summaryrefslogtreecommitdiff
path: root/http
AgeCommit message (Collapse)AuthorFilesLines
2021-02-19Fix nlohmann::json::dump callsEd Tanous1-1/+2
The nlohmann::json::dump call needs to be called with specific arguments to avoid throwing in failure cases. http connection already does this properly, but a bunch of code has snuck in (mostly in redfish) that ignores this, and calls it incorrectly. This can potentially lead to a crash if the wrong thing throws on invalid UTF8 characters. This audits the whole codebase, and replaces every dump() call with the correct dump(2, ' ', true, nlohmann::json::error_handler_t::replace) call. For correct output, the callers should expect no change, and in practice, this would require injecting non-utf8 characters into the BMC. Tested: Ran several of the endpoints/error conditions in question, including some of the error cases. Observed correct responses. I don't know of a security issue that would allow injecting invalid utf8 into the BMC, but in theory if it were possible, this would prevent a crash. Signed-off-by: Ed Tanous <edtanous@google.com> Change-Id: I4a15b8e260e3db129bc20484ade4ed5449f75ad0
2021-02-13Bind dev server to ipv4 onlyEd Tanous1-1/+1
On systems that don't support ipv6, or systems that don't have an ipv6 address, binding to all ipv6 addresses can fail. Because this is just the dev server, it's perfectly reasonable to limit to ipv4 addresses only. This failure has been reported by several people over time, but it was only recently that I root caused this as their problem. This should have no effect on the BMC itself, as the bmc is using socket activation, and completely bypasses this code path. Tested: Launched bmcweb on a system that was previously failing because of a bind error, and observed that I could launch bmcweb and have it work correctly. Signed-off-by: Ed Tanous <edtanous@google.com> Change-Id: Ife6b051aa62d62e1691c5221d8ddee0b9bd012c0
2021-02-06Add chrono include to http/utility.hppEd Tanous1-0/+1
In commit d139c2364bec98a5da1fe803414f3b02fdcd3092, http utility picked up a dependency on chrono (for getting timestamps) but was relying on another files include to function. This adds the appropriate include. Tested: Code builds. No functional changes. Signed-off-by: Ed Tanous <edtanous@google.com> Change-Id: I7c2353f2b5f991d78a76dbe19a0b55850c0126b9
2021-02-03http: utility: Add base64encodeAdriana Kobylak2-0/+98
Add the base64encode() function to be used to encode binary data to offload out of the BMC. Based on crow/utility.h, reworked for readability. Tested: Added unit test cases. Also verified data encoded with this function was the same as the original binary when using a decoder. Change-Id: I0a27ffb0090c4613e296af33d11e2e2657957167 Signed-off-by: Adriana Kobylak <anoo@us.ibm.com>
2021-01-16Add missing nullptr checkEd Tanous1-7/+10
In theory, having a sessionless websocket isn't possible. In practice, this did come up when an ownership issue caused UB, which is how I saw this. Tested: Tested with scripts/websocket_test.py and saw sensor values streaming by as expected. Signed-off-by: Ed Tanous <edtanous@google.com> Change-Id: I7cc9c9660c8207ba857e6f6f14f010eaf79b73ef
2020-12-18Fix .clang-tidyEd Tanous6-82/+81
camelLower is not a type, camelBack is. Changes were made automatically with clang-tidy --fix-errors To be able to apply changes automatically, the only way I've found that works was to build the version of clang/clang-tidy that yocto has, and run the fix script within bitbake -c devshell bmcweb. Unfortunately, yocto has clang-tidy 11, which can apparently find a couple extra errors in tests we already had enabled. As such, a couple of those are also included. Tested: Ran clang-tidy-11 and got a clean result. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I9d1080b67f0342229c2f267160849445c065ca51
2020-12-12Flush the timer queue at each timer cancellationKarthick Sundarrajan1-0/+5
