1
|
/**
|
2
|
* This file is part of Haketilo.
|
3
|
*
|
4
|
* Function: Filtering request headers to remove haketilo cookies that might
|
5
|
* have slipped through.
|
6
|
*
|
7
|
* Copyright (C) 2021 Wojtek Kosior
|
8
|
*
|
9
|
* This program is free software: you can redistribute it and/or modify
|
10
|
* it under the terms of the GNU General Public License as published by
|
11
|
* the Free Software Foundation, either version 3 of the License, or
|
12
|
* (at your option) any later version.
|
13
|
*
|
14
|
* This program is distributed in the hope that it will be useful,
|
15
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
16
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
17
|
* GNU General Public License for more details.
|
18
|
*
|
19
|
* As additional permission under GNU GPL version 3 section 7, you
|
20
|
* may distribute forms of that code without the copy of the GNU
|
21
|
* GPL normally required by section 4, provided you include this
|
22
|
* license notice and, in case of non-source distribution, a URL
|
23
|
* through which recipients can access the Corresponding Source.
|
24
|
* If you modify file(s) with this exception, you may extend this
|
25
|
* exception to your version of the file(s), but you are not
|
26
|
* obligated to do so. If you do not wish to do so, delete this
|
27
|
* exception statement from your version.
|
28
|
*
|
29
|
* As a special exception to the GPL, any HTML file which merely
|
30
|
* makes function calls to this code, and for that purpose
|
31
|
* includes it by reference shall be deemed a separate work for
|
32
|
* copyright law purposes. If you modify this code, you may extend
|
33
|
* this exception to your version of the code, but you are not
|
34
|
* obligated to do so. If you do not wish to do so, delete this
|
35
|
* exception statement from your version.
|
36
|
*
|
37
|
* You should have received a copy of the GNU General Public License
|
38
|
* along with this program. If not, see <https://www.gnu.org/licenses/>.
|
39
|
*
|
40
|
* I, Wojtek Kosior, thereby promise not to sue for violation of this file's
|
41
|
* license. Although I request that you do not make use this code in a
|
42
|
* proprietary program, I am not going to enforce this in court.
|
43
|
*/
|
44
|
|
45
|
/*
|
46
|
* IMPORTS_START
|
47
|
* IMPORT extract_signed
|
48
|
* IMPORTS_END
|
49
|
*/
|
50
|
|
51
|
function is_valid_haketilo_cookie(cookie)
|
52
|
{
|
53
|
const match = /^haketilo-(\w*)=(.*)$/.exec(cookie);
|
54
|
if (!match)
|
55
|
return false;
|
56
|
|
57
|
return !extract_signed(match.slice(1, 3)).fail;
|
58
|
}
|
59
|
|
60
|
function remove_haketilo_cookies(header)
|
61
|
{
|
62
|
if (header.name !== "Cookie")
|
63
|
return header;
|
64
|
|
65
|
const cookies = header.value.split("; ");
|
66
|
const value = cookies.filter(c => !is_valid_haketilo_cookie(c)).join("; ");
|
67
|
|
68
|
return value ? {name: "Cookie", value} : null;
|
69
|
}
|
70
|
|
71
|
function filter_cookie_headers(headers)
|
72
|
{
|
73
|
return headers.map(remove_haketilo_cookies).filter(h => h);
|
74
|
}
|
75
|
|
76
|
/*
|
77
|
* EXPORTS_START
|
78
|
* EXPORT filter_cookie_headers
|
79
|
* EXPORTS_END
|
80
|
*/
|