* sanitize ob_httpetaghandler
[m6w6/ext-http] / http.c
diff --git a/http.c b/http.c
index 0cf01ae3ea9f7291397710398859be8549216232..452ec8f86a98fed4ea6e2e4e17c2a43fd6f69372 100644 (file)
--- a/http.c
+++ b/http.c
@@ -15,6 +15,7 @@
 
 /* $Id$ */
 
+#define _WINSOCKAPI_
 #define ZEND_INCLUDE_FULL_WINDOWS_HEADERS
 
 #ifdef HAVE_CONFIG_H
@@ -109,6 +110,7 @@ function_entry http_functions[] = {
 #ifndef ZEND_ENGINE_2
        PHP_FE(http_build_query, NULL)
 #endif
+       PHP_FE(ob_httpetaghandler, NULL)
        {NULL, NULL, NULL}
 };
 /* }}} */
@@ -439,28 +441,60 @@ PHP_FUNCTION(http_cache_etag)
                RETURN_FALSE;
        }
 
-       php_end_ob_buffers(0 TSRMLS_CC);
        http_send_header("Cache-Control: private, must-revalidate, max-age=0");
 
-       /* if no etag is given and we didn't already
-        * start ob_etaghandler -- start it
-        */
-       if (!HTTP_G(etag_started) && !etag_len) {
-               php_ob_set_internal_handler(_http_ob_etaghandler, (uint) 4096, "etag output handler", 0 TSRMLS_CC);
-               HTTP_G(etag_started) = 1;
-               RETURN_BOOL(php_start_ob_buffer_named("etag output handler", (uint) 4096, 0 TSRMLS_CC));
+       if (etag_len) {
+               http_send_etag(etag, etag_len);
+               if (http_etag_match("HTTP_IF_NONE_MATCH", etag)) {
+                       if (SUCCESS == http_send_status(304)) {
+                               zend_bailout();
+                       } else {
+                               php_error_docref(NULL TSRMLS_CC, E_WARNING, "Could not send 304 Not Modified");
+                               RETURN_FALSE;
+                       }
+               }
        }
 
-       if (http_etag_match("HTTP_IF_NONE_MATCH", etag)) {
-               if (SUCCESS == http_send_status(304)) {
-                       zend_bailout();
-               } else {
-                       php_error_docref(NULL TSRMLS_CC, E_WARNING, "Could not send 304 Not Modified");
-                       RETURN_FALSE;
+       /* if no etag is given and we didn't already start ob_etaghandler -- start it */
+       if (!HTTP_G(etag_started)) {
+               RETURN_BOOL(HTTP_G(etag_started) = (SUCCESS == http_start_ob_handler(_http_ob_etaghandler, "ob_etaghandler", 4096, 1)));
+       }
+       RETURN_TRUE;
+}
+/* }}} */
+
+/* {{{ proto string ob_httpetaghandler(string data, int mode)
+ *
+ * For use with ob_start(). 
+ * Note that this has to be started as first output buffer.
+ * WARNING: Don't use with http_send_*().
+ */
+PHP_FUNCTION(ob_httpetaghandler)
+{
+       char *data;
+       int data_len;
+       long mode;
+
+       if (SUCCESS != zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "sl", &data, &data_len, &mode)) {
+               RETURN_FALSE;
+       }
+
+       if (mode & PHP_OUTPUT_HANDLER_START) {
+               if (HTTP_G(etag_started)) {
+                       php_error_docref(NULL TSRMLS_CC, E_WARNING, "ob_httpetaghandler can only be used once");
+                       RETURN_STRINGL(data, data_len, 1);
                }
+               http_send_header("Cache-Control: private, must-revalidate, max-age=0");
+               HTTP_G(etag_started) = 1;
        }
 
-       RETURN_SUCCESS(http_send_etag(etag, etag_len));
+    if (OG(ob_nesting_level) > 1) {
+        php_error_docref(NULL TSRMLS_CC, E_WARNING, "ob_httpetaghandler must be started prior to other output buffers");
+        RETURN_STRINGL(data, data_len, 1);
+    }
+    
+       Z_TYPE_P(return_value) = IS_STRING;
+       http_ob_etaghandler(data, data_len, &Z_STRVAL_P(return_value), &Z_STRLEN_P(return_value), mode);
 }
 /* }}} */
 
