TLS1_3)
  15281. minor = MBEDTLS_SSL_MINOR_VERSION_4; // TLS 1.3
  15282. #else
  15283. minor = MBEDTLS_SSL_MINOR_VERSION_3; // Fall back to TLS 1.2
  15284. #endif
  15285. }
  15286. mbedtls_ssl_conf_min_version(&mctx->conf, major, minor);
  15287. #endif
  15288. return true;
  15289. }
  15290. inline bool load_ca_pem(ctx_t ctx, const char *pem, size_t len) {
  15291. if (!ctx || !pem) { return false; }
  15292. auto mctx = static_cast<impl::MbedTlsContext *>(ctx);
  15293. // mbedtls_x509_crt_parse expects null-terminated string for PEM
  15294. // Add null terminator if not present
  15295. std::string pem_str(pem, len);
  15296. int ret = mbedtls_x509_crt_parse(
  15297. &mctx->ca_chain, reinterpret_cast<const unsigned char *>(pem_str.c_str()),
  15298. pem_str.size() + 1);
  15299. if (ret != 0) {
  15300. impl::mbedtls_last_error() = ret;
  15301. return false;
  15302. }
  15303. mbedtls_ssl_conf_ca_chain(&mctx->conf, &mctx->ca_chain, nullptr);
  15304. return true;
  15305. }
  15306. inline bool load_ca_file(ctx_t ctx, const char *file_path) {
  15307. if (!ctx || !file_path) { return false; }
  15308. auto mctx = static_cast<impl::MbedTlsContext *>(ctx);
  15309. int ret = mbedtls_x509_crt_parse_file(&mctx->ca_chain, file_path);
  15310. if (ret != 0) {
  15311. impl::mbedtls_last_error() = ret;
  15312. return false;
  15313. }
  15314. mbedtls_ssl_conf_ca_chain(&mctx->conf, &mctx->ca_chain, nullptr);
  15315. return true;
  15316. }
  15317. inline bool load_ca_dir(ctx_t ctx, const char *dir_path) {
  15318. if (!ctx || !dir_path) { return false; }
  15319. auto mctx = static_cast<impl::MbedTlsContext *>(ctx);
  15320. int ret = mbedtls_x509_crt_parse_path(&mctx->ca_chain, dir_path);
  15321. if (ret < 0) { // Returns number of certs on success, negative on error
  15322. impl::mbedtls_last_error() = ret;
  15323. return false;
  15324. }
  15325. mbedtls_ssl_conf_ca_chain(&mctx->conf, &mctx->ca_chain, nullptr);
  15326. return true;
  15327. }
  15328. inline bool load_system_certs(ctx_t ctx) {
  15329. if (!ctx) { return false; }
  15330. auto mctx = static_cast<impl::MbedTlsContext *>(ctx);
  15331. bool loaded = false;
  15332. #ifdef _WIN32
  15333. loaded = impl::enumerate_windows_system_certs(
  15334. [&](const unsigned char *data, size_t len) {
  15335. return mbedtls_x509_crt_parse_der(&mctx->ca_chain, data, len) == 0;
  15336. });
  15337. #elif defined(__APPLE__) && defined(CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN)
  15338. loaded = impl::enumerate_macos_keychain_certs(
  15339. [&](const unsigned char *data, size_t len) {
  15340. return mbedtls_x509_crt_parse_der(&mctx->ca_chain, data, len) == 0;
  15341. });
  15342. #else
  15343. for (auto path = impl::system_ca_paths(); *path; ++path) {
  15344. if (mbedtls_x509_crt_parse_file(&mctx->ca_chain, *path) >= 0) {
  15345. loaded = true;
  15346. break;
  15347. }
  15348. }
  15349. if (!loaded) {
  15350. for (auto dir = impl::system_ca_dirs(); *dir; ++dir) {
  15351. if (mbedtls_x509_crt_parse_path(&mctx->ca_chain, *dir) >= 0) {
  15352. loaded = true;
  15353. break;
  15354. }
  15355. }
  15356. }
  15357. #endif
  15358. if (loaded) {
  15359. mbedtls_ssl_conf_ca_chain(&mctx->conf, &mctx->ca_chain, nullptr);
  15360. }
  15361. return loaded;
  15362. }
  15363. inline bool set_client_cert_pem(ctx_t ctx, const char *cert, const char *key,
  15364. const char *password) {
  15365. if (!ctx || !cert || !key) { return false; }
  15366. auto mctx = static_cast<impl::MbedTlsContext *>(ctx);
  15367. // Parse certificate
  15368. std::string cert_str(cert);
  15369. int ret = mbedtls_x509_crt_parse(
  15370. &mctx->own_cert,
  15371. reinterpret_cast<const unsigned char *>(cert_str.c_str()),
  15372. cert_str.size() + 1);
  15373. if (ret != 0) {
  15374. impl::mbedtls_last_error() = ret;
  15375. return false;
  15376. }
  15377. // Parse private key
  15378. std::string key_str(key);
  15379. const unsigned char *pwd =
  15380. password ? reinterpret_cast<const unsigned char *>(password) : nullptr;
  15381. size_t pwd_len = password ? strlen(password) : 0;
  15382. #ifdef CPPHTTPLIB_MBEDTLS_V3
  15383. ret = mbedtls_pk_parse_key(
  15384. &mctx->own_key, reinterpret_cast<const unsigned char *>(key_str.c_str()),
  15385. key_str.size() + 1, pwd, pwd_len, mbedtls_ctr_drbg_random,
  15386. &mctx->ctr_drbg);
  15387. #else
  15388. ret = mbedtls_pk_parse_key(
  15389. &mctx->own_key, reinterpret_cast<const unsigned char *>(key_str.c_str()),
  15390. key_str.size() + 1, pwd, pwd_len);
  15391. #endif
  15392. if (ret != 0) {
  15393. impl::mbedtls_last_error() = ret;
  15394. return false;
  15395. }
  15396. // Verify that the certificate and private key match
  15397. #ifdef CPPHTTPLIB_MBEDTLS_V3
  15398. ret = mbedtls_pk_check_pair(&mctx->own_cert.pk, &mctx->own_key,
  15399. mbedtls_ctr_drbg_random, &mctx->ctr_drbg);
  15400. #else
  15401. ret = mbedtls_pk_check_pair(&mctx->own_cert.pk, &mctx->own_key);
  15402. #endif
  15403. if (ret != 0) {
  15404. impl::mbedtls_last_error() = ret;
  15405. return false;
  15406. }
  15407. ret = mbedtls_ssl_conf_own_cert(&mctx->conf, &mctx->own_cert, &mctx->own_key);
  15408. if (ret != 0) {
  15409. impl::mbedtls_last_error() = ret;
  15410. return false;
  15411. }
  15412. return true;
  15413. }
  15414. inline bool set_client_cert_file(ctx_t ctx, const char *cert_path,
  15415. const char *key_path, const char *password) {
  15416. if (!ctx || !cert_path || !key_path) { return false; }
  15417. auto mctx = static_cast<impl::MbedTlsContext *>(ctx);
  15418. // Parse certificate file
  15419. int ret = mbedtls_x509_crt_parse_file(&mctx->own_cert, cert_path);
  15420. if (ret != 0) {
  15421. impl::mbedtls_last_error() = ret;
  15422. return false;
  15423. }
  15424. // Parse private key file
  15425. #ifdef CPPHTTPLIB_MBEDTLS_V3
  15426. ret = mbedtls_pk_parse_keyfile(&mctx->own_key, key_path, password,
  15427. mbedtls_ctr_drbg_random, &mctx->ctr_drbg);
  15428. #else
  15429. ret = mbedtls_pk_parse_keyfile(&mctx->own_key, key_path, password);
  15430. #endif
  15431. if (ret != 0) {
  15432. impl::mbedtls_last_error() = ret;
  15433. return false;
  15434. }
  15435. // Verify that the certificate and private key match
  15436. #ifdef CPPHTTPLIB_MBEDTLS_V3
  15437. ret = mbedtls_pk_check_pair(&mctx->own_cert.pk, &mctx->own_key,
  15438. mbedtls_ctr_drbg_random, &mctx->ctr_drbg);
  15439. #else
  15440. ret = mbedtls_pk_check_pair(&mctx->own_cert.pk, &mctx->own_key);
  15441. #endif
  15442. if (ret != 0) {
  15443. impl::mbedtls_last_error() = ret;
  15444. return false;
  15445. }
  15446. ret = mbedtls_ssl_conf_own_cert(&mctx->conf, &mctx->own_cert, &mctx->own_key);
  15447. if (ret != 0) {
  15448. impl::mbedtls_last_error() = ret;
  15449. return false;
  15450. }
  15451. return true;
  15452. }
  15453. inline void set_verify_client(ctx_t ctx, bool require) {
  15454. if (!ctx) { return; }
  15455. auto mctx = static_cast<impl::MbedTlsContext *>(ctx);
  15456. mctx->verify_client = require;
  15457. if (require) {
  15458. mbedtls_ssl_conf_authmode(&mctx->conf, MBEDTLS_SSL_VERIFY_REQUIRED);
  15459. } else {
  15460. // If a verify callback is set, use OPTIONAL mode to ensure the callback
  15461. // is called (matching OpenSSL behavior). Otherwise use NONE.
  15462. mbedtls_ssl_conf_authmode(&mctx->conf, mctx->has_verify_callback
  15463. ? MBEDTLS_SSL_VERIFY_OPTIONAL
  15464. : MBEDTLS_SSL_VERIFY_NONE);
  15465. }
  15466. }
  15467. inline session_t create_session(ctx_t ctx, socket_t sock) {
  15468. if (!ctx || sock == INVALID_SOCKET) { return nullptr; }
  15469. auto mctx = static_cast<impl::MbedTlsContext *>(ctx);
  15470. auto session = new (std::nothrow) impl::MbedTlsSession();
  15471. if (!session) { return nullptr; }
  15472. session->sock = sock;
  15473. int ret = mbedtls_ssl_setup(&session->ssl, &mctx->conf);
  15474. if (ret != 0) {
  15475. impl::mbedtls_last_error() = ret;
  15476. delete session;
  15477. return nullptr;
  15478. }
  15479. // Explicitly opt out of in-handshake hostname verification by default;
  15480. // since Mbed TLS 3.6.4 a client handshake with certificate verification
  15481. // fails outright when no hostname was set. set_sni() installs the real
  15482. // hostname for DNS hosts; for IP hosts (where SNI must not be set) the
  15483. // caller verifies the certificate identity post-handshake via
  15484. // verify_hostname().
  15485. mbedtls_ssl_set_hostname(&session->ssl, nullptr);
  15486. // Set BIO callbacks
  15487. mbedtls_ssl_set_bio(&session->ssl, &session->sock, impl::mbedtls_net_send_cb,
  15488. impl::mbedtls_net_recv_cb, nullptr);
  15489. // Set per-session verify callback with session pointer if callback is
  15490. // registered
  15491. if (mctx->has_verify_callback) {
  15492. mbedtls_ssl_set_verify(&session->ssl, impl::mbedtls_verify_callback,
  15493. session);
  15494. }
  15495. return static_cast<session_t>(session);
  15496. }
  15497. inline void free_session(session_t session) {
  15498. if (session) { delete static_cast<impl::MbedTlsSession *>(session); }
  15499. }
  15500. inline bool set_sni(session_t session, const char *hostname) {
  15501. if (!session || !hostname) { return false; }
  15502. auto msession = static_cast<impl::MbedTlsSession *>(session);
  15503. int ret = mbedtls_ssl_set_hostname(&msession->ssl, hostname);
  15504. if (ret != 0) {
  15505. impl::mbedtls_last_error() = ret;
  15506. return false;
  15507. }
  15508. msession->hostname = hostname;
  15509. return true;
  15510. }
  15511. inline bool set_hostname(session_t session, const char *hostname) {
  15512. // In Mbed TLS, set_hostname also sets up hostname verification
  15513. return set_sni(session, hostname);
  15514. }
  15515. inline TlsError connect(session_t session) {
  15516. TlsError err;
  15517. if (!session) {
  15518. err.code = ErrorCode::Fatal;
  15519. return err;
  15520. }
  15521. auto msession = static_cast<impl::MbedTlsSession *>(session);
  15522. int ret = mbedtls_ssl_handshake(&msession->ssl);
  15523. if (ret == 0) {
  15524. err.code = ErrorCode::Success;
  15525. } else {
  15526. err.code = impl::map_mbedtls_error(ret, err.sys_errno);
  15527. err.backend_code = static_cast<uint64_t>(-ret);
  15528. impl::mbedtls_last_error() = ret;
  15529. }
  15530. return err;
  15531. }
  15532. inline TlsError accept(session_t session) {
  15533. // Same as connect for Mbed TLS - handshake works for both client and server
  15534. auto result = connect(session);
  15535. // After successful handshake, capture SNI from thread-local storage
  15536. if (result.code == ErrorCode::Success && session) {
  15537. auto msession = static_cast<impl::MbedTlsSession *>(session);
  15538. msession->sni_hostname = std::move(impl::mbedpending_sni());
  15539. impl::mbedpending_sni().clear();
  15540. }
  15541. return result;
  15542. }
  15543. inline bool connect_nonblocking(session_t session, socket_t sock,
  15544. time_t timeout_sec, time_t timeout_usec,
  15545. TlsError *err) {
  15546. if (!session) {
  15547. if (err) { err->code = ErrorCode::Fatal; }
  15548. return false;
  15549. }
  15550. auto msession = static_cast<impl::MbedTlsSession *>(session);
  15551. // Set socket to non-blocking mode
  15552. detail::set_nonblocking(sock, true);
  15553. auto cleanup =
  15554. detail::scope_exit([&]() { detail::set_nonblocking(sock, false); });
  15555. int ret;
  15556. while ((ret = mbedtls_ssl_handshake(&msession->ssl)) != 0) {
  15557. if (ret == MBEDTLS_ERR_SSL_WANT_READ) {
  15558. if (detail::select_read(sock, timeout_sec, timeout_usec) > 0) {
  15559. continue;
  15560. }
  15561. } else if (ret == MBEDTLS_ERR_SSL_WANT_WRITE) {
  15562. if (detail::select_write(sock, timeout_sec, timeout_usec) > 0) {
  15563. continue;
  15564. }
  15565. }
  15566. // TlsError or timeout
  15567. if (err) {
  15568. err->code = impl::map_mbedtls_error(ret, err->sys_errno);
  15569. err->backend_code = static_cast<uint64_t>(-ret);
  15570. }
  15571. impl::mbedtls_last_error() = ret;
  15572. return false;
  15573. }
  15574. if (err) { err->code = ErrorCode::Success; }
  15575. return true;
  15576. }
  15577. inline bool accept_nonblocking(session_t session, socket_t sock,
  15578. time_t timeout_sec, time_t timeout_usec,
  15579. TlsError *err) {
  15580. // Same implementation as connect for Mbed TLS
  15581. bool result =
  15582. connect_nonblocking(session, sock, timeout_sec, timeout_usec, err);
  15583. // After successful handshake, capture SNI from thread-local storage
  15584. if (result && session) {
  15585. auto msession = static_cast<impl::MbedTlsSession *>(session);
  15586. msession->sni_hostname = std::move(impl::mbedpending_sni());
  15587. impl::mbedpending_sni().clear();
  15588. }
  15589. return result;
  15590. }
  15591. inline ssize_t read(session_t session, void *buf, size_t len, TlsError &err) {
  15592. if (!session || !buf) {
  15593. err.code = ErrorCode::Fatal;
  15594. return -1;
  15595. }
  15596. auto msession = static_cast<impl::MbedTlsSession *>(session);
  15597. int ret =
  15598. mbedtls_ssl_read(&msession->ssl, static_cast<unsigned char *>(buf), len);
  15599. if (ret > 0) {
  15600. err.code = ErrorCode::Success;
  15601. return static_cast<ssize_t>(ret);
  15602. }
  15603. if (ret == 0) {
  15604. err.code = ErrorCode::PeerClosed;
  15605. return 0;
  15606. }
  15607. err.code = impl::map_mbedtls_error(ret, err.sys_errno);
  15608. err.backend_code = static_cast<uint64_t>(-ret);
  15609. impl::mbedtls_last_error() = ret;
  15610. // mbedTLS signals a clean close_notify via a negative error code rather
  15611. // than 0; surface it as a clean EOF the way OpenSSL/wolfSSL do.
