From c3580e3f1929eb52225dbf2fb4052909831d49ce Mon Sep 17 00:00:00 2001 From: Otavio Pontes Date: Thu, 27 Jun 2019 14:56:26 -0700 Subject: [PATCH] curl: Don't look at content_url and version_url on is_url_allowed() function Instead of using the globals content_url and version_url in is_url_allowed() we could use them in the function that calls it so is_url_allowed() is more generic. --- src/curl.c | 5 +++-- src/helpers.c | 14 +------------- 2 files changed, 4 insertions(+), 15 deletions(-) diff --git a/src/curl.c b/src/curl.c index 9d603603..8da1b0b7 100644 --- a/src/curl.c +++ b/src/curl.c @@ -200,8 +200,9 @@ int swupd_curl_init(void) return -1; } - /* enforce the use of https */ - if (!is_url_allowed(NULL)) { + /* enforce the use of https or file */ + if (!is_url_allowed(version_url) || + (strcmp(content_url, version_url) != 0 && !is_url_allowed(content_url))) { return -1; } diff --git a/src/helpers.c b/src/helpers.c index ba26a8c2..22dd0ed0 100644 --- a/src/helpers.c +++ b/src/helpers.c @@ -1018,19 +1018,7 @@ void print_regexp_error(int errcode, regex_t *regexp) bool is_url_allowed(char *url) { - bool insecure = false; - - if (url) { - if (strncmp(url, "http://", 7) == 0) { - insecure = true; - } - } else { - if (strncmp(version_url, "http://", 7) == 0 || strncmp(content_url, "http://", 7) == 0) { - insecure = true; - } - } - - if (insecure) { + if (strncmp(url, "http://", 7) == 0) { if (allow_insecure_http) { warn("This is an insecure connection\n"); info("The --allow-insecure-http flag was used, be aware that this poses a threat to the system\n\n");