When attempting to make parallel connections, the BMC is not able to handle more than 25 connections. Found that the timerQueue gets filled with both valid and expired timers. The main timer fires every one second and flush the queue which is not enough for BMCs with high speed processors. So flushing the queue in TimerQueue::cancel() to make room for new connections when the timers are cancelled. Tested: Tested on the BMC with high speed processor and able to make parallel connections without failures. Change-Id: Ib899f5ba3f60c009aeeff462f01d4b45522b803d Signed-off-by: Karthick Sundarrajan <karthick.sundarrajan@intel.com>
2020-11-18Avoid std::filesystem exception on trust storeJonathan Doman1-2/+4
Use non-throwing version of is_empty() in case the directory (/etc/ssl/certs/authority) doesn't exist. This directory is normally created by another certificate manager daemon so this crash would only be encountered under unusual scenarios (which we did encounter due to misconfigured build). Tested: 1. Stopped phosphor-certificate-manager@authority and deleted /etc/ssl/certs/authority. 2. Start non-modified bmcweb and observe exception in journal. 3. Start this build of bmcweb and observe no exception. 4. Browse around in web ui and everything looks normal. Signed-off-by: Jonathan Doman <jonathan.doman@intel.com> Change-Id: Ife086da6d36ddeb30a9f8632d629420310625ea3
2020-11-10Redfish Session : Support ClientOriginIPAddressSunitha Harish2-2/+29
This commit implements the ClientOriginIPAddress property on the session resource. The IP address is persisted across the reboot Tested by: 1. Create session POST https://${bmc}/redfish/v1/SessionService/Sessions -d '{"UserName":<>, "Password":<>}' 2. Check the session gets updated with the ClientOriginIPAddress GET https://${bmc}/redfish/v1/SessionService/Sessions/<id> 3. Redfish validator passed 4. Create session and reboot the BMC to ensure the IP address is persisted 5. Tested the basic auth populates the clientIp at req Signed-off-by: Sunitha Harish <sunharis@in.ibm.com> Change-Id: Iaa60d0657c991bde4bcf6c86819055c71c92e421
2020-10-29Revert "Redfish Session : Support ClientOriginIPAddress"Ed Tanous2-6/+0
This reverts commit e436008377fbcf287be02c9e9e1b59c6627d7673. Reason for revert: This breaks several things. 1. Not all login endpoints are handled, which lead to returning blank ip addresses 2. IP addresses are not persisted. 3. This crashes occasionally on remote_endpoint, and ignores ec. Change-Id: I58c875721cf48bf02db833c9c57a9eead5e249d5
2020-10-23Turn on ALL perf checksEd Tanous3-20/+9
1st, alphabetize the tidy-list for good housekeeping. Next, enable all the clang-tidy performance checks, and resolve all the issues. most of the issues boil down to: 1. Using std::move on const variables. This does nothing. 2. Passing big variables (like std::string) by value. 3. Using double quotes on a find call, which constructs an intermediate string, rather than using the character overload. Tested Loaded on system, logged in successfully and pulled down webui-vue. No new errors. Walked the Redfish tree a bit, and observed no new problems. Ran redfish service validator. Got no new failures (although there are a lot of log service deprecation warnings that we should look at). Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I2238958c4b22c1e554e09a0a1787c744bdbca43e
2020-10-23fix include namesEd Tanous12-30/+25
cppcheck isn't smart enough to recognize these are c++ headers, not c headers. Considering we're already inconsistent about our naming, it's easier to just be consistent, and move the last few files to use .hpp instead of .h. Tested: Code builds, no changes. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: Ic348d695f8527fa4a0ded53f433e1558c319db40
2020-10-22Avoid using deleted Connection in ResponseWludzik, Jozef1-1/+2
Connection is destroyed when completeRequestHandler is nulled. It causes that memory is freed. When Response::end() is called and connection is not alive, completeRequest() method removes last shared_ptr reference by setting nullptr on completeRequestHandler member of Response. In this moment code is executed on destroyed object and can cause stack overflow. Fixed it by moving a call to completeRequest method to Asio executor in completeRequestHandler. Tested: - Ran stress test that send a lot of GET and POST requests without a bmcweb service crash Change-Id: Idcf6a06dac32e9eac08285b9b53a5e8afe36c955 Signed-off-by: Wludzik, Jozef <jozef.wludzik@intel.com>
