فهرست منبع

Fix error body leaks

activitypub_post_handler uses custom error responses for 400 and 403.
The 400 NULL check was reversed and 403 was missing the check in
httpd_connection and both errors were lost and leaked.

Add a common custom error gate around all default errors to avoid
similar issues in the future.
Santtu Lakkala 2 ماه پیش
والد
کامیت
4a5f9150d0
1فایلهای تغییر یافته به همراه10 افزوده شده و 8 حذف شده
  1. 10 8
      httpd.c

+ 10 - 8
httpd.c

@@ -600,17 +600,19 @@ void httpd_connection(FILE *f)
         status = HTTP_STATUS_NOT_FOUND;
     }
 
-    if (status == HTTP_STATUS_FORBIDDEN)
-        body = xs_str_new("<h1>403 Forbidden (" USER_AGENT ")</h1>");
+    if (body == NULL) {
+        if (status == HTTP_STATUS_FORBIDDEN)
+            body = xs_str_new("<h1>403 Forbidden (" USER_AGENT ")</h1>");
 
-    if (status == HTTP_STATUS_NOT_FOUND)
-        body = xs_str_new("<h1>404 Not Found (" USER_AGENT ")</h1>");
+        if (status == HTTP_STATUS_NOT_FOUND)
+            body = xs_str_new("<h1>404 Not Found (" USER_AGENT ")</h1>");
 
-    if (status == HTTP_STATUS_GONE)
-        body = xs_str_new("<h1>410 Gone (" USER_AGENT ")</h1>");
+        if (status == HTTP_STATUS_GONE)
+            body = xs_str_new("<h1>410 Gone (" USER_AGENT ")</h1>");
 
-    if (status == HTTP_STATUS_BAD_REQUEST && body != NULL)
-        body = xs_str_new("<h1>400 Bad Request (" USER_AGENT ")</h1>");
+        if (status == HTTP_STATUS_BAD_REQUEST)
+            body = xs_str_new("<h1>400 Bad Request (" USER_AGENT ")</h1>");
+    }
 
     if (status == HTTP_STATUS_SEE_OTHER)
         headers = xs_dict_append(headers, "location", body);