]>
Commit | Line | Data |
---|---|---|
8000a965 | 1 | /* |
8000a965 | 2 | * DEBUG: section 28 Access Control |
3 | * AUTHOR: Duane Wessels | |
4 | * | |
5 | * SQUID Web Proxy Cache http://www.squid-cache.org/ | |
6 | * ---------------------------------------------------------- | |
7 | * | |
8 | * Squid is the result of efforts by numerous individuals from | |
9 | * the Internet community; see the CONTRIBUTORS file for full | |
10 | * details. Many organizations have provided support for Squid's | |
11 | * development; see the SPONSORS file for full details. Squid is | |
12 | * Copyrighted (C) 2001 by the Regents of the University of | |
13 | * California; see the COPYRIGHT file for full details. Squid | |
14 | * incorporates software developed and/or copyrighted by other | |
15 | * sources; see the CREDITS file for full details. | |
16 | * | |
17 | * This program is free software; you can redistribute it and/or modify | |
18 | * it under the terms of the GNU General Public License as published by | |
19 | * the Free Software Foundation; either version 2 of the License, or | |
20 | * (at your option) any later version. | |
26ac0430 | 21 | * |
8000a965 | 22 | * This program is distributed in the hope that it will be useful, |
23 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
24 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
25 | * GNU General Public License for more details. | |
26ac0430 | 26 | * |
8000a965 | 27 | * You should have received a copy of the GNU General Public License |
28 | * along with this program; if not, write to the Free Software | |
29 | * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111, USA. | |
30 | * | |
31 | * Copyright (c) 2003, Robert Collins <robertc@squid-cache.org> | |
32 | */ | |
33 | ||
582c2af2 | 34 | #include "squid.h" |
c0941a6a AR |
35 | #include "acl/DestinationIp.h" |
36 | #include "acl/FilledChecklist.h" | |
582c2af2 | 37 | #include "client_side.h" |
bfe4e2fe | 38 | #include "comm/Connection.h" |
a2ac85d9 | 39 | #include "HttpRequest.h" |
4d5904f7 | 40 | #include "SquidConfig.h" |
8000a965 | 41 | |
8000a965 | 42 | char const * |
43 | ACLDestinationIP::typeString() const | |
44 | { | |
45 | return "dst"; | |
46 | } | |
47 | ||
48 | int | |
c0941a6a | 49 | ACLDestinationIP::match(ACLChecklist *cl) |
8000a965 | 50 | { |
af6a12ee | 51 | ACLFilledChecklist *checklist = Filled(cl); |
bfe4e2fe AJ |
52 | |
53 | // Bug 3243: CVE 2009-0801 | |
54 | // Bypass of browser same-origin access control in intercepted communication | |
55 | // To resolve this we will force DIRECT and only to the original client destination. | |
56 | // In which case, we also need this ACL to accurately match the destination | |
478a0611 | 57 | if (Config.onoff.client_dst_passthru && (checklist->request->flags.intercepted || checklist->request->flags.spoofClientIp)) { |
bfe4e2fe AJ |
58 | assert(checklist->conn() && checklist->conn()->clientConnection != NULL); |
59 | return ACLIP::match(checklist->conn()->clientConnection->local); | |
60 | } | |
61 | ||
cc192b50 | 62 | const ipcache_addrs *ia = ipcache_gethostbyname(checklist->request->GetHost(), IP_LOOKUP_IF_MISS); |
62e76326 | 63 | |
8000a965 | 64 | if (ia) { |
62e76326 | 65 | /* Entry in cache found */ |
66 | ||
742a021b | 67 | for (int k = 0; k < (int) ia->count; ++k) { |
62e76326 | 68 | if (ACLIP::match(ia->in_addrs[k])) |
69 | return 1; | |
70 | } | |
71 | ||
72 | return 0; | |
450fe1cb | 73 | } else if (!checklist->request->flags.destinationIpLookedUp) { |
62e76326 | 74 | /* No entry in cache, lookup not attempted */ |
cc192b50 | 75 | debugs(28, 3, "aclMatchAcl: Can't yet compare '" << name << "' ACL for '" << checklist->request->GetHost() << "'"); |
62e76326 | 76 | checklist->changeState (DestinationIPLookup::Instance()); |
77 | return 0; | |
8000a965 | 78 | } else { |
656393e2 | 79 | return 0; |
8000a965 | 80 | } |
81 | } | |
82 | ||
83 | DestinationIPLookup DestinationIPLookup::instance_; | |
84 | ||
85 | DestinationIPLookup * | |
86 | DestinationIPLookup::Instance() | |
87 | { | |
88 | return &instance_; | |
89 | } | |
90 | ||
91 | void | |
c0941a6a | 92 | DestinationIPLookup::checkForAsync(ACLChecklist *cl)const |
8000a965 | 93 | { |
af6a12ee | 94 | ACLFilledChecklist *checklist = Filled(cl); |
8000a965 | 95 | checklist->asyncInProgress(true); |
cc192b50 | 96 | ipcache_nbgethostbyname(checklist->request->GetHost(), LookupDone, checklist); |
8000a965 | 97 | } |
98 | ||
99 | void | |
3ff65596 | 100 | DestinationIPLookup::LookupDone(const ipcache_addrs *, const DnsLookupDetails &details, void *data) |
8000a965 | 101 | { |
3ff65596 | 102 | ACLFilledChecklist *checklist = Filled((ACLChecklist*)data); |
8000a965 | 103 | assert (checklist->asyncState() == DestinationIPLookup::Instance()); |
450fe1cb | 104 | checklist->request->flags.destinationIpLookedUp=true; |
3ff65596 | 105 | checklist->request->recordLookup(details); |
8000a965 | 106 | checklist->asyncInProgress(false); |
107 | checklist->changeState (ACLChecklist::NullState::Instance()); | |
2efeb0b7 | 108 | checklist->matchNonBlocking(); |
8000a965 | 109 | } |
110 | ||
8000a965 | 111 | ACL * |
112 | ACLDestinationIP::clone() const | |
113 | { | |
114 | return new ACLDestinationIP(*this); | |
115 | } |