msi: Fix a typo.
[wine] / dlls / wininet / http.c
1 /*
2  * Wininet - Http Implementation
3  *
4  * Copyright 1999 Corel Corporation
5  * Copyright 2002 CodeWeavers Inc.
6  * Copyright 2002 TransGaming Technologies Inc.
7  * Copyright 2004 Mike McCormack for CodeWeavers
8  * Copyright 2005 Aric Stewart for CodeWeavers
9  * Copyright 2006 Robert Shearman for CodeWeavers
10  *
11  * Ulrich Czekalla
12  * David Hammerton
13  *
14  * This library is free software; you can redistribute it and/or
15  * modify it under the terms of the GNU Lesser General Public
16  * License as published by the Free Software Foundation; either
17  * version 2.1 of the License, or (at your option) any later version.
18  *
19  * This library is distributed in the hope that it will be useful,
20  * but WITHOUT ANY WARRANTY; without even the implied warranty of
21  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
22  * Lesser General Public License for more details.
23  *
24  * You should have received a copy of the GNU Lesser General Public
25  * License along with this library; if not, write to the Free Software
26  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
27  */
28
29 #include "config.h"
30 #include "wine/port.h"
31
32 #include <sys/types.h>
33 #ifdef HAVE_SYS_SOCKET_H
34 # include <sys/socket.h>
35 #endif
36 #ifdef HAVE_ARPA_INET_H
37 # include <arpa/inet.h>
38 #endif
39 #include <stdarg.h>
40 #include <stdio.h>
41 #include <stdlib.h>
42 #ifdef HAVE_UNISTD_H
43 # include <unistd.h>
44 #endif
45 #include <time.h>
46 #include <assert.h>
47
48 #include "windef.h"
49 #include "winbase.h"
50 #include "wininet.h"
51 #include "winerror.h"
52 #define NO_SHLWAPI_STREAM
53 #define NO_SHLWAPI_REG
54 #define NO_SHLWAPI_STRFCNS
55 #define NO_SHLWAPI_GDI
56 #include "shlwapi.h"
57 #include "sspi.h"
58 #include "wincrypt.h"
59
60 #include "internet.h"
61 #include "wine/debug.h"
62 #include "wine/unicode.h"
63
64 WINE_DEFAULT_DEBUG_CHANNEL(wininet);
65
66 static const WCHAR g_szHttp1_0[] = {'H','T','T','P','/','1','.','0',0};
67 static const WCHAR g_szHttp1_1[] = {'H','T','T','P','/','1','.','1',0};
68 static const WCHAR g_szReferer[] = {'R','e','f','e','r','e','r',0};
69 static const WCHAR g_szAccept[] = {'A','c','c','e','p','t',0};
70 static const WCHAR g_szUserAgent[] = {'U','s','e','r','-','A','g','e','n','t',0};
71 static const WCHAR szHost[] = { 'H','o','s','t',0 };
72 static const WCHAR szAuthorization[] = { 'A','u','t','h','o','r','i','z','a','t','i','o','n',0 };
73 static const WCHAR szProxy_Authorization[] = { 'P','r','o','x','y','-','A','u','t','h','o','r','i','z','a','t','i','o','n',0 };
74 static const WCHAR szStatus[] = { 'S','t','a','t','u','s',0 };
75 static const WCHAR szKeepAlive[] = {'K','e','e','p','-','A','l','i','v','e',0};
76 static const WCHAR szGET[] = { 'G','E','T', 0 };
77
78 #define MAXHOSTNAME 100
79 #define MAX_FIELD_VALUE_LEN 256
80 #define MAX_FIELD_LEN 256
81
82 #define HTTP_REFERER    g_szReferer
83 #define HTTP_ACCEPT     g_szAccept
84 #define HTTP_USERAGENT  g_szUserAgent
85
86 #define HTTP_ADDHDR_FLAG_ADD                            0x20000000
87 #define HTTP_ADDHDR_FLAG_ADD_IF_NEW                     0x10000000
88 #define HTTP_ADDHDR_FLAG_COALESCE                       0x40000000
89 #define HTTP_ADDHDR_FLAG_COALESCE_WITH_COMMA            0x40000000
90 #define HTTP_ADDHDR_FLAG_COALESCE_WITH_SEMICOLON        0x01000000
91 #define HTTP_ADDHDR_FLAG_REPLACE                        0x80000000
92 #define HTTP_ADDHDR_FLAG_REQ                            0x02000000
93
94 #define ARRAYSIZE(array) (sizeof(array)/sizeof((array)[0]))
95
96 struct HttpAuthInfo
97 {
98     LPWSTR scheme;
99     CredHandle cred;
100     CtxtHandle ctx;
101     TimeStamp exp;
102     ULONG attr;
103     ULONG max_token;
104     void *auth_data;
105     unsigned int auth_data_len;
106     BOOL finished; /* finished authenticating */
107 };
108
109 static BOOL HTTP_OpenConnection(LPWININETHTTPREQW lpwhr);
110 static BOOL HTTP_GetResponseHeaders(LPWININETHTTPREQW lpwhr, BOOL clear);
111 static BOOL HTTP_ProcessHeader(LPWININETHTTPREQW lpwhr, LPCWSTR field, LPCWSTR value, DWORD dwModifier);
112 static LPWSTR * HTTP_InterpretHttpHeader(LPCWSTR buffer);
113 static BOOL HTTP_InsertCustomHeader(LPWININETHTTPREQW lpwhr, LPHTTPHEADERW lpHdr);
114 static INT HTTP_GetCustomHeaderIndex(LPWININETHTTPREQW lpwhr, LPCWSTR lpszField, INT index, BOOL Request);
115 static BOOL HTTP_DeleteCustomHeader(LPWININETHTTPREQW lpwhr, DWORD index);
116 static LPWSTR HTTP_build_req( LPCWSTR *list, int len );
117 static BOOL WINAPI HTTP_HttpQueryInfoW( LPWININETHTTPREQW lpwhr, DWORD
118         dwInfoLevel, LPVOID lpBuffer, LPDWORD lpdwBufferLength, LPDWORD
119         lpdwIndex);
120 static BOOL HTTP_HandleRedirect(LPWININETHTTPREQW lpwhr, LPCWSTR lpszUrl);
121 static UINT HTTP_DecodeBase64(LPCWSTR base64, LPSTR bin);
122 static BOOL HTTP_VerifyValidHeader(LPWININETHTTPREQW lpwhr, LPCWSTR field);
123 static void HTTP_DrainContent(WININETHTTPREQW *req);
124
125 LPHTTPHEADERW HTTP_GetHeader(LPWININETHTTPREQW req, LPCWSTR head)
126 {
127     int HeaderIndex = 0;
128     HeaderIndex = HTTP_GetCustomHeaderIndex(req, head, 0, TRUE);
129     if (HeaderIndex == -1)
130         return NULL;
131     else
132         return &req->pCustHeaders[HeaderIndex];
133 }
134
135 /***********************************************************************
136  *           HTTP_Tokenize (internal)
137  *
138  *  Tokenize a string, allocating memory for the tokens.
139  */
140 static LPWSTR * HTTP_Tokenize(LPCWSTR string, LPCWSTR token_string)
141 {
142     LPWSTR * token_array;
143     int tokens = 0;
144     int i;
145     LPCWSTR next_token;
146
147     /* empty string has no tokens */
148     if (*string)
149         tokens++;
150     /* count tokens */
151     for (i = 0; string[i]; i++)
152         if (!strncmpW(string+i, token_string, strlenW(token_string)))
153         {
154             DWORD j;
155             tokens++;
156             /* we want to skip over separators, but not the null terminator */
157             for (j = 0; j < strlenW(token_string) - 1; j++)
158                 if (!string[i+j])
159                     break;
160             i += j;
161         }
162
163     /* add 1 for terminating NULL */
164     token_array = HeapAlloc(GetProcessHeap(), 0, (tokens+1) * sizeof(*token_array));
165     token_array[tokens] = NULL;
166     if (!tokens)
167         return token_array;
168     for (i = 0; i < tokens; i++)
169     {
170         int len;
171         next_token = strstrW(string, token_string);
172         if (!next_token) next_token = string+strlenW(string);
173         len = next_token - string;
174         token_array[i] = HeapAlloc(GetProcessHeap(), 0, (len+1)*sizeof(WCHAR));
175         memcpy(token_array[i], string, len*sizeof(WCHAR));
176         token_array[i][len] = '\0';
177         string = next_token+strlenW(token_string);
178     }
179     return token_array;
180 }
181
182 /***********************************************************************
183  *           HTTP_FreeTokens (internal)
184  *
185  *  Frees memory returned from HTTP_Tokenize.
186  */
187 static void HTTP_FreeTokens(LPWSTR * token_array)
188 {
189     int i;
190     for (i = 0; token_array[i]; i++)
191         HeapFree(GetProcessHeap(), 0, token_array[i]);
192     HeapFree(GetProcessHeap(), 0, token_array);
193 }
194
195 /* **********************************************************************
196  * 
197  * Helper functions for the HttpSendRequest(Ex) functions
198  * 
199  */
200 static void AsyncHttpSendRequestProc(WORKREQUEST *workRequest)
201 {
202     struct WORKREQ_HTTPSENDREQUESTW const *req = &workRequest->u.HttpSendRequestW;
203     LPWININETHTTPREQW lpwhr = (LPWININETHTTPREQW) workRequest->hdr;
204
205     TRACE("%p\n", lpwhr);
206
207     HTTP_HttpSendRequestW(lpwhr, req->lpszHeader,
208             req->dwHeaderLength, req->lpOptional, req->dwOptionalLength,
209             req->dwContentLength, req->bEndRequest);
210
211     HeapFree(GetProcessHeap(), 0, req->lpszHeader);
212 }
213
214 static void HTTP_FixURL( LPWININETHTTPREQW lpwhr)
215 {
216     static const WCHAR szSlash[] = { '/',0 };
217     static const WCHAR szHttp[] = { 'h','t','t','p',':','/','/', 0 };
218
219     /* If we don't have a path we set it to root */
220     if (NULL == lpwhr->lpszPath)
221         lpwhr->lpszPath = WININET_strdupW(szSlash);
222     else /* remove \r and \n*/
223     {
224         int nLen = strlenW(lpwhr->lpszPath);
225         while ((nLen >0 ) && ((lpwhr->lpszPath[nLen-1] == '\r')||(lpwhr->lpszPath[nLen-1] == '\n')))
226         {
227             nLen--;
228             lpwhr->lpszPath[nLen]='\0';
229         }
230         /* Replace '\' with '/' */
231         while (nLen>0) {
232             nLen--;
233             if (lpwhr->lpszPath[nLen] == '\\') lpwhr->lpszPath[nLen]='/';
234         }
235     }
236
237     if(CSTR_EQUAL != CompareStringW( LOCALE_SYSTEM_DEFAULT, NORM_IGNORECASE,
238                        lpwhr->lpszPath, strlenW(lpwhr->lpszPath), szHttp, strlenW(szHttp) )
239        && lpwhr->lpszPath[0] != '/') /* not an absolute path ?? --> fix it !! */
240     {
241         WCHAR *fixurl = HeapAlloc(GetProcessHeap(), 0, 
242                              (strlenW(lpwhr->lpszPath) + 2)*sizeof(WCHAR));
243         *fixurl = '/';
244         strcpyW(fixurl + 1, lpwhr->lpszPath);
245         HeapFree( GetProcessHeap(), 0, lpwhr->lpszPath );
246         lpwhr->lpszPath = fixurl;
247     }
248 }
249
250 static LPWSTR HTTP_BuildHeaderRequestString( LPWININETHTTPREQW lpwhr, LPCWSTR verb, LPCWSTR path, LPCWSTR version )
251 {
252     LPWSTR requestString;
253     DWORD len, n;
254     LPCWSTR *req;
255     UINT i;
256     LPWSTR p;
257
258     static const WCHAR szSpace[] = { ' ',0 };
259     static const WCHAR szcrlf[] = {'\r','\n', 0};
260     static const WCHAR szColon[] = { ':',' ',0 };
261     static const WCHAR sztwocrlf[] = {'\r','\n','\r','\n', 0};
262
263     /* allocate space for an array of all the string pointers to be added */
264     len = (lpwhr->nCustHeaders)*4 + 10;
265     req = HeapAlloc( GetProcessHeap(), 0, len*sizeof(LPCWSTR) );
266
267     /* add the verb, path and HTTP version string */
268     n = 0;
269     req[n++] = verb;
270     req[n++] = szSpace;
271     req[n++] = path;
272     req[n++] = szSpace;
273     req[n++] = version;
274
275     /* Append custom request headers */
276     for (i = 0; i < lpwhr->nCustHeaders; i++)
277     {
278         if (lpwhr->pCustHeaders[i].wFlags & HDR_ISREQUEST)
279         {
280             req[n++] = szcrlf;
281             req[n++] = lpwhr->pCustHeaders[i].lpszField;
282             req[n++] = szColon;
283             req[n++] = lpwhr->pCustHeaders[i].lpszValue;
284
285             TRACE("Adding custom header %s (%s)\n",
286                    debugstr_w(lpwhr->pCustHeaders[i].lpszField),
287                    debugstr_w(lpwhr->pCustHeaders[i].lpszValue));
288         }
289     }
290
291     if( n >= len )
292         ERR("oops. buffer overrun\n");
293
294     req[n] = NULL;
295     requestString = HTTP_build_req( req, 4 );
296     HeapFree( GetProcessHeap(), 0, req );
297
298     /*
299      * Set (header) termination string for request
300      * Make sure there's exactly two new lines at the end of the request
301      */
302     p = &requestString[strlenW(requestString)-1];
303     while ( (*p == '\n') || (*p == '\r') )
304        p--;
305     strcpyW( p+1, sztwocrlf );
306     
307     return requestString;
308 }
309
310 static void HTTP_ProcessCookies( LPWININETHTTPREQW lpwhr )
311 {
312     static const WCHAR szSet_Cookie[] = { 'S','e','t','-','C','o','o','k','i','e',0 };
313     int HeaderIndex;
314     LPHTTPHEADERW setCookieHeader;
315
316     HeaderIndex = HTTP_GetCustomHeaderIndex(lpwhr, szSet_Cookie, 0, FALSE);
317     if (HeaderIndex == -1)
318             return;
319     setCookieHeader = &lpwhr->pCustHeaders[HeaderIndex];
320
321     if (!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_COOKIES) && setCookieHeader->lpszValue)
322     {
323         int nPosStart = 0, nPosEnd = 0, len;
324         static const WCHAR szFmt[] = { 'h','t','t','p',':','/','/','%','s','/',0};
325
326         while (setCookieHeader->lpszValue[nPosEnd] != '\0')
327         {
328             LPWSTR buf_cookie, cookie_name, cookie_data;
329             LPWSTR buf_url;
330             LPWSTR domain = NULL;
331             LPHTTPHEADERW Host;
332
333             int nEqualPos = 0;
334             while (setCookieHeader->lpszValue[nPosEnd] != ';' && setCookieHeader->lpszValue[nPosEnd] != ',' &&
335                    setCookieHeader->lpszValue[nPosEnd] != '\0')
336             {
337                 nPosEnd++;
338             }
339             if (setCookieHeader->lpszValue[nPosEnd] == ';')
340             {
341                 /* fixme: not case sensitive, strcasestr is gnu only */
342                 int nDomainPosEnd = 0;
343                 int nDomainPosStart = 0, nDomainLength = 0;
344                 static const WCHAR szDomain[] = {'d','o','m','a','i','n','=',0};
345                 LPWSTR lpszDomain = strstrW(&setCookieHeader->lpszValue[nPosEnd], szDomain);
346                 if (lpszDomain)
347                 { /* they have specified their own domain, lets use it */
348                     while (lpszDomain[nDomainPosEnd] != ';' && lpszDomain[nDomainPosEnd] != ',' &&
349                            lpszDomain[nDomainPosEnd] != '\0')
350                     {
351                         nDomainPosEnd++;
352                     }
353                     nDomainPosStart = strlenW(szDomain);
354                     nDomainLength = (nDomainPosEnd - nDomainPosStart) + 1;
355                     domain = HeapAlloc(GetProcessHeap(), 0, (nDomainLength + 1)*sizeof(WCHAR));
356                     lstrcpynW(domain, &lpszDomain[nDomainPosStart], nDomainLength + 1);
357                 }
358             }
359             if (setCookieHeader->lpszValue[nPosEnd] == '\0') break;
360             buf_cookie = HeapAlloc(GetProcessHeap(), 0, ((nPosEnd - nPosStart) + 1)*sizeof(WCHAR));
361             lstrcpynW(buf_cookie, &setCookieHeader->lpszValue[nPosStart], (nPosEnd - nPosStart) + 1);
362             TRACE("%s\n", debugstr_w(buf_cookie));
363             while (buf_cookie[nEqualPos] != '=' && buf_cookie[nEqualPos] != '\0')
364             {
365                 nEqualPos++;
366             }
367             if (buf_cookie[nEqualPos] == '\0' || buf_cookie[nEqualPos + 1] == '\0')
368             {
369                 HeapFree(GetProcessHeap(), 0, buf_cookie);
370                 break;
371             }
372
373             cookie_name = HeapAlloc(GetProcessHeap(), 0, (nEqualPos + 1)*sizeof(WCHAR));
374             lstrcpynW(cookie_name, buf_cookie, nEqualPos + 1);
375             cookie_data = &buf_cookie[nEqualPos + 1];
376
377             Host = HTTP_GetHeader(lpwhr,szHost);
378             len = lstrlenW((domain ? domain : (Host?Host->lpszValue:NULL))) + 
379                 strlenW(lpwhr->lpszPath) + 9;
380             buf_url = HeapAlloc(GetProcessHeap(), 0, len*sizeof(WCHAR));
381             sprintfW(buf_url, szFmt, (domain ? domain : (Host?Host->lpszValue:NULL))); /* FIXME PATH!!! */
382             InternetSetCookieW(buf_url, cookie_name, cookie_data);
383
384             HeapFree(GetProcessHeap(), 0, buf_url);
385             HeapFree(GetProcessHeap(), 0, buf_cookie);
386             HeapFree(GetProcessHeap(), 0, cookie_name);
387             HeapFree(GetProcessHeap(), 0, domain);
388             nPosStart = nPosEnd;
389         }
390     }
391 }
392
393 static inline BOOL is_basic_auth_value( LPCWSTR pszAuthValue )
394 {
395     static const WCHAR szBasic[] = {'B','a','s','i','c'}; /* Note: not nul-terminated */
396     return !strncmpiW(pszAuthValue, szBasic, ARRAYSIZE(szBasic)) &&
397         ((pszAuthValue[ARRAYSIZE(szBasic)] != ' ') || !pszAuthValue[ARRAYSIZE(szBasic)]);
398 }
399
400 static BOOL HTTP_DoAuthorization( LPWININETHTTPREQW lpwhr, LPCWSTR pszAuthValue,
401                                   struct HttpAuthInfo **ppAuthInfo,
402                                   LPWSTR domain_and_username, LPWSTR password )
403 {
404     SECURITY_STATUS sec_status;
405     struct HttpAuthInfo *pAuthInfo = *ppAuthInfo;
406     BOOL first = FALSE;
407
408     TRACE("%s\n", debugstr_w(pszAuthValue));
409
410     if (!pAuthInfo)
411     {
412         TimeStamp exp;
413
414         first = TRUE;
415         pAuthInfo = HeapAlloc(GetProcessHeap(), 0, sizeof(*pAuthInfo));
416         if (!pAuthInfo)
417             return FALSE;
418
419         SecInvalidateHandle(&pAuthInfo->cred);
420         SecInvalidateHandle(&pAuthInfo->ctx);
421         memset(&pAuthInfo->exp, 0, sizeof(pAuthInfo->exp));
422         pAuthInfo->attr = 0;
423         pAuthInfo->auth_data = NULL;
424         pAuthInfo->auth_data_len = 0;
425         pAuthInfo->finished = FALSE;
426
427         if (is_basic_auth_value(pszAuthValue))
428         {
429             static const WCHAR szBasic[] = {'B','a','s','i','c',0};
430             pAuthInfo->scheme = WININET_strdupW(szBasic);
431             if (!pAuthInfo->scheme)
432             {
433                 HeapFree(GetProcessHeap(), 0, pAuthInfo);
434                 return FALSE;
435             }
436         }
437         else
438         {
439             PVOID pAuthData;
440             SEC_WINNT_AUTH_IDENTITY_W nt_auth_identity;
441
442             pAuthInfo->scheme = WININET_strdupW(pszAuthValue);
443             if (!pAuthInfo->scheme)
444             {
445                 HeapFree(GetProcessHeap(), 0, pAuthInfo);
446                 return FALSE;
447             }
448
449             if (domain_and_username)
450             {
451                 WCHAR *user = strchrW(domain_and_username, '\\');
452                 WCHAR *domain = domain_and_username;
453
454                 /* FIXME: make sure scheme accepts SEC_WINNT_AUTH_IDENTITY before calling AcquireCredentialsHandle */
