http_aws_sigv4: improve sigv4 url encoding and canonicalization

Closes #17129
This commit is contained in:
Nigel Brittain 2025-04-27 00:22:23 +00:00 committed by Daniel Stenberg
parent 5763449112
commit c19465ca55
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
11 changed files with 695 additions and 129 deletions

View file

@ -240,7 +240,7 @@ test1933 test1934 test1935 test1936 test1937 test1938 test1939 test1940 \
test1941 test1942 test1943 test1944 test1945 test1946 test1947 test1948 \
test1955 test1956 test1957 test1958 test1959 test1960 test1964 \
test1970 test1971 test1972 test1973 test1974 test1975 test1976 test1977 \
test1978 \
test1978 test1979 test1980 \
\
test2000 test2001 test2002 test2003 test2004 test2005 \
\

22
tests/data/test1979 Normal file
View file

@ -0,0 +1,22 @@
<testcase>
<info>
<keywords>
unittest
canon_string
</keywords>
</info>
#
# Client-side
<client>
<server>
none
</server>
<features>
unittest
</features>
<name>
sigv4 canon_string unit tests
</name>
</client>
</testcase>

22
tests/data/test1980 Normal file
View file

@ -0,0 +1,22 @@
<testcase>
<info>
<keywords>
unittest
canon_query
</keywords>
</info>
#
# Client-side
<client>
<server>
none
</server>
<features>
unittest
</features>
<name>
sigv4 canon_query unit tests
</name>
</client>
</testcase>

View file

@ -39,7 +39,7 @@ aws
aws-sigv4 with query
</name>
<command>
"http://fake.fake.fake:8000/%TESTNUMBER/?name=me%&noval&aim=b%aad&&&weirdo=*.//-" -u user:secret --aws-sigv4 "aws:amz:us-east-2:es" --connect-to fake.fake.fake:8000:%HOSTIP:%HTTPPORT
"http://fake.fake.fake:8000/%TESTNUMBER/?name=me&noval&aim=b%aad&&&weirdo=*.//-" -u user:secret --aws-sigv4 "aws:amz:us-east-2:es" --connect-to fake.fake.fake:8000:%HOSTIP:%HTTPPORT
</command>
</client>
@ -47,9 +47,9 @@ aws-sigv4 with query
# Verify data after the test has been "shot"
<verify>
<protocol crlf="yes">
GET /439/?name=me%&noval&aim=b%aad&&&weirdo=*.//- HTTP/1.1
GET /439/?name=me&noval&aim=b%aad&&&weirdo=*.//- HTTP/1.1
Host: fake.fake.fake:8000
Authorization: AWS4-HMAC-SHA256 Credential=user/19700101/us-east-2/es/aws4_request, SignedHeaders=host;x-amz-date, Signature=cbbf4a72764e27e396730f5e56cea046d4ce862a2d91db4856fb086b92f49270
Authorization: AWS4-HMAC-SHA256 Credential=user/19700101/us-east-2/es/aws4_request, SignedHeaders=host;x-amz-date, Signature=9dd8592929306832a6673d10063491391e486e5f50de4647ea7c2c797277e0a6
X-Amz-Date: 19700101T000000Z
User-Agent: curl/%VERSION
Accept: */*

View file

@ -50,7 +50,7 @@ aws-sigv4 with query
<protocol crlf="yes">
GET /472/a=%e3%81%82 HTTP/1.1
Host: fake.fake.fake:8000
Authorization: AWS4-HMAC-SHA256 Credential=user/19700101/us-east-2/es/aws4_request, SignedHeaders=host;x-amz-date, Signature=c63315c199922f7ee00141869a250389405d19e205057249fb74726d940b1fc3
Authorization: AWS4-HMAC-SHA256 Credential=user/19700101/us-east-2/es/aws4_request, SignedHeaders=host;x-amz-date, Signature=d2f4797c813fc51d729ac555a23ac682be908fdbfae2042ba98d214c9298201b
X-Amz-Date: 19700101T000000Z
User-Agent: curl/%VERSION
Accept: */*

View file

@ -41,6 +41,7 @@ UNITPROGS = unit1300 unit1302 unit1303 unit1304 unit1305 unit1307 \
unit1650 unit1651 unit1652 unit1653 unit1654 unit1655 unit1656 unit1657 \
unit1658 \
unit1660 unit1661 unit1663 unit1664 \
unit1979 unit1980 \
unit2600 unit2601 unit2602 unit2603 unit2604 \
unit3200 \
unit3205 \
@ -132,6 +133,10 @@ unit1663_SOURCES = unit1663.c $(UNITFILES)
unit1664_SOURCES = unit1664.c $(UNITFILES)
unit1979_SOURCES = unit1979.c $(UNITFILES)
unit1980_SOURCES = unit1980.c $(UNITFILES)
unit2600_SOURCES = unit2600.c $(UNITFILES)
unit2601_SOURCES = unit2601.c $(UNITFILES)

