Web.hx 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403
  1. /*
  2. * Copyright (C)2005-2017 Haxe Foundation
  3. *
  4. * Permission is hereby granted, free of charge, to any person obtaining a
  5. * copy of this software and associated documentation files (the "Software"),
  6. * to deal in the Software without restriction, including without limitation
  7. * the rights to use, copy, modify, merge, publish, distribute, sublicense,
  8. * and/or sell copies of the Software, and to permit persons to whom the
  9. * Software is furnished to do so, subject to the following conditions:
  10. *
  11. * The above copyright notice and this permission notice shall be included in
  12. * all copies or substantial portions of the Software.
  13. *
  14. * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
  15. * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
  16. * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
  17. * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
  18. * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
  19. * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
  20. * DEALINGS IN THE SOFTWARE.
  21. */
  22. package php;
  23. import haxe.io.Bytes;
  24. /**
  25. This class is used for accessing the local Web server and the current
  26. client request and information.
  27. **/
  28. class Web {
  29. /**
  30. Returns the GET and POST parameters.
  31. **/
  32. public static function getParams() : Map<String,String> {
  33. #if force_std_separator
  34. var a : NativeArray = untyped __php__("$_POST");
  35. if(untyped __call__("get_magic_quotes_gpc"))
  36. untyped __php__("reset($a); while(list($k, $v) = each($a)) $a[$k] = stripslashes((string)$v)");
  37. var h = Lib.hashOfAssociativeArray(a);
  38. var params = getParamsString();
  39. if( params == "" )
  40. return h;
  41. for( p in ~/[;&]/g.split(params) ) {
  42. var a = p.split("=");
  43. var n = a.shift();
  44. h.set(StringTools.urlDecode(n),StringTools.urlDecode(a.join("=")));
  45. }
  46. return h;
  47. #else
  48. var a : NativeArray = untyped __php__("array_merge($_GET, $_POST)");
  49. if(untyped __call__("get_magic_quotes_gpc"))
  50. untyped __php__("reset($a); while(list($k, $v) = each($a)) $a[$k] = stripslashes((string)$v)");
  51. return Lib.hashOfAssociativeArray(a);
  52. #end
  53. }
  54. /**
  55. Returns an Array of Strings built using GET / POST values.
  56. If you have in your URL the parameters `a[]=foo;a[]=hello;a[5]=bar;a[3]=baz` then
  57. `php.Web.getParamValues("a")` will return `["foo","hello",null,"baz",null,"bar"]`.
  58. **/
  59. public static function getParamValues( param : String ) : Array<String> {
  60. var reg = new EReg("^"+param+"(\\[|%5B)([0-9]*?)(\\]|%5D)=(.*?)$", "");
  61. var res = new Array<String>();
  62. var explore = function(data:String){
  63. if (data == null || data.length == 0)
  64. return;
  65. for (part in data.split("&")){
  66. if (reg.match(part)){
  67. var idx = reg.matched(2);
  68. var val = StringTools.urlDecode(reg.matched(4));
  69. if (idx == "")
  70. res.push(val);
  71. else
  72. res[Std.parseInt(idx)] = val;
  73. }
  74. }
  75. }
  76. explore(StringTools.replace(getParamsString(), ";", "&"));
  77. explore(getPostData());
  78. if (res.length == 0) {
  79. var post:haxe.ds.StringMap<Dynamic> = Lib.hashOfAssociativeArray(untyped __php__("$_POST"));
  80. var data = post.get(param);
  81. var k = 0, v = "";
  82. if (untyped __call__("is_array", data)) {
  83. untyped __php__(" reset($data); while(list($k, $v) = each($data)) { ");
  84. res[k] = v;
  85. untyped __php__(" } ");
  86. }
  87. }
  88. if (res.length == 0)
  89. return null;
  90. return res;
  91. }
  92. /**
  93. Returns the local server host name.
  94. **/
  95. public static inline function getHostName() : String {
  96. return untyped __php__("$_SERVER['SERVER_NAME']");