2020-10-15Lots of performance improvementsEd Tanous3-9/+9
(In the voice of the kid from sixth sense) I see string copies... Apparently there are a lot of places we make unnecessary copies. This fixes all of them. Not sure how to split this up into smaller patches, or if it even needs split up. It seems pretty easy to review to me, because basically every diff is identical. Change-Id: I22b4ae4f96f7e4082d2bc701098a04f7bed95369 Signed-off-by: Ed Tanous <ed@tanous.net> Signed-off-by: Wludzik, Jozef <jozef.wludzik@intel.com>
2020-10-09Write the clang-tidy file OpenBMC needsEd Tanous3-18/+36
Now that CI can handle clang-tidy, and a lot of the individual fixes have landed for the various static analysis checks, lets see how close we are. This includes bringing a bunch of the code up to par with the checks that require. Most of them fall into the category of extraneous else statements, const correctness problems, or extra copies. Tested: CI only. Unit tests pass. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I9fbd346560a75fdd3901fa40c57932486275e912
2020-10-08Redfish Session : Support ClientOriginIPAddressSunitha Harish2-0/+6
This commit implements the ClientOriginIPAddress property on the session resource Tested by: 1. Create session POST https://${bmc}/redfish/v1/SessionService/Sessions -d '{"UserName":<>, "Password":<>}' 2. Check the session gets updated with the ClientOriginIPAddress GET https://${bmc}/redfish/v1/SessionService/Sessions/<id> 3. Redfish validator passed Signed-off-by: Sunitha Harish <sunharis@in.ibm.com> Change-Id: I4c5c6f651bb6faec0cb1b1b78d9da593ecb85ff0
2020-10-07Clean up utilsEd Tanous3-329/+105
Lots of the utils functions have been superceeded or replaced by std:: implementations, or are no longer needed because of the removal of middlewares. Tested: Ran on a bmc with this implemented. Pulled down the webui, and observed no issues. Code compiles and passes clang-tidy cert checks. Change-Id: If29bb5f4ba9979912aeb2a8fa4cbd9f4e4f32006 Signed-off-by: Ed Tanous <ed@tanous.net>
2020-10-07Fix PATCH verbEd Tanous1-1/+1
Fix PATCH in the router. https://github.com/openbmc/bmcweb/commit/888880af0ec22bb50e262917bd5dab5d221d521c was injected recently which attempted to reduce the memory load on the system by reducing the number of handlers we hold. This code is already brittle, as it relies on a specific order of verbs in boost. unfortunately, patch was accidentally removed from the router. This commit reverts the attempted memory reclaiming, and does what the old code did, claiming all the way to UNLINK verb. Tested: only inspected at this point, but CI was able to catch the failure. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I62a531cb20c2508db2dcedec249c2f39719a2181
2020-10-06Cleanup per methodsEd Tanous1-4/+13
These were kind of a mess beforehand Change-Id: I78410dfd026d76d720a7fd55d85e6e6967e1a0a4 Signed-off-by: Ed Tanous <ed@tanous.net>
2020-10-06Fix includesEd Tanous4-8/+8
Lots of bad includes got put in recently, including big things, like boost/http and beast/core. These are lots of code to parse, and leads to files including things they didn't mean to. Tested: Code compiles Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I38de889fdfd9b23f66a2259bb30bf6584345e77f
2020-10-05Fix naming conventions in loggerEd Tanous1-17/+17
Tested: No functional changes. Change-Id: I10144229b07959de4d8a5d5a471caff8a2b87e6f Signed-off-by: Ed Tanous <ed@tanous.net>
2020-10-01Remove socket() call from RequestEd Tanous1-7/+0
The socket() call in the request object is a pretty bad architecture break. Requests should have no knowledge of the underlying socket. It is currently not used. Tested: Code compiles Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I1f72667857c377df370e3238a81d6c46fba1e8f5
2020-09-30Remove Server header from responsesEd Tanous2-14/+14