455
456                 pAuthData = &nt_auth_identity;
457
458                 if (user) user++;
459                 else
460                 {
461                     user = domain_and_username;
462                     domain = NULL;
463                 }
464
465                 nt_auth_identity.Flags = SEC_WINNT_AUTH_IDENTITY_UNICODE;
466                 nt_auth_identity.User = user;
467                 nt_auth_identity.UserLength = strlenW(nt_auth_identity.User);
468                 nt_auth_identity.Domain = domain;
469                 nt_auth_identity.DomainLength = domain ? user - domain - 1 : 0;
470                 nt_auth_identity.Password = password;
471                 nt_auth_identity.PasswordLength = strlenW(nt_auth_identity.Password);
472             }
473             else
474                 /* use default credentials */
475                 pAuthData = NULL;
476
477             sec_status = AcquireCredentialsHandleW(NULL, pAuthInfo->scheme,
478                                                    SECPKG_CRED_OUTBOUND, NULL,
479                                                    pAuthData, NULL,
480                                                    NULL, &pAuthInfo->cred,
481                                                    &exp);
482             if (sec_status == SEC_E_OK)
483             {
484                 PSecPkgInfoW sec_pkg_info;
485                 sec_status = QuerySecurityPackageInfoW(pAuthInfo->scheme, &sec_pkg_info);
486                 if (sec_status == SEC_E_OK)
487                 {
488                     pAuthInfo->max_token = sec_pkg_info->cbMaxToken;
489                     FreeContextBuffer(sec_pkg_info);
490                 }
491             }
492             if (sec_status != SEC_E_OK)
493             {
494                 WARN("AcquireCredentialsHandleW for scheme %s failed with error 0x%08x\n",
495                      debugstr_w(pAuthInfo->scheme), sec_status);
496                 HeapFree(GetProcessHeap(), 0, pAuthInfo->scheme);
497                 HeapFree(GetProcessHeap(), 0, pAuthInfo);
498                 return FALSE;
499             }
500         }
501         *ppAuthInfo = pAuthInfo;
502     }
503     else if (pAuthInfo->finished)
504         return FALSE;
505
506     if ((strlenW(pszAuthValue) < strlenW(pAuthInfo->scheme)) ||
507         strncmpiW(pszAuthValue, pAuthInfo->scheme, strlenW(pAuthInfo->scheme)))
508     {
509         ERR("authentication scheme changed from %s to %s\n",
510             debugstr_w(pAuthInfo->scheme), debugstr_w(pszAuthValue));
511         return FALSE;
512     }
513
514     if (is_basic_auth_value(pszAuthValue))
515     {
516         int userlen;
517         int passlen;
518         char *auth_data;
519
520         TRACE("basic authentication\n");
521
522         /* we don't cache credentials for basic authentication, so we can't
523          * retrieve them if the application didn't pass us any credentials */
524         if (!domain_and_username) return FALSE;
525
526         userlen = WideCharToMultiByte(CP_UTF8, 0, domain_and_username, lstrlenW(domain_and_username), NULL, 0, NULL, NULL);
527         passlen = WideCharToMultiByte(CP_UTF8, 0, password, lstrlenW(password), NULL, 0, NULL, NULL);
528
529         /* length includes a nul terminator, which will be re-used for the ':' */
530         auth_data = HeapAlloc(GetProcessHeap(), 0, userlen + 1 + passlen);
531         if (!auth_data)
532             return FALSE;
533
534         WideCharToMultiByte(CP_UTF8, 0, domain_and_username, -1, auth_data, userlen, NULL, NULL);
535         auth_data[userlen] = ':';
536         WideCharToMultiByte(CP_UTF8, 0, password, -1, &auth_data[userlen+1], passlen, NULL, NULL);
537
538         pAuthInfo->auth_data = auth_data;
539         pAuthInfo->auth_data_len = userlen + 1 + passlen;
540         pAuthInfo->finished = TRUE;
541
542         return TRUE;
543     }
544     else
545     {
546         LPCWSTR pszAuthData;
547         SecBufferDesc out_desc, in_desc;
548         SecBuffer out, in;
549         unsigned char *buffer;
550         ULONG context_req = ISC_REQ_CONNECTION | ISC_REQ_USE_DCE_STYLE |
551             ISC_REQ_MUTUAL_AUTH | ISC_REQ_DELEGATE;
552
553         in.BufferType = SECBUFFER_TOKEN;
554         in.cbBuffer = 0;
555         in.pvBuffer = NULL;
556
557         in_desc.ulVersion = 0;
558         in_desc.cBuffers = 1;
559         in_desc.pBuffers = &in;
560
561         pszAuthData = pszAuthValue + strlenW(pAuthInfo->scheme);
562         if (*pszAuthData == ' ')
563         {
564             pszAuthData++;
565             in.cbBuffer = HTTP_DecodeBase64(pszAuthData, NULL);
566             in.pvBuffer = HeapAlloc(GetProcessHeap(), 0, in.cbBuffer);
567             HTTP_DecodeBase64(pszAuthData, in.pvBuffer);
568         }
569
570         buffer = HeapAlloc(GetProcessHeap(), 0, pAuthInfo->max_token);
571
572         out.BufferType = SECBUFFER_TOKEN;
573         out.cbBuffer = pAuthInfo->max_token;
574         out.pvBuffer = buffer;
575
576         out_desc.ulVersion = 0;
577         out_desc.cBuffers = 1;
578         out_desc.pBuffers = &out;
579
580         sec_status = InitializeSecurityContextW(first ? &pAuthInfo->cred : NULL,
581                                                 first ? NULL : &pAuthInfo->ctx,
582                                                 first ? lpwhr->lpHttpSession->lpszServerName : NULL,
583                                                 context_req, 0, SECURITY_NETWORK_DREP,
584                                                 in.pvBuffer ? &in_desc : NULL,
585                                                 0, &pAuthInfo->ctx, &out_desc,
586                                                 &pAuthInfo->attr, &pAuthInfo->exp);
587         if (sec_status == SEC_E_OK)
588         {
589             pAuthInfo->finished = TRUE;
590             pAuthInfo->auth_data = out.pvBuffer;
591             pAuthInfo->auth_data_len = out.cbBuffer;
592             TRACE("sending last auth packet\n");
593         }
594         else if (sec_status == SEC_I_CONTINUE_NEEDED)
595         {
596             pAuthInfo->auth_data = out.pvBuffer;
597             pAuthInfo->auth_data_len = out.cbBuffer;
598             TRACE("sending next auth packet\n");
599         }
600         else
601         {
602             ERR("InitializeSecurityContextW returned error 0x%08x\n", sec_status);
603             pAuthInfo->finished = TRUE;
604             HeapFree(GetProcessHeap(), 0, out.pvBuffer);
605             return FALSE;
606         }
607     }
608
609     return TRUE;
610 }
611
612 /***********************************************************************
613  *           HTTP_HttpAddRequestHeadersW (internal)
614  */
615 static BOOL WINAPI HTTP_HttpAddRequestHeadersW(LPWININETHTTPREQW lpwhr,
616         LPCWSTR lpszHeader, DWORD dwHeaderLength, DWORD dwModifier)
617 {
618     LPWSTR lpszStart;
619     LPWSTR lpszEnd;
620     LPWSTR buffer;
621     BOOL bSuccess = FALSE;
622     DWORD len;
623
624     TRACE("copying header: %s\n", debugstr_wn(lpszHeader, dwHeaderLength));
625
626     if( dwHeaderLength == ~0U )
627         len = strlenW(lpszHeader);
628     else
629         len = dwHeaderLength;
630     buffer = HeapAlloc( GetProcessHeap(), 0, sizeof(WCHAR)*(len+1) );
631     lstrcpynW( buffer, lpszHeader, len + 1);
632
633     lpszStart = buffer;
634
635     do
636     {
637         LPWSTR * pFieldAndValue;
638
639         lpszEnd = lpszStart;
640
641         while (*lpszEnd != '\0')
642         {
643             if (*lpszEnd == '\r' && *(lpszEnd + 1) == '\n')
644                  break;
645             lpszEnd++;
646         }
647
648         if (*lpszStart == '\0')
649             break;
650
651         if (*lpszEnd == '\r')
652         {
653             *lpszEnd = '\0';
654             lpszEnd += 2; /* Jump over \r\n */
655         }
656         TRACE("interpreting header %s\n", debugstr_w(lpszStart));
657         pFieldAndValue = HTTP_InterpretHttpHeader(lpszStart);
658         if (pFieldAndValue)
659         {
660             bSuccess = HTTP_VerifyValidHeader(lpwhr, pFieldAndValue[0]);
661             if (bSuccess)
662                 bSuccess = HTTP_ProcessHeader(lpwhr, pFieldAndValue[0],
663                     pFieldAndValue[1], dwModifier | HTTP_ADDHDR_FLAG_REQ);
664             HTTP_FreeTokens(pFieldAndValue);
665         }
666
667         lpszStart = lpszEnd;
668     } while (bSuccess);
669
670     HeapFree(GetProcessHeap(), 0, buffer);
671
672     return bSuccess;
673 }
674
675 /***********************************************************************
676  *           HttpAddRequestHeadersW (WININET.@)
677  *
678  * Adds one or more HTTP header to the request handler
679  *
680  * NOTE
681  * On Windows if dwHeaderLength includes the trailing '\0', then
682  * HttpAddRequestHeadersW() adds it too. However this results in an
683  * invalid Http header which is rejected by some servers so we probably
684  * don't need to match Windows on that point.
685  *
686  * RETURNS
687  *    TRUE  on success
688  *    FALSE on failure
689  *
690  */
691 BOOL WINAPI HttpAddRequestHeadersW(HINTERNET hHttpRequest,
692         LPCWSTR lpszHeader, DWORD dwHeaderLength, DWORD dwModifier)
693 {
694     BOOL bSuccess = FALSE;
695     LPWININETHTTPREQW lpwhr;
696
697     TRACE("%p, %s, %i, %i\n", hHttpRequest, debugstr_wn(lpszHeader, dwHeaderLength), dwHeaderLength, dwModifier);
698
699     if (!lpszHeader) 
700       return TRUE;
701
702     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hHttpRequest );
703     if (NULL == lpwhr ||  lpwhr->hdr.htype != WH_HHTTPREQ)
704     {
705         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
706         goto lend;
707     }
708     bSuccess = HTTP_HttpAddRequestHeadersW( lpwhr, lpszHeader, dwHeaderLength, dwModifier );
709 lend:
710     if( lpwhr )
711         WININET_Release( &lpwhr->hdr );
712
713     return bSuccess;
714 }
715
716 /***********************************************************************
717  *           HttpAddRequestHeadersA (WININET.@)
718  *
719  * Adds one or more HTTP header to the request handler
720  *
721  * RETURNS
722  *    TRUE  on success
723  *    FALSE on failure
724  *
725  */
726 BOOL WINAPI HttpAddRequestHeadersA(HINTERNET hHttpRequest,
727         LPCSTR lpszHeader, DWORD dwHeaderLength, DWORD dwModifier)
728 {
729     DWORD len;
730     LPWSTR hdr;
731     BOOL r;
732
733     TRACE("%p, %s, %i, %i\n", hHttpRequest, debugstr_an(lpszHeader, dwHeaderLength), dwHeaderLength, dwModifier);
734
735     len = MultiByteToWideChar( CP_ACP, 0, lpszHeader, dwHeaderLength, NULL, 0 );
736     hdr = HeapAlloc( GetProcessHeap(), 0, len*sizeof(WCHAR) );
737     MultiByteToWideChar( CP_ACP, 0, lpszHeader, dwHeaderLength, hdr, len );
738     if( dwHeaderLength != ~0U )
739         dwHeaderLength = len;
740
741     r = HttpAddRequestHeadersW( hHttpRequest, hdr, dwHeaderLength, dwModifier );
742
743     HeapFree( GetProcessHeap(), 0, hdr );
744
745     return r;
746 }
747
748 /***********************************************************************
749  *           HttpEndRequestA (WININET.@)
750  *
751  * Ends an HTTP request that was started by HttpSendRequestEx
752  *
753  * RETURNS
754  *    TRUE      if successful
755  *    FALSE     on failure
756  *
757  */
758 BOOL WINAPI HttpEndRequestA(HINTERNET hRequest, 
759         LPINTERNET_BUFFERSA lpBuffersOut, DWORD dwFlags, DWORD_PTR dwContext)
760 {
761     LPINTERNET_BUFFERSA ptr;
762     LPINTERNET_BUFFERSW lpBuffersOutW,ptrW;
763     BOOL rc = FALSE;
764
765     TRACE("(%p, %p, %08x, %08lx): stub\n", hRequest, lpBuffersOut, dwFlags,
766             dwContext);
767
768     ptr = lpBuffersOut;
769     if (ptr)
770         lpBuffersOutW = (LPINTERNET_BUFFERSW)HeapAlloc(GetProcessHeap(),
771                 HEAP_ZERO_MEMORY, sizeof(INTERNET_BUFFERSW));
772     else
773         lpBuffersOutW = NULL;
774
775     ptrW = lpBuffersOutW;
776     while (ptr)
777     {
778         if (ptr->lpvBuffer && ptr->dwBufferLength)
779             ptrW->lpvBuffer = HeapAlloc(GetProcessHeap(),0,ptr->dwBufferLength);
780         ptrW->dwBufferLength = ptr->dwBufferLength;
781         ptrW->dwBufferTotal= ptr->dwBufferTotal;
782
783         if (ptr->Next)
784             ptrW->Next = HeapAlloc(GetProcessHeap(),HEAP_ZERO_MEMORY,
785                     sizeof(INTERNET_BUFFERSW));
786
787         ptr = ptr->Next;
788         ptrW = ptrW->Next;
789     }
790
791     rc = HttpEndRequestW(hRequest, lpBuffersOutW, dwFlags, dwContext);
792
793     if (lpBuffersOutW)
794     {
795         ptrW = lpBuffersOutW;
796         while (ptrW)
797         {
798             LPINTERNET_BUFFERSW ptrW2;
799
800             FIXME("Do we need to translate info out of these buffer?\n");
801
802             HeapFree(GetProcessHeap(),0,ptrW->lpvBuffer);
803             ptrW2 = ptrW->Next;
804             HeapFree(GetProcessHeap(),0,ptrW);
805             ptrW = ptrW2;
806         }
807     }
808
809     return rc;
810 }
811
812 /***********************************************************************
813  *           HttpEndRequestW (WININET.@)
814  *
815  * Ends an HTTP request that was started by HttpSendRequestEx
816  *
817  * RETURNS
818  *    TRUE      if successful
819  *    FALSE     on failure
820  *
821  */
822 BOOL WINAPI HttpEndRequestW(HINTERNET hRequest, 
823         LPINTERNET_BUFFERSW lpBuffersOut, DWORD dwFlags, DWORD_PTR dwContext)
824 {
825     BOOL rc = FALSE;
826     LPWININETHTTPREQW lpwhr;
827     INT responseLen;
828     DWORD dwBufferSize;
829
830     TRACE("-->\n");
831     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hRequest );
832
833     if (NULL == lpwhr || lpwhr->hdr.htype != WH_HHTTPREQ)
834     {
835         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
836         if (lpwhr)
837             WININET_Release( &lpwhr->hdr );
838         return FALSE;
839     }
840
841     lpwhr->hdr.dwFlags |= dwFlags;
842     lpwhr->hdr.dwContext = dwContext;
843
844     /* We appear to do nothing with lpBuffersOut.. is that correct? */
845
846     SendAsyncCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
847             INTERNET_STATUS_RECEIVING_RESPONSE, NULL, 0);
848
849     responseLen = HTTP_GetResponseHeaders(lpwhr, TRUE);
850     if (responseLen)
851             rc = TRUE;
852
853     SendAsyncCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
854             INTERNET_STATUS_RESPONSE_RECEIVED, &responseLen, sizeof(DWORD));
855
856     /* process cookies here. Is this right? */
857     HTTP_ProcessCookies(lpwhr);
858
859     dwBufferSize = sizeof(lpwhr->dwContentLength);
860     if (!HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_FLAG_NUMBER|HTTP_QUERY_CONTENT_LENGTH,
861                              &lpwhr->dwContentLength,&dwBufferSize,NULL))
862         lpwhr->dwContentLength = -1;
863
864     if (lpwhr->dwContentLength == 0)
865         HTTP_FinishedReading(lpwhr);
866
867     if(!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_AUTO_REDIRECT))
868     {
869         DWORD dwCode,dwCodeLength=sizeof(DWORD);
870         if(HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_FLAG_NUMBER|HTTP_QUERY_STATUS_CODE,&dwCode,&dwCodeLength,NULL) &&
871             (dwCode==302 || dwCode==301))
872         {
873             WCHAR szNewLocation[INTERNET_MAX_URL_LENGTH];
874             dwBufferSize=sizeof(szNewLocation);
875             if(HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_LOCATION,szNewLocation,&dwBufferSize,NULL))
876             {
877                 /* redirects are always GETs */
878                 HeapFree(GetProcessHeap(),0,lpwhr->lpszVerb);
879                 lpwhr->lpszVerb = WININET_strdupW(szGET);
880                 HTTP_DrainContent(lpwhr);
881                 INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
882                                       INTERNET_STATUS_REDIRECT, szNewLocation,
883                                       dwBufferSize);
884                 rc = HTTP_HandleRedirect(lpwhr, szNewLocation);
885                 if (rc)
886                     rc = HTTP_HttpSendRequestW(lpwhr, NULL, 0, NULL, 0, 0, TRUE);
887             }
888         }
889     }
890
891     WININET_Release( &lpwhr->hdr );
892     TRACE("%i <--\n",rc);
893     return rc;
894 }
895
896 /***********************************************************************
897  *           HttpOpenRequestW (WININET.@)
898  *
899  * Open a HTTP request handle
900  *
901  * RETURNS
902  *    HINTERNET  a HTTP request handle on success
903  *    NULL       on failure
904  *
905  */
906 HINTERNET WINAPI HttpOpenRequestW(HINTERNET hHttpSession,
907         LPCWSTR lpszVerb, LPCWSTR lpszObjectName, LPCWSTR lpszVersion,
908         LPCWSTR lpszReferrer , LPCWSTR *lpszAcceptTypes,
909         DWORD dwFlags, DWORD_PTR dwContext)
910 {
911     LPWININETHTTPSESSIONW lpwhs;
912     HINTERNET handle = NULL;
913
914     TRACE("(%p, %s, %s, %s, %s, %p, %08x, %08lx)\n", hHttpSession,
915           debugstr_w(lpszVerb), debugstr_w(lpszObjectName),
916           debugstr_w(lpszVersion), debugstr_w(lpszReferrer), lpszAcceptTypes,
917           dwFlags, dwContext);
918     if(lpszAcceptTypes!=NULL)
919     {
920         int i;
921         for(i=0;lpszAcceptTypes[i]!=NULL;i++)
922             TRACE("\taccept type: %s\n",debugstr_w(lpszAcceptTypes[i]));
923     }    
924
925     lpwhs = (LPWININETHTTPSESSIONW) WININET_GetObject( hHttpSession );
926     if (NULL == lpwhs ||  lpwhs->hdr.htype != WH_HHTTPSESSION)
927     {
928         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
929         goto lend;
930     }
931
932     /*
933      * My tests seem to show that the windows version does not
934      * become asynchronous until after this point. And anyhow
935      * if this call was asynchronous then how would you get the
936      * necessary HINTERNET pointer returned by this function.
