Coverage Report

Created: 2026-09-14 07:06

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/curl/lib/cookie.c
Line
Count
Source
1
/***************************************************************************
2
 *                                  _   _ ____  _
3
 *  Project                     ___| | | |  _ \| |
4
 *                             / __| | | | |_) | |
5
 *                            | (__| |_| |  _ <| |___
6
 *                             \___|\___/|_| \_\_____|
7
 *
8
 * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
9
 *
10
 * This software is licensed as described in the file COPYING, which
11
 * you should have received as part of this distribution. The terms
12
 * are also available at https://curl.se/docs/copyright.html.
13
 *
14
 * You may opt to use, copy, modify, merge, publish, distribute and/or sell
15
 * copies of the Software, and permit persons to whom the Software is
16
 * furnished to do so, under the terms of the COPYING file.
17
 *
18
 * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
19
 * KIND, either express or implied.
20
 *
21
 * SPDX-License-Identifier: curl
22
 *
23
 ***************************************************************************/
24
#include "curl_setup.h"
25
26
#if !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_COOKIES)
27
28
#include "urldata.h"
29
#include "cookie.h"
30
#include "psl.h"
31
#include "curl_trc.h"
32
#include "transfer.h"
33
#include "slist.h"
34
#include "curl_share.h"
35
#include "strcase.h"
36
#include "curl_fopen.h"
37
#include "curl_get_line.h"
38
#include "curl_memrchr.h"
39
#include "parsedate.h"
40
#include "curlx/strdup.h"
41
#include "llist.h"
42
#include "curlx/strparse.h"
43
44
/* number of seconds in 400 days */
45
470
#define COOKIES_MAXAGE (400 * 24 * 3600)
46
47
/* Make sure cookies never expire further away in time than 400 days into the
48
   future. (from RFC6265bis draft-19)
49
50
   For the sake of easier testing, align the capped time to an even 60 second
51
   boundary. */
52
static void cap_expires(time_t now, struct Cookie *co)
53
13.2k
{
54
13.2k
  if(co->expires && (TIME_T_MAX - COOKIES_MAXAGE - 30) > now) {
55
235
    timediff_t cap = now + COOKIES_MAXAGE;
56
235
    if(co->expires > cap) {
57
58
      cap += 30;
58
58
      co->expires = (cap / 60) * 60;
59
58
    }
60
235
  }
61
13.2k
}
62
63
static void freecookie(struct Cookie *co, bool maintoo)
64
11.7k
{
65
11.7k
  curlx_free(co->domain);
66
11.7k
  curlx_free(co->path);
67
11.7k
  curlx_free(co->name);
68
11.7k
  curlx_free(co->value);
69
11.7k
  if(maintoo)
70
1.41k
    curlx_free(co);
71
11.7k
}
72
73
static bool cookie_tailmatch(const char *cookie_domain,
74
                             const size_t cookie_domain_len,
75
                             const char *hostname)
76
0
{
77
0
  size_t hostname_len = strlen(hostname);
78
79
0
  if(hostname_len < cookie_domain_len)
80
0
    return FALSE;
81
82
0
  if(!curl_strnequal(cookie_domain,
83
0
                     hostname + hostname_len - cookie_domain_len,
84
0
                     cookie_domain_len))
85
0
    return FALSE;
86
87
  /*
88
   * A lead char of cookie_domain is not '.'.
89
   * RFC6265 4.1.2.3. The Domain Attribute says:
90
   * For example, if the value of the Domain attribute is
91
   * "example.com", the user agent will include the cookie in the Cookie
92
   * header when making HTTP requests to example.com, www.example.com, and
93
   * www.corp.example.com.
94
   */
95
0
  if(hostname_len == cookie_domain_len)
96
0
    return TRUE;
97
0
  if('.' == *(hostname + hostname_len - cookie_domain_len - 1))
98
0
    return TRUE;
99
0
  return FALSE;
100
0
}
101
102
/*
103
 * matching cookie path and URL path
104
 * RFC6265 5.1.4 Paths and Path-Match
105
 */
106
static bool pathmatch(const char *cookie_path, const char *uri_path)
107
0
{
108
0
  size_t cookie_path_len;
109
0
  size_t uri_path_len;
110
0
  bool ret = FALSE;
111
112
  /* cookie_path must not have last '/' separator. ex: /sample */
113
0
  cookie_path_len = strlen(cookie_path);
114
0
  if(cookie_path_len == 1) {
115
    /* cookie_path must be '/' */
116
0
    return TRUE;
117
0
  }
118
119
  /* #-fragments are already cut off! */
120
0
  if(strlen(uri_path) == 0 || uri_path[0] != '/')
121
0
    uri_path = "/";
122
123
  /*
124
   * here, RFC6265 5.1.4 says
125
   *  4. Output the characters of the uri-path from the first character up
126
   *     to, but not including, the right-most %x2F ("/").
127
   *  but URL path /hoge?fuga=xxx means /hoge/index.cgi?fuga=xxx in some site
128
   *  without redirect.
129
   *  Ignore this algorithm because /hoge is uri path for this case
130
   *  (uri path is not /).
131
   */
132
133
0
  uri_path_len = strlen(uri_path);
134
135
0
  if(uri_path_len < cookie_path_len)
136
0
    goto pathmatched;
137
138
  /* not using checkprefix() because matching should be case-sensitive */
139
0
  if(strncmp(cookie_path, uri_path, cookie_path_len))
140
0
    goto pathmatched;
141
142
  /* The cookie-path and the uri-path are identical. */
143
0
  if(cookie_path_len == uri_path_len) {
144
0
    ret = TRUE;
145
0
    goto pathmatched;
146
0
  }
147
148
  /* here, cookie_path_len < uri_path_len */
149
0
  if(uri_path[cookie_path_len] == '/') {
150
0
    ret = TRUE;
151
0
    goto pathmatched;
152
0
  }
153
154
0
pathmatched:
155
0
  return ret;
156
0
}
157
158
/*
159
 * Return the top-level domain, for optimal hashing.
160
 */
161
static const char *get_top_domain(const char * const domain, size_t *outlen)
162
756
{
163
756
  size_t len = 0;
164
756
  const char *first = NULL, *last;
165
166
756
  if(domain) {
167
756
    len = strlen(domain);
168
756
    last = memrchr(domain, '.', len);
169
756
    if(last) {
170
74
      first = memrchr(domain, '.', (last - domain));
171
74
      if(first)
172
26
        len -= (++first - domain);
173
74
    }
174
756
  }
175
176
756
  if(outlen)
177
756
    *outlen = len;
178
179
756
  return first ? first : domain;
180
756
}
181
182
/* Avoid C1001, an "internal error" with MSVC14 */
183
#if defined(_MSC_VER) && (_MSC_VER == 1900)
184
#pragma optimize("", off)
185
#endif
186
187
/*
188
 * A case-insensitive hash for the cookie domains.
189
 */
190
static size_t cookie_hash_domain(const char *domain, const size_t len)
191
756
{
192
756
  const char *end = domain + len;
193
756
  size_t h = 5381;
194
195
1.96k
  while(domain < end) {
196
1.20k
    size_t j = (size_t)Curl_raw_toupper(*domain++);
197
1.20k
    h += h << 5;
198
1.20k
    h ^= j;
199
1.20k
  }
200
201
756
  return (h % COOKIE_HASH_SIZE);
202
756
}
203
204
#if defined(_MSC_VER) && (_MSC_VER == 1900)
205
#pragma optimize("", on)
206
#endif
207
208
/*
209
 * Hash this domain.
210
 */
211
static size_t cookiehash(const char * const domain)
212
2.82k
{
213
2.82k
  const char *top;
214
2.82k
  size_t len;
215
216
2.82k
  if(!domain || Curl_host_is_ipnum(domain))
217
2.06k
    return 0;
218
219
756
  top = get_top_domain(domain, &len);
220
756
  return cookie_hash_domain(top, len);
221
2.82k
}
222
223
/*
224
 * cookie path sanitize
225
 */
226
static char *sanitize_cookie_path(const char *cookie_path, size_t len)
227
103
{
228
  /* some sites send path attribute within '"'. */
229
103
  if(len && (cookie_path[0] == '\"')) {
230
12
    cookie_path++;
231
12
    len--;
232
233
12
    if(len && (cookie_path[len - 1] == '\"'))
234
2
      len--;
235
12
  }
236
237
  /* RFC6265 5.2.4 The Path Attribute */
238
103
  if(!len || (cookie_path[0] != '/'))
239
    /* Let cookie-path be the default-path. */
240
78
    return curlx_strdup("/");
241
242
  /* remove trailing slash when path is non-empty */
243
  /* convert /hoge/ to /hoge */
244
25
  if(len > 1 && cookie_path[len - 1] == '/')
245
2
    len--;
246
247
25
  return curlx_memdup0(cookie_path, len);
248
103
}
249
250
/*
251
 * strstore
252
 *
253
 * A thin wrapper around curlx_memdup0().