  97. }
  98. /**
  99. Surprisingly returns the client IP address.
  100. **/
  101. public static inline function getClientIP() : String {
  102. return untyped __php__("$_SERVER['REMOTE_ADDR']");
  103. }
  104. /**
  105. Returns the original request URL (before any server internal redirections).
  106. **/
  107. public static function getURI() : String {
  108. var s : String = untyped __php__("$_SERVER['REQUEST_URI']");
  109. return s.split("?")[0];
  110. }
  111. /**
  112. Tell the client to redirect to the given url ("Location" header).
  113. **/
  114. public static function redirect( url : String ) {
  115. untyped __call__('header', "Location: " + url);
  116. }
  117. /**
  118. Set an output header value. If some data have been printed, the headers have
  119. already been sent so this will raise an exception.
  120. **/
  121. public static inline function setHeader( h : String, v : String ) {
  122. untyped __call__('header', h+": "+v);
  123. }
  124. /**
  125. Set the HTTP return code. Same remark as `php.Web.setHeader()`.
  126. See status code explanation here: http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html
  127. **/
  128. public static function setReturnCode( r : Int ) {
  129. var code : String;
  130. switch(r) {
  131. case 100: code = "100 Continue";
  132. case 101: code = "101 Switching Protocols";
  133. case 200: code = "200 OK";
  134. case 201: code = "201 Created";
  135. case 202: code = "202 Accepted";
  136. case 203: code = "203 Non-Authoritative Information";
  137. case 204: code = "204 No Content";
  138. case 205: code = "205 Reset Content";
  139. case 206: code = "206 Partial Content";
  140. case 300: code = "300 Multiple Choices";
  141. case 301: code = "301 Moved Permanently";
  142. case 302: code = "302 Found";
  143. case 303: code = "303 See Other";
  144. case 304: code = "304 Not Modified";
  145. case 305: code = "305 Use Proxy";
  146. case 307: code = "307 Temporary Redirect";
  147. case 400: code = "400 Bad Request";
  148. case 401: code = "401 Unauthorized";
  149. case 402: code = "402 Payment Required";
  150. case 403: code = "403 Forbidden";
  151. case 404: code = "404 Not Found";
  152. case 405: code = "405 Method Not Allowed";
  153. case 406: code = "406 Not Acceptable";
  154. case 407: code = "407 Proxy Authentication Required";
  155. case 408: code = "408 Request Timeout";
  156. case 409: code = "409 Conflict";
  157. case 410: code = "410 Gone";
  158. case 411: code = "411 Length Required";
  159. case 412: code = "412 Precondition Failed";
  160. case 413: code = "413 Request Entity Too Large";
  161. case 414: code = "414 Request-URI Too Long";
  162. case 415: code = "415 Unsupported Media Type";
  163. case 416: code = "416 Requested Range Not Satisfiable";
  164. case 417: code = "417 Expectation Failed";
  165. case 500: code = "500 Internal Server Error";
  166. case 501: code = "501 Not Implemented";
  167. case 502: code = "502 Bad Gateway";
  168. case 503: code = "503 Service Unavailable";
  169. case 504: code = "504 Gateway Timeout";
  170. case 505: code = "505 HTTP Version Not Supported";
  171. default: code = Std.string(r);
  172. }
  173. untyped __call__('header', "HTTP/1.1 " + code, true, r);
  174. }
  175. /**
  176. Retrieve a client header value sent with the request.
  177. **/
  178. public static function getClientHeader( k : String ) : String {
  179. var k = StringTools.replace(k.toUpperCase(),"-","_");
  180. for(i in getClientHeaders()) {
  181. if(i.header == k)
  182. return i.value;
  183. }
  184. return null;
  185. }
  186. private static var _client_headers : List<{header : String, value : String}>;
  187. /**
  188. Retrieve all the client headers.
  189. **/
  190. public static function getClientHeaders() {
  191. if(_client_headers == null) {
  192. _client_headers = new List();
  193. var h = Lib.hashOfAssociativeArray(untyped __php__("$_SERVER"));
  194. for(k in h.keys()) {
  195. if(k.substr(0,5) == "HTTP_") {
  196. _client_headers.add({ header : k.substr(5), value : h.get(k)});
  197. // this is also a valid prefix (issue #1883)
  198. } else if(k.substr(0,8) == "CONTENT_") {
  199. _client_headers.add({ header : k, value : h.get(k)});
  200. }
  201. }
  202. // and these(issue #5270)
  203. if(untyped __php__("isset($_SERVER['REDIRECT_HTTP_AUTHORIZATION'])")) {
  204. _client_headers.add({header: 'AUTHORIZATION', value: untyped __php__("(string)$_SERVER['REDIRECT_HTTP_AUTHORIZATION']")});
  205. } else if(untyped __php__("isset($_SERVER['PHP_AUTH_USER'])")) {
  206. var basic_pass = untyped __php__("isset($_SERVER['PHP_AUTH_PW']) ? (string)$_SERVER['PHP_AUTH_PW'] : ''");
  207. _client_headers.add({header: 'AUTHORIZATION', value: 'Basic ' + untyped __php__("base64_encode($_SERVER['PHP_AUTH_USER'] + ':' + $basic_pass)")});
  208. } else if(untyped __php__("isset($_SERVER['PHP_AUTH_DIGEST'])")) {
  209. _client_headers.add({header: 'AUTHORIZATION', value: untyped __php__("(string)$_SERVER['PHP_AUTH_DIGEST']")});
  210. }
  211. }
  212. return _client_headers;
  213. }
  214. /**
  215. Returns all the GET parameters `String`
  216. **/
  217. public static function getParamsString() : String {
  218. if(untyped __call__("isset", __var__("_SERVER", "QUERY_STRING")))
  219. return untyped __var__("_SERVER", "QUERY_STRING");
  220. else
  221. return "";
  222. }
  223. /**
  224. Returns all the POST data. POST Data is always parsed as
  225. being application/x-www-form-urlencoded and is stored into
  226. the getParams hashtable. POST Data is maximimized to 256K
  227. unless the content type is multipart/form-data. In that
  228. case, you will have to use `php.Web.getMultipart()` or
  229. `php.Web.parseMultipart()` methods.
  230. **/
  231. public static function getPostData() : Null<String> {
  232. var h = untyped __call__("fopen", "php://input", "r");
  233. var bsize = 8192;
  234. var max = 32;
  235. var data : String = null;
  236. var counter = 0;
  237. while (!untyped __call__("feof", h) && counter < max) {
  238. data = untyped __php__('{0} . fread({1}, {2})', data, h, bsize);
  239. counter++;
  240. }
  241. untyped __call__("fclose", h);
  242. return data;
  243. }
  244. /**
  245. Returns an hashtable of all Cookies sent by the client.
  246. Modifying the hashtable will not modify the cookie, use `php.Web.setCookie()`
  247. instead.
  248. **/
  249. public static function getCookies():Map<String,String> {
  250. return Lib.hashOfAssociativeArray(untyped __php__("$_COOKIE"));
  251. }
  252. /**
  253. Set a Cookie value in the HTTP headers. Same remark as `php.Web.setHeader()`.
  254. **/
  255. public static function setCookie( key : String, value : String, ?expire: Date, ?domain: String, ?path: String, ?secure: Bool, ?httpOnly: Bool ) {
  256. var t = expire == null ? 0 : Std.int(expire.getTime()/1000.0);
  257. if(path == null) path = '/';
  258. if(domain == null) domain = '';
  259. if(secure == null) secure = false;
  260. if(httpOnly == null) httpOnly = false;
  261. untyped __call__("setcookie", key, value, t, path, domain, secure, httpOnly);
  262. }
  263. /**
  264. Returns an object with the authorization sent by the client (Basic scheme only).
  265. **/
  266. public static function getAuthorization() : { user : String, pass : String } {
  267. if(!untyped __php__("isset($_SERVER['PHP_AUTH_USER'])"))
  268. return null;
  269. return untyped {user: __php__("$_SERVER['PHP_AUTH_USER']"), pass: __php__("$_SERVER['PHP_AUTH_PW']")};
  270. }
  271. /**
  272. Get the current script directory in the local filesystem.
  273. **/
  274. public static inline function getCwd() : String {
  275. return untyped __php__("dirname($_SERVER[\"SCRIPT_FILENAME\"])") + "/";
  276. }
  277. /**
  278. Get the multipart parameters as an hashtable. The data
  279. cannot exceed the maximum size specified.
  280. **/
  281. public static function getMultipart( maxSize : Int ) : Map<String,String> {
  282. var h = new haxe.ds.StringMap();
  283. var buf : StringBuf = null;
  284. var curname = null;
  285. parseMultipart(function(p,_) {
  286. if( curname != null )
  287. h.set(curname,buf.toString());
  288. curname = p;
  289. buf = new StringBuf();
  290. maxSize -= p.length;
  291. if( maxSize < 0 )
  292. throw "Maximum size reached";
  293. }, function(str,pos,len) {
  294. maxSize -= len;
  295. if( maxSize < 0 )
  296. throw "Maximum size reached";
  297. buf.addSub(str.toString(),pos,len);
  298. });
  299. if( curname != null )
  300. h.set(curname,buf.toString());
  301. return h;
  302. }
  303. /**
  304. Parse the multipart data. Call `onPart` when a new part is found
  305. with the part name and the filename if present
  306. and `onData` when some part data is read. You can this way
  307. directly save the data on hard drive in the case of a file upload.
  308. **/
  309. public static function parseMultipart( onPart : String -> String -> Void, onData : Bytes -> Int -> Int -> Void ) : Void {
  310. var a : NativeArray = untyped __var__("_POST");
  311. if(untyped __call__("get_magic_quotes_gpc"))
  312. untyped __php__("reset($a); while(list($k, $v) = each($a)) $a[$k] = stripslashes((string)$v)");
  313. var post = Lib.hashOfAssociativeArray(a);
  314. for (key in post.keys())
  315. {
  316. onPart(key, "");
  317. var v = post.get(key);
  318. onData(Bytes.ofString(v), 0, untyped __call__("strlen", v));
  319. }
  320. if(!untyped __call__("isset", __php__("$_FILES"))) return;
  321. var parts : Array<String> = untyped __call__("new _hx_array",__call__("array_keys", __php__("$_FILES")));
  322. for(part in parts) {
  323. var info : Dynamic = untyped __php__("$_FILES[$part]");
  324. var tmp : String = untyped info['tmp_name'];
  325. var file : String = untyped info['name'];
  326. var err : Int = untyped info['error'];
  327. if(err > 0) {
  328. switch(err) {
  329. case 1: throw "The uploaded file exceeds the max size of " + untyped __call__('ini_get', 'upload_max_filesize');
  330. case 2: throw "The uploaded file exceeds the max file size directive specified in the HTML form (max is" + untyped __call__('ini_get', 'post_max_size') + ")";
  331. case 3: throw "The uploaded file was only partially uploaded";
  332. case 4: continue; // No file was uploaded
  333. case 6: throw "Missing a temporary folder";
  334. case 7: throw "Failed to write file to disk";
  335. case 8: throw "File upload stopped by extension";
  336. }
  337. }
  338. onPart(part, file);
  339. if ("" != file)
  340. {
  341. var h = untyped __call__("fopen", tmp, "r");
  342. var bsize = 8192;
  343. while (!untyped __call__("feof", h)) {
  344. var buf : String = untyped __call__("fread", h, bsize);
  345. var size : Int = untyped __call__("strlen", buf);
  346. onData(Bytes.ofString(buf), 0, size);
  347. }
  348. untyped __call__("fclose", h);
  349. }
  350. }
  351. }
  352. /**
  353. Flush the data sent to the client. By default on Apache, outgoing data is buffered so
  354. this can be useful for displaying some long operation progress.
  355. **/
  356. public static inline function flush() : Void {
  357. untyped __call__("flush");
  358. }
  359. /**
  360. Get the HTTP method used by the client.
  361. **/
  362. public static function getMethod() : String {
  363. if(untyped __php__("isset($_SERVER['REQUEST_METHOD'])"))
  364. return untyped __php__("$_SERVER['REQUEST_METHOD']");
  365. else
  366. return null;
  367. }
  368. public static var isModNeko(default,null) : Bool;
  369. static function __init__() {
  370. isModNeko = !php.Lib.isCli();
  371. }
  372. }