937      *
938      */
939     handle = HTTP_HttpOpenRequestW(lpwhs, lpszVerb, lpszObjectName,
940                                    lpszVersion, lpszReferrer, lpszAcceptTypes,
941                                    dwFlags, dwContext);
942 lend:
943     if( lpwhs )
944         WININET_Release( &lpwhs->hdr );
945     TRACE("returning %p\n", handle);
946     return handle;
947 }
948
949
950 /***********************************************************************
951  *           HttpOpenRequestA (WININET.@)
952  *
953  * Open a HTTP request handle
954  *
955  * RETURNS
956  *    HINTERNET  a HTTP request handle on success
957  *    NULL       on failure
958  *
959  */
960 HINTERNET WINAPI HttpOpenRequestA(HINTERNET hHttpSession,
961         LPCSTR lpszVerb, LPCSTR lpszObjectName, LPCSTR lpszVersion,
962         LPCSTR lpszReferrer , LPCSTR *lpszAcceptTypes,
963         DWORD dwFlags, DWORD_PTR dwContext)
964 {
965     LPWSTR szVerb = NULL, szObjectName = NULL;
966     LPWSTR szVersion = NULL, szReferrer = NULL, *szAcceptTypes = NULL;
967     INT len;
968     INT acceptTypesCount;
969     HINTERNET rc = FALSE;
970     TRACE("(%p, %s, %s, %s, %s, %p, %08x, %08lx)\n", hHttpSession,
971           debugstr_a(lpszVerb), debugstr_a(lpszObjectName),
972           debugstr_a(lpszVersion), debugstr_a(lpszReferrer), lpszAcceptTypes,
973           dwFlags, dwContext);
974
975     if (lpszVerb)
976     {
977         len = MultiByteToWideChar(CP_ACP, 0, lpszVerb, -1, NULL, 0 );
978         szVerb = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR) );
979         if ( !szVerb )
980             goto end;
981         MultiByteToWideChar(CP_ACP, 0, lpszVerb, -1, szVerb, len);
982     }
983
984     if (lpszObjectName)
985     {
986         len = MultiByteToWideChar(CP_ACP, 0, lpszObjectName, -1, NULL, 0 );
987         szObjectName = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR) );
988         if ( !szObjectName )
989             goto end;
990         MultiByteToWideChar(CP_ACP, 0, lpszObjectName, -1, szObjectName, len );
991     }
992
993     if (lpszVersion)
994     {
995         len = MultiByteToWideChar(CP_ACP, 0, lpszVersion, -1, NULL, 0 );
996         szVersion = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR));
997         if ( !szVersion )
998             goto end;
999         MultiByteToWideChar(CP_ACP, 0, lpszVersion, -1, szVersion, len );
1000     }
1001
1002     if (lpszReferrer)
1003     {
1004         len = MultiByteToWideChar(CP_ACP, 0, lpszReferrer, -1, NULL, 0 );
1005         szReferrer = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR));
1006         if ( !szReferrer )
1007             goto end;
1008         MultiByteToWideChar(CP_ACP, 0, lpszReferrer, -1, szReferrer, len );
1009     }
1010
1011     acceptTypesCount = 0;
1012     if (lpszAcceptTypes)
1013     {
1014         /* find out how many there are */
1015         while (lpszAcceptTypes[acceptTypesCount] && *lpszAcceptTypes[acceptTypesCount])
1016             acceptTypesCount++;
1017         szAcceptTypes = HeapAlloc(GetProcessHeap(), 0, sizeof(WCHAR *) * (acceptTypesCount+1));
1018         acceptTypesCount = 0;
1019         while (lpszAcceptTypes[acceptTypesCount] && *lpszAcceptTypes[acceptTypesCount])
1020         {
1021             len = MultiByteToWideChar(CP_ACP, 0, lpszAcceptTypes[acceptTypesCount],
1022                                 -1, NULL, 0 );
1023             szAcceptTypes[acceptTypesCount] = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR));
1024             if (!szAcceptTypes[acceptTypesCount] )
1025                 goto end;
1026             MultiByteToWideChar(CP_ACP, 0, lpszAcceptTypes[acceptTypesCount],
1027                                 -1, szAcceptTypes[acceptTypesCount], len );
1028             acceptTypesCount++;
1029         }
1030         szAcceptTypes[acceptTypesCount] = NULL;
1031     }
1032     else szAcceptTypes = 0;
1033
1034     rc = HttpOpenRequestW(hHttpSession, szVerb, szObjectName,
1035                           szVersion, szReferrer,
1036                           (LPCWSTR*)szAcceptTypes, dwFlags, dwContext);
1037
1038 end:
1039     if (szAcceptTypes)
1040     {
1041         acceptTypesCount = 0;
1042         while (szAcceptTypes[acceptTypesCount])
1043         {
1044             HeapFree(GetProcessHeap(), 0, szAcceptTypes[acceptTypesCount]);
1045             acceptTypesCount++;
1046         }
1047         HeapFree(GetProcessHeap(), 0, szAcceptTypes);
1048     }
1049     HeapFree(GetProcessHeap(), 0, szReferrer);
1050     HeapFree(GetProcessHeap(), 0, szVersion);
1051     HeapFree(GetProcessHeap(), 0, szObjectName);
1052     HeapFree(GetProcessHeap(), 0, szVerb);
1053
1054     return rc;
1055 }
1056
1057 /***********************************************************************
1058  *  HTTP_EncodeBase64
1059  */
1060 static UINT HTTP_EncodeBase64( LPCSTR bin, unsigned int len, LPWSTR base64 )
1061 {
1062     UINT n = 0, x;
1063     static const CHAR HTTP_Base64Enc[] =
1064         "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
1065
1066     while( len > 0 )
1067     {
1068         /* first 6 bits, all from bin[0] */
1069         base64[n++] = HTTP_Base64Enc[(bin[0] & 0xfc) >> 2];
1070         x = (bin[0] & 3) << 4;
1071
1072         /* next 6 bits, 2 from bin[0] and 4 from bin[1] */
1073         if( len == 1 )
1074         {
1075             base64[n++] = HTTP_Base64Enc[x];
1076             base64[n++] = '=';
1077             base64[n++] = '=';
1078             break;
1079         }
1080         base64[n++] = HTTP_Base64Enc[ x | ( (bin[1]&0xf0) >> 4 ) ];
1081         x = ( bin[1] & 0x0f ) << 2;
1082
1083         /* next 6 bits 4 from bin[1] and 2 from bin[2] */
1084         if( len == 2 )
1085         {
1086             base64[n++] = HTTP_Base64Enc[x];
1087             base64[n++] = '=';
1088             break;
1089         }
1090         base64[n++] = HTTP_Base64Enc[ x | ( (bin[2]&0xc0 ) >> 6 ) ];
1091
1092         /* last 6 bits, all from bin [2] */
1093         base64[n++] = HTTP_Base64Enc[ bin[2] & 0x3f ];
1094         bin += 3;
1095         len -= 3;
1096     }
1097     base64[n] = 0;
1098     return n;
1099 }
1100
1101 #define CH(x) (((x) >= 'A' && (x) <= 'Z') ? (x) - 'A' : \
1102                ((x) >= 'a' && (x) <= 'z') ? (x) - 'a' + 26 : \
1103                ((x) >= '0' && (x) <= '9') ? (x) - '0' + 52 : \
1104                ((x) == '+') ? 62 : ((x) == '/') ? 63 : -1)
1105 static const signed char HTTP_Base64Dec[256] =
1106 {
1107     CH( 0),CH( 1),CH( 2),CH( 3),CH( 4),CH( 5),CH( 6),CH( 7),CH( 8),CH( 9),
1108     CH(10),CH(11),CH(12),CH(13),CH(14),CH(15),CH(16),CH(17),CH(18),CH(19),
1109     CH(20),CH(21),CH(22),CH(23),CH(24),CH(25),CH(26),CH(27),CH(28),CH(29),
1110     CH(30),CH(31),CH(32),CH(33),CH(34),CH(35),CH(36),CH(37),CH(38),CH(39),
1111     CH(40),CH(41),CH(42),CH(43),CH(44),CH(45),CH(46),CH(47),CH(48),CH(49),
1112     CH(50),CH(51),CH(52),CH(53),CH(54),CH(55),CH(56),CH(57),CH(58),CH(59),
1113     CH(60),CH(61),CH(62),CH(63),CH(64),CH(65),CH(66),CH(67),CH(68),CH(69),
1114     CH(70),CH(71),CH(72),CH(73),CH(74),CH(75),CH(76),CH(77),CH(78),CH(79),
1115     CH(80),CH(81),CH(82),CH(83),CH(84),CH(85),CH(86),CH(87),CH(88),CH(89),
1116     CH(90),CH(91),CH(92),CH(93),CH(94),CH(95),CH(96),CH(97),CH(98),CH(99),
1117     CH(100),CH(101),CH(102),CH(103),CH(104),CH(105),CH(106),CH(107),CH(108),CH(109),
1118     CH(110),CH(111),CH(112),CH(113),CH(114),CH(115),CH(116),CH(117),CH(118),CH(119),
1119     CH(120),CH(121),CH(122),CH(123),CH(124),CH(125),CH(126),CH(127),CH(128),CH(129),
1120     CH(130),CH(131),CH(132),CH(133),CH(134),CH(135),CH(136),CH(137),CH(138),CH(139),
1121     CH(140),CH(141),CH(142),CH(143),CH(144),CH(145),CH(146),CH(147),CH(148),CH(149),
1122     CH(150),CH(151),CH(152),CH(153),CH(154),CH(155),CH(156),CH(157),CH(158),CH(159),
1123     CH(160),CH(161),CH(162),CH(163),CH(164),CH(165),CH(166),CH(167),CH(168),CH(169),
1124     CH(170),CH(171),CH(172),CH(173),CH(174),CH(175),CH(176),CH(177),CH(178),CH(179),
1125     CH(180),CH(181),CH(182),CH(183),CH(184),CH(185),CH(186),CH(187),CH(188),CH(189),
1126     CH(190),CH(191),CH(192),CH(193),CH(194),CH(195),CH(196),CH(197),CH(198),CH(199),
1127     CH(200),CH(201),CH(202),CH(203),CH(204),CH(205),CH(206),CH(207),CH(208),CH(209),
1128     CH(210),CH(211),CH(212),CH(213),CH(214),CH(215),CH(216),CH(217),CH(218),CH(219),
1129     CH(220),CH(221),CH(222),CH(223),CH(224),CH(225),CH(226),CH(227),CH(228),CH(229),
1130     CH(230),CH(231),CH(232),CH(233),CH(234),CH(235),CH(236),CH(237),CH(238),CH(239),
1131     CH(240),CH(241),CH(242),CH(243),CH(244),CH(245),CH(246),CH(247),CH(248), CH(249),
1132     CH(250),CH(251),CH(252),CH(253),CH(254),CH(255),
1133 };
1134 #undef CH
1135
1136 /***********************************************************************
1137  *  HTTP_DecodeBase64
1138  */
1139 static UINT HTTP_DecodeBase64( LPCWSTR base64, LPSTR bin )
1140 {
1141     unsigned int n = 0;
1142
1143     while(*base64)
1144     {
1145         signed char in[4];
1146
1147         if (base64[0] >= ARRAYSIZE(HTTP_Base64Dec) ||
1148             ((in[0] = HTTP_Base64Dec[base64[0]]) == -1) ||
1149             base64[1] >= ARRAYSIZE(HTTP_Base64Dec) ||
1150             ((in[1] = HTTP_Base64Dec[base64[1]]) == -1))
1151         {
1152             WARN("invalid base64: %s\n", debugstr_w(base64));
1153             return 0;
1154         }
1155         if (bin)
1156             bin[n] = (unsigned char) (in[0] << 2 | in[1] >> 4);
1157         n++;
1158
1159         if ((base64[2] == '=') && (base64[3] == '='))
1160             break;
1161         if (base64[2] > ARRAYSIZE(HTTP_Base64Dec) ||
1162             ((in[2] = HTTP_Base64Dec[base64[2]]) == -1))
1163         {
1164             WARN("invalid base64: %s\n", debugstr_w(&base64[2]));
1165             return 0;
1166         }
1167         if (bin)
1168             bin[n] = (unsigned char) (in[1] << 4 | in[2] >> 2);
1169         n++;
1170
1171         if (base64[3] == '=')
1172             break;
1173         if (base64[3] > ARRAYSIZE(HTTP_Base64Dec) ||
1174             ((in[3] = HTTP_Base64Dec[base64[3]]) == -1))
1175         {
1176             WARN("invalid base64: %s\n", debugstr_w(&base64[3]));
1177             return 0;
1178         }
1179         if (bin)
1180             bin[n] = (unsigned char) (((in[2] << 6) & 0xc0) | in[3]);
1181         n++;
1182
1183         base64 += 4;
1184     }
1185
1186     return n;
1187 }
1188
1189 /***********************************************************************
1190  *  HTTP_InsertAuthorizationForHeader
1191  *
1192  *   Insert or delete the authorization field in the request header.
