| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681 | 
							- using System;
 
- using System.Collections.Generic;
 
- using System.Globalization;
 
- using System.IO;
 
- using System.Net;
 
- using System.Text;
 
- using System.Threading.Tasks;
 
- using MediaBrowser.Model.Services;
 
- using Microsoft.Extensions.Primitives;
 
- namespace Emby.Server.Implementations.SocketSharp
 
- {
 
-     public partial class WebSocketSharpRequest : IHttpRequest
 
-     {
 
-         internal static string GetParameter(string header, string attr)
 
-         {
 
-             int ap = header.IndexOf(attr, StringComparison.Ordinal);
 
-             if (ap == -1)
 
-             {
 
-                 return null;
 
-             }
 
-             ap += attr.Length;
 
-             if (ap >= header.Length)
 
-             {
 
-                 return null;
 
-             }
 
-             char ending = header[ap];
 
-             if (ending != '"')
 
-             {
 
-                 ending = ' ';
 
-             }
 
-             int end = header.IndexOf(ending, ap + 1);
 
-             if (end == -1)
 
-             {
 
-                 return ending == '"' ? null : header.Substring(ap);
 
-             }
 
-             return header.Substring(ap + 1, end - ap - 1);
 
-         }
 
-         private async Task LoadMultiPart(WebROCollection form)
 
-         {
 
-             string boundary = GetParameter(ContentType, "; boundary=");
 
-             if (boundary == null)
 
-             {
 
-                 return;
 
-             }
 
-             using (var requestStream = InputStream)
 
-             {
 
-                 // DB: 30/01/11 - Hack to get around non-seekable stream and received HTTP request
 
-                 // Not ending with \r\n?
 
-                 var ms = new MemoryStream(32 * 1024);
 
-                 await requestStream.CopyToAsync(ms).ConfigureAwait(false);
 
-                 var input = ms;
 
-                 ms.WriteByte((byte)'\r');
 
-                 ms.WriteByte((byte)'\n');
 
-                 input.Position = 0;
 
-                 // Uncomment to debug
 
-                 // var content = new StreamReader(ms).ReadToEnd();
 
-                 // Console.WriteLine(boundary + "::" + content);
 
-                 // input.Position = 0;
 
-                 var multi_part = new HttpMultipart(input, boundary, ContentEncoding);
 
-                 HttpMultipart.Element e;
 
-                 while ((e = multi_part.ReadNextElement()) != null)
 
-                 {
 
-                     if (e.Filename == null)
 
-                     {
 
-                         byte[] copy = new byte[e.Length];
 
-                         input.Position = e.Start;
 
-                         input.Read(copy, 0, (int)e.Length);
 
-                         form.Add(e.Name, (e.Encoding ?? ContentEncoding).GetString(copy, 0, copy.Length));
 
-                     }
 
-                     else
 
-                     {
 
-                         // We use a substream, as in 2.x we will support large uploads streamed to disk,
 
-                         var sub = new HttpPostedFile(e.Filename, e.ContentType, input, e.Start, e.Length);
 
-                         files[e.Name] = sub;
 
-                     }
 
-                 }
 
-             }
 
-         }
 
-         public async Task<QueryParamCollection> GetFormData()
 
-         {
 
-             var form = new WebROCollection();
 
-             files = new Dictionary<string, HttpPostedFile>();
 
-             if (IsContentType("multipart/form-data", true))
 
-             {
 
-                 await LoadMultiPart(form).ConfigureAwait(false);
 
-             }
 
-             else if (IsContentType("application/x-www-form-urlencoded", true))
 
-             {
 
-                 await LoadWwwForm(form).ConfigureAwait(false);
 
-             }
 
- #if NET_4_0
 
-             if (validateRequestNewMode && !checked_form) {
 
-                 // Setting this before calling the validator prevents
 
-                 // possible endless recursion
 
-                 checked_form = true;
 
-                 ValidateNameValueCollection("Form", query_string_nvc, RequestValidationSource.Form);
 
-             } else
 
- #endif
 
-             if (validate_form && !checked_form)
 
