#2565: HTMLForm: optional enforcement of Content-Length instead of Chunked Transfer-Encoding

This commit is contained in:
Günter Obiltschnig
2018-12-12 18:00:58 +01:00
parent e1aac5ff95
commit db86fec382
4 changed files with 73 additions and 39 deletions

View File

@@ -19,6 +19,7 @@
#include "Poco/Net/NetException.h"
#include <sstream>
#include <iostream>
using Poco::Net::HTMLForm;
using Poco::Net::PartSource;
@@ -37,7 +38,7 @@ namespace
StringPartHandler()
{
}
void handlePart(const MessageHeader& header, std::istream& stream)
{
_disp = header["Content-Disposition"];
@@ -49,7 +50,7 @@ namespace
ch = stream.get();
}
}
const std::string& data() const
{
return _data;
@@ -64,7 +65,7 @@ namespace
{
return _type;
}
private:
std::string _data;
std::string _disp;
@@ -91,7 +92,7 @@ void HTMLFormTest::testWriteUrl()
form.set("field3", "value=3");
form.set("field4", "value&4");
form.set("field5", "value+5");
std::ostringstream ostr;
form.write(ostr);
std::string s = ostr.str();
@@ -106,16 +107,16 @@ void HTMLFormTest::testWriteMultipart()
form.set("field2", "value 2");
form.set("field3", "value=3");
form.set("field4", "value&4");
form.addPart("attachment1", new StringPartSource("This is an attachment"));
StringPartSource* pSPS = new StringPartSource("This is another attachment", "text/plain", "att2.txt");
pSPS->headers().set("Content-ID", "1234abcd");
form.addPart("attachment2", pSPS);
std::ostringstream ostr;
form.write(ostr, "MIME_boundary_0123456789");
std::string s = ostr.str();
assertTrue (s ==
assertTrue (s ==
"--MIME_boundary_0123456789\r\n"
"Content-Disposition: form-data; name=\"field1\"\r\n"
"\r\n"
@@ -166,7 +167,7 @@ void HTMLFormTest::testReadUrlGETMultiple()
HTTPRequest req("GET", "/form.cgi?field1=value1&field1=value%202&field1=value%3D3&field1=value%264");
HTMLForm form(req);
assertTrue (form.size() == 4);
HTMLForm::ConstIterator it = form.find("field1");
assertTrue (it != form.end());
assertTrue (it->first == "field1" && it->second == "value1");
@@ -256,7 +257,7 @@ void HTMLFormTest::testReadMultipart()
HTTPRequest req("POST", "/form.cgi");
req.setContentType(HTMLForm::ENCODING_MULTIPART + "; boundary=\"MIME_boundary_0123456789\"");
StringPartHandler sah;
HTMLForm form(req, istr, sah);
HTMLForm form(req, istr, sah);
assertTrue (form.size() == 4);
assertTrue (form["field1"] == "value1");
assertTrue (form["field2"] == "value 2");
@@ -276,7 +277,7 @@ void HTMLFormTest::testSubmit1()
form.set("field2", "value 2");
form.set("field3", "value=3");
form.set("field4", "value&4");
HTTPRequest req("GET", "/form.cgi");
form.prepareSubmit(req);
assertTrue (req.getURI() == "/form.cgi?field1=value1&field2=value%202&field3=value%3D3&field4=value%264");
@@ -290,10 +291,11 @@ void HTMLFormTest::testSubmit2()
form.set("field2", "value 2");
form.set("field3", "value=3");
form.set("field4", "value&4");
HTTPRequest req("POST", "/form.cgi");
form.prepareSubmit(req);
assertTrue (req.getContentType() == HTMLForm::ENCODING_URL);
assertTrue (req.getContentLength() == 64);
}
@@ -304,7 +306,7 @@ void HTMLFormTest::testSubmit3()
form.set("field2", "value 2");
form.set("field3", "value=3");
form.set("field4", "value&4");
HTTPRequest req("POST", "/form.cgi", HTTPMessage::HTTP_1_1);
form.prepareSubmit(req);
std::string expCT(HTMLForm::ENCODING_MULTIPART);
@@ -323,7 +325,7 @@ void HTMLFormTest::testSubmit4()
form.add("field1", "value 2");
form.add("field1", "value=3");
form.add("field1", "value&4");
HTTPRequest req("GET", "/form.cgi");
form.prepareSubmit(req);
@@ -331,6 +333,25 @@ void HTMLFormTest::testSubmit4()
}
void HTMLFormTest::testSubmit5()
{
HTMLForm form(HTMLForm::ENCODING_MULTIPART);
form.set("field1", "value1");
form.set("field2", "value 2");
form.set("field3", "value=3");
form.set("field4", "value&4");
HTTPRequest req("POST", "/form.cgi", HTTPMessage::HTTP_1_1);
form.prepareSubmit(req, HTMLForm::OPT_USE_CONTENT_LENGTH);
std::string expCT(HTMLForm::ENCODING_MULTIPART);
expCT.append("; boundary=\"");
expCT.append(form.boundary());
expCT.append("\"");
assertTrue (req.getContentType() == expCT);
assertTrue (req.getContentLength() == 403);
}
void HTMLFormTest::testFieldLimitUrl()
{
HTTPRequest req("GET", "/form.cgi?field1=value1&field2=value%202&field3=value%3D3&field4=value%264");
@@ -381,7 +402,7 @@ void HTMLFormTest::testFieldLimitMultipart()
form.setFieldLimit(3);
try
{
form.load(req, istr, sah);
form.load(req, istr, sah);
fail("field limit violated - must throw");
}
catch (Poco::Net::HTMLFormException&)
@@ -416,6 +437,7 @@ CppUnit::Test* HTMLFormTest::suite()
CppUnit_addTest(pSuite, HTMLFormTest, testSubmit2);
CppUnit_addTest(pSuite, HTMLFormTest, testSubmit3);
CppUnit_addTest(pSuite, HTMLFormTest, testSubmit4);
CppUnit_addTest(pSuite, HTMLFormTest, testSubmit5);
CppUnit_addTest(pSuite, HTMLFormTest, testFieldLimitUrl);
CppUnit_addTest(pSuite, HTMLFormTest, testFieldLimitMultipart);

View File

@@ -36,6 +36,7 @@ public:
void testSubmit2();
void testSubmit3();
void testSubmit4();
void testSubmit5();
void testFieldLimitUrl();
void testFieldLimitMultipart();