The HTTP Server header allows potential attackers to fingerprint the BMC much easier than they could otherwise, as the bmc essentially reports its name to requests. From section 7.4.2 of RFC7231: "An origin server MAY generate a Server field in its responses." This patchset moves bmcwebs position that it will not publish the server field, as it does not contain useful data for the client. It should be noted, it looks like OpenSSL was using the server name for its connection ID. It's not clear this is correct, or desired, but I've inlined the old value (to avoid changing behavior). Also, it was missing a return code check, so I added it. Tested: Will verify in the webui (TBD) Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: Ieee6f15d8299e76517952514ff196008a563b63c
2020-09-29Fix naming conventionsEd Tanous4-12/+12
Lots of code has been checked in that doesn't match the naming conventions. Lets fix that. Tested: Code compiles. Variable/function renames only. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I6bd107811d0b724f1fad990016113cdf035b604b
2020-09-24Improve JSON->HTML conversionEd Tanous2-66/+3
The existing JSON to html conversion is quite unfortunate, as it runs several very expensive regular expressions on an output to properly invoke the correct behavior, and to escape things like links. This patchset adjusts the behavior to directly dump the tree to HTML, skipping the json step entirely. Most of the code was pulled from the nlohmann::serializer class. Small side node: This also resolves the CSP issue with the inline CSS classes that are currently embedded in the json UI. Note, in terms of user facing behavior, this finally fixes the CSS issue, so the div is now centered as designed. Previously it was left justified. Tested: Ran several redfish schemas and compared to old ones. Output appears the same in the window, and content security policy warnings are gone. Verified several links works as expected, and verified the behavior of all base types, as well as empty arrays and empty objects. All appear to work correctly. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: Id9bf6dc33acb1603f009de4cd322e81d83f334be
2020-09-17Fix using namespaceEd Tanous3-14/+10
We inherited a "using namespace" crow. Lets fix it. Tested: Code compiles. No functional changes. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: Id47446150dfb312c5cd84a4b4284fb824eba8021
2020-09-11Remove tick timerEd Tanous2-62/+11
External tick timers were never something we used, so they're effectively dead code, even if they do still execute. Remove them. Tested: Loaded bmcweb on a system, and pulled down webui-vue. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I65bbc24d59cfa45adeb013055a2eab2eeb26ad3d
2020-09-03Revert http::Request::socket() callbackEd Tanous1-4/+0
Details on why this revert is needed are here. https://lists.ozlabs.org/pipermail/openbmc/2020-August/022478.html Appu and Ravi still have not commented. It should be noted, this also causes a memory leak in http connection, where connections refuse to be freed, because of a bad usage of shared_from_this. This code wasn't very well thought through, and needs rearchitected to not break the unit testability of bmcweb, nor cause memory leaks. https://github.com/openbmc/bmcweb/blob/218bd4746130aac22366968c8c9a34a929e45a3d/http/http_connection.h#L351 Is the memory leak in question. Specifically, this reverts: The /attachment download in LogServices. This needs reimplemented properly, but is an OEM property, so it shouldn't be a big deal to revert, and shouldn't break our redfish compliance. The IpAddress property in SessionService. I have no idea why this was injected, and it's functionally incorrect. IpAddresses are not related to a session, and IP addresses can change over the course of a session, so this property is already broken as written. I suspect the author really wanted RedfishEvent type logging, but that was too complex, so they half implemented this. Redfish SSE properties. This needs to be reimplemented similar to the patchset here: https://gerrit.openbmc-project.xyz/c/openbmc/bmcweb/+/13948 Where the ownership of the HTTP connection does not leave the http framework. As written, the SSE implementation causes ownership issues, as there's no clear delineation