1193  */
1194 static BOOL HTTP_InsertAuthorization( LPWININETHTTPREQW lpwhr, struct HttpAuthInfo *pAuthInfo, LPCWSTR header )
1195 {
1196     if (pAuthInfo)
1197     {
1198         static const WCHAR wszSpace[] = {' ',0};
1199         static const WCHAR wszBasic[] = {'B','a','s','i','c',0};
1200         unsigned int len;
1201         WCHAR *authorization = NULL;
1202
1203         if (pAuthInfo->auth_data_len)
1204         {
1205             /* scheme + space + base64 encoded data (3/2/1 bytes data -> 4 bytes of characters) */
1206             len = strlenW(pAuthInfo->scheme)+1+((pAuthInfo->auth_data_len+2)*4)/3;
1207             authorization = HeapAlloc(GetProcessHeap(), 0, (len+1)*sizeof(WCHAR));
1208             if (!authorization)
1209                 return FALSE;
1210
1211             strcpyW(authorization, pAuthInfo->scheme);
1212             strcatW(authorization, wszSpace);
1213             HTTP_EncodeBase64(pAuthInfo->auth_data,
1214                               pAuthInfo->auth_data_len,
1215                               authorization+strlenW(authorization));
1216
1217             /* clear the data as it isn't valid now that it has been sent to the
1218              * server, unless it's Basic authentication which doesn't do
1219              * connection tracking */
1220             if (strcmpiW(pAuthInfo->scheme, wszBasic))
1221             {
1222                 HeapFree(GetProcessHeap(), 0, pAuthInfo->auth_data);
1223                 pAuthInfo->auth_data = NULL;
1224                 pAuthInfo->auth_data_len = 0;
1225             }
1226         }
1227
1228         TRACE("Inserting authorization: %s\n", debugstr_w(authorization));
1229
1230         HTTP_ProcessHeader(lpwhr, header, authorization, HTTP_ADDHDR_FLAG_REQ | HTTP_ADDHDR_FLAG_REPLACE);
1231
1232         HeapFree(GetProcessHeap(), 0, authorization);
1233     }
1234     return TRUE;
1235 }
1236
1237 static WCHAR *HTTP_BuildProxyRequestUrl(WININETHTTPREQW *req)
1238 {
1239     WCHAR new_location[INTERNET_MAX_URL_LENGTH], *url;
1240     DWORD size;
1241
1242     size = sizeof(new_location);
1243     if (HTTP_HttpQueryInfoW(req, HTTP_QUERY_LOCATION, new_location, &size, NULL))
1244     {
1245         if (!(url = HeapAlloc( GetProcessHeap(), 0, size + sizeof(WCHAR) ))) return NULL;
1246         strcpyW( url, new_location );
1247     }
1248     else
1249     {
1250         static const WCHAR slash[] = { '/',0 };
1251         static const WCHAR format[] = { 'h','t','t','p',':','/','/','%','s',':','%','d',0 };
1252         WININETHTTPSESSIONW *session = req->lpHttpSession;
1253
1254         size = 15; /* "http://" + sizeof(port#) + ":/\0" */
1255         size += strlenW( session->lpszHostName ) + strlenW( req->lpszPath );
1256
1257         if (!(url = HeapAlloc( GetProcessHeap(), 0, size * sizeof(WCHAR) ))) return FALSE;
1258
1259         sprintfW( url, format, session->lpszHostName, session->nHostPort );
1260         if (req->lpszPath[0] != '/') strcatW( url, slash );
1261         strcatW( url, req->lpszPath );
1262     }
1263     TRACE("url=%s\n", debugstr_w(url));
1264     return url;
1265 }
1266
1267 /***********************************************************************
1268  *           HTTP_DealWithProxy
1269  */
1270 static BOOL HTTP_DealWithProxy( LPWININETAPPINFOW hIC,
1271     LPWININETHTTPSESSIONW lpwhs, LPWININETHTTPREQW lpwhr)
1272 {
1273     WCHAR buf[MAXHOSTNAME];
1274     WCHAR proxy[MAXHOSTNAME + 15]; /* 15 == "http://" + sizeof(port#) + ":/\0" */
1275     static WCHAR szNul[] = { 0 };
1276     URL_COMPONENTSW UrlComponents;
1277     static const WCHAR szHttp[] = { 'h','t','t','p',':','/','/',0 };
1278     static const WCHAR szFormat[] = { 'h','t','t','p',':','/','/','%','s',0 };
1279
1280     memset( &UrlComponents, 0, sizeof UrlComponents );
1281     UrlComponents.dwStructSize = sizeof UrlComponents;
1282     UrlComponents.lpszHostName = buf;
1283     UrlComponents.dwHostNameLength = MAXHOSTNAME;
1284
1285     if( CSTR_EQUAL != CompareStringW(LOCALE_SYSTEM_DEFAULT, NORM_IGNORECASE,
1286                                  hIC->lpszProxy,strlenW(szHttp),szHttp,strlenW(szHttp)) )
1287         sprintfW(proxy, szFormat, hIC->lpszProxy);
1288     else
1289         strcpyW(proxy, hIC->lpszProxy);
1290     if( !InternetCrackUrlW(proxy, 0, 0, &UrlComponents) )
1291         return FALSE;
1292     if( UrlComponents.dwHostNameLength == 0 )
1293         return FALSE;
1294
1295     if( !lpwhr->lpszPath )
1296         lpwhr->lpszPath = szNul;
1297
1298     if(UrlComponents.nPort == INTERNET_INVALID_PORT_NUMBER)
1299         UrlComponents.nPort = INTERNET_DEFAULT_HTTP_PORT;
1300
1301     HeapFree(GetProcessHeap(), 0, lpwhs->lpszServerName);
1302     lpwhs->lpszServerName = WININET_strdupW(UrlComponents.lpszHostName);
1303     lpwhs->nServerPort = UrlComponents.nPort;
1304
1305     TRACE("proxy server=%s port=%d\n", debugstr_w(lpwhs->lpszServerName), lpwhs->nServerPort);
1306     return TRUE;
1307 }
1308
1309 static BOOL HTTP_ResolveName(LPWININETHTTPREQW lpwhr)
1310 {
1311     char szaddr[32];
1312     LPWININETHTTPSESSIONW lpwhs = lpwhr->lpHttpSession;
1313
1314     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
1315                           INTERNET_STATUS_RESOLVING_NAME,
1316                           lpwhs->lpszServerName,
1317                           strlenW(lpwhs->lpszServerName)+1);
1318
1319     if (!GetAddress(lpwhs->lpszServerName, lpwhs->nServerPort,
1320                     &lpwhs->socketAddress))
1321     {
1322         INTERNET_SetLastError(ERROR_INTERNET_NAME_NOT_RESOLVED);
1323         return FALSE;
1324     }
1325
1326     inet_ntop(lpwhs->socketAddress.sin_family, &lpwhs->socketAddress.sin_addr,
1327               szaddr, sizeof(szaddr));
1328     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
1329                           INTERNET_STATUS_NAME_RESOLVED,
1330                           szaddr, strlen(szaddr)+1);
1331     return TRUE;
1332 }
1333
1334
1335 /***********************************************************************
1336  *           HTTPREQ_Destroy (internal)
1337  *
1338  * Deallocate request handle
1339  *
1340  */
1341 static void HTTPREQ_Destroy(WININETHANDLEHEADER *hdr)
1342 {
1343     LPWININETHTTPREQW lpwhr = (LPWININETHTTPREQW) hdr;
1344     DWORD i;
1345
1346     TRACE("\n");
1347
1348     if(lpwhr->hCacheFile)
1349         CloseHandle(lpwhr->hCacheFile);
1350
1351     if(lpwhr->lpszCacheFile) {
1352         DeleteFileW(lpwhr->lpszCacheFile); /* FIXME */
1353         HeapFree(GetProcessHeap(), 0, lpwhr->lpszCacheFile);
1354     }
1355
1356     WININET_Release(&lpwhr->lpHttpSession->hdr);
1357
1358     HeapFree(GetProcessHeap(), 0, lpwhr->lpszPath);
1359     HeapFree(GetProcessHeap(), 0, lpwhr->lpszVerb);
1360     HeapFree(GetProcessHeap(), 0, lpwhr->lpszRawHeaders);
1361     HeapFree(GetProcessHeap(), 0, lpwhr->lpszVersion);
1362     HeapFree(GetProcessHeap(), 0, lpwhr->lpszStatusText);
1363
1364     for (i = 0; i < lpwhr->nCustHeaders; i++)
1365     {
1366         HeapFree(GetProcessHeap(), 0, lpwhr->pCustHeaders[i].lpszField);
1367         HeapFree(GetProcessHeap(), 0, lpwhr->pCustHeaders[i].lpszValue);
1368     }
1369
1370     HeapFree(GetProcessHeap(), 0, lpwhr->pCustHeaders);
1371     HeapFree(GetProcessHeap(), 0, lpwhr);
1372 }
1373
1374 static void HTTPREQ_CloseConnection(WININETHANDLEHEADER *hdr)
1375 {
1376     LPWININETHTTPREQW lpwhr = (LPWININETHTTPREQW) hdr;
1377     LPWININETHTTPSESSIONW lpwhs = NULL;
1378
1379     TRACE("%p\n",lpwhr);
1380
1381     if (!NETCON_connected(&lpwhr->netConnection))
1382         return;
1383
1384     if (lpwhr->pAuthInfo)
1385     {
1386         if (SecIsValidHandle(&lpwhr->pAuthInfo->ctx))
1387             DeleteSecurityContext(&lpwhr->pAuthInfo->ctx);
1388         if (SecIsValidHandle(&lpwhr->pAuthInfo->cred))
1389             FreeCredentialsHandle(&lpwhr->pAuthInfo->cred);
1390
1391         HeapFree(GetProcessHeap(), 0, lpwhr->pAuthInfo->auth_data);
1392         HeapFree(GetProcessHeap(), 0, lpwhr->pAuthInfo->scheme);
1393         HeapFree(GetProcessHeap(), 0, lpwhr->pAuthInfo);
1394         lpwhr->pAuthInfo = NULL;
1395     }
1396     if (lpwhr->pProxyAuthInfo)
1397     {
1398         if (SecIsValidHandle(&lpwhr->pProxyAuthInfo->ctx))
1399             DeleteSecurityContext(&lpwhr->pProxyAuthInfo->ctx);
1400         if (SecIsValidHandle(&lpwhr->pProxyAuthInfo->cred))
1401             FreeCredentialsHandle(&lpwhr->pProxyAuthInfo->cred);
1402
1403         HeapFree(GetProcessHeap(), 0, lpwhr->pProxyAuthInfo->auth_data);
1404         HeapFree(GetProcessHeap(), 0, lpwhr->pProxyAuthInfo->scheme);
1405         HeapFree(GetProcessHeap(), 0, lpwhr->pProxyAuthInfo);
1406         lpwhr->pProxyAuthInfo = NULL;
1407     }
1408
1409     lpwhs = lpwhr->lpHttpSession;
1410
1411     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
1412                           INTERNET_STATUS_CLOSING_CONNECTION, 0, 0);
1413
1414     NETCON_close(&lpwhr->netConnection);
1415
1416     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
1417                           INTERNET_STATUS_CONNECTION_CLOSED, 0, 0);
1418 }
1419
1420 static DWORD HTTPREQ_QueryOption(WININETHANDLEHEADER *hdr, DWORD option, void *buffer, DWORD *size, BOOL unicode)
1421 {
1422     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1423
1424     switch(option) {
1425     case INTERNET_OPTION_HANDLE_TYPE:
1426         TRACE("INTERNET_OPTION_HANDLE_TYPE\n");
1427
1428         if (*size < sizeof(ULONG))
1429             return ERROR_INSUFFICIENT_BUFFER;
1430
1431         *size = sizeof(DWORD);
1432         *(DWORD*)buffer = INTERNET_HANDLE_TYPE_HTTP_REQUEST;
1433         return ERROR_SUCCESS;
1434
1435     case INTERNET_OPTION_URL: {
1436         WCHAR url[INTERNET_MAX_URL_LENGTH];
1437         HTTPHEADERW *host;
1438         DWORD len;
1439
1440         static const WCHAR formatW[] = {'h','t','t','p',':','/','/','%','s','%','s',0};
1441         static const WCHAR hostW[] = {'H','o','s','t',0};
1442
1443         TRACE("INTERNET_OPTION_URL\n");
1444
1445         host = HTTP_GetHeader(req, hostW);
1446         sprintfW(url, formatW, host->lpszValue, req->lpszPath);
1447         TRACE("INTERNET_OPTION_URL: %s\n",debugstr_w(url));
1448
1449         if(unicode) {
1450             len = (strlenW(url)+1) * sizeof(WCHAR);
1451             if(*size < len)
1452                 return ERROR_INSUFFICIENT_BUFFER;
1453
1454             *size = len;
1455             strcpyW(buffer, url);
1456             return ERROR_SUCCESS;
1457         }else {
1458             len = WideCharToMultiByte(CP_ACP, 0, url, -1, buffer, *size, NULL, NULL);
1459             if(len > *size)
1460                 return ERROR_INSUFFICIENT_BUFFER;
1461
1462             *size = len;
1463             return ERROR_SUCCESS;
1464         }
1465     }
1466
1467     case INTERNET_OPTION_DATAFILE_NAME: {
1468         DWORD req_size;
1469
1470         TRACE("INTERNET_OPTION_DATAFILE_NAME\n");
1471
1472         if(!req->lpszCacheFile) {
1473             *size = 0;
1474             return ERROR_INTERNET_ITEM_NOT_FOUND;
1475         }
1476
1477         if(unicode) {
1478             req_size = (lstrlenW(req->lpszCacheFile)+1) * sizeof(WCHAR);
1479             if(*size < req_size)
1480                 return ERROR_INSUFFICIENT_BUFFER;
1481
1482             *size = req_size;
1483             memcpy(buffer, req->lpszCacheFile, *size);
1484             return ERROR_SUCCESS;
1485         }else {
1486             req_size = WideCharToMultiByte(CP_ACP, 0, req->lpszCacheFile, -1, NULL, 0, NULL, NULL);
1487             if (req_size > *size)
1488                 return ERROR_INSUFFICIENT_BUFFER;
1489
1490             *size = WideCharToMultiByte(CP_ACP, 0, req->lpszCacheFile,
1491                     -1, buffer, *size, NULL, NULL);
1492             return ERROR_SUCCESS;
1493         }
1494     }
1495
1496     case INTERNET_OPTION_SECURITY_CERTIFICATE_STRUCT: {
1497         PCCERT_CONTEXT context;
1498
1499         if(*size < sizeof(INTERNET_CERTIFICATE_INFOW)) {
1500             *size = sizeof(INTERNET_CERTIFICATE_INFOW);
1501             return ERROR_INSUFFICIENT_BUFFER;
1502         }
1503
1504         context = (PCCERT_CONTEXT)NETCON_GetCert(&(req->netConnection));
1505         if(context) {
1506             INTERNET_CERTIFICATE_INFOW *info = (INTERNET_CERTIFICATE_INFOW*)buffer;
1507             DWORD len;
1508
1509             memset(info, 0, sizeof(INTERNET_CERTIFICATE_INFOW));
1510             info->ftExpiry = context->pCertInfo->NotAfter;
1511             info->ftStart = context->pCertInfo->NotBefore;
1512             if(unicode) {
1513                 len = CertNameToStrW(context->dwCertEncodingType,
1514                         &context->pCertInfo->Subject, CERT_SIMPLE_NAME_STR, NULL, 0);
1515                 info->lpszSubjectInfo = LocalAlloc(0, len*sizeof(WCHAR));
1516                 if(info->lpszSubjectInfo)
1517                     CertNameToStrW(context->dwCertEncodingType,
1518                              &context->pCertInfo->Subject, CERT_SIMPLE_NAME_STR,
1519                              info->lpszSubjectInfo, len);
1520                 len = CertNameToStrW(context->dwCertEncodingType,
1521                          &context->pCertInfo->Issuer, CERT_SIMPLE_NAME_STR, NULL, 0);
1522                 info->lpszIssuerInfo = LocalAlloc(0, len*sizeof(WCHAR));
1523                 if (info->lpszIssuerInfo)
1524                     CertNameToStrW(context->dwCertEncodingType,
1525                              &context->pCertInfo->Issuer, CERT_SIMPLE_NAME_STR,
1526                              info->lpszIssuerInfo, len);
1527             }else {
1528                 INTERNET_CERTIFICATE_INFOA *infoA = (INTERNET_CERTIFICATE_INFOA*)info;
1529
1530                 len = CertNameToStrA(context->dwCertEncodingType,
1531                          &context->pCertInfo->Subject, CERT_SIMPLE_NAME_STR, NULL, 0);
1532                 infoA->lpszSubjectInfo = LocalAlloc(0, len);
1533                 if(infoA->lpszSubjectInfo)
1534                     CertNameToStrA(context->dwCertEncodingType,
1535                              &context->pCertInfo->Subject, CERT_SIMPLE_NAME_STR,
1536                              infoA->lpszSubjectInfo, len);
1537                 len = CertNameToStrA(context->dwCertEncodingType,
1538                          &context->pCertInfo->Issuer, CERT_SIMPLE_NAME_STR, NULL, 0);
1539                 infoA->lpszIssuerInfo = LocalAlloc(0, len);
1540                 if(infoA->lpszIssuerInfo)
1541                     CertNameToStrA(context->dwCertEncodingType,
1542                              &context->pCertInfo->Issuer, CERT_SIMPLE_NAME_STR,
1543                              infoA->lpszIssuerInfo, len);
1544             }
1545
1546             /*
1547              * Contrary to MSDN, these do not appear to be set.
1548              * lpszProtocolName
1549              * lpszSignatureAlgName
1550              * lpszEncryptionAlgName
1551              * dwKeySize
1552              */
1553             CertFreeCertificateContext(context);
1554             return ERROR_SUCCESS;
1555         }
1556     }
1557     }
1558
1559     FIXME("Not implemented option %d\n", option);
1560     return ERROR_INTERNET_INVALID_OPTION;
1561 }
1562
1563 static DWORD HTTPREQ_SetOption(WININETHANDLEHEADER *hdr, DWORD option, void *buffer, DWORD size)
1564 {
1565     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1566
1567     switch(option) {
1568     case INTERNET_OPTION_SEND_TIMEOUT:
1569     case INTERNET_OPTION_RECEIVE_TIMEOUT:
1570         TRACE("INTERNET_OPTION_SEND/RECEIVE_TIMEOUT\n");
1571
1572         if (size != sizeof(DWORD))
1573             return ERROR_INVALID_PARAMETER;
1574
1575         return NETCON_set_timeout(&req->netConnection, option == INTERNET_OPTION_SEND_TIMEOUT,
1576                     *(DWORD*)buffer);
1577     }
1578
1579     return ERROR_INTERNET_INVALID_OPTION;
1580 }
1581
1582 static DWORD HTTP_Read(WININETHTTPREQW *req, void *buffer, DWORD size, DWORD *read, BOOL sync)
1583 {
1584     int bytes_read;
1585
1586     if(!NETCON_recv(&req->netConnection, buffer, min(size, req->dwContentLength - req->dwContentRead),
1587                      sync ? MSG_WAITALL : 0, &bytes_read)) {
1588         if(req->dwContentLength != -1 && req->dwContentRead != req->dwContentLength)
1589             ERR("not all data received %d/%d\n", req->dwContentRead, req->dwContentLength);
1590
1591         /* always return success, even if the network layer returns an error */
1592         *read = 0;
1593         HTTP_FinishedReading(req);
1594         return ERROR_SUCCESS;
