Jari Sundell
64881317c6
Fix RPC/SCGI security and crash bugs by @sirus20x6
2026-05-26 17:27:10 +09:00
Jari Sundell
5a4ba8bc32
Removed deprecated rak header files.
2026-04-10 22:04:02 +09:00
Xirvik
598914908f
Add untrusted connection security infrastructure (v3)
...
Replace the v2 blacklist approach with a per-command flag system.
Commands must opt in to being available for untrusted connections
via flag_untrusted_safe (0x400), checked in call_command() which
catches all execution paths including nested commands.
Infrastructure changes:
- Add flag_untrusted_safe to CommandMap
- Add untrusted_error exception type for proper error codes
- Enforce trust check in both call_command() overloads
- Add catch blocks in xmlrpc_c, xmlrpc_tinyxml2, and jsonrpc handlers
- Port SCGI trust state management from v2 (thread_local, header parsing)
- Add _U macro variants in command_helpers.h for safe command registration
- Add CMD2_VAR_*_U and CMD2_VAR_*_U_GET variants for variables
2026-03-23 15:11:07 +01:00
Jari Sundell
48f82c17c2
Remove deprecated no-target flags for commands.
2025-09-20 17:27:26 +09:00
Jorge Israel Peña
58a74cee48
Wrap fault struct in value
2025-05-02 12:13:49 +02:00
rakshasa
8ac31afd06
Fixed tinyxml2 compile error.
2025-03-28 16:07:55 +01:00
kannibalox
9f48226663
Add JSON-RPC capability
...
Inline nlohmann/json for the JSON parsing itself, and handle requests
with the same SCGI interface as XML-RPC.
Based off the work in https://github.com/jesec/rtorrent
2025-01-20 12:31:04 +01:00
simonc56
2bf81aa8f5
tinyxml2: array with data for dict type
2025-01-01 21:33:30 +09:00
simonc56
a9c0b65b9d
tinyxml2: in xmlrpc an array must include values in a data element
2025-01-01 21:33:30 +09:00
stickz
73fed24459
tinyxml2: Change from i4 to i8
...
We need to follow the same specification as xmlrpc-c until we deprecate it. It is breaking various software such as sonarr. We can't have xmlrpc using i8 and tinyxml2 using i4, while we allow both to be used.
2025-01-01 21:32:23 +09:00
kannibalox
8f0331625a
Correctly handle commands that are flagged as not using targets
...
Fixes #1346
2024-12-27 01:00:23 +09:00
kannibalox
5792ed1ae2
Apply clang-format
2024-12-07 19:26:29 +09:00
kannibalox
8cfc71b936
Fix system.multicall parameter parsing
2024-12-07 19:26:29 +09:00
kannibalox
f33c2560a3
Default to an empty list when not passed explicit <params>
2024-12-07 19:26:29 +09:00
kannibalox
48c40ee0c6
Fix typo: methodReponse -> methodResponse
2024-12-07 19:26:29 +09:00
kannibalox
3aeb213dc4
Avoid <int> in tinyxml2 responses
...
It's part of the XML-RPC spec, but some clients only accept i4/i8, which
should be supported nearly universally.
Fixes #1330
2024-12-07 19:26:29 +09:00
kannibalox
b3fabd2a2b
Align argument name with header definition
2024-11-25 18:44:28 +09:00
kannibalox
4b7c3ffafe
Use empty() instead of checking size
...