-             {
 
-                 checked_form = true;
 
-                 ValidateNameValueCollection("Form", form);
 
-             }
 
-             return form;
 
-         }
 
-         public string Accept => StringValues.IsNullOrEmpty(request.Headers["Accept"]) ? null : request.Headers["Accept"].ToString();
 
-         public string Authorization => StringValues.IsNullOrEmpty(request.Headers["Authorization"]) ? null : request.Headers["Authorization"].ToString();
 
-         protected bool validate_cookies { get; set; }
 
-         protected bool validate_query_string { get; set; }
 
-         protected bool validate_form { get; set; }
 
-         protected bool checked_cookies { get; set; }
 
-         protected bool checked_query_string { get; set; }
 
-         protected bool checked_form { get; set; }
 
-         private static void ThrowValidationException(string name, string key, string value)
 
-         {
 
-             string v = "\"" + value + "\"";
 
-             if (v.Length > 20)
 
-             {
 
-                 v = v.Substring(0, 16) + "...\"";
 
-             }
 
-             string msg = string.Format(
 
-                 CultureInfo.InvariantCulture,
 
-                 "A potentially dangerous Request.{0} value was detected from the client ({1}={2}).",
 
-                 name,
 
-                 key,
 
-                 v);
 
-             throw new Exception(msg);
 
-         }
 
-         private static void ValidateNameValueCollection(string name, QueryParamCollection coll)
 
-         {
 
-             if (coll == null)
 
-             {
 
-                 return;
 
-             }
 
-             foreach (var pair in coll)
 
-             {
 
-                 var key = pair.Name;
 
-                 var val = pair.Value;
 
-                 if (val != null && val.Length > 0 && IsInvalidString(val))
 
-                 {
 
-                     ThrowValidationException(name, key, val);
 
-                 }
 
-             }
 
-         }
 
-         internal static bool IsInvalidString(string val)
 
-             => IsInvalidString(val, out var validationFailureIndex);
 
-         internal static bool IsInvalidString(string val, out int validationFailureIndex)
 
-         {
 
-             validationFailureIndex = 0;
 
-             int len = val.Length;
 
-             if (len < 2)
 
-             {
 
-                 return false;
 
-             }
 
-             char current = val[0];
 
-             for (int idx = 1; idx < len; idx++)
 
-             {
 
-                 char next = val[idx];
 
-                 // See http://secunia.com/advisories/14325
 
-                 if (current == '<' || current == '\xff1c')
 
-                 {
 
-                     if (next == '!' || next < ' '
 
-                         || (next >= 'a' && next <= 'z')
 
-                         || (next >= 'A' && next <= 'Z'))
 
-                     {
 
-                         validationFailureIndex = idx - 1;
 
-                         return true;
 
-                     }
 
-                 }
 
-                 else if (current == '&' && next == '#')
 
-                 {
 
-                     validationFailureIndex = idx - 1;
 
-                     return true;
 
-                 }
 
-                 current = next;
 
-             }
 
-             return false;
 
-         }
 
-         public void ValidateInput()
 
-         {
 
-             validate_cookies = true;
 
-             validate_query_string = true;
 
-             validate_form = true;
 
-         }
 
-         private bool IsContentType(string ct, bool starts_with)
 
-         {
 
-             if (ct == null || ContentType == null)
 
-             {
 
-                 return false;
 
-             }
 
-             if (starts_with)
 
-             {
 
-                 return ContentType.StartsWith(ct, StringComparison.OrdinalIgnoreCase);
 
-             }
 
-             return string.Equals(ContentType, ct, StringComparison.OrdinalIgnoreCase);
 
-         }
 
-         private async Task LoadWwwForm(WebROCollection form)
 
-         {
 
-             using (var input = InputStream)
 
-             {
 
-                 using (var ms = new MemoryStream())
 
-                 {
 
-                     await input.CopyToAsync(ms).ConfigureAwait(false);
 
-                     ms.Position = 0;
 
-                     using (var s = new StreamReader(ms, ContentEncoding))
 
-                     {
 
-                         var key = new StringBuilder();
 
