mirror of
https://github.com/SWG-Source/src.git
synced 2026-07-29 23:15:56 -04:00
Change encoding/decoding binary data to use base64 vs utf-8 to prevent bad characters in the oracle string encoding.
This commit is contained in:
@@ -12,6 +12,126 @@
|
||||
#include "serverDatabase/DatabaseProcess.h"
|
||||
#include "sharedLog/Log.h"
|
||||
|
||||
/*
|
||||
base64.cpp and base64.h
|
||||
|
||||
Copyright (C) 2004-2008 René Nyffenegger
|
||||
|
||||
This source code is provided 'as-is', without any express or implied
|
||||
warranty. In no event will the author be held liable for any damages
|
||||
arising from the use of this software.
|
||||
|
||||
Permission is granted to anyone to use this software for any purpose,
|
||||
including commercial applications, and to alter it and redistribute it
|
||||
freely, subject to the following restrictions:
|
||||
|
||||
1. The origin of this source code must not be misrepresented; you must not
|
||||
claim that you wrote the original source code. If you use this source code
|
||||
in a product, an acknowledgment in the product documentation would be
|
||||
appreciated but is not required.
|
||||
|
||||
2. Altered source versions must be plainly marked as such, and must not be
|
||||
misrepresented as being the original source code.
|
||||
|
||||
3. This notice may not be removed or altered from any source distribution.
|
||||
|
||||
René Nyffenegger [email protected]
|
||||
*/
|
||||
|
||||
static const std::string base64_chars =
|
||||
"ABCDEFGHIJKLMNOPQRSTUVWXYZ"
|
||||
"abcdefghijklmnopqrstuvwxyz"
|
||||
"0123456789+/";
|
||||
|
||||
|
||||
static inline bool is_base64(unsigned char c) {
|
||||
return (isalnum(c) || (c == '+') || (c == '/'));
|
||||
}
|
||||
|
||||
std::string base64_encode(unsigned char const* bytes_to_encode, unsigned int in_len) {
|
||||
std::string ret;
|
||||
int i = 0;
|
||||
int j = 0;
|
||||
unsigned char char_array_3[3];
|
||||
unsigned char char_array_4[4];
|
||||
|
||||
while (in_len--) {
|
||||
char_array_3[i++] = *(bytes_to_encode++);
|
||||
if (i == 3) {
|
||||
char_array_4[0] = (char_array_3[0] & 0xfc) >> 2;
|
||||
char_array_4[1] = ((char_array_3[0] & 0x03) << 4) + ((char_array_3[1] & 0xf0) >> 4);
|
||||
char_array_4[2] = ((char_array_3[1] & 0x0f) << 2) + ((char_array_3[2] & 0xc0) >> 6);
|
||||
char_array_4[3] = char_array_3[2] & 0x3f;
|
||||
|
||||
for(i = 0; (i <4) ; i++)
|
||||
ret += base64_chars[char_array_4[i]];
|
||||
i = 0;
|
||||
}
|
||||
}
|
||||
|
||||
if (i)
|
||||
{
|
||||
for(j = i; j < 3; j++)
|
||||
char_array_3[j] = '\0';
|
||||
|
||||
char_array_4[0] = (char_array_3[0] & 0xfc) >> 2;
|
||||
char_array_4[1] = ((char_array_3[0] & 0x03) << 4) + ((char_array_3[1] & 0xf0) >> 4);
|
||||
char_array_4[2] = ((char_array_3[1] & 0x0f) << 2) + ((char_array_3[2] & 0xc0) >> 6);
|
||||
char_array_4[3] = char_array_3[2] & 0x3f;
|
||||
|
||||
for (j = 0; (j < i + 1); j++)
|
||||
ret += base64_chars[char_array_4[j]];
|
||||
|
||||
while((i++ < 3))
|
||||
ret += '=';
|
||||
|
||||
}
|
||||
|
||||
return ret;
|
||||
|
||||
}
|
||||
|
||||
std::string base64_decode(std::string const& encoded_string) {
|
||||
int in_len = encoded_string.size();
|
||||
int i = 0;
|
||||
int j = 0;
|
||||
int in_ = 0;
|
||||
