2021-05-21 19:36:51 +02:00
|
|
|
<?php
|
|
|
|
/**
|
|
|
|
* @copyright Copyright (C) 2010-2021, the Friendica project
|
|
|
|
*
|
|
|
|
* @license GNU AGPL version 3 or any later version
|
|
|
|
*
|
|
|
|
* This program is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU Affero General Public License as
|
|
|
|
* published by the Free Software Foundation, either version 3 of the
|
|
|
|
* License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU Affero General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Affero General Public License
|
|
|
|
* along with this program. If not, see <https://www.gnu.org/licenses/>.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
|
|
|
namespace Friendica\Util;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Derived from the work of Reid Johnson <https://codereview.stackexchange.com/users/4020/reid-johnson>
|
|
|
|
* @see https://codereview.stackexchange.com/questions/69882/parsing-multipart-form-data-in-php-for-put-requests
|
|
|
|
*/
|
|
|
|
class HTTPInputData
|
|
|
|
{
|
2021-11-28 14:01:13 +01:00
|
|
|
/** @var array The $_SERVER variable */
|
|
|
|
protected $server;
|
|
|
|
|
|
|
|
public function __construct(array $server)
|
|
|
|
{
|
|
|
|
$this->server = $server;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Process the PHP input stream and creates an array with its content
|
|
|
|
*
|
|
|
|
* @return array|array[]
|
|
|
|
*/
|
|
|
|
public function process(): array
|
2021-05-21 19:36:51 +02:00
|
|
|
{
|
2021-11-28 14:01:13 +01:00
|
|
|
$content_parts = explode(';', $this->server['CONTENT_TYPE'] ?? 'application/x-www-form-urlencoded');
|
2021-05-21 19:36:51 +02:00
|
|
|
|
|
|
|
$boundary = '';
|
|
|
|
$encoding = '';
|
|
|
|
|
|
|
|
$content_type = array_shift($content_parts);
|
|
|
|
|
|
|
|
foreach ($content_parts as $part) {
|
|
|
|
if (strpos($part, 'boundary') !== false) {
|
|
|
|
$part = explode('=', $part, 2);
|
|
|
|
if (!empty($part[1])) {
|
|
|
|
$boundary = '--' . $part[1];
|
|
|
|
}
|
|
|
|
} elseif (strpos($part, 'charset') !== false) {
|
|
|
|
$part = explode('=', $part, 2);
|
|
|
|
if (!empty($part[1])) {
|
|
|
|
$encoding = $part[1];
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if ($boundary !== '' && $encoding !== '') {
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if ($content_type == 'multipart/form-data') {
|
2021-11-28 14:01:13 +01:00
|
|
|
return $this->fetchFromMultipart($boundary);
|
2021-05-21 19:36:51 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// can be handled by built in PHP functionality
|
2021-05-23 19:58:09 +02:00
|
|
|
$content = static::getPhpInputContent();
|
2021-05-21 19:36:51 +02:00
|
|
|
|
2021-05-24 07:22:25 +02:00
|
|
|
$variables = json_decode($content, true);
|
2021-05-21 19:36:51 +02:00
|
|
|
|
|
|
|
if (empty($variables)) {
|
|
|
|
parse_str($content, $variables);
|
|
|
|
}
|
|
|
|
|
|
|
|
return ['variables' => $variables, 'files' => []];
|
|
|
|
}
|
|
|
|
|
2021-11-28 14:01:13 +01:00
|
|
|
private function fetchFromMultipart(string $boundary): array
|
2021-05-21 19:36:51 +02:00
|
|
|
{
|
|
|
|
$result = ['variables' => [], 'files' => []];
|
|
|
|
|
2021-05-23 19:58:09 +02:00
|
|
|
$stream = static::getPhpInputStream();
|
2021-05-21 19:36:51 +02:00
|
|
|
|
|
|
|
$sanity = fgets($stream, strlen($boundary) + 5);
|
|
|
|
|
|
|
|
// malformed file, boundary should be first item
|
|
|
|
if (rtrim($sanity) !== $boundary) {
|
|
|
|
return $result;
|
|
|
|
}
|
|
|
|
|
|
|
|
$raw_headers = '';
|
|
|
|
|
|
|
|
while (($chunk = fgets($stream)) !== false) {
|
|
|
|
if ($chunk === $boundary) {