  15612. if (err.code == ErrorCode::PeerClosed) { return 0; }
  15613. return -1;
  15614. }
  15615. inline ssize_t write(session_t session, const void *buf, size_t len,
  15616. TlsError &err) {
  15617. if (!session || !buf) {
  15618. err.code = ErrorCode::Fatal;
  15619. return -1;
  15620. }
  15621. auto msession = static_cast<impl::MbedTlsSession *>(session);
  15622. int ret = mbedtls_ssl_write(&msession->ssl,
  15623. static_cast<const unsigned char *>(buf), len);
  15624. if (ret > 0) {
  15625. err.code = ErrorCode::Success;
  15626. return static_cast<ssize_t>(ret);
  15627. }
  15628. if (ret == 0) {
  15629. err.code = ErrorCode::PeerClosed;
  15630. return 0;
  15631. }
  15632. err.code = impl::map_mbedtls_error(ret, err.sys_errno);
  15633. err.backend_code = static_cast<uint64_t>(-ret);
  15634. impl::mbedtls_last_error() = ret;
  15635. return -1;
  15636. }
  15637. inline int pending(const_session_t session) {
  15638. if (!session) { return 0; }
  15639. auto msession =
  15640. static_cast<impl::MbedTlsSession *>(const_cast<void *>(session));
  15641. return static_cast<int>(mbedtls_ssl_get_bytes_avail(&msession->ssl));
  15642. }
  15643. inline void shutdown(session_t session, bool graceful) {
  15644. if (!session) { return; }
  15645. auto msession = static_cast<impl::MbedTlsSession *>(session);
  15646. if (graceful) {
  15647. // Try to send close_notify, but don't block forever
  15648. int ret;
  15649. int attempts = 0;
  15650. while ((ret = mbedtls_ssl_close_notify(&msession->ssl)) != 0 &&
  15651. attempts < 3) {
  15652. if (ret != MBEDTLS_ERR_SSL_WANT_READ &&
  15653. ret != MBEDTLS_ERR_SSL_WANT_WRITE) {
  15654. break;
  15655. }
  15656. attempts++;
  15657. }
  15658. }
  15659. }
  15660. inline bool is_peer_closed(session_t session, socket_t sock) {
  15661. if (!session || sock == INVALID_SOCKET) { return true; }
  15662. auto msession = static_cast<impl::MbedTlsSession *>(session);
  15663. // Check if there's already decrypted data available in the TLS buffer
  15664. // If so, the connection is definitely alive
  15665. if (mbedtls_ssl_get_bytes_avail(&msession->ssl) > 0) { return false; }
  15666. // Set socket to non-blocking to avoid blocking on read
  15667. detail::set_nonblocking(sock, true);
  15668. auto cleanup =
  15669. detail::scope_exit([&]() { detail::set_nonblocking(sock, false); });
  15670. // Try a 1-byte read to check connection status
  15671. // Note: This will consume the byte if data is available, but for the
  15672. // purpose of checking if peer is closed, this should be acceptable
  15673. // since we're only called when we expect the connection might be closing
  15674. unsigned char buf;
  15675. int ret = mbedtls_ssl_read(&msession->ssl, &buf, 1);
  15676. // If we got data or WANT_READ (would block), connection is alive
  15677. if (ret > 0 || ret == MBEDTLS_ERR_SSL_WANT_READ) { return false; }
  15678. // If we get a peer close notify or a connection reset, the peer is closed
  15679. return ret == MBEDTLS_ERR_SSL_PEER_CLOSE_NOTIFY ||
  15680. ret == MBEDTLS_ERR_NET_CONN_RESET || ret == 0;
  15681. }
  15682. inline cert_t get_peer_cert(const_session_t session) {
  15683. if (!session) { return nullptr; }
  15684. auto msession =
  15685. static_cast<impl::MbedTlsSession *>(const_cast<void *>(session));
  15686. // Mbed TLS returns a pointer to the internal peer cert chain.
  15687. // WARNING: This pointer is only valid while the session is active.
  15688. // Do not use the certificate after calling free_session().
  15689. const mbedtls_x509_crt *cert = mbedtls_ssl_get_peer_cert(&msession->ssl);
  15690. return const_cast<mbedtls_x509_crt *>(cert);
  15691. }
  15692. inline void free_cert(cert_t cert) {
  15693. // Mbed TLS: peer certificate is owned by the SSL context.
  15694. // No-op here, but callers should still call this for cross-backend
  15695. // portability.
  15696. (void)cert;
  15697. }
  15698. inline bool verify_hostname(cert_t cert, const char *hostname) {
  15699. if (!cert || !hostname) { return false; }
  15700. auto mcert = static_cast<const mbedtls_x509_crt *>(cert);
  15701. std::string host_str(hostname);
  15702. // Check if hostname is an IP address
  15703. bool is_ip = impl::is_ipv4_address(host_str);
  15704. unsigned char ip_bytes[4];
  15705. if (is_ip) { impl::parse_ipv4(host_str, ip_bytes); }
  15706. // Check Subject Alternative Names (SAN)
  15707. // In Mbed TLS 3.x, subject_alt_names contains raw values without ASN.1 tags
  15708. // - DNS names: raw string bytes
  15709. // - IP addresses: raw IP bytes (4 for IPv4, 16 for IPv6)
  15710. const mbedtls_x509_sequence *san = &mcert->subject_alt_names;
  15711. while (san != nullptr && san->buf.p != nullptr && san->buf.len > 0) {
  15712. const unsigned char *p = san->buf.p;
  15713. size_t len = san->buf.len;
  15714. if (is_ip) {
  15715. // Check if this SAN is an IPv4 address (4 bytes)
  15716. if (len == 4 && memcmp(p, ip_bytes, 4) == 0) { return true; }
  15717. // Check if this SAN is an IPv6 address (16 bytes) - skip for now
  15718. } else {
  15719. // Check if this SAN is a DNS name (printable ASCII string)
  15720. bool is_dns = len > 0;
  15721. for (size_t i = 0; i < len && is_dns; i++) {
  15722. if (p[i] < 32 || p[i] > 126) { is_dns = false; }
  15723. }
  15724. if (is_dns) {
  15725. std::string san_name(reinterpret_cast<const char *>(p), len);
  15726. if (detail::match_hostname(san_name, host_str)) { return true; }
  15727. }
  15728. }
  15729. san = san->next;
  15730. }
  15731. // Fallback: Check Common Name (CN) in subject
  15732. char cn[256];
  15733. int ret = mbedtls_x509_dn_gets(cn, sizeof(cn), &mcert->subject);
  15734. if (ret > 0) {
  15735. std::string cn_str(cn);
  15736. // Look for "CN=" in the DN string
  15737. size_t cn_pos = cn_str.find("CN=");
  15738. if (cn_pos != std::string::npos) {
  15739. size_t start = cn_pos + 3;
  15740. size_t end = cn_str.find(',', start);
  15741. std::string cn_value =
  15742. cn_str.substr(start, end == std::string::npos ? end : end - start);
  15743. if (detail::match_hostname(cn_value, host_str)) { return true; }
  15744. }
  15745. }
  15746. return false;
  15747. }
  15748. inline uint64_t hostname_mismatch_code() {
  15749. return static_cast<uint64_t>(MBEDTLS_X509_BADCERT_CN_MISMATCH);
  15750. }
  15751. inline long get_verify_result(const_session_t session) {
  15752. if (!session) { return -1; }
  15753. auto msession =
  15754. static_cast<impl::MbedTlsSession *>(const_cast<void *>(session));
  15755. uint32_t flags = mbedtls_ssl_get_verify_result(&msession->ssl);
  15756. // Return 0 (X509_V_OK equivalent) if verification passed
  15757. return flags == 0 ? 0 : static_cast<long>(flags);
  15758. }
  15759. inline std::string get_cert_subject_cn(cert_t cert) {
  15760. if (!cert) return "";
  15761. auto x509 = static_cast<mbedtls_x509_crt *>(cert);
  15762. // Find the CN in the subject
  15763. const mbedtls_x509_name *name = &x509->subject;
  15764. while (name != nullptr) {
  15765. if (MBEDTLS_OID_CMP(MBEDTLS_OID_AT_CN, &name->oid) == 0) {
  15766. return std::string(reinterpret_cast<const char *>(name->val.p),
  15767. name->val.len);
  15768. }
  15769. name = name->next;
  15770. }
  15771. return "";
  15772. }
  15773. inline std::string get_cert_issuer_name(cert_t cert) {
  15774. if (!cert) return "";
  15775. auto x509 = static_cast<mbedtls_x509_crt *>(cert);
  15776. // Build a human-readable issuer name string
  15777. char buf[512];
  15778. int ret = mbedtls_x509_dn_gets(buf, sizeof(buf), &x509->issuer);
  15779. if (ret < 0) return "";
  15780. return std::string(buf);
  15781. }
  15782. inline bool get_cert_sans(cert_t cert, std::vector<SanEntry> &sans) {
  15783. sans.clear();
  15784. if (!cert) return false;
  15785. auto x509 = static_cast<mbedtls_x509_crt *>(cert);
  15786. // Parse the Subject Alternative Name extension
  15787. const mbedtls_x509_sequence *cur = &x509->subject_alt_names;
  15788. while (cur != nullptr) {
  15789. if (cur->buf.len > 0) {
  15790. // Mbed TLS stores SAN as ASN.1 sequences
  15791. // The tag byte indicates the type
  15792. const unsigned char *p = cur->buf.p;
  15793. size_t len = cur->buf.len;
  15794. // First byte is the tag
  15795. unsigned char tag = *p;
  15796. p++;
  15797. len--;
  15798. // Parse length (simple single-byte length assumed)
  15799. if (len > 0 && *p < 0x80) {
  15800. size_t value_len = *p;
  15801. p++;
  15802. len--;
  15803. if (value_len <= len) {
  15804. SanEntry entry;
  15805. // ASN.1 context tags for GeneralName
  15806. switch (tag & 0x1F) {
  15807. case 2: // dNSName
  15808. entry.type = SanType::DNS;
  15809. entry.value =
  15810. std::string(reinterpret_cast<const char *>(p), value_len);
  15811. break;
  15812. case 7: // iPAddress
  15813. entry.type = SanType::IP;
  15814. if (value_len == 4) {
  15815. // IPv4
  15816. char buf[16];
  15817. snprintf(buf, sizeof(buf), "%d.%d.%d.%d", p[0], p[1], p[2], p[3]);
  15818. entry.value = buf;
  15819. } else if (value_len == 16) {
  15820. // IPv6
  15821. char buf[64];
  15822. snprintf(buf, sizeof(buf),
  15823. "%02x%02x:%02x%02x:%02x%02x:%02x%02x:"
  15824. "%02x%02x:%02x%02x:%02x%02x:%02x%02x",
  15825. p[0], p[1], p[2], p[3], p[4], p[5], p[6], p[7], p[8],
  15826. p[9], p[10], p[11], p[12], p[13], p[14], p[15]);
  15827. entry.value = buf;
  15828. }
  15829. break;
  15830. case 1: // rfc822Name (email)
  15831. entry.type = SanType::EMAIL;
  15832. entry.value =
  15833. std::string(reinterpret_cast<const char *>(p), value_len);
  15834. break;
  15835. case 6: // uniformResourceIdentifier
  15836. entry.type = SanType::URI;
  15837. entry.value =
  15838. std::string(reinterpret_cast<const char *>(p), value_len);
  15839. break;
  15840. default: entry.type = SanType::OTHER; break;
  15841. }
  15842. if (!entry.value.empty()) { sans.push_back(std::move(entry)); }
  15843. }
  15844. }
  15845. }
  15846. cur = cur->next;
  15847. }
  15848. return true;
  15849. }
  15850. inline bool get_cert_validity(cert_t cert, time_t &not_before,
  15851. time_t &not_after) {
  15852. if (!cert) return false;
  15853. auto x509 = static_cast<mbedtls_x509_crt *>(cert);
  15854. // Convert mbedtls_x509_time to time_t
  15855. auto to_time_t = [](const mbedtls_x509_time &t) -> time_t {
  15856. struct tm tm_time = {};
  15857. tm_time.tm_year = t.year - 1900;
  15858. tm_time.tm_mon = t.mon - 1;
  15859. tm_time.tm_mday = t.day;
  15860. tm_time.tm_hour = t.hour;
  15861. tm_time.tm_min = t.min;
  15862. tm_time.tm_sec = t.sec;
  15863. #ifdef _WIN32
  15864. return _mkgmtime(&tm_time);
  15865. #else
  15866. return timegm(&tm_time);
  15867. #endif
  15868. };
  15869. not_before = to_time_t(x509->valid_from);
  15870. not_after = to_time_t(x509->valid_to);
  15871. return true;
  15872. }
  15873. inline std::string get_cert_serial(cert_t cert) {
