www-cgi/: Decentralize the whitelist of environment variables.
[userv-utils] / www-cgi / ucgi.c
1 /*
2 * Usage: as CGI script
3 */
4 /*
5 * Copyright (C) 1998-1999,2003 Ian Jackson
6 *
7 * This is free software; you can redistribute it and/or modify it
8 * under the terms of the GNU General Public License as published by
9 * the Free Software Foundation; either version 2 of the License, or
10 * (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful, but
13 * WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with userv-utils; if not, write to the Free Software
19 * Foundation, 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
20 *
21 * $Id$
22 */
23
24 #include <stdio.h>
25 #include <string.h>
26 #include <ctype.h>
27 #include <unistd.h>
28 #include <sys/types.h>
29 #include <sys/wait.h>
30
31 #include "ucgi.h"
32
33 static const char *const envok[] = {
34 "AUTH_TYPE",
35 "CONTENT_TYPE",
36 "CONTENT_LENGTH",
37 "DOCUMENT_ROOT",
38 "GATEWAY_INTERFACE",
39 "HTTP_*",
40 "HTTPS",
41 "PATH_INFO",
42 "PATH_TRANSLATED",
43 "QUERY_STRING",
44 "REMOTE_*",
45 "REQUEST_METHOD",
46 "REQUEST_URI",
47 "SCRIPT_*",
48 "SERVER_*",
49 0
50 };
51
52 struct buildargs {
53 const char **v;
54 int n, max;
55 };
56
57 static void addarg(struct buildargs *args, const char *a) {
58 if (args->n > args->max) error("too many arguments");
59 args->v[args->n++]= a;
60 }
61
62 static void add_userv_var(const char *fulln,
63 const char *en, const char *ev, void *p) {
64 struct buildargs *args= p;
65 size_t l;
66 char *a;
67
68 l= strlen(ev); if (l > MAX_ENVVAR_VALUE) error("environment variable too long");
69 a= xmalloc(strlen(en)+l+6);
70 sprintf(a,"-DE_%s=%s",en,ev);
71 addarg(args, a);
72 }
73
74 int main(int argc, const char **argv) {
75 char *username;
76 const char *slash2, *pathi, *av;
77 size_t usernamelen, l;
78 struct buildargs args;
79 pid_t child, rchild;
80 int status;
81
82 l= strlen(argv[0]);
83 if (l>6 && !strcmp(argv[0]+l-6,"-debug")) debugmode= 1;
84
85 if (debugmode) {
86 if (fputs("Content-Type: text/plain\n\n",stdout)==EOF || fflush(stdout))
87 syserror("write stdout");
88 if (dup2(1,2)<0) { perror("dup stdout to stderr"); exit(-1); }
89 D( printf(";;; UCGI\n"); )
90 }
91
92 if (argc > MAX_ARGS) error("too many arguments");
93
94 pathi= getenv("PATH_INFO");
95 if (!pathi) error("PATH_INFO not found");
96 D( if (debugmode) {
97 printf(";; find user name...\n"
98 ";; initial PATH_INFO = `%s'\n",
99 pathi);
100 } )
101 if (pathi[0] != '/' || pathi[1] != '~') error("PATH_INFO must start with /~");
102 slash2= strchr(pathi+2,'/'); if (!slash2) error("PATH_INFO must have more than one /");
103 usernamelen= slash2-(pathi+2);
104 if (usernamelen > MAX_USERNAME_LEN) error("PATH_INFO username too long");
105 username= xmalloc(usernamelen+1);
106 memcpy(username,pathi+2,usernamelen); username[usernamelen]= 0;
107 D( if (debugmode)
108 printf(";; user = `%s'; tail = `%s'\n", username, slash2); )
109 if (!isalpha(username[0])) error("username 1st character is not alphabetic");
110 xsetenv("PATH_INFO",slash2,1);
111
112 args.n= 0; args.max= argc + MAX_ENVVARS + 10;
113 args.v= xmalloc(args.max * sizeof(*args.v));
114
115 addarg(&args, "userv");
116 if (debugmode) addarg(&args, "-DDEBUG=1");
117
118 filter_environment(FILTF_WILDCARD, "", envok, add_userv_var, &args);
119
120 addarg(&args, username);
121 addarg(&args, "www-cgi");
122 while ((av= (*++argv))) addarg(&args, av);
123 addarg(&args, 0);
124
125 if (debugmode) {
126 D( fflush(stdout); )
127 child= fork(); if (child==-1) syserror("fork");
128 if (child) {
129 rchild= waitpid(child,&status,0);
130 if (rchild==-1) syserror("waitpid");
131 printf("\nexit status %d %d\n",(status>>8)&0x0ff,status&0x0ff);
132 exit(0);
133 }
134 }
135
136 D( if (debugmode) {
137 int i;
138
139 printf(";; final command line...\n");
140 for (i = 0; args.v[i]; i++)
141 printf(";; %s\n", args.v[i]);
142 fflush(stdout);
143 } )
144
145 execvp("userv",(char*const*)args.v);
146 syserror("exec userv");
147 return -1;
148 }