254
 */
255
static CURLcode strstore(char **str, const char *newstr, size_t len)
256
2.06k
{
257
2.06k
  DEBUGASSERT(str);
258
2.06k
  *str = curlx_memdup0(newstr, len);
259
2.06k
  if(!*str)
260
0
    return CURLE_OUT_OF_MEMORY;
261
2.06k
  return CURLE_OK;
262
2.06k
}
263
264
/*
265
 * remove_expired
266
 *
267
 * Remove expired cookies from the hash by inspecting the expires timestamp on
268
 * each cookie in the hash, freeing and deleting any where the timestamp is in
269
 * the past. If the cookiejar has recorded the next timestamp at which one or
270
 * more cookies expire, then processing will exit early in case this timestamp
271
 * is in the future.
272
 */
273
static void remove_expired(struct CookieInfo *ci)
274
21.3k
{
275
21.3k
  struct Cookie *co;
276
21.3k
  curl_off_t now = (curl_off_t)time(NULL);
277
21.3k
  unsigned int i;
278
279
  /*
280
   * If the earliest expiration timestamp in the jar is in the future we can
281
   * skip scanning the whole jar and instead exit early as there will not be
282
   * any cookies to evict. If we need to evict, reset the next_expiration
283
   * counter in order to track the next one. In case the recorded first
284
   * expiration is the max offset, then perform the safe fallback of checking
285
   * all cookies.
286
   */
287
21.3k
  if(now < ci->next_expiration &&
288
21.1k
     ci->next_expiration != CURL_OFF_T_MAX)
289
232
    return;
290
21.0k
  else
291
21.0k
    ci->next_expiration = CURL_OFF_T_MAX;
292
293
1.34M
  for(i = 0; i < COOKIE_HASH_SIZE; i++) {
294
1.32M
    struct Curl_llist_node *n;
295
1.32M
    struct Curl_llist_node *e = NULL;
296
297
1.32M
    for(n = Curl_llist_head(&ci->cookielist[i]); n; n = e) {
298
603
      co = Curl_node_elem(n);
299
603
      e = Curl_node_next(n);
300
603
      if(co->expires) {
301
131
        if(co->expires < now) {
302
129
          Curl_node_remove(n);
303
129
          freecookie(co, TRUE);
304
129
          ci->numcookies--;
305
129
        }
306
2
        else if(co->expires < ci->next_expiration)
307
          /*
308
           * If this cookie has an expiration timestamp earlier than what we
309
           * have seen so far then record it for the next round of expirations.
310
           */
311
0
          ci->next_expiration = co->expires;
312
131
      }
313
603
    }
314
1.32M
  }
315
21.0k
}
316
317
#ifndef USE_LIBPSL
318
/* Make sure domain contains a dot or is localhost. */
319
static bool bad_domain(const char *domain, size_t len)
320
0
{
321
0
  if((len == 9) && curl_strnequal(domain, "localhost", 9))
322
0
    return FALSE;
323
0
  else {
324
    /* there must be a dot present, but that dot must not be a trailing dot */
325
0
    const char *dot = memchr(domain, '.', len);
326
0
    if(dot) {
327
0
      size_t i = dot - domain;
328
0
      if((len - i) > 1)
329
        /* the dot is not the last byte */
330
0
        return FALSE;
331
0
    }
332
0
  }
333
0
  return TRUE;
334
0
}
335
#endif
336
337
/* RFC 6265 section 4.1.1 says a server should accept this range:
338
339
   cookie-octet    = %x21 / %x23-2B / %x2D-3A / %x3C-5B / %x5D-7E
340
341
   Yet, Firefox and Chrome as of June 2022 accept space, comma and
342
   double-quotes fine. The prime reason for filtering out control bytes is that
343
   some HTTP servers return 400 for requests that contain such.
344
 */
345
static bool invalid_octets(const char *ptr, size_t len)
346
41.9k
{
347
41.9k
  const unsigned char *p = (const unsigned char *)ptr;
348
  /* Reject all bytes \x01 - \x1f + \x7f */
349
424k
  while(len && *p) {
350
382k
    if((*p < 0x20) || (*p == 0x7f))
351
43
      return TRUE;
352
382k
    p++;
353
382k
    len--;
354
382k
  }
355
41.9k
  return FALSE;
356
41.9k
}
357
358
/* The maximum length we accept a date string for the 'expire' keyword. The
359
   standard date formats are within the 30 bytes range. This adds an extra
360
   margin to make sure it realistically works with what is used out there. */
361
13.2k
#define MAX_DATE_LENGTH 80
362
363
1.05k
#define COOKIE_NAME   0
364
1.05k
#define COOKIE_VALUE  1
365
0
#define COOKIE_DOMAIN 2
366
217
#define COOKIE_PATH   3
367
368
#define COOKIE_PIECES 4 /* the list above */
369
370
static CURLcode storecookie(struct Cookie *co, const struct Curl_str *cp,
371
                            const char *path, const char *domain)
372
1.03k
{
373
1.03k
  CURLcode result;
374
1.03k
  result = strstore(&co->name, curlx_str(&cp[COOKIE_NAME]),
375
1.03k
                    curlx_strlen(&cp[COOKIE_NAME]));
376
1.03k
  if(!result)
377
1.03k
    result = strstore(&co->value, curlx_str(&cp[COOKIE_VALUE]),
378
1.03k
                      curlx_strlen(&cp[COOKIE_VALUE]));
379
1.03k
  if(!result) {
380
1.03k
    size_t plen = 0;
381
1.03k
    if(curlx_strlen(&cp[COOKIE_PATH])) {
382
19
      path = curlx_str(&cp[COOKIE_PATH]);
383
19
      plen = curlx_strlen(&cp[COOKIE_PATH]);
384
19
    }
385
1.01k
    else if(path) {
386
      /* No path was given in the header line, set the default */
387
0
      const char *endslash = strrchr(path, '/');
388
0
      if(endslash)
389
0
        plen = endslash - path + 1; /* include end slash */
390
0
      else
391
0
        plen = strlen(path);
392
0
    }
393
394
1.03k
    if(path) {
395
19
      co->path = sanitize_cookie_path(path, plen);
396
19
      if(!co->path)
397
0
        result = CURLE_OUT_OF_MEMORY;
398
19
    }
399
1.03k
  }
400
1.03k
  if(!result) {
401
1.03k
    if(curlx_strlen(&cp[COOKIE_DOMAIN]))
402
0
      result = strstore(&co->domain, curlx_str(&cp[COOKIE_DOMAIN]),
403
0
                        curlx_strlen(&cp[COOKIE_DOMAIN]));
404
1.03k
    else if(domain) {
405
      /* no domain was given in the header line, set the default */
406
0
      co->domain = curlx_strdup(domain);
407
0
      if(!co->domain)
408
0
        result = CURLE_OUT_OF_MEMORY;
409
0
    }
410
1.03k
  }
411
1.03k
  return result;
412
1.03k
}
413
414
/*
415
 * Parse the first name/value pair of the cookie header, which is the actual
416
 * cookie name and value.
417
 */
418
static bool parse_first_pair(struct Curl_easy *data, struct Cookie *co,
419
                             struct Curl_str *cookie,
420
                             struct Curl_str *name,
421
                             struct Curl_str *val,
422
                             bool sep)
423
1.08k
{
424
  /* The first name/value pair is the actual cookie name */
425
1.08k
  if(!sep || !curlx_strlen(name)) {
426
28
    infof(data, "invalid cookie, dropped");
427
28
    return FALSE;
428
28
  }
429
430
  /*
431
   * Check for too long individual name or contents. Chrome and Firefox
432
   * support 4095 or 4096 bytes combo
433
   */
434
1.05k
  if((curlx_strlen(name) + curlx_strlen(val)) > MAX_NAME) {
435
2
    infof(data, "oversized cookie dropped, name/val %zu + %zu bytes",
436
2
          curlx_strlen(name), curlx_strlen(val));
437
2
    return FALSE;
438
2
  }
439
440
  /* Check if we have a reserved prefix set. */
441
1.05k
  if(!strncmp("__Secure-", curlx_str(name), 9))
442
3
    co->prefix_secure = TRUE;
443
1.04k
  else if(!strncmp("__Host-", curlx_str(name), 7))
444
6
    co->prefix_host = TRUE;
445
446
1.05k
  cookie[COOKIE_NAME] = *name;
447
1.05k
  cookie[COOKIE_VALUE] = *val;
448
1.05k
  return TRUE;
449
1.05k
}
450
451
static bool parse_flag(struct Curl_easy *data, struct Cookie *co,
452
                       const struct CookieInfo *ci,
453
                       struct Curl_str *name, bool secure)
454
4.39k
{
455
  /*
456
   * secure cookies are only allowed to be set when the connection is
457
   * using a secure protocol, or when the cookie is being set by
458
   * reading from file
459
   */
460
4.39k
  if(curlx_str_casecompare(name, "secure")) {
461
196
    if(secure || !ci->running)
462
196
      co->secure = TRUE;
463
0
    else {
464
0
      infof(data, "skipped cookie because not 'secure'");
465
0
      return FALSE;
466
0
    }
467
196
  }
468
4.19k
  else if(curlx_str_casecompare(name, "httponly"))
469
194
    co->httponly = TRUE;
470
471
4.39k
  return TRUE;
472
4.39k
}
473
474
static bool parse_domain(struct Curl_easy *data, struct Cookie *co,
475
                         struct Curl_str *cookie_domain,
476
                         struct Curl_str *val,
477
                         const char **domainp)
478
0
{
479
0
  bool is_ip;
480
0
  const char *domain = *domainp;
481
0
  const char *v = curlx_str(val);
482
  /*
483
   * Now, we make sure that our host is within the given domain, or
484
   * the given domain is not valid and thus cannot be set.