unsigned char char_array_4[4], char_array_3[3];
|
||||
std::string ret;
|
||||
|
||||
while (in_len-- && ( encoded_string[in_] != '=') && is_base64(encoded_string[in_])) {
|
||||
char_array_4[i++] = encoded_string[in_]; in_++;
|
||||
if (i ==4) {
|
||||
for (i = 0; i <4; i++)
|
||||
char_array_4[i] = base64_chars.find(char_array_4[i]);
|
||||
|
||||
char_array_3[0] = (char_array_4[0] << 2) + ((char_array_4[1] & 0x30) >> 4);
|
||||
char_array_3[1] = ((char_array_4[1] & 0xf) << 4) + ((char_array_4[2] & 0x3c) >> 2);
|
||||
char_array_3[2] = ((char_array_4[2] & 0x3) << 6) + char_array_4[3];
|
||||
|
||||
for (i = 0; (i < 3); i++)
|
||||
ret += char_array_3[i];
|
||||
i = 0;
|
||||
}
|
||||
}
|
||||
|
||||
if (i) {
|
||||
for (j = i; j <4; j++)
|
||||
char_array_4[j] = 0;
|
||||
|
||||
for (j = 0; j <4; j++)
|
||||
char_array_4[j] = base64_chars.find(char_array_4[j]);
|
||||
|
||||
char_array_3[0] = (char_array_4[0] << 2) + ((char_array_4[1] & 0x30) >> 4);
|
||||
char_array_3[1] = ((char_array_4[1] & 0xf) << 4) + ((char_array_4[2] & 0x3c) >> 2);
|
||||
char_array_3[2] = ((char_array_4[2] & 0x3) << 6) + char_array_4[3];
|
||||
|
||||
for (j = 0; (j < i - 1); j++) ret += char_array_3[j];
|
||||
}
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
//TODO: don't save non-guaranteed messages
|
||||
|
||||
// ======================================================================
|
||||
@@ -145,25 +265,7 @@ void SaveMessageQuery::getSQL(std::string &sql)
|
||||
|
||||
void SaveMessageQuery::convertMessageToUTF8(const std::vector<int8> & messageData, std::string & utf8Data) const
|
||||
{
|
||||
int count = messageData.size();
|
||||
utf8Data.resize(0);
|
||||
utf8Data.reserve(count * 2);
|
||||
uint8 c;
|
||||
for (int i = 0; i < count; ++i)
|
||||
{
|
||||
c = messageData[i];
|
||||
if (c >= 0x01 && c <= 0x7f)
|
||||
{
|
||||
// store the data as one byte
|
||||
utf8Data += c;
|
||||
}
|
||||
else
|
||||
{
|
||||
// store the data as two bytes
|
||||
utf8Data += static_cast<char>(0xc0 | ((c >> 6) & 0x1f));
|
||||
utf8Data += static_cast<char>(0x80 | (c & 0x3f));
|
||||
}
|
||||
}
|
||||
utf8Data = base64_encode(reinterpret_cast<const unsigned char*>(messageData.data()), messageData.size());
|
||||
}
|
||||
|
||||
// ----------------------------------------------------------------------
|
||||
@@ -326,24 +428,8 @@ void LoadMessagesQuery::getSQL(std::string &sql)
|
||||
|
||||
void LoadMessagesQuery::convertUTF8ToMessage(const std::string & utf8Data, std::vector<int8> & messageData) const
|
||||
{
|
||||
int count = utf8Data.size();
|
||||
messageData.resize(0);
|
||||
messageData.reserve(count);
|
||||
uint8 c;
|
||||
for (int i = 0; i < count; ++i)
|
||||
{
|
||||
c = utf8Data[i];
|
||||
if ((c & 0xc0) == 0xc0)
|
||||
{
|
||||
// data is stored in 2 bytes
|
||||
messageData.push_back(static_cast<char>(((c & 0x1f) << 6) + (utf8Data[++i] & 0x3f)));
|
||||
}
|
||||
else
|
||||
{
|
||||
// data is stored in 1 byte
|
||||
messageData.push_back(c);
|
||||
}
|
||||
}
|
||||
auto tmp = base64_decode(utf8Data);
|
||||
messageData.insert(std::begin(messageData), std::begin(tmp), std::end(tmp));
|
||||
}
|
||||
|
||||
// ======================================================================
|
||||
|
||||
Reference in New Issue
Block a user