1595     }
1596
1597     req->dwContentRead += bytes_read;
1598     *read = bytes_read;
1599
1600     if(req->lpszCacheFile) {
1601         BOOL res;
1602
1603         res = WriteFile(req->hCacheFile, buffer, bytes_read, NULL, NULL);
1604         if(!res)
1605             WARN("WriteFile failed: %u\n", GetLastError());
1606     }
1607
1608     if(!bytes_read && (req->dwContentRead == req->dwContentLength))
1609         HTTP_FinishedReading(req);
1610
1611     return ERROR_SUCCESS;
1612 }
1613
1614 static DWORD get_chunk_size(const char *buffer)
1615 {
1616     const char *p;
1617     DWORD size = 0;
1618
1619     for (p = buffer; *p; p++)
1620     {
1621         if (*p >= '0' && *p <= '9') size = size * 16 + *p - '0';
1622         else if (*p >= 'a' && *p <= 'f') size = size * 16 + *p - 'a' + 10;
1623         else if (*p >= 'A' && *p <= 'F') size = size * 16 + *p - 'A' + 10;
1624         else if (*p == ';') break;
1625     }
1626     return size;
1627 }
1628
1629 static DWORD HTTP_ReadChunked(WININETHTTPREQW *req, void *buffer, DWORD size, DWORD *read, BOOL sync)
1630 {
1631     char reply[MAX_REPLY_LEN], *p = buffer;
1632     DWORD buflen, to_read, to_write = size;
1633     int bytes_read;
1634
1635     *read = 0;
1636     for (;;)
1637     {
1638         if (*read == size) break;
1639
1640         if (req->dwContentLength == ~0UL) /* new chunk */
1641         {
1642             buflen = sizeof(reply);
1643             if (!NETCON_getNextLine(&req->netConnection, reply, &buflen)) break;
1644
1645             if (!(req->dwContentLength = get_chunk_size(reply)))
1646             {
1647                 /* zero sized chunk marks end of transfer; read any trailing headers and return */
1648                 HTTP_GetResponseHeaders(req, FALSE);
1649                 break;
1650             }
1651         }
1652         to_read = min(to_write, req->dwContentLength - req->dwContentRead);
1653
1654         if (!NETCON_recv(&req->netConnection, p, to_read, sync ? MSG_WAITALL : 0, &bytes_read))
1655         {
1656             if (bytes_read != to_read)
1657                 ERR("Not all data received %d/%d\n", bytes_read, to_read);
1658
1659             /* always return success, even if the network layer returns an error */
1660             *read = 0;
1661             break;
1662         }
1663         if (!bytes_read) break;
1664
1665         req->dwContentRead += bytes_read;
1666         to_write -= bytes_read;
1667         *read += bytes_read;
1668
1669         if (req->lpszCacheFile)
1670         {
1671             if (!WriteFile(req->hCacheFile, p, bytes_read, NULL, NULL))
1672                 WARN("WriteFile failed: %u\n", GetLastError());
1673         }
1674         p += bytes_read;
1675
1676         if (req->dwContentRead == req->dwContentLength) /* chunk complete */
1677         {
1678             req->dwContentRead = 0;
1679             req->dwContentLength = ~0UL;
1680
1681             buflen = sizeof(reply);
1682             if (!NETCON_getNextLine(&req->netConnection, reply, &buflen))
1683             {
1684                 ERR("Malformed chunk\n");
1685                 *read = 0;
1686                 break;
1687             }
1688         }
1689     }
1690     if (!*read) HTTP_FinishedReading(req);
1691     return ERROR_SUCCESS;
1692 }
1693
1694 static DWORD HTTPREQ_Read(WININETHTTPREQW *req, void *buffer, DWORD size, DWORD *read, BOOL sync)
1695 {
1696     WCHAR encoding[20];
1697     DWORD buflen = sizeof(encoding);
1698     static const WCHAR szChunked[] = {'c','h','u','n','k','e','d',0};
1699
1700     if (HTTP_HttpQueryInfoW(req, HTTP_QUERY_TRANSFER_ENCODING, encoding, &buflen, NULL) &&
1701         !strcmpiW(encoding, szChunked))
1702     {
1703         return HTTP_ReadChunked(req, buffer, size, read, sync);
1704     }
1705     else
1706         return HTTP_Read(req, buffer, size, read, sync);
1707 }
1708
1709 static DWORD HTTPREQ_ReadFile(WININETHANDLEHEADER *hdr, void *buffer, DWORD size, DWORD *read)
1710 {
1711     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1712     return HTTPREQ_Read(req, buffer, size, read, TRUE);
1713 }
1714
1715 static void HTTPREQ_AsyncReadFileExProc(WORKREQUEST *workRequest)
1716 {
1717     struct WORKREQ_INTERNETREADFILEEXA const *data = &workRequest->u.InternetReadFileExA;
1718     WININETHTTPREQW *req = (WININETHTTPREQW*)workRequest->hdr;
1719     INTERNET_ASYNC_RESULT iar;
1720     DWORD res;
1721
1722     TRACE("INTERNETREADFILEEXA %p\n", workRequest->hdr);
1723
1724     res = HTTPREQ_Read(req, data->lpBuffersOut->lpvBuffer,
1725             data->lpBuffersOut->dwBufferLength, &data->lpBuffersOut->dwBufferLength, TRUE);
1726
1727     iar.dwResult = res == ERROR_SUCCESS;
1728     iar.dwError = res;
1729
1730     INTERNET_SendCallback(&req->hdr, req->hdr.dwContext,
1731                           INTERNET_STATUS_REQUEST_COMPLETE, &iar,
1732                           sizeof(INTERNET_ASYNC_RESULT));
1733 }
1734
1735 static DWORD HTTPREQ_ReadFileExA(WININETHANDLEHEADER *hdr, INTERNET_BUFFERSA *buffers,
1736         DWORD flags, DWORD_PTR context)
1737 {
1738
1739     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1740     DWORD res;
1741
1742     if (flags & ~(IRF_ASYNC|IRF_NO_WAIT))
1743         FIXME("these dwFlags aren't implemented: 0x%x\n", flags & ~(IRF_ASYNC|IRF_NO_WAIT));
1744
1745     if (buffers->dwStructSize != sizeof(*buffers))
1746         return ERROR_INVALID_PARAMETER;
1747
1748     INTERNET_SendCallback(&req->hdr, req->hdr.dwContext, INTERNET_STATUS_RECEIVING_RESPONSE, NULL, 0);
1749
1750     if (hdr->dwFlags & INTERNET_FLAG_ASYNC) {
1751         DWORD available = 0;
1752
1753         NETCON_query_data_available(&req->netConnection, &available);
1754         if (!available)
1755         {
1756             WORKREQUEST workRequest;
1757
1758             workRequest.asyncproc = HTTPREQ_AsyncReadFileExProc;
1759             workRequest.hdr = WININET_AddRef(&req->hdr);
1760             workRequest.u.InternetReadFileExA.lpBuffersOut = buffers;
1761
1762             INTERNET_AsyncCall(&workRequest);
1763
1764             return ERROR_IO_PENDING;
1765         }
1766     }
1767
1768     res = HTTPREQ_Read(req, buffers->lpvBuffer, buffers->dwBufferLength, &buffers->dwBufferLength,
1769             !(flags & IRF_NO_WAIT));
1770
1771     if (res == ERROR_SUCCESS) {
1772         DWORD size = buffers->dwBufferLength;
1773         INTERNET_SendCallback(&req->hdr, req->hdr.dwContext, INTERNET_STATUS_RESPONSE_RECEIVED,
1774                 &size, sizeof(size));
1775     }
1776
1777     return res;
1778 }
1779
1780 static BOOL HTTPREQ_WriteFile(WININETHANDLEHEADER *hdr, const void *buffer, DWORD size, DWORD *written)
1781 {
1782     LPWININETHTTPREQW lpwhr = (LPWININETHTTPREQW)hdr;
1783
1784     return NETCON_send(&lpwhr->netConnection, buffer, size, 0, (LPINT)written);
1785 }
1786
1787 static void HTTPREQ_AsyncQueryDataAvailableProc(WORKREQUEST *workRequest)
1788 {
1789     WININETHTTPREQW *req = (WININETHTTPREQW*)workRequest->hdr;
1790     INTERNET_ASYNC_RESULT iar;
1791     char buffer[4048];
1792
1793     TRACE("%p\n", workRequest->hdr);
1794
1795     iar.dwResult = NETCON_recv(&req->netConnection, buffer,
1796                                min(sizeof(buffer), req->dwContentLength - req->dwContentRead),
1797                                MSG_PEEK, (int *)&iar.dwError);
1798
1799     INTERNET_SendCallback(&req->hdr, req->hdr.dwContext, INTERNET_STATUS_REQUEST_COMPLETE, &iar,
1800                           sizeof(INTERNET_ASYNC_RESULT));
1801 }
1802
1803 static DWORD HTTPREQ_QueryDataAvailable(WININETHANDLEHEADER *hdr, DWORD *available, DWORD flags, DWORD_PTR ctx)
1804 {
1805     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1806     BYTE buffer[4048];
1807     BOOL async;
1808
1809     TRACE("(%p %p %x %lx)\n", req, available, flags, ctx);
1810
1811     if(!NETCON_query_data_available(&req->netConnection, available) || *available)
1812         return ERROR_SUCCESS;
1813
1814     /* Even if we are in async mode, we need to determine whether
1815      * there is actually more data available. We do this by trying
1816      * to peek only a single byte in async mode. */
1817     async = (req->lpHttpSession->lpAppInfo->hdr.dwFlags & INTERNET_FLAG_ASYNC) != 0;
1818
1819     if (NETCON_recv(&req->netConnection, buffer,
1820                     min(async ? 1 : sizeof(buffer), req->dwContentLength - req->dwContentRead),
1821                     MSG_PEEK, (int *)available) && async && *available)
1822     {
1823         WORKREQUEST workRequest;
1824
1825         *available = 0;
1826         workRequest.asyncproc = HTTPREQ_AsyncQueryDataAvailableProc;
1827         workRequest.hdr = WININET_AddRef( &req->hdr );
1828
1829         INTERNET_AsyncCall(&workRequest);
1830
1831         return ERROR_IO_PENDING;
1832     }
1833
1834     return ERROR_SUCCESS;
1835 }
1836
1837 static const HANDLEHEADERVtbl HTTPREQVtbl = {
1838     HTTPREQ_Destroy,
1839     HTTPREQ_CloseConnection,
1840     HTTPREQ_QueryOption,
1841     HTTPREQ_SetOption,
1842     HTTPREQ_ReadFile,
1843     HTTPREQ_ReadFileExA,
1844     HTTPREQ_WriteFile,
1845     HTTPREQ_QueryDataAvailable,
1846     NULL
1847 };
1848
1849 /***********************************************************************
1850  *           HTTP_HttpOpenRequestW (internal)
1851  *
1852  * Open a HTTP request handle
1853  *
1854  * RETURNS
1855  *    HINTERNET  a HTTP request handle on success
1856  *    NULL       on failure
1857  *
1858  */
1859 HINTERNET WINAPI HTTP_HttpOpenRequestW(LPWININETHTTPSESSIONW lpwhs,
1860         LPCWSTR lpszVerb, LPCWSTR lpszObjectName, LPCWSTR lpszVersion,
1861         LPCWSTR lpszReferrer , LPCWSTR *lpszAcceptTypes,
1862         DWORD dwFlags, DWORD_PTR dwContext)
1863 {
1864     LPWININETAPPINFOW hIC = NULL;
1865     LPWININETHTTPREQW lpwhr;
1866     LPWSTR lpszCookies;
1867     LPWSTR lpszUrl = NULL;
1868     DWORD nCookieSize;
1869     HINTERNET handle = NULL;
1870     static const WCHAR szUrlForm[] = {'h','t','t','p',':','/','/','%','s',0};
1871     DWORD len;
1872     LPHTTPHEADERW Host;
1873
1874     TRACE("-->\n");
1875
1876     assert( lpwhs->hdr.htype == WH_HHTTPSESSION );
1877     hIC = lpwhs->lpAppInfo;
1878
1879     lpwhr = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sizeof(WININETHTTPREQW));
1880     if (NULL == lpwhr)
1881     {
1882         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
1883         goto lend;
1884     }
1885     lpwhr->hdr.htype = WH_HHTTPREQ;
1886     lpwhr->hdr.vtbl = &HTTPREQVtbl;
1887     lpwhr->hdr.dwFlags = dwFlags;
1888     lpwhr->hdr.dwContext = dwContext;
1889     lpwhr->hdr.refs = 1;
1890     lpwhr->hdr.lpfnStatusCB = lpwhs->hdr.lpfnStatusCB;
1891     lpwhr->hdr.dwInternalFlags = lpwhs->hdr.dwInternalFlags & INET_CALLBACKW;
1892
1893     WININET_AddRef( &lpwhs->hdr );
1894     lpwhr->lpHttpSession = lpwhs;
1895     list_add_head( &lpwhs->hdr.children, &lpwhr->hdr.entry );
1896
1897     handle = WININET_AllocHandle( &lpwhr->hdr );
1898     if (NULL == handle)
1899     {
1900         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
1901         goto lend;
1902     }
1903
1904     if (!NETCON_init(&lpwhr->netConnection, dwFlags & INTERNET_FLAG_SECURE))
1905     {
1906         InternetCloseHandle( handle );
1907         handle = NULL;
1908         goto lend;
1909     }
1910
1911     if (lpszObjectName && *lpszObjectName) {
1912         HRESULT rc;
1913
1914         len = 0;
1915         rc = UrlEscapeW(lpszObjectName, NULL, &len, URL_ESCAPE_SPACES_ONLY);
1916         if (rc != E_POINTER)
1917             len = strlenW(lpszObjectName)+1;
1918         lpwhr->lpszPath = HeapAlloc(GetProcessHeap(), 0, len*sizeof(WCHAR));
1919         rc = UrlEscapeW(lpszObjectName, lpwhr->lpszPath, &len,
1920                    URL_ESCAPE_SPACES_ONLY);
1921         if (rc)
1922         {
1923             ERR("Unable to escape string!(%s) (%d)\n",debugstr_w(lpszObjectName),rc);
1924             strcpyW(lpwhr->lpszPath,lpszObjectName);
1925         }
1926     }
1927
1928     if (lpszReferrer && *lpszReferrer)
1929         HTTP_ProcessHeader(lpwhr, HTTP_REFERER, lpszReferrer, HTTP_ADDREQ_FLAG_ADD | HTTP_ADDHDR_FLAG_REQ);
1930
1931     if (lpszAcceptTypes)
1932     {
1933         int i;
1934         for (i = 0; lpszAcceptTypes[i]; i++)
1935         {
1936             if (!*lpszAcceptTypes[i]) continue;
1937             HTTP_ProcessHeader(lpwhr, HTTP_ACCEPT, lpszAcceptTypes[i],
1938                                HTTP_ADDHDR_FLAG_COALESCE_WITH_COMMA |
1939                                HTTP_ADDHDR_FLAG_REQ |
1940                                (i == 0 ? HTTP_ADDHDR_FLAG_REPLACE : 0));
1941         }
1942     }
1943
1944     lpwhr->lpszVerb = WININET_strdupW(lpszVerb && *lpszVerb ? lpszVerb : szGET);
1945
1946     if (lpszVersion)
1947         lpwhr->lpszVersion = WININET_strdupW(lpszVersion);
1948     else
1949         lpwhr->lpszVersion = WININET_strdupW(g_szHttp1_1);
1950
1951     HTTP_ProcessHeader(lpwhr, szHost, lpwhs->lpszHostName, HTTP_ADDREQ_FLAG_ADD | HTTP_ADDHDR_FLAG_REQ);
1952
1953     if (lpwhs->nServerPort == INTERNET_INVALID_PORT_NUMBER)
1954         lpwhs->nServerPort = (dwFlags & INTERNET_FLAG_SECURE ?
1955                         INTERNET_DEFAULT_HTTPS_PORT :
1956                         INTERNET_DEFAULT_HTTP_PORT);
1957
1958     if (lpwhs->nHostPort == INTERNET_INVALID_PORT_NUMBER)
1959         lpwhs->nHostPort = (dwFlags & INTERNET_FLAG_SECURE ?
1960                         INTERNET_DEFAULT_HTTPS_PORT :
1961                         INTERNET_DEFAULT_HTTP_PORT);
1962
1963     if (NULL != hIC->lpszProxy && hIC->lpszProxy[0] != 0)
1964         HTTP_DealWithProxy( hIC, lpwhs, lpwhr );
1965
1966     Host = HTTP_GetHeader(lpwhr,szHost);
1967
1968     len = lstrlenW(Host->lpszValue) + strlenW(szUrlForm);
1969     lpszUrl = HeapAlloc(GetProcessHeap(), 0, len*sizeof(WCHAR));
1970     sprintfW( lpszUrl, szUrlForm, Host->lpszValue );
1971
1972     if (!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_COOKIES) &&
1973         InternetGetCookieW(lpszUrl, NULL, NULL, &nCookieSize))
1974     {
1975         int cnt = 0;
1976         static const WCHAR szCookie[] = {'C','o','o','k','i','e',':',' ',0};
1977         static const WCHAR szcrlf[] = {'\r','\n',0};
1978
1979         lpszCookies = HeapAlloc(GetProcessHeap(), 0, (nCookieSize + 1 + 8)*sizeof(WCHAR));
1980
1981         cnt += sprintfW(lpszCookies, szCookie);
1982         InternetGetCookieW(lpszUrl, NULL, lpszCookies + cnt, &nCookieSize);
1983         strcatW(lpszCookies, szcrlf);
1984
1985         HTTP_HttpAddRequestHeadersW(lpwhr, lpszCookies, strlenW(lpszCookies),
1986                                HTTP_ADDREQ_FLAG_ADD);
1987         HeapFree(GetProcessHeap(), 0, lpszCookies);
1988     }
1989     HeapFree(GetProcessHeap(), 0, lpszUrl);
1990
1991
1992     INTERNET_SendCallback(&lpwhs->hdr, dwContext,
1993                           INTERNET_STATUS_HANDLE_CREATED, &handle,
1994                           sizeof(handle));
1995
1996     /*
1997      * A STATUS_REQUEST_COMPLETE is NOT sent here as per my tests on windows
1998      */
1999
2000     if (!HTTP_ResolveName(lpwhr))
2001     {
2002         InternetCloseHandle( handle );
2003         handle = NULL;
2004     }
2005
2006 lend:
2007     if( lpwhr )
2008         WININET_Release( &lpwhr->hdr );
2009
2010     TRACE("<-- %p (%p)\n", handle, lpwhr);
2011     return handle;
2012 }
2013
2014 /* read any content returned by the server so that the connection can be
2015  * reused */
2016 static void HTTP_DrainContent(WININETHTTPREQW *req)
2017 {
2018     DWORD bytes_read;
2019
2020     if (!NETCON_connected(&req->netConnection)) return;
2021
2022     if (req->dwContentLength == -1)
2023         NETCON_close(&req->netConnection);
2024
2025     do
2026     {
2027         char buffer[2048];
2028         if (HTTP_Read(req, buffer, sizeof(buffer), &bytes_read, TRUE) != ERROR_SUCCESS)
2029             return;
2030     } while (bytes_read);
2031 }
2032
2033 static const WCHAR szAccept[] = { 'A','c','c','e','p','t',0 };
2034 static const WCHAR szAccept_Charset[] = { 'A','c','c','e','p','t','-','C','h','a','r','s','e','t', 0 };
2035 static const WCHAR szAccept_Encoding[] = { 'A','c','c','e','p','t','-','E','n','c','o','d','i','n','g',0 };
2036 static const WCHAR szAccept_Language[] = { 'A','c','c','e','p','t','-','L','a','n','g','u','a','g','e',0 };
2037 static const WCHAR szAccept_Ranges[] = { 'A','c','c','e','p','t','-','R','a','n','g','e','s',0 };
2038 static const WCHAR szAge[] = { 'A','g','e',0 };
2039 static const WCHAR szAllow[] = { 'A','l','l','o','w',0 };