485
   */
486
487
0
  if('.' == *v)
488
0
    curlx_str_nudge(val, 1);
489
490
0
#ifndef USE_LIBPSL
491
  /*
492
   * Without PSL we do not know when the incoming cookie is set on a
493
   * TLD or otherwise "protected" suffix. To reduce risk, we require a
494
   * dot OR the exact hostname being "localhost".
495
   */
496
0
  if(bad_domain(curlx_str(val), curlx_strlen(val))) {
497
0
    *domainp = ":";
498
0
    domain = ":";
499
0
  }
500
0
#endif
501
502
0
  is_ip = Curl_host_is_ipnum(domain ? domain : curlx_str(val));
503
504
0
  if(!domain ||
505
0
     (is_ip &&
506
0
      !strncmp(curlx_str(val), domain, curlx_strlen(val)) &&
507
0
      (curlx_strlen(val) == strlen(domain))) ||
508
0
     (!is_ip && cookie_tailmatch(curlx_str(val),
509
0
                                  curlx_strlen(val), domain))) {
510
0
    *cookie_domain = *val;
511
0
    if(!is_ip)
512
0
      co->tailmatch = TRUE; /* we always do that if the domain name was
513
                               given */
514
0
  }
515
0
  else {
516
    /*
517
     * We did not get a tailmatch and then the attempted set domain is
518
     * not a domain to which the current host belongs. Mark as bad.
519
     */
520
0
    infof(data, "skipped cookie with bad tailmatch domain: %s",
521
0
          curlx_str(val));
522
0
    return FALSE;
523
0
  }
524
0
  return TRUE;
525
0
}
526
527
static void parse_maxage(struct Cookie *co, struct Curl_str *val,
528
                         time_t *nowp)
529
0
{
530
0
  int rc;
531
0
  const char *maxage = curlx_str(val);
532
0
  if(*maxage == '\"')
533
0
    maxage++;
534
0
  rc = curlx_str_number(&maxage, &co->expires, CURL_OFF_T_MAX);
535
0
  if(!*nowp)
536
0
    *nowp = time(NULL);
537
0
  switch(rc) {
538
0
  case STRE_OVERFLOW:
539
    /* overflow, used max value */
540
0
    co->expires = CURL_OFF_T_MAX;
541
0
    break;
542
0
  default:
543
    /* negative or otherwise bad, expire */
544
0
    co->expires = 1;
545
0
    break;
546
0
  case STRE_OK:
547
0
    if(!co->expires)
548
0
      co->expires = 1; /* expire now */
549
0
    else if(CURL_OFF_T_MAX - *nowp < co->expires)
550
      /* would overflow */
551
0
      co->expires = CURL_OFF_T_MAX;
552
0
    else
553
0
      co->expires += *nowp;
554
0
    break;
555
0
  }
556
0
  cap_expires(*nowp, co);
557
0
}
558
559
static void parse_expires(struct Cookie *co, struct Curl_str *val,
560
                          time_t *nowp)
561
13.5k
{
562
  /*
563
   * Let max-age have priority.
564
   *
565
   * If the date cannot get parsed for whatever reason, the cookie
566
   * will be treated as a session cookie
567
   */
568
13.5k
  if(!co->expires && (curlx_strlen(val) < MAX_DATE_LENGTH)) {
569
13.2k
    char dbuf[MAX_DATE_LENGTH + 1];
570
13.2k
    time_t date = 0;
571
13.2k
    memcpy(dbuf, curlx_str(val), curlx_strlen(val));
572
13.2k
    dbuf[curlx_strlen(val)] = 0;
573
13.2k
    if(!Curl_getdate_capped(dbuf, &date)) {
574
235
      if(!date)
575
1
        date++;
576
235
      co->expires = (curl_off_t)date;
577
235
    }
578
12.9k
    else
579
12.9k
      co->expires = 0;
580
13.2k
    if(!*nowp)
581
862
      *nowp = time(NULL);
582
13.2k
    cap_expires(*nowp, co);
583
13.2k
  }
584
13.5k
}
585
586
/* this function returns errors on OOM etc, not for cookie format problems */
587
static CURLcode
588
parse_cookie_header(struct Curl_easy *data,
589
                    struct Cookie *co,
590
                    const struct CookieInfo *ci,
591
                    bool *okay, /* if the cookie was fine */
592
                    const char *ptr, /* the header */
593
                    const char *domain, /* default domain */
594
                    /* full path used when this cookie is set */
595
                    const char *path,
596
                    bool secure_origin)
597
1.09k
{
598
  /* This line was read off an HTTP-header */
599
1.09k
  time_t now = 0;
600
1.09k
  size_t linelength = strlen(ptr);
601
1.09k
  CURLcode result = CURLE_OK;
602
1.09k
  struct Curl_str cookie[COOKIE_PIECES];
603
1.09k
  *okay = FALSE;
604
1.09k
  if(linelength > MAX_COOKIE_LINE)
605
    /* discard overly long lines at once */
606
1
    return CURLE_OK;
607
608
  /* memset instead of initializer because gcc 4.8.1 is silly */
609
1.09k
  memset(cookie, 0, sizeof(cookie));
610
24.2k
  do {
611
24.2k
    struct Curl_str name;
612
613
    /* we have a <name>=<value> pair or a stand-alone word here */
614
24.2k
    if(!curlx_str_cspn(&ptr, &name, ";\r\n=")) {
615
22.8k
      struct Curl_str val;
616
22.8k
      bool sep = FALSE;
617
22.8k
      curlx_str_trimblanks(&name);
618
619
22.8k
      if(invalid_octets(curlx_str(&name), curlx_strlen(&name))) {
620
19
        infof(data, "invalid octets in name, cookie dropped");
621
19
        return CURLE_OK;
622
19
      }
623
624
22.7k
      if(!curlx_str_single(&ptr, '=')) {
625
18.3k
        sep = TRUE; /* a '=' was used */
626
18.3k
        if(!curlx_str_cspn(&ptr, &val, ";\r\n"))
627
15.9k
          curlx_str_trimblanks(&val);
628
629
18.3k
        if(invalid_octets(curlx_str(&val), curlx_strlen(&val))) {
630
7
          infof(data, "invalid octets in value, cookie dropped");
631
7
          return CURLE_OK;
632
7
        }
633
18.3k
      }
634
4.42k
      else
635
4.42k
        curlx_str_init(&val);
636
637
22.7k
      if(!curlx_strlen(&cookie[COOKIE_NAME])) {
638
1.08k
        if(!parse_first_pair(data, co, cookie, &name, &val, sep))
639
30
          return CURLE_OK;
640
1.08k
      }
641
21.6k
      else if(!sep) {
642
4.39k
        if(!parse_flag(data, co, ci, &name, secure_origin))
643
0
          return CURLE_OK;
644
4.39k
      }
645
17.3k
      else if(curlx_str_casecompare(&name, "path"))
646
217
        cookie[COOKIE_PATH] = val;
647
17.0k
      else if(curlx_str_casecompare(&name, "domain") && curlx_strlen(&val)) {
648
0
        if(!parse_domain(data, co, &cookie[COOKIE_DOMAIN], &val, &domain))
649
0
          return CURLE_OK;
650
0
      }
651
17.0k
      else if(curlx_str_casecompare(&name, "max-age") && curlx_strlen(&val))
652
0
        parse_maxage(co, &val, &now);
653
17.0k
      else if(curlx_str_casecompare(&name, "expires") && curlx_strlen(&val))
654
13.5k
        parse_expires(co, &val, &now);
655
22.7k
    }
656
24.2k
  } while(!curlx_str_single(&ptr, ';'));
657
658
1.04k
  if(curlx_strlen(&cookie[COOKIE_NAME])) {
659
    /* the header was fine, now store the data */
660
1.03k
    result = storecookie(co, &cookie[0], path, domain);
661
1.03k
    if(!result)
662
1.03k
      *okay = TRUE;
663
1.03k
  }
664
1.04k
  return result;
665
1.09k
}
666
667
static CURLcode parse_netscape(struct Cookie *co,
668
                               const struct CookieInfo *ci,
669
                               bool *okay,
670
                               const char *lineptr,
671
                               bool secure_origin)
672
10.6k
{
673
  /*
674
   * This line is NOT an HTTP header style line, we do offer support for
675
   * reading the odd netscape cookies-file format here
676
   */
677
10.6k
  const char *ptr, *next;
678
10.6k
  int fields;
679
10.6k
  size_t len;
680
10.6k
  *okay = FALSE;
681
682
  /*
683
   * In 2008, Internet Explorer introduced HTTP-only cookies to prevent XSS
684
   * attacks. Cookies marked httpOnly are not accessible to JavaScript. In
685
   * Firefox's cookie files, they are prefixed #HttpOnly_ and the rest
686
   * remains as usual, so we skip 10 characters of the line.