of the ownership between HttpConnection and the SSE framework. Tested: On current master, running this command: wget -O- --no-http-keep-alive --no-check-certificate https://{bmc hostname}:18080/redfish/v1 Which should download the service root, then immediately close and destroy the connection, prints: (2020-08-28 16:55:24) [DEBUG "routing.h":1258] Matched rule '/redfish/v1/' 2 / 4 (2020-08-28 16:55:24) [DEBUG "http_response.h":130] calling completion handler (2020-08-28 16:55:24) [DEBUG "http_response.h":133] completion handler was valid (2020-08-28 16:55:24) [INFO "http_connection.h":429] Response: 0x1e1ee28 /redfish/v1 200 keepalive=0 (2020-08-28 16:55:24) [DEBUG "timer_queue.h":48] timer add inside: 0x1d3d1a8 7 (2020-08-28 16:55:24) [DEBUG "http_connection.h":751] 0x1e1ee28 timer added: 0x1d3d1a8 7 (2020-08-28 16:55:24) [DEBUG "http_connection.h":655] 0x1e1ee28 doWrite (2020-08-28 16:55:24) [DEBUG "http_connection.h":663] 0x1e1ee28 async_write 1555 bytes (2020-08-28 16:55:24) [DEBUG "http_connection.h":697] 0x1e1ee28 timer cancelled: 0x1d3d1a8 7 (2020-08-28 16:55:24) [DEBUG "http_connection.h":676] 0x1e1ee28 from write(1) Then stops. Note, that the connection was not destroyed, and has leaked. Once this patchset is added, the connection closes and destroys properly, and doesn't leak, so it prints the above, but also prints. (2020-08-28 16:27:10) [DEBUG "http_connection.h":305] 0x1d15c90 Connection closed, total 1 Ran Redfish service validator. Saw one unrelated failure due to UUID, all other things pass. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I18686037bf58f20389d31facc0d77020274d38a1
2020-08-26Fix build error in debugEd Tanous1-1/+1
std::exception doesn't have a direct conversion to iostream. This only shows up when building for debug. Tested: Forced -DCMAKE_BUILD_TYPE=Debug, and verified code builds. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I6fdd0e561f1cecc5f40f0e8b9c624f746ce6456f
2020-08-25Implement Modified Event log propertyGeorge Liu1-0/+10
Refer to https://gerrit.openbmc-project.xyz/c/openbmc/phosphor-dbus-interfaces/+/29734 and implement Modified Event log property Tested: curl -k -H "X-Auth-Token: $token" https://${bmc}/redfish/v1/Systems/system/LogServices/EventLog/Entries/1 { "@odata.id": "/redfish/v1/Systems/system/LogServices/EventLog/Entries/1", "@odata.type": "#LogEntry.v1_6_0.LogEntry", "Created": "1970-01-01T00:01:35+00:00", "EntryType": "Event", "Id": "1", "Message": "xyz.openbmc_project.Common.Device.Error.ReadFailure", "Modified": "1970-01-01T00:01:35+00:00", "Name": "System Event Log Entry", "Severity": "Critical" } Passed the validator: VERBO - ServiceRoot -> Systems.Systems -> Members.ComputerSystem#0 -> LogServices.LogServices -> Members.LogService#0 -> Entries.Entries -> Members.LogEntry#0, LogEntry.v1_6_1, LogEntry VERBO - @odata.id PASS VERBO - @odata.type PASS VERBO - Created PASS VERBO - EntryType PASS VERBO - Id PASS VERBO - Message PASS VERBO - Modified PASS VERBO - Name PASS VERBO - Severity PASS Signed-off-by: George Liu <liuxiwei@inspur.com> Change-Id: I5a59a298e95e78acaad11a99558f9046675820d3
2020-08-24Prep for boost 1.74.0Ed Tanous1-12/+13
Boost 1.74.0 got released the yesterday and deprecated some more stuff that we use. This patchset prepares us so we will build for it when meta-oe picks it up. Tested: Code builds under boost 1.74.0 Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: Icc6c54da6705098fc76e3ee6dbdc6c3b5c57fbda
2020-08-20Catch more errors in url_viewEd Tanous1-1/+2
Url_view can throw more exceptions. Tested: I wish I knew of a good way to test this, but because it relies on breaking the protocol, it's difficult to use existing things to test. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: Iccaf864221cd1389574106316d3049283b44d08c
2020-08-18Improve base64Decode bounds checkingJonathan Doman2-5/+31
Index the decode array with an unsigned char rather than a signed int (which could accees outside the bounds of decodingData, leading to undefined behavior). Add unit tests for basic decoding functionality. Remove duplicate unused base64 functions. Tested: ran webtest and observed that previously failing Base64DecodeNonAscii now passes. Also tested basic auth: $ curl -vku root:0penBmc https://<ip>/redfish/v1/Managers/bmc ... < HTTP/1.1 200 OK ... Change-Id: I9f9e32650b1796f9fc0b2b25d482dffa35fac72d Signed-off-by: Jonathan Doman <jonathan.doman@intel.com>