  15874. if (!cert) return "";
  15875. auto x509 = static_cast<mbedtls_x509_crt *>(cert);
  15876. // Convert serial number to hex string
  15877. std::string result;
  15878. result.reserve(x509->serial.len * 2);
  15879. for (size_t i = 0; i < x509->serial.len; i++) {
  15880. char hex[3];
  15881. snprintf(hex, sizeof(hex), "%02X", x509->serial.p[i]);
  15882. result += hex;
  15883. }
  15884. return result;
  15885. }
  15886. inline bool get_cert_der(cert_t cert, std::vector<unsigned char> &der) {
  15887. if (!cert) return false;
  15888. auto crt = static_cast<mbedtls_x509_crt *>(cert);
  15889. if (!crt->raw.p || crt->raw.len == 0) return false;
  15890. der.assign(crt->raw.p, crt->raw.p + crt->raw.len);
  15891. return true;
  15892. }
  15893. inline const char *get_sni(const_session_t session) {
  15894. if (!session) return nullptr;
  15895. auto msession = static_cast<const impl::MbedTlsSession *>(session);
  15896. // For server: return SNI received from client during handshake
  15897. if (!msession->sni_hostname.empty()) {
  15898. return msession->sni_hostname.c_str();
  15899. }
  15900. // For client: return the hostname set via set_sni
  15901. if (!msession->hostname.empty()) { return msession->hostname.c_str(); }
  15902. return nullptr;
  15903. }
  15904. inline uint64_t peek_error() {
  15905. // Mbed TLS doesn't have an error queue, return the last error
  15906. return static_cast<uint64_t>(-impl::mbedtls_last_error());
  15907. }
  15908. inline uint64_t get_error() {
  15909. // Mbed TLS doesn't have an error queue, return and clear the last error
  15910. uint64_t err = static_cast<uint64_t>(-impl::mbedtls_last_error());
  15911. impl::mbedtls_last_error() = 0;
  15912. return err;
  15913. }
  15914. inline std::string error_string(uint64_t code) {
  15915. char buf[256];
  15916. mbedtls_strerror(-static_cast<int>(code), buf, sizeof(buf));
  15917. return std::string(buf);
  15918. }
  15919. inline ca_store_t create_ca_store(const char *pem, size_t len) {
  15920. auto *ca_chain = new (std::nothrow) mbedtls_x509_crt;
  15921. if (!ca_chain) { return nullptr; }
  15922. mbedtls_x509_crt_init(ca_chain);
  15923. // mbedtls_x509_crt_parse expects null-terminated PEM
  15924. int ret = mbedtls_x509_crt_parse(ca_chain,
  15925. reinterpret_cast<const unsigned char *>(pem),
  15926. len + 1); // +1 for null terminator
  15927. if (ret != 0) {
  15928. // Try without +1 in case PEM is already null-terminated
  15929. ret = mbedtls_x509_crt_parse(
  15930. ca_chain, reinterpret_cast<const unsigned char *>(pem), len);
  15931. if (ret != 0) {
  15932. mbedtls_x509_crt_free(ca_chain);
  15933. delete ca_chain;
  15934. return nullptr;
  15935. }
  15936. }
  15937. return static_cast<ca_store_t>(ca_chain);
  15938. }
  15939. inline void free_ca_store(ca_store_t store) {
  15940. if (store) {
  15941. auto *ca_chain = static_cast<mbedtls_x509_crt *>(store);
  15942. mbedtls_x509_crt_free(ca_chain);
  15943. delete ca_chain;
  15944. }
  15945. }
  15946. inline bool set_ca_store(ctx_t ctx, ca_store_t store) {
  15947. if (!ctx || !store) { return false; }
  15948. auto *mbed_ctx = static_cast<impl::MbedTlsContext *>(ctx);
  15949. auto *ca_chain = static_cast<mbedtls_x509_crt *>(store);
  15950. // Free existing CA chain
  15951. mbedtls_x509_crt_free(&mbed_ctx->ca_chain);
  15952. mbedtls_x509_crt_init(&mbed_ctx->ca_chain);
  15953. // Copy the CA chain (deep copy)
  15954. // Parse from the raw data of the source cert
  15955. mbedtls_x509_crt *src = ca_chain;
  15956. while (src != nullptr) {
  15957. int ret = mbedtls_x509_crt_parse_der(&mbed_ctx->ca_chain, src->raw.p,
  15958. src->raw.len);
  15959. if (ret != 0) {
  15960. free_ca_store(store);
  15961. return false;
  15962. }
  15963. src = src->next;
  15964. }
  15965. // This function takes ownership of the store; the chain was deep-copied
  15966. // above, so release the source
  15967. free_ca_store(store);
  15968. // Update the SSL config to use the new CA chain
  15969. mbedtls_ssl_conf_ca_chain(&mbed_ctx->conf, &mbed_ctx->ca_chain, nullptr);
  15970. return true;
  15971. }
  15972. inline size_t get_ca_certs(ctx_t ctx, std::vector<cert_t> &certs) {
  15973. certs.clear();
  15974. if (!ctx) { return 0; }
  15975. auto *mbed_ctx = static_cast<impl::MbedTlsContext *>(ctx);
  15976. // Iterate through the CA chain
  15977. mbedtls_x509_crt *cert = &mbed_ctx->ca_chain;
  15978. while (cert != nullptr && cert->raw.len > 0) {
  15979. // Create a copy of the certificate for the caller
  15980. auto *copy = new mbedtls_x509_crt;
  15981. mbedtls_x509_crt_init(copy);
  15982. int ret = mbedtls_x509_crt_parse_der(copy, cert->raw.p, cert->raw.len);
  15983. if (ret == 0) {
  15984. certs.push_back(static_cast<cert_t>(copy));
  15985. } else {
  15986. mbedtls_x509_crt_free(copy);
  15987. delete copy;
  15988. }
  15989. cert = cert->next;
  15990. }
  15991. return certs.size();
  15992. }
  15993. inline std::vector<std::string> get_ca_names(ctx_t ctx) {
  15994. std::vector<std::string> names;
  15995. if (!ctx) { return names; }
  15996. auto *mbed_ctx = static_cast<impl::MbedTlsContext *>(ctx);
  15997. // Iterate through the CA chain
  15998. mbedtls_x509_crt *cert = &mbed_ctx->ca_chain;
  15999. while (cert != nullptr && cert->raw.len > 0) {
  16000. char buf[512];
  16001. int ret = mbedtls_x509_dn_gets(buf, sizeof(buf), &cert->subject);
  16002. if (ret > 0) { names.push_back(buf); }
  16003. cert = cert->next;
  16004. }
  16005. return names;
  16006. }
  16007. inline bool update_server_cert(ctx_t ctx, const char *cert_pem,
  16008. const char *key_pem, const char *password) {
  16009. if (!ctx || !cert_pem || !key_pem) { return false; }
  16010. auto *mbed_ctx = static_cast<impl::MbedTlsContext *>(ctx);
  16011. // Free existing certificate and key
  16012. mbedtls_x509_crt_free(&mbed_ctx->own_cert);
  16013. mbedtls_pk_free(&mbed_ctx->own_key);
  16014. mbedtls_x509_crt_init(&mbed_ctx->own_cert);
  16015. mbedtls_pk_init(&mbed_ctx->own_key);
  16016. // Parse certificate PEM
  16017. int ret = mbedtls_x509_crt_parse(
  16018. &mbed_ctx->own_cert, reinterpret_cast<const unsigned char *>(cert_pem),
  16019. strlen(cert_pem) + 1);
  16020. if (ret != 0) {
  16021. impl::mbedtls_last_error() = ret;
  16022. return false;
  16023. }
  16024. // Parse private key PEM
  16025. #ifdef CPPHTTPLIB_MBEDTLS_V3
  16026. ret = mbedtls_pk_parse_key(
  16027. &mbed_ctx->own_key, reinterpret_cast<const unsigned char *>(key_pem),
  16028. strlen(key_pem) + 1,
  16029. password ? reinterpret_cast<const unsigned char *>(password) : nullptr,
  16030. password ? strlen(password) : 0, mbedtls_ctr_drbg_random,
  16031. &mbed_ctx->ctr_drbg);
  16032. #else
  16033. ret = mbedtls_pk_parse_key(
  16034. &mbed_ctx->own_key, reinterpret_cast<const unsigned char *>(key_pem),
  16035. strlen(key_pem) + 1,
  16036. password ? reinterpret_cast<const unsigned char *>(password) : nullptr,
  16037. password ? strlen(password) : 0);
  16038. #endif
  16039. if (ret != 0) {
  16040. impl::mbedtls_last_error() = ret;
  16041. return false;
  16042. }
  16043. // Configure SSL to use the new certificate and key
  16044. ret = mbedtls_ssl_conf_own_cert(&mbed_ctx->conf, &mbed_ctx->own_cert,
  16045. &mbed_ctx->own_key);
  16046. if (ret != 0) {
  16047. impl::mbedtls_last_error() = ret;
  16048. return false;
  16049. }
  16050. return true;
  16051. }
  16052. inline bool update_server_client_ca(ctx_t ctx, const char *ca_pem) {
  16053. if (!ctx || !ca_pem) { return false; }
  16054. auto *mbed_ctx = static_cast<impl::MbedTlsContext *>(ctx);
  16055. // Free existing CA chain
  16056. mbedtls_x509_crt_free(&mbed_ctx->ca_chain);
  16057. mbedtls_x509_crt_init(&mbed_ctx->ca_chain);
  16058. // Parse CA PEM
  16059. int ret = mbedtls_x509_crt_parse(
  16060. &mbed_ctx->ca_chain, reinterpret_cast<const unsigned char *>(ca_pem),
  16061. strlen(ca_pem) + 1);
  16062. if (ret != 0) {
  16063. impl::mbedtls_last_error() = ret;
  16064. return false;
  16065. }
  16066. // Update SSL config to use new CA chain
  16067. mbedtls_ssl_conf_ca_chain(&mbed_ctx->conf, &mbed_ctx->ca_chain, nullptr);
  16068. return true;
  16069. }
  16070. inline bool set_verify_callback(ctx_t ctx, VerifyCallback callback) {
  16071. if (!ctx) { return false; }
  16072. auto *mbed_ctx = static_cast<impl::MbedTlsContext *>(ctx);
  16073. impl::get_verify_callback() = std::move(callback);
  16074. mbed_ctx->has_verify_callback =
  16075. static_cast<bool>(impl::get_verify_callback());
  16076. if (mbed_ctx->has_verify_callback) {
  16077. // Set OPTIONAL mode to ensure callback is called even when verification
  16078. // is disabled (matching OpenSSL behavior where SSL_VERIFY_PEER is set)
  16079. mbedtls_ssl_conf_authmode(&mbed_ctx->conf, MBEDTLS_SSL_VERIFY_OPTIONAL);
  16080. mbedtls_ssl_conf_verify(&mbed_ctx->conf, impl::mbedtls_verify_callback,
  16081. nullptr);
  16082. } else {
  16083. mbedtls_ssl_conf_verify(&mbed_ctx->conf, nullptr, nullptr);
  16084. }
  16085. return true;
  16086. }
  16087. inline long get_verify_error(const_session_t session) {
  16088. if (!session) { return -1; }
  16089. auto *msession =
  16090. static_cast<impl::MbedTlsSession *>(const_cast<void *>(session));
  16091. return static_cast<long>(mbedtls_ssl_get_verify_result(&msession->ssl));
  16092. }
  16093. inline std::string verify_error_string(long error_code) {
  16094. if (error_code == 0) { return ""; }
  16095. char buf[256];
  16096. mbedtls_x509_crt_verify_info(buf, sizeof(buf), "",
  16097. static_cast<uint32_t>(error_code));
  16098. // Remove trailing newline if present
  16099. std::string result(buf);
  16100. while (!result.empty() && (result.back() == '\n' || result.back() == ' ')) {
  16101. result.pop_back();
  16102. }
  16103. return result;
  16104. }
  16105. } // namespace tls
  16106. #endif // CPPHTTPLIB_MBEDTLS_SUPPORT
  16107. /*
  16108. * Group 10: TLS abstraction layer - wolfSSL backend
  16109. */
  16110. /*
  16111. * wolfSSL Backend Implementation
  16112. */
  16113. #ifdef CPPHTTPLIB_WOLFSSL_SUPPORT
  16114. namespace tls {
  16115. namespace impl {
  16116. // wolfSSL session wrapper
  16117. struct WolfSSLSession {
  16118. WOLFSSL *ssl = nullptr;
  16119. socket_t sock = INVALID_SOCKET;
  16120. std::string hostname; // For client: set via set_sni
  16121. std::string sni_hostname; // For server: received from client via SNI callback
  16122. WolfSSLSession() = default;
  16123. ~WolfSSLSession() {
  16124. if (ssl) { wolfSSL_free(ssl); }
  16125. }
  16126. WolfSSLSession(const WolfSSLSession &) = delete;
  16127. WolfSSLSession &operator=(const WolfSSLSession &) = delete;
  16128. };
  16129. // Thread-local error code accessor for wolfSSL
  16130. inline uint64_t &wolfssl_last_error() {
  16131. static thread_local uint64_t err = 0;
  16132. return err;
  16133. }
  16134. // Helper to map wolfSSL error to ErrorCode.
