]>
Commit | Line | Data |
---|---|---|
8000a965 | 1 | /* |
8000a965 | 2 | * DEBUG: section 28 Access Control |
3 | * AUTHOR: Duane Wessels | |
4 | * | |
5 | * SQUID Web Proxy Cache http://www.squid-cache.org/ | |
6 | * ---------------------------------------------------------- | |
7 | * | |
8 | * Squid is the result of efforts by numerous individuals from | |
9 | * the Internet community; see the CONTRIBUTORS file for full | |
10 | * details. Many organizations have provided support for Squid's | |
11 | * development; see the SPONSORS file for full details. Squid is | |
12 | * Copyrighted (C) 2001 by the Regents of the University of | |
13 | * California; see the COPYRIGHT file for full details. Squid | |
14 | * incorporates software developed and/or copyrighted by other | |
15 | * sources; see the CREDITS file for full details. | |
16 | * | |
17 | * This program is free software; you can redistribute it and/or modify | |
18 | * it under the terms of the GNU General Public License as published by | |
19 | * the Free Software Foundation; either version 2 of the License, or | |
20 | * (at your option) any later version. | |
26ac0430 | 21 | * |
8000a965 | 22 | * This program is distributed in the hope that it will be useful, |
23 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
24 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
25 | * GNU General Public License for more details. | |
26ac0430 | 26 | * |
8000a965 | 27 | * You should have received a copy of the GNU General Public License |
28 | * along with this program; if not, write to the Free Software | |
29 | * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111, USA. | |
30 | * | |
31 | * Copyright (c) 2003, Robert Collins <robertc@squid-cache.org> | |
32 | */ | |
33 | ||
582c2af2 | 34 | #include "squid.h" |
c0941a6a AR |
35 | #include "acl/DestinationIp.h" |
36 | #include "acl/FilledChecklist.h" | |
582c2af2 | 37 | #include "client_side.h" |
bfe4e2fe | 38 | #include "comm/Connection.h" |
a2ac85d9 | 39 | #include "HttpRequest.h" |
bfe4e2fe | 40 | #include "structs.h" |
8000a965 | 41 | |
8000a965 | 42 | char const * |
43 | ACLDestinationIP::typeString() const | |
44 | { | |
45 | return "dst"; | |
46 | } | |
47 | ||
48 | int | |
c0941a6a | 49 | ACLDestinationIP::match(ACLChecklist *cl) |
8000a965 | 50 | { |
af6a12ee | 51 | ACLFilledChecklist *checklist = Filled(cl); |
bfe4e2fe AJ |
52 | |
53 | // Bug 3243: CVE 2009-0801 | |
54 | // Bypass of browser same-origin access control in intercepted communication | |
55 | // To resolve this we will force DIRECT and only to the original client destination. | |
56 | // In which case, we also need this ACL to accurately match the destination | |
57 | if (Config.onoff.client_dst_passthru && checklist->request && | |
58 | (checklist->request->flags.intercepted || checklist->request->flags.spoof_client_ip)) { | |
59 | assert(checklist->conn() && checklist->conn()->clientConnection != NULL); | |
60 | return ACLIP::match(checklist->conn()->clientConnection->local); | |
61 | } | |
62 | ||
cc192b50 | 63 | const ipcache_addrs *ia = ipcache_gethostbyname(checklist->request->GetHost(), IP_LOOKUP_IF_MISS); |
62e76326 | 64 | |
8000a965 | 65 | if (ia) { |
62e76326 | 66 | /* Entry in cache found */ |
67 | ||
742a021b | 68 | for (int k = 0; k < (int) ia->count; ++k) { |
62e76326 | 69 | if (ACLIP::match(ia->in_addrs[k])) |
70 | return 1; | |
71 | } | |
72 | ||
73 | return 0; | |
8000a965 | 74 | } else if (!checklist->request->flags.destinationIPLookedUp()) { |
62e76326 | 75 | /* No entry in cache, lookup not attempted */ |
cc192b50 | 76 | debugs(28, 3, "aclMatchAcl: Can't yet compare '" << name << "' ACL for '" << checklist->request->GetHost() << "'"); |
62e76326 | 77 | checklist->changeState (DestinationIPLookup::Instance()); |
78 | return 0; | |
8000a965 | 79 | } else { |
656393e2 | 80 | return 0; |
8000a965 | 81 | } |
82 | } | |
83 | ||
84 | DestinationIPLookup DestinationIPLookup::instance_; | |
85 | ||
86 | DestinationIPLookup * | |
87 | DestinationIPLookup::Instance() | |
88 | { | |
89 | return &instance_; | |
90 | } | |
91 | ||
92 | void | |
c0941a6a | 93 | DestinationIPLookup::checkForAsync(ACLChecklist *cl)const |
8000a965 | 94 | { |
af6a12ee | 95 | ACLFilledChecklist *checklist = Filled(cl); |
8000a965 | 96 | checklist->asyncInProgress(true); |
cc192b50 | 97 | ipcache_nbgethostbyname(checklist->request->GetHost(), LookupDone, checklist); |
8000a965 | 98 | } |
99 | ||
100 | void | |
3ff65596 | 101 | DestinationIPLookup::LookupDone(const ipcache_addrs *, const DnsLookupDetails &details, void *data) |
8000a965 | 102 | { |
3ff65596 | 103 | ACLFilledChecklist *checklist = Filled((ACLChecklist*)data); |
8000a965 | 104 | assert (checklist->asyncState() == DestinationIPLookup::Instance()); |
3ff65596 AR |
105 | checklist->request->flags.destinationIPLookupCompleted(); |
106 | checklist->request->recordLookup(details); | |
8000a965 | 107 | checklist->asyncInProgress(false); |
108 | checklist->changeState (ACLChecklist::NullState::Instance()); | |
2efeb0b7 | 109 | checklist->matchNonBlocking(); |
8000a965 | 110 | } |
111 | ||
8000a965 | 112 | ACL * |
113 | ACLDestinationIP::clone() const | |
114 | { | |
115 | return new ACLDestinationIP(*this); | |
116 | } |