From 3a48b898ad161fe54dbf2723ded3cdac7c4e400b Mon Sep 17 00:00:00 2001 From: Roberto De Ioris Date: Sat, 27 Oct 2012 15:37:14 +0200 Subject: [PATCH] refactored router_access plugin --- plugins/router_access/router_access.c | 124 +++++++++++--------------- 1 file changed, 50 insertions(+), 74 deletions(-) diff --git a/plugins/router_access/router_access.c b/plugins/router_access/router_access.c index 2f380f0c..a228e8c6 100644 --- a/plugins/router_access/router_access.c +++ b/plugins/router_access/router_access.c @@ -1,91 +1,67 @@ -#include -#include -#include #include "../../uwsgi.h" +#include -extern struct uwsgi_server uwsgi; -int allow_severity = LOG_INFO; -int deny_severity = LOG_WARNING; +/* + + by Colin Ligertwood + + syntax: + + route = /^foobar access:action=hosts,daemon=uwsgi + route = /^foobar access:action=allow,daemon=uwsgi,addr=127.0.0.1 + route = /^foobar access:action=deny,daemon=uwsgi2,addr=192.168.* + route = /^foobar access:action=deny,daemon=uwsgi3,addr=192.168.0.0/24 + + TODO only the 'hosts' action is supported + +*/ + +struct uwsgi_router_access_conf { + char *action; + char *daemon; + char *addr; +}; int uwsgi_routing_func_access(struct wsgi_request *wsgi_req, struct uwsgi_route *ur){ + int pass = 0; - char *access_data = malloc(0xff); - char *access_action = malloc(0xff); - char *access_param = malloc(0xff); - char *access_addr = malloc(0xff); + struct uwsgi_router_access_conf *urac = (struct uwsgi_router_access_conf *) ur->data2; - bzero(access_data, 0xff); - bzero(access_action, 0xff); - bzero(access_param, 0xff); - bzero(access_addr, 0xff); - - if (uwsgi_parse_vars(wsgi_req)) { - return UWSGI_ROUTE_BREAK; + if (!urac) { + urac = uwsgi_calloc(sizeof(struct uwsgi_router_access_conf)); + if (uwsgi_kvlist_parse(ur->data, ur->data_len, ',', '=', + "action", &urac->action, + "daemon", &urac->daemon, + "addr", &urac->addr, NULL)) { + free(urac); + goto forbidden; + } + if (!urac->action) urac->action = "hosts"; + if (!urac->daemon) urac->action = "uwsgi"; + ur->data2 = urac; } -#ifdef UWSGI_DEBUG - uwsgi_log("Access: Parsing router: %s\n", ur->data); -#endif + char *addr = uwsgi_concat2n(wsgi_req->remote_addr, wsgi_req->remote_addr_len, "", 0); - strncpy(access_data, ur->data, 0xff); - - if (strchr(access_data, '=')){ - // parse router config: action=param - access_action = strtok(access_data, "="); - access_param = strtok(NULL, ""); - - if (!access_param){ - // config syntax error if no access_param - uwsgi_log("Access: syntax error - no paramater specified after action\n"); - return UWSGI_ROUTE_BREAK; - } - - } else { - // set default access_action, access_param if no colon found - access_action = "hosts"; - access_param = "uwsgi"; + if (!strcmp(urac->action, "hosts")){ + pass = hosts_ctl(urac->daemon, STRING_UNKNOWN, addr, STRING_UNKNOWN); + } + else if (!strcmp(urac->action, "allow") && urac->addr){ + // unimplemented + } + else if (!strcmp(urac->action, "deny") && urac->addr){ + // unimplemented } -#ifdef UWSGI_DEBUG - uwsgi_log("Access: access_action = %s, access_param = %s\n", access_action, access_param); -#endif + free(addr); - if (!strncmp(access_action, "hosts", 4)){ - // syntax access:hosts=svcname to use hosts.allow, hosts.deny with svcname as daemon name - access_addr = uwsgi_concat2n(wsgi_req->remote_addr, wsgi_req->remote_addr_len, "", 0); - pass = hosts_ctl(access_param, STRING_UNKNOWN, access_addr, STRING_UNKNOWN); - } else if (!strncmp(access_action, "allow", 4)){ - // implement hosts allow check on syntax access:allow=addr - } else if (!strncmp(access_action, "deny", 3)){ - // implement hosts deny check on syntax access:deny=addr - } - - free(access_data); + if (pass) return UWSGI_ROUTE_NEXT; - if (pass == 1){ +forbidden: -#ifdef UWSGI_DEBUG - uwsgi_log("Access: allowing access from %s\n", access_addr); -#endif - free(access_addr); - return UWSGI_ROUTE_NEXT; - } else if (pass == 0){ -#ifdef UWSGI_DEBUG - uwsgi_log("Access: denying access from %s\n", access_addr); -#endif - wsgi_req->status = 403; - wsgi_req->headers_size += wsgi_req->socket->proto_write_header(wsgi_req, "HTTP/1.0 403 Forbidden\r\nContent-Type: text/html\r\n\r\n", 51); - wsgi_req->response_size += wsgi_req->socket->proto_write(wsgi_req,"

403 Forbidden

", 23); - - free(access_addr); - return UWSGI_ROUTE_BREAK; - } - -#ifdef UWSGI_DEBUG - uwsgi_log("Access: Something went wrong: %d\n", pass); -#endif - - free(access_addr); + wsgi_req->status = 403; + wsgi_req->headers_size += wsgi_req->socket->proto_write_header(wsgi_req, "HTTP/1.0 403 Forbidden\r\nContent-Type: text/html\r\n\r\n", 51); + wsgi_req->response_size += wsgi_req->socket->proto_write(wsgi_req,"

403 Forbidden

", 23); return UWSGI_ROUTE_BREAK; }