  16135. // ssl_error is the value from wolfSSL_get_error().
  16136. // raw_ret is the raw return value from the wolfSSL call (for low-level error).
  16137. inline ErrorCode map_wolfssl_error(WOLFSSL *ssl, int ssl_error,
  16138. int &out_errno) {
  16139. switch (ssl_error) {
  16140. case SSL_ERROR_NONE: return ErrorCode::Success;
  16141. case SSL_ERROR_WANT_READ: return ErrorCode::WantRead;
  16142. case SSL_ERROR_WANT_WRITE: return ErrorCode::WantWrite;
  16143. case SSL_ERROR_ZERO_RETURN: return ErrorCode::PeerClosed;
  16144. case SSL_ERROR_SYSCALL: out_errno = errno; return ErrorCode::SyscallError;
  16145. default:
  16146. if (ssl) {
  16147. // wolfSSL stores the low-level error code as a negative value.
  16148. // DOMAIN_NAME_MISMATCH (-322) indicates hostname verification failure.
  16149. int low_err = ssl_error; // wolfSSL_get_error returns the low-level code
  16150. if (low_err == DOMAIN_NAME_MISMATCH) {
  16151. return ErrorCode::HostnameMismatch;
  16152. }
  16153. // Check verify result to distinguish cert verification from generic SSL
  16154. // errors.
  16155. long vr = wolfSSL_get_verify_result(ssl);
  16156. if (vr != 0) { return ErrorCode::CertVerifyFailed; }
  16157. }
  16158. return ErrorCode::Fatal;
  16159. }
  16160. }
  16161. // WolfSSLContext constructor/destructor implementations
  16162. inline WolfSSLContext::WolfSSLContext() { wolfSSL_Init(); }
  16163. inline WolfSSLContext::~WolfSSLContext() {
  16164. if (ctx) { wolfSSL_CTX_free(ctx); }
  16165. }
  16166. // Thread-local storage for SNI captured during handshake
  16167. inline std::string &wolfssl_pending_sni() {
  16168. static thread_local std::string sni;
  16169. return sni;
  16170. }
  16171. // SNI callback for wolfSSL server to capture client's SNI hostname
  16172. inline int wolfssl_sni_callback(WOLFSSL *ssl, int *ret, void *exArg) {
  16173. (void)ret;
  16174. (void)exArg;
  16175. void *name_data = nullptr;
  16176. unsigned short name_len =
  16177. wolfSSL_SNI_GetRequest(ssl, WOLFSSL_SNI_HOST_NAME, &name_data);
  16178. if (name_data && name_len > 0) {
  16179. wolfssl_pending_sni().assign(static_cast<const char *>(name_data),
  16180. name_len);
  16181. } else {
  16182. wolfssl_pending_sni().clear();
  16183. }
  16184. return 0; // Continue regardless
  16185. }
  16186. // wolfSSL verify callback wrapper
  16187. inline int wolfssl_verify_callback(int preverify_ok,
  16188. WOLFSSL_X509_STORE_CTX *x509_ctx) {
  16189. auto &callback = get_verify_callback();
  16190. if (!callback) { return preverify_ok; }
  16191. WOLFSSL_X509 *cert = wolfSSL_X509_STORE_CTX_get_current_cert(x509_ctx);
  16192. int depth = wolfSSL_X509_STORE_CTX_get_error_depth(x509_ctx);
  16193. int err = wolfSSL_X509_STORE_CTX_get_error(x509_ctx);
  16194. // Get the WOLFSSL object from the X509_STORE_CTX
  16195. WOLFSSL *ssl = static_cast<WOLFSSL *>(wolfSSL_X509_STORE_CTX_get_ex_data(
  16196. x509_ctx, wolfSSL_get_ex_data_X509_STORE_CTX_idx()));
  16197. VerifyContext verify_ctx;
  16198. verify_ctx.session = static_cast<session_t>(ssl);
  16199. verify_ctx.cert = static_cast<cert_t>(cert);
  16200. verify_ctx.depth = depth;
  16201. verify_ctx.preverify_ok = (preverify_ok != 0);
  16202. verify_ctx.error_code = static_cast<long>(err);
  16203. if (err != 0) {
  16204. verify_ctx.error_string = wolfSSL_X509_verify_cert_error_string(err);
  16205. } else {
  16206. verify_ctx.error_string = nullptr;
  16207. }
  16208. bool accepted = callback(verify_ctx);
  16209. return accepted ? 1 : 0;
  16210. }
  16211. inline void set_wolfssl_password_cb(WOLFSSL_CTX *ctx, const char *password) {
  16212. wolfSSL_CTX_set_default_passwd_cb_userdata(ctx, const_cast<char *>(password));
  16213. wolfSSL_CTX_set_default_passwd_cb(
  16214. ctx, [](char *buf, int size, int /*rwflag*/, void *userdata) -> int {
  16215. auto *pwd = static_cast<const char *>(userdata);
  16216. if (!pwd) return 0;
  16217. auto len = static_cast<int>(strlen(pwd));
  16218. if (len > size) len = size;
  16219. memcpy(buf, pwd, static_cast<size_t>(len));
  16220. return len;
  16221. });
  16222. }
  16223. } // namespace impl
  16224. inline ctx_t create_client_context() {
  16225. auto ctx = new (std::nothrow) impl::WolfSSLContext();
  16226. if (!ctx) { return nullptr; }
  16227. ctx->is_server = false;
  16228. WOLFSSL_METHOD *method = wolfTLSv1_2_client_method();
  16229. if (!method) {
  16230. delete ctx;
  16231. return nullptr;
  16232. }
  16233. ctx->ctx = wolfSSL_CTX_new(method);
  16234. if (!ctx->ctx) {
  16235. delete ctx;
  16236. return nullptr;
  16237. }
  16238. // Default: verify peer certificate
  16239. wolfSSL_CTX_set_verify(ctx->ctx, SSL_VERIFY_PEER, nullptr);
  16240. return static_cast<ctx_t>(ctx);
  16241. }
  16242. inline ctx_t create_server_context() {
  16243. auto ctx = new (std::nothrow) impl::WolfSSLContext();
  16244. if (!ctx) { return nullptr; }
  16245. ctx->is_server = true;
  16246. WOLFSSL_METHOD *method = wolfTLSv1_2_server_method();
  16247. if (!method) {
  16248. delete ctx;
  16249. return nullptr;
  16250. }
  16251. ctx->ctx = wolfSSL_CTX_new(method);
  16252. if (!ctx->ctx) {
  16253. delete ctx;
  16254. return nullptr;
  16255. }
  16256. // Default: don't verify client
  16257. wolfSSL_CTX_set_verify(ctx->ctx, SSL_VERIFY_NONE, nullptr);
  16258. // Enable SNI on server
  16259. wolfSSL_CTX_SNI_SetOptions(ctx->ctx, WOLFSSL_SNI_HOST_NAME,
  16260. WOLFSSL_SNI_CONTINUE_ON_MISMATCH);
  16261. wolfSSL_CTX_set_servername_callback(ctx->ctx, impl::wolfssl_sni_callback);
  16262. return static_cast<ctx_t>(ctx);
  16263. }
  16264. inline void free_context(ctx_t ctx) {
  16265. if (ctx) { delete static_cast<impl::WolfSSLContext *>(ctx); }
  16266. }
  16267. inline bool set_min_version(ctx_t ctx, Version version) {
  16268. if (!ctx) { return false; }
  16269. auto wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16270. int min_ver = WOLFSSL_TLSV1_2;
  16271. if (version >= Version::TLS1_3) { min_ver = WOLFSSL_TLSV1_3; }
  16272. return wolfSSL_CTX_SetMinVersion(wctx->ctx, min_ver) == WOLFSSL_SUCCESS;
  16273. }
  16274. inline bool load_ca_pem(ctx_t ctx, const char *pem, size_t len) {
  16275. if (!ctx || !pem) { return false; }
  16276. auto wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16277. int ret = wolfSSL_CTX_load_verify_buffer(
  16278. wctx->ctx, reinterpret_cast<const unsigned char *>(pem),
  16279. static_cast<long>(len), SSL_FILETYPE_PEM);
  16280. if (ret != SSL_SUCCESS) {
  16281. impl::wolfssl_last_error() =
  16282. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16283. return false;
  16284. }
  16285. wctx->ca_pem_data_.append(pem, len);
  16286. return true;
  16287. }
  16288. inline bool load_ca_file(ctx_t ctx, const char *file_path) {
  16289. if (!ctx || !file_path) { return false; }
  16290. auto wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16291. int ret = wolfSSL_CTX_load_verify_locations(wctx->ctx, file_path, nullptr);
  16292. if (ret != SSL_SUCCESS) {
  16293. impl::wolfssl_last_error() =
  16294. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16295. return false;
  16296. }
  16297. return true;
  16298. }
  16299. inline bool load_ca_dir(ctx_t ctx, const char *dir_path) {
  16300. if (!ctx || !dir_path) { return false; }
  16301. auto wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16302. int ret = wolfSSL_CTX_load_verify_locations(wctx->ctx, nullptr, dir_path);
  16303. // wolfSSL may fail if the directory doesn't contain properly hashed certs.
  16304. // Unlike OpenSSL which lazily loads certs from directories, wolfSSL scans
  16305. // immediately. Return true even on failure since the CA file may have
  16306. // already been loaded, matching OpenSSL's lenient behavior.
