Denis V. Dedkov ded

ded a sincronizat consemnările de la v0.60.1 la ded/cpp-httplib din oglindire

2 ore în urmă

ded a sincronizat referință nouă v0.60.1 la ded/cpp-httplib din oglindire

2 ore în urmă

ded a sincronizat consemnările de la master la ded/cpp-httplib din oglindire

  • 00afaaed6a Release v0.60.1
  • e803f5e413 Let the SSL chain policy alone judge the Windows chain (#2618) verify_cert_with_windows_schannel() rejected a chain whenever TrustStatus.dwErrorStatus was non-zero, before CertVerifyCertificateChainPolicy() ran. The CERT_CHAIN_POLICY_IGNORE_ALL_REV_UNKNOWN_FLAGS flag passed to that policy check was therefore dead code: a certificate without revocation information, or one whose CRL could not be fetched, failed with CERT_TRUST_REVOCATION_STATUS_UNKNOWN. Drop the pre-check so the SSL chain policy is the only judge. Revocation checking becomes best-effort: a revoked certificate and every other chain error are still rejected, while an undetermined revocation status is accepted. On a rejected chain, ssl_backend_error() now holds the policy status, such as CERT_E_UNTRUSTEDROOT, instead of the trust status bit mask.
  • 57b8aca6da Avoid name clash with class WebSocketClient by explicit qualification (#2616) Adds an explicit namespace qualification and a forward declaration for class WebSocketClient. This change avoids a name clash on code bases containing unrelated WebSocketClient classes.
  • 213029685a Serve the whole body for a suffix range longer than it (#2615) RFC 9110 14.1.2: if the representation is shorter than the suffix-length, the entire representation is used. range_error computed a negative first byte position for bytes=-8 on a 7-byte body and answered 416. Clamp it at 0, as #711 did before the range handling was reworked. Co-authored-by: youdie006 <youdie006@users.noreply.github.com>
  • Vizualizați comparația pentru aceste 4 consemnări »

2 ore în urmă

ded a sincronizat consemnările de la v0.60.0 la ded/cpp-httplib din oglindire

1 zi în urmă

ded a sincronizat referință nouă v0.60.0 la ded/cpp-httplib din oglindire

1 zi în urmă

ded a sincronizat consemnările de la master la ded/cpp-httplib din oglindire

1 zi în urmă

ded a sincronizat consemnările de la master la ded/cpp-httplib din oglindire

  • edc9760005 use the SAN type tag in Mbed TLS verify_hostname and get_cert_sans (#2614) * use the SAN type tag in Mbed TLS verify_hostname and get_cert_sans Mbed TLS keeps a subjectAltName entry's GeneralName tag in buf.tag and the bare value in buf.p / buf.len. verify_hostname ignored the tag, so a dNSName whose bytes equal an address authenticated that IP host, and an iPAddress or rfc822Name was matched as a DNS pattern. get_cert_sans looked for the tag inside the value, so it reported no entries for an ordinary certificate, or part of a dNSName as an entry of its own. * Shorten the SAN type comments --------- Co-authored-by: yhirose <yuji.hirose.bug@gmail.com>

2 zile în urmă

ded a sincronizat consemnările de la master la ded/cpp-httplib din oglindire

  • 6d1049462d Ignore a subprotocol the WebSocket client did not offer A SubProtocolSelector could return a value outside the client's Sec-WebSocket-Protocol list, and the server sent it back as is. The server now treats such a value as no selection.
  • 4fcbc08f2d reject an unoffered subprotocol in read_websocket_upgrade_response (#2595) * reject an unoffered subprotocol in the ws client handshake * test the subprotocol check through WebSocketClient so the split build compiles * Trim comments in the subprotocol check --------- Co-authored-by: yhirose <yuji.hirose.bug@gmail.com>
  • Vizualizați comparația pentru aceste 2 consemnări »

3 zile în urmă

ded a sincronizat consemnările de la master la ded/cpp-httplib din oglindire

  • d59f3e438c Remove semantically redundant closed_ checks in ping thread. (#2613)

3 zile în urmă

ded a sincronizat consemnările de la master la ded/cpp-httplib din oglindire

  • 09fa6820fe Fix 303 redirect request bodies and Location path decoding (Fix #2606, #2607) A 303 response turns the follow-up request into a GET, but only the buffered body and headers were cleared. A content provider (sized or chunked) stayed on the request, so the original payload was sent again, and for a chunked provider the unframed chunks also broke the keep-alive connection. The redirect also percent-decoded the Location path before sending it. That turned %23, %3F and %25 into a fragment, a query delimiter and a different octet, so the client requested a different resource than the one named, and made set_path_encode(false) fail on any Location containing %20. The path is now sent as given.
  • 438319cfcb Fix WebSocket pings being sent early on spurious wakeups The heartbeat thread waited on ping_cv_ without a predicate, so a spurious wakeup ended the wait early and sent a ping before ping_interval_sec_ had elapsed. With max_missed_pongs enabled, the early ping also counted toward the pong timeout. Pass a predicate to wait_for so that the wait only ends when the interval elapses or the connection is closed. Reported in #2612.
  • eda9a10bfe Fix SSE client not clearing Last-Event-ID on an empty id field (Fix #2611) An event with an empty id field must reset the last event ID, so that no Last-Event-ID header is sent on reconnect. run_event_loop only updated last_event_id_ when the id was non-empty, so it could not tell an empty id field from an event with no id field, and kept sending the stale ID. Track whether an id field was seen with a has_id flag, as has_data does for the data field, and add a regression test.
  • Vizualizați comparația pentru aceste 3 consemnări »