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!empty(trim($chunk))) {
|
|
|
|
$raw_headers .= $chunk;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
2021-11-28 14:01:13 +01:00
|
|
|
$result = $this->parseRawHeader($stream, $raw_headers, $boundary, $result);
|
2021-05-22 22:29:15 +02:00
|
|
|
|
2021-05-21 19:36:51 +02:00
|
|
|
$raw_headers = '';
|
|
|
|
}
|
|
|
|
|
|
|
|
fclose($stream);
|
|
|
|
|
|
|
|
return $result;
|
|
|
|
}
|
|
|
|
|
2021-11-28 14:01:13 +01:00
|
|
|
private function parseRawHeader($stream, string $raw_headers, string $boundary, array $result)
|
2021-05-21 19:36:51 +02:00
|
|
|
{
|
|
|
|
$variables = $result['variables'];
|
|
|
|
$files = $result['files'];
|
|
|
|
|
|
|
|
$headers = [];
|
|
|
|
|
|
|
|
foreach (explode("\r\n", $raw_headers) as $header) {
|
|
|
|
if (strpos($header, ':') === false) {
|
|
|
|
continue;
|
|
|
|
}
|
2021-11-28 14:01:13 +01:00
|
|
|
[$name, $value] = explode(':', $header, 2);
|
2021-05-22 22:29:15 +02:00
|
|
|
|
2021-05-21 19:36:51 +02:00
|
|
|
$headers[strtolower($name)] = ltrim($value, ' ');
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!isset($headers['content-disposition'])) {
|
|
|
|
return ['variables' => $variables, 'files' => $files];
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!preg_match('/^(.+); *name="([^"]+)"(; *filename="([^"]+)")?/', $headers['content-disposition'], $matches)) {
|
|
|
|
return ['variables' => $variables, 'files' => $files];
|
|
|
|
}
|
|
|
|
|
|
|
|
$name = $matches[2];
|
|
|
|
$filename = $matches[4] ?? '';
|
|
|
|
|
|
|
|
if (!empty($filename)) {
|
2021-05-24 10:08:01 +02:00
|
|
|
$files[$name] = static::fetchFileData($stream, $boundary, $headers, $filename);
|
2021-05-21 19:36:51 +02:00
|
|
|
return ['variables' => $variables, 'files' => $files];
|
|
|
|
} else {
|
2021-11-28 14:01:13 +01:00
|
|
|
$variables = $this->fetchVariables($stream, $boundary, $headers, $name, $variables);
|
2021-05-21 19:36:51 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
return ['variables' => $variables, 'files' => $files];
|
|
|
|
}
|
|
|
|
|
2021-11-28 14:01:13 +01:00
|
|
|
protected function fetchFileData($stream, string $boundary, array $headers, string $filename)
|
2021-05-21 19:36:51 +02:00
|
|
|
{
|
|
|
|
$error = UPLOAD_ERR_OK;
|
|
|
|
|
|
|
|
if (isset($headers['content-type'])) {
|
|
|
|
$tmp = explode(';', $headers['content-type']);
|
2021-05-22 22:29:15 +02:00
|
|
|
|
2021-05-21 19:36:51 +02:00
|
|
|
$contentType = $tmp[0];
|
|
|
|
} else {
|
|
|
|
$contentType = 'unknown';
|
|
|
|
}
|
|
|
|
|
|
|
|
$tmpnam = tempnam(ini_get('upload_tmp_dir'), 'php');
|
|
|
|
$fileHandle = fopen($tmpnam, 'wb');
|
|
|
|
|
|
|
|
if ($fileHandle === false) {
|
|
|
|
$error = UPLOAD_ERR_CANT_WRITE;
|
|
|
|
} else {
|
2021-05-22 22:31:50 +02:00
|
|
|
$lastLine = null;
|
2021-05-21 19:36:51 +02:00
|
|
|
while (($chunk = fgets($stream, 8096)) !== false && strpos($chunk, $boundary) !== 0) {
|
2021-05-22 22:31:50 +02:00
|
|
|
if ($lastLine !== null) {
|
2021-05-25 20:21:51 +02:00
|
|
|
if (!fwrite($fileHandle, $lastLine)) {
|
2021-05-21 19:36:51 +02:00
|
|
|
$error = UPLOAD_ERR_CANT_WRITE;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
$lastLine = $chunk;
|
|
|
|
}
|
|
|
|
|
2021-05-22 22:31:50 +02:00
|
|
|
if ($lastLine !== null && $error !== UPLOAD_ERR_CANT_WRITE) {
|
2021-05-25 20:21:51 +02:00
|
|
|
if (!fwrite($fileHandle, rtrim($lastLine, "\r\n"))) {
|
2021-05-21 19:36:51 +02:00
|
|
|
$error = UPLOAD_ERR_CANT_WRITE;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return [
|
|
|
|
'name' => $filename,
|
|
|
|
'type' => $contentType,
|
|
|
|
'tmp_name' => $tmpnam,