  16307. (void)ret;
  16308. return true;
  16309. }
  16310. inline bool load_system_certs(ctx_t ctx) {
  16311. if (!ctx) { return false; }
  16312. auto wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16313. bool loaded = false;
  16314. #ifdef _WIN32
  16315. loaded = impl::enumerate_windows_system_certs(
  16316. [&](const unsigned char *data, size_t len) {
  16317. return wolfSSL_CTX_load_verify_buffer(wctx->ctx, data,
  16318. static_cast<long>(len),
  16319. SSL_FILETYPE_ASN1) == SSL_SUCCESS;
  16320. });
  16321. #elif defined(__APPLE__) && defined(CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN)
  16322. loaded = impl::enumerate_macos_keychain_certs(
  16323. [&](const unsigned char *data, size_t len) {
  16324. return wolfSSL_CTX_load_verify_buffer(wctx->ctx, data,
  16325. static_cast<long>(len),
  16326. SSL_FILETYPE_ASN1) == SSL_SUCCESS;
  16327. });
  16328. #else
  16329. for (auto path = impl::system_ca_paths(); *path; ++path) {
  16330. if (wolfSSL_CTX_load_verify_locations(wctx->ctx, *path, nullptr) ==
  16331. SSL_SUCCESS) {
  16332. loaded = true;
  16333. break;
  16334. }
  16335. }
  16336. if (!loaded) {
  16337. for (auto dir = impl::system_ca_dirs(); *dir; ++dir) {
  16338. if (wolfSSL_CTX_load_verify_locations(wctx->ctx, nullptr, *dir) ==
  16339. SSL_SUCCESS) {
  16340. loaded = true;
  16341. break;
  16342. }
  16343. }
  16344. }
  16345. #endif
  16346. return loaded;
  16347. }
  16348. inline bool set_client_cert_pem(ctx_t ctx, const char *cert, const char *key,
  16349. const char *password) {
  16350. if (!ctx || !cert || !key) { return false; }
  16351. auto wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16352. // Load certificate
  16353. int ret = wolfSSL_CTX_use_certificate_buffer(
  16354. wctx->ctx, reinterpret_cast<const unsigned char *>(cert),
  16355. static_cast<long>(strlen(cert)), SSL_FILETYPE_PEM);
  16356. if (ret != SSL_SUCCESS) {
  16357. impl::wolfssl_last_error() =
  16358. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16359. return false;
  16360. }
  16361. // Set password callback if password is provided
  16362. if (password) { impl::set_wolfssl_password_cb(wctx->ctx, password); }
  16363. // Load private key
  16364. ret = wolfSSL_CTX_use_PrivateKey_buffer(
  16365. wctx->ctx, reinterpret_cast<const unsigned char *>(key),
  16366. static_cast<long>(strlen(key)), SSL_FILETYPE_PEM);
  16367. if (ret != SSL_SUCCESS) {
  16368. impl::wolfssl_last_error() =
  16369. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16370. return false;
  16371. }
  16372. // Verify that the certificate and private key match
  16373. return wolfSSL_CTX_check_private_key(wctx->ctx) == SSL_SUCCESS;
  16374. }
  16375. inline bool set_client_cert_file(ctx_t ctx, const char *cert_path,
  16376. const char *key_path, const char *password) {
  16377. if (!ctx || !cert_path || !key_path) { return false; }
  16378. auto wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16379. // Load certificate file
  16380. int ret =
  16381. wolfSSL_CTX_use_certificate_file(wctx->ctx, cert_path, SSL_FILETYPE_PEM);
  16382. if (ret != SSL_SUCCESS) {
  16383. impl::wolfssl_last_error() =
  16384. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16385. return false;
  16386. }
  16387. // Set password callback if password is provided
  16388. if (password) { impl::set_wolfssl_password_cb(wctx->ctx, password); }
  16389. // Load private key file
  16390. ret = wolfSSL_CTX_use_PrivateKey_file(wctx->ctx, key_path, SSL_FILETYPE_PEM);
  16391. if (ret != SSL_SUCCESS) {
  16392. impl::wolfssl_last_error() =
  16393. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16394. return false;
  16395. }
  16396. // Verify that the certificate and private key match
  16397. return wolfSSL_CTX_check_private_key(wctx->ctx) == SSL_SUCCESS;
  16398. }
  16399. inline void set_verify_client(ctx_t ctx, bool require) {
  16400. if (!ctx) { return; }
  16401. auto wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16402. wctx->verify_client = require;
  16403. if (require) {
  16404. wolfSSL_CTX_set_verify(
  16405. wctx->ctx, SSL_VERIFY_PEER | SSL_VERIFY_FAIL_IF_NO_PEER_CERT,
  16406. wctx->has_verify_callback ? impl::wolfssl_verify_callback : nullptr);
  16407. } else {
  16408. if (wctx->has_verify_callback) {
  16409. wolfSSL_CTX_set_verify(wctx->ctx, SSL_VERIFY_PEER,
  16410. impl::wolfssl_verify_callback);
  16411. } else {
  16412. wolfSSL_CTX_set_verify(wctx->ctx, SSL_VERIFY_NONE, nullptr);
  16413. }
  16414. }
  16415. }
  16416. inline session_t create_session(ctx_t ctx, socket_t sock) {
  16417. if (!ctx || sock == INVALID_SOCKET) { return nullptr; }
  16418. auto wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16419. auto session = new (std::nothrow) impl::WolfSSLSession();
  16420. if (!session) { return nullptr; }
  16421. session->sock = sock;
  16422. session->ssl = wolfSSL_new(wctx->ctx);
  16423. if (!session->ssl) {
  16424. impl::wolfssl_last_error() =
  16425. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16426. delete session;
  16427. return nullptr;
  16428. }
  16429. wolfSSL_set_fd(session->ssl, static_cast<int>(sock));
  16430. return static_cast<session_t>(session);
  16431. }
  16432. inline void free_session(session_t session) {
  16433. if (session) { delete static_cast<impl::WolfSSLSession *>(session); }
  16434. }
  16435. inline bool set_sni(session_t session, const char *hostname) {
  16436. if (!session || !hostname) { return false; }
  16437. auto wsession = static_cast<impl::WolfSSLSession *>(session);
  16438. int ret = wolfSSL_UseSNI(wsession->ssl, WOLFSSL_SNI_HOST_NAME, hostname,
  16439. static_cast<word16>(strlen(hostname)));
  16440. if (ret != WOLFSSL_SUCCESS) {
  16441. impl::wolfssl_last_error() =
  16442. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16443. return false;
  16444. }
  16445. // Also set hostname for verification
  16446. wolfSSL_check_domain_name(wsession->ssl, hostname);
  16447. wsession->hostname = hostname;
  16448. return true;
  16449. }
  16450. inline bool set_hostname(session_t session, const char *hostname) {
  16451. // In wolfSSL, set_hostname also sets up hostname verification
  16452. return set_sni(session, hostname);
  16453. }
  16454. inline TlsError connect(session_t session) {
  16455. TlsError err;
  16456. if (!session) {
  16457. err.code = ErrorCode::Fatal;
  16458. return err;
  16459. }
  16460. auto wsession = static_cast<impl::WolfSSLSession *>(session);
  16461. int ret = wolfSSL_connect(wsession->ssl);
  16462. if (ret == SSL_SUCCESS) {
  16463. err.code = ErrorCode::Success;
  16464. } else {
  16465. int ssl_error = wolfSSL_get_error(wsession->ssl, ret);
  16466. err.code = impl::map_wolfssl_error(wsession->ssl, ssl_error, err.sys_errno);
  16467. err.backend_code = static_cast<uint64_t>(ssl_error);
  16468. impl::wolfssl_last_error() = err.backend_code;
  16469. }
  16470. return err;
  16471. }
  16472. inline TlsError accept(session_t session) {
  16473. TlsError err;
  16474. if (!session) {
  16475. err.code = ErrorCode::Fatal;
  16476. return err;
  16477. }
  16478. auto wsession = static_cast<impl::WolfSSLSession *>(session);
  16479. int ret = wolfSSL_accept(wsession->ssl);
  16480. if (ret == SSL_SUCCESS) {
  16481. err.code = ErrorCode::Success;
  16482. // Capture SNI from thread-local storage after successful handshake
  16483. wsession->sni_hostname = std::move(impl::wolfssl_pending_sni());
  16484. impl::wolfssl_pending_sni().clear();
  16485. } else {
  16486. int ssl_error = wolfSSL_get_error(wsession->ssl, ret);
  16487. err.code = impl::map_wolfssl_error(wsession->ssl, ssl_error, err.sys_errno);
  16488. err.backend_code = static_cast<uint64_t>(ssl_error);
  16489. impl::wolfssl_last_error() = err.backend_code;
  16490. }
  16491. return err;
  16492. }
  16493. inline bool connect_nonblocking(session_t session, socket_t sock,
  16494. time_t timeout_sec, time_t timeout_usec,
  16495. TlsError *err) {
  16496. if (!session) {
  16497. if (err) { err->code = ErrorCode::Fatal; }
  16498. return false;
  16499. }
  16500. auto wsession = static_cast<impl::WolfSSLSession *>(session);
  16501. // Set socket to non-blocking mode
  16502. detail::set_nonblocking(sock, true);
  16503. auto cleanup =
  16504. detail::scope_exit([&]() { detail::set_nonblocking(sock, false); });
  16505. int ret;
  16506. while ((ret = wolfSSL_connect(wsession->ssl)) != SSL_SUCCESS) {
  16507. int ssl_error = wolfSSL_get_error(wsession->ssl, ret);
  16508. if (ssl_error == SSL_ERROR_WANT_READ) {
  16509. if (detail::select_read(sock, timeout_sec, timeout_usec) > 0) {
  16510. continue;
  16511. }
  16512. } else if (ssl_error == SSL_ERROR_WANT_WRITE) {
  16513. if (detail::select_write(sock, timeout_sec, timeout_usec) > 0) {
  16514. continue;
  16515. }
  16516. }
  16517. // Error or timeout
  16518. if (err) {
  16519. err->code =
  16520. impl::map_wolfssl_error(wsession->ssl, ssl_error, err->sys_errno);
  16521. err->backend_code = static_cast<uint64_t>(ssl_error);
  16522. }
  16523. impl::wolfssl_last_error() = static_cast<uint64_t>(ssl_error);
  16524. return false;
  16525. }
  16526. if (err) { err->code = ErrorCode::Success; }
  16527. return true;
  16528. }
  16529. inline bool accept_nonblocking(session_t session, socket_t sock,
  16530. time_t timeout_sec, time_t timeout_usec,
  16531. TlsError *err) {
  16532. if (!session) {
  16533. if (err) { err->code = ErrorCode::Fatal; }
  16534. return false;
  16535. }
  16536. auto wsession = static_cast<impl::WolfSSLSession *>(session);
  16537. // Set socket to non-blocking mode
  16538. detail::set_nonblocking(sock, true);
  16539. auto cleanup =
  16540. detail::scope_exit([&]() { detail::set_nonblocking(sock, false); });
  16541. int ret;
  16542. while ((ret = wolfSSL_accept(wsession->ssl)) != SSL_SUCCESS) {
  16543. int ssl_error = wolfSSL_get_error(wsession->ssl, ret);
  16544. if (ssl_error == SSL_ERROR_WANT_READ) {
  16545. if (detail::select_read(sock, timeout_sec, timeout_usec) > 0) {
  16546. continue;
  16547. }
  16548. } else if (ssl_error == SSL_ERROR_WANT_WRITE) {
  16549. if (detail::select_write(sock, timeout_sec, timeout_usec) > 0) {
  16550. continue;
  16551. }
  16552. }
  16553. // Error or timeout
  16554. if (err) {
  16555. err->code =
  16556. impl::map_wolfssl_error(wsession->ssl, ssl_error, err->sys_errno);
  16557. err->backend_code = static_cast<uint64_t>(ssl_error);
  16558. }
  16559. impl::wolfssl_last_error() = static_cast<uint64_t>(ssl_error);
  16560. return false;
  16561. }
  16562. if (err) { err->code = ErrorCode::Success; }
  16563. // Capture SNI from thread-local storage after successful handshake
  16564. wsession->sni_hostname = std::move(impl::wolfssl_pending_sni());
  16565. impl::wolfssl_pending_sni().clear();
  16566. return true;
  16567. }
  16568. inline ssize_t read(session_t session, void *buf, size_t len, TlsError &err) {
  16569. if (!session || !buf) {
  16570. err.code = ErrorCode::Fatal;
  16571. return -1;
  16572. }
  16573. auto wsession = static_cast<impl::WolfSSLSession *>(session);
  16574. int ret = wolfSSL_read(wsession->ssl, buf, static_cast<int>(len));
  16575. if (ret > 0) {
  16576. err.code = ErrorCode::Success;
  16577. return static_cast<ssize_t>(ret);
  16578. }
  16579. if (ret == 0) {
  16580. err.code = ErrorCode::PeerClosed;
  16581. return 0;
  16582. }
  16583. int ssl_error = wolfSSL_get_error(wsession->ssl, ret);
  16584. err.code = impl::map_wolfssl_error(wsession->ssl, ssl_error, err.sys_errno);
  16585. err.backend_code = static_cast<uint64_t>(ssl_error);
  16586. impl::wolfssl_last_error() = err.backend_code;
  16587. return -1;
  16588. }
  16589. inline ssize_t write(session_t session, const void *buf, size_t len,
  16590. TlsError &err) {
  16591. if (!session || !buf) {
  16592. err.code = ErrorCode::Fatal;
  16593. return -1;
  16594. }
  16595. auto wsession = static_cast<impl::WolfSSLSession *>(session);
  16596. int ret = wolfSSL_write(wsession->ssl, buf, static_cast<int>(len));
  16597. if (ret > 0) {
  16598. err.code = ErrorCode::Success;
  16599. return static_cast<ssize_t>(ret);
  16600. }
  16601. // wolfSSL_write returns 0 when the peer has sent a close_notify.
  16602. // Treat this as an error (return -1) so callers don't spin in a
  16603. // write loop adding zero to the offset.
