mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
Move rend client name checks to one function
This commit is contained in:
committed by
Nick Mathewson
parent
dcc11674db
commit
162aa14eef
@@ -750,6 +750,22 @@ rend_valid_descriptor_id(const char *query)
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** Return true iff <b>client_name</b> is a syntactically valid name
|
||||
* for rendezvous client authentication. */
|
||||
int
|
||||
rend_valid_client_name(const char *client_name)
|
||||
{
|
||||
size_t len = strlen(client_name);
|
||||
if (len < 1 || len > REND_CLIENTNAME_MAX_LEN) {
|
||||
return 0;
|
||||
}
|
||||
if (strspn(client_name, REND_LEGAL_CLIENTNAME_CHARACTERS) != len) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** Called when we get a rendezvous-related relay cell on circuit
|
||||
* <b>circ</b>. Dispatch on rendezvous relay command. */
|
||||
void
|
||||
|
||||
@@ -45,6 +45,7 @@ void rend_intro_point_free(rend_intro_point_t *intro);
|
||||
|
||||
int rend_valid_service_id(const char *query);
|
||||
int rend_valid_descriptor_id(const char *query);
|
||||
int rend_valid_client_name(const char *client_name);
|
||||
int rend_encode_v2_descriptors(smartlist_t *descs_out,
|
||||
rend_service_descriptor_t *desc, time_t now,
|
||||
uint8_t period, rend_auth_type_t auth_type,
|
||||
|
||||
+4
-14
@@ -672,27 +672,17 @@ rend_config_services(const or_options_t *options, int validate_only)
|
||||
SMARTLIST_FOREACH_BEGIN(clients, const char *, client_name)
|
||||
{
|
||||
rend_authorized_client_t *client;
|
||||
size_t len = strlen(client_name);
|
||||
if (len < 1 || len > REND_CLIENTNAME_MAX_LEN) {
|
||||
if (!rend_valid_client_name(client_name)) {
|
||||
log_warn(LD_CONFIG, "HiddenServiceAuthorizeClient contains an "
|
||||
"illegal client name: '%s'. Length must be "
|
||||
"between 1 and %d characters.",
|
||||
"illegal client name: '%s'. Names must be "
|
||||
"between 1 and %d characters and contain "
|
||||
"only [A-Za-z0-9+_-].",
|
||||
client_name, REND_CLIENTNAME_MAX_LEN);
|
||||
SMARTLIST_FOREACH(clients, char *, cp, tor_free(cp));
|
||||
smartlist_free(clients);
|
||||
rend_service_free(service);
|
||||
return -1;
|
||||
}
|
||||
if (strspn(client_name, REND_LEGAL_CLIENTNAME_CHARACTERS) != len) {
|
||||
log_warn(LD_CONFIG, "HiddenServiceAuthorizeClient contains an "
|
||||
"illegal client name: '%s'. Valid "
|
||||
"characters are [A-Za-z0-9+_-].",
|
||||
client_name);
|
||||
SMARTLIST_FOREACH(clients, char *, cp, tor_free(cp));
|
||||
smartlist_free(clients);
|
||||
rend_service_free(service);
|
||||
return -1;
|
||||
}
|
||||
client = tor_malloc_zero(sizeof(rend_authorized_client_t));
|
||||
client->client_name = tor_strdup(client_name);
|
||||
smartlist_add(service->clients, client);
|
||||
|
||||
@@ -5300,7 +5300,6 @@ rend_parse_client_keys(strmap_t *parsed_clients, const char *ckstr)
|
||||
current_entry = eat_whitespace(ckstr);
|
||||
while (!strcmpstart(current_entry, "client-name ")) {
|
||||
rend_authorized_client_t *parsed_entry;
|
||||
size_t len;
|
||||
/* Determine end of string. */
|
||||
const char *eos = strstr(current_entry, "\nclient-name ");
|
||||
if (!eos)
|
||||
@@ -5329,12 +5328,10 @@ rend_parse_client_keys(strmap_t *parsed_clients, const char *ckstr)
|
||||
tor_assert(tok == smartlist_get(tokens, 0));
|
||||
tor_assert(tok->n_args == 1);
|
||||
|
||||
len = strlen(tok->args[0]);
|
||||
if (len < 1 || len > 19 ||
|
||||
strspn(tok->args[0], REND_LEGAL_CLIENTNAME_CHARACTERS) != len) {
|
||||
if (!rend_valid_client_name(tok->args[0])) {
|
||||
log_warn(LD_CONFIG, "Illegal client name: %s. (Length must be "
|
||||
"between 1 and 19, and valid characters are "
|
||||
"[A-Za-z0-9+-_].)", tok->args[0]);
|
||||
"between 1 and %d, and valid characters are "
|
||||
"[A-Za-z0-9+-_].)", tok->args[0], REND_CLIENTNAME_MAX_LEN);
|
||||
goto err;
|
||||
}
|
||||
/* Check if client name is duplicate. */
|
||||
|
||||
Reference in New Issue
Block a user