Stefan uncovered a bug in mhttpd URI decoding, the following did not work:
cd midas, cd resources, cp example.html c++.html, open http://midas/example.html (works), open c++.html and it bombs with error about "c .html" (two pluses replaced by two spaces).
Stefan did a quick fix for this and I now finished the follow up.
here are the rules for encoding URLs for mhttpd: (using this example URL)
https://experiment.triumf.ca/vslice/?cmd=ODB&odb_path=foo
the query parameter value "foo" should be percent-encoded using encodeURIComponent(). this replaces spaces with %20, slashes with %2F and pluses with %2B, etc. a plain bare plus character "+" is permitted here, it will seen as a space by mhttpd (odb_path=A+B becomes "A B").
the query parameter name "odb_path" should also be percent-encoded, but standard mhttpd parameters only use ascii character for parameter names and it is okey to skip encodeURIComponent() and hardcode them. if custom parameter names use special characters or other funny characters, they should be percent-encoded.
the elements of the URL path "vslice" should be percent-encoded if they contain special URI characters like "?" and "&". internally mhttpd runs the URL path through decodeURIComponent(). this expands all percent-encoded characters. (plus and space characters are not changed, URLs like c++.html work).
one exception for percent-encoded URLs is the percent-encoded slash ("%2F" instead of "/"). for security reasons apache httpd and other web servers do not permit this. for consistency, mhttpd also rejects "%2F" in the URL path with the "404 Not Found" error.
TL&DR:
1) replaced old url-encode and decode functions with encodeURIComponent() and decodeURIComponent(). the mhttpd encoder is more aggressive compared to most javascript encoders (they leave characters like "_" and "(" unencoded). this is safe.
2) rewrote decode_query() to remove a strdup(), remove strtok() and manually parse the query string using bare URI query delimiters "&" and "=". malformed queries (mismatched "=" and "&") are silently truncated. in parameter values, plus is decoded as a space, decodeURIComponent() is consistently applied to parameter names and values.
3) added a trap in handle_http_message() against percent-encoded slash ("%2F" is rejected with "404 Not Found").
K.O. |