Http.cpp 9.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231
  1. //---------------------------------------------------------------------------
  2. #include <vcl.h>
  3. #pragma hdrstop
  4. #include "Http.h"
  5. #include "NeonIntf.h"
  6. #include "Exceptions.h"
  7. #include "ne_request.h"
  8. #include "TextsCore.h"
  9. #include <openssl/ssl.h>
  10. //---------------------------------------------------------------------------
  11. THttp::THttp()
  12. {
  13. FProxyPort = 0;
  14. FOnDownload = NULL;
  15. FResponseLimit = -1;
  16. }
  17. //---------------------------------------------------------------------------
  18. THttp::~THttp()
  19. {
  20. }
  21. //---------------------------------------------------------------------------
  22. void THttp::SendRequest(const char * Method, const UnicodeString & Request)
  23. {
  24. std::unique_ptr<TStringList> AttemptedUrls(CreateSortedStringList());
  25. AttemptedUrls->Add(URL);
  26. UnicodeString RequestUrl = URL;
  27. bool WasTlsUri = false; // shut up
  28. bool Retry;
  29. do
  30. {
  31. ne_uri uri;
  32. NeonParseUrl(RequestUrl, uri);
  33. bool IsTls = IsTlsUri(uri);
  34. if (RequestUrl == URL)
  35. {
  36. WasTlsUri = IsTls;
  37. }
  38. else
  39. {
  40. if (!IsTls && WasTlsUri)
  41. {
  42. throw Exception(LoadStr(UNENCRYPTED_REDIRECT));
  43. }
  44. }
  45. FHostName = StrFromNeon(uri.host);
  46. UnicodeString Uri = StrFromNeon(uri.path);
  47. if (uri.query != NULL)
  48. {
  49. Uri += L"?" + StrFromNeon(uri.query);
  50. }
  51. FResponse.SetLength(0);
  52. FCertificateError.SetLength(0);
  53. FException.reset(NULL);
  54. TProxyMethod ProxyMethod = ProxyHost.IsEmpty() ? ::pmNone : pmHTTP;
  55. ne_session_s * NeonSession =
  56. CreateNeonSession(
  57. uri, ProxyMethod, ProxyHost, ProxyPort, UnicodeString(), UnicodeString());
  58. try
  59. {
  60. if (IsTls)
  61. {
  62. SetNeonTlsInit(NeonSession, InitSslSession);
  63. ne_ssl_set_verify(NeonSession, NeonServerSSLCallback, this);
  64. ne_ssl_trust_default_ca(NeonSession);
  65. }
  66. ne_request_s * NeonRequest = ne_request_create(NeonSession, Method, StrToNeon(Uri));
  67. try
  68. {
  69. UTF8String RequestUtf;
  70. if (!Request.IsEmpty())
  71. {
  72. RequestUtf = UTF8String(Request);
  73. ne_set_request_body_buffer(NeonRequest, RequestUtf.c_str(), RequestUtf.Length());
  74. }
  75. ne_add_response_body_reader(NeonRequest, ne_accept_2xx, NeonBodyReader, this);
  76. int Status = ne_request_dispatch(NeonRequest);
  77. // Exception has precedence over status as status will always be NE_ERROR,
  78. // as we returned 1 from NeonBodyReader
  79. if (FException.get() != NULL)
  80. {
  81. RethrowException(FException.get());
  82. }
  83. if (Status == NE_REDIRECT)
  84. {
  85. Retry = true;
  86. RequestUrl = GetNeonRedirectUrl(NeonSession);
  87. CheckRedirectLoop(RequestUrl, AttemptedUrls.get());
  88. }
  89. else
  90. {
  91. Retry = false;
  92. CheckNeonStatus(NeonSession, Status, FHostName, FCertificateError);
  93. const ne_status * NeonStatus = ne_get_status(NeonRequest);
  94. if (NeonStatus->klass != 2)
  95. {
  96. throw Exception(FMTLOAD(HTTP_ERROR, (NeonStatus->code, StrFromNeon(NeonStatus->reason_phrase), FHostName)));
  97. }
  98. }
  99. }
  100. __finally
  101. {
  102. ne_request_destroy(NeonRequest);
  103. }
  104. }
  105. __finally
  106. {
