Revert "Merge pull request #981 from methane/websocket"
[mono.git] / mcs / class / System / System.Net / HttpListenerContext.cs
1 //
2 // System.Net.HttpListenerContext
3 //
4 // Author:
5 //      Gonzalo Paniagua Javier (gonzalo@novell.com)
6 //
7 // Copyright (c) 2005 Novell, Inc. (http://www.novell.com)
8 //
9 // Permission is hereby granted, free of charge, to any person obtaining
10 // a copy of this software and associated documentation files (the
11 // "Software"), to deal in the Software without restriction, including
12 // without limitation the rights to use, copy, modify, merge, publish,
13 // distribute, sublicense, and/or sell copies of the Software, and to
14 // permit persons to whom the Software is furnished to do so, subject to
15 // the following conditions:
16 // 
17 // The above copyright notice and this permission notice shall be
18 // included in all copies or substantial portions of the Software.
19 // 
20 // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
21 // EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
22 // MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
23 // NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
24 // LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
25 // OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
26 // WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
27 //
28
29 #if SECURITY_DEP
30
31 using System.Collections.Specialized;
32 using System.IO;
33 using System.Security.Principal;
34 using System.Text;
35 namespace System.Net {
36         public sealed class HttpListenerContext {
37                 HttpListenerRequest request;
38                 HttpListenerResponse response;
39                 IPrincipal user;
40                 HttpConnection cnc;
41                 string error;
42                 int err_status = 400;
43                 internal HttpListener Listener;
44
45                 internal HttpListenerContext (HttpConnection cnc)
46                 {
47                         this.cnc = cnc;
48                         request = new HttpListenerRequest (this);
49                         response = new HttpListenerResponse (this);
50                 }
51
52                 internal int ErrorStatus {
53                         get { return err_status; }
54                         set { err_status = value; }
55                 }
56
57                 internal string ErrorMessage {
58                         get { return error; }
59                         set { error = value; }
60                 }
61
62                 internal bool HaveError {
63                         get { return (error != null); }
64                 }
65
66                 internal HttpConnection Connection {
67                         get { return cnc; }
68                 }
69
70                 public HttpListenerRequest Request {
71                         get { return request; }
72                 }
73
74                 public HttpListenerResponse Response {
75                         get { return response; }
76                 }
77
78                 public IPrincipal User {
79                         get { return user; }
80                 }
81
82                 internal void ParseAuthentication (AuthenticationSchemes expectedSchemes) {
83                         if (expectedSchemes == AuthenticationSchemes.Anonymous)
84                                 return;
85
86                         // TODO: Handle NTLM/Digest modes
87                         string header = request.Headers ["Authorization"];
88                         if (header == null || header.Length < 2)
89                                 return;
90
91                         string [] authenticationData = header.Split (new char [] {' '}, 2);
92                         if (string.Compare (authenticationData [0], "basic", true) == 0) {
93                                 user = ParseBasicAuthentication (authenticationData [1]);
94                         }
95                         // TODO: throw if malformed -> 400 bad request
96                 }
97         
98                 internal IPrincipal ParseBasicAuthentication (string authData) {
99                         try {
100                                 // Basic AUTH Data is a formatted Base64 String
101                                 //string domain = null;
102                                 string user = null;
103                                 string password = null;
104                                 int pos = -1;
105                                 string authString = System.Text.Encoding.Default.GetString (Convert.FromBase64String (authData));
106         
107                                 // The format is DOMAIN\username:password
108                                 // Domain is optional
109
110                                 pos = authString.IndexOf (':');
111         
112                                 // parse the password off the end
113                                 password = authString.Substring (pos+1);
114                                 
115                                 // discard the password
116                                 authString = authString.Substring (0, pos);
117         
118                                 // check if there is a domain
119                                 pos = authString.IndexOf ('\\');
120         
121                                 if (pos > 0) {
122                                         //domain = authString.Substring (0, pos);
123                                         user = authString.Substring (pos);
124                                 } else {
125                                         user = authString;
126                                 }
127         
128                                 HttpListenerBasicIdentity identity = new HttpListenerBasicIdentity (user, password);
129                                 // TODO: What are the roles MS sets
130                                 return new GenericPrincipal (identity, new string [0]);
131                         } catch (Exception) {
132                                 // Invalid auth data is swallowed silently
133                                 return null;
134                         } 
135                 }
136         }
137 }
138 #endif
139