687
   */
688
10.6k
  if(!strncmp(lineptr, "#HttpOnly_", 10)) {
689
1
    lineptr += 10;
690
1
    co->httponly = TRUE;
691
1
  }
692
693
10.6k
  if(lineptr[0] == '#')
694
    /* do not even try the comments */
695
83
    return CURLE_OK;
696
697
  /*
698
   * Now loop through the fields and init the struct we already have
699
   * allocated
700
   */
701
10.5k
  fields = 0;
702
23.4k
  for(next = lineptr; next; fields++) {
703
12.9k
    ptr = next;
704
12.9k
    len = strcspn(ptr, "\t\r\n");
705
12.9k
    next = (ptr[len] == '\t' ? &ptr[len + 1] : NULL);
706
12.9k
    switch(fields) {
707
10.5k
    case 0:
708
10.5k
      if(ptr[0] == '.') { /* skip preceding dots */
709
4
        ptr++;
710
4
        len--;
711
4
      }
712
10.5k
      co->domain = curlx_memdup0(ptr, len);
713
10.5k
      if(!co->domain)
714
0
        return CURLE_OUT_OF_MEMORY;
715
10.5k
      break;
716
10.5k
    case 1:
717
      /*
718
       * flag: A TRUE/FALSE value indicating if all machines within a given
719
       * domain can access the variable. Set TRUE when the cookie says
720
       * .example.com and to false when the domain is complete www.example.com
721
       */
722
559
      co->tailmatch = !!curl_strnequal(ptr, "TRUE", len);
723
559
      break;
724
549
    case 2:
725
      /* The file format allows the path field to remain not filled in */
726
549
      if(strncmp("TRUE", ptr, len) && strncmp("FALSE", ptr, len)) {
727
        /* only if the path does not look like a boolean option! */
728
84
        co->path = sanitize_cookie_path(ptr, len);
729
84
        if(!co->path)
730
0
          return CURLE_OUT_OF_MEMORY;
731
84
        break;
732
84
      }
733
465
      else {
734
        /* this does not look like a path, make one up! */
735
465
        co->path = curlx_strdup("/");
736
465
        if(!co->path)
737
0
          return CURLE_OUT_OF_MEMORY;
738
465
      }
739
465
      fields++; /* add a field and fall down to secure */
740
465
      FALLTHROUGH();
741
476
    case 3:
742
476
      co->secure = FALSE;
743
476
      if(curl_strnequal(ptr, "TRUE", len)) {
744
462
        if(secure_origin || ci->running)
745
462
          co->secure = TRUE;
746
0
        else
747
0
          return CURLE_OK;
748
462
      }
749
476
      break;
750
476
    case 4:
751
468
      if(curlx_str_number(&ptr, &co->expires, CURL_OFF_T_MAX))
752
42
        return CURLE_OK;
753
426
      break;
754
426
    case 5:
755
420
      co->name = curlx_memdup0(ptr, len);
756
420
      if(!co->name)
757
0
        return CURLE_OUT_OF_MEMORY;
758
420
      else {
759
        /* For Netscape file format cookies we check prefix on the name.
760
           These prefixes are matched case sensitively, same as on the
761
           header path and as the 6265bis document specifies. */
762
420
        if(!strncmp("__Secure-", co->name, 9))
763
2
          co->prefix_secure = TRUE;
764
418
        else if(!strncmp("__Host-", co->name, 7))
765
4
          co->prefix_host = TRUE;
766
420
      }
767
420
      break;
768
420
    case 6:
769
35
      co->value = curlx_memdup0(ptr, len);
770
35
      if(!co->value)
771
0
        return CURLE_OUT_OF_MEMORY;
772
35
      break;
773
12.9k
    }
774
12.9k
  }
775
10.5k
  if(fields == 6) {
776
    /* we got a cookie with blank contents, fix it */
777
385
    co->value = curlx_strdup("");
778
385
    if(!co->value)
779
0
      return CURLE_OUT_OF_MEMORY;
780
385
    else
781
385
      fields++;
782
385
  }
783
784
10.5k
  if(fields != 7)
785
    /* we did not find the sufficient number of fields */
786
10.0k
    return CURLE_OK;
787
788
  /* Reject control octets in the name or value, matching the filtering done
789
     for cookies set over HTTP. A cookie loaded from a file is later sent in
790
     request headers, so the same bytes that make a server reject a request
791
     must not slip in through the file. */
792
408
  if(invalid_octets(co->name, strlen(co->name)) ||
793
395
     invalid_octets(co->value, strlen(co->value)))
794
17
    return CURLE_OK;
795
796
391
  *okay = TRUE;
797
391
  return CURLE_OK;
798
408
}
799
800
static bool is_public_suffix(struct Curl_easy *data,
801
                             struct Cookie *co,
802
                             const char *domain)
803
0
{
804
#ifdef USE_LIBPSL
805
  /*
806
   * Check if the domain is a Public Suffix and if yes, ignore the cookie.
807
   * 'domain' is NULL when the cookie is loaded from file or
808
   * CURLOPT_COOKIELIST.
809
   */
810
  DEBUGASSERT(data);
811
  DEBUGASSERT(co);
812
  DEBUGF(infof(data, "PSL check set-cookie '%s' for domain=%s in %s",
813
               co->name, co->domain ? co->domain : "[blank]",
814
               domain ? domain : "[file]"));
815
  if(!co->domain || Curl_host_is_ipnum(co->domain))
816
    return FALSE;
817
818
  else {
819
    bool acceptable = FALSE;
820
    char lcase[256];
821
    char lcookie[256];
822
    size_t dlen = domain ? strlen(domain) : 0;
823
    size_t clen = strlen(co->domain);
824
825
    /* trim trailing dots */
826
    if(dlen && (domain[dlen - 1] == '.'))
827
      dlen--;
828
    if(clen && (co->domain[clen - 1] == '.'))
829
      clen--;
830
831
    if((dlen < sizeof(lcase)) && (clen < sizeof(lcookie))) {
832
      const psl_ctx_t *psl = Curl_psl_use(data);
833
      if(psl) {
834
        /* the PSL check requires lowercase domain name and pattern */
835
        Curl_strntolower(lcookie, co->domain, clen);
836
        lcookie[clen] = 0;
837
        if(domain) {
838
          Curl_strntolower(lcase, domain, dlen);
839
          lcase[dlen] = 0;
840
          acceptable = psl_is_cookie_domain_acceptable(psl, lcase, lcookie);
841
842
          /* if the cookie is acceptable, but is set for a PSL domain, then it
843
             cannot be tailmatching */
844
          if(acceptable && co->tailmatch &&
845
             curl_strequal(co->domain, domain) &&
846
             psl_is_public_suffix(psl, lcookie))
847
            co->tailmatch = FALSE;
848
        }
849
        else {
850
          /* libpsl says localhost is a PSL, we think not */
851
          acceptable =
852
            curl_strequal(lcookie, "localhost") ||
853
            /* note that this PSL function returns the opposite value than
854
               psl_is_cookie_domain_acceptable() does */
855
            !psl_is_public_suffix(psl, lcookie);
856
        }
857
        Curl_psl_release(data);
858
      }
859
      else
860
        infof(data, "libpsl problem, rejecting cookie for safety");
861
    }
862
863
    if(!acceptable) {
864
      infof(data, "cookie '%s' dropped, domain '%s' must not "
865
            "set cookies for '%s'", co->name,
866
            domain ? domain : "[file]", co->domain);
867
      return TRUE;
868
    }
869
  }
870
#else
871
0
  (void)data;
872
0
  (void)co;
873
0
  (void)domain;
874
0
  DEBUGF(infof(data, "NO PSL to check set-cookie '%s' for domain=%s in %s",
875
0
               co->name, co->domain, domain ? domain : "[file]"));
876
0
#endif
877
0
  return FALSE;
878
0
}
879
880
/* returns TRUE when replaced */
881
static bool replace_existing(struct Curl_easy *data,
882
                             struct Cookie *co,
883
                             const struct CookieInfo *ci,
884
                             bool secure,
885
                             bool *replacep)
886
1.41k
{
887
1.41k
  bool replace_old = FALSE;
888
1.41k
  struct Curl_llist_node *replace_n = NULL;
889
1.41k
  struct Curl_llist_node *n;
890
1.41k
  size_t myhash = cookiehash(co->domain);
891
1.41k
  for(n = Curl_llist_head(&ci->cookielist[myhash]); n; n = Curl_node_next(n)) {
892
0
    struct Cookie *clist = Curl_node_elem(n);
893
0
    if(!strcmp(clist->name, co->name)) {
894
      /* the names are identical */
895
0
      bool matching_domains = FALSE;
896
897
0
      if(clist->domain && co->domain) {
898
0
        if(cookie_tailmatch(clist->domain, strlen(clist->domain),
899
0
                            co->domain) ||
900
0
           cookie_tailmatch(co->domain, strlen(co->domain), clist->domain))
901
          /* The existing one is a tail of the new or vice versa */
902
0
          matching_domains = TRUE;
903
0
      }
904
0
      else if(!clist->domain && !co->domain)
905
0
        matching_domains = TRUE;
906
907
0
      if(matching_domains && /* the domains were identical */
908
0
         clist->path && co->path && /* both have paths */
909
0
         clist->secure && !co->secure && !secure) {
910
0
        size_t cllen;
911
0
        const char *sep = NULL;
912
913
        /*
914
         * A non-secure cookie may not overlay an existing secure cookie.
