]>
Commit | Line | Data |
---|---|---|
8000a965 | 1 | /* |
2 | * $Id$ | |
3 | * | |
4 | * DEBUG: section 28 Access Control | |
5 | * AUTHOR: Duane Wessels | |
6 | * | |
7 | * SQUID Web Proxy Cache http://www.squid-cache.org/ | |
8 | * ---------------------------------------------------------- | |
9 | * | |
10 | * Squid is the result of efforts by numerous individuals from | |
11 | * the Internet community; see the CONTRIBUTORS file for full | |
12 | * details. Many organizations have provided support for Squid's | |
13 | * development; see the SPONSORS file for full details. Squid is | |
14 | * Copyrighted (C) 2001 by the Regents of the University of | |
15 | * California; see the COPYRIGHT file for full details. Squid | |
16 | * incorporates software developed and/or copyrighted by other | |
17 | * sources; see the CREDITS file for full details. | |
18 | * | |
19 | * This program is free software; you can redistribute it and/or modify | |
20 | * it under the terms of the GNU General Public License as published by | |
21 | * the Free Software Foundation; either version 2 of the License, or | |
22 | * (at your option) any later version. | |
26ac0430 | 23 | * |
8000a965 | 24 | * This program is distributed in the hope that it will be useful, |
25 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
26 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
27 | * GNU General Public License for more details. | |
26ac0430 | 28 | * |
8000a965 | 29 | * You should have received a copy of the GNU General Public License |
30 | * along with this program; if not, write to the Free Software | |
31 | * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111, USA. | |
32 | * | |
33 | * Copyright (c) 2003, Robert Collins <robertc@squid-cache.org> | |
34 | */ | |
35 | ||
582c2af2 | 36 | #include "squid.h" |
c0941a6a AR |
37 | #include "acl/DestinationIp.h" |
38 | #include "acl/FilledChecklist.h" | |
582c2af2 | 39 | #include "client_side.h" |
bfe4e2fe | 40 | #include "comm/Connection.h" |
a2ac85d9 | 41 | #include "HttpRequest.h" |
bfe4e2fe | 42 | #include "structs.h" |
8000a965 | 43 | |
8000a965 | 44 | char const * |
45 | ACLDestinationIP::typeString() const | |
46 | { | |
47 | return "dst"; | |
48 | } | |
49 | ||
50 | int | |
c0941a6a | 51 | ACLDestinationIP::match(ACLChecklist *cl) |
8000a965 | 52 | { |
af6a12ee | 53 | ACLFilledChecklist *checklist = Filled(cl); |
bfe4e2fe AJ |
54 | |
55 | // Bug 3243: CVE 2009-0801 | |
56 | // Bypass of browser same-origin access control in intercepted communication | |
57 | // To resolve this we will force DIRECT and only to the original client destination. | |
58 | // In which case, we also need this ACL to accurately match the destination | |
59 | if (Config.onoff.client_dst_passthru && checklist->request && | |
60 | (checklist->request->flags.intercepted || checklist->request->flags.spoof_client_ip)) { | |
61 | assert(checklist->conn() && checklist->conn()->clientConnection != NULL); | |
62 | return ACLIP::match(checklist->conn()->clientConnection->local); | |
63 | } | |
64 | ||
cc192b50 | 65 | const ipcache_addrs *ia = ipcache_gethostbyname(checklist->request->GetHost(), IP_LOOKUP_IF_MISS); |
62e76326 | 66 | |
8000a965 | 67 | if (ia) { |
62e76326 | 68 | /* Entry in cache found */ |
69 | ||
742a021b | 70 | for (int k = 0; k < (int) ia->count; ++k) { |
62e76326 | 71 | if (ACLIP::match(ia->in_addrs[k])) |
72 | return 1; | |
73 | } | |
74 | ||
75 | return 0; | |
8000a965 | 76 | } else if (!checklist->request->flags.destinationIPLookedUp()) { |
62e76326 | 77 | /* No entry in cache, lookup not attempted */ |
cc192b50 | 78 | debugs(28, 3, "aclMatchAcl: Can't yet compare '" << name << "' ACL for '" << checklist->request->GetHost() << "'"); |
62e76326 | 79 | checklist->changeState (DestinationIPLookup::Instance()); |
80 | return 0; | |
8000a965 | 81 | } else { |
656393e2 | 82 | return 0; |
8000a965 | 83 | } |
84 | } | |
85 | ||
86 | DestinationIPLookup DestinationIPLookup::instance_; | |
87 | ||
88 | DestinationIPLookup * | |
89 | DestinationIPLookup::Instance() | |
90 | { | |
91 | return &instance_; | |
92 | } | |
93 | ||
94 | void | |
c0941a6a | 95 | DestinationIPLookup::checkForAsync(ACLChecklist *cl)const |
8000a965 | 96 | { |
af6a12ee | 97 | ACLFilledChecklist *checklist = Filled(cl); |
8000a965 | 98 | checklist->asyncInProgress(true); |
cc192b50 | 99 | ipcache_nbgethostbyname(checklist->request->GetHost(), LookupDone, checklist); |
8000a965 | 100 | } |
101 | ||
102 | void | |
3ff65596 | 103 | DestinationIPLookup::LookupDone(const ipcache_addrs *, const DnsLookupDetails &details, void *data) |
8000a965 | 104 | { |
3ff65596 | 105 | ACLFilledChecklist *checklist = Filled((ACLChecklist*)data); |
8000a965 | 106 | assert (checklist->asyncState() == DestinationIPLookup::Instance()); |
3ff65596 AR |
107 | checklist->request->flags.destinationIPLookupCompleted(); |
108 | checklist->request->recordLookup(details); | |
8000a965 | 109 | checklist->asyncInProgress(false); |
110 | checklist->changeState (ACLChecklist::NullState::Instance()); | |
2efeb0b7 | 111 | checklist->matchNonBlocking(); |
8000a965 | 112 | } |
113 | ||
8000a965 | 114 | |
8000a965 | 115 | |
116 | ACL * | |
117 | ACLDestinationIP::clone() const | |
118 | { | |
119 | return new ACLDestinationIP(*this); | |
120 | } |