  107. DestroyNeonSession(NeonSession);
  108. ne_uri_free(&uri);
  109. }
  110. }
  111. while (Retry);
  112. }
  113. //---------------------------------------------------------------------------
  114. void THttp::Get()
  115. {
  116. SendRequest("GET", UnicodeString());
  117. }
  118. //---------------------------------------------------------------------------
  119. void THttp::Post(const UnicodeString & Request)
  120. {
  121. SendRequest("POST", Request);
  122. }
  123. //---------------------------------------------------------------------------
  124. UnicodeString THttp::GetResponse()
  125. {
  126. UTF8String UtfResponse(FResponse);
  127. return UnicodeString(UtfResponse);
  128. }
  129. //---------------------------------------------------------------------------
  130. int THttp::NeonBodyReaderImpl(const char * Buf, size_t Len)
  131. {
  132. bool Result = true;
  133. if ((FResponseLimit < 0) ||
  134. (FResponse.Length() + Len <= FResponseLimit))
  135. {
  136. FResponse += RawByteString(Buf, Len);
  137. if (FOnDownload != NULL)
  138. {
  139. bool Cancel = false;
  140. try
  141. {
  142. FOnDownload(this, ResponseLength, Cancel);
  143. }
  144. catch (Exception & E)
  145. {
  146. FException.reset(CloneException(&E));
  147. Result = false;
  148. }
  149. if (Cancel)
  150. {
  151. FException.reset(new EAbort(UnicodeString()));
  152. Result = false;
  153. }
  154. }
  155. }
  156. // neon wants 0 for success
  157. return Result ? 0 : 1;
  158. }
  159. //---------------------------------------------------------------------------
  160. int THttp::NeonBodyReader(void * UserData, const char * Buf, size_t Len)
  161. {
  162. THttp * Http = static_cast<THttp *>(UserData);
  163. return Http->NeonBodyReaderImpl(Buf, Len);
  164. }
  165. //---------------------------------------------------------------------------
  166. __int64 THttp::GetResponseLength()
  167. {
  168. return FResponse.Length();
  169. }
  170. //------------------------------------------------------------------------------
  171. void THttp::InitSslSession(ssl_st * Ssl, ne_session * /*Session*/)
  172. {
  173. int Options = SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3 | SSL_OP_NO_TLSv1 | SSL_OP_NO_TLSv1_1;
  174. SSL_ctrl(Ssl, SSL_CTRL_OPTIONS, Options, NULL);
  175. }
  176. //---------------------------------------------------------------------------
  177. int THttp::NeonServerSSLCallback(void * UserData, int Failures, const ne_ssl_certificate * Certificate)
  178. {
  179. THttp * Http = static_cast<THttp *>(UserData);
  180. return Http->NeonServerSSLCallbackImpl(Failures, Certificate);
  181. }
  182. //---------------------------------------------------------------------------
  183. int THttp::NeonServerSSLCallbackImpl(int Failures, const ne_ssl_certificate * Certificate)
  184. {
  185. AnsiString AsciiCert = NeonExportCertificate(Certificate);
  186. // winscp.net 31.05.2015 - 02.06.2016