  16604. if (ret == 0) {
  16605. err.code = ErrorCode::PeerClosed;
  16606. return -1;
  16607. }
  16608. int ssl_error = wolfSSL_get_error(wsession->ssl, ret);
  16609. err.code = impl::map_wolfssl_error(wsession->ssl, ssl_error, err.sys_errno);
  16610. err.backend_code = static_cast<uint64_t>(ssl_error);
  16611. impl::wolfssl_last_error() = err.backend_code;
  16612. return -1;
  16613. }
  16614. inline int pending(const_session_t session) {
  16615. if (!session) { return 0; }
  16616. auto wsession =
  16617. static_cast<impl::WolfSSLSession *>(const_cast<void *>(session));
  16618. return wolfSSL_pending(wsession->ssl);
  16619. }
  16620. inline void shutdown(session_t session, bool graceful) {
  16621. if (!session) { return; }
  16622. auto wsession = static_cast<impl::WolfSSLSession *>(session);
  16623. if (graceful) {
  16624. int ret;
  16625. int attempts = 0;
  16626. while ((ret = wolfSSL_shutdown(wsession->ssl)) != SSL_SUCCESS &&
  16627. attempts < 3) {
  16628. int ssl_error = wolfSSL_get_error(wsession->ssl, ret);
  16629. if (ssl_error != SSL_ERROR_WANT_READ &&
  16630. ssl_error != SSL_ERROR_WANT_WRITE) {
  16631. break;
  16632. }
  16633. attempts++;
  16634. }
  16635. } else {
  16636. wolfSSL_shutdown(wsession->ssl);
  16637. }
  16638. }
  16639. inline bool is_peer_closed(session_t session, socket_t sock) {
  16640. if (!session || sock == INVALID_SOCKET) { return true; }
  16641. auto wsession = static_cast<impl::WolfSSLSession *>(session);
  16642. // Check if there's already decrypted data available
  16643. if (wolfSSL_pending(wsession->ssl) > 0) { return false; }
  16644. // Set socket to non-blocking to avoid blocking on read
  16645. detail::set_nonblocking(sock, true);
  16646. auto cleanup =
  16647. detail::scope_exit([&]() { detail::set_nonblocking(sock, false); });
  16648. // Peek 1 byte to check connection status without consuming data
  16649. unsigned char buf;
  16650. int ret = wolfSSL_peek(wsession->ssl, &buf, 1);
  16651. // If we got data or WANT_READ (would block), connection is alive
  16652. if (ret > 0) { return false; }
  16653. int ssl_error = wolfSSL_get_error(wsession->ssl, ret);
  16654. if (ssl_error == SSL_ERROR_WANT_READ) { return false; }
  16655. return ssl_error == SSL_ERROR_ZERO_RETURN || ssl_error == SSL_ERROR_SYSCALL ||
  16656. ret == 0;
  16657. }
  16658. inline cert_t get_peer_cert(const_session_t session) {
  16659. if (!session) { return nullptr; }
  16660. auto wsession =
  16661. static_cast<impl::WolfSSLSession *>(const_cast<void *>(session));
  16662. WOLFSSL_X509 *cert = wolfSSL_get_peer_certificate(wsession->ssl);
  16663. return static_cast<cert_t>(cert);
  16664. }
  16665. inline void free_cert(cert_t cert) {
  16666. if (cert) { wolfSSL_X509_free(static_cast<WOLFSSL_X509 *>(cert)); }
  16667. }
  16668. inline bool verify_hostname(cert_t cert, const char *hostname) {
  16669. if (!cert || !hostname) { return false; }
  16670. auto x509 = static_cast<WOLFSSL_X509 *>(cert);
  16671. std::string host_str(hostname);
  16672. // Check if hostname is an IP address
  16673. bool is_ip = impl::is_ipv4_address(host_str);
  16674. unsigned char ip_bytes[4];
  16675. if (is_ip) { impl::parse_ipv4(host_str, ip_bytes); }
  16676. // Check Subject Alternative Names
  16677. auto *san_names = static_cast<WOLF_STACK_OF(WOLFSSL_GENERAL_NAME) *>(
  16678. wolfSSL_X509_get_ext_d2i(x509, NID_subject_alt_name, nullptr, nullptr));
  16679. if (san_names) {
  16680. int san_count = wolfSSL_sk_num(san_names);
  16681. for (int i = 0; i < san_count; i++) {
  16682. auto *names =
  16683. static_cast<WOLFSSL_GENERAL_NAME *>(wolfSSL_sk_value(san_names, i));
  16684. if (!names) continue;
  16685. if (!is_ip && names->type == WOLFSSL_GEN_DNS) {
  16686. // DNS name
  16687. unsigned char *dns_name = nullptr;
  16688. int dns_len = wolfSSL_ASN1_STRING_to_UTF8(&dns_name, names->d.dNSName);
  16689. if (dns_name && dns_len > 0) {
  16690. std::string san_name(reinterpret_cast<char *>(dns_name),
  16691. static_cast<size_t>(dns_len));
  16692. XFREE(dns_name, nullptr, DYNAMIC_TYPE_OPENSSL);
  16693. if (detail::match_hostname(san_name, host_str)) {
  16694. wolfSSL_sk_free(san_names);
  16695. return true;
  16696. }
  16697. }
  16698. } else if (is_ip && names->type == WOLFSSL_GEN_IPADD) {
  16699. // IP address
  16700. unsigned char *ip_data = wolfSSL_ASN1_STRING_data(names->d.iPAddress);
  16701. int ip_len = wolfSSL_ASN1_STRING_length(names->d.iPAddress);
  16702. if (ip_data && ip_len == 4 && memcmp(ip_data, ip_bytes, 4) == 0) {
  16703. wolfSSL_sk_free(san_names);
  16704. return true;
  16705. }
  16706. }
  16707. }
  16708. wolfSSL_sk_free(san_names);
  16709. }
  16710. // Fallback: Check Common Name (CN) in subject
  16711. WOLFSSL_X509_NAME *subject = wolfSSL_X509_get_subject_name(x509);
  16712. if (subject) {
  16713. char cn[256] = {};
  16714. int cn_len = wolfSSL_X509_NAME_get_text_by_NID(subject, NID_commonName, cn,
  16715. sizeof(cn));
  16716. if (cn_len > 0) {
  16717. std::string cn_str(cn, static_cast<size_t>(cn_len));
  16718. if (detail::match_hostname(cn_str, host_str)) { return true; }
  16719. }
  16720. }
  16721. return false;
  16722. }
  16723. inline uint64_t hostname_mismatch_code() {
  16724. return static_cast<uint64_t>(DOMAIN_NAME_MISMATCH);
  16725. }
  16726. inline long get_verify_result(const_session_t session) {
  16727. if (!session) { return -1; }
  16728. auto wsession =
  16729. static_cast<impl::WolfSSLSession *>(const_cast<void *>(session));
  16730. long result = wolfSSL_get_verify_result(wsession->ssl);
  16731. return result;
  16732. }
  16733. inline std::string get_cert_subject_cn(cert_t cert) {
  16734. if (!cert) return "";
  16735. auto x509 = static_cast<WOLFSSL_X509 *>(cert);
  16736. WOLFSSL_X509_NAME *subject = wolfSSL_X509_get_subject_name(x509);
  16737. if (!subject) return "";
  16738. char cn[256] = {};
  16739. int cn_len = wolfSSL_X509_NAME_get_text_by_NID(subject, NID_commonName, cn,
  16740. sizeof(cn));
  16741. if (cn_len <= 0) return "";
  16742. return std::string(cn, static_cast<size_t>(cn_len));
  16743. }
  16744. inline std::string get_cert_issuer_name(cert_t cert) {
  16745. if (!cert) return "";
  16746. auto x509 = static_cast<WOLFSSL_X509 *>(cert);
  16747. WOLFSSL_X509_NAME *issuer = wolfSSL_X509_get_issuer_name(x509);
  16748. if (!issuer) return "";
  16749. char *name_str = wolfSSL_X509_NAME_oneline(issuer, nullptr, 0);
  16750. if (!name_str) return "";
  16751. std::string result(name_str);
  16752. XFREE(name_str, nullptr, DYNAMIC_TYPE_OPENSSL);
  16753. return result;
  16754. }
  16755. inline bool get_cert_sans(cert_t cert, std::vector<SanEntry> &sans) {
  16756. sans.clear();
  16757. if (!cert) return false;
  16758. auto x509 = static_cast<WOLFSSL_X509 *>(cert);
  16759. auto *san_names = static_cast<WOLF_STACK_OF(WOLFSSL_GENERAL_NAME) *>(
  16760. wolfSSL_X509_get_ext_d2i(x509, NID_subject_alt_name, nullptr, nullptr));
  16761. if (!san_names) return true; // No SANs is not an error
  16762. int count = wolfSSL_sk_num(san_names);
  16763. for (int i = 0; i < count; i++) {
  16764. auto *name =
  16765. static_cast<WOLFSSL_GENERAL_NAME *>(wolfSSL_sk_value(san_names, i));
  16766. if (!name) continue;
  16767. SanEntry entry;
  16768. switch (name->type) {
  16769. case WOLFSSL_GEN_DNS: {
  16770. entry.type = SanType::DNS;
  16771. unsigned char *dns_name = nullptr;
  16772. int dns_len = wolfSSL_ASN1_STRING_to_UTF8(&dns_name, name->d.dNSName);
  16773. if (dns_name && dns_len > 0) {
  16774. entry.value = std::string(reinterpret_cast<char *>(dns_name),
  16775. static_cast<size_t>(dns_len));
  16776. XFREE(dns_name, nullptr, DYNAMIC_TYPE_OPENSSL);
  16777. }
  16778. break;
  16779. }
  16780. case WOLFSSL_GEN_IPADD: {
  16781. entry.type = SanType::IP;
  16782. unsigned char *ip_data = wolfSSL_ASN1_STRING_data(name->d.iPAddress);
  16783. int ip_len = wolfSSL_ASN1_STRING_length(name->d.iPAddress);
  16784. if (ip_data && ip_len == 4) {
  16785. char buf[16];
  16786. snprintf(buf, sizeof(buf), "%d.%d.%d.%d", ip_data[0], ip_data[1],
  16787. ip_data[2], ip_data[3]);
  16788. entry.value = buf;
  16789. } else if (ip_data && ip_len == 16) {
  16790. char buf[64];
  16791. snprintf(buf, sizeof(buf),
  16792. "%02x%02x:%02x%02x:%02x%02x:%02x%02x:"
  16793. "%02x%02x:%02x%02x:%02x%02x:%02x%02x",
  16794. ip_data[0], ip_data[1], ip_data[2], ip_data[3], ip_data[4],
  16795. ip_data[5], ip_data[6], ip_data[7], ip_data[8], ip_data[9],
  16796. ip_data[10], ip_data[11], ip_data[12], ip_data[13],
  16797. ip_data[14], ip_data[15]);
  16798. entry.value = buf;
  16799. }
  16800. break;
  16801. }
  16802. case WOLFSSL_GEN_EMAIL:
  16803. entry.type = SanType::EMAIL;
  16804. {
  16805. unsigned char *email = nullptr;
  16806. int email_len = wolfSSL_ASN1_STRING_to_UTF8(&email, name->d.rfc822Name);
  16807. if (email && email_len > 0) {
  16808. entry.value = std::string(reinterpret_cast<char *>(email),
  16809. static_cast<size_t>(email_len));
  16810. XFREE(email, nullptr, DYNAMIC_TYPE_OPENSSL);
  16811. }
  16812. }
  16813. break;
  16814. case WOLFSSL_GEN_URI:
  16815. entry.type = SanType::URI;
  16816. {
  16817. unsigned char *uri = nullptr;
  16818. int uri_len = wolfSSL_ASN1_STRING_to_UTF8(
  16819. &uri, name->d.uniformResourceIdentifier);
  16820. if (uri && uri_len > 0) {
  16821. entry.value = std::string(reinterpret_cast<char *>(uri),
  16822. static_cast<size_t>(uri_len));
  16823. XFREE(uri, nullptr, DYNAMIC_TYPE_OPENSSL);
  16824. }
  16825. }
  16826. break;
  16827. default: entry.type = SanType::OTHER; break;
  16828. }
  16829. if (!entry.value.empty()) { sans.push_back(std::move(entry)); }
  16830. }
  16831. wolfSSL_sk_free(san_names);
  16832. return true;
  16833. }
  16834. inline bool get_cert_validity(cert_t cert, time_t &not_before,
  16835. time_t &not_after) {
  16836. if (!cert) return false;
  16837. auto x509 = static_cast<WOLFSSL_X509 *>(cert);
  16838. const WOLFSSL_ASN1_TIME *nb = wolfSSL_X509_get_notBefore(x509);
  16839. const WOLFSSL_ASN1_TIME *na = wolfSSL_X509_get_notAfter(x509);
  16840. if (!nb || !na) return false;
  16841. // wolfSSL_ASN1_TIME_to_tm is available
  16842. struct tm tm_nb = {}, tm_na = {};
  16843. if (wolfSSL_ASN1_TIME_to_tm(nb, &tm_nb) != WOLFSSL_SUCCESS) return false;
  16844. if (wolfSSL_ASN1_TIME_to_tm(na, &tm_na) != WOLFSSL_SUCCESS) return false;
  16845. #ifdef _WIN32
  16846. not_before = _mkgmtime(&tm_nb);
  16847. not_after = _mkgmtime(&tm_na);
  16848. #else
  16849. not_before = timegm(&tm_nb);
  16850. not_after = timegm(&tm_na);
  16851. #endif
  16852. return true;
  16853. }
  16854. inline std::string get_cert_serial(cert_t cert) {
  16855. if (!cert) return "";
  16856. auto x509 = static_cast<WOLFSSL_X509 *>(cert);
  16857. WOLFSSL_ASN1_INTEGER *serial_asn1 = wolfSSL_X509_get_serialNumber(x509);
  16858. if (!serial_asn1) return "";
  16859. // Get the serial number data
  16860. int len = serial_asn1->length;
  16861. unsigned char *data = serial_asn1->data;
  16862. if (!data || len <= 0) return "";
  16863. std::string result;
  16864. result.reserve(static_cast<size_t>(len) * 2);
  16865. for (int i = 0; i < len; i++) {
  16866. char hex[3];
  16867. snprintf(hex, sizeof(hex), "%02X", data[i]);
  16868. result += hex;
  16869. }
  16870. return result;
  16871. }
  16872. inline bool get_cert_der(cert_t cert, std::vector<unsigned char> &der) {
  16873. if (!cert) return false;
  16874. auto x509 = static_cast<WOLFSSL_X509 *>(cert);
  16875. int der_len = 0;
  16876. const unsigned char *der_data = wolfSSL_X509_get_der(x509, &der_len);
  16877. if (!der_data || der_len <= 0) return false;
  16878. der.assign(der_data, der_data + der_len);
  16879. return true;
  16880. }
  16881. inline const char *get_sni(const_session_t session) {
  16882. if (!session) return nullptr;
  16883. auto wsession = static_cast<const impl::WolfSSLSession *>(session);
  16884. // For server: return SNI received from client during handshake
  16885. if (!wsession->sni_hostname.empty()) {
  16886. return wsession->sni_hostname.c_str();
  16887. }
  16888. // For client: return the hostname set via set_sni
  16889. if (!wsession->hostname.empty()) { return wsession->hostname.c_str(); }
  16890. return nullptr;
  16891. }
  16892. inline uint64_t peek_error() {
