http_aws_sigv4.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523
  1. /***************************************************************************
  2. * _ _ ____ _
  3. * Project ___| | | | _ \| |
  4. * / __| | | | |_) | |
  5. * | (__| |_| | _ <| |___
  6. * \___|\___/|_| \_\_____|
  7. *
  8. * Copyright (C) 1998 - 2022, Daniel Stenberg, <daniel@haxx.se>, et al.
  9. *
  10. * This software is licensed as described in the file COPYING, which
  11. * you should have received as part of this distribution. The terms
  12. * are also available at https://curl.haxx.se/docs/copyright.html.
  13. *
  14. * You may opt to use, copy, modify, merge, publish, distribute and/or sell
  15. * copies of the Software, and permit persons to whom the Software is
  16. * furnished to do so, under the terms of the COPYING file.
  17. *
  18. * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
  19. * KIND, either express or implied.
  20. *
  21. * SPDX-License-Identifier: curl
  22. *
  23. ***************************************************************************/
  24. #include "curl_setup.h"
  25. #if !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_CRYPTO_AUTH)
  26. #include "urldata.h"
  27. #include "strcase.h"
  28. #include "strdup.h"
  29. #include "http_aws_sigv4.h"
  30. #include "curl_sha256.h"
  31. #include "transfer.h"
  32. #include "parsedate.h"
  33. #include "sendf.h"
  34. #include <time.h>
  35. /* The last 3 #include files should be in this order */
  36. #include "curl_printf.h"
  37. #include "curl_memory.h"
  38. #include "memdebug.h"
  39. #include "slist.h"
  40. #define HMAC_SHA256(k, kl, d, dl, o) \
  41. do { \
  42. ret = Curl_hmacit(Curl_HMAC_SHA256, \
  43. (unsigned char *)k, \
  44. (unsigned int)kl, \
  45. (unsigned char *)d, \
  46. (unsigned int)dl, o); \
  47. if(ret) { \
  48. goto fail; \
  49. } \
  50. } while(0)
  51. #define TIMESTAMP_SIZE 17
  52. static void sha256_to_hex(char *dst, unsigned char *sha, size_t dst_l)
  53. {
  54. int i;
  55. DEBUGASSERT(dst_l >= 65);
  56. for(i = 0; i < 32; ++i) {
  57. msnprintf(dst + (i * 2), dst_l - (i * 2), "%02x", sha[i]);
  58. }
  59. }
  60. static char *find_date_hdr(struct Curl_easy *data, const char *sig_hdr)
  61. {
  62. char *tmp = Curl_checkheaders(data, sig_hdr, strlen(sig_hdr));
  63. if(tmp)
  64. return tmp;
  65. return Curl_checkheaders(data, STRCONST("Date"));
  66. }
  67. /* remove whitespace, and lowercase all headers */
  68. static void trim_headers(struct curl_slist *head)
  69. {
  70. struct curl_slist *l;
  71. for(l = head; l; l = l->next) {
  72. char *value; /* to read from */
  73. char *store;
  74. size_t colon = strcspn(l->data, ":");
  75. Curl_strntolower(l->data, l->data, colon);
  76. value = &l->data[colon];
  77. if(!*value)
  78. continue;
  79. ++value;
  80. store = value;
  81. /* skip leading whitespace */
  82. while(*value && ISBLANK(*value))
  83. value++;
  84. while(*value) {
  85. int space = 0;
  86. while(*value && ISBLANK(*value)) {
  87. value++;
  88. space++;
  89. }
  90. if(space) {
  91. /* replace any number of consecutive whitespace with a single space,
  92. unless at the end of the string, then nothing */
  93. if(*value)
  94. *store++ = ' ';
  95. }
  96. else
  97. *store++ = *value++;
  98. }
  99. *store = 0; /* null terminate */
  100. }
  101. }
  102. /* maximum lenth for the aws sivg4 parts */
  103. #define MAX_SIGV4_LEN 64
  104. #define MAX_SIGV4_LEN_TXT "64"
  105. #define DATE_HDR_KEY_LEN (MAX_SIGV4_LEN + sizeof("X--Date"))
  106. #define MAX_HOST_LEN 255
  107. /* FQDN + host: */
  108. #define FULL_HOST_LEN (MAX_HOST_LEN + sizeof("host:"))
  109. /* string been x-PROVIDER-date:TIMESTAMP, I need +1 for ':' */
  110. #define DATE_FULL_HDR_LEN (DATE_HDR_KEY_LEN + TIMESTAMP_SIZE + 1)
