xref: /aosp_15_r20/external/cronet/url/url_canon_query.cc (revision 6777b5387eb2ff775bb5750e3f5d96f37fb7352b)
1*6777b538SAndroid Build Coastguard Worker // Copyright 2013 The Chromium Authors
2*6777b538SAndroid Build Coastguard Worker // Use of this source code is governed by a BSD-style license that can be
3*6777b538SAndroid Build Coastguard Worker // found in the LICENSE file.
4*6777b538SAndroid Build Coastguard Worker 
5*6777b538SAndroid Build Coastguard Worker #include "url/url_canon.h"
6*6777b538SAndroid Build Coastguard Worker #include "url/url_canon_internal.h"
7*6777b538SAndroid Build Coastguard Worker 
8*6777b538SAndroid Build Coastguard Worker // Query canonicalization in IE
9*6777b538SAndroid Build Coastguard Worker // ----------------------------
10*6777b538SAndroid Build Coastguard Worker // IE is very permissive for query parameters specified in links on the page
11*6777b538SAndroid Build Coastguard Worker // (in contrast to links that it constructs itself based on form data). It does
12*6777b538SAndroid Build Coastguard Worker // not unescape any character. It does not reject any escape sequence (be they
13*6777b538SAndroid Build Coastguard Worker // invalid like "%2y" or freaky like %00).
14*6777b538SAndroid Build Coastguard Worker //
15*6777b538SAndroid Build Coastguard Worker // IE only escapes spaces and nothing else. Embedded NULLs, tabs (0x09),
16*6777b538SAndroid Build Coastguard Worker // LF (0x0a), and CR (0x0d) are removed (this probably happens at an earlier
17*6777b538SAndroid Build Coastguard Worker // layer since they are removed from all portions of the URL). All other
18*6777b538SAndroid Build Coastguard Worker // characters are passed unmodified. Invalid UTF-16 sequences are preserved as
19*6777b538SAndroid Build Coastguard Worker // well, with each character in the input being converted to UTF-8. It is the
20*6777b538SAndroid Build Coastguard Worker // server's job to make sense of this invalid query.
21*6777b538SAndroid Build Coastguard Worker //
22*6777b538SAndroid Build Coastguard Worker // Invalid multibyte sequences (for example, invalid UTF-8 on a UTF-8 page)
23*6777b538SAndroid Build Coastguard Worker // are converted to the invalid character and sent as unescaped UTF-8 (0xef,
24*6777b538SAndroid Build Coastguard Worker // 0xbf, 0xbd). This may not be canonicalization, the parser may generate these
25*6777b538SAndroid Build Coastguard Worker // strings before the URL handler ever sees them.
26*6777b538SAndroid Build Coastguard Worker //
27*6777b538SAndroid Build Coastguard Worker // Our query canonicalization
28*6777b538SAndroid Build Coastguard Worker // --------------------------
29*6777b538SAndroid Build Coastguard Worker // We escape all non-ASCII characters and control characters, like Firefox.
30*6777b538SAndroid Build Coastguard Worker // This is more conformant to the URL spec, and there do not seem to be many
31*6777b538SAndroid Build Coastguard Worker // problems relating to Firefox's behavior.
32*6777b538SAndroid Build Coastguard Worker //
33*6777b538SAndroid Build Coastguard Worker // Like IE, we will never unescape (although the application may want to try
34*6777b538SAndroid Build Coastguard Worker // unescaping to present the user with a more understandable URL). We will
35*6777b538SAndroid Build Coastguard Worker // replace all invalid sequences (including invalid UTF-16 sequences, which IE
36*6777b538SAndroid Build Coastguard Worker // doesn't) with the "invalid character," and we will escape it.
37*6777b538SAndroid Build Coastguard Worker 
38*6777b538SAndroid Build Coastguard Worker namespace url {
39*6777b538SAndroid Build Coastguard Worker 
40*6777b538SAndroid Build Coastguard Worker namespace {
41*6777b538SAndroid Build Coastguard Worker 
42*6777b538SAndroid Build Coastguard Worker // Appends the given string to the output, escaping characters that do not
43*6777b538SAndroid Build Coastguard Worker // match the given |type| in SharedCharTypes. This version will accept 8 or 16
44*6777b538SAndroid Build Coastguard Worker // bit characters, but assumes that they have only 7-bit values. It also assumes
45*6777b538SAndroid Build Coastguard Worker // that all UTF-8 values are correct, so doesn't bother checking
46*6777b538SAndroid Build Coastguard Worker template<typename CHAR>
AppendRaw8BitQueryString(const CHAR * source,int length,CanonOutput * output)47*6777b538SAndroid Build Coastguard Worker void AppendRaw8BitQueryString(const CHAR* source, int length,
48*6777b538SAndroid Build Coastguard Worker                               CanonOutput* output) {
49*6777b538SAndroid Build Coastguard Worker   for (int i = 0; i < length; i++) {
50*6777b538SAndroid Build Coastguard Worker     if (!IsQueryChar(static_cast<unsigned char>(source[i])))
51*6777b538SAndroid Build Coastguard Worker       AppendEscapedChar(static_cast<unsigned char>(source[i]), output);
52*6777b538SAndroid Build Coastguard Worker     else  // Doesn't need escaping.
