Просмотр исходного кода

Tweaked check_signature() for GET variables.

Instead of unconditionally stripping ? variables when retrieving the keyId,
try first calling actor_request() directly, and only strip them and retry
if it fails.
grunfink 5 месяцев назад
Родитель
Сommit
083a3387fc
1 измененных файлов с 13 добавлено и 5 удалено
  1. 13 5
      http.c

+ 13 - 5
http.c

@@ -182,14 +182,22 @@ int check_signature(const xs_dict *req, xs_str **err)
     if ((p = strchr(keyId, '#')) != NULL)
         *p = '\0';
 
-    /* also strip cgi variables */
-    if ((p = strchr(keyId, '?')) != NULL)
-        *p = '\0';
-
     xs *actor = NULL;
     int status;
 
-    if (!valid_status((status = actor_request(NULL, keyId, &actor)))) {
+    /* does it have ? variables? */
+    if ((p = strchr(keyId, '?')) != NULL) {
+        /* try first with them */
+        if (!valid_status((status = actor_request(NULL, keyId, &actor)))) {
+            *p = '\0';
+            /* retry stripping them */
+            status = actor_request(NULL, keyId, &actor);
+        }
+    }
+    else
+        status = actor_request(NULL, keyId, &actor);
+
+    if (!valid_status(status)) {
         *err = xs_fmt("actor request error %s %d", keyId, status);
         return 0;
     }