2020-08-18url_view throws if a parse error is foundEd Tanous1-3/+18
This causes a strange condition where the webserver crashes on bad urls. Tested: Loaded on RPI. Verified that this particular crash no longer breaks the fuzzer. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I459421e27c8d07c2bc45099b5942f7c7c929610d
2020-08-17Enable unused variable warnings and resolveEd Tanous5-42/+42
This commit enables the "unused variables" warning in clang. Throughout this, it did point out several issues that would've been functional bugs, so I think it was worthwhile. It also cleaned up several unused variable from old constructs that no longer exist. Tested: Built with clang. Code no longer emits warnings. Downloaded bmcweb to system and pulled up the webui, observed webui loads and logs in properly. Change-Id: I51505f4222cc147d6f2b87b14d7e2ac4a74cafa8 Signed-off-by: Ed Tanous <ed@tanous.net>
2020-08-17Enable clang warningsEd Tanous9-60/+34
This commit enables clang warnings, and fixes all warnings that were found. Most of these fall into a couple categories: Variable shadow issues were fixed by renaming variables unused parameter warnings were resolved by either checking error codes that had been ignored, or removing the name of the variable from the scope. Other various warnings were fixed in the best way I was able to come up with. Note, the redfish Node class is especially insidious, as it causes all imlementers to have variables for parameters, regardless of whether or not they are used. Deprecating the Node class is on my list of things to do, as it adds extra overhead, and in general isn't a useful abstraction. For now, I have simply fixed all the handlers. Tested: Added the current meta-clang meta layer into bblayers.conf, and added TOOLCHAIN_pn-bmcweb = "clang" to my local.conf Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: Ia75b94010359170159c703e535d1c1af182fe700
2020-08-17Remove middlewaresEd Tanous7-347/+43
Middlewares, while kinda cool from an academic standpoint, make our build times even worse than they already are. Given that we only really use 1 real middleware today (token auth) and it needs to move into the parser mode anyway (for security limiting buffer sizes), we might as well use this as an opportunity to delete some code. Some other things that happen: 1. Persistent data now moves out of the crow namespace 2. App is no longer a template 3. All request_routes implementations no longer become templates. This should be a decent (unmeasured) win on compile times. This commit was part of a commit previously called "various cleanups". This separates ONLY the middleware deletion part of that. Note, this also deletes about 400 lines of hard to understand code. Change-Id: I4c19e25491a153a2aa2e4ef46fc797bcb5b3581a Signed-off-by: Ed Tanous <ed@tanous.net>
2020-08-04Remove QueryStringJames Feist3-431/+16
QueryString is an error-prone library that was leftover from crow. Replace it with boost::url, a header only library based and written by the one of the authors of boost beast. Tested: Verified logging paging still worked as expected Change-Id: I47c225089aa7d0f7d2299142f91806294f879381 Signed-off-by: James Feist <james.feist@linux.intel.com>
2020-07-31Revert "Add out of bounds check in base64Decode"James Feist1-28/+6
This reverts commit afd77a536ce84c934f56eae4f69d831fbd238d9a. Reason for revert: Broke basic auth Change-Id: I6510a3f8e1df95daba68b8124e2825c05e923b15 Signed-off-by: James Feist <james.feist@linux.intel.com>
2020-07-31Add out of bounds check in base64DecodeZhikui Ren1-6/+28
Use size_t type and check for out of bounds when index into static const decodingData. Tested: Build with change and BMC web run as before. Signed-off-by: Zhikui Ren <zhikui.ren@intel.com> Change-Id: Ib891d36f79f80b579423b40da493ae6749db5a54
2020-07-29Fix MTLS AuthJames Feist1-35/+1