915
         * For an existing cookie "a" with path "/login", refuse a new
916
         * cookie "a" with for example path "/login/en", while the path
917
         * "/loginhelper" is ok.
918
         */
919
920
0
        DEBUGASSERT(clist->path[0]);
921
0
        if(clist->path[0])
922
0
          sep = strchr(clist->path + 1, '/');
923
0
        if(sep)
924
0
          cllen = sep - clist->path;
925
0
        else
926
0
          cllen = strlen(clist->path);
927
928
0
        if(!strncmp(clist->path, co->path, cllen)) {
929
0
          infof(data, "cookie '%s' for domain '%s' dropped, would "
930
0
                "overlay an existing cookie", co->name, co->domain);
931
0
          return FALSE;
932
0
        }
933
0
      }
934
0
    }
935
936
0
    if(!replace_n && !strcmp(clist->name, co->name)) {
937
      /* the names are identical */
938
939
0
      if(clist->domain && co->domain) {
940
0
        if(curl_strequal(clist->domain, co->domain) &&
941
0
           (clist->tailmatch == co->tailmatch))
942
          /* The domains are identical */
943
0
          replace_old = TRUE;
944
0
      }
945
0
      else if(!clist->domain && !co->domain)
946
0
        replace_old = TRUE;
947
948
0
      if(replace_old) {
949
        /* the domains were identical */
950
951
0
        if(clist->path && co->path &&
952
0
           strcmp(clist->path, co->path))
953
0
          replace_old = FALSE;
954
0
        else if(!clist->path != !co->path)
955
0
          replace_old = FALSE;
956
0
      }
957
958
0
      if(replace_old && !co->livecookie && clist->livecookie) {
959
        /*
960
         * Both cookies matched fine, except that the already present cookie
961
         * is "live", which means it was set from a header, while the new one
962
         * was read from a file and thus is not "live". "live" cookies are
963
         * preferred so the new cookie is freed.
964
         */
965
0
        return FALSE;
966
0
      }
967
0
      if(replace_old)
968
0
        replace_n = n;
969
0
    }
970
0
  }
971
1.41k
  if(replace_n) {
972
0
    struct Cookie *repl = Curl_node_elem(replace_n);
973
974
    /* when replacing, creationtime is kept from old */
975
0
    co->creationtime = repl->creationtime;
976
977
    /* unlink the old */
978
0
    Curl_node_remove(replace_n);
979
980
    /* free the old cookie */
981
0
    freecookie(repl, TRUE);
982
0
  }
983
1.41k
  *replacep = replace_old;
984
1.41k
  return TRUE;
985
1.41k
}
986
987
/*
988
 * Curl_cookie_add
989
 *
990
 * Add a single cookie line to the cookie keeping object. Be aware that
991
 * sometimes we get an IP-only hostname, and that might also be a numerical
992
 * IPv6 address.
993
 *
994
 */
995
CURLcode Curl_cookie_add(struct Curl_easy *data,
996
                         struct CookieInfo *ci,
997
                         const char *lineptr, /* first character of the line */
998
                         const char *domain,  /* default domain */
999
                         const char *path,    /* full path used when this
1000
                                                 cookie is set, used to get
1001
                                                 default path for the cookie
1002
                                                 unless set */
1003
                         const int flags)
1004
11.7k
{
1005
11.7k
  struct Cookie comem;
1006
11.7k
  struct Cookie *co;
1007
11.7k
  size_t myhash;
1008
11.7k
  CURLcode result;
1009
11.7k
  bool replaces = FALSE;
1010
11.7k
  bool okay;
1011
1012
11.7k
  DEBUGASSERT(data);
1013
11.7k
  DEBUGASSERT(MAX_SET_COOKIE_AMOUNT <= 255); /* counter is an unsigned char */
1014
11.7k
  if(data->req.setcookies >= MAX_SET_COOKIE_AMOUNT)
1015
0
    return CURLE_OK; /* silently ignore */
1016
1017
11.7k
  co = &comem;
1018
11.7k
  memset(co, 0, sizeof(comem));
1019
1020
11.7k
  if(flags & COOKIE_HTTPHEADER)
1021
1.09k
    result = parse_cookie_header(data, co, ci, &okay,
1022
1.09k
                                 lineptr, domain, path, flags & COOKIE_SECURE);
1023
10.6k
  else
1024
10.6k
    result = parse_netscape(co, ci, &okay, lineptr, flags & COOKIE_SECURE);
1025
1026
11.7k
  if(result || !okay)
1027
10.3k
    goto fail;
1028
1029
1.42k
  if(co->prefix_secure && !co->secure)
1030
    /* The __Secure- prefix only requires that the cookie be set secure */
1031
4
    goto fail;
1032
1033
1.42k
  if(!(flags & COOKIE_NOPSL) && is_public_suffix(data, co, domain))
1034
0
    goto fail;
1035
1036
1.42k
  if(co->prefix_host) {
1037
    /*
1038
     * The __Host- prefix requires the cookie to be secure, have a "/" path
1039
     * and not have a domain set.
1040
     */
1041
9
    if(co->secure && co->path && !strcmp(co->path, "/") && !co->tailmatch)
1042
1
      ;
1043
8
    else
1044
8
      goto fail;
1045
9
  }
1046
1047
1.41k
  if(!ci->running &&    /* read from a file */
1048
1.41k
     ci->newsession &&  /* clean session cookies */
1049
0
     !co->expires)      /* this is a session cookie */
1050
0
    goto fail;
1051
1052
1.41k
  co->livecookie = ci->running;
1053
1.41k
  co->creationtime = ++ci->lastct;
1054
1055
1.41k
  if(!(flags & COOKIE_NOEXPIRE))
1056
1.41k
    remove_expired(ci);
1057
1058
  /*
1059
   * Now we have parsed the incoming line, we must now check if this supersedes
1060
   * an already existing cookie, which it may if the previous have the same
1061
   * domain and path as this.
1062
   */
1063
1.41k
  if(!replace_existing(data, co, ci, flags & COOKIE_SECURE, &replaces))
1064
0
    goto fail;
1065
1066
  /* clone the stack struct into heap */
1067
1.41k
  co = curlx_memdup(&comem, sizeof(comem));
1068
1.41k
  if(!co) {
1069
0
    co = &comem;
1070
0
    result = CURLE_OUT_OF_MEMORY;
1071
0
    goto fail; /* bail out if we are this low on memory */
1072
0
  }
1073
1074
  /* add this cookie to the list */
1075
1.41k
  myhash = cookiehash(co->domain);
1076
1.41k
  Curl_llist_append(&ci->cookielist[myhash], co, &co->node);
1077
1078
1.41k
  if(ci->running)
1079
    /* Only show this when NOT reading the cookies from a file */
1080
0
    infof(data, "%s cookie %s=\"%s\" for domain %s, path %s, "
1081
1.41k
          "expire %" FMT_OFF_T,
1082
1.41k
          replaces ? "Replaced" : "Added", co->name, co->value,
1083
1.41k
          co->domain, co->path, co->expires);
1084
1085
1.41k
  if(!replaces)
1086
1.41k
    ci->numcookies++; /* one more cookie in the jar */
1087
1088
  /*
1089
   * Now that we have added a new cookie to the jar, update the expiration
1090
   * tracker in case it is the next one to expire.
