Rework CGI error reporting.

- remove 'undocumented' stackTraceNL
- add 'undocumented' errorMessageWriter
- make printing errors for browser optional (for security)
This commit is contained in:
Michał Zieliński
2013-12-18 18:15:39 +01:00
parent 646458d328
commit 74a63c004f
2 changed files with 49 additions and 29 deletions

View File

@@ -342,16 +342,35 @@ proc writeContentType*() =
##
## .. code-block:: Nimrod
## write(stdout, "Content-type: text/html\n\n")
##
## It also modifies the debug stack traces so that they contain
## ``<br />`` and are easily readable in a browser.
write(stdout, "Content-type: text/html\n\n")
system.stackTraceNewLine = "<br />\n"
proc setStackTraceNewLine*() =
## Modifies the debug stack traces so that they contain
## ``<br />`` and are easily readable in a browser.
system.stackTraceNewLine = "<br />\n"
proc resetForStacktrace() =
stdout.write """<!--: spam
Content-Type: text/html
<body bgcolor=#f0f0f8><font color=#f0f0f8 size=-5> -->
<body bgcolor=#f0f0f8><font color=#f0f0f8 size=-5> --> -->
</font> </font> </font> </script> </object> </blockquote> </pre>
</table> </table> </table> </table> </table> </font> </font> </font>
"""
proc writeErrorMessage*(data: string) =
## Tries to reset browser state and writes `data` to stdout in
## <plaintext> tag.
resetForStacktrace()
# We use <plaintext> here, instead of escaping, so stacktrace can
# be understood by human looking at source.
stdout.write("<plaintext>\n")
stdout.write(data)
proc setStackTraceStdout*() =
## Makes Nimrod output stacktraces to stdout, instead of server log.
errorMessageWriter = writeErrorMessage
proc setStackTraceNewLine*() {.deprecated.} =
## Makes Nimrod output stacktraces to stdout, instead of server log.
## Depracated alias for setStackTraceStdout.
setStackTraceStdout()
proc setCookie*(name, value: string) =
## Sets a cookie.
@@ -374,4 +393,3 @@ when isMainModule:
const test1 = "abc\L+def xyz"
assert UrlEncode(test1) == "abc%0A%2Bdef+xyz"
assert UrlDecode(UrlEncode(test1)) == test1

View File

@@ -11,11 +11,10 @@
# use the heap (and nor exceptions) do not include the GC or memory allocator.
var
stackTraceNewLine*: string ## undocumented feature; it is replaced by ``<br>``
## for CGI applications
template stackTraceNL: expr =
(if IsNil(stackTraceNewLine): "\n" else: stackTraceNewLine)
errorMessageWriter*: (proc(msg: string): void {.tags: [FWriteIO].})
## Function that will be called
## instead of stdmsg.write when printing stacktrace.
## Unstable API.
when not defined(windows) or not defined(guiapp):
proc writeToStdErr(msg: CString) = write(stdmsg, msg)
@@ -27,6 +26,12 @@ else:
proc writeToStdErr(msg: CString) =
discard MessageBoxA(0, msg, nil, 0)
proc showErrorMessage(data: cstring) =
if errorMessageWriter != nil:
errorMessageWriter($data)
else:
writeToStdErr(data)
proc chckIndx(i, a, b: int): int {.inline, compilerproc.}
proc chckRange(i, a, b: int): int {.inline, compilerproc.}
proc chckRangeF(x, a, b: float): float {.inline, compilerproc.}
@@ -111,7 +116,7 @@ when defined(nativeStacktrace) and nativeStackTraceSupported:
add(s, tempDlInfo.dli_sname)
else:
add(s, '?')
add(s, stackTraceNL)
add(s, "\n")
else:
if dlresult != 0 and tempDlInfo.dli_sname != nil and
c_strcmp(tempDlInfo.dli_sname, "signalHandler") == 0'i32:
@@ -172,21 +177,18 @@ proc auxWriteStackTrace(f: PFrame, s: var string) =
add(s, ')')
for k in 1..max(1, 25-(s.len-oldLen)): add(s, ' ')
add(s, tempFrames[j].procname)
add(s, stackTraceNL)
add(s, "\n")
when hasSomeStackTrace:
proc rawWriteStackTrace(s: var string) =
when nimrodStackTrace:
if framePtr == nil:
add(s, "No stack traceback available")
add(s, stackTraceNL)
add(s, "No stack traceback available\n")
else:
add(s, "Traceback (most recent call last)")
add(s, stackTraceNL)
add(s, "Traceback (most recent call last)\n")
auxWriteStackTrace(framePtr, s)
elif defined(nativeStackTrace) and nativeStackTraceSupported:
add(s, "Traceback from system (most recent call last)")
add(s, stackTraceNL)
add(s, "Traceback from system (most recent call last)\n")
auxWriteStackTraceWithBacktrace(s)
else:
add(s, "No stack traceback available\n")
@@ -207,7 +209,7 @@ proc raiseExceptionAux(e: ref E_Base) =
pushCurrentException(e)
c_longjmp(excHandler.context, 1)
elif e[] of EOutOfMemory:
writeToStdErr(e.name)
showErrorMessage(e.name)
quitOrDebug()
else:
when hasSomeStackTrace:
@@ -219,7 +221,7 @@ proc raiseExceptionAux(e: ref E_Base) =
add(buf, " [")
add(buf, $e.name)
add(buf, "]\n")
writeToStdErr(buf)
showErrorMessage(buf)
else:
# ugly, but avoids heap allocations :-)
template xadd(buf, s, slen: expr) =
@@ -235,7 +237,7 @@ proc raiseExceptionAux(e: ref E_Base) =
add(buf, " [")
xadd(buf, e.name, c_strlen(e.name))
add(buf, "]\n")
writeToStdErr(buf)
showErrorMessage(buf)
quitOrDebug()
proc raiseException(e: ref E_Base, ename: CString) {.compilerRtl.} =
@@ -255,9 +257,9 @@ proc WriteStackTrace() =
when hasSomeStackTrace:
var s = ""
rawWriteStackTrace(s)
writeToStdErr(s)
showErrorMessage(s)
else:
writeToStdErr("No stack traceback available\n")
showErrorMessage("No stack traceback available\n")
proc getStackTrace(): string =
when hasSomeStackTrace:
@@ -298,13 +300,13 @@ when not defined(noSignalHandler):
var buf = newStringOfCap(2000)
rawWriteStackTrace(buf)
processSignal(sig, buf.add) # nice hu? currying a la nimrod :-)
writeToStdErr(buf)
showErrorMessage(buf)
GC_enable()
else:
var msg: cstring
template asgn(y: expr) = msg = y
processSignal(sig, asgn)
writeToStdErr(msg)
showErrorMessage(msg)
when defined(endb): dbgAborting = True
quit(1) # always quit when SIGABRT