2002-09-03 19:52:59 +08:00
|
|
|
/***************************************************************************
|
2004-02-23 16:22:43 +08:00
|
|
|
* _ _ ____ _
|
|
|
|
* Project ___| | | | _ \| |
|
|
|
|
* / __| | | | |_) | |
|
|
|
|
* | (__| |_| | _ <| |___
|
2001-08-03 21:51:44 +08:00
|
|
|
* \___|\___/|_| \_\_____|
|
|
|
|
*
|
2023-01-02 20:51:48 +08:00
|
|
|
* Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
|
2001-08-03 21:51:44 +08:00
|
|
|
*
|
2002-09-03 19:52:59 +08:00
|
|
|
* This software is licensed as described in the file COPYING, which
|
|
|
|
* you should have received as part of this distribution. The terms
|
2020-11-04 21:02:01 +08:00
|
|
|
* are also available at https://curl.se/docs/copyright.html.
|
2004-02-23 16:22:43 +08:00
|
|
|
*
|
2001-08-03 21:51:44 +08:00
|
|
|
* You may opt to use, copy, modify, merge, publish, distribute and/or sell
|
|
|
|
* copies of the Software, and permit persons to whom the Software is
|
2002-09-03 19:52:59 +08:00
|
|
|
* furnished to do so, under the terms of the COPYING file.
|
2001-08-03 21:51:44 +08:00
|
|
|
*
|
|
|
|
* This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
|
|
|
|
* KIND, either express or implied.
|
|
|
|
*
|
2011-08-24 14:07:36 +08:00
|
|
|
* SPDX-License-Identifier: curl
|
2022-05-17 17:16:50 +08:00
|
|
|
*
|
2002-09-03 19:52:59 +08:00
|
|
|
***************************************************************************/
|
2001-08-03 21:51:44 +08:00
|
|
|
|
2011-04-18 05:03:33 +08:00
|
|
|
/* Base64 encoding/decoding */
|
2000-09-28 16:01:52 +08:00
|
|
|
|
2013-01-07 02:06:49 +08:00
|
|
|
#include "curl_setup.h"
|
2019-05-05 23:08:21 +08:00
|
|
|
|
2019-08-16 22:19:43 +08:00
|
|
|
#if !defined(CURL_DISABLE_HTTP_AUTH) || defined(USE_SSH) || \
|
|
|
|
!defined(CURL_DISABLE_LDAP) || \
|
2020-09-08 15:23:09 +08:00
|
|
|
!defined(CURL_DISABLE_SMTP) || \
|
2020-09-10 04:32:17 +08:00
|
|
|
!defined(CURL_DISABLE_POP3) || \
|
|
|
|
!defined(CURL_DISABLE_IMAP) || \
|
2023-12-02 08:09:29 +08:00
|
|
|
!defined(CURL_DISABLE_DIGEST_AUTH) || \
|
2023-10-02 21:10:55 +08:00
|
|
|
!defined(CURL_DISABLE_DOH) || defined(USE_SSL) || defined(BUILDING_CURL)
|
2023-07-31 17:50:28 +08:00
|
|
|
#include "curl/curl.h"
|
2013-01-04 09:50:28 +08:00
|
|
|
#include "warnless.h"
|
2008-08-17 08:25:38 +08:00
|
|
|
#include "curl_base64.h"
|
2000-09-28 16:01:52 +08:00
|
|
|
|
2022-12-04 07:34:09 +08:00
|
|
|
/* The last 2 #include files should be in this order */
|
2023-07-31 17:50:28 +08:00
|
|
|
#ifdef BUILDING_LIBCURL
|
2015-03-25 06:12:03 +08:00
|
|
|
#include "curl_memory.h"
|
2023-07-31 17:50:28 +08:00
|
|
|
#endif
|
2013-01-04 09:50:28 +08:00
|
|
|
#include "memdebug.h"
|
2004-05-11 19:30:23 +08:00
|
|
|
|
2007-01-04 07:04:38 +08:00
|
|
|