@@ -1069,22 +1103,30 @@ static void php_http_init_globals(zend_http_globals *http_globals)
 }
 /* }}} */
 
-/* {{{ PHP_INI */
-PHP_INI_MH(update_allowed_methods)
+/* {{{ static inline STATUS http_check_allowed_methods(char *, int) */
+#define http_check_allowed_methods(m, l) _http_check_allowed_methods((m), (l) TSRMLS_CC)
+static inline void _http_check_allowed_methods(char *methods, int length TSRMLS_DC)
 {
-       if (SG(request_info).request_method && new_value_length && (!strstr(new_value, SG(request_info).request_method))) {
-               char *allow_header = emalloc(new_value_length + sizeof("Allow: "));
-               sprintf(allow_header, "Allow: %s", new_value);
+       if (length && SG(request_info).request_method && (!strstr(methods, SG(request_info).request_method))) {
+               char *allow_header = emalloc(length + sizeof("Allow: "));
+               sprintf(allow_header, "Allow: %s", methods);
                http_send_header(allow_header);
                efree(allow_header);
                http_send_status(405);
-               return SUCCESS;
+               zend_bailout();
        }
+}
+/* }}} */
+
+/* {{{ PHP_INI */
+PHP_INI_MH(update_allowed_methods)
+{
+       http_check_allowed_methods(new_value, new_value_length);
        return OnUpdateString(entry, new_value, new_value_length, mh_arg1, mh_arg2, mh_arg3, stage TSRMLS_CC);
 }
 
 PHP_INI_BEGIN()
-       STD_PHP_INI_ENTRY("http.allowed_methods", "HEAD,GET,POST", PHP_INI_ALL, update_allowed_methods, allowed_methods, zend_http_globals, http_globals)
+       STD_PHP_INI_ENTRY("http.allowed_methods", "OPTIONS,GET,HEAD,POST,PUT,DELETE,TRACE,CONNECT", PHP_INI_ALL, update_allowed_methods, allowed_methods, zend_http_globals, http_globals)
 PHP_INI_END()
 /* }}} */
 
@@ -1114,14 +1156,7 @@ PHP_MSHUTDOWN_FUNCTION(http)
 PHP_RINIT_FUNCTION(http)
 {
        char *allowed_methods = INI_STR("http.allowed_methods");
-       int am_len;
-       if (SG(request_info).request_method && (am_len = strlen(allowed_methods)) && (!strstr(allowed_methods, SG(request_info).request_method))) {
-               char *allow_header = emalloc(am_len + sizeof("Allow: "));
-               sprintf(allow_header, "Allow: %s", allowed_methods);
-               http_send_header(allow_header);
-               efree(allow_header);
-               http_send_status(405);
-       }
+       http_check_allowed_methods(allowed_methods, strlen(allowed_methods));
        return SUCCESS;
 }
 /* }}} */
@@ -1129,14 +1164,18 @@ PHP_RINIT_FUNCTION(http)
 /* {{{ PHP_RSHUTDOWN_FUNCTION */
 PHP_RSHUTDOWN_FUNCTION(http)
 {
-       if (HTTP_G(ctype)) {
-               efree(HTTP_G(ctype));
-               HTTP_G(ctype) = NULL;
-       }
+       HTTP_G(etag_started) = 0;
+       HTTP_G(lmod) = 0;
+
        if (HTTP_G(etag)) {
                efree(HTTP_G(etag));
                HTTP_G(etag) = NULL;
        }
+
+       if (HTTP_G(ctype)) {
+               efree(HTTP_G(ctype));
+               HTTP_G(ctype) = NULL;
+       }
 #ifdef HTTP_HAVE_CURL
        if (HTTP_G(curlbuf).body.data) {
                efree(HTTP_G(curlbuf).body.data);