4 zile în urmă

ded a sincronizat consemnările de la v0.59.0 la ded/cpp-httplib din oglindire

5 zile în urmă

ded a sincronizat referință nouă v0.59.0 la ded/cpp-httplib din oglindire

5 zile în urmă

ded a sincronizat consemnările de la master la ded/cpp-httplib din oglindire

  • cf3693cb5c Release v0.59.0
  • 4fd9ae8f42 Serve pipelined requests without waiting for the keep-alive timeout A client may pipeline its requests (RFC 9112 9.3.2). The server read the following request(s) into a per-request SocketStream buffer, discarded them with the stream after the first response, and then waited in keep_alive() for socket data that never came, closing the connection after the keep-alive timeout. Over TLS the bytes stayed decrypted in the TLS library, where keep_alive() could not see them either. Create one stream per connection and serve a request that is already buffered (Stream::is_readable()) without waiting in keep_alive(). Keeping the buffer means an extra CRLF that some clients send after a request body is now parsed as the next request line, which answered 400 and closed the connection. Ignore one empty line before the request-line, as RFC 9112 2.2 recommends. Fixes #2599
  • 3d40dfc727 Fix SSE parsing of CRLF field names and data-less events A field line without a colon kept the \r of a CRLF line ending in its name, so "data\r\n" was not recognized. Strip the \r once per line before parsing instead of from each value. An event without a data field was neither dispatched nor cleared, so its event type leaked into the next event and its id only reached last_event_id after a later event was dispatched. Reset the message on every blank line and record the id even when nothing is dispatched. The parsing tests exercised a copy of parse_sse_line that had drifted from the real one. Run them through SSEClient against a local server instead, and add regression tests for the cases above.
  • dd71728110 escape quoted-string auth-params in make_digest_authentication_header (#2597)
  • 7255a7e979 Preserve empty SSE data fields (#2594) SSE events may contain an empty data field, and a data field without a colon also has an empty value. Track whether a data field was seen separately from the accumulated payload so empty events are dispatched and leading empty lines are preserved. Add an integration regression test for both forms.
  • Vizualizați comparația pentru aceste 9 consemnări »

5 zile în urmă

ded referință sincronizată și ștersă windows-verify-intermediates la ded/cpp-httplib din oglindire

5 zile în urmă

ded referință sincronizată și ștersă windows-defer-missing-root la ded/cpp-httplib din oglindire

5 zile în urmă

ded a sincronizat consemnările de la windows-defer-missing-root la ded/cpp-httplib din oglindire

  • 9af2341702 Let CryptoAPI decide on a root missing from the OpenSSL store Windows adds a root it trusts to its store only when CryptoAPI needs it to build a chain. The OpenSSL store is loaded from the Windows store, so OpenSSL fails with "unable to get local issuer certificate" before the CryptoAPI check runs, and Windows never gets to fetch the root. When Windows certificate verification is enabled, leave that error to the CryptoAPI check. Since OpenSSL then skips its purpose check, request the server authentication usage from CryptoAPI, and fail instead of skipping the CryptoAPI check when the leaf cannot be encoded. Refs #2596
  • 086a648364 Pass the server's intermediates to Windows certificate verification CryptoAPI got only the leaf, so it fetched an issuer from the leaf's AIA URL instead of using the intermediates the server sent. For accounts.spotify.com that issuer chains to Certainly Root R1, which Windows does not trust, while the server's own chain ends at Starfield Root G2. Add the server's intermediates to the store CryptoAPI builds the chain from. This covers the OpenSSL backend. Refs #2596
  • 639391ad7f Reject an invalid Content-Length and honor Connection: close A request whose Content-Length was present but not a valid decimal length (e.g. "42, 42", "+42", "0x2e" or empty) was treated as having no body unless a handler read it: no 400 was returned, the body was not drained, and the bytes after the header block were parsed as the next request on the keep-alive connection. Reject such a request with 400 and close the connection before routing, as RFC 9112 Section 6.3 requires. The server also kept reading after a response that announced Connection: close. A rejected request line or header block left the rest of the message to be parsed as a new request, and an error response to a bodyless request did the same with whatever followed. Close the connection whenever the final response carries Connection: close (RFC 9112 Section 9.6), and mark the two request-head rejection paths closed explicitly as the other rejection paths already do.
  • 0715c2739e Enforce a minimum SSE reconnect wait to avoid a busy loop (#2592) SSEClient::wait_for_reconnect() sleeps in 100ms steps until the reconnect interval has elapsed. With an interval of 0 (for example "retry: 0" from the server, or set_reconnect_interval(0)) it never slept at all, so a server that sends "retry: 0" and closes the stream made the client reconnect in a tight loop. set_max_reconnect_attempts() does not stop this either, because each successful connection resets the attempt counter. Always wait at least one step (100ms). Intervals of 1-99ms already waited 100ms because of the step size, so only 0 and negative values change behavior.
  • 3330d0eb06 Ignore an SSE retry field that is not all digits (#2591) parse_sse_line checked only the error code of from_chars, which accepts a leading '-' and stops at the first non-digit, so retry: -1 made the client reconnect without waiting and retry: 10s set 10 ms. The SSE spec ignores a retry value that is not all ASCII digits.
  • Vizualizați comparația pentru aceste 10 consemnări »