/* ---- Base64 Encoding/Decoding Table --- */
|
2022-07-13 01:03:45 +08:00
|
|
|
/* Padding character string starts at offset 64. */
|
2023-05-09 18:10:40 +08:00
|
|
|
static const char base64encdec[]=
|
2022-07-13 01:03:45 +08:00
|
|
|
"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=";
|
2000-10-09 19:12:34 +08:00
|
|
|
|
2022-10-11 22:01:37 +08:00
|
|
|
/* The Base 64 encoding with a URL and filename safe alphabet, RFC 4648
|
2014-07-25 14:24:03 +08:00
|
|
|
section 5 */
|
|
|
|
static const char base64url[]=
|
|
|
|
"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_";
|
|
|
|
|
2022-12-05 16:40:10 +08:00
|
|
|
static const unsigned char decodetable[] =
|
|
|
|
{ 62, 255, 255, 255, 63, 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 255, 255, 255,
|
|
|
|
255, 255, 255, 255, 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16,
|
|
|
|
17, 18, 19, 20, 21, 22, 23, 24, 25, 255, 255, 255, 255, 255, 255, 26, 27, 28,
|
|
|
|
29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47,
|
|
|
|
48, 49, 50, 51 };
|
2004-02-23 16:22:43 +08:00
|
|
|
/*
|
|
|
|
* Curl_base64_decode()
|
|
|
|
*
|
2011-08-24 14:07:36 +08:00
|
|
|
* Given a base64 NUL-terminated string at src, decode it and return a
|
|
|
|
* pointer in *outptr to a newly allocated memory area holding decoded
|
|
|
|
* data. Size of decoded data is returned in variable pointed by outlen.
|
|
|
|
*
|
|
|
|
* Returns CURLE_OK on success, otherwise specific error code. Function
|
|
|
|
* output shall not be considered valid unless CURLE_OK is returned.
|
|
|
|
*
|
|
|
|
* When decoded data length is 0, returns NULL in *outptr.
|
2011-06-10 20:40:46 +08:00
|
|
|
*
|
|
|
|
* @unittest: 1302
|
2001-08-03 21:51:44 +08:00
|
|
|
*/
|
2011-08-24 14:07:36 +08:00
|
|
|
CURLcode Curl_base64_decode(const char *src,
|
|
|
|
unsigned char **outptr, size_t *outlen)
|
2000-09-28 16:01:52 +08:00
|
|
|
{
|
2013-12-01 21:47:11 +08:00
|
|
|
size_t srclen = 0;
|
|
|
|
size_t padding = 0;
|
2010-02-20 09:15:10 +08:00
|
|
|
size_t i;
|
|
|
|
size_t numQuantums;
|
2022-12-05 16:40:10 +08:00
|
|
|
size_t fullQuantums;
|
2010-02-20 09:15:10 +08:00
|
|
|
size_t rawlen = 0;
|
2013-12-01 19:05:11 +08:00
|
|
|
unsigned char *pos;
|
2005-02-22 20:10:30 +08:00
|
|
|
unsigned char *newstr;
|
2022-12-05 16:40:10 +08:00
|
|
|
unsigned char lookup[256];
|
2005-02-22 20:10:30 +08:00
|
|
|
|
|
|
|
*outptr = NULL;
|
2011-08-24 14:07:36 +08:00
|
|
|
*outlen = 0;
|
2013-12-01 21:47:11 +08:00
|
|
|
srclen = strlen(src);
|
2004-02-23 16:22:43 +08:00
|
|
|
|
2013-10-30 15:31:22 +08:00
|
|
|
/* Check the length of the input string is valid */
|
2013-12-01 21:47:11 +08:00
|
|
|
if(!srclen || srclen % 4)
|
2013-10-30 15:31:22 +08:00
|
|
|
return CURLE_BAD_CONTENT_ENCODING;
|
|
|
|
|