1091
   */
1092
1.41k
  if(co->expires && (co->expires < ci->next_expiration))
1093
532
    ci->next_expiration = co->expires;
1094
1095
1.41k
  if(flags & COOKIE_HTTPHEADER)
1096
1.02k
    data->req.setcookies++;
1097
1098
1.41k
  return result;
1099
10.3k
fail:
1100
10.3k
  freecookie(co, FALSE);
1101
10.3k
  return result;
1102
1.41k
}
1103
1104
/*
1105
 * Curl_cookie_init()
1106
 *
1107
 * Inits a cookie struct to read data from a local file. This is always
1108
 * called before any cookies are set. File may be NULL in which case only the
1109
 * struct is initialized. Is file is "-" then STDIN is read.
1110
 *
1111
 * If 'newsession' is TRUE, discard all "session cookies" on read from file.
1112
 *
1113
 * Note that 'data' might be called as NULL pointer. If data is NULL, 'file'
1114
 * will be ignored.
1115
 *
1116
 * Returns NULL on out of memory.
1117
 */
1118
struct CookieInfo *Curl_cookie_init(void)
1119
13.0k
{
1120
13.0k
  int i;
1121
13.0k
  struct CookieInfo *ci = curlx_calloc(1, sizeof(struct CookieInfo));
1122
13.0k
  if(!ci)
1123
0
    return NULL;
1124
1125
  /* This does not use the destructor callback since we want to add
1126
     and remove to lists while keeping the cookie struct intact */
1127
833k
  for(i = 0; i < COOKIE_HASH_SIZE; i++)
1128
820k
    Curl_llist_init(&ci->cookielist[i], NULL);
1129
  /*
1130
   * Initialize the next_expiration time to signal that we do not have enough
1131
   * information yet.
1132
   */
1133
13.0k
  ci->next_expiration = CURL_OFF_T_MAX;
1134
1135
13.0k
  return ci;
1136
13.0k
}
1137
1138
/*
1139
 * cookie_load()
1140
 *
1141
 * Reads cookies from a local file. This is always called before any cookies
1142
 * are set. If file is "-" then STDIN is read.
1143
 *
1144
 * If 'flags' has the COOKIE_NOSESSION bit set, discard all "session cookies"
1145
 * read from file.
1146
 */
1147
static CURLcode cookie_load(struct Curl_easy *data, const char *file,
1148
                            struct CookieInfo *ci, int flags)
1149
9.94k
{
1150
9.94k
  FILE *handle = NULL;
1151
9.94k
  CURLcode result = CURLE_OK;
1152
9.94k
  FILE *fp = NULL;
1153
9.94k
  DEBUGASSERT(ci);
1154
9.94k
  DEBUGASSERT(data);
1155
9.94k
  DEBUGASSERT(file);
1156
1157
9.94k
  ci->newsession = !!(flags & COOKIE_NOSESSION); /* new session? */
1158
9.94k
  ci->running = FALSE; /* this is not running, this is init */
1159
1160
9.94k
  if(file && *file) {
1161
9.94k
    if(!strcmp(file, "-"))
1162
0
      fp = stdin;
1163
9.94k
    else {
1164
9.94k
      fp = curlx_fopen(file, "rb");
1165
9.94k
      if(!fp)
1166
0
        infof(data, "WARNING: failed to open cookie file \"%s\"", file);
1167
9.94k
      else {
1168
9.94k
        curlx_struct_stat stat;
1169
9.94k
        if((curlx_fstat(fileno(fp), &stat) != -1) && S_ISDIR(stat.st_mode)) {
1170
0
          curlx_fclose(fp);
1171
0
          fp = NULL;
1172
0
          infof(data, "WARNING: cookie filename points to a directory: \"%s\"",
1173
0
                file);
1174
0
        }
1175
9.94k
        else
1176
9.94k
          handle = fp;
1177
9.94k
      }
1178
9.94k
    }
1179
9.94k
  }
1180
1181
9.94k
  if(fp) {
1182
9.94k
    struct dynbuf buf;
1183
9.94k
    bool eof = FALSE;
1184
9.94k
    curlx_dyn_init(&buf, MAX_COOKIE_LINE);
1185
9.94k
    do {
1186
9.94k
      result = Curl_get_line(&buf, fp, &eof);
1187
9.94k
      if(!result) {
1188
9.94k
        const char *lineptr = curlx_dyn_ptr(&buf);
1189
9.94k
        bool headerline = FALSE;
1190
9.94k
        if(checkprefix("Set-Cookie:", lineptr)) {
1191
          /* This is a cookie line, get it! */
1192
0
          lineptr += 11;
1193
0
          headerline = TRUE;
1194
0
          curlx_str_passblanks(&lineptr);
1195
0
        }
1196
1197
9.94k
        result = Curl_cookie_add(data, ci, lineptr, NULL, NULL,
1198
9.94k
                                 (headerline ? COOKIE_HTTPHEADER : 0) |
1199
9.94k
                                 COOKIE_NOEXPIRE | COOKIE_SECURE |
1200
9.94k
                                 (flags & COOKIE_NOPSL));
1201
        /* Ignore individual cookie problems unless we ran out of memory */
1202
9.94k
        if(result != CURLE_OUT_OF_MEMORY)
1203
9.94k
          result = CURLE_OK;
1204
9.94k
      }
1205
9.94k
    } while(!result && !eof);
1206
9.94k
    curlx_dyn_free(&buf); /* free the line buffer */
1207
1208
    /*
1209
     * Remove expired cookies from the hash. We must make sure to run this
1210
     * after reading the file, and not on every cookie.
1211
     */
1212
9.94k
    remove_expired(ci);
1213
1214
9.94k
    if(handle)
1215
9.94k
      curlx_fclose(handle);
1216
9.94k
  }
1217
9.94k
  data->state.cookie_engine = TRUE;
1218
9.94k
  ci->running = TRUE; /* now, we are running */
1219
1220
9.94k
  return result;
1221
9.94k
}
1222
1223
/*
1224
 * Load cookies from all given cookie files (CURLOPT_COOKIEFILE).
1225
 */
1226
CURLcode Curl_cookie_loadfiles(struct Curl_easy *data,
1227
                               int flags)
1228
9.94k
{
1229
9.94k
  CURLcode result = CURLE_OK;
1230
9.94k
  struct curl_slist *list = data->state.cookielist;
1231
9.94k
  if(list) {
1232
9.94k
    Curl_share_lock(data, CURL_LOCK_DATA_COOKIE, CURL_LOCK_ACCESS_SINGLE);
1233
9.94k
    if(!data->cookies)
1234
0
      data->cookies = Curl_cookie_init();
1235
9.94k
    if(!data->cookies)
1236
0
      result = CURLE_OUT_OF_MEMORY;
1237
9.94k
    else {
1238
9.94k
      data->state.cookie_engine = TRUE;
1239
19.8k
      while(list) {
1240
9.94k
        result = cookie_load(data, list->data, data->cookies, flags);
1241
9.94k
        if(result)
1242
0
          break;
1243
9.94k
        list = list->next;
1244
9.94k
      }
1245
9.94k
    }
1246
9.94k
    Curl_share_unlock(data, CURL_LOCK_DATA_COOKIE);
1247
9.94k
  }
1248
9.94k
  return result;
1249
9.94k
}
1250
1251
/*
1252
 * cookie_sort
1253
 *
1254
 * Helper function to sort cookies such that the longest path gets before the
1255
 * shorter path. Path, domain and name lengths are considered in that order,
1256
 * with the creationtime as the tiebreaker. The creationtime is guaranteed to
1257
 * be unique per cookie, so we know we will get an ordering at that point.
1258
 */
1259
static int cookie_sort(const void *p1, const void *p2)
1260
0
{
1261
0
  const struct Cookie *c1 = *(const struct Cookie * const *)p1;
1262
0
  const struct Cookie *c2 = *(const struct Cookie * const *)p2;
1263
0
  size_t l1, l2;
1264
1265
  /* 1 - compare cookie path lengths */
1266
0
  l1 = c1->path ? strlen(c1->path) : 0;
1267
0
  l2 = c2->path ? strlen(c2->path) : 0;
1268
1269
0
  if(l1 != l2)
1270
0
    return (l2 > l1) ? 1 : -1; /* avoid size_t <=> int conversions */
1271
1272
  /* 2 - compare cookie domain lengths */
1273
0
  l1 = c1->domain ? strlen(c1->domain) : 0;
1274
0
  l2 = c2->domain ? strlen(c2->domain) : 0;
1275
1276
0
  if(l1 != l2)
1277
0
    return (l2 > l1) ? 1 : -1; /* avoid size_t <=> int conversions */
1278
1279
  /* 3 - compare cookie name lengths */
1280
0
  l1 = c1->name ? strlen(c1->name) : 0;
1281
0
  l2 = c2->name ? strlen(c2->name) : 0;
1282
1283
0
  if(l1 != l2)
1284
0
    return (l2 > l1) ? 1 : -1;
1285
1286
  /* 4 - compare cookie creation time */
1287
0
  return (c2->creationtime > c1->creationtime) ? 1 : -1;
1288
0
}
1289
1290
/*
1291
 * cookie_sort_ct
1292
 *
1293
 * Helper function to sort cookies according to creation time.