53*6777b538SAndroid Build Coastguard Worker       output->push_back(static_cast<char>(source[i]));
54*6777b538SAndroid Build Coastguard Worker   }
55*6777b538SAndroid Build Coastguard Worker }
56*6777b538SAndroid Build Coastguard Worker 
57*6777b538SAndroid Build Coastguard Worker // Runs the converter on the given UTF-8 input. Since the converter expects
58*6777b538SAndroid Build Coastguard Worker // UTF-16, we have to convert first. The converter must be non-NULL.
RunConverter(const char * spec,const Component & query,CharsetConverter * converter,CanonOutput * output)59*6777b538SAndroid Build Coastguard Worker void RunConverter(const char* spec,
60*6777b538SAndroid Build Coastguard Worker                   const Component& query,
61*6777b538SAndroid Build Coastguard Worker                   CharsetConverter* converter,
62*6777b538SAndroid Build Coastguard Worker                   CanonOutput* output) {
63*6777b538SAndroid Build Coastguard Worker   DCHECK(query.is_valid());
64*6777b538SAndroid Build Coastguard Worker   // This function will replace any misencoded values with the invalid
65*6777b538SAndroid Build Coastguard Worker   // character. This is what we want so we don't have to check for error.
66*6777b538SAndroid Build Coastguard Worker   RawCanonOutputW<1024> utf16;
67*6777b538SAndroid Build Coastguard Worker   ConvertUTF8ToUTF16(&spec[query.begin], static_cast<size_t>(query.len),
68*6777b538SAndroid Build Coastguard Worker                      &utf16);
69*6777b538SAndroid Build Coastguard Worker   converter->ConvertFromUTF16(utf16.data(), utf16.length(), output);
70*6777b538SAndroid Build Coastguard Worker }
71*6777b538SAndroid Build Coastguard Worker 
72*6777b538SAndroid Build Coastguard Worker // Runs the converter with the given UTF-16 input. We don't have to do
73*6777b538SAndroid Build Coastguard Worker // anything, but this overridden function allows us to use the same code
74*6777b538SAndroid Build Coastguard Worker // for both UTF-8 and UTF-16 input.
RunConverter(const char16_t * spec,const Component & query,CharsetConverter * converter,CanonOutput * output)75*6777b538SAndroid Build Coastguard Worker void RunConverter(const char16_t* spec,
76*6777b538SAndroid Build Coastguard Worker                   const Component& query,
77*6777b538SAndroid Build Coastguard Worker                   CharsetConverter* converter,
78*6777b538SAndroid Build Coastguard Worker                   CanonOutput* output) {
79*6777b538SAndroid Build Coastguard Worker   DCHECK(query.is_valid());
80*6777b538SAndroid Build Coastguard Worker   converter->ConvertFromUTF16(&spec[query.begin],
81*6777b538SAndroid Build Coastguard Worker                               static_cast<size_t>(query.len), output);
82*6777b538SAndroid Build Coastguard Worker }
83*6777b538SAndroid Build Coastguard Worker 
84*6777b538SAndroid Build Coastguard Worker template <typename CHAR, typename UCHAR>
DoConvertToQueryEncoding(const CHAR * spec,const Component & query,CharsetConverter * converter,CanonOutput * output)85*6777b538SAndroid Build Coastguard Worker void DoConvertToQueryEncoding(const CHAR* spec,
86*6777b538SAndroid Build Coastguard Worker                               const Component& query,
87*6777b538SAndroid Build Coastguard Worker                               CharsetConverter* converter,
88*6777b538SAndroid Build Coastguard Worker                               CanonOutput* output) {
89*6777b538SAndroid Build Coastguard Worker   if (converter) {
90*6777b538SAndroid Build Coastguard Worker     // Run the converter to get an 8-bit string, then append it, escaping
91*6777b538SAndroid Build Coastguard Worker     // necessary values.
92*6777b538SAndroid Build Coastguard Worker     RawCanonOutput<1024> eight_bit;
93*6777b538SAndroid Build Coastguard Worker     RunConverter(spec, query, converter, &eight_bit);
94*6777b538SAndroid Build Coastguard Worker     AppendRaw8BitQueryString(eight_bit.data(), eight_bit.length(), output);
95*6777b538SAndroid Build Coastguard Worker 
96*6777b538SAndroid Build Coastguard Worker   } else {
97*6777b538SAndroid Build Coastguard Worker     // No converter, do our own UTF-8 conversion.
