aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* ctfw.c: Avoid trailing forward slashXavier Del Campo Romero2023-06-061-1/+2
| | | | | | Otherwise, this would generate strings such as "directory//resource" if dirpath contained a trailing slash, which could be problematic for users relying on ctfw.
* wildcard_cmp.c: Fix a couple of bugsXavier Del Campo Romero2023-06-061-3/+22
| | | | | | | wildcard_cmp would otherwise fail with the following use cases: s = "mymi", p = "*mi*" s = "mymi", p = "*mi"
* wildcard_cmp.c: Remove leftoversXavier Del Campo Romero2023-06-061-4/+0
| | | | | These statements had no effect since it was always executed when n == 0.
* wildcard_cmp: Allow case-insensitive searchesXavier Del Campo Romero2023-06-063-14/+29
| | | | The new search feature will require them.
* Split wildcard_cmp into its own componentXavier Del Campo Romero2023-06-066-43/+55
| | | | Future commits will make use of this function outside handler.c.
* page.c: Apply minor fixes and improvements to stylesheetXavier Del Campo Romero2023-06-061-3/+3
| | | | | | - Rules applying to body already apply to input. - input already had a "margin: auto" rule. - Missing whitespace on "margin:auto" rule.
* page.c: Call page_not_found on ENOTDIRXavier Del Campo Romero2023-06-061-1/+1
| | | | | ENOTDIR is another non-fatal errno value that can be returned by stat(2).
* page.c: Display login forms as gridXavier Del Campo Romero2023-06-021-1/+5
| | | | | | While commit 1ffba8f5 fixed a wrong display of the mkdir, upload and logout forms, it did not take login forms into consideration, which must displayed as grid.
* page.c: Add padding to mkdir, logout, and upload formsXavier Del Campo Romero2023-06-021-0/+24
|
* page.c: Do not display forms as gridXavier Del Campo Romero2023-06-021-4/+0
| | | | | Otherwise, each element from the form would be stacked on top of another, which is confusing to users.
* page.c: Apply max-width to tableXavier Del Campo Romero2023-05-301-0/+4
| | | | This will help users to read tables with long file names.
* page.c: Apply lightgray background to even cellsXavier Del Campo Romero2023-05-301-0/+4
| | | | This will help users to navigate through large tables.
* auth.c: Fix wrong size checkXavier Del Campo Romero2023-05-281-1/+1
| | | | Otherwise, sb.st_size + 1 would exceed SIZE_MAX.
* cftw.c: Add missing portability definitionXavier Del Campo Romero2023-05-281-0/+2
|
* Makefile: Use dynstr's own MakefileXavier Del Campo Romero2023-05-282-4/+8
| | | | | dynstr has been recently modified so as to allow building also from make(1).
* usergen: Force newline after password inputXavier Del Campo Romero2023-05-281-0/+2
|
* usergen: Do not print password to ttyXavier Del Campo Romero2023-05-181-0/+5
|
* Avoid crashing on SIGPIPEXavier Del Campo Romero2023-05-012-2/+20
| | | | | | | | | Under some circumstances, clients could cause SIGPIPE to slcl. Since this signal was not handled by server.c (i.e., via sigaction(3)), slcl would crash without any error messages printed to stderr. In such situation, SIGPIPE should not be usually considered a fatal error, so it is preferrable to close the connection and keep working.
* http.c: Decode URL resource and parameters separatelyXavier Del Campo Romero2023-05-013-34/+45
| | | | | | | | | Given the following contrived example request: /example%FB%DC&arg%DE1=examplevalue%AA slcl must decode each token separately, so that percent-encoded characters '&', '=' or '?' do not get accidently intepreted.
* usergen: Fix wrong password and username usageXavier Del Campo Romero2023-05-011-6/+12
| | | | | | | | | Due to the lack of double quotes, passwords with whitespaces were not passed correctly to printf(1), thus making users not able to log into their account. OTOH, for some reason usernames containing whitespaces made jq(1) complain, so it has been decided not to support them.