  187. const AnsiString WebCert = "MIIEqzCCA5OgAwIBAgIDBMLgMA0GCSqGSIb3DQEBCwUAMEcxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMSAwHgYDVQQDExdSYXBpZFNTTCBTSEEyNTYgQ0EgLSBHMzAeFw0xNTA1MzEwMDA1NTRaFw0xNjA2MDIwNTUxNTNaMIGSMRMwEQYDVQQLEwpHVDUyNTA2NDcyMTEwLwYDVQQLEyhTZWUgd3d3LnJhcGlkc3NsLmNvbS9yZXNvdXJjZXMvY3BzIChjKTE1MS8wLQYDVQQLEyZEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQgLSBSYXBpZFNTTChSKTEXMBUGA1UEAxMOd3d3LndpbnNjcC5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDRHP+5FLE+q+oeu0Qlx2eX1nV8Vc0jOkwam95Vr6JV9Ar5ZZIbR8a/jBJv/tDlQ8nvx38gPoFCcPX3qBjRhxIBuNETbLi+7Yd69CXyZKNrbo0pxAbn5C/JKFgog5EkSdR65gia0J6YGPDw/iq180MpkNIBAFInq8Pc36hLz4jrAunFjxJ18pkmBlOVSr7/4Ppd15Co9fhF4A3QI2wcrAOjEfGhssfk7aRp8x36/GI3rs/Or1SbO6/ZSg9h7a5uvJFgQPDVRmqytd03EC9HLVOvRK/70gcQfYcOSEWkEkEO8jQ7eXv0u1y5E20Te0Zk9hVXll2RpCO8u5RyyzhSKW1DAgMBAAGjggFSMIIBTjAfBgNVHSMEGDAWgBTDnPP800YINLvORn+gfFvz4gjLWTBXBggrBgEFBQcBAQRLMEkwHwYIKwYBBQUHMAGGE2h0dHA6Ly9ndi5zeW1jZC5jb20wJgYIKwYBBQUHMAKGGmh0dHA6Ly9ndi5zeW1jYi5jb20vZ3YuY3J0MA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwJQYDVR0RBB4wHIIOd3d3LndpbnNjcC5uZXSCCndpbnNjcC5uZXQwKwYDVR0fBCQwIjAgoB6gHIYaaHR0cDovL2d2LnN5bWNiLmNvbS9ndi5jcmwwDAYDVR0TAQH/BAIwADBBBgNVHSAEOjA4MDYGBmeBDAECATAsMCoGCCsGAQUFBwIBFh5odHRwczovL3d3dy5yYXBpZHNzbC5jb20vbGVnYWwwDQYJKoZIhvcNAQELBQADggEBAHzQ0JNQOtaYUbcw6OCyyiV5O5VemJSDagD5VG5W2gkLfxa9v1ly9hxbdlkKv4d9ruq36ZiHxqKBLoBzw68RNOG/CFY85Xam5Wygo8afSIuhLOYgSUMriH8aoBUXssG15t54z1em58Qh5xMp0crQAbY7D4opo0pEzkaTaS8ulwOxu5SSpK3DF12VKUdKhBs7T0QY+oOJZsqkx7GdmeKxoKRpBQvnRegCszR7vkdWsY0fFZHeNdThkY1iRxI6b4tyDYgZ0COj8WXCBia9wZm/czMmq/d7KED2V06w3Ttc4hDOHl+Onm/gQFLs++1f2Z/X6iPNhIEMNKKH51y/eHJQMxE=";
  188. // cdn.winscp.net 02.06.2015 - 04.06.2016
  189. const AnsiString CdnCert = "MIIEnzCCA4egAwIBAgIDBMxPMA0GCSqGSIb3DQEBCwUAMEcxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMSAwHgYDVQQDExdSYXBpZFNTTCBTSEEyNTYgQ0EgLSBHMzAeFw0xNTA2MDIwNjIzMDFaFw0xNjA2MDQwMDU0NTVaMIGSMRMwEQYDVQQLEwpHVDUwMzQ0NzgyMTEwLwYDVQQLEyhTZWUgd3d3LnJhcGlkc3NsLmNvbS9yZXNvdXJjZXMvY3BzIChjKTE1MS8wLQYDVQQLEyZEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQgLSBSYXBpZFNTTChSKTEXMBUGA1UEAxMOY2RuLndpbnNjcC5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC5ykjjmhjnd6hMmb7WNlQwSzjGCiLA3b+U2xfUYGsR+0o8frU3bv50vNp+IlTFXn32Qt3QtskuoLdi/nip0ABBtgEUt4FAoZ/AMKPyT0hD95ZEFlaclCzUANmSJswWdQIZltbLulMAqt618Snkog3Z3nkjzAMZuKvEYvPV9ujuM2kzkWZr0/OoPHINUkaI6mZwTxCvxwmazBtyIx5tXqmfiOJ1R+viAZm4Av5nqaXz1dTqSjrgpvFtwkTu8YQpK3qrpjN+H67PnClOAS1GY0oaSMccxq0bYL1w0hORa+NyQ+ZTIiXVwiXFJ0w23qHadaoKOiG8WnQ49YvCpbDhMU+3AgMBAAGjggFGMIIBQjAfBgNVHSMEGDAWgBTDnPP800YINLvORn+gfFvz4gjLWTBXBggrBgEFBQcBAQRLMEkwHwYIKwYBBQUHMAGGE2h0dHA6Ly9ndi5zeW1jZC5jb20wJgYIKwYBBQUHMAKGGmh0dHA6Ly9ndi5zeW1jYi5jb20vZ3YuY3J0MA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwGQYDVR0RBBIwEIIOY2RuLndpbnNjcC5uZXQwKwYDVR0fBCQwIjAgoB6gHIYaaHR0cDovL2d2LnN5bWNiLmNvbS9ndi5jcmwwDAYDVR0TAQH/BAIwADBBBgNVHSAEOjA4MDYGBmeBDAECATAsMCoGCCsGAQUFBwIBFh5odHRwczovL3d3dy5yYXBpZHNzbC5jb20vbGVnYWwwDQYJKoZIhvcNAQELBQADggEBAF9BN1+whMrK/HCDggLi/76+zDkzqVvNjdTgOLLSBCZaTJV1xNwIfxrPVwECEKkqV0D3eYx53aMxudVq+QuQ7VlS2k0Nu12Bfr0LFcUIOOO55jfjXUnJ8QLWoZQIJ6spOk0Bilxos4yzcORxOfASjkECEg1XUK3THnNgVLKZS92JSdxzsRkZvkpKCSNlX4ftoaPyDsgYWv0gBBA4RPAjAJB5qQTUeu0xIO/r1IhqLqnhlnJ3ewE68ScHbE5sMpl5RLEiaVRBeNw/whVEDPe2TY+JNzk6NdsGWq6uPCFsCXTGzX2QkAwR+rk2y4PPoY2vnj2cQoYWXF5pBjpMPYyRu8Q=";
  190. if ((AsciiCert == WebCert) ||
  191. (AsciiCert == CdnCert))
  192. {
  193. Failures &= ~NE_SSL_UNTRUSTED;
  194. }
  195. if (Failures != 0)
  196. {
  197. NeonWindowsValidateCertificate(Failures, AsciiCert);
  198. }
  199. if (Failures != 0)
  200. {
  201. FCertificateError = NeonCertificateFailuresErrorStr(Failures, FHostName);
  202. }
  203. return (Failures == 0) ? NE_OK : NE_ERROR;
  204. }
  205. //---------------------------------------------------------------------------