98*6777b538SAndroid Build Coastguard Worker     AppendStringOfType(&spec[query.begin], static_cast<size_t>(query.len),
99*6777b538SAndroid Build Coastguard Worker                        CHAR_QUERY, output);
100*6777b538SAndroid Build Coastguard Worker   }
101*6777b538SAndroid Build Coastguard Worker }
102*6777b538SAndroid Build Coastguard Worker 
103*6777b538SAndroid Build Coastguard Worker template<typename CHAR, typename UCHAR>
DoCanonicalizeQuery(const CHAR * spec,const Component & query,CharsetConverter * converter,CanonOutput * output,Component * out_query)104*6777b538SAndroid Build Coastguard Worker void DoCanonicalizeQuery(const CHAR* spec,
105*6777b538SAndroid Build Coastguard Worker                          const Component& query,
106*6777b538SAndroid Build Coastguard Worker                          CharsetConverter* converter,
107*6777b538SAndroid Build Coastguard Worker                          CanonOutput* output,
108*6777b538SAndroid Build Coastguard Worker                          Component* out_query) {
109*6777b538SAndroid Build Coastguard Worker   if (!query.is_valid()) {
110*6777b538SAndroid Build Coastguard Worker     *out_query = Component();
111*6777b538SAndroid Build Coastguard Worker     return;
112*6777b538SAndroid Build Coastguard Worker   }
113*6777b538SAndroid Build Coastguard Worker 
114*6777b538SAndroid Build Coastguard Worker   output->push_back('?');
115*6777b538SAndroid Build Coastguard Worker   out_query->begin = output->length();
116*6777b538SAndroid Build Coastguard Worker 
117*6777b538SAndroid Build Coastguard Worker   DoConvertToQueryEncoding<CHAR, UCHAR>(spec, query, converter, output);
118*6777b538SAndroid Build Coastguard Worker 
119*6777b538SAndroid Build Coastguard Worker   out_query->len = output->length() - out_query->begin;
120*6777b538SAndroid Build Coastguard Worker }
121*6777b538SAndroid Build Coastguard Worker 
122*6777b538SAndroid Build Coastguard Worker }  // namespace
123*6777b538SAndroid Build Coastguard Worker 
CanonicalizeQuery(const char * spec,const Component & query,CharsetConverter * converter,CanonOutput * output,Component * out_query)124*6777b538SAndroid Build Coastguard Worker void CanonicalizeQuery(const char* spec,
125*6777b538SAndroid Build Coastguard Worker                        const Component& query,
126*6777b538SAndroid Build Coastguard Worker                        CharsetConverter* converter,
127*6777b538SAndroid Build Coastguard Worker                        CanonOutput* output,
128*6777b538SAndroid Build Coastguard Worker                        Component* out_query) {
129*6777b538SAndroid Build Coastguard Worker   DoCanonicalizeQuery<char, unsigned char>(spec, query, converter,
130*6777b538SAndroid Build Coastguard Worker                                            output, out_query);
131*6777b538SAndroid Build Coastguard Worker }
132*6777b538SAndroid Build Coastguard Worker 
CanonicalizeQuery(const char16_t * spec,const Component & query,CharsetConverter * converter,CanonOutput * output,Component * out_query)133*6777b538SAndroid Build Coastguard Worker void CanonicalizeQuery(const char16_t* spec,
134*6777b538SAndroid Build Coastguard Worker                        const Component& query,
135*6777b538SAndroid Build Coastguard Worker                        CharsetConverter* converter,
136*6777b538SAndroid Build Coastguard Worker                        CanonOutput* output,
137*6777b538SAndroid Build Coastguard Worker                        Component* out_query) {
138*6777b538SAndroid Build Coastguard Worker   DoCanonicalizeQuery<char16_t, char16_t>(spec, query, converter, output,
139*6777b538SAndroid Build Coastguard Worker                                           out_query);
140*6777b538SAndroid Build Coastguard Worker }
141*6777b538SAndroid Build Coastguard Worker 
ConvertUTF16ToQueryEncoding(const char16_t * input,const Component & query,CharsetConverter * converter,CanonOutput * output)142*6777b538SAndroid Build Coastguard Worker void ConvertUTF16ToQueryEncoding(const char16_t* input,
143*6777b538SAndroid Build Coastguard Worker                                  const Component& query,
144*6777b538SAndroid Build Coastguard Worker                                  CharsetConverter* converter,
145*6777b538SAndroid Build Coastguard Worker                                  CanonOutput* output) {
146*6777b538SAndroid Build Coastguard Worker   DoConvertToQueryEncoding<char16_t, char16_t>(input, query, converter, output);
147*6777b538SAndroid Build Coastguard Worker }
148*6777b538SAndroid Build Coastguard Worker 
149*6777b538SAndroid Build Coastguard Worker }  // namespace url
150