  16893. return static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16894. }
  16895. inline uint64_t get_error() {
  16896. uint64_t err = impl::wolfssl_last_error();
  16897. impl::wolfssl_last_error() = 0;
  16898. return err;
  16899. }
  16900. inline std::string error_string(uint64_t code) {
  16901. char buf[256];
  16902. wolfSSL_ERR_error_string(static_cast<unsigned long>(code), buf);
  16903. return std::string(buf);
  16904. }
  16905. inline ca_store_t create_ca_store(const char *pem, size_t len) {
  16906. if (!pem || len == 0) { return nullptr; }
  16907. // Validate by attempting to load into a temporary ctx
  16908. WOLFSSL_CTX *tmp_ctx = wolfSSL_CTX_new(wolfTLSv1_2_client_method());
  16909. if (!tmp_ctx) { return nullptr; }
  16910. int ret = wolfSSL_CTX_load_verify_buffer(
  16911. tmp_ctx, reinterpret_cast<const unsigned char *>(pem),
  16912. static_cast<long>(len), SSL_FILETYPE_PEM);
  16913. wolfSSL_CTX_free(tmp_ctx);
  16914. if (ret != SSL_SUCCESS) { return nullptr; }
  16915. return static_cast<ca_store_t>(
  16916. new impl::WolfSSLCAStore{std::string(pem, len)});
  16917. }
  16918. inline void free_ca_store(ca_store_t store) {
  16919. delete static_cast<impl::WolfSSLCAStore *>(store);
  16920. }
  16921. inline bool set_ca_store(ctx_t ctx, ca_store_t store) {
  16922. if (!ctx || !store) { return false; }
  16923. auto *wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16924. auto *ca = static_cast<impl::WolfSSLCAStore *>(store);
  16925. int ret = wolfSSL_CTX_load_verify_buffer(
  16926. wctx->ctx, reinterpret_cast<const unsigned char *>(ca->pem_data.data()),
  16927. static_cast<long>(ca->pem_data.size()), SSL_FILETYPE_PEM);
  16928. if (ret == SSL_SUCCESS) { wctx->ca_pem_data_ += ca->pem_data; }
  16929. // This function takes ownership of the store; the PEM data was copied into
  16930. // the context, so release the source
  16931. free_ca_store(store);
  16932. return ret == SSL_SUCCESS;
  16933. }
  16934. inline size_t get_ca_certs(ctx_t ctx, std::vector<cert_t> &certs) {
  16935. certs.clear();
  16936. if (!ctx) { return 0; }
  16937. auto *wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16938. if (wctx->ca_pem_data_.empty()) { return 0; }
  16939. const std::string &pem = wctx->ca_pem_data_;
  16940. const std::string begin_marker = "-----BEGIN CERTIFICATE-----";
  16941. const std::string end_marker = "-----END CERTIFICATE-----";
  16942. size_t pos = 0;
  16943. while ((pos = pem.find(begin_marker, pos)) != std::string::npos) {
  16944. size_t end_pos = pem.find(end_marker, pos);
  16945. if (end_pos == std::string::npos) { break; }
  16946. end_pos += end_marker.size();
  16947. std::string cert_pem = pem.substr(pos, end_pos - pos);
  16948. WOLFSSL_X509 *x509 = wolfSSL_X509_load_certificate_buffer(
  16949. reinterpret_cast<const unsigned char *>(cert_pem.data()),
  16950. static_cast<int>(cert_pem.size()), WOLFSSL_FILETYPE_PEM);
  16951. if (x509) { certs.push_back(static_cast<cert_t>(x509)); }
  16952. pos = end_pos;
  16953. }
  16954. return certs.size();
  16955. }
  16956. inline std::vector<std::string> get_ca_names(ctx_t ctx) {
  16957. std::vector<std::string> names;
  16958. if (!ctx) { return names; }
  16959. auto *wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16960. if (wctx->ca_pem_data_.empty()) { return names; }
  16961. const std::string &pem = wctx->ca_pem_data_;
  16962. const std::string begin_marker = "-----BEGIN CERTIFICATE-----";
  16963. const std::string end_marker = "-----END CERTIFICATE-----";
  16964. size_t pos = 0;
  16965. while ((pos = pem.find(begin_marker, pos)) != std::string::npos) {
  16966. size_t end_pos = pem.find(end_marker, pos);
  16967. if (end_pos == std::string::npos) { break; }
  16968. end_pos += end_marker.size();
  16969. std::string cert_pem = pem.substr(pos, end_pos - pos);
  16970. WOLFSSL_X509 *x509 = wolfSSL_X509_load_certificate_buffer(
  16971. reinterpret_cast<const unsigned char *>(cert_pem.data()),
  16972. static_cast<int>(cert_pem.size()), WOLFSSL_FILETYPE_PEM);
  16973. if (x509) {
  16974. WOLFSSL_X509_NAME *subject = wolfSSL_X509_get_subject_name(x509);
  16975. if (subject) {
  16976. char *name_str = wolfSSL_X509_NAME_oneline(subject, nullptr, 0);
  16977. if (name_str) {
  16978. names.push_back(name_str);
  16979. XFREE(name_str, nullptr, DYNAMIC_TYPE_OPENSSL);
  16980. }
  16981. }
  16982. wolfSSL_X509_free(x509);
  16983. }
  16984. pos = end_pos;
  16985. }
  16986. return names;
  16987. }
  16988. inline bool update_server_cert(ctx_t ctx, const char *cert_pem,
  16989. const char *key_pem, const char *password) {
  16990. if (!ctx || !cert_pem || !key_pem) { return false; }
  16991. auto *wctx = static_cast<impl::WolfSSLContext *>(ctx);
  16992. // Load new certificate
  16993. int ret = wolfSSL_CTX_use_certificate_buffer(
  16994. wctx->ctx, reinterpret_cast<const unsigned char *>(cert_pem),
  16995. static_cast<long>(strlen(cert_pem)), SSL_FILETYPE_PEM);
  16996. if (ret != SSL_SUCCESS) {
  16997. impl::wolfssl_last_error() =
  16998. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  16999. return false;
  17000. }
  17001. // Set password if provided
  17002. if (password) { impl::set_wolfssl_password_cb(wctx->ctx, password); }
  17003. // Load new private key
  17004. ret = wolfSSL_CTX_use_PrivateKey_buffer(
  17005. wctx->ctx, reinterpret_cast<const unsigned char *>(key_pem),
  17006. static_cast<long>(strlen(key_pem)), SSL_FILETYPE_PEM);
  17007. if (ret != SSL_SUCCESS) {
  17008. impl::wolfssl_last_error() =
  17009. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  17010. return false;
  17011. }
  17012. return true;
  17013. }
  17014. inline bool update_server_client_ca(ctx_t ctx, const char *ca_pem) {
  17015. if (!ctx || !ca_pem) { return false; }
  17016. auto *wctx = static_cast<impl::WolfSSLContext *>(ctx);
  17017. int ret = wolfSSL_CTX_load_verify_buffer(
  17018. wctx->ctx, reinterpret_cast<const unsigned char *>(ca_pem),
  17019. static_cast<long>(strlen(ca_pem)), SSL_FILETYPE_PEM);
  17020. if (ret != SSL_SUCCESS) {
  17021. impl::wolfssl_last_error() =
  17022. static_cast<uint64_t>(wolfSSL_ERR_peek_last_error());
  17023. return false;
  17024. }
  17025. return true;
  17026. }
  17027. inline bool set_verify_callback(ctx_t ctx, VerifyCallback callback) {
  17028. if (!ctx) { return false; }
  17029. auto *wctx = static_cast<impl::WolfSSLContext *>(ctx);
  17030. impl::get_verify_callback() = std::move(callback);
  17031. wctx->has_verify_callback = static_cast<bool>(impl::get_verify_callback());
  17032. if (wctx->has_verify_callback) {
  17033. wolfSSL_CTX_set_verify(wctx->ctx, SSL_VERIFY_PEER,
  17034. impl::wolfssl_verify_callback);
  17035. } else {
  17036. wolfSSL_CTX_set_verify(
  17037. wctx->ctx,
  17038. wctx->verify_client
  17039. ? (SSL_VERIFY_PEER | SSL_VERIFY_FAIL_IF_NO_PEER_CERT)
  17040. : SSL_VERIFY_NONE,
  17041. nullptr);
  17042. }
  17043. return true;
  17044. }
  17045. inline long get_verify_error(const_session_t session) {
  17046. if (!session) { return -1; }
  17047. auto *wsession =
  17048. static_cast<impl::WolfSSLSession *>(const_cast<void *>(session));
  17049. return wolfSSL_get_verify_result(wsession->ssl);
  17050. }
  17051. inline std::string verify_error_string(long error_code) {
  17052. if (error_code == 0) { return ""; }
  17053. const char *str =
  17054. wolfSSL_X509_verify_cert_error_string(static_cast<int>(error_code));
  17055. return str ? std::string(str) : std::string();
  17056. }
  17057. } // namespace tls
  17058. #endif // CPPHTTPLIB_WOLFSSL_SUPPORT
  17059. // WebSocket implementation
  17060. namespace ws {
  17061. inline bool WebSocket::send_frame(Opcode op, const char *data, size_t len,
  17062. bool fin) {
  17063. std::lock_guard<std::mutex> lock(write_mutex_);
  17064. if (closed_) { return false; }
  17065. return detail::write_websocket_frame(strm_, op, data, len, fin, !is_server_);
  17066. }
  17067. inline ReadResult WebSocket::read(std::string &msg) {
  17068. while (!closed_) {
  17069. Opcode opcode;
  17070. std::string payload;
  17071. bool fin;
  17072. if (!impl::read_websocket_frame(strm_, opcode, payload, fin, is_server_,
  17073. CPPHTTPLIB_WEBSOCKET_MAX_PAYLOAD_LENGTH)) {
  17074. closed_ = true;
  17075. return Fail;
  17076. }
  17077. switch (opcode) {
  17078. case Opcode::Ping: {
  17079. std::lock_guard<std::mutex> lock(write_mutex_);
  17080. detail::write_websocket_frame(strm_, Opcode::Pong, payload.data(),
  17081. payload.size(), true, !is_server_);
  17082. continue;
  17083. }
  17084. case Opcode::Pong: {
  17085. std::lock_guard<std::mutex> lock(ping_mutex_);
  17086. unacked_pings_ = 0;
  17087. continue;
  17088. }
  17089. case Opcode::Close: {
  17090. if (!closed_.exchange(true)) {
  17091. // Echo close frame back
  17092. std::lock_guard<std::mutex> lock(write_mutex_);
  17093. detail::write_websocket_frame(strm_, Opcode::Close, payload.data(),
  17094. payload.size(), true, !is_server_);
  17095. }
  17096. return Fail;
  17097. }
  17098. case Opcode::Text:
  17099. case Opcode::Binary: {
  17100. auto result = opcode == Opcode::Text ? Text : Binary;
  17101. msg = std::move(payload);
  17102. // Handle fragmentation
  17103. if (!fin) {
  17104. while (true) {
  17105. Opcode cont_opcode;
  17106. std::string cont_payload;
  17107. bool cont_fin;
  17108. if (!impl::read_websocket_frame(
  17109. strm_, cont_opcode, cont_payload, cont_fin, is_server_,
  17110. CPPHTTPLIB_WEBSOCKET_MAX_PAYLOAD_LENGTH)) {
  17111. closed_ = true;
  17112. return Fail;
  17113. }
  17114. if (cont_opcode == Opcode::Ping) {
  17115. std::lock_guard<std::mutex> lock(write_mutex_);
  17116. detail::write_websocket_frame(
  17117. strm_, Opcode::Pong, cont_payload.data(), cont_payload.size(),
  17118. true, !is_server_);
  17119. continue;
  17120. }
  17121. if (cont_opcode == Opcode::Pong) {
  17122. std::lock_guard<std::mutex> lock(ping_mutex_);
  17123. unacked_pings_ = 0;
  17124. continue;
  17125. }
  17126. if (cont_opcode == Opcode::Close) {
  17127. if (!closed_.exchange(true)) {
  17128. std::lock_guard<std::mutex> lock(write_mutex_);
  17129. detail::write_websocket_frame(
  17130. strm_, Opcode::Close, cont_payload.data(),
  17131. cont_payload.size(), true, !is_server_);
  17132. }
  17133. return Fail;
  17134. }
  17135. // RFC 6455: continuation frames must use opcode 0x0
  17136. if (cont_opcode != Opcode::Continuation) {
  17137. closed_ = true;
  17138. return Fail;
  17139. }
  17140. msg += cont_payload;
  17141. if (msg.size() > CPPHTTPLIB_WEBSOCKET_MAX_PAYLOAD_LENGTH) {
  17142. closed_ = true;
  17143. return Fail;
  17144. }
  17145. if (cont_fin) { break; }
  17146. }
  17147. }
  17148. // RFC 6455 Section 5.6: text frames must contain valid UTF-8
  17149. if (result == Text && !impl::is_valid_utf8(msg)) {
  17150. close(CloseStatus::InvalidPayload, "invalid UTF-8");
  17151. return Fail;
  17152. }
  17153. return result;
  17154. }
  17155. default: closed_ = true; return Fail;
  17156. }
  17157. }
  17158. return Fail;
  17159. }
  17160. inline bool WebSocket::send(const std::string &data) {
  17161. return send_frame(Opcode::Text, data.data(), data.size());
  17162. }
  17163. inline bool WebSocket::send(const char *data, size_t len) {
  17164. return send_frame(Opcode::Binary, data, len);
  17165. }
  17166. inline void WebSocket::close(CloseStatus status, const std::string &reason) {
  17167. if (closed_.exchange(true)) { return; }
  17168. ping_cv_.notify_all();
  17169. std::string payload;
  17170. auto code = static_cast<uint16_t>(status);
  17171. payload.push_back(static_cast<char>((code >> 8) & 0xFF));
  17172. payload.push_back(static_cast<char>(code & 0xFF));
  17173. // RFC 6455 Section 5.5: control frame payload must not exceed 125 bytes
  17174. // Close frame has 2-byte status code, so reason is limited to 123 bytes
  17175. payload += reason.substr(0, 123);
  17176. {
  17177. std::lock_guard<std::mutex> lock(write_mutex_);
  17178. detail::write_websocket_frame(strm_, Opcode::Close, payload.data(),
  17179. payload.size(), true, !is_server_);
  17180. }
  17181. // RFC 6455 Section 7.1.1: after sending a Close frame, wait for the peer's
  17182. // Close response before closing the TCP connection. Use a short timeout to
  17183. // avoid hanging if the peer doesn't respond.