5 zile în urmă

ded a sincronizat referință nouă windows-defer-missing-root la ded/cpp-httplib din oglindire

5 zile în urmă

ded a sincronizat consemnările de la windows-verify-intermediates la ded/cpp-httplib din oglindire

  • 413c7d42f6 Pass the server's intermediates to Windows certificate verification verify_cert_with_windows_schannel() built the chain from the leaf alone, so CryptoAPI fetched an issuer from the leaf's AIA URL instead of using the intermediates the server sent. When that issuer chains to a root Windows does not trust, verification failed with CERT_TRUST_IS_UNTRUSTED_ROOT even though the chain the server sent ends at a trusted root. accounts.spotify.com is such a site: its leaf's AIA leads to Certainly Root R1, while the server sends an intermediate cross-signed by Starfield Root G2. Add tls::get_peer_cert_chain_der() for all backends and hand the whole chain to CertGetCertificateChain() through an in-memory store, falling back to the leaf alone when the chain is unavailable. Refs #2596
  • 639391ad7f Reject an invalid Content-Length and honor Connection: close A request whose Content-Length was present but not a valid decimal length (e.g. "42, 42", "+42", "0x2e" or empty) was treated as having no body unless a handler read it: no 400 was returned, the body was not drained, and the bytes after the header block were parsed as the next request on the keep-alive connection. Reject such a request with 400 and close the connection before routing, as RFC 9112 Section 6.3 requires. The server also kept reading after a response that announced Connection: close. A rejected request line or header block left the rest of the message to be parsed as a new request, and an error response to a bodyless request did the same with whatever followed. Close the connection whenever the final response carries Connection: close (RFC 9112 Section 9.6), and mark the two request-head rejection paths closed explicitly as the other rejection paths already do.
  • 0715c2739e Enforce a minimum SSE reconnect wait to avoid a busy loop (#2592) SSEClient::wait_for_reconnect() sleeps in 100ms steps until the reconnect interval has elapsed. With an interval of 0 (for example "retry: 0" from the server, or set_reconnect_interval(0)) it never slept at all, so a server that sends "retry: 0" and closes the stream made the client reconnect in a tight loop. set_max_reconnect_attempts() does not stop this either, because each successful connection resets the attempt counter. Always wait at least one step (100ms). Intervals of 1-99ms already waited 100ms because of the step size, so only 0 and negative values change behavior.
  • 3330d0eb06 Ignore an SSE retry field that is not all digits (#2591) parse_sse_line checked only the error code of from_chars, which accepts a leading '-' and stops at the first non-digit, so retry: -1 made the client reconnect without waiting and retry: 10s set 10 ms. The SSE spec ignores a retry value that is not all ASCII digits.
  • c1c2b1f4b4 Apply the request-target check to the client and encode control chars Share the server's request-target check as fields::is_request_target() and use it in write_request_line too. The client previously used is_field_value(), which let an embedded SP or HTAB through. encode_path() only escaped CR/LF among the control characters, so with path encoding enabled a path like "/a\tb" would now be rejected instead of sent. Percent-encode every control character (0x00-0x1F, 0x7F).
  • Vizualizați comparația pentru aceste 10 consemnări »

6 zile în urmă

ded a sincronizat referință nouă windows-verify-intermediates la ded/cpp-httplib din oglindire

6 zile în urmă

ded a sincronizat consemnările de la master la ded/cpp-httplib din oglindire

  • 639391ad7f Reject an invalid Content-Length and honor Connection: close A request whose Content-Length was present but not a valid decimal length (e.g. "42, 42", "+42", "0x2e" or empty) was treated as having no body unless a handler read it: no 400 was returned, the body was not drained, and the bytes after the header block were parsed as the next request on the keep-alive connection. Reject such a request with 400 and close the connection before routing, as RFC 9112 Section 6.3 requires. The server also kept reading after a response that announced Connection: close. A rejected request line or header block left the rest of the message to be parsed as a new request, and an error response to a bodyless request did the same with whatever followed. Close the connection whenever the final response carries Connection: close (RFC 9112 Section 9.6), and mark the two request-head rejection paths closed explicitly as the other rejection paths already do.

6 zile în urmă