  111. /* timestamp should point to a buffer of at last TIMESTAMP_SIZE bytes */
  112. static CURLcode make_headers(struct Curl_easy *data,
  113. const char *hostname,
  114. char *timestamp,
  115. char *provider1,
  116. char **date_header,
  117. struct dynbuf *canonical_headers,
  118. struct dynbuf *signed_headers)
  119. {
  120. char date_hdr_key[DATE_HDR_KEY_LEN];
  121. char date_full_hdr[DATE_FULL_HDR_LEN];
  122. struct curl_slist *head = NULL;
  123. struct curl_slist *tmp_head = NULL;
  124. CURLcode ret = CURLE_OUT_OF_MEMORY;
  125. struct curl_slist *l;
  126. int again = 1;
  127. /* provider1 mid */
  128. Curl_strntolower(provider1, provider1, strlen(provider1));
  129. provider1[0] = Curl_raw_toupper(provider1[0]);
  130. msnprintf(date_hdr_key, DATE_HDR_KEY_LEN, "X-%s-Date", provider1);
  131. /* provider1 lowercase */
  132. Curl_strntolower(provider1, provider1, 1); /* first byte only */
  133. msnprintf(date_full_hdr, DATE_FULL_HDR_LEN,
  134. "x-%s-date:%s", provider1, timestamp);
  135. if(Curl_checkheaders(data, STRCONST("Host"))) {
  136. head = NULL;
  137. }
  138. else {
  139. char full_host[FULL_HOST_LEN + 1];
  140. if(data->state.aptr.host) {
  141. size_t pos;
  142. if(strlen(data->state.aptr.host) > FULL_HOST_LEN) {
  143. ret = CURLE_URL_MALFORMAT;
  144. goto fail;
  145. }
  146. strcpy(full_host, data->state.aptr.host);
  147. /* remove /r/n as the separator for canonical request must be '\n' */
  148. pos = strcspn(full_host, "\n\r");
  149. full_host[pos] = 0;
  150. }
  151. else {
  152. if(strlen(hostname) > MAX_HOST_LEN) {
  153. ret = CURLE_URL_MALFORMAT;
  154. goto fail;
  155. }
  156. msnprintf(full_host, FULL_HOST_LEN, "host:%s", hostname);
  157. }
  158. head = curl_slist_append(NULL, full_host);
  159. if(!head)
  160. goto fail;
  161. }
  162. for(l = data->set.headers; l; l = l->next) {
  163. tmp_head = curl_slist_append(head, l->data);
  164. if(!tmp_head)
  165. goto fail;
  166. head = tmp_head;
  167. }
  168. trim_headers(head);
  169. *date_header = find_date_hdr(data, date_hdr_key);
  170. if(!*date_header) {
  171. tmp_head = curl_slist_append(head, date_full_hdr);
  172. if(!tmp_head)
  173. goto fail;
  174. head = tmp_head;
  175. *date_header = curl_maprintf("%s: %s", date_hdr_key, timestamp);
  176. }
  177. else {
  178. char *value;
  179. *date_header = strdup(*date_header);
  180. if(!*date_header)
  181. goto fail;
  182. value = strchr(*date_header, ':');
  183. if(!value)
  184. goto fail;
  185. ++value;
  186. while(ISBLANK(*value))
  187. ++value;
  188. strncpy(timestamp, value, TIMESTAMP_SIZE - 1);
  189. timestamp[TIMESTAMP_SIZE - 1] = 0;
  190. }
  191. /* alpha-sort in a case sensitive manner */
  192. do {
  193. again = 0;
  194. for(l = head; l; l = l->next) {
  195. struct curl_slist *next = l->next;
  196. if(next && strcmp(l->data, next->data) > 0) {
  197. char *tmp = l->data;
  198. l->data = next->data;
  199. next->data = tmp;
  200. again = 1;
  201. }
  202. }
  203. } while(again);
  204. for(l = head; l; l = l->next) {
  205. char *tmp;
  206. if(Curl_dyn_add(canonical_headers, l->data))
  207. goto fail;
  208. if(Curl_dyn_add(canonical_headers, "\n"))
  209. goto fail;
  210. tmp = strchr(l->data, ':');
  211. if(tmp)
  212. *tmp = 0;
  213. if(l != head) {
  214. if(Curl_dyn_add(signed_headers, ";"))
  215. goto fail;
  216. }
  217. if(Curl_dyn_add(signed_headers, l->data))
  218. goto fail;
  219. }
  220. ret = CURLE_OK;
  221. fail:
  222. curl_slist_free_all(head);
  223. return ret;
  224. }
  225. CURLcode Curl_output_aws_sigv4(struct Curl_easy *data, bool proxy)
  226. {
  227. CURLcode ret = CURLE_OUT_OF_MEMORY;
  228. struct connectdata *conn = data->conn;
  229. size_t len;
  230. const char *arg;
