xirvik
019c16a077
rpc: multicall requires methodName as the struct's first member
...
Faults clearly instead of the confusing positional parse error it replaces.
2026-09-24 09:20:25 +02:00
xirvik
80ae6a4590
Answer an oversized RPC response with a fault
...
Cap XML-RPC and JSON-RPC output at the SCGI response limit before handing it over.
2026-09-19 18:04:09 +02:00
noctuum
5ebb7bd151
Call the target deleter in the tinyxml2 backend
...
A tracker target allocates, and the deleter went out of scope unused.
2026-09-17 10:33:45 +02:00
xirvik
b24db0eaa5
Do not dereference missing text nodes in the tinyxml2 backend.
...
Empty elements and element children crashed the parser on a null.
2026-08-14 13:16:17 +02:00
Jari Sundell
a5a96236df
Moved base64 transform and validation functions.
2026-06-04 06:37:01 +09:00
Jari Sundell
f1cfe8ad72
Added hex to Object and string_utf8.
2026-06-04 04:22:16 +09:00
Jari Sundell
add305f90c
Added support base64 support for non-UTF8 strings.
2026-05-30 00:25:16 +09:00
Jari Sundell
64881317c6
Fix RPC/SCGI security and crash bugs by @sirus20x6
2026-05-26 17:27:10 +09:00
Jari Sundell
5a4ba8bc32
Removed deprecated rak header files.
2026-04-10 22:04:02 +09:00
Xirvik
598914908f
Add untrusted connection security infrastructure (v3)
...
Replace the v2 blacklist approach with a per-command flag system.
Commands must opt in to being available for untrusted connections
via flag_untrusted_safe (0x400), checked in call_command() which
catches all execution paths including nested commands.
Infrastructure changes:
- Add flag_untrusted_safe to CommandMap
- Add untrusted_error exception type for proper error codes
- Enforce trust check in both call_command() overloads
- Add catch blocks in xmlrpc_c, xmlrpc_tinyxml2, and jsonrpc handlers
- Port SCGI trust state management from v2 (thread_local, header parsing)
- Add _U macro variants in command_helpers.h for safe command registration
- Add CMD2_VAR_*_U and CMD2_VAR_*_U_GET variants for variables
2026-03-23 15:11:07 +01:00
Jari Sundell
48f82c17c2
Remove deprecated no-target flags for commands.
2025-09-20 17:27:26 +09:00
Jorge Israel Peña
58a74cee48
Wrap fault struct in value
2025-05-02 12:13:49 +02:00
rakshasa
8ac31afd06
Fixed tinyxml2 compile error.
2025-03-28 16:07:55 +01:00
kannibalox
9f48226663
Add JSON-RPC capability
...
Inline nlohmann/json for the JSON parsing itself, and handle requests
with the same SCGI interface as XML-RPC.
Based off the work in https://github.com/jesec/rtorrent
2025-01-20 12:31:04 +01:00
simonc56
2bf81aa8f5
tinyxml2: array with data for dict type
2025-01-01 21:33:30 +09:00
simonc56
a9c0b65b9d
tinyxml2: in xmlrpc an array must include values in a data element
2025-01-01 21:33:30 +09:00
stickz
73fed24459
tinyxml2: Change from i4 to i8
...
We need to follow the same specification as xmlrpc-c until we deprecate it. It is breaking various software such as sonarr. We can't have xmlrpc using i8 and tinyxml2 using i4, while we allow both to be used.
2025-01-01 21:32:23 +09:00
kannibalox
8f0331625a
Correctly handle commands that are flagged as not using targets
...
Fixes #1346
2024-12-27 01:00:23 +09:00
kannibalox
5792ed1ae2
Apply clang-format
2024-12-07 19:26:29 +09:00
kannibalox
8cfc71b936
Fix system.multicall parameter parsing
2024-12-07 19:26:29 +09:00
kannibalox
f33c2560a3
Default to an empty list when not passed explicit <params>
2024-12-07 19:26:29 +09:00
kannibalox
48c40ee0c6
Fix typo: methodReponse -> methodResponse
2024-12-07 19:26:29 +09:00
kannibalox
3aeb213dc4
Avoid <int> in tinyxml2 responses
...
It's part of the XML-RPC spec, but some clients only accept i4/i8, which
should be supported nearly universally.
Fixes #1330
2024-12-07 19:26:29 +09:00
kannibalox
b3fabd2a2b
Align argument name with header definition
2024-11-25 18:44:28 +09:00
kannibalox
4b7c3ffafe
Use empty() instead of checking size
...
Also use a const pointer for a child element
2024-11-25 18:44:28 +09:00
kannibalox
730d43b6c7
Explicitly mark narrowing conversion
2024-11-25 18:44:28 +09:00
kannibalox
af2f30c183
Remove unused variable
2024-11-25 18:44:28 +09:00
kannibalox
36fd837d27
Fix unnecessary narrowing with proper return type
2024-11-25 18:44:28 +09:00
kannibalox
8dd8d691c5
Explicitly check result of std::strncmp
2024-11-25 18:44:28 +09:00
kannibalox
e367b162ab
Share object_to_target between tinyxml2 and xmlrpc-c
2024-11-25 18:44:28 +09:00
kannibalox
49cdfee65a
Avoid ambiguous value_* in variable names
2024-11-25 18:44:28 +09:00
kannibalox
5680db3598
Parse out target param first if available
2024-11-25 18:44:28 +09:00
kannibalox
fa2c7d961b
Remove unnecessary std::string() and use lowercase for error msgs
2024-11-25 18:44:28 +09:00
kannibalox
d6dcbc4a69
Add size limit to XML-RPC documents, defaulting to max SCGI size
2024-11-25 18:44:28 +09:00
kannibalox
cadfcb50d2
Print iterator for TYPE_DICT_KEY, not object
2024-11-25 18:44:28 +09:00
kannibalox
71a39cd8a0
Keep as_*() outside of loops
2024-11-25 18:44:28 +09:00
kannibalox
0658486966
Change base64 decoder name, and add util for removing newlines
2024-11-25 18:44:28 +09:00
kannibalox
687fbbb83d
Formatting
2024-11-25 18:44:28 +09:00
kannibalox
f9c9fa2e3b
Move int element converter to helper function
...
Also fix strncmp checks
2024-11-25 18:44:28 +09:00
kannibalox
782b1e4ea8
Skip converting value_element_type to std::string
2024-11-25 18:44:28 +09:00
kannibalox
67babb65d6
Convert element_access to use initializer lists
...
Also remove uses element_access for single child accesses
2024-11-25 18:44:28 +09:00
kannibalox
e0d5c95821
Use correct terminology in comment
2024-11-25 18:44:28 +09:00
kannibalox
dd45684584
Move vendored tinyxml2 files to rpc namespace and directory
2024-11-25 18:44:28 +09:00
kannibalox
fb8632e990
Change lingering camelCase to snake_case
2024-11-25 18:44:28 +09:00
kannibalox
b043b7b39e
Simplify iterator names
2024-11-25 18:44:28 +09:00
kannibalox
168093d256
Remove extra return
2024-11-25 18:44:28 +09:00
kannibalox
4a9d9952e1
Be explicit about the desired result
2024-11-25 18:44:28 +09:00
kannibalox
fd1d5dbdb2
Add test case for bad boolean value
2024-11-25 18:44:28 +09:00
kannibalox
3a8e462bd3
Throw error if attempting to use both xmlrpc-c and tinyxml2
2024-11-25 18:44:28 +09:00
kannibalox
b360a734f1
Use std::strtoll instead of std::stol
2024-11-25 18:44:28 +09:00