Add untrusted connection security infrastructure (v3)

Replace the v2 blacklist approach with a per-command flag system.
Commands must opt in to being available for untrusted connections
via flag_untrusted_safe (0x400), checked in call_command() which
catches all execution paths including nested commands.

Infrastructure changes:
- Add flag_untrusted_safe to CommandMap
- Add untrusted_error exception type for proper error codes
- Enforce trust check in both call_command() overloads
- Add catch blocks in xmlrpc_c, xmlrpc_tinyxml2, and jsonrpc handlers
- Port SCGI trust state management from v2 (thread_local, header parsing)
- Add _U macro variants in command_helpers.h for safe command registration
- Add CMD2_VAR_*_U and CMD2_VAR_*_U_GET variants for variables
This commit is contained in:
Xirvik
2026-03-01 16:39:45 +00:00
committed by Jari Sundell
parent 38fc815d52
commit 598914908f
10 changed files with 199 additions and 21 deletions
+22
View File
@@ -13,6 +13,28 @@ CommandMap commands;
RpcManager rpc;
ExecFile execFile;
// Trusted/untrusted XMLRPC connection model.
//
// The trust state is set per-request by the SCGI layer based on the
// UNTRUSTED_CONNECTION header. Commands without flag_untrusted_safe
// are blocked for untrusted connections. The check is in
// CommandMap::call_command(), which catches all command execution
// including nested calls through argument expansion.
thread_local bool RpcManager::m_trusted = true;
bool
RpcManager::set_trusted(bool trusted) {
bool prev = m_trusted;
m_trusted = trusted;
return prev;
}
bool
RpcManager::is_trusted() {
return m_trusted;
}
void
RpcManager::object_to_target(const torrent::Object& obj, int call_flags, rpc::target_type* target, std::function<void()>* deleter) {
if (!obj.is_string())