strictier use of URL separators; fixes #3253; fixes #4714 (#4716)
Costa Tsaousis committed
Nov 23, 2018 at 01:13 UTC
cfc740a7a2e7b7236ad1378fdb7a73c281cb867e
6 files changed
+12
-30
streaming/rrdpush.c
+1
-1
@@ -1114,7 +1114,7 @@ int rrdpush_receiver_thread_spawn(RRDHOST *host, struct web_client *w, char *url
1114
char buf[GUID_LEN + 1];
1115
1116
while(url) {
1117
- char *value = mystrsep(&url, "?&");
1117
+ char *value = mystrsep(&url, "&");
1118
if(!value || !*value) continue;
1119
1120
char *name = mystrsep(&value, "=");
web/api/badges/README.md
-18
@@ -261,24 +261,6 @@ character|name|escape sequence
261
` \ `|backslash (when you need a `/`)|`%5C`
262
` \| `|pipe (delimiting parameters)|`%7C`
263
264
----
265
-
266
-## Using the path instead of the query string
267
-
268
-The badges can also be generated using the URL path for passing parameters. The format is exactly the same.
269
-
270
-So instead of:
271
-
272
- `http://your.netdata:19999/api/v1/badge.svg?option1&option2&option3&...`
273
-
274
-you can write:
275
-
276
- `http://your.netdata:19999/api/v1/badge.svg/option1/option2/option3/...`
277
-
278
-You can also append anything else you like, like this:
279
-
280
- `http://your.netdata:19999/api/v1/badge.svg/option1/option2/option3/my-super-badge.svg`
281
-
264
## FAQ
265
266
#### Is it fast?
web/api/badges/web_buffer_svg.c
+1
-1
@@ -913,7 +913,7 @@ int web_client_api_request_v1_badge(RRDHOST *host, struct web_client *w, char *u
913
uint32_t options = 0x00000000;
914
915
while(url) {
916
- char *value = mystrsep(&url, "/?&");
916
+ char *value = mystrsep(&url, "&");
917
if(!value || !*value) continue;
918
919
char *name = mystrsep(&value, "=");
web/api/exporters/allmetrics.c
+1
-1
@@ -24,7 +24,7 @@ inline int web_client_api_request_v1_allmetrics(RRDHOST *host, struct web_client
24
const char *prometheus_prefix = global_backend_prefix;
25
26
while(url) {
27
- char *value = mystrsep(&url, "?&");
27
+ char *value = mystrsep(&url, "&");
28
if (!value || !*value) continue;
29
30
char *name = mystrsep(&value, "=");
web/api/web_api_v1.c
+6
-6
@@ -136,7 +136,7 @@ inline int web_client_api_request_v1_alarms(RRDHOST *host, struct web_client *w,
136
int all = 0;
137
138
while(url) {
139
- char *value = mystrsep(&url, "?&");
139
+ char *value = mystrsep(&url, "&");
140
if (!value || !*value) continue;
141
142
if(!strcmp(value, "all")) all = 1;
@@ -153,7 +153,7 @@ inline int web_client_api_request_v1_alarm_log(RRDHOST *host, struct web_client
153
uint32_t after = 0;
154
155
while(url) {
156
- char *value = mystrsep(&url, "?&");
156
+ char *value = mystrsep(&url, "&");
157
if (!value || !*value) continue;
158
159
char *name = mystrsep(&value, "=");
@@ -176,7 +176,7 @@ inline int web_client_api_request_single_chart(RRDHOST *host, struct web_client
176
buffer_flush(w->response.data);
177
178
while(url) {
179
- char *value = mystrsep(&url, "?&");
179
+ char *value = mystrsep(&url, "&");
180
if(!value || !*value) continue;
181
182
char *name = mystrsep(&value, "=");
@@ -271,7 +271,7 @@ inline int web_client_api_request_v1_data(RRDHOST *host, struct web_client *w, c
271
uint32_t options = 0x00000000;
272
273
while(url) {
274
- char *value = mystrsep(&url, "?&");
274
+ char *value = mystrsep(&url, "&");
275
if(!value || !*value) continue;
276
277
char *name = mystrsep(&value, "=");
@@ -489,7 +489,7 @@ inline int web_client_api_request_v1_registry(RRDHOST *host, struct web_client *
489
*/
490
491
while(url) {
492
- char *value = mystrsep(&url, "?&");
492
+ char *value = mystrsep(&url, "&");
493
if (!value || !*value) continue;
494
495
char *name = mystrsep(&value, "=");
@@ -652,7 +652,7 @@ inline int web_client_api_request_v1(RRDHOST *host, struct web_client *w, char *
652
}
653
654
// get the command
655
- char *tok = mystrsep(&url, "/?&");
655
+ char *tok = mystrsep(&url, "?");
656
if(tok && *tok) {
657
debug(D_WEB_CLIENT, "%llu: Searching for API v1 command '%s'.", w->id, tok);
658
uint32_t hash = simple_hash(tok);
web/server/web_client.c
+3
-3
@@ -580,7 +580,7 @@ static inline int check_host_and_dashboard_acl_and_call(RRDHOST *host, struct we
580
int web_client_api_request(RRDHOST *host, struct web_client *w, char *url)
581
{
582
// get the api version
583
- char *tok = mystrsep(&url, "/?&");
583
+ char *tok = mystrsep(&url, "/");
584
if(tok && *tok) {
585
debug(D_WEB_CLIENT, "%llu: Searching for API version '%s'.", w->id, tok);
586
if(strcmp(tok, "v1") == 0)
@@ -1071,7 +1071,7 @@ static inline int web_client_switch_host(RRDHOST *host, struct web_client *w, ch
1071
return 400;
1072
}
1073
1074
- char *tok = mystrsep(&url, "/?&");
1074
+ char *tok = mystrsep(&url, "/");
1075
if(tok && *tok) {
1076
debug(D_WEB_CLIENT, "%llu: Searching for host with name '%s'.", w->id, tok);
1077
@@ -1163,7 +1163,7 @@ static inline int web_client_process_url(RRDHOST *host, struct web_client *w, ch
1163
buffer_flush(w->response.data);
1164
1165
// get the name of the data to show
1166
- tok = mystrsep(&url, "/?&");
1166
+ tok = mystrsep(&url, "&");
1167
if(tok && *tok) {
1168
debug(D_WEB_CLIENT, "%llu: Searching for RRD data with name '%s'.", w->id, tok);
1169