|
|
|
|
'error' => $error,
|
|
|
|
'size' => filesize($tmpnam)
|
|
|
|
];
|
|
|
|
}
|
|
|
|
|
2021-11-28 14:01:13 +01:00
|
|
|
private function fetchVariables($stream, string $boundary, array $headers, string $name, array $variables)
|
2021-05-21 19:36:51 +02:00
|
|
|
{
|
|
|
|
$fullValue = '';
|
2021-05-22 22:31:50 +02:00
|
|
|
$lastLine = null;
|
2021-05-21 19:36:51 +02:00
|
|
|
|
|
|
|
while (($chunk = fgets($stream)) !== false && strpos($chunk, $boundary) !== 0) {
|
2021-05-22 22:31:50 +02:00
|
|
|
if ($lastLine !== null) {
|
2021-05-21 19:36:51 +02:00
|
|
|
$fullValue .= $lastLine;
|
|
|
|
}
|
|
|
|
|
|
|
|
$lastLine = $chunk;
|
|
|
|
}
|
|
|
|
|
2021-05-22 22:31:50 +02:00
|
|
|
if ($lastLine !== null) {
|
2021-05-21 19:36:51 +02:00
|
|
|
$fullValue .= rtrim($lastLine, "\r\n");
|
|
|
|
}
|
|
|
|
|
|
|
|
if (isset($headers['content-type'])) {
|
|
|
|
$encoding = '';
|
|
|
|
|
|
|
|
foreach (explode(';', $headers['content-type']) as $part) {
|
|
|
|
if (strpos($part, 'charset') !== false) {
|
|
|
|
$part = explode($part, '=', 2);
|
|
|
|
if (isset($part[1])) {
|
|
|
|
$encoding = $part[1];
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if ($encoding !== '' && strtoupper($encoding) !== 'UTF-8' && strtoupper($encoding) !== 'UTF8') {
|
2021-05-22 22:29:15 +02:00
|
|
|
$tmp = mb_convert_encoding($fullValue, 'UTF-8', $encoding);
|
|
|
|
if ($tmp !== false) {
|
|
|
|
$fullValue = $tmp;
|
|
|
|
}
|
2021-05-21 19:36:51 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
$fullValue = $name . '=' . $fullValue;
|
|
|
|
|
|
|
|
$tmp = [];
|
|
|
|
parse_str($fullValue, $tmp);
|
|
|
|
|
2021-11-28 14:01:13 +01:00
|
|
|
return $this->expandVariables(explode('[', $name), $variables, $tmp);
|
2021-05-21 19:36:51 +02:00
|
|
|
}
|
|
|
|
|
2021-11-28 14:01:13 +01:00
|
|
|
private function expandVariables(array $names, $variables, array $values)
|
2021-05-21 19:36:51 +02:00
|
|
|
{
|
|
|
|
if (!is_array($variables)) {
|
|
|
|
return $values;
|
|
|
|
}
|
|
|
|
|
|
|
|
$name = rtrim(array_shift($names), ']');
|
|
|
|
if ($name !== '') {
|
|
|
|
$name = $name . '=p';
|
|
|
|
|
|
|
|
$tmp = [];
|
|
|
|
parse_str($name, $tmp);
|
|
|
|
|
|
|
|
$tmp = array_keys($tmp);
|
|
|
|
$name = reset($tmp);
|
|
|
|
}
|
|
|
|
|
|
|
|
if ($name === '') {
|
|
|
|
$variables[] = reset($values);
|
|
|
|
} elseif (isset($variables[$name]) && isset($values[$name])) {
|
2021-11-28 14:01:13 +01:00
|
|
|
$variables[$name] = $this->expandVariables($names, $variables[$name], $values[$name]);
|
2021-05-21 19:36:51 +02:00
|
|
|
} elseif (isset($values[$name])) {
|
|
|
|
$variables[$name] = $values[$name];
|
|
|
|
}
|
|
|
|
|
|
|
|
return $variables;
|
|
|
|
}
|
2021-05-23 19:58:09 +02:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Returns the current PHP input stream
|
|
|
|
* Mainly used for test doubling
|
2021-05-23 22:40:41 +02:00
|
|
|
*
|
2021-05-23 19:58:09 +02:00
|
|
|
* @return false|resource
|
|
|
|
*/
|
2021-11-28 14:01:13 +01:00
|
|
|
protected function getPhpInputStream()
|
2021-05-23 19:58:09 +02:00
|
|
|
{
|
|
|
|
return fopen('php://input', 'rb');
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2021-05-23 20:30:27 +02:00
|
|
|
* Returns the content of the current PHP input
|
2021-05-23 19:58:09 +02:00
|
|
|
* Mainly used for test doubling
|
2021-05-23 22:40:41 +02:00
|
|
|
*
|
2021-05-23 19:58:09 +02:00
|
|
|
* @return false|string
|
|
|
|
*/
|
2021-11-28 14:01:13 +01:00
|
|
|
protected function getPhpInputContent()
|
2021-05-23 19:58:09 +02:00
|
|
|
{
|
|
|
|
return file_get_contents('php://input');
|
|
|
|
}
|
2021-05-21 19:36:51 +02:00
|
|
|
}
|