2040 static const WCHAR szCache_Control[] = { 'C','a','c','h','e','-','C','o','n','t','r','o','l',0 };
2041 static const WCHAR szConnection[] = { 'C','o','n','n','e','c','t','i','o','n',0 };
2042 static const WCHAR szContent_Base[] = { 'C','o','n','t','e','n','t','-','B','a','s','e',0 };
2043 static const WCHAR szContent_Encoding[] = { 'C','o','n','t','e','n','t','-','E','n','c','o','d','i','n','g',0 };
2044 static const WCHAR szContent_ID[] = { 'C','o','n','t','e','n','t','-','I','D',0 };
2045 static const WCHAR szContent_Language[] = { 'C','o','n','t','e','n','t','-','L','a','n','g','u','a','g','e',0 };
2046 static const WCHAR szContent_Length[] = { 'C','o','n','t','e','n','t','-','L','e','n','g','t','h',0 };
2047 static const WCHAR szContent_Location[] = { 'C','o','n','t','e','n','t','-','L','o','c','a','t','i','o','n',0 };
2048 static const WCHAR szContent_MD5[] = { 'C','o','n','t','e','n','t','-','M','D','5',0 };
2049 static const WCHAR szContent_Range[] = { 'C','o','n','t','e','n','t','-','R','a','n','g','e',0 };
2050 static const WCHAR szContent_Transfer_Encoding[] = { 'C','o','n','t','e','n','t','-','T','r','a','n','s','f','e','r','-','E','n','c','o','d','i','n','g',0 };
2051 static const WCHAR szContent_Type[] = { 'C','o','n','t','e','n','t','-','T','y','p','e',0 };
2052 static const WCHAR szCookie[] = { 'C','o','o','k','i','e',0 };
2053 static const WCHAR szDate[] = { 'D','a','t','e',0 };
2054 static const WCHAR szFrom[] = { 'F','r','o','m',0 };
2055 static const WCHAR szETag[] = { 'E','T','a','g',0 };
2056 static const WCHAR szExpect[] = { 'E','x','p','e','c','t',0 };
2057 static const WCHAR szExpires[] = { 'E','x','p','i','r','e','s',0 };
2058 static const WCHAR szIf_Match[] = { 'I','f','-','M','a','t','c','h',0 };
2059 static const WCHAR szIf_Modified_Since[] = { 'I','f','-','M','o','d','i','f','i','e','d','-','S','i','n','c','e',0 };
2060 static const WCHAR szIf_None_Match[] = { 'I','f','-','N','o','n','e','-','M','a','t','c','h',0 };
2061 static const WCHAR szIf_Range[] = { 'I','f','-','R','a','n','g','e',0 };
2062 static const WCHAR szIf_Unmodified_Since[] = { 'I','f','-','U','n','m','o','d','i','f','i','e','d','-','S','i','n','c','e',0 };
2063 static const WCHAR szLast_Modified[] = { 'L','a','s','t','-','M','o','d','i','f','i','e','d',0 };
2064 static const WCHAR szLocation[] = { 'L','o','c','a','t','i','o','n',0 };
2065 static const WCHAR szMax_Forwards[] = { 'M','a','x','-','F','o','r','w','a','r','d','s',0 };
2066 static const WCHAR szMime_Version[] = { 'M','i','m','e','-','V','e','r','s','i','o','n',0 };
2067 static const WCHAR szPragma[] = { 'P','r','a','g','m','a',0 };
2068 static const WCHAR szProxy_Authenticate[] = { 'P','r','o','x','y','-','A','u','t','h','e','n','t','i','c','a','t','e',0 };
2069 static const WCHAR szProxy_Connection[] = { 'P','r','o','x','y','-','C','o','n','n','e','c','t','i','o','n',0 };
2070 static const WCHAR szPublic[] = { 'P','u','b','l','i','c',0 };
2071 static const WCHAR szRange[] = { 'R','a','n','g','e',0 };
2072 static const WCHAR szReferer[] = { 'R','e','f','e','r','e','r',0 };
2073 static const WCHAR szRetry_After[] = { 'R','e','t','r','y','-','A','f','t','e','r',0 };
2074 static const WCHAR szServer[] = { 'S','e','r','v','e','r',0 };
2075 static const WCHAR szSet_Cookie[] = { 'S','e','t','-','C','o','o','k','i','e',0 };
2076 static const WCHAR szTransfer_Encoding[] = { 'T','r','a','n','s','f','e','r','-','E','n','c','o','d','i','n','g',0 };
2077 static const WCHAR szUnless_Modified_Since[] = { 'U','n','l','e','s','s','-','M','o','d','i','f','i','e','d','-','S','i','n','c','e',0 };
2078 static const WCHAR szUpgrade[] = { 'U','p','g','r','a','d','e',0 };
2079 static const WCHAR szURI[] = { 'U','R','I',0 };
2080 static const WCHAR szUser_Agent[] = { 'U','s','e','r','-','A','g','e','n','t',0 };
2081 static const WCHAR szVary[] = { 'V','a','r','y',0 };
2082 static const WCHAR szVia[] = { 'V','i','a',0 };
2083 static const WCHAR szWarning[] = { 'W','a','r','n','i','n','g',0 };
2084 static const WCHAR szWWW_Authenticate[] = { 'W','W','W','-','A','u','t','h','e','n','t','i','c','a','t','e',0 };
2085
2086 static const LPCWSTR header_lookup[] = {
2087     szMime_Version,             /* HTTP_QUERY_MIME_VERSION = 0 */
2088     szContent_Type,             /* HTTP_QUERY_CONTENT_TYPE = 1 */
2089     szContent_Transfer_Encoding,/* HTTP_QUERY_CONTENT_TRANSFER_ENCODING = 2 */
2090     szContent_ID,               /* HTTP_QUERY_CONTENT_ID = 3 */
2091     NULL,                       /* HTTP_QUERY_CONTENT_DESCRIPTION = 4 */
2092     szContent_Length,           /* HTTP_QUERY_CONTENT_LENGTH =  5 */
2093     szContent_Language,         /* HTTP_QUERY_CONTENT_LANGUAGE =  6 */
2094     szAllow,                    /* HTTP_QUERY_ALLOW = 7 */
2095     szPublic,                   /* HTTP_QUERY_PUBLIC = 8 */
2096     szDate,                     /* HTTP_QUERY_DATE = 9 */
2097     szExpires,                  /* HTTP_QUERY_EXPIRES = 10 */
2098     szLast_Modified,            /* HTTP_QUERY_LAST_MODIFIED = 11 */
2099     NULL,                       /* HTTP_QUERY_MESSAGE_ID = 12 */
2100     szURI,                      /* HTTP_QUERY_URI = 13 */
2101     szFrom,                     /* HTTP_QUERY_DERIVED_FROM = 14 */
2102     NULL,                       /* HTTP_QUERY_COST = 15 */
2103     NULL,                       /* HTTP_QUERY_LINK = 16 */
2104     szPragma,                   /* HTTP_QUERY_PRAGMA = 17 */
2105     NULL,                       /* HTTP_QUERY_VERSION = 18 */
2106     szStatus,                   /* HTTP_QUERY_STATUS_CODE = 19 */
2107     NULL,                       /* HTTP_QUERY_STATUS_TEXT = 20 */
2108     NULL,                       /* HTTP_QUERY_RAW_HEADERS = 21 */
2109     NULL,                       /* HTTP_QUERY_RAW_HEADERS_CRLF = 22 */
2110     szConnection,               /* HTTP_QUERY_CONNECTION = 23 */
2111     szAccept,                   /* HTTP_QUERY_ACCEPT = 24 */
2112     szAccept_Charset,           /* HTTP_QUERY_ACCEPT_CHARSET = 25 */
2113     szAccept_Encoding,          /* HTTP_QUERY_ACCEPT_ENCODING = 26 */
2114     szAccept_Language,          /* HTTP_QUERY_ACCEPT_LANGUAGE = 27 */
2115     szAuthorization,            /* HTTP_QUERY_AUTHORIZATION = 28 */
2116     szContent_Encoding,         /* HTTP_QUERY_CONTENT_ENCODING = 29 */
2117     NULL,                       /* HTTP_QUERY_FORWARDED = 30 */
2118     NULL,                       /* HTTP_QUERY_FROM = 31 */
2119     szIf_Modified_Since,        /* HTTP_QUERY_IF_MODIFIED_SINCE = 32 */
2120     szLocation,                 /* HTTP_QUERY_LOCATION = 33 */
2121     NULL,                       /* HTTP_QUERY_ORIG_URI = 34 */
2122     szReferer,                  /* HTTP_QUERY_REFERER = 35 */
2123     szRetry_After,              /* HTTP_QUERY_RETRY_AFTER = 36 */
2124     szServer,                   /* HTTP_QUERY_SERVER = 37 */
2125     NULL,                       /* HTTP_TITLE = 38 */
2126     szUser_Agent,               /* HTTP_QUERY_USER_AGENT = 39 */
2127     szWWW_Authenticate,         /* HTTP_QUERY_WWW_AUTHENTICATE = 40 */
2128     szProxy_Authenticate,       /* HTTP_QUERY_PROXY_AUTHENTICATE = 41 */
2129     szAccept_Ranges,            /* HTTP_QUERY_ACCEPT_RANGES = 42 */
2130     szSet_Cookie,               /* HTTP_QUERY_SET_COOKIE = 43 */
2131     szCookie,                   /* HTTP_QUERY_COOKIE = 44 */
2132     NULL,                       /* HTTP_QUERY_REQUEST_METHOD = 45 */
2133     NULL,                       /* HTTP_QUERY_REFRESH = 46 */
2134     NULL,                       /* HTTP_QUERY_CONTENT_DISPOSITION = 47 */
2135     szAge,                      /* HTTP_QUERY_AGE = 48 */
2136     szCache_Control,            /* HTTP_QUERY_CACHE_CONTROL = 49 */
2137     szContent_Base,             /* HTTP_QUERY_CONTENT_BASE = 50 */
2138     szContent_Location,         /* HTTP_QUERY_CONTENT_LOCATION = 51 */
2139     szContent_MD5,              /* HTTP_QUERY_CONTENT_MD5 = 52 */
2140     szContent_Range,            /* HTTP_QUERY_CONTENT_RANGE = 53 */
2141     szETag,                     /* HTTP_QUERY_ETAG = 54 */
2142     szHost,                     /* HTTP_QUERY_HOST = 55 */
2143     szIf_Match,                 /* HTTP_QUERY_IF_MATCH = 56 */
2144     szIf_None_Match,            /* HTTP_QUERY_IF_NONE_MATCH = 57 */
2145     szIf_Range,                 /* HTTP_QUERY_IF_RANGE = 58 */
2146     szIf_Unmodified_Since,      /* HTTP_QUERY_IF_UNMODIFIED_SINCE = 59 */
2147     szMax_Forwards,             /* HTTP_QUERY_MAX_FORWARDS = 60 */
2148     szProxy_Authorization,      /* HTTP_QUERY_PROXY_AUTHORIZATION = 61 */
2149     szRange,                    /* HTTP_QUERY_RANGE = 62 */
2150     szTransfer_Encoding,        /* HTTP_QUERY_TRANSFER_ENCODING = 63 */
2151     szUpgrade,                  /* HTTP_QUERY_UPGRADE = 64 */
2152     szVary,                     /* HTTP_QUERY_VARY = 65 */
2153     szVia,                      /* HTTP_QUERY_VIA = 66 */
2154     szWarning,                  /* HTTP_QUERY_WARNING = 67 */
2155     szExpect,                   /* HTTP_QUERY_EXPECT = 68 */
2156     szProxy_Connection,         /* HTTP_QUERY_PROXY_CONNECTION = 69 */
2157     szUnless_Modified_Since,    /* HTTP_QUERY_UNLESS_MODIFIED_SINCE = 70 */
2158 };
2159
2160 #define LAST_TABLE_HEADER (sizeof(header_lookup)/sizeof(header_lookup[0]))
2161
2162 /***********************************************************************
2163  *           HTTP_HttpQueryInfoW (internal)
2164  */
2165 static BOOL WINAPI HTTP_HttpQueryInfoW( LPWININETHTTPREQW lpwhr, DWORD dwInfoLevel,
2166         LPVOID lpBuffer, LPDWORD lpdwBufferLength, LPDWORD lpdwIndex)
2167 {
2168     LPHTTPHEADERW lphttpHdr = NULL;
2169     BOOL bSuccess = FALSE;
2170     BOOL request_only = dwInfoLevel & HTTP_QUERY_FLAG_REQUEST_HEADERS;
2171     INT requested_index = lpdwIndex ? *lpdwIndex : 0;
2172     INT level = (dwInfoLevel & ~HTTP_QUERY_MODIFIER_FLAGS_MASK);
2173     INT index = -1;
2174
2175     /* Find requested header structure */
2176     switch (level)
2177     {
2178     case HTTP_QUERY_CUSTOM:
2179         index = HTTP_GetCustomHeaderIndex(lpwhr, lpBuffer, requested_index, request_only);
2180         break;
2181
2182     case HTTP_QUERY_RAW_HEADERS_CRLF:
2183         {
2184             LPWSTR headers;
2185             DWORD len;
2186             BOOL ret;
2187
2188             if (request_only)
2189                 headers = HTTP_BuildHeaderRequestString(lpwhr, lpwhr->lpszVerb, lpwhr->lpszPath, lpwhr->lpszVersion);
2190             else
2191                 headers = lpwhr->lpszRawHeaders;
2192
2193             len = strlenW(headers);
2194             if (len + 1 > *lpdwBufferLength/sizeof(WCHAR))
2195             {
2196                 *lpdwBufferLength = (len + 1) * sizeof(WCHAR);
2197                 INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2198                 ret = FALSE;
2199             } else
2200             {
2201                 memcpy(lpBuffer, headers, (len+1)*sizeof(WCHAR));
2202                 *lpdwBufferLength = len * sizeof(WCHAR);
2203
2204                 TRACE("returning data: %s\n", debugstr_wn((WCHAR*)lpBuffer, len));
2205                 ret = TRUE;
2206             }
2207
2208             if (request_only)
2209                 HeapFree(GetProcessHeap(), 0, headers);
2210             return ret;
2211         }
2212     case HTTP_QUERY_RAW_HEADERS:
2213         {
2214             static const WCHAR szCrLf[] = {'\r','\n',0};
2215             LPWSTR * ppszRawHeaderLines = HTTP_Tokenize(lpwhr->lpszRawHeaders, szCrLf);
2216             DWORD i, size = 0;
2217             LPWSTR pszString = (WCHAR*)lpBuffer;
2218
2219             for (i = 0; ppszRawHeaderLines[i]; i++)
2220                 size += strlenW(ppszRawHeaderLines[i]) + 1;
2221
2222             if (size + 1 > *lpdwBufferLength/sizeof(WCHAR))
2223             {
2224                 HTTP_FreeTokens(ppszRawHeaderLines);
2225                 *lpdwBufferLength = (size + 1) * sizeof(WCHAR);
2226                 INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2227                 return FALSE;
2228             }
2229
2230             for (i = 0; ppszRawHeaderLines[i]; i++)
2231             {
2232                 DWORD len = strlenW(ppszRawHeaderLines[i]);
2233                 memcpy(pszString, ppszRawHeaderLines[i], (len+1)*sizeof(WCHAR));
2234                 pszString += len+1;
2235             }
2236             *pszString = '\0';
2237
2238             TRACE("returning data: %s\n", debugstr_wn((WCHAR*)lpBuffer, size));
2239
2240             *lpdwBufferLength = size * sizeof(WCHAR);
2241             HTTP_FreeTokens(ppszRawHeaderLines);
2242
2243             return TRUE;
2244         }
2245     case HTTP_QUERY_STATUS_TEXT:
2246         if (lpwhr->lpszStatusText)
2247         {
2248             DWORD len = strlenW(lpwhr->lpszStatusText);
2249             if (len + 1 > *lpdwBufferLength/sizeof(WCHAR))
2250             {
2251                 *lpdwBufferLength = (len + 1) * sizeof(WCHAR);
2252                 INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2253                 return FALSE;
2254             }
2255             memcpy(lpBuffer, lpwhr->lpszStatusText, (len+1)*sizeof(WCHAR));
2256             *lpdwBufferLength = len * sizeof(WCHAR);
2257
2258             TRACE("returning data: %s\n", debugstr_wn((WCHAR*)lpBuffer, len));
2259
2260             return TRUE;
2261         }
2262         break;
2263     case HTTP_QUERY_VERSION:
2264         if (lpwhr->lpszVersion)
2265         {
2266             DWORD len = strlenW(lpwhr->lpszVersion);
2267             if (len + 1 > *lpdwBufferLength/sizeof(WCHAR))
2268             {
2269                 *lpdwBufferLength = (len + 1) * sizeof(WCHAR);
2270                 INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2271                 return FALSE;
2272             }
2273             memcpy(lpBuffer, lpwhr->lpszVersion, (len+1)*sizeof(WCHAR));
2274             *lpdwBufferLength = len * sizeof(WCHAR);
2275
2276             TRACE("returning data: %s\n", debugstr_wn((WCHAR*)lpBuffer, len));
2277
2278             return TRUE;
2279         }
2280         break;
2281     default:
2282         assert (LAST_TABLE_HEADER == (HTTP_QUERY_UNLESS_MODIFIED_SINCE + 1));
2283
2284         if (level >= 0 && level < LAST_TABLE_HEADER && header_lookup[level])
2285             index = HTTP_GetCustomHeaderIndex(lpwhr, header_lookup[level],
2286                                               requested_index,request_only);
2287     }
2288
2289     if (index >= 0)
2290         lphttpHdr = &lpwhr->pCustHeaders[index];
2291
2292     /* Ensure header satisfies requested attributes */
2293     if (!lphttpHdr ||
2294         ((dwInfoLevel & HTTP_QUERY_FLAG_REQUEST_HEADERS) &&
2295          (~lphttpHdr->wFlags & HDR_ISREQUEST)))
2296     {
2297         INTERNET_SetLastError(ERROR_HTTP_HEADER_NOT_FOUND);
2298         return bSuccess;
2299     }
2300
2301     if (lpdwIndex)
2302         (*lpdwIndex)++;
2303
2304     /* coalesce value to requested type */
2305     if (dwInfoLevel & HTTP_QUERY_FLAG_NUMBER)
2306     {
2307         *(int *)lpBuffer = atoiW(lphttpHdr->lpszValue);
2308         bSuccess = TRUE;
2309
2310         TRACE(" returning number : %d\n", *(int *)lpBuffer);
2311     }
2312     else if (dwInfoLevel & HTTP_QUERY_FLAG_SYSTEMTIME)
2313     {
2314         time_t tmpTime;
2315         struct tm tmpTM;
2316         SYSTEMTIME *STHook;
2317
2318         tmpTime = ConvertTimeString(lphttpHdr->lpszValue);
2319
2320         tmpTM = *gmtime(&tmpTime);
2321         STHook = (SYSTEMTIME *) lpBuffer;
2322         if(STHook==NULL)
2323             return bSuccess;
2324
2325         STHook->wDay = tmpTM.tm_mday;
2326         STHook->wHour = tmpTM.tm_hour;
2327         STHook->wMilliseconds = 0;
2328         STHook->wMinute = tmpTM.tm_min;
2329         STHook->wDayOfWeek = tmpTM.tm_wday;
2330         STHook->wMonth = tmpTM.tm_mon + 1;
2331         STHook->wSecond = tmpTM.tm_sec;
2332         STHook->wYear = tmpTM.tm_year;
2333         
2334         bSuccess = TRUE;
2335         
2336         TRACE(" returning time : %04d/%02d/%02d - %d - %02d:%02d:%02d.%02d\n", 
2337               STHook->wYear, STHook->wMonth, STHook->wDay, STHook->wDayOfWeek,
2338               STHook->wHour, STHook->wMinute, STHook->wSecond, STHook->wMilliseconds);
2339     }
2340     else if (lphttpHdr->lpszValue)
2341     {
2342         DWORD len = (strlenW(lphttpHdr->lpszValue) + 1) * sizeof(WCHAR);
2343
2344         if (len > *lpdwBufferLength)
2345         {
2346             *lpdwBufferLength = len;
2347             INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2348             return bSuccess;
2349         }
