Commit 8ec5800e authored by Eric Covener's avatar Eric Covener
Browse files

Add StrictHostCheck

.. to allow ucnonfigured hostnames to be rejected. 

The checks happen during NVH mapping and checks that the
mapped VH itself has the host as a name or alias.



git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1838055 13f79535-47bb-0310-9956-ffa450edef68
parent c512efe0
Loading
Loading
Loading
Loading
+3 −0
Changes for CHANGES: 3 added lines, 0 removed lines.
Original line number Diff line number Diff line
                                                         -*- coding: utf-8 -*-
Changes with Apache 2.5.1

  *) core: Add StrictHostCheck to allow ucnonfigured hostnames to be
     rejected. [Eric Covener]

  *) mod_status: Cumulate CPU time of exited child processes in the
     "cu" and "cs" values. Add CPU time of the parent process to the
     "c" and "s" values.
+34 −0
Changes for docs/manual/mod/core.xml: 34 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -5240,6 +5240,40 @@ as if 'QualifyRedirectURL ON' was configured.</compatibility>
</usage>
</directivesynopsis>

<directivesynopsis>
<name>StrictHostCheck</name>
<description>Controls whether the server requires the requested hostname be
             listed enumerated in the virtual host handling the request
             </description>
<syntax>StrictHostCheck ON|OFF</syntax>
<default>StrictHostCheck OFF</default>
<contextlist><context>server config</context><context>virtual host</context>
</contextlist>
<compatibility>Added in 2.5.1</compatibility>

<usage>
    <p>By default, the server will respond to requests for any hostname,
    including requests addressed to unexpected or unconfigured hostnames. 
    While this is convenient, it is sometimes desirable to limit what hostnames
    a backend application handles since it will often generate self-referential
    responses.</p>

    <p>By setting <directive>StrictHostCheck</directive> to <em>ON</em>,
    the server will return an HTTP 400 error if the requested hostname
    hasn't been explicitly listed by either <directive module="core"
    >ServerName</directive> or <directive module="core"
    >ServerAlias</directive> in the virtual host that best matches the
    details of the incoming connection.</p>

   <p>This directive also allows matching of the requested hostname to hostnames
   specified within the opening <directive module="core">VirtualHost</directive>
   tag, which is a relatively obscure configuration mechanism that acts like
   additional <directive module="core">ServerAlias</directive> entries.</p>

   <p>This directive has no affect in non-default virtual hosts. The value
   inherited from the global server configuration, or the default virtualhost 
   for the ip:port the underlying connection, determine the effective value.</p>
</usage>
</directivesynopsis>

</modulesynopsis>
+1 −0
Changes for include/http_core.h: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -770,6 +770,7 @@ typedef struct {
 
    apr_size_t   flush_max_threshold;
    apr_int32_t  flush_max_pipelined;
    unsigned int strict_host_check;
} core_server_config;

/* for AddOutputFiltersByType in core.c */
+13 −0
Changes for include/http_vhost.h: 13 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -99,6 +99,19 @@ AP_DECLARE(void) ap_update_vhost_given_ip(conn_rec *conn);
 */
AP_DECLARE(void) ap_update_vhost_from_headers(request_rec *r);

/**
 * Updates r->server with the best name-based virtual host match, within
 * the chain of matching virtual hosts selected by ap_update_vhost_given_ip.
 * @param r The current request
 * @param require_match 1 to return an HTTP error if the requested hostname is
 * not explicitly matched to a VirtualHost. 
 * @return return HTTP_OK unless require_match was specified and the requested
 * hostname did not match any ServerName, ServerAlias, or VirtualHost 
 * address-spec.
 */
AP_DECLARE(int) ap_update_vhost_from_headers_ex(request_rec *r, int require_match);


/**
 * Match the host in the header with the hostname of the server for this
 * request.
+17 −3
Changes for server/core.c: 17 added lines, 3 removed lines.
Original line number Diff line number Diff line
@@ -525,6 +525,7 @@ static void *create_core_server_config(apr_pool_t *a, server_rec *s)
    conf->protocols = apr_array_make(a, 5, sizeof(const char *));
    conf->protocols_honor_order = -1;
    conf->async_filter = 0;
    conf->strict_host_check= AP_CORE_CONFIG_UNSET; 

    return (void *)conf;
}
@@ -620,6 +621,12 @@ static void *merge_core_server_configs(apr_pool_t *p, void *basev, void *virtv)
                                  ? virt->flush_max_pipelined
                                  : base->flush_max_pipelined;

    conf->strict_host_check = (virt->strict_host_check != AP_CORE_CONFIG_UNSET)
                              ? virt->strict_host_check 
                              : base->strict_host_check;

    AP_CORE_MERGE_FLAG(strict_host_check, conf, base, virt);

    return conf;
}

@@ -1962,7 +1969,12 @@ static const char *set_qualify_redirect_url(cmd_parms *cmd, void *d_, int flag)

    return NULL;
}

static const char *set_core_server_flag(cmd_parms *cmd, void *s_, int flag)
{
    core_server_config *conf =
        ap_get_core_module_config(cmd->server->module_config);
    return ap_set_flag_slot(cmd, conf, flag);
}
static const char *set_override_list(cmd_parms *cmd, void *d_, int argc, char *const argv[])
{
    core_dir_config *d = d_;
@@ -4816,7 +4828,10 @@ AP_INIT_TAKE2("CGIVar", set_cgi_var, NULL, OR_FILEINFO,
AP_INIT_FLAG("QualifyRedirectURL", set_qualify_redirect_url, NULL, OR_FILEINFO,
             "Controls whether the REDIRECT_URL environment variable is fully "
             "qualified"),

AP_INIT_FLAG("StrictHostCheck", set_core_server_flag, 
             (void *)APR_OFFSETOF(core_server_config, strict_host_check),  
             RSRC_CONF,
             "Controls whether a hostname match is required"),
AP_INIT_TAKE1("ForceType", ap_set_string_slot_lower,
       (void *)APR_OFFSETOF(core_dir_config, mime_type), OR_FILEINFO,
     "a mime type that overrides other configured type"),
@@ -5891,4 +5906,3 @@ AP_DECLARE_MODULE(core) = {
    core_cmds,                    /* command apr_table_t */
    register_hooks                /* register hooks */
};
Loading