  231. char provider0[MAX_SIGV4_LEN + 1]="";
  232. char provider1[MAX_SIGV4_LEN + 1]="";
  233. char region[MAX_SIGV4_LEN + 1]="";
  234. char service[MAX_SIGV4_LEN + 1]="";
  235. const char *hostname = conn->host.name;
  236. time_t clock;
  237. struct tm tm;
  238. char timestamp[TIMESTAMP_SIZE];
  239. char date[9];
  240. struct dynbuf canonical_headers;
  241. struct dynbuf signed_headers;
  242. char *date_header = NULL;
  243. const char *post_data = data->set.postfields;
  244. size_t post_data_len = 0;
  245. unsigned char sha_hash[32];
  246. char sha_hex[65];
  247. char *canonical_request = NULL;
  248. char *request_type = NULL;
  249. char *credential_scope = NULL;
  250. char *str_to_sign = NULL;
  251. const char *user = data->state.aptr.user ? data->state.aptr.user : "";
  252. char *secret = NULL;
  253. unsigned char sign0[32] = {0};
  254. unsigned char sign1[32] = {0};
  255. char *auth_headers = NULL;
  256. DEBUGASSERT(!proxy);
  257. (void)proxy;
  258. if(Curl_checkheaders(data, STRCONST("Authorization"))) {
  259. /* Authorization already present, Bailing out */
  260. return CURLE_OK;
  261. }
  262. /* we init thoses buffers here, so goto fail will free initialized dynbuf */
  263. Curl_dyn_init(&canonical_headers, CURL_MAX_HTTP_HEADER);
  264. Curl_dyn_init(&signed_headers, CURL_MAX_HTTP_HEADER);
  265. /*
  266. * Parameters parsing
  267. * Google and Outscale use the same OSC or GOOG,
  268. * but Amazon uses AWS and AMZ for header arguments.
  269. * AWS is the default because most of non-amazon providers
  270. * are still using aws:amz as a prefix.
  271. */
  272. arg = data->set.str[STRING_AWS_SIGV4] ?
  273. data->set.str[STRING_AWS_SIGV4] : "aws:amz";
  274. /* provider1[:provider2[:region[:service]]]
  275. No string can be longer than N bytes of non-whitespace
  276. */
  277. (void)sscanf(arg, "%" MAX_SIGV4_LEN_TXT "[^:]"
  278. ":%" MAX_SIGV4_LEN_TXT "[^:]"
  279. ":%" MAX_SIGV4_LEN_TXT "[^:]"
  280. ":%" MAX_SIGV4_LEN_TXT "s",
  281. provider0, provider1, region, service);
  282. if(!provider0[0]) {
  283. failf(data, "first provider can't be empty");
  284. ret = CURLE_BAD_FUNCTION_ARGUMENT;
  285. goto fail;
  286. }
  287. else if(!provider1[0])
  288. strcpy(provider1, provider0);
  289. if(!service[0]) {
  290. char *hostdot = strchr(hostname, '.');
  291. if(!hostdot) {
  292. failf(data, "service missing in parameters and hostname");
  293. ret = CURLE_URL_MALFORMAT;
  294. goto fail;
  295. }
  296. len = hostdot - hostname;
  297. if(len > MAX_SIGV4_LEN) {
  298. failf(data, "service too long in hostname");
  299. ret = CURLE_URL_MALFORMAT;
  300. goto fail;
  301. }
  302. strncpy(service, hostname, len);
  303. service[len] = '\0';
  304. if(!region[0]) {
  305. const char *reg = hostdot + 1;
  306. const char *hostreg = strchr(reg, '.');
  307. if(!hostreg) {
  308. failf(data, "region missing in parameters and hostname");
  309. ret = CURLE_URL_MALFORMAT;
  310. goto fail;
  311. }
  312. len = hostreg - reg;
  313. if(len > MAX_SIGV4_LEN) {
  314. failf(data, "region too long in hostname");
  315. ret = CURLE_URL_MALFORMAT;
  316. goto fail;
  317. }
  318. strncpy(region, reg, len);
  319. region[len] = '\0';
  320. }
  321. }
  322. #ifdef DEBUGBUILD
  323. {
  324. char *force_timestamp = getenv("CURL_FORCETIME");
  325. if(force_timestamp)
  326. clock = 0;
  327. else
  328. time(&clock);
  329. }
  330. #else
  331. time(&clock);
  332. #endif
  333. ret = Curl_gmtime(clock, &tm);
  334. if(ret) {
  335. goto fail;
  336. }
  337. if(!strftime(timestamp, sizeof(timestamp), "%Y%m%dT%H%M%SZ", &tm)) {
  338. ret = CURLE_OUT_OF_MEMORY;
  339. goto fail;
  340. }
  341. ret = make_headers(data, hostname, timestamp, provider1,
  342. &date_header, &canonical_headers, &signed_headers);