  17184. strm_.set_read_timeout(CPPHTTPLIB_WEBSOCKET_CLOSE_TIMEOUT_SECOND, 0);
  17185. Opcode op;
  17186. std::string resp;
  17187. bool fin;
  17188. while (impl::read_websocket_frame(strm_, op, resp, fin, is_server_, 125)) {
  17189. if (op == Opcode::Close) { break; }
  17190. }
  17191. }
  17192. inline WebSocket::~WebSocket() {
  17193. {
  17194. std::lock_guard<std::mutex> lock(ping_mutex_);
  17195. closed_ = true;
  17196. }
  17197. ping_cv_.notify_all();
  17198. if (ping_thread_.joinable()) { ping_thread_.join(); }
  17199. }
  17200. inline void WebSocket::start_heartbeat() {
  17201. if (ping_interval_sec_ == 0) { return; }
  17202. ping_thread_ = std::thread([this]() {
  17203. std::unique_lock<std::mutex> lock(ping_mutex_);
  17204. while (!closed_) {
  17205. ping_cv_.wait_for(lock, std::chrono::seconds(ping_interval_sec_));
  17206. if (closed_) { break; }
  17207. // If the peer has failed to respond to the previous pings, give up.
  17208. // RFC 6455 does not define a pong-timeout mechanism; this is an
  17209. // opt-in liveness check controlled by max_missed_pongs_.
  17210. if (max_missed_pongs_ > 0 && unacked_pings_ >= max_missed_pongs_) {
  17211. lock.unlock();
  17212. close(CloseStatus::GoingAway, "pong timeout");
  17213. return;
  17214. }
  17215. lock.unlock();
  17216. if (!send_frame(Opcode::Ping, nullptr, 0)) {
  17217. lock.lock();
  17218. closed_ = true;
  17219. break;
  17220. }
  17221. lock.lock();
  17222. unacked_pings_++;
  17223. }
  17224. });
  17225. }
  17226. inline const Request &WebSocket::request() const { return req_; }
  17227. inline bool WebSocket::is_open() const { return !closed_; }
  17228. // WebSocketClient implementation
  17229. inline WebSocketClient::WebSocketClient(
  17230. const std::string &scheme_host_port_path, const Headers &headers)
  17231. : headers_(headers) {
  17232. detail::UrlComponents uc;
  17233. if (detail::parse_url(scheme_host_port_path, uc) && !uc.scheme.empty() &&
  17234. !uc.host.empty() && !uc.path.empty()) {
  17235. auto &scheme = uc.scheme;
  17236. #ifdef CPPHTTPLIB_SSL_ENABLED
  17237. if (scheme != "ws" && scheme != "wss") {
  17238. #else
  17239. if (scheme != "ws") {
  17240. #endif
  17241. #ifndef CPPHTTPLIB_NO_EXCEPTIONS
  17242. std::string msg = "'" + scheme + "' scheme is not supported.";
  17243. throw std::invalid_argument(msg);
  17244. #endif
  17245. return;
  17246. }
  17247. auto is_ssl = scheme == "wss";
  17248. host_ = std::move(uc.host);
  17249. port_ = is_ssl ? 443 : 80;
  17250. if (!uc.port.empty() && !detail::parse_port(uc.port, port_)) { return; }
  17251. path_ = std::move(uc.path);
  17252. if (!uc.query.empty()) { path_ += uc.query; }
  17253. #ifdef CPPHTTPLIB_SSL_ENABLED
  17254. is_ssl_ = is_ssl;
  17255. if (is_ssl_) {
  17256. // The context lives as long as the client so that CA configuration
  17257. // survives reconnects; sessions are created per connection.
  17258. tls_ctx_ = tls::create_client_context();
  17259. if (!tls_ctx_) { return; }
  17260. }
  17261. #else
  17262. if (is_ssl) { return; }
  17263. #endif
  17264. is_valid_ = true;
  17265. }
  17266. }
  17267. inline WebSocketClient::~WebSocketClient() {
  17268. shutdown_and_close();
  17269. #ifdef CPPHTTPLIB_SSL_ENABLED
  17270. if (tls_ctx_) {
  17271. tls::free_context(tls_ctx_);
  17272. tls_ctx_ = nullptr;
  17273. }
  17274. #endif
  17275. }
  17276. inline bool WebSocketClient::is_valid() const { return is_valid_; }
  17277. inline void WebSocketClient::shutdown_and_close() {
  17278. #ifdef CPPHTTPLIB_SSL_ENABLED
  17279. if (is_ssl_) {
  17280. if (tls_session_) {
  17281. tls::shutdown(tls_session_, true);
  17282. tls::free_session(tls_session_);
  17283. tls_session_ = nullptr;
  17284. }
  17285. }
  17286. #endif
  17287. if (ws_ && ws_->is_open()) { ws_->close(); }
  17288. ws_.reset();
  17289. if (sock_ != INVALID_SOCKET) {
  17290. detail::shutdown_socket(sock_);
  17291. detail::close_socket(sock_);
  17292. sock_ = INVALID_SOCKET;
  17293. }
  17294. }
  17295. inline bool WebSocketClient::create_stream(std::unique_ptr<Stream> &strm) {
  17296. #ifdef CPPHTTPLIB_SSL_ENABLED
  17297. if (is_ssl_) {
  17298. if (server_certificate_verification_ && !certs_loaded_) {
  17299. uint64_t backend_error = 0;
  17300. detail::load_client_ca_config(tls_ctx_, ca_cert_file_path_, std::string(),
  17301. custom_ca_loaded_, system_ca_mode_,
  17302. backend_error);
  17303. certs_loaded_ = true;
  17304. }
  17305. if (!detail::setup_client_tls_session(host_, tls_ctx_, tls_session_, sock_,
  17306. server_certificate_verification_,
  17307. read_timeout_sec_,
  17308. read_timeout_usec_)) {
  17309. return false;
  17310. }
  17311. strm = std::unique_ptr<Stream>(new detail::SSLSocketStream(
  17312. sock_, tls_session_, read_timeout_sec_, read_timeout_usec_,
  17313. write_timeout_sec_, write_timeout_usec_));
  17314. return true;
  17315. }
  17316. #endif
  17317. strm = std::unique_ptr<Stream>(
  17318. new detail::SocketStream(sock_, read_timeout_sec_, read_timeout_usec_,
  17319. write_timeout_sec_, write_timeout_usec_));
  17320. return true;
  17321. }
  17322. inline bool WebSocketClient::connect() {
  17323. if (!is_valid_) { return false; }
  17324. shutdown_and_close();
  17325. // Check is custom IP specified for host_
  17326. std::string ip;
  17327. auto it = addr_map_.find(host_);
  17328. if (it != addr_map_.end()) { ip = it->second; }
  17329. Error error;
  17330. sock_ = detail::create_client_socket(
  17331. host_, ip, port_, address_family_, tcp_nodelay_, ipv6_v6only_,
  17332. socket_options_, connection_timeout_sec_, connection_timeout_usec_,
  17333. read_timeout_sec_, read_timeout_usec_, write_timeout_sec_,
  17334. write_timeout_usec_, interface_, error);
  17335. if (sock_ == INVALID_SOCKET) { return false; }
  17336. std::unique_ptr<Stream> strm;
  17337. if (!create_stream(strm)) {
  17338. shutdown_and_close();
  17339. return false;
  17340. }
  17341. std::string selected_subprotocol;
  17342. if (!detail::perform_websocket_handshake(*strm, host_, port_, path_, headers_,
  17343. selected_subprotocol)) {
  17344. shutdown_and_close();
  17345. return false;
  17346. }
  17347. subprotocol_ = std::move(selected_subprotocol);
  17348. Request req;
  17349. req.method = "GET";
  17350. req.path = path_;
  17351. ws_ = std::unique_ptr<WebSocket>(new WebSocket(std::move(strm), req, false,
  17352. websocket_ping_interval_sec_,
  17353. websocket_max_missed_pongs_));
  17354. return true;
  17355. }
  17356. inline ReadResult WebSocketClient::read(std::string &msg) {
  17357. if (!ws_) { return Fail; }
  17358. return ws_->read(msg);
  17359. }
  17360. inline bool WebSocketClient::send(const std::string &data) {
  17361. if (!ws_) { return false; }
  17362. return ws_->send(data);
  17363. }
  17364. inline bool WebSocketClient::send(const char *data, size_t len) {
  17365. if (!ws_) { return false; }
  17366. return ws_->send(data, len);
  17367. }
  17368. inline void WebSocketClient::close(CloseStatus status,
  17369. const std::string &reason) {
  17370. if (ws_) { ws_->close(status, reason); }
  17371. }
  17372. inline bool WebSocketClient::is_open() const { return ws_ && ws_->is_open(); }
  17373. inline const std::string &WebSocketClient::subprotocol() const {
  17374. return subprotocol_;
  17375. }
  17376. inline void WebSocketClient::set_read_timeout(time_t sec, time_t usec) {
  17377. read_timeout_sec_ = sec;
  17378. read_timeout_usec_ = usec;
  17379. }
  17380. inline void WebSocketClient::set_write_timeout(time_t sec, time_t usec) {
  17381. write_timeout_sec_ = sec;
  17382. write_timeout_usec_ = usec;
  17383. }
  17384. inline void WebSocketClient::set_websocket_ping_interval(time_t sec) {
  17385. websocket_ping_interval_sec_ = sec;
  17386. }
  17387. inline void WebSocketClient::set_websocket_max_missed_pongs(int count) {
  17388. websocket_max_missed_pongs_ = count;
  17389. }
  17390. inline void WebSocketClient::set_tcp_nodelay(bool on) { tcp_nodelay_ = on; }
  17391. inline void WebSocketClient::set_address_family(int family) {
  17392. address_family_ = family;
  17393. }
  17394. inline void WebSocketClient::set_ipv6_v6only(bool on) { ipv6_v6only_ = on; }
  17395. inline void WebSocketClient::set_socket_options(SocketOptions socket_options) {
  17396. socket_options_ = std::move(socket_options);
  17397. }
  17398. inline void WebSocketClient::set_connection_timeout(time_t sec, time_t usec) {
  17399. connection_timeout_sec_ = sec;
  17400. connection_timeout_usec_ = usec;
  17401. }
  17402. inline void WebSocketClient::set_interface(const std::string &intf) {
  17403. interface_ = intf;
  17404. }
  17405. inline void WebSocketClient::set_hostname_addr_map(
  17406. std::map<std::string, std::string> addr_map) {
  17407. addr_map_ = std::move(addr_map);
  17408. }
  17409. #ifdef CPPHTTPLIB_SSL_ENABLED
  17410. inline void WebSocketClient::set_ca_cert_path(const std::string &path) {
  17411. ca_cert_file_path_ = path;
  17412. }
  17413. inline void WebSocketClient::set_ca_cert_store(tls::ca_store_t store) {
  17414. if (store && tls_ctx_) {
  17415. // set_ca_store takes ownership of store
  17416. tls::set_ca_store(tls_ctx_, store);
  17417. custom_ca_loaded_ = true;
  17418. } else if (store) {
  17419. tls::free_ca_store(store);
  17420. }
  17421. }
  17422. inline void WebSocketClient::load_ca_cert_store(const char *ca_cert,
  17423. std::size_t size) {
  17424. if (tls_ctx_ && ca_cert && size > 0) {
  17425. tls::load_ca_pem(tls_ctx_, ca_cert, size);
  17426. custom_ca_loaded_ = true;
  17427. }
  17428. }
  17429. inline void
  17430. WebSocketClient::enable_server_certificate_verification(bool enabled) {
  17431. server_certificate_verification_ = enabled;
  17432. }
  17433. inline void WebSocketClient::enable_system_ca(bool enabled) {
  17434. system_ca_mode_ = enabled ? SystemCAMode::Enabled : SystemCAMode::Disabled;
  17435. }
  17436. #endif // CPPHTTPLIB_SSL_ENABLED
  17437. } // namespace ws
  17438. // ----------------------------------------------------------------------------
  17439. } // namespace httplib
  17440. #endif // CPPHTTPLIB_HTTPLIB_H