MTLS Auth was not in the authenticate header, making it authenticate too late now (in handle) as we now authenticate before reading the headers. Move it to the authenticate header. Tested: MTLS in Chrome and via scripting allowed GETs on resources Change-Id: Ia765efd5c588b497de010605b474f6bb886a9dd1 Signed-off-by: James Feist <james.feist@linux.intel.com>
2020-07-24Add back reset body limitGunnar Mills1-0/+2
This fixes a problem we are seeing in CI. Was removed in 3909dc82a003893812f598434d6c4558107afa28. Change-Id: If50b5fcf4e6106bf82be5c410fabe8211c9dec72 Tested: Code update via CI works. Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2020-07-23Add 'reason' message to websocket close methodWludzik, Jozef1-1/+1
Now websocket client receives a proper reason from a server. Removed filling asyncResp from onopen() method from nbdproxy.h because it was redundant. Websocket does not response to client using asyncResp. Removed close from NbdProxyServer destructor because it is always called in onclose() method. Tested: - Mounted and unmounted virtual media using proxy mode few times as administrator with success. - Mounted virtual media using proxy mode as operator and receives proper reason on client side. - Verify if errors are received properly on client side when mounting operation fails. Signed-off-by: Wludzik, Jozef <jozef.wludzik@intel.com> Change-Id: If3b1cc9782de71a0975416872bc2fe8e3824148a
2020-07-22Add read in progress check to timerJames Feist1-3/+13
Add it back so that slow connections can upload images. Tested: Firmware update still works. Change-Id: Ib674252b68297ad473de038069962e9c3202b486 Signed-off-by: James Feist <james.feist@linux.intel.com>
2020-07-20CancelDeadlineTimer after doWriteJames Feist1-0/+2
After doWrite we are no longer in a context where the user can keep the connection open. Cancel the timer. Tested: On a slow connection, still get responses Change-Id: I75a5bb32ccaaae173bb37fe9717b3e63e85c7131 Signed-off-by: James Feist <james.feist@linux.intel.com>
2020-07-16Deprecate the "" operator, and isEqPEd Tanous2-30/+0
While a cool example of how to do string matching in constexpr space, the set of verbs available to HTTP has been fixed for a very long time. This was ported over to beast a while back, but we kept the API for.... mediocre reasons of backward compatibility. Remove that, and delete the now unused code. Tested: Built and loaded on a Witherspoon. Validator passes. Signed-off-by: Ed Tanous <ed.tanous@intel.com> Change-Id: Iaf048e196f9b6e71983189877203bf80390df286 Signed-off-by: James Feist <james.feist@linux.intel.com> Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2020-07-16Rework Authorization flowJames Feist2-38/+103
Currently we parse the whole message before authenticating, allowing an attacker the ability to upload a large image, or keep a connection open for the max amount of time easier than it should be. This moves the authentication to the earliest point possible, and restricts unauthenticated users timeouts and max upload sizes. It also makes it so that unauthenticated users cannot keep the connection alive forever by refusing to close the connection. Tested: - login/logout - firmware update - large POST when unauthenticated - timeouts when unauthenticated - slowhttptest Change-Id: Ifa02d8db04eac1821e8950eb85e71634a9e6d265 Signed-off-by: James Feist <james.feist@linux.intel.com>
2020-07-10Server Name: Rename iBMC to bmcwebGunnar Mills1-1/+1
Before: iBMC server is running, local endpoint [::]:443 Tested: None. Change-Id: I69eae1b34ac2070e7fcbea2d15e21c9a00112c6f Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2020-07-10Codespell spelling fixesGunnar Mills3-3/+3
These spelling errors were found using https://github.com/codespell-project/codespell Tested: Built and ran against validator. Signed-off-by: Gunnar Mills <gmills@us.ibm.com> Change-Id: I214fe102550295578cfdf0fc58305897d261ce55
2020-07-10Spelling: 's/Resposne/Response/g'Gunnar Mills1-3/+3
Tested: Top commit (along with this) was built and ran against validator. Change-Id: I294783208b5016732fde56467ed5629dd5352a3d Signed-off-by: Gunnar Mills <gmills@us.ibm.com>