1294
 */
1295
static int cookie_sort_ct(const void *p1, const void *p2)
1296
0
{
1297
0
  const struct Cookie *c1 = *(const struct Cookie * const *)p1;
1298
0
  const struct Cookie *c2 = *(const struct Cookie * const *)p2;
1299
1300
0
  return (c2->creationtime > c1->creationtime) ? 1 : -1;
1301
0
}
1302
1303
bool Curl_secure_context(struct Curl_easy *data, const char *host)
1304
0
{
1305
0
  return Curl_xfer_is_secure(data) ||
1306
0
    curl_strequal("localhost", host) ||
1307
0
    !strcmp(host, "127.0.0.1") ||
1308
0
    !strcmp(host, "::1");
1309
0
}
1310
1311
/*
1312
 * Curl_cookie_getlist
1313
 *
1314
 * For a given host and path, return a linked list of cookies that the client
1315
 * should send to the server if used now.
1316
 *
1317
 * It shall only return cookies that have not expired.
1318
 *
1319
 * 'okay' is TRUE when there is a list returned.
1320
 */
1321
CURLcode Curl_cookie_getlist(struct Curl_easy *data,
1322
                             bool *okay,
1323
                             const char *host,
1324
                             struct Curl_llist *list)
1325
0
{
1326
0
  size_t matches = 0;
1327
0
  const bool is_ip = Curl_host_is_ipnum(host);
1328
0
  const size_t myhash = cookiehash(host);
1329
0
  struct Curl_llist_node *n;
1330
0
  const bool secure = Curl_secure_context(data, host);
1331
0
  struct CookieInfo *ci = data->cookies;
1332
0
  const char *path = data->state.up.path;
1333
0
  CURLcode result = CURLE_OK;
1334
0
  *okay = FALSE;
1335
1336
0
  Curl_llist_init(list, NULL);
1337
1338
0
  if(!ci || !Curl_llist_count(&ci->cookielist[myhash]))
1339
0
    return CURLE_OK; /* no cookie struct or no cookies in the struct */
1340
1341
  /* at first, remove expired cookies */
1342
0
  remove_expired(ci);
1343
1344
0
  for(n = Curl_llist_head(&ci->cookielist[myhash]); n; n = Curl_node_next(n)) {
1345
0
    struct Cookie *co = Curl_node_elem(n);
1346
1347
    /* if the cookie requires we are secure we must only continue if we are! */
1348
0
    if(co->secure ? secure : TRUE) {
1349
1350
      /* now check if the domain is correct */
1351
0
      if(!co->domain ||
1352
0
         (co->tailmatch && !is_ip &&
1353
0
          cookie_tailmatch(co->domain, strlen(co->domain), host)) ||
1354
0
         ((!co->tailmatch || is_ip) && curl_strequal(host, co->domain))) {
1355
        /*
1356
         * the right part of the host matches the domain stuff in the
1357
         * cookie data
1358
         */
1359
1360
        /*
1361
         * now check the left part of the path with the cookies path
1362
         * requirement
1363
         */
1364
0
        if(!co->path || pathmatch(co->path, path)) {
1365
1366
          /*
1367
           * This is a match and we add it to the return-linked-list
1368
           */
1369
0
          Curl_llist_append(list, co, &co->getnode);
1370
0
          matches++;
1371
0
          if(matches >= MAX_COOKIE_SEND_AMOUNT) {
1372
0
            infof(data, "Included max number of cookies (%zu) in request!",
1373
0
                  matches);
1374
0
            break;
1375
0
          }
1376
0
        }
1377
0
      }
1378
0
    }
1379
0
  }
1380
1381
0
  if(matches) {
1382
    /*
1383
     * Now we need to make sure that if there is a name appearing more than
1384
     * once, the longest specified path version comes first. To make this the
1385
     * swiftest way, we sort them all based on path length.
1386
     */
1387
0
    struct Cookie **array;
1388
0
    size_t i;
1389
1390
    /* alloc an array and store all cookie pointers */
1391
0
    array = curlx_malloc(sizeof(struct Cookie *) * matches);
1392
0
    if(!array) {
1393
0
      result = CURLE_OUT_OF_MEMORY;
1394
0
      goto fail;
1395
0
    }
1396
1397
0
    n = Curl_llist_head(list);
1398
1399
0
    for(i = 0; n; n = Curl_node_next(n))
1400
0
      array[i++] = Curl_node_elem(n);
1401
1402
    /* now sort the cookie pointers in path length order */
1403
0
    qsort(array, matches, sizeof(struct Cookie *), cookie_sort);
1404
1405
    /* remake the linked list order according to the new order */
1406
0
    Curl_llist_destroy(list, NULL);
1407
1408
0
    for(i = 0; i < matches; i++)
1409
0
      Curl_llist_append(list, array[i], &array[i]->getnode);
1410
1411
0
    curlx_free(array); /* remove the temporary data again */
1412
0
  }
1413
1414
0
  *okay = TRUE;
1415
0
  return CURLE_OK; /* success */
1416
1417
0
fail:
1418
  /* failure, clear up the allocated chain and return NULL */
1419
0
  Curl_llist_destroy(list, NULL);
1420
0
  return result; /* error */
1421
0
}
1422
1423
/*
1424
 * Curl_cookie_clearall
1425
 *
1426
 * Clear all existing cookies and reset the counter.
1427
 */
1428
void Curl_cookie_clearall(struct CookieInfo *ci)
1429
13.0k
{
1430
13.0k
  if(ci) {
1431
13.0k
    unsigned int i;
1432
833k
    for(i = 0; i < COOKIE_HASH_SIZE; i++) {
1433
820k
      struct Curl_llist_node *n;
1434
821k
      for(n = Curl_llist_head(&ci->cookielist[i]); n;) {
1435
1.28k
        struct Cookie *c = Curl_node_elem(n);
1436
1.28k
        struct Curl_llist_node *e = Curl_node_next(n);
1437
1.28k
        Curl_node_remove(n);
1438
1.28k
        freecookie(c, TRUE);
1439
1.28k
        n = e;
1440
1.28k
      }
1441
820k
    }
1442
13.0k
    ci->numcookies = 0;
1443
13.0k
  }
1444
13.0k
}
1445
1446
/*
1447
 * Curl_cookie_clearsess
1448
 *
1449
 * Free all session cookies in the cookies list.
1450
 */
1451
void Curl_cookie_clearsess(struct CookieInfo *ci)
1452
1
{
1453
1
  unsigned int i;
1454
1455
1
  if(!ci)
1456
1
    return;
1457
1458
0
  for(i = 0; i < COOKIE_HASH_SIZE; i++) {
1459
0
    struct Curl_llist_node *n = Curl_llist_head(&ci->cookielist[i]);
1460
0
    struct Curl_llist_node *e = NULL;
1461
1462
0
    for(; n; n = e) {
1463
0
      struct Cookie *curr = Curl_node_elem(n);
1464
0
      e = Curl_node_next(n); /* in case the node is removed, get it early */
1465
0
      if(!curr->expires) {
1466
0
        Curl_node_remove(n);
1467
0
        freecookie(curr, TRUE);
1468
0
        ci->numcookies--;
1469
0
      }
1470
0
    }
1471
0
  }
1472
0
}
1473
1474
/*
1475
 * Curl_cookie_cleanup()
1476
 *
1477
 * Free a "cookie object" previous created with Curl_cookie_init().
1478
 */
1479
void Curl_cookie_cleanup(struct CookieInfo *ci)
1480
13.0k
{
1481
13.0k
  if(ci) {
1482
13.0k
    Curl_cookie_clearall(ci);
1483
13.0k
    curlx_free(ci); /* free the base struct as well */
1484
13.0k
  }
1485
13.0k
}
1486
1487
/*
1488
 * get_netscape_format()
1489
 *
1490
 * Formats a string for Netscape output file, w/o a newline at the end.
1491
 * Function returns a char * to a formatted line. The caller is responsible
1492
 * for freeing the returned pointer.
1493
 */
1494
static char *get_netscape_format(const struct Cookie *co)
1495
138
{
1496
138
  return curl_maprintf(
1497
138
    "%s"               /* httponly preamble */
1498
138
    "%s%s\t"           /* domain */
1499
138
    "%s\t"             /* tailmatch */
1500
138
    "%s\t"             /* path */
1501
138
    "%s\t"             /* secure */
1502
138
    "%" FMT_OFF_T "\t" /* expires */
1503
138
    "%s\t"             /* name */
1504
138
    "%s",              /* value */
1505
138
    co->httponly ? "#HttpOnly_" : "",
1506
    /*
1507
     * Make sure all domains are prefixed with a dot if they allow
1508
     * tailmatching. This is Mozilla-style.