145
tests/unit/unit1979.c Normal file
View file

@ -0,0 +1,145 @@
/***************************************************************************
* _ _ ____ _
* Project ___| | | | _ \| |
* / __| | | | |_) | |
* | (__| |_| | _ <| |___
* \___|\___/|_| \_\_____|
*
* Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
*
* This software is licensed as described in the file COPYING, which
* you should have received as part of this distribution. The terms
* are also available at https://curl.se/docs/copyright.html.
*
* You may opt to use, copy, modify, merge, publish, distribute and/or sell
* copies of the Software, and permit persons to whom the Software is
* furnished to do so, under the terms of the COPYING file.
*
* This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
* KIND, either express or implied.
*
* SPDX-License-Identifier: curl
*
***************************************************************************/
#include "curlcheck.h"
#include "http_aws_sigv4.h"
#include "dynbuf.h"
static CURLcode unit_setup(void)
{
return CURLE_OK;
}
static void unit_stop(void)
{
}
UNITTEST_START
#if !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_AWS)
struct testcase
{
const char *testname;
const bool normalize;
const char *url_part;
const char *canonical_url;
};
static const struct testcase testcases[] = {
{
"test-equals-encode",
true,
"/a=b",
"/a%3Db",
},
{
"test-equals-noencode",
false,
"/a=b",
"/a=b",
},
{
"test-s3-tables",
true,
"/tables/arn%3Aaws%3As3tables%3Aus-east-1%3A022954301426%3Abucket%2Fja"
"soehartablebucket/jasoeharnamespace/jasoehartable/encryption",
"/tables/arn%253Aaws%253As3tables%253Aus-east-1%253A022954301426%253Ab"
"ucket%252Fjasoehartablebucket/jasoeharnamespace/jasoehartable/encrypt"
"ion",
},
{
"get-vanilla",
true,
"/",
"/",
},
{
"get-unreserved",
true,
"/-._~0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz",
"/-._~0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz",
},
{
"get-slashes-unnormalized",
false,
"//example//",
"//example//",
},
{
"get-space-normalized",
true,
"/example space/",
"/example%20space/",
},
{
"get-slash-dot-slash-unnormalized",
false,
"/./",
"/./",
},
{
"get-slash-unnormalized",
false,
"//",
"//",
},
{
"get-relative-relative-unnormalized",
false,
"/example1/example2/../..",
"/example1/example2/../..",
}
};
struct dynbuf canonical_path;
char buffer[1024];
char *canonical_path_string;
size_t i;
int result;
int msnprintf_result;
for(i = 0; i < CURL_ARRAYSIZE(testcases); i++) {
curlx_dyn_init(&canonical_path, CURL_MAX_HTTP_HEADER);
result = canon_path(testcases[i].url_part, strlen(testcases[i].url_part),
&canonical_path,
testcases[i].normalize);
canonical_path_string = curlx_dyn_ptr(&canonical_path);
msnprintf_result = curl_msnprintf(buffer, sizeof(buffer),
"%s: Received \"%s\" and should be \"%s\", normalize (%d)",
testcases[i].testname, curlx_dyn_ptr(&canonical_path),
testcases[i].canonical_url, testcases[i].normalize);
fail_unless(msnprintf_result >= 0, "curl_msnprintf fails");
fail_unless(!result && canonical_path_string &&
!strcmp(canonical_path_string,
testcases[i].canonical_url), buffer);
curlx_dyn_free(&canonical_path);
}
#endif /* !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_AWS) */
UNITTEST_STOP

114
tests/unit/unit1980.c Normal file
View file

@ -0,0 +1,114 @@
/***************************************************************************
* _ _ ____ _
* Project ___| | | | _ \| |
* / __| | | | |_) | |
* | (__| |_| | _ <| |___
* \___|\___/|_| \_\_____|
*
* Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
*
* This software is licensed as described in the file COPYING, which
* you should have received as part of this distribution. The terms
* are also available at https://curl.se/docs/copyright.html.
*
* You may opt to use, copy, modify, merge, publish, distribute and/or sell
* copies of the Software, and permit persons to whom the Software is
* furnished to do so, under the terms of the COPYING file.
*
* This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
* KIND, either express or implied.
*
* SPDX-License-Identifier: curl
*
***************************************************************************/
#include "curlcheck.h"
#include "http_aws_sigv4.h"
#include "dynbuf.h"
static CURLcode unit_setup(void)
{
return CURLE_OK;
}
static void unit_stop(void)
{
}
UNITTEST_START
#if !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_AWS)
struct testcase {
const char *testname;
const char *query_part;
const char *canonical_query;
};
static const struct testcase testcases[] = {
{
"no-value",
"Param1=",
"Param1="
},
{
"test-439",
"name=me&noval&aim=b%aad&weirdo=*.//-",
"aim=b%AAd&name=me&noval=&weirdo=%2A.%2F%2F-"
},
{
"blank-query-params",
"hello=a&b&c=&d",
"b=&c=&d=&hello=a"
},
{
"get-vanilla-query-order-key-case",
"Param2=value2&Param1=value1",
"Param1=value1&Param2=value2"
},
{
"get-vanilla-query-unreserved",
"-._~0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz="
"-._~0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz",
"-._~0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz="
"-._~0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz"
},
{
"get-vanilla-empty-query-key",
"Param1=value1",
"Param1=value1"
},
{
"get-vanilla-query-order-encoded",
"Param-3=Value3&Param=Value2&%E1%88%B4=Value1",
"%E1%88%B4=Value1&Param=Value2&Param-3=Value3"
},
};
struct dynbuf canonical_query;
char buffer[1024];
char *canonical_query_ptr;
size_t i;
int result;
int msnprintf_result;
for(i = 0; i < CURL_ARRAYSIZE(testcases); i++) {
curlx_dyn_init(&canonical_query, CURL_MAX_HTTP_HEADER);
result = canon_query(testcases[i].query_part, &canonical_query);
canonical_query_ptr = curlx_dyn_ptr(&canonical_query);
msnprintf_result = curl_msnprintf(buffer, sizeof(buffer),
"%s: Received \"%s\" and should be \"%s\"",
testcases[i].testname, canonical_query_ptr,
testcases[i].canonical_query);
fail_unless(msnprintf_result >= 0, "curl_msnprintf fails");
fail_unless(!result && canonical_query_ptr && !strcmp(canonical_query_ptr,
testcases[i].canonical_query),
buffer);
curlx_dyn_free(&canonical_query);
}
#endif /* !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_AWS) */
UNITTEST_STOP