-                         var value = new StringBuilder();
 
-                         int c;
 
-                         while ((c = s.Read()) != -1)
 
-                         {
 
-                             if (c == '=')
 
-                             {
 
-                                 value.Length = 0;
 
-                                 while ((c = s.Read()) != -1)
 
-                                 {
 
-                                     if (c == '&')
 
-                                     {
 
-                                         AddRawKeyValue(form, key, value);
 
-                                         break;
 
-                                     }
 
-                                     else
 
-                                     {
 
-                                         value.Append((char)c);
 
-                                     }
 
-                                 }
 
-                                 if (c == -1)
 
-                                 {
 
-                                     AddRawKeyValue(form, key, value);
 
-                                     return;
 
-                                 }
 
-                             }
 
-                             else if (c == '&')
 
-                             {
 
-                                 AddRawKeyValue(form, key, value);
 
-                             }
 
-                             else
 
-                             {
 
-                                 key.Append((char)c);
 
-                             }
 
-                         }
 
-                         if (c == -1)
 
-                         {
 
-                             AddRawKeyValue(form, key, value);
 
-                         }
 
-                     }
 
-                 }
 
-             }
 
-         }
 
-         private static void AddRawKeyValue(WebROCollection form, StringBuilder key, StringBuilder value)
 
-         {
 
-             form.Add(WebUtility.UrlDecode(key.ToString()), WebUtility.UrlDecode(value.ToString()));
 
-             key.Length = 0;
 
-             value.Length = 0;
 
-         }
 
-         private Dictionary<string, HttpPostedFile> files;
 
-         private class WebROCollection : QueryParamCollection
 
-         {
 
-             public override string ToString()
 
-             {
 
-                 var result = new StringBuilder();
 
-                 foreach (var pair in this)
 
-                 {
 
-                     if (result.Length > 0)
 
-                     {
 
-                         result.Append('&');
 
-                     }
 
-                     var key = pair.Name;
 
-                     if (key != null && key.Length > 0)
 
-                     {
 
-                         result.Append(key);
 
-                         result.Append('=');
 
-                     }
 
-                     result.Append(pair.Value);
 
-                 }
 
-                 return result.ToString();
 
-             }
 
-         }
 
-         private class HttpMultipart
 
-         {
 
-             public class Element
 
-             {
 
-                 public string ContentType { get; set; }
 
-                 public string Name { get; set; }
 
-                 public string Filename { get; set; }
 
-                 public Encoding Encoding { get; set; }
 
-                 public long Start { get; set; }
 
-                 public long Length { get; set; }
 
-                 public override string ToString()
 
-                 {
 
-                     return "ContentType " + ContentType + ", Name " + Name + ", Filename " + Filename + ", Start " +
 
-                         Start.ToString(CultureInfo.CurrentCulture) + ", Length " + Length.ToString(CultureInfo.CurrentCulture);
 
-                 }
 
-             }
 
-             private const byte LF = (byte)'\n';
 
-             private const byte CR = (byte)'\r';
 
-             private Stream data;
 
-             private string boundary;
 
-             private byte[] boundaryBytes;
 
-             private byte[] buffer;
 
-             private bool atEof;
 
-             private Encoding encoding;
 
-             private StringBuilder sb;
 
-             // See RFC 2046
 
-             // In the case of multipart entities, in which one or more different
 
-             // sets of data are combined in a single body, a "multipart" media type
 
-             // field must appear in the entity's header.  The body must then contain
 
-             // one or more body parts, each preceded by a boundary delimiter line,
 
-             // and the last one followed by a closing boundary delimiter line.
 
-             // After its boundary delimiter line, each body part then consists of a
 
-             // header area, a blank line, and a body area.  Thus a body part is
 
-             // similar to an RFC 822 message in syntax, but different in meaning.
 