2350
2351         memcpy(lpBuffer, lphttpHdr->lpszValue, len);
2352         *lpdwBufferLength = len - sizeof(WCHAR);
2353         bSuccess = TRUE;
2354
2355         TRACE(" returning string : %s\n", debugstr_w(lpBuffer));
2356     }
2357     return bSuccess;
2358 }
2359
2360 /***********************************************************************
2361  *           HttpQueryInfoW (WININET.@)
2362  *
2363  * Queries for information about an HTTP request
2364  *
2365  * RETURNS
2366  *    TRUE  on success
2367  *    FALSE on failure
2368  *
2369  */
2370 BOOL WINAPI HttpQueryInfoW(HINTERNET hHttpRequest, DWORD dwInfoLevel,
2371         LPVOID lpBuffer, LPDWORD lpdwBufferLength, LPDWORD lpdwIndex)
2372 {
2373     BOOL bSuccess = FALSE;
2374     LPWININETHTTPREQW lpwhr;
2375
2376     if (TRACE_ON(wininet)) {
2377 #define FE(x) { x, #x }
2378         static const wininet_flag_info query_flags[] = {
2379             FE(HTTP_QUERY_MIME_VERSION),
2380             FE(HTTP_QUERY_CONTENT_TYPE),
2381             FE(HTTP_QUERY_CONTENT_TRANSFER_ENCODING),
2382             FE(HTTP_QUERY_CONTENT_ID),
2383             FE(HTTP_QUERY_CONTENT_DESCRIPTION),
2384             FE(HTTP_QUERY_CONTENT_LENGTH),
2385             FE(HTTP_QUERY_CONTENT_LANGUAGE),
2386             FE(HTTP_QUERY_ALLOW),
2387             FE(HTTP_QUERY_PUBLIC),
2388             FE(HTTP_QUERY_DATE),
2389             FE(HTTP_QUERY_EXPIRES),
2390             FE(HTTP_QUERY_LAST_MODIFIED),
2391             FE(HTTP_QUERY_MESSAGE_ID),
2392             FE(HTTP_QUERY_URI),
2393             FE(HTTP_QUERY_DERIVED_FROM),
2394             FE(HTTP_QUERY_COST),
2395             FE(HTTP_QUERY_LINK),
2396             FE(HTTP_QUERY_PRAGMA),
2397             FE(HTTP_QUERY_VERSION),
2398             FE(HTTP_QUERY_STATUS_CODE),
2399             FE(HTTP_QUERY_STATUS_TEXT),
2400             FE(HTTP_QUERY_RAW_HEADERS),
2401             FE(HTTP_QUERY_RAW_HEADERS_CRLF),
2402             FE(HTTP_QUERY_CONNECTION),
2403             FE(HTTP_QUERY_ACCEPT),
2404             FE(HTTP_QUERY_ACCEPT_CHARSET),
2405             FE(HTTP_QUERY_ACCEPT_ENCODING),
2406             FE(HTTP_QUERY_ACCEPT_LANGUAGE),
2407             FE(HTTP_QUERY_AUTHORIZATION),
2408             FE(HTTP_QUERY_CONTENT_ENCODING),
2409             FE(HTTP_QUERY_FORWARDED),
2410             FE(HTTP_QUERY_FROM),
2411             FE(HTTP_QUERY_IF_MODIFIED_SINCE),
2412             FE(HTTP_QUERY_LOCATION),
2413             FE(HTTP_QUERY_ORIG_URI),
2414             FE(HTTP_QUERY_REFERER),
2415             FE(HTTP_QUERY_RETRY_AFTER),
2416             FE(HTTP_QUERY_SERVER),
2417             FE(HTTP_QUERY_TITLE),
2418             FE(HTTP_QUERY_USER_AGENT),
2419             FE(HTTP_QUERY_WWW_AUTHENTICATE),
2420             FE(HTTP_QUERY_PROXY_AUTHENTICATE),
2421             FE(HTTP_QUERY_ACCEPT_RANGES),
2422         FE(HTTP_QUERY_SET_COOKIE),
2423         FE(HTTP_QUERY_COOKIE),
2424             FE(HTTP_QUERY_REQUEST_METHOD),
2425             FE(HTTP_QUERY_REFRESH),
2426             FE(HTTP_QUERY_CONTENT_DISPOSITION),
2427             FE(HTTP_QUERY_AGE),
2428             FE(HTTP_QUERY_CACHE_CONTROL),
2429             FE(HTTP_QUERY_CONTENT_BASE),
2430             FE(HTTP_QUERY_CONTENT_LOCATION),
2431             FE(HTTP_QUERY_CONTENT_MD5),
2432             FE(HTTP_QUERY_CONTENT_RANGE),
2433             FE(HTTP_QUERY_ETAG),
2434             FE(HTTP_QUERY_HOST),
2435             FE(HTTP_QUERY_IF_MATCH),
2436             FE(HTTP_QUERY_IF_NONE_MATCH),
2437             FE(HTTP_QUERY_IF_RANGE),
2438             FE(HTTP_QUERY_IF_UNMODIFIED_SINCE),
2439             FE(HTTP_QUERY_MAX_FORWARDS),
2440             FE(HTTP_QUERY_PROXY_AUTHORIZATION),
2441             FE(HTTP_QUERY_RANGE),
2442             FE(HTTP_QUERY_TRANSFER_ENCODING),
2443             FE(HTTP_QUERY_UPGRADE),
2444             FE(HTTP_QUERY_VARY),
2445             FE(HTTP_QUERY_VIA),
2446             FE(HTTP_QUERY_WARNING),
2447             FE(HTTP_QUERY_CUSTOM)
2448         };
2449         static const wininet_flag_info modifier_flags[] = {
2450             FE(HTTP_QUERY_FLAG_REQUEST_HEADERS),
2451             FE(HTTP_QUERY_FLAG_SYSTEMTIME),
2452             FE(HTTP_QUERY_FLAG_NUMBER),
2453             FE(HTTP_QUERY_FLAG_COALESCE)
2454         };
2455 #undef FE
2456         DWORD info_mod = dwInfoLevel & HTTP_QUERY_MODIFIER_FLAGS_MASK;
2457         DWORD info = dwInfoLevel & HTTP_QUERY_HEADER_MASK;
2458         DWORD i;
2459
2460         TRACE("(%p, 0x%08x)--> %d\n", hHttpRequest, dwInfoLevel, dwInfoLevel);
2461         TRACE("  Attribute:");
2462         for (i = 0; i < (sizeof(query_flags) / sizeof(query_flags[0])); i++) {
2463             if (query_flags[i].val == info) {
2464                 TRACE(" %s", query_flags[i].name);
2465                 break;
2466             }
2467         }
2468         if (i == (sizeof(query_flags) / sizeof(query_flags[0]))) {
2469             TRACE(" Unknown (%08x)", info);
2470         }
2471
2472         TRACE(" Modifier:");
2473         for (i = 0; i < (sizeof(modifier_flags) / sizeof(modifier_flags[0])); i++) {
2474             if (modifier_flags[i].val & info_mod) {
2475                 TRACE(" %s", modifier_flags[i].name);
2476                 info_mod &= ~ modifier_flags[i].val;
2477             }
2478         }
2479         
2480         if (info_mod) {
2481             TRACE(" Unknown (%08x)", info_mod);
2482         }
2483         TRACE("\n");
2484     }
2485     
2486     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hHttpRequest );
2487     if (NULL == lpwhr ||  lpwhr->hdr.htype != WH_HHTTPREQ)
2488     {
2489         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2490         goto lend;
2491     }
2492
2493     if (lpBuffer == NULL)
2494         *lpdwBufferLength = 0;
2495     bSuccess = HTTP_HttpQueryInfoW( lpwhr, dwInfoLevel,
2496                                     lpBuffer, lpdwBufferLength, lpdwIndex);
2497
2498 lend:
2499     if( lpwhr )
2500          WININET_Release( &lpwhr->hdr );
2501
2502     TRACE("%d <--\n", bSuccess);
2503     return bSuccess;
2504 }
2505
2506 /***********************************************************************
2507  *           HttpQueryInfoA (WININET.@)
2508  *
2509  * Queries for information about an HTTP request
2510  *
2511  * RETURNS
2512  *    TRUE  on success
2513  *    FALSE on failure
2514  *
2515  */
2516 BOOL WINAPI HttpQueryInfoA(HINTERNET hHttpRequest, DWORD dwInfoLevel,
2517         LPVOID lpBuffer, LPDWORD lpdwBufferLength, LPDWORD lpdwIndex)
2518 {
2519     BOOL result;
2520     DWORD len;
2521     WCHAR* bufferW;
2522
2523     if((dwInfoLevel & HTTP_QUERY_FLAG_NUMBER) ||
2524        (dwInfoLevel & HTTP_QUERY_FLAG_SYSTEMTIME))
2525     {
2526         return HttpQueryInfoW( hHttpRequest, dwInfoLevel, lpBuffer,
2527                                lpdwBufferLength, lpdwIndex );
2528     }
2529
2530     if (lpBuffer)
2531     {
2532         DWORD alloclen;
2533         len = (*lpdwBufferLength)*sizeof(WCHAR);
2534         if ((dwInfoLevel & HTTP_QUERY_HEADER_MASK) == HTTP_QUERY_CUSTOM)
2535         {
2536             alloclen = MultiByteToWideChar( CP_ACP, 0, lpBuffer, -1, NULL, 0 ) * sizeof(WCHAR);
2537             if (alloclen < len)
2538                 alloclen = len;
2539         }
2540         else
2541             alloclen = len;
2542         bufferW = HeapAlloc( GetProcessHeap(), 0, alloclen );
2543         /* buffer is in/out because of HTTP_QUERY_CUSTOM */
2544         if ((dwInfoLevel & HTTP_QUERY_HEADER_MASK) == HTTP_QUERY_CUSTOM)
2545             MultiByteToWideChar( CP_ACP, 0, lpBuffer, -1, bufferW, alloclen / sizeof(WCHAR) );
2546     } else
2547     {
2548         bufferW = NULL;
2549         len = 0;
2550     }
2551
2552     result = HttpQueryInfoW( hHttpRequest, dwInfoLevel, bufferW,
2553                            &len, lpdwIndex );
2554     if( result )
2555     {
2556         len = WideCharToMultiByte( CP_ACP,0, bufferW, len / sizeof(WCHAR) + 1,
2557                                      lpBuffer, *lpdwBufferLength, NULL, NULL );
2558         *lpdwBufferLength = len - 1;
2559
2560         TRACE("lpBuffer: %s\n", debugstr_a(lpBuffer));
2561     }
2562     else
2563         /* since the strings being returned from HttpQueryInfoW should be
2564          * only ASCII characters, it is reasonable to assume that all of
2565          * the Unicode characters can be reduced to a single byte */
2566         *lpdwBufferLength = len / sizeof(WCHAR);
2567
2568     HeapFree(GetProcessHeap(), 0, bufferW );
2569
2570     return result;
2571 }
2572
2573 /***********************************************************************
2574  *           HttpSendRequestExA (WININET.@)
2575  *
2576  * Sends the specified request to the HTTP server and allows chunked
2577  * transfers.
2578  *
2579  * RETURNS
2580  *  Success: TRUE
2581  *  Failure: FALSE, call GetLastError() for more information.
2582  */
2583 BOOL WINAPI HttpSendRequestExA(HINTERNET hRequest,
2584                                LPINTERNET_BUFFERSA lpBuffersIn,
2585                                LPINTERNET_BUFFERSA lpBuffersOut,
2586                                DWORD dwFlags, DWORD_PTR dwContext)
2587 {
2588     INTERNET_BUFFERSW BuffersInW;
2589     BOOL rc = FALSE;
2590     DWORD headerlen;
2591     LPWSTR header = NULL;
2592
2593     TRACE("(%p, %p, %p, %08x, %08lx)\n", hRequest, lpBuffersIn,
2594             lpBuffersOut, dwFlags, dwContext);
2595
2596     if (lpBuffersIn)
2597     {
2598         BuffersInW.dwStructSize = sizeof(LPINTERNET_BUFFERSW);
2599         if (lpBuffersIn->lpcszHeader)
2600         {
2601             headerlen = MultiByteToWideChar(CP_ACP,0,lpBuffersIn->lpcszHeader,
2602                     lpBuffersIn->dwHeadersLength,0,0);
2603             header = HeapAlloc(GetProcessHeap(),0,headerlen*sizeof(WCHAR));
2604             if (!(BuffersInW.lpcszHeader = header))
2605             {
2606                 INTERNET_SetLastError(ERROR_OUTOFMEMORY);
2607                 return FALSE;
2608             }
2609             BuffersInW.dwHeadersLength = MultiByteToWideChar(CP_ACP, 0,
2610                     lpBuffersIn->lpcszHeader, lpBuffersIn->dwHeadersLength,
2611                     header, headerlen);
2612         }
2613         else
2614             BuffersInW.lpcszHeader = NULL;
2615         BuffersInW.dwHeadersTotal = lpBuffersIn->dwHeadersTotal;
2616         BuffersInW.lpvBuffer = lpBuffersIn->lpvBuffer;
2617         BuffersInW.dwBufferLength = lpBuffersIn->dwBufferLength;
2618         BuffersInW.dwBufferTotal = lpBuffersIn->dwBufferTotal;
2619         BuffersInW.Next = NULL;
2620     }
2621
2622     rc = HttpSendRequestExW(hRequest, lpBuffersIn ? &BuffersInW : NULL, NULL, dwFlags, dwContext);
2623
2624     HeapFree(GetProcessHeap(),0,header);
2625
2626     return rc;
2627 }
2628
2629 /***********************************************************************
2630  *           HttpSendRequestExW (WININET.@)
2631  *
2632  * Sends the specified request to the HTTP server and allows chunked
2633  * transfers
2634  *
2635  * RETURNS
2636  *  Success: TRUE
2637  *  Failure: FALSE, call GetLastError() for more information.
2638  */
2639 BOOL WINAPI HttpSendRequestExW(HINTERNET hRequest,
2640                    LPINTERNET_BUFFERSW lpBuffersIn,
2641                    LPINTERNET_BUFFERSW lpBuffersOut,
2642                    DWORD dwFlags, DWORD_PTR dwContext)
2643 {
2644     BOOL ret = FALSE;
2645     LPWININETHTTPREQW lpwhr;
2646     LPWININETHTTPSESSIONW lpwhs;
2647     LPWININETAPPINFOW hIC;
2648
2649     TRACE("(%p, %p, %p, %08x, %08lx)\n", hRequest, lpBuffersIn,
2650             lpBuffersOut, dwFlags, dwContext);
2651
2652     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hRequest );
2653
2654     if (NULL == lpwhr || lpwhr->hdr.htype != WH_HHTTPREQ)
2655     {
2656         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2657         goto lend;
2658     }
2659
2660     lpwhs = lpwhr->lpHttpSession;
2661     assert(lpwhs->hdr.htype == WH_HHTTPSESSION);
2662     hIC = lpwhs->lpAppInfo;
2663     assert(hIC->hdr.htype == WH_HINIT);
2664
2665     if (hIC->hdr.dwFlags & INTERNET_FLAG_ASYNC)
2666     {
2667         WORKREQUEST workRequest;
2668         struct WORKREQ_HTTPSENDREQUESTW *req;
2669
2670         workRequest.asyncproc = AsyncHttpSendRequestProc;
2671         workRequest.hdr = WININET_AddRef( &lpwhr->hdr );
2672         req = &workRequest.u.HttpSendRequestW;
2673         if (lpBuffersIn)
2674         {
2675             if (lpBuffersIn->lpcszHeader)
2676                 /* FIXME: this should use dwHeadersLength or may not be necessary at all */
2677                 req->lpszHeader = WININET_strdupW(lpBuffersIn->lpcszHeader);
2678             else
2679                 req->lpszHeader = NULL;
2680             req->dwHeaderLength = lpBuffersIn->dwHeadersLength;
2681             req->lpOptional = lpBuffersIn->lpvBuffer;
2682             req->dwOptionalLength = lpBuffersIn->dwBufferLength;
2683             req->dwContentLength = lpBuffersIn->dwBufferTotal;
2684         }
2685         else
2686         {
2687             req->lpszHeader = NULL;
2688             req->dwHeaderLength = 0;
2689             req->lpOptional = NULL;
2690             req->dwOptionalLength = 0;
2691             req->dwContentLength = 0;
2692         }
2693
2694         req->bEndRequest = FALSE;
2695
2696         INTERNET_AsyncCall(&workRequest);
2697         /*
2698          * This is from windows.
2699          */
2700         INTERNET_SetLastError(ERROR_IO_PENDING);
2701     }
2702     else
2703     {
2704         if (lpBuffersIn)
2705             ret = HTTP_HttpSendRequestW(lpwhr, lpBuffersIn->lpcszHeader, lpBuffersIn->dwHeadersLength,
2706                                         lpBuffersIn->lpvBuffer, lpBuffersIn->dwBufferLength,
2707                                         lpBuffersIn->dwBufferTotal, FALSE);
2708         else
2709             ret = HTTP_HttpSendRequestW(lpwhr, NULL, 0, NULL, 0, 0, FALSE);
2710     }
2711
2712 lend:
2713     if ( lpwhr )
2714         WININET_Release( &lpwhr->hdr );
2715
2716     TRACE("<---\n");
2717     return ret;
2718 }
2719
2720 /***********************************************************************
2721  *           HttpSendRequestW (WININET.@)
2722  *
2723  * Sends the specified request to the HTTP server
2724  *
2725  * RETURNS
2726  *    TRUE  on success
2727  *    FALSE on failure
2728  *
2729  */
2730 BOOL WINAPI HttpSendRequestW(HINTERNET hHttpRequest, LPCWSTR lpszHeaders,
2731         DWORD dwHeaderLength, LPVOID lpOptional ,DWORD dwOptionalLength)
2732 {
2733     LPWININETHTTPREQW lpwhr;
2734     LPWININETHTTPSESSIONW lpwhs = NULL;
2735     LPWININETAPPINFOW hIC = NULL;
2736     BOOL r;
2737
2738     TRACE("%p, %s, %i, %p, %i)\n", hHttpRequest,
2739             debugstr_wn(lpszHeaders, dwHeaderLength), dwHeaderLength, lpOptional, dwOptionalLength);
2740
2741     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hHttpRequest );
2742     if (NULL == lpwhr || lpwhr->hdr.htype != WH_HHTTPREQ)
2743     {
2744         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2745         r = FALSE;
2746         goto lend;
2747     }
2748
2749     lpwhs = lpwhr->lpHttpSession;
2750     if (NULL == lpwhs ||  lpwhs->hdr.htype != WH_HHTTPSESSION)
2751     {
2752         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2753         r = FALSE;
2754         goto lend;
2755     }
2756
2757     hIC = lpwhs->lpAppInfo;
2758     if (NULL == hIC ||  hIC->hdr.htype != WH_HINIT)
2759     {
2760         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2761         r = FALSE;
2762         goto lend;
2763     }
2764
2765     if (hIC->hdr.dwFlags & INTERNET_FLAG_ASYNC)
2766     {
2767         WORKREQUEST workRequest;
2768         struct WORKREQ_HTTPSENDREQUESTW *req;
2769
2770         workRequest.asyncproc = AsyncHttpSendRequestProc;
2771         workRequest.hdr = WININET_AddRef( &lpwhr->hdr );
2772         req = &workRequest.u.HttpSendRequestW;
2773         if (lpszHeaders)
2774         {
2775             req->lpszHeader = HeapAlloc(GetProcessHeap(), 0, dwHeaderLength * sizeof(WCHAR));
2776             memcpy(req->lpszHeader, lpszHeaders, dwHeaderLength * sizeof(WCHAR));
2777         }
2778         else
2779             req->lpszHeader = 0;
2780         req->dwHeaderLength = dwHeaderLength;
2781         req->lpOptional = lpOptional;
2782         req->dwOptionalLength = dwOptionalLength;
2783         req->dwContentLength = dwOptionalLength;
2784         req->bEndRequest = TRUE;
2785
2786         INTERNET_AsyncCall(&workRequest);
2787         /*
2788          * This is from windows.
