mirror of
https://github.com/rakshasa/rtorrent.git
synced 2026-10-05 05:39:22 +00:00
Address review feedback: explicit mark_safe whitelist and rpc trust flow
This commit is contained in:
+25
-3
@@ -21,8 +21,6 @@ ExecFile execFile;
|
||||
// CommandMap::call_command(), which catches all command execution
|
||||
// including nested calls through argument expansion.
|
||||
|
||||
thread_local bool RpcManager::m_trusted = true;
|
||||
|
||||
bool
|
||||
RpcManager::set_trusted(bool trusted) {
|
||||
bool prev = m_trusted;
|
||||
@@ -31,7 +29,7 @@ RpcManager::set_trusted(bool trusted) {
|
||||
}
|
||||
|
||||
bool
|
||||
RpcManager::is_trusted() {
|
||||
RpcManager::is_trusted() const {
|
||||
return m_trusted;
|
||||
}
|
||||
|
||||
@@ -146,6 +144,20 @@ RpcManager::process(RPCType type, const char* in_buffer, uint32_t length, slot_r
|
||||
}
|
||||
}
|
||||
|
||||
bool
|
||||
RpcManager::process_untrusted(RPCType type, const char* in_buffer, uint32_t length, slot_response_callback callback) {
|
||||
bool previous = set_trusted(false);
|
||||
|
||||
try {
|
||||
bool result = process(type, in_buffer, length, callback);
|
||||
set_trusted(previous);
|
||||
return result;
|
||||
} catch (...) {
|
||||
set_trusted(previous);
|
||||
throw;
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
RpcManager::initialize_handlers() {
|
||||
if (m_handlers_initialized)
|
||||
@@ -197,4 +209,14 @@ RpcManager::insert_command(const char* name, const char* parm, const char* doc)
|
||||
m_jsonrpc.insert_command(name, parm, doc);
|
||||
}
|
||||
|
||||
void
|
||||
RpcManager::mark_safe(const std::string& key) {
|
||||
auto itr = commands.find(key);
|
||||
|
||||
if (itr == commands.end())
|
||||
return;
|
||||
|
||||
itr->second.m_flags |= CommandMap::flag_untrusted_safe;
|
||||
}
|
||||
|
||||
} // namespace rpc
|
||||
|
||||
Reference in New Issue
Block a user