  343. if(ret)
  344. goto fail;
  345. ret = CURLE_OUT_OF_MEMORY;
  346. memcpy(date, timestamp, sizeof(date));
  347. date[sizeof(date) - 1] = 0;
  348. if(post_data) {
  349. if(data->set.postfieldsize < 0)
  350. post_data_len = strlen(post_data);
  351. else
  352. post_data_len = (size_t)data->set.postfieldsize;
  353. }
  354. if(Curl_sha256it(sha_hash, (const unsigned char *) post_data,
  355. post_data_len))
  356. goto fail;
  357. sha256_to_hex(sha_hex, sha_hash, sizeof(sha_hex));
  358. {
  359. Curl_HttpReq httpreq;
  360. const char *method;
  361. Curl_http_method(data, conn, &method, &httpreq);
  362. canonical_request =
  363. curl_maprintf("%s\n" /* HTTPRequestMethod */
  364. "%s\n" /* CanonicalURI */
  365. "%s\n" /* CanonicalQueryString */
  366. "%s\n" /* CanonicalHeaders */
  367. "%s\n" /* SignedHeaders */
  368. "%s", /* HashedRequestPayload in hex */
  369. method,
  370. data->state.up.path,
  371. data->state.up.query ? data->state.up.query : "",
  372. Curl_dyn_ptr(&canonical_headers),
  373. Curl_dyn_ptr(&signed_headers),
  374. sha_hex);
  375. if(!canonical_request)
  376. goto fail;
  377. }
  378. /* provider 0 lowercase */
  379. Curl_strntolower(provider0, provider0, strlen(provider0));
  380. request_type = curl_maprintf("%s4_request", provider0);
  381. if(!request_type)
  382. goto fail;
  383. credential_scope = curl_maprintf("%s/%s/%s/%s",
  384. date, region, service, request_type);
  385. if(!credential_scope)
  386. goto fail;
  387. if(Curl_sha256it(sha_hash, (unsigned char *) canonical_request,
  388. strlen(canonical_request)))
  389. goto fail;
  390. sha256_to_hex(sha_hex, sha_hash, sizeof(sha_hex));
  391. /* provider 0 uppercase */
  392. Curl_strntoupper(provider0, provider0, strlen(provider0));
  393. /*
  394. * Google allows using RSA key instead of HMAC, so this code might change
  395. * in the future. For now we ony support HMAC.
  396. */
  397. str_to_sign = curl_maprintf("%s4-HMAC-SHA256\n" /* Algorithm */
  398. "%s\n" /* RequestDateTime */
  399. "%s\n" /* CredentialScope */
  400. "%s", /* HashedCanonicalRequest in hex */
  401. provider0,
  402. timestamp,
  403. credential_scope,
  404. sha_hex);
  405. if(!str_to_sign) {
  406. goto fail;
  407. }
  408. /* provider 0 uppercase */
  409. secret = curl_maprintf("%s4%s", provider0,
  410. data->state.aptr.passwd ?
  411. data->state.aptr.passwd : "");
  412. if(!secret)
  413. goto fail;
  414. HMAC_SHA256(secret, strlen(secret), date, strlen(date), sign0);
  415. HMAC_SHA256(sign0, sizeof(sign0), region, strlen(region), sign1);
  416. HMAC_SHA256(sign1, sizeof(sign1), service, strlen(service), sign0);
  417. HMAC_SHA256(sign0, sizeof(sign0), request_type, strlen(request_type), sign1);
  418. HMAC_SHA256(sign1, sizeof(sign1), str_to_sign, strlen(str_to_sign), sign0);
  419. sha256_to_hex(sha_hex, sign0, sizeof(sha_hex));
  420. /* provider 0 uppercase */
  421. auth_headers = curl_maprintf("Authorization: %s4-HMAC-SHA256 "
  422. "Credential=%s/%s, "
  423. "SignedHeaders=%s, "
  424. "Signature=%s\r\n"
  425. "%s\r\n",
  426. provider0,
  427. user,
  428. credential_scope,
  429. Curl_dyn_ptr(&signed_headers),
  430. sha_hex,
  431. date_header);
  432. if(!auth_headers) {
  433. goto fail;
  434. }
  435. Curl_safefree(data->state.aptr.userpwd);
  436. data->state.aptr.userpwd = auth_headers;
  437. data->state.authhost.done = TRUE;
  438. ret = CURLE_OK;
  439. fail:
  440. Curl_dyn_free(&canonical_headers);
  441. Curl_dyn_free(&signed_headers);
  442. free(canonical_request);
  443. free(request_type);
  444. free(credential_scope);
  445. free(str_to_sign);
  446. free(secret);
  447. free(date_header);
  448. return ret;
  449. }
  450. #endif /* !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_CRYPTO_AUTH) */