Also use a const pointer for a child element
2024-11-25 18:44:28 +09:00
kannibalox
730d43b6c7
Explicitly mark narrowing conversion
2024-11-25 18:44:28 +09:00
kannibalox
af2f30c183
Remove unused variable
2024-11-25 18:44:28 +09:00
kannibalox
36fd837d27
Fix unnecessary narrowing with proper return type
2024-11-25 18:44:28 +09:00
kannibalox
8dd8d691c5
Explicitly check result of std::strncmp
2024-11-25 18:44:28 +09:00
kannibalox
e367b162ab
Share object_to_target between tinyxml2 and xmlrpc-c
2024-11-25 18:44:28 +09:00
kannibalox
49cdfee65a
Avoid ambiguous value_* in variable names
2024-11-25 18:44:28 +09:00
kannibalox
5680db3598
Parse out target param first if available
2024-11-25 18:44:28 +09:00
kannibalox
fa2c7d961b
Remove unnecessary std::string() and use lowercase for error msgs
2024-11-25 18:44:28 +09:00
kannibalox
d6dcbc4a69
Add size limit to XML-RPC documents, defaulting to max SCGI size
2024-11-25 18:44:28 +09:00
kannibalox
cadfcb50d2
Print iterator for TYPE_DICT_KEY, not object
2024-11-25 18:44:28 +09:00
kannibalox
71a39cd8a0
Keep as_*() outside of loops
2024-11-25 18:44:28 +09:00
kannibalox
0658486966
Change base64 decoder name, and add util for removing newlines
2024-11-25 18:44:28 +09:00
kannibalox
687fbbb83d
Formatting
2024-11-25 18:44:28 +09:00
kannibalox
f9c9fa2e3b
Move int element converter to helper function
...
Also fix strncmp checks
2024-11-25 18:44:28 +09:00
kannibalox
782b1e4ea8
Skip converting value_element_type to std::string
2024-11-25 18:44:28 +09:00
kannibalox
67babb65d6
Convert element_access to use initializer lists
...
Also remove uses element_access for single child accesses
2024-11-25 18:44:28 +09:00
kannibalox
e0d5c95821
Use correct terminology in comment
2024-11-25 18:44:28 +09:00
kannibalox
dd45684584
Move vendored tinyxml2 files to rpc namespace and directory
2024-11-25 18:44:28 +09:00
kannibalox
fb8632e990
Change lingering camelCase to snake_case
2024-11-25 18:44:28 +09:00
kannibalox
b043b7b39e
Simplify iterator names
2024-11-25 18:44:28 +09:00
kannibalox
168093d256
Remove extra return
2024-11-25 18:44:28 +09:00
kannibalox
4a9d9952e1
Be explicit about the desired result
2024-11-25 18:44:28 +09:00
kannibalox
fd1d5dbdb2
Add test case for bad boolean value
2024-11-25 18:44:28 +09:00
kannibalox
3a8e462bd3
Throw error if attempting to use both xmlrpc-c and tinyxml2
2024-11-25 18:44:28 +09:00
kannibalox
b360a734f1
Use std::strtoll instead of std::stol
2024-11-25 18:44:28 +09:00
kannibalox
c18df7a366
Use std::strncmp for string comparison
2024-11-25 18:44:28 +09:00
kannibalox
a269f808e1
Fix swapped variable names
2024-11-25 18:44:28 +09:00
kannibalox
4444df2e97
Change internal error to type error
2024-11-25 18:44:28 +09:00
kannibalox
5a194ab037
Remove stack from exception message
2024-11-25 18:44:28 +09:00
kannibalox
1b43f8b591
Use snake case for variable names
...
Also use `||` instead of `or`, and throw an error if an unknown boolean
string is received
2024-11-25 18:44:28 +09:00
kannibalox
d6427203a4
Refactor to only use a position variable
2024-11-25 18:44:28 +09:00
kannibalox
87c6422052
Allow using vendored tinyxml2 for XMLRPC
...
By default, builds will still not have XMLRPC enabled at all and the
configure flag `--with-xmlrpc-tinyxml2` must be specified. If both
xmlrpc-c and tinyxml2 are specified, xmlrpc-c takes precedence.
Basic benchmarks indicate tinyxml2 is 2x faster for small
requests/responses, and that only increases as response sizes get
larger.
2024-11-25 18:44:28 +09:00