1
0
mirror of https://github.com/d47081/qBittorrent.git synced 2025-01-12 15:57:57 +00:00

Separate URL components before percent-decoding

Allow special characters in query string parameters.
Closes #9116.
This commit is contained in:
Vladimir Golovnev (Glassez) 2019-01-26 21:49:58 +03:00
parent fc534e88a3
commit b0446380c6
No known key found for this signature in database
GPG Key ID: 52A2C7DEE2DFA6F7
3 changed files with 17 additions and 10 deletions

View File

@ -140,8 +140,11 @@ void Tracker::respondToAnnounceRequest()
const int sepPos = param.indexOf('='); const int sepPos = param.indexOf('=');
if (sepPos <= 0) continue; // ignores params without name if (sepPos <= 0) continue; // ignores params without name
const QString paramName {QString::fromUtf8(param.constData(), sepPos)}; const QByteArray nameComponent = midView(param, 0, sepPos);
const QByteArray paramValue {param.mid(sepPos + 1)}; const QByteArray valueComponent = midView(param, (sepPos + 1));
const QString paramName = QString::fromUtf8(QByteArray::fromPercentEncoding(nameComponent));
const QByteArray paramValue = QByteArray::fromPercentEncoding(valueComponent);
queryParams[paramName] = paramValue; queryParams[paramName] = paramValue;
} }

View File

@ -180,11 +180,14 @@ bool RequestParser::parseRequestLine(const QString &line)
m_request.method = match.captured(1); m_request.method = match.captured(1);
// Request Target // Request Target
const QByteArray decodedUrl {QByteArray::fromPercentEncoding(match.captured(2).toLatin1())}; // URL components should be separated before percent-decoding
const int sepPos = decodedUrl.indexOf('?'); // [rfc3986] 2.4 When to Encode or Decode
m_request.path = QString::fromUtf8(decodedUrl.constData(), (sepPos == -1 ? decodedUrl.size() : sepPos)); const QByteArray url {match.captured(2).toLatin1()};
const int sepPos = url.indexOf('?');
const QByteArray pathComponent = ((sepPos == -1) ? url : Utils::ByteArray::midView(url, 0, sepPos));
m_request.path = QString::fromUtf8(QByteArray::fromPercentEncoding(pathComponent));
if (sepPos >= 0) if (sepPos >= 0)
m_request.query = decodedUrl.mid(sepPos + 1); m_request.query = url.mid(sepPos + 1);
// HTTP-version // HTTP-version
m_request.version = match.captured(3); m_request.version = match.captured(3);

View File

@ -423,10 +423,11 @@ Http::Response WebApplication::processRequest(const Http::Request &request, cons
const int sepPos = param.indexOf('='); const int sepPos = param.indexOf('=');
if (sepPos <= 0) continue; // ignores params without name if (sepPos <= 0) continue; // ignores params without name
const QString paramName {QString::fromUtf8(param.constData(), sepPos)}; const QByteArray nameComponent = midView(param, 0, sepPos);
const int valuePos = sepPos + 1; const QByteArray valueComponent = midView(param, (sepPos + 1));
const QString paramValue {
QString::fromUtf8(param.constData() + valuePos, param.size() - valuePos)}; const QString paramName = QString::fromUtf8(QByteArray::fromPercentEncoding(nameComponent));
const QString paramValue = QString::fromUtf8(QByteArray::fromPercentEncoding(valueComponent));
m_params[paramName] = paramValue; m_params[paramName] = paramValue;
} }
} }