2022-12-05 16:40:10 +08:00
|
|
|
/* srclen is at least 4 here */
|
|
|
|
while(src[srclen - 1 - padding] == '=') {
|
|
|
|
/* count padding characters */
|
2013-12-01 21:47:11 +08:00
|
|
|
padding++;
|
2022-07-13 01:03:45 +08:00
|
|
|
/* A maximum of two = padding characters is allowed */
|
2022-12-05 16:40:10 +08:00
|
|
|
if(padding > 2)
|
2022-07-13 01:03:45 +08:00
|
|
|
return CURLE_BAD_CONTENT_ENCODING;
|
|
|
|
}
|
2004-02-23 16:22:43 +08:00
|
|
|
|
2013-10-30 15:31:22 +08:00
|
|
|
/* Calculate the number of quantums */
|
2013-12-01 21:47:11 +08:00
|
|
|
numQuantums = srclen / 4;
|
2022-12-05 16:40:10 +08:00
|
|
|
fullQuantums = numQuantums - (padding ? 1 : 0);
|
2005-03-01 07:54:17 +08:00
|
|
|
|
2013-10-30 15:31:22 +08:00
|
|
|
/* Calculate the size of the decoded string */
|
2013-12-01 21:47:11 +08:00
|
|
|
rawlen = (numQuantums * 3) - padding;
|
2004-02-23 16:22:43 +08:00
|
|
|
|
2022-09-17 23:32:21 +08:00
|
|
|
/* Allocate our buffer including room for a null-terminator */
|
2013-12-01 03:09:09 +08:00
|
|
|
newstr = malloc(rawlen + 1);
|
2005-02-22 20:10:30 +08:00
|
|
|
if(!newstr)
|
2011-08-24 14:07:36 +08:00
|
|
|
return CURLE_OUT_OF_MEMORY;
|
2005-02-22 20:10:30 +08:00
|
|
|
|
2013-12-01 19:05:11 +08:00
|
|
|
pos = newstr;
|
2005-02-22 20:10:30 +08:00
|
|
|
|
2022-12-05 16:40:10 +08:00
|
|
|
memset(lookup, 0xff, sizeof(lookup));
|
|
|
|
memcpy(&lookup['+'], decodetable, sizeof(decodetable));
|
|
|
|
/* replaces
|
|
|
|
{
|
|
|
|
unsigned char c;
|
2023-05-09 18:10:40 +08:00
|
|
|
const unsigned char *p = (const unsigned char *)base64encdec;
|
2022-12-05 16:40:10 +08:00
|
|
|
for(c = 0; *p; c++, p++)
|
|
|
|
lookup[*p] = c;
|
|
|
|
}
|
|
|
|
*/
|
|
|
|
|
|
|
|
/* Decode the complete quantums first */
|
|
|
|
for(i = 0; i < fullQuantums; i++) {
|
|
|
|
unsigned char val;
|
|
|
|
unsigned int x = 0;
|
|
|
|
int j;
|
|
|
|
|
|
|
|
for(j = 0; j < 4; j++) {
|
|
|
|
val = lookup[(unsigned char)*src++];
|
|
|
|
if(val == 0xff) /* bad symbol */
|
|
|
|
goto bad;
|
|
|
|
x = (x << 6) | val;
|
2013-12-01 19:05:11 +08:00
|
|
|
}
|
2022-12-05 16:40:10 +08:00
|
|
|
pos[2] = x & 0xff;
|
|
|
|
pos[1] = (x >> 8) & 0xff;
|
|
|
|
pos[0] = (x >> 16) & 0xff;
|
|
|
|
pos += 3;
|
|
|
|
}
|
|
|
|
if(padding) {
|
|
|
|
/* this means either 8 or 16 bits output */
|
|
|
|
unsigned char val;
|
|
|
|
unsigned int x = 0;
|
|
|
|
int j;
|
|
|
|
size_t padc = 0;
|
|
|
|
for(j = 0; j < 4; j++) {
|
|
|
|
if(*src == '=') {
|
|
|
|
x <<= 6;
|
|
|
|
src++;
|
|
|
|
if(++padc > padding)
|
|
|
|
/* this is a badly placed '=' symbol! */
|
|
|
|
goto bad;
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
val = lookup[(unsigned char)*src++];
|
|
|
|
if(val == 0xff) /* bad symbol */
|
|
|
|
goto bad;
|
|
|
|