* Fix missing error checks for strtoul(3)Xavier Del Campo Romero2023-05-012-4/+13
|
* Return error if write_ctx_free failsXavier Del Campo Romero2023-05-011-4/+10
| | | | | | | | | | | | | | | Otherwise, write_body_mem and write_body_mem would silently fail, causing undefined behaviour. Notes: The return value for write_ctx_free is currently assigned to that of fclose(3), which can be either 0 on success or EOF on failure. However, it makes sense for write_body_mem and write_body_mem to simply check against non-zero. Also, it would not be sensible to return EOF to caller functions, which expect either 0 (success), -1 (fatal error) or 1 (input error).
* Makefile: remove .SUFFIXESXavier Del Campo Romero2023-05-011-1/+0
| | | | | According to POSIX.1-2008, .c and .o are already included by the default .SUFFIX rule, among other suffixes.
* Remove HTTP/1.0 supportXavier Del Campo Romero2023-05-012-34/+6
| | | | | | | | | | | Considering http.h defined HTTP/1.1-only responses such as "303 See Other", as well as incoming HTTP/1.1-only features (e.g.: byte serving), it did not make much sense to keep a somewhat broken compatibility against HTTP/1.0. Unfortunately, this breaks support with some existing clients such as lynx(1), even if HTTP/1.0 was already deprecated many years ago. However, even lynx(1) can be configured to support HTTP/1.1.
* Replace select(2) with poll(2)Xavier Del Campo Romero2023-05-013-29/+68
| | | | | | select(2) has a number of well-known issues (e.g.: FD_SETSIZE limiting the maximum amount of file descriptors to watch) that are mostly solved by poll(2) and thus can be used as a drop-in replacement.
* Implement file previewsXavier Del Campo Romero2023-04-233-27/+106
| | | | | | | | | | | | | When using HTTP "Content-Disposition: attachment;", users are forced to download files in order to use them, whereas others might prefer to open them in the browser. Therefore, now that URL parameters are supported by http.h, previews can be forced by adding "preview=1" or "preview=true" (case-insensitive) as a URL parameters. Any other parameters are ignored by slcl. For users, a "Preview" link has been added next to the "Share" button for each file.
* Support URL parametersXavier Del Campo Romero2023-04-232-19/+241
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now, http_payload includes a list of human-readable parameters that can be read (but not modified) by users. Given the following example link: /test?key1=value1&key2=value2 This will generate two parameters, with the following values: { .args = { [0] = {.key = "key1", .value = "value1"}, [1] = {.key = "key2", .value = "value2"} }, .n_args = 2 } As expected, if any URL parameters are given, struct http_payload member "resource" is accordingly trimmed so as not to include any parameters. Therefore, considering the example above: {.args = {...}, .resource = "/test"} Limitations: - Since the definition of struct http_arg is both shared by http.h (as a read-only pointer within struct http_payload) and http.c (as a read/write pointer within struct ctx), its members (namely key and value) must remain as read/write pointers, even if they must not be modified by users of http.h.
* Improve CSS and apply to list_dirXavier Del Campo Romero2023-04-171-10/+54
|
* Makefile: make -MF write to .d file instead of stdoutXavier Del Campo Romero2023-03-291-4/+1
| | | | | This way, the default rule for .c.o can be used, simplifying the Makefile a bit more.
* auth.c: Ensure absolute path for a->dirXavier Del Campo Romero2023-03-251-13/+64
| | | | | Otherwise, slcl would create broken symbolic links if the user passes a relative path as command line argument.
* main.c: Use S_ISDIR in ensure_dirXavier Del Campo Romero2023-03-251-0/+5
|
* Define _POSIX_C_SOURCEXavier Del Campo Romero2023-03-247-1/+12
| | | | | This allows using the default compiler defined by make(1) (i.e., c99(1)), thus improving POSIX compatibility.
* http.c: Add missing #includeXavier Del Campo Romero2023-03-241-0/+1
| | | | As required by strncasecmp(3).