-             public HttpMultipart(Stream data, string b, Encoding encoding)
 
-             {
 
-                 this.data = data;
 
-                 boundary = b;
 
-                 boundaryBytes = encoding.GetBytes(b);
 
-                 buffer = new byte[boundaryBytes.Length + 2]; // CRLF or '--'
 
-                 this.encoding = encoding;
 
-                 sb = new StringBuilder();
 
-             }
 
-             public Element ReadNextElement()
 
-             {
 
-                 if (atEof || ReadBoundary())
 
-                 {
 
-                     return null;
 
-                 }
 
-                 var elem = new Element();
 
-                 string header;
 
-                 while ((header = ReadHeaders()) != null)
 
-                 {
 
-                     if (header.StartsWith("Content-Disposition:", StringComparison.OrdinalIgnoreCase))
 
-                     {
 
-                         elem.Name = GetContentDispositionAttribute(header, "name");
 
-                         elem.Filename = StripPath(GetContentDispositionAttributeWithEncoding(header, "filename"));
 
-                     }
 
-                     else if (header.StartsWith("Content-Type:", StringComparison.OrdinalIgnoreCase))
 
-                     {
 
-                         elem.ContentType = header.Substring("Content-Type:".Length).Trim();
 
-                         elem.Encoding = GetEncoding(elem.ContentType);
 
-                     }
 
-                 }
 
-                 long start = data.Position;
 
-                 elem.Start = start;
 
-                 long pos = MoveToNextBoundary();
 
-                 if (pos == -1)
 
-                 {
 
-                     return null;
 
-                 }
 
-                 elem.Length = pos - start;
 
-                 return elem;
 
-             }
 
-             private string ReadLine()
 
-             {
 
-                 // CRLF or LF are ok as line endings.
 
-                 bool got_cr = false;
 
-                 int b = 0;
 
-                 sb.Length = 0;
 
-                 while (true)
 
-                 {
 
-                     b = data.ReadByte();
 
-                     if (b == -1)
 
-                     {
 
-                         return null;
 
-                     }
 
-                     if (b == LF)
 
-                     {
 
-                         break;
 
-                     }
 
-                     got_cr = b == CR;
 
-                     sb.Append((char)b);
 
-                 }
 
-                 if (got_cr)
 
-                 {
 
-                     sb.Length--;
 
-                 }
 
-                 return sb.ToString();
 
-             }
 
-             private static string GetContentDispositionAttribute(string l, string name)
 
-             {
 
-                 int idx = l.IndexOf(name + "=\"", StringComparison.Ordinal);
 
-                 if (idx < 0)
 
-                 {
 
-                     return null;
 
-                 }
 
-                 int begin = idx + name.Length + "=\"".Length;
 
-                 int end = l.IndexOf('"', begin);
 
-                 if (end < 0)
 
-                 {
 
-                     return null;
 
-                 }
 
-                 if (begin == end)
 
-                 {
 
-                     return string.Empty;
 
-                 }
 
-                 return l.Substring(begin, end - begin);
 
-             }
 
-             private string GetContentDispositionAttributeWithEncoding(string l, string name)
 
-             {
 
-                 int idx = l.IndexOf(name + "=\"", StringComparison.Ordinal);
 
-                 if (idx < 0)
 
-                 {
 
-                     return null;
 
-                 }
 
-                 int begin = idx + name.Length + "=\"".Length;
 
-                 int end = l.IndexOf('"', begin);
 
-                 if (end < 0)
 
-                 {
 
-                     return null;
 
-                 }
 
-                 if (begin == end)
 
-                 {
 
-                     return string.Empty;
 
-                 }
 
-                 string temp = l.Substring(begin, end - begin);
 
-                 byte[] source = new byte[temp.Length];
 
-                 for (int i = temp.Length - 1; i >= 0; i--)
 
-                 {
 
-                     source[i] = (byte)temp[i];
 
-                 }
 
-                 return encoding.GetString(source, 0, source.Length);
 
-             }
 
-             private bool ReadBoundary()
 
-             {
 
-                 try
 
-                 {
 
-                     string line;
 
-                     do
 
-                     {
 
-                         line = ReadLine();
 
-                     }
 
-                     while (line.Length == 0);
 
-                     if (line[0] != '-' || line[1] != '-')
 