x = (x << 6) | val;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if(padding == 1)
|
|
|
|
pos[1] = (x >> 8) & 0xff;
|
|
|
|
pos[0] = (x >> 16) & 0xff;
|
|
|
|
pos += 3 - padding;
|
2000-09-28 16:01:52 +08:00
|
|
|
}
|
2001-08-03 21:51:44 +08:00
|
|
|
|
2013-12-01 03:09:09 +08:00
|
|
|
/* Zero terminate */
|
2013-12-01 21:47:11 +08:00
|
|
|
*pos = '\0';
|
2011-08-24 14:07:36 +08:00
|
|
|
|
2013-12-01 19:05:11 +08:00
|
|
|
/* Return the decoded data */
|
|
|
|
*outptr = newstr;
|
2013-12-01 03:09:09 +08:00
|
|
|
*outlen = rawlen;
|
2011-08-24 14:07:36 +08:00
|
|
|
|
|
|
|
return CURLE_OK;
|
2023-05-18 12:54:18 +08:00
|
|
|
bad:
|
2022-12-05 16:40:10 +08:00
|
|
|
free(newstr);
|
|
|
|
return CURLE_BAD_CONTENT_ENCODING;
|
2000-09-28 16:01:52 +08:00
|
|
|
}
|
2000-09-21 16:46:44 +08:00
|
|
|
|
2014-07-25 14:24:03 +08:00
|
|
|
static CURLcode base64_encode(const char *table64,
|
|
|
|
const char *inputbuff, size_t insize,
|
|
|
|
char **outptr, size_t *outlen)
|
2000-09-28 16:01:52 +08:00
|
|
|
{
|
2001-08-03 21:51:44 +08:00
|
|
|
char *output;
|
|
|
|
char *base64data;
|
2022-12-04 07:34:09 +08:00
|
|
|
const unsigned char *in = (unsigned char *)inputbuff;
|
2022-07-13 01:03:45 +08:00
|
|
|
const char *padstr = &table64[64]; /* Point to padding string. */
|
2001-08-03 21:51:44 +08:00
|
|
|
|
2011-08-24 14:07:36 +08:00
|
|
|
*outptr = NULL;
|
|
|
|
*outlen = 0;
|
2004-05-12 21:23:17 +08:00
|
|
|
|
2016-03-14 01:59:06 +08:00
|
|
|
if(!insize)
|
2022-12-04 07:34:09 +08:00
|
|
|
insize = strlen(inputbuff);
|
2001-08-03 21:51:44 +08:00
|
|
|
|
2016-09-28 06:05:12 +08:00
|
|
|
#if SIZEOF_SIZE_T == 4
|
|
|
|
if(insize > UINT_MAX/4)
|
|
|
|
return CURLE_OUT_OF_MEMORY;
|
|
|
|
#endif
|
|
|
|
|
2022-12-04 07:07:52 +08:00
|
|
|
base64data = output = malloc((insize + 2) / 3 * 4 + 1);
|
2016-03-14 01:59:06 +08:00
|
|
|
if(!output)
|
2011-08-24 14:07:36 +08:00
|
|
|
return CURLE_OUT_OF_MEMORY;
|
2001-08-03 21:51:44 +08:00
|
|
|
|
2022-12-04 07:34:09 +08:00
|
|
|
while(insize >= 3) {
|
|
|
|
*output++ = table64[ in[0] >> 2 ];
|
|
|
|
*output++ = table64[ ((in[0] & 0x03) << 4) | (in[1] >> 4) ];
|
|
|
|
*output++ = table64[ ((in[1] & 0x0F) << 2) | ((in[2] & 0xC0) >> 6) ];
|
|
|
|
*output++ = table64[ in[2] & 0x3F ];
|
|
|
|
insize -= 3;
|
|
|
|
in += 3;
|
|
|
|
}
|
|
|
|
if(insize) {
|
|
|
|
/* this is only one or two bytes now */
|
|
|
|
*output++ = table64[ in[0] >> 2 ];
|
|
|
|
if(insize == 1) {
|
|
|
|
*output++ = table64[ ((in[0] & 0x03) << 4) ];
|
|
|
|
if(*padstr) {
|
|
|
|
*output++ = *padstr;
|
|
|
|
*output++ = *padstr;
|
2001-08-03 21:51:44 +08:00
|
|
|
}
|
1999-12-29 22:20:26 +08:00
|
|
|
}
|
2022-12-04 07:34:09 +08:00
|
|
|
else {
|
|
|
|
/* insize == 2 */
|
|
|
|
*output++ = table64[ ((in[0] & 0x03) << 4) | ((in[1] & 0xF0) >> 4) ];