1509
     */
1510
138
    (co->tailmatch && co->domain && co->domain[0] != '.') ? "." : "",
1511
138
    co->domain ? co->domain : "unknown",
1512
138
    co->tailmatch ? "TRUE" : "FALSE",
1513
138
    co->path ? co->path : "/",
1514
138
    co->secure ? "TRUE" : "FALSE",
1515
138
    co->expires,
1516
138
    co->name,
1517
138
    co->value ? co->value : "");
1518
138
}
1519
1520
/*
1521
 * cookie_output()
1522
 *
1523
 * Writes all internally known cookies to the specified file. Specify
1524
 * "-" as filename to write to stdout.
1525
 *
1526
 * The function returns non-zero on write failure.
1527
 */
1528
static CURLcode cookie_output(struct Curl_easy *data,
1529
                              struct CookieInfo *ci,
1530
                              const char *filename)
1531
9.94k
{
1532
9.94k
  FILE *out = NULL;
1533
9.94k
  bool use_stdout = FALSE;
1534
9.94k
  char *tempstore = NULL;
1535
9.94k
  CURLcode result = CURLE_OK;
1536
1537
9.94k
  if(!ci)
1538
    /* no cookie engine alive */
1539
0
    return CURLE_OK;
1540
1541
  /* at first, remove expired cookies */
1542
9.94k
  remove_expired(ci);
1543
1544
9.94k
  if(!strcmp("-", filename)) {
1545
    /* use stdout */
1546
0
    out = stdout;
1547
0
    use_stdout = TRUE;
1548
0
  }
1549
9.94k
  else {
1550
9.94k
    result = Curl_fopen(data, filename, &out, &tempstore);
1551
9.94k
    if(result)
1552
0
      goto error;
1553
9.94k
  }
1554
1555
9.94k
  fputs("# Netscape HTTP Cookie File\n"
1556
9.94k
        "# https://curl.se/docs/http-cookies.html\n"
1557
9.94k
        "# This file was generated by libcurl! Edit at your own risk.\n\n",
1558
9.94k
        out);
1559
1560
9.94k
  if(ci->numcookies) {
1561
353
    unsigned int i;
1562
353
    size_t nvalid = 0;
1563
353
    struct Cookie **array;
1564
353
    struct Curl_llist_node *n;
1565
1566
353
    array = curlx_calloc(1, sizeof(struct Cookie *) * ci->numcookies);
1567
353
    if(!array) {
1568
0
      result = CURLE_OUT_OF_MEMORY;
1569
0
      goto error;
1570
0
    }
1571
1572
    /* only sort the cookies with a domain property */
1573
22.5k
    for(i = 0; i < COOKIE_HASH_SIZE; i++) {
1574
22.5k
      for(n = Curl_llist_head(&ci->cookielist[i]); n; n = Curl_node_next(n)) {
1575
353
        struct Cookie *co = Curl_node_elem(n);
1576
353
        if(!co->domain)
1577
215
          continue;
1578
138
        array[nvalid++] = co;
1579
138
      }
1580
22.2k
    }
1581
1582
353
    qsort(array, nvalid, sizeof(struct Cookie *), cookie_sort_ct);
1583
1584
491
    for(i = 0; i < nvalid; i++) {
1585
138
      char *format_ptr = get_netscape_format(array[i]);
1586
138
      if(!format_ptr) {
1587
0
        curlx_free(array);
1588
0
        result = CURLE_OUT_OF_MEMORY;
1589
0
        goto error;
1590
0
      }
1591
138
      curl_mfprintf(out, "%s\n", format_ptr);
1592
138
      curlx_free(format_ptr);
1593
138
    }
1594
1595
353
    curlx_free(array);
1596
353
  }
1597
1598
9.94k
  if(!use_stdout) {
1599
9.94k
    curlx_fclose(out);
1600
9.94k
    out = NULL;
1601
9.94k
    if(tempstore && curlx_rename(tempstore, filename)) {
1602
0
      result = CURLE_WRITE_ERROR;
1603
0
      goto error;
1604
0
    }
1605
9.94k
  }
1606
1607
  /*
1608
   * If we reach here we have successfully written a cookie file so there is
1609
   * no need to inspect the error, any error case should have jumped into the
1610
   * error block below.
1611
   */
1612
9.94k
  curlx_free(tempstore);
1613
9.94k
  return CURLE_OK;
1614
1615
0
error:
1616
0
  if(out && !use_stdout)
1617
0
    curlx_fclose(out);
1618
0
  if(tempstore) {
1619
0
    unlink(tempstore);
1620
0
    curlx_free(tempstore);
1621
0
  }
1622
0
  return result;
1623
9.94k
}
1624
1625
static struct curl_slist *cookie_list(const struct Curl_easy *data)
1626
0
{
1627
0
  struct curl_slist *list = NULL;
1628
0
  struct curl_slist *beg;
1629
0
  unsigned int i;
1630
0
  struct Curl_llist_node *n;
1631
1632
0
  if(!data->cookies || (data->cookies->numcookies == 0))
1633
0
    return NULL;
1634
1635
  /* at first, remove expired cookies */
1636
0
  remove_expired(data->cookies);
1637
1638
0
  for(i = 0; i < COOKIE_HASH_SIZE; i++) {
1639
0
    for(n = Curl_llist_head(&data->cookies->cookielist[i]); n;
1640
0
        n = Curl_node_next(n)) {
1641
0
      struct Cookie *c = Curl_node_elem(n);
1642
0
      char *line;
1643
0
      if(!c->domain)
1644
0
        continue;
1645
0
      line = get_netscape_format(c);
1646
0
      if(!line) {
1647
0
        curl_slist_free_all(list);
1648
0
        return NULL;
1649
0
      }
1650
0
      beg = Curl_slist_append_nodup(list, line);
1651
0
      if(!beg) {
1652
0
        curlx_free(line);
1653
0
        curl_slist_free_all(list);
1654
0
        return NULL;
1655
0
      }
1656
0
      list = beg;
1657
0
    }
1658
0
  }
1659
1660
0
  return list;
1661
0
}
1662
1663
struct curl_slist *Curl_cookie_list(struct Curl_easy *data)
1664
0
{
1665
0
  struct curl_slist *list;
1666
0
  Curl_share_lock(data, CURL_LOCK_DATA_COOKIE, CURL_LOCK_ACCESS_SINGLE);
1667
0
  list = cookie_list(data);
1668
0
  Curl_share_unlock(data, CURL_LOCK_DATA_COOKIE);
1669
0
  return list;
1670
0
}
1671
1672
void Curl_flush_cookies(struct Curl_easy *data, bool cleanup)
1673
27.7k
{
1674
27.7k
  Curl_share_lock(data, CURL_LOCK_DATA_COOKIE, CURL_LOCK_ACCESS_SINGLE);
1675
  /* only save the cookie file if a transfer was started (cookies->running is
1676
     set), as otherwise the cookies were not completely initialized and there
1677
     might be cookie files that were not loaded so saving the file is the
1678
     wrong thing. */
1679
27.7k
  if(data->cookies) {
1680
13.0k
    const char *cookiejar = CURL_EASY_STR(data, STRING_COOKIEJAR);
1681
13.0k
    if(cookiejar && data->cookies->running) {
1682
      /* if we have a destination file for all the cookies to get dumped to */
1683
9.94k
      CURLcode result = cookie_output(data, data->cookies, cookiejar);
1684
9.94k
      if(result)
1685
0
        infof(data, "WARNING: failed to save cookies in %s: %s",
1686
9.94k
              cookiejar, curl_easy_strerror(result));
1687
9.94k
    }
1688
1689
13.0k
    if(cleanup && (!data->share || (data->cookies != data->share->cookies))) {
1690
13.0k
      Curl_cookie_cleanup(data->cookies);
1691
13.0k
      data->cookies = NULL;
1692
13.0k
    }
1693
13.0k
  }
1694
27.7k
  Curl_share_unlock(data, CURL_LOCK_DATA_COOKIE);
1695
27.7k
}
1696
1697
void Curl_cookie_run(struct Curl_easy *data)
1698
9.94k
{
1699
9.94k
  Curl_share_lock(data, CURL_LOCK_DATA_COOKIE, CURL_LOCK_ACCESS_SINGLE);
1700
9.94k
  if(data->cookies)
1701
9.94k
    data->cookies->running = TRUE;
1702
9.94k
  Curl_share_unlock(data, CURL_LOCK_DATA_COOKIE);
1703
9.94k
}
1704
1705
#endif /* CURL_DISABLE_HTTP || CURL_DISABLE_COOKIES */