-                     {
 
-                         return false;
 
-                     }
 
-                     if (!line.EndsWith(boundary, StringComparison.Ordinal))
 
-                     {
 
-                         return true;
 
-                     }
 
-                 }
 
-                 catch
 
-                 {
 
-                 }
 
-                 return false;
 
-             }
 
-             private string ReadHeaders()
 
-             {
 
-                 string s = ReadLine();
 
-                 if (s.Length == 0)
 
-                 {
 
-                     return null;
 
-                 }
 
-                 return s;
 
-             }
 
-             private static bool CompareBytes(byte[] orig, byte[] other)
 
-             {
 
-                 for (int i = orig.Length - 1; i >= 0; i--)
 
-                 {
 
-                     if (orig[i] != other[i])
 
-                     {
 
-                         return false;
 
-                     }
 
-                 }
 
-                 return true;
 
-             }
 
-             private long MoveToNextBoundary()
 
-             {
 
-                 long retval = 0;
 
-                 bool got_cr = false;
 
-                 int state = 0;
 
-                 int c = data.ReadByte();
 
-                 while (true)
 
-                 {
 
-                     if (c == -1)
 
-                     {
 
-                         return -1;
 
-                     }
 
-                     if (state == 0 && c == LF)
 
-                     {
 
-                         retval = data.Position - 1;
 
-                         if (got_cr)
 
-                         {
 
-                             retval--;
 
-                         }
 
-                         state = 1;
 
-                         c = data.ReadByte();
 
-                     }
 
-                     else if (state == 0)
 
-                     {
 
-                         got_cr = c == CR;
 
-                         c = data.ReadByte();
 
-                     }
 
-                     else if (state == 1 && c == '-')
 
-                     {
 
-                         c = data.ReadByte();
 
-                         if (c == -1)
 
-                         {
 
-                             return -1;
 
-                         }
 
-                         if (c != '-')
 
-                         {
 
-                             state = 0;
 
-                             got_cr = false;
 
-                             continue; // no ReadByte() here
 
-                         }
 
-                         int nread = data.Read(buffer, 0, buffer.Length);
 
-                         int bl = buffer.Length;
 
-                         if (nread != bl)
 
-                         {
 
-                             return -1;
 
-                         }
 
-                         if (!CompareBytes(boundaryBytes, buffer))
 
-                         {
 
-                             state = 0;
 
-                             data.Position = retval + 2;
 
-                             if (got_cr)
 
-                             {
 
-                                 data.Position++;
 
-                                 got_cr = false;
 
-                             }
 
-                             c = data.ReadByte();
 
-                             continue;
 
-                         }
 
-                         if (buffer[bl - 2] == '-' && buffer[bl - 1] == '-')
 
-                         {
 
-                             atEof = true;
 
-                         }
 
-                         else if (buffer[bl - 2] != CR || buffer[bl - 1] != LF)
 
-                         {
 
-                             state = 0;
 
-                             data.Position = retval + 2;
 
-                             if (got_cr)
 
-                             {
 
-                                 data.Position++;
 
-                                 got_cr = false;
 
-                             }
 
-                             c = data.ReadByte();
 
-                             continue;
 
-                         }
 
-                         data.Position = retval + 2;
 
-                         if (got_cr)
 
-                         {
 
-                             data.Position++;
 
-                         }
 
-                         break;
 
-                     }
 
-                     else
 
-                     {
 
-                         // state == 1
 
-                         state = 0; // no ReadByte() here
 
-                     }
 
-                 }
 
-                 return retval;
 
-             }
 
-             private static string StripPath(string path)
 
-             {
 
-                 if (path == null || path.Length == 0)
 
-                 {
 
-                     return path;
 
-                 }
 
-                 if (path.IndexOf(":\\", StringComparison.Ordinal) != 1
 
-                     && !path.StartsWith("\\\\", StringComparison.Ordinal))
 
-                 {
 
-                     return path;
 
-                 }
 
-                 return path.Substring(path.LastIndexOf('\\') + 1);
 
-             }
 
-         }
 
-     }
 
- }
 
 
  |