#include "config.h"
#include "FetchHeaders.h"
#if ENABLE(FETCH_API)
#include "ExceptionCode.h"
#include "HTTPParsers.h"
namespace WebCore {
static bool isForbiddenHeaderName(const String& name)
{
HTTPHeaderName headerName;
if (findHTTPHeaderName(name, headerName)) {
switch (headerName) {
case HTTPHeaderName::AcceptCharset:
case HTTPHeaderName::AcceptEncoding:
case HTTPHeaderName::AccessControlRequestHeaders:
case HTTPHeaderName::AccessControlRequestMethod:
case HTTPHeaderName::Connection:
case HTTPHeaderName::ContentLength:
case HTTPHeaderName::Cookie:
case HTTPHeaderName::Cookie2:
case HTTPHeaderName::Date:
case HTTPHeaderName::DNT:
case HTTPHeaderName::Expect:
case HTTPHeaderName::Host:
case HTTPHeaderName::KeepAlive:
case HTTPHeaderName::Origin:
case HTTPHeaderName::Referer:
case HTTPHeaderName::TE:
case HTTPHeaderName::Trailer:
case HTTPHeaderName::TransferEncoding:
case HTTPHeaderName::Upgrade:
case HTTPHeaderName::Via:
return true;
default:
break;
}
}
return startsWithLettersIgnoringASCIICase(name, "sec-") || startsWithLettersIgnoringASCIICase(name, "proxy-");
}
static bool isForbiddenResponseHeaderName(const String& name)
{
return equalLettersIgnoringASCIICase(name, "set-cookie") || equalLettersIgnoringASCIICase(name, "set-cookie2");
}
static bool isSimpleHeader(const String& name, const String& value)
{
HTTPHeaderName headerName;
if (!findHTTPHeaderName(name, headerName))
return false;
switch (headerName) {
case HTTPHeaderName::Accept:
case HTTPHeaderName::AcceptLanguage:
case HTTPHeaderName::ContentLanguage:
return true;
case HTTPHeaderName::ContentType: {
String mimeType = extractMIMETypeFromMediaType(value);
return equalLettersIgnoringASCIICase(mimeType, "application/x-www-form-urlencoded") || equalLettersIgnoringASCIICase(mimeType, "multipart/form-data") || equalLettersIgnoringASCIICase(mimeType, "text/plain");
}
default:
return false;
}
}
static bool canWriteHeader(const String& name, const String& value, FetchHeaders::Guard guard, ExceptionCode& ec)
{
if (!isValidHTTPToken(name) || !isValidHTTPHeaderValue(value)) {
ec = TypeError;
return false;
}
if (guard == FetchHeaders::Guard::Immutable) {
ec = TypeError;
return false;
}
if (guard == FetchHeaders::Guard::Request && isForbiddenHeaderName(name))
return false;
if (guard == FetchHeaders::Guard::RequestNoCors && !isSimpleHeader(name, value))
return false;
if (guard == FetchHeaders::Guard::Response && isForbiddenResponseHeaderName(name))
return false;
return true;
}
void FetchHeaders::append(const String& name, const String& value, ExceptionCode& ec)
{
String normalizedValue = stripLeadingAndTrailingHTTPSpaces(value);
if (!canWriteHeader(name, normalizedValue, m_guard, ec))
return;
m_headers.add(name, normalizedValue);
}
void FetchHeaders::remove(const String& name, ExceptionCode& ec)
{
if (!canWriteHeader(name, String(), m_guard, ec))
return;
m_headers.remove(name);
}
String FetchHeaders::get(const String& name, ExceptionCode& ec) const
{
if (!isValidHTTPToken(name)) {
ec = TypeError;
return String();
}
return m_headers.get(name);
}
bool FetchHeaders::has(const String& name, ExceptionCode& ec) const
{
if (!isValidHTTPToken(name)) {
ec = TypeError;
return false;
}
return m_headers.contains(name);
}
void FetchHeaders::set(const String& name, const String& value, ExceptionCode& ec)
{
String normalizedValue = stripLeadingAndTrailingHTTPSpaces(value);
if (!canWriteHeader(name, normalizedValue, m_guard, ec))
return;
m_headers.set(name, normalizedValue);
}
void FetchHeaders::fill(const FetchHeaders* headers)
{
ASSERT(m_guard != Guard::Immutable);
if (!headers)
return;
filterAndFill(headers->m_headers, m_guard);
}
void FetchHeaders::filterAndFill(const HTTPHeaderMap& headers, Guard guard)
{
ExceptionCode ec;
for (auto& header : headers) {
if (canWriteHeader(header.key, header.value, guard, ec)) {
if (header.keyAsHTTPHeaderName)
m_headers.add(header.keyAsHTTPHeaderName.value(), header.value);
else
m_headers.add(header.key, header.value);
}
}
}
Optional<WTF::KeyValuePair<String, String>> FetchHeaders::Iterator::next()
{
while (m_currentIndex < m_keys.size()) {
String key = m_keys[m_currentIndex++];
String value = m_headers->m_headers.get(key);
if (!value.isNull())
return WTF::KeyValuePair<String, String>(WTFMove(key), WTFMove(value));
}
m_keys.clear();
return Nullopt;
}
FetchHeaders::Iterator::Iterator(FetchHeaders& headers)
: m_headers(headers)
{
m_keys.reserveInitialCapacity(headers.m_headers.size());
for (auto& header : headers.m_headers)
m_keys.uncheckedAppend(header.key.convertToASCIILowercase());
std::sort(m_keys.begin(), m_keys.end(), WTF::codePointCompareLessThan);
}
}
#endif // ENABLE(FETCH_API)