Thu, 22 Jan 2015 13:21:57 +0100
Incorporate requested changes from Mozilla in review:
https://bugzilla.mozilla.org/show_bug.cgi?id=1123480#c6
michael@0 | 1 | /* |
michael@0 | 2 | * ==================================================================== |
michael@0 | 3 | * Licensed to the Apache Software Foundation (ASF) under one |
michael@0 | 4 | * or more contributor license agreements. See the NOTICE file |
michael@0 | 5 | * distributed with this work for additional information |
michael@0 | 6 | * regarding copyright ownership. The ASF licenses this file |
michael@0 | 7 | * to you under the Apache License, Version 2.0 (the |
michael@0 | 8 | * "License"); you may not use this file except in compliance |
michael@0 | 9 | * with the License. You may obtain a copy of the License at |
michael@0 | 10 | * |
michael@0 | 11 | * http://www.apache.org/licenses/LICENSE-2.0 |
michael@0 | 12 | * |
michael@0 | 13 | * Unless required by applicable law or agreed to in writing, |
michael@0 | 14 | * software distributed under the License is distributed on an |
michael@0 | 15 | * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY |
michael@0 | 16 | * KIND, either express or implied. See the License for the |
michael@0 | 17 | * specific language governing permissions and limitations |
michael@0 | 18 | * under the License. |
michael@0 | 19 | * ==================================================================== |
michael@0 | 20 | * |
michael@0 | 21 | * This software consists of voluntary contributions made by many |
michael@0 | 22 | * individuals on behalf of the Apache Software Foundation. For more |
michael@0 | 23 | * information on the Apache Software Foundation, please see |
michael@0 | 24 | * <http://www.apache.org/>. |
michael@0 | 25 | * |
michael@0 | 26 | */ |
michael@0 | 27 | package ch.boye.httpclientandroidlib.impl.cookie; |
michael@0 | 28 | |
michael@0 | 29 | import ch.boye.httpclientandroidlib.annotation.Immutable; |
michael@0 | 30 | |
michael@0 | 31 | import ch.boye.httpclientandroidlib.cookie.Cookie; |
michael@0 | 32 | import ch.boye.httpclientandroidlib.cookie.CookieAttributeHandler; |
michael@0 | 33 | import ch.boye.httpclientandroidlib.cookie.CookieOrigin; |
michael@0 | 34 | import ch.boye.httpclientandroidlib.cookie.CookieRestrictionViolationException; |
michael@0 | 35 | import ch.boye.httpclientandroidlib.cookie.MalformedCookieException; |
michael@0 | 36 | import ch.boye.httpclientandroidlib.cookie.SetCookie; |
michael@0 | 37 | |
michael@0 | 38 | /** |
michael@0 | 39 | * |
michael@0 | 40 | * @since 4.0 |
michael@0 | 41 | */ |
michael@0 | 42 | @Immutable |
michael@0 | 43 | public class BasicDomainHandler implements CookieAttributeHandler { |
michael@0 | 44 | |
michael@0 | 45 | public BasicDomainHandler() { |
michael@0 | 46 | super(); |
michael@0 | 47 | } |
michael@0 | 48 | |
michael@0 | 49 | public void parse(final SetCookie cookie, final String value) |
michael@0 | 50 | throws MalformedCookieException { |
michael@0 | 51 | if (cookie == null) { |
michael@0 | 52 | throw new IllegalArgumentException("Cookie may not be null"); |
michael@0 | 53 | } |
michael@0 | 54 | if (value == null) { |
michael@0 | 55 | throw new MalformedCookieException("Missing value for domain attribute"); |
michael@0 | 56 | } |
michael@0 | 57 | if (value.trim().length() == 0) { |
michael@0 | 58 | throw new MalformedCookieException("Blank value for domain attribute"); |
michael@0 | 59 | } |
michael@0 | 60 | cookie.setDomain(value); |
michael@0 | 61 | } |
michael@0 | 62 | |
michael@0 | 63 | public void validate(final Cookie cookie, final CookieOrigin origin) |
michael@0 | 64 | throws MalformedCookieException { |
michael@0 | 65 | if (cookie == null) { |
michael@0 | 66 | throw new IllegalArgumentException("Cookie may not be null"); |
michael@0 | 67 | } |
michael@0 | 68 | if (origin == null) { |
michael@0 | 69 | throw new IllegalArgumentException("Cookie origin may not be null"); |
michael@0 | 70 | } |
michael@0 | 71 | // Validate the cookies domain attribute. NOTE: Domains without |
michael@0 | 72 | // any dots are allowed to support hosts on private LANs that don't |
michael@0 | 73 | // have DNS names. Since they have no dots, to domain-match the |
michael@0 | 74 | // request-host and domain must be identical for the cookie to sent |
michael@0 | 75 | // back to the origin-server. |
michael@0 | 76 | String host = origin.getHost(); |
michael@0 | 77 | String domain = cookie.getDomain(); |
michael@0 | 78 | if (domain == null) { |
michael@0 | 79 | throw new CookieRestrictionViolationException("Cookie domain may not be null"); |
michael@0 | 80 | } |
michael@0 | 81 | if (host.contains(".")) { |
michael@0 | 82 | // Not required to have at least two dots. RFC 2965. |
michael@0 | 83 | // A Set-Cookie2 with Domain=ajax.com will be accepted. |
michael@0 | 84 | |
michael@0 | 85 | // domain must match host |
michael@0 | 86 | if (!host.endsWith(domain)) { |
michael@0 | 87 | if (domain.startsWith(".")) { |
michael@0 | 88 | domain = domain.substring(1, domain.length()); |
michael@0 | 89 | } |
michael@0 | 90 | if (!host.equals(domain)) { |
michael@0 | 91 | throw new CookieRestrictionViolationException( |
michael@0 | 92 | "Illegal domain attribute \"" + domain |
michael@0 | 93 | + "\". Domain of origin: \"" + host + "\""); |
michael@0 | 94 | } |
michael@0 | 95 | } |
michael@0 | 96 | } else { |
michael@0 | 97 | if (!host.equals(domain)) { |
michael@0 | 98 | throw new CookieRestrictionViolationException( |
michael@0 | 99 | "Illegal domain attribute \"" + domain |
michael@0 | 100 | + "\". Domain of origin: \"" + host + "\""); |
michael@0 | 101 | } |
michael@0 | 102 | } |
michael@0 | 103 | } |
michael@0 | 104 | |
michael@0 | 105 | public boolean match(final Cookie cookie, final CookieOrigin origin) { |
michael@0 | 106 | if (cookie == null) { |
michael@0 | 107 | throw new IllegalArgumentException("Cookie may not be null"); |
michael@0 | 108 | } |
michael@0 | 109 | if (origin == null) { |
michael@0 | 110 | throw new IllegalArgumentException("Cookie origin may not be null"); |
michael@0 | 111 | } |
michael@0 | 112 | String host = origin.getHost(); |
michael@0 | 113 | String domain = cookie.getDomain(); |
michael@0 | 114 | if (domain == null) { |
michael@0 | 115 | return false; |
michael@0 | 116 | } |
michael@0 | 117 | if (host.equals(domain)) { |
michael@0 | 118 | return true; |
michael@0 | 119 | } |
michael@0 | 120 | if (!domain.startsWith(".")) { |
michael@0 | 121 | domain = '.' + domain; |
michael@0 | 122 | } |
michael@0 | 123 | return host.endsWith(domain) || host.equals(domain.substring(1)); |
michael@0 | 124 | } |
michael@0 | 125 | |
michael@0 | 126 | } |