2789          */
2790         INTERNET_SetLastError(ERROR_IO_PENDING);
2791         r = FALSE;
2792     }
2793     else
2794     {
2795         r = HTTP_HttpSendRequestW(lpwhr, lpszHeaders,
2796                 dwHeaderLength, lpOptional, dwOptionalLength,
2797                 dwOptionalLength, TRUE);
2798     }
2799 lend:
2800     if( lpwhr )
2801         WININET_Release( &lpwhr->hdr );
2802     return r;
2803 }
2804
2805 /***********************************************************************
2806  *           HttpSendRequestA (WININET.@)
2807  *
2808  * Sends the specified request to the HTTP server
2809  *
2810  * RETURNS
2811  *    TRUE  on success
2812  *    FALSE on failure
2813  *
2814  */
2815 BOOL WINAPI HttpSendRequestA(HINTERNET hHttpRequest, LPCSTR lpszHeaders,
2816         DWORD dwHeaderLength, LPVOID lpOptional ,DWORD dwOptionalLength)
2817 {
2818     BOOL result;
2819     LPWSTR szHeaders=NULL;
2820     DWORD nLen=dwHeaderLength;
2821     if(lpszHeaders!=NULL)
2822     {
2823         nLen=MultiByteToWideChar(CP_ACP,0,lpszHeaders,dwHeaderLength,NULL,0);
2824         szHeaders=HeapAlloc(GetProcessHeap(),0,nLen*sizeof(WCHAR));
2825         MultiByteToWideChar(CP_ACP,0,lpszHeaders,dwHeaderLength,szHeaders,nLen);
2826     }
2827     result=HttpSendRequestW(hHttpRequest, szHeaders, nLen, lpOptional, dwOptionalLength);
2828     HeapFree(GetProcessHeap(),0,szHeaders);
2829     return result;
2830 }
2831
2832 static BOOL HTTP_GetRequestURL(WININETHTTPREQW *req, LPWSTR buf)
2833 {
2834     LPHTTPHEADERW host_header;
2835
2836     static const WCHAR formatW[] = {'h','t','t','p',':','/','/','%','s','%','s',0};
2837
2838     host_header = HTTP_GetHeader(req, szHost);
2839     if(!host_header)
2840         return FALSE;
2841
2842     sprintfW(buf, formatW, host_header->lpszValue, req->lpszPath); /* FIXME */
2843     return TRUE;
2844 }
2845
2846 /***********************************************************************
2847  *           HTTP_HandleRedirect (internal)
2848  */
2849 static BOOL HTTP_HandleRedirect(LPWININETHTTPREQW lpwhr, LPCWSTR lpszUrl)
2850 {
2851     static const WCHAR szContentType[] = {'C','o','n','t','e','n','t','-','T','y','p','e',0};
2852     static const WCHAR szContentLength[] = {'C','o','n','t','e','n','t','-','L','e','n','g','t','h',0};
2853     LPWININETHTTPSESSIONW lpwhs = lpwhr->lpHttpSession;
2854     LPWININETAPPINFOW hIC = lpwhs->lpAppInfo;
2855     BOOL using_proxy = hIC->lpszProxy && hIC->lpszProxy[0];
2856     WCHAR path[INTERNET_MAX_URL_LENGTH];
2857     int index;
2858
2859     if(lpszUrl[0]=='/')
2860     {
2861         /* if it's an absolute path, keep the same session info */
2862         lstrcpynW(path, lpszUrl, INTERNET_MAX_URL_LENGTH);
2863     }
2864     else
2865     {
2866         URL_COMPONENTSW urlComponents;
2867         WCHAR protocol[32], hostName[MAXHOSTNAME], userName[1024];
2868         static WCHAR szHttp[] = {'h','t','t','p',0};
2869         static WCHAR szHttps[] = {'h','t','t','p','s',0};
2870         DWORD url_length = 0;
2871         LPWSTR orig_url;
2872         LPWSTR combined_url;
2873
2874         urlComponents.dwStructSize = sizeof(URL_COMPONENTSW);
2875         urlComponents.lpszScheme = (lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE) ? szHttps : szHttp;
2876         urlComponents.dwSchemeLength = 0;
2877         urlComponents.lpszHostName = lpwhs->lpszHostName;
2878         urlComponents.dwHostNameLength = 0;
2879         urlComponents.nPort = lpwhs->nHostPort;
2880         urlComponents.lpszUserName = lpwhs->lpszUserName;
2881         urlComponents.dwUserNameLength = 0;
2882         urlComponents.lpszPassword = NULL;
2883         urlComponents.dwPasswordLength = 0;
2884         urlComponents.lpszUrlPath = lpwhr->lpszPath;
2885         urlComponents.dwUrlPathLength = 0;
2886         urlComponents.lpszExtraInfo = NULL;
2887         urlComponents.dwExtraInfoLength = 0;
2888
2889         if (!InternetCreateUrlW(&urlComponents, 0, NULL, &url_length) &&
2890             (GetLastError() != ERROR_INSUFFICIENT_BUFFER))
2891             return FALSE;
2892
2893         orig_url = HeapAlloc(GetProcessHeap(), 0, url_length);
2894
2895         /* convert from bytes to characters */
2896         url_length = url_length / sizeof(WCHAR) - 1;
2897         if (!InternetCreateUrlW(&urlComponents, 0, orig_url, &url_length))
2898         {
2899             HeapFree(GetProcessHeap(), 0, orig_url);
2900             return FALSE;
2901         }
2902
2903         url_length = 0;
2904         if (!InternetCombineUrlW(orig_url, lpszUrl, NULL, &url_length, ICU_ENCODE_SPACES_ONLY) &&
2905             (GetLastError() != ERROR_INSUFFICIENT_BUFFER))
2906         {
2907             HeapFree(GetProcessHeap(), 0, orig_url);
2908             return FALSE;
2909         }
2910         combined_url = HeapAlloc(GetProcessHeap(), 0, url_length * sizeof(WCHAR));
2911
2912         if (!InternetCombineUrlW(orig_url, lpszUrl, combined_url, &url_length, ICU_ENCODE_SPACES_ONLY))
2913         {
2914             HeapFree(GetProcessHeap(), 0, orig_url);
2915             HeapFree(GetProcessHeap(), 0, combined_url);
2916             return FALSE;
2917         }
2918         HeapFree(GetProcessHeap(), 0, orig_url);
2919
2920         userName[0] = 0;
2921         hostName[0] = 0;
2922         protocol[0] = 0;
2923
2924         urlComponents.dwStructSize = sizeof(URL_COMPONENTSW);
2925         urlComponents.lpszScheme = protocol;
2926         urlComponents.dwSchemeLength = 32;
2927         urlComponents.lpszHostName = hostName;
2928         urlComponents.dwHostNameLength = MAXHOSTNAME;
2929         urlComponents.lpszUserName = userName;
2930         urlComponents.dwUserNameLength = 1024;
2931         urlComponents.lpszPassword = NULL;
2932         urlComponents.dwPasswordLength = 0;
2933         urlComponents.lpszUrlPath = path;
2934         urlComponents.dwUrlPathLength = 2048;
2935         urlComponents.lpszExtraInfo = NULL;
2936         urlComponents.dwExtraInfoLength = 0;
2937         if(!InternetCrackUrlW(combined_url, strlenW(combined_url), 0, &urlComponents))
2938         {
2939             HeapFree(GetProcessHeap(), 0, combined_url);
2940             return FALSE;
2941         }
2942
2943         HeapFree(GetProcessHeap(), 0, combined_url);
2944
2945         if (!strncmpW(szHttp, urlComponents.lpszScheme, strlenW(szHttp)) &&
2946             (lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE))
2947         {
2948             TRACE("redirect from secure page to non-secure page\n");
2949             /* FIXME: warn about from secure redirect to non-secure page */
2950             lpwhr->hdr.dwFlags &= ~INTERNET_FLAG_SECURE;
2951         }
2952         if (!strncmpW(szHttps, urlComponents.lpszScheme, strlenW(szHttps)) &&
2953             !(lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE))
2954         {
2955             TRACE("redirect from non-secure page to secure page\n");
2956             /* FIXME: notify about redirect to secure page */
2957             lpwhr->hdr.dwFlags |= INTERNET_FLAG_SECURE;
2958         }
2959
2960         if (urlComponents.nPort == INTERNET_INVALID_PORT_NUMBER)
2961         {
2962             if (lstrlenW(protocol)>4) /*https*/
2963                 urlComponents.nPort = INTERNET_DEFAULT_HTTPS_PORT;
2964             else /*http*/
2965                 urlComponents.nPort = INTERNET_DEFAULT_HTTP_PORT;
2966         }
2967
2968 #if 0
2969         /*
2970          * This upsets redirects to binary files on sourceforge.net 
2971          * and gives an html page instead of the target file
2972          * Examination of the HTTP request sent by native wininet.dll
2973          * reveals that it doesn't send a referrer in that case.
2974          * Maybe there's a flag that enables this, or maybe a referrer
2975          * shouldn't be added in case of a redirect.
2976          */
2977
2978         /* consider the current host as the referrer */
2979         if (lpwhs->lpszServerName && *lpwhs->lpszServerName)
2980             HTTP_ProcessHeader(lpwhr, HTTP_REFERER, lpwhs->lpszServerName,
2981                            HTTP_ADDHDR_FLAG_REQ|HTTP_ADDREQ_FLAG_REPLACE|
2982                            HTTP_ADDHDR_FLAG_ADD_IF_NEW);
2983 #endif
2984         
2985         HeapFree(GetProcessHeap(), 0, lpwhs->lpszHostName);
2986         if (urlComponents.nPort != INTERNET_DEFAULT_HTTP_PORT &&
2987             urlComponents.nPort != INTERNET_DEFAULT_HTTPS_PORT)
2988         {
2989             int len;
2990             static const WCHAR fmt[] = {'%','s',':','%','i',0};
2991             len = lstrlenW(hostName);
2992             len += 7; /* 5 for strlen("65535") + 1 for ":" + 1 for '\0' */
2993             lpwhs->lpszHostName = HeapAlloc(GetProcessHeap(), 0, len*sizeof(WCHAR));
2994             sprintfW(lpwhs->lpszHostName, fmt, hostName, urlComponents.nPort);
2995         }
2996         else
2997             lpwhs->lpszHostName = WININET_strdupW(hostName);
2998
2999         HTTP_ProcessHeader(lpwhr, szHost, lpwhs->lpszHostName, HTTP_ADDREQ_FLAG_ADD | HTTP_ADDREQ_FLAG_REPLACE | HTTP_ADDHDR_FLAG_REQ);
3000
3001         HeapFree(GetProcessHeap(), 0, lpwhs->lpszUserName);
3002         lpwhs->lpszUserName = NULL;
3003         if (userName[0])
3004             lpwhs->lpszUserName = WININET_strdupW(userName);
3005
3006         if (!using_proxy)
3007         {
3008             HeapFree(GetProcessHeap(), 0, lpwhs->lpszServerName);
3009             lpwhs->lpszServerName = WININET_strdupW(hostName);
3010             lpwhs->nServerPort = urlComponents.nPort;
3011
3012             if (!HTTP_ResolveName(lpwhr))
3013                 return FALSE;
3014
3015             NETCON_close(&lpwhr->netConnection);
3016
3017             if (!NETCON_init(&lpwhr->netConnection,lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE))
3018                 return FALSE;
3019         }
3020         else
3021             TRACE("Redirect through proxy\n");
3022     }
3023
3024     HeapFree(GetProcessHeap(), 0, lpwhr->lpszPath);
3025     lpwhr->lpszPath=NULL;
3026     if (*path)
3027     {
3028         DWORD needed = 0;
3029         HRESULT rc;
3030
3031         rc = UrlEscapeW(path, NULL, &needed, URL_ESCAPE_SPACES_ONLY);
3032         if (rc != E_POINTER)
3033             needed = strlenW(path)+1;
3034         lpwhr->lpszPath = HeapAlloc(GetProcessHeap(), 0, needed*sizeof(WCHAR));
3035         rc = UrlEscapeW(path, lpwhr->lpszPath, &needed,
3036                         URL_ESCAPE_SPACES_ONLY);
3037         if (rc)
3038         {
3039             ERR("Unable to escape string!(%s) (%d)\n",debugstr_w(path),rc);
3040             strcpyW(lpwhr->lpszPath,path);
3041         }
3042     }
3043
3044     /* Remove custom content-type/length headers on redirects.  */
3045     index = HTTP_GetCustomHeaderIndex(lpwhr, szContentType, 0, TRUE);
3046     if (0 <= index)
3047         HTTP_DeleteCustomHeader(lpwhr, index);
3048     index = HTTP_GetCustomHeaderIndex(lpwhr, szContentLength, 0, TRUE);
3049     if (0 <= index)
3050         HTTP_DeleteCustomHeader(lpwhr, index);
3051
3052     return TRUE;
3053 }
3054
3055 /***********************************************************************
3056  *           HTTP_build_req (internal)
3057  *
3058  *  concatenate all the strings in the request together
3059  */
3060 static LPWSTR HTTP_build_req( LPCWSTR *list, int len )
3061 {
3062     LPCWSTR *t;
3063     LPWSTR str;
3064
3065     for( t = list; *t ; t++  )
3066         len += strlenW( *t );
3067     len++;
3068
3069     str = HeapAlloc( GetProcessHeap(), 0, len*sizeof(WCHAR) );
3070     *str = 0;
3071
3072     for( t = list; *t ; t++ )
3073         strcatW( str, *t );
3074
3075     return str;
3076 }
3077
3078 static BOOL HTTP_SecureProxyConnect(LPWININETHTTPREQW lpwhr)
3079 {
3080     LPWSTR lpszPath;
3081     LPWSTR requestString;
3082     INT len;
3083     INT cnt;
3084     INT responseLen;
3085     char *ascii_req;
3086     BOOL ret;
3087     static const WCHAR szConnect[] = {'C','O','N','N','E','C','T',0};
3088     static const WCHAR szFormat[] = {'%','s',':','%','d',0};
3089     LPWININETHTTPSESSIONW lpwhs = lpwhr->lpHttpSession;
3090
3091     TRACE("\n");
3092
3093     lpszPath = HeapAlloc( GetProcessHeap(), 0, (lstrlenW( lpwhs->lpszHostName ) + 13)*sizeof(WCHAR) );
3094     sprintfW( lpszPath, szFormat, lpwhs->lpszHostName, lpwhs->nHostPort );
3095     requestString = HTTP_BuildHeaderRequestString( lpwhr, szConnect, lpszPath, g_szHttp1_1 );
3096     HeapFree( GetProcessHeap(), 0, lpszPath );
3097
3098     len = WideCharToMultiByte( CP_ACP, 0, requestString, -1,
3099                                 NULL, 0, NULL, NULL );
3100     len--; /* the nul terminator isn't needed */
3101     ascii_req = HeapAlloc( GetProcessHeap(), 0, len );
3102     WideCharToMultiByte( CP_ACP, 0, requestString, -1,
3103                             ascii_req, len, NULL, NULL );
3104     HeapFree( GetProcessHeap(), 0, requestString );
3105
3106     TRACE("full request -> %s\n", debugstr_an( ascii_req, len ) );
3107
3108     ret = NETCON_send( &lpwhr->netConnection, ascii_req, len, 0, &cnt );
3109     HeapFree( GetProcessHeap(), 0, ascii_req );
3110     if (!ret || cnt < 0)
3111         return FALSE;
3112
3113     responseLen = HTTP_GetResponseHeaders( lpwhr, TRUE );
3114     if (!responseLen)
3115         return FALSE;
3116
3117     return TRUE;
3118 }
3119
3120 /***********************************************************************
3121  *           HTTP_HttpSendRequestW (internal)
3122  *
3123  * Sends the specified request to the HTTP server
3124  *
3125  * RETURNS
3126  *    TRUE  on success
3127  *    FALSE on failure
3128  *
3129  */
3130 BOOL WINAPI HTTP_HttpSendRequestW(LPWININETHTTPREQW lpwhr, LPCWSTR lpszHeaders,
3131         DWORD dwHeaderLength, LPVOID lpOptional, DWORD dwOptionalLength,
3132         DWORD dwContentLength, BOOL bEndRequest)
3133 {
3134     INT cnt;
3135     BOOL bSuccess = FALSE;
3136     LPWSTR requestString = NULL;
3137     INT responseLen;
3138     BOOL loop_next;
3139     INTERNET_ASYNC_RESULT iar;
3140     static const WCHAR szClose[] = { 'C','l','o','s','e',0 };
3141     static const WCHAR szPost[] = { 'P','O','S','T',0 };
3142     static const WCHAR szContentLength[] =
3143         { 'C','o','n','t','e','n','t','-','L','e','n','g','t','h',':',' ','%','l','i','\r','\n',0 };
3144     WCHAR contentLengthStr[sizeof szContentLength/2 /* includes \r\n */ + 20 /* int */ ];
3145
3146     TRACE("--> %p\n", lpwhr);
3147
3148     assert(lpwhr->hdr.htype == WH_HHTTPREQ);
3149
3150     /* Clear any error information */
3151     INTERNET_SetLastError(0);
3152
3153     /* if the verb is NULL default to GET */
3154     if (!lpwhr->lpszVerb)
3155         lpwhr->lpszVerb = WININET_strdupW(szGET);
3156
3157     if (dwContentLength || !strcmpW(lpwhr->lpszVerb, szPost))
3158     {
3159         sprintfW(contentLengthStr, szContentLength, dwContentLength);
3160         HTTP_HttpAddRequestHeadersW(lpwhr, contentLengthStr, -1L, HTTP_ADDREQ_FLAG_ADD | HTTP_ADDHDR_FLAG_REPLACE);
3161     }
3162     if (lpwhr->lpHttpSession->lpAppInfo->lpszAgent)
3163     {
3164         WCHAR *agent_header;
3165         static const WCHAR user_agent[] = {'U','s','e','r','-','A','g','e','n','t',':',' ','%','s','\r','\n',0};
3166         int len;
3167
3168         len = strlenW(lpwhr->lpHttpSession->lpAppInfo->lpszAgent) + strlenW(user_agent);
3169         agent_header = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR));
3170         sprintfW(agent_header, user_agent, lpwhr->lpHttpSession->lpAppInfo->lpszAgent);
3171
3172         HTTP_HttpAddRequestHeadersW(lpwhr, agent_header, strlenW(agent_header), HTTP_ADDREQ_FLAG_ADD_IF_NEW);
3173         HeapFree(GetProcessHeap(), 0, agent_header);
3174     }
3175
3176     do
3177     {
3178         DWORD len;
3179         char *ascii_req;
3180
3181         loop_next = FALSE;
3182
3183         /* like native, just in case the caller forgot to call InternetReadFile
3184          * for all the data */
3185         HTTP_DrainContent(lpwhr);
3186         lpwhr->dwContentRead = 0;
3187
3188         if (TRACE_ON(wininet))
3189         {
3190             LPHTTPHEADERW Host = HTTP_GetHeader(lpwhr,szHost);
3191             TRACE("Going to url %s %s\n", debugstr_w(Host->lpszValue), debugstr_w(lpwhr->lpszPath));
3192         }
3193
3194         HTTP_FixURL(lpwhr);
3195         HTTP_ProcessHeader(lpwhr, szConnection,
3196                            lpwhr->hdr.dwFlags & INTERNET_FLAG_KEEP_CONNECTION ? szKeepAlive : szClose,
3197                            HTTP_ADDHDR_FLAG_REQ | HTTP_ADDHDR_FLAG_REPLACE);
3198
3199         HTTP_InsertAuthorization(lpwhr, lpwhr->pAuthInfo, szAuthorization);
3200         HTTP_InsertAuthorization(lpwhr, lpwhr->pProxyAuthInfo, szProxy_Authorization);
3201
3202         /* add the headers the caller supplied */
3203         if( lpszHeaders && dwHeaderLength )
3204         {
3205             HTTP_HttpAddRequestHeadersW(lpwhr, lpszHeaders, dwHeaderLength,
3206                         HTTP_ADDREQ_FLAG_ADD | HTTP_ADDHDR_FLAG_REPLACE);
3207         }
3208
3209         if (lpwhr->lpHttpSession->lpAppInfo->lpszProxy && lpwhr->lpHttpSession->lpAppInfo->lpszProxy[0])
3210         {
3211             WCHAR *url = HTTP_BuildProxyRequestUrl(lpwhr);
3212             requestString = HTTP_BuildHeaderRequestString(lpwhr, lpwhr->lpszVerb, url, lpwhr->lpszVersion);
3213             HeapFree(GetProcessHeap(), 0, url);
3214         }
3215         else
3216             requestString = HTTP_BuildHeaderRequestString(lpwhr, lpwhr->lpszVerb, lpwhr->lpszPath, lpwhr->lpszVersion);
3217
3218  
3219         TRACE("Request header -> %s\n", debugstr_w(requestString) );
3220
3221         /* Send the request and store the results */
3222         if (!HTTP_OpenConnection(lpwhr))
3223             goto lend;
3224
3225         /* send the request as ASCII, tack on the optional data */
3226         if( !lpOptional )
3227             dwOptionalLength = 0;
3228         len = WideCharToMultiByte( CP_ACP, 0, requestString, -1,
3229                                    NULL, 0, NULL, NULL );
3230         ascii_req = HeapAlloc( GetProcessHeap(), 0, len + dwOptionalLength );
3231         WideCharToMultiByte( CP_ACP, 0, requestString, -1,
3232                              ascii_req, len, NULL, NULL );
3233         if( lpOptional )
3234             memcpy( &ascii_req[len-1], lpOptional, dwOptionalLength );
3235         len = (len + dwOptionalLength - 1);
3236         ascii_req[len] = 0;
3237         