|
|
|
|
*output++ = table64[ ((in[1] & 0x0F) << 2) ];
|
|
|
|
if(*padstr)
|
|
|
|
*output++ = *padstr;
|
1999-12-29 22:20:26 +08:00
|
|
|
}
|
|
|
|
}
|
2016-03-14 01:59:06 +08:00
|
|
|
|
|
|
|
/* Zero terminate */
|
2011-08-24 14:07:36 +08:00
|
|
|
*output = '\0';
|
2016-03-14 01:59:06 +08:00
|
|
|
|
|
|
|
/* Return the pointer to the new data (allocated memory) */
|
|
|
|
*outptr = base64data;
|
2001-08-03 21:51:44 +08:00
|
|
|
|
2016-03-14 01:59:06 +08:00
|
|
|
/* Return the length of the new data */
|
2022-02-01 20:39:06 +08:00
|
|
|
*outlen = output - base64data;
|
2011-08-24 14:07:36 +08:00
|
|
|
|
|
|
|
return CURLE_OK;
|
2001-08-03 21:51:44 +08:00
|
|
|
}
|
2014-07-25 14:24:03 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Curl_base64_encode()
|
|
|
|
*
|
|
|
|
* Given a pointer to an input buffer and an input size, encode it and
|
|
|
|
* return a pointer in *outptr to a newly allocated memory area holding
|
|
|
|
* encoded data. Size of encoded data is returned in variable pointed by
|
|
|
|
* outlen.
|
|
|
|
*
|
|
|
|
* Input length of 0 indicates input buffer holds a NUL-terminated string.
|
|
|
|
*
|
|
|
|
* Returns CURLE_OK on success, otherwise specific error code. Function
|
|
|
|
* output shall not be considered valid unless CURLE_OK is returned.
|
|
|
|
*
|
|
|
|
* @unittest: 1302
|
|
|
|
*/
|
2022-02-03 20:04:30 +08:00
|
|
|
CURLcode Curl_base64_encode(const char *inputbuff, size_t insize,
|
2014-07-25 14:24:03 +08:00
|
|
|
char **outptr, size_t *outlen)
|
|
|
|
{
|
2023-05-09 18:10:40 +08:00
|
|
|
return base64_encode(base64encdec, inputbuff, insize, outptr, outlen);
|
2014-07-25 14:24:03 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Curl_base64url_encode()
|
|
|
|
*
|
|
|
|
* Given a pointer to an input buffer and an input size, encode it and
|
|
|
|
* return a pointer in *outptr to a newly allocated memory area holding
|
|
|
|
* encoded data. Size of encoded data is returned in variable pointed by
|
|
|
|
* outlen.
|
|
|
|
*
|
|
|
|
* Input length of 0 indicates input buffer holds a NUL-terminated string.
|
|
|
|
*
|
|
|
|
* Returns CURLE_OK on success, otherwise specific error code. Function
|
|
|
|
* output shall not be considered valid unless CURLE_OK is returned.
|
|
|
|
*
|
2014-07-25 14:38:16 +08:00
|
|
|
* @unittest: 1302
|
2014-07-25 14:24:03 +08:00
|
|
|
*/
|
2022-02-03 20:04:30 +08:00
|
|
|
CURLcode Curl_base64url_encode(const char *inputbuff, size_t insize,
|
2014-07-25 14:24:03 +08:00
|
|
|
char **outptr, size_t *outlen)
|
|
|
|
{
|
2022-02-03 20:04:30 +08:00
|
|
|
return base64_encode(base64url, inputbuff, insize, outptr, outlen);
|
2014-07-25 14:24:03 +08:00
|
|
|
}
|
2019-05-05 23:08:21 +08:00
|
|
|
|
|
|
|
#endif /* no users so disabled */
|