* Send response on quota exceededXavier Del Campo Romero2023-03-207-13/+136
| | | | | | | | | | | | | | | | | So far, slcl would just close the connection with a client when the Content-Length of an incoming request exceeded the user quota, without any meaningful information given back to the user. Now, slcl responds with a HTML file with meaningful information about the error. Limitations: - While this commits has been successfully tested on ungoogled-chromium, LibreWolf (and I assume Firefox and any other derivates too) does not seem to receive the response from the server. - However, this issue only occurred during local testing, but not on remote instances.
* README.md: Fix wrong linksXavier Del Campo Romero2023-03-201-4/+4
|
* README.md: Update according to current statusXavier Del Campo Romero2023-03-191-14/+26
|
* main.c: Fix double free(3) and refactor form handlingXavier Del Campo Romero2023-03-191-71/+74
| | | | | | | | | | | | | - When a non-empty username and an empty password was given, slcl would crash due to a double free(3). This happened because append_form would grow the form list before sanitizing the input and, since the output pointer was not updated to the caller function, the latter would attempt to free a now-old pointer. - Additionally, some compilers such as clang complained about the potential use of an uninitialized variable when calling forms_free. - Also, it was a good opportunity to refactor get_forms and its caller functions, as get_forms was not differentiate fatal errors from user input errors.
* main.c: Fix undefined value for curXavier Del Campo Romero2023-03-161-5/+6
| | | | | | | | | | As otherwise reported by clang 14.0.0: main.c:679:14: warning: variable 'cur' is used uninitialized whenever '&&' condition is false [-Wsometimes-uninitialized] else if (available && quota_current(a, username, &cur)) This was a minor issue after all, as pq was not used unless available were set.
* auth.c: Add friendly reminderXavier Del Campo Romero2023-03-161-1/+2
|
* Add man page for usergen(1)Xavier Del Campo Romero2023-03-162-0/+95
|
* Make usergen a bit more usefulXavier Del Campo Romero2023-03-162-7/+40
| | | | | | So far, usergen printed a JSON object over standard output that had to be manually copied into db.json. Now, this step is done automatically, thanks to jq(1). OTOH, user directory is now also created by usergen.
* page.c: Set Content-Disposition when serving filesXavier Del Campo Romero2023-03-161-5/+96
| | | | | | | | | | | | | | So far, slcl used the default browser behaviour (i.e., Content-Disposition: inline), which means files were typically shown on the web browser itself. However, this caused two issues: - Users would have to right-click -> "Save Link As..." to download a file, which might be inconvenient for some users. - The original file name would not be retrieved for publicly shared files. Now, file download is always requested to the browser, and the original file path is retrieved via readlink(2).
* main.c: Ensure essential directories on startupXavier Del Campo Romero2023-03-161-0/+72
| | | | | | So far, slcl failed with poorly described error messages when any of the essential directories were missing. Now, these are created automatically so that the initial setup is easier.
* slcl.1: Update TODOXavier Del Campo Romero2023-03-161-1/+1
| | | | | - User quota was implemented by commit ff8da797a. - Public file sharing was implemented by commit 2e1b1313.
* page.c: Fix wrong error messageXavier Del Campo Romero2023-03-091-1/+1
|
* main.c: Call form_free instead of repeating codeXavier Del Campo Romero2023-03-091-4/+1
|
* Implement public file sharingXavier Del Campo Romero2023-03-093-15/+369
| | | | | | | | | | | | | An HTML form is now added next to each regular file, that generates a POST request. Then, slcl replies with a HTML document with a link to the public resource (which are implemented as symlinks). Limitations: - For now, only regular files can be shared i.e., sharing directories is not possible. While feasible, it still requires a larger refactor to list_dir and resource_layout, so that read-only access to the directory is provided to anonymous users.
* page.c: Provide meaningful description on HTTP 404Xavier Del Campo Romero2023-03-091-8/+28
|
* page.c: Implement function for common <head> nodesXavier Del Campo Romero2023-03-091-34/+55
| | | | This will be used by future commits.
* Translate whitespace to '+' in append_formXavier Del Campo Romero2023-03-091-11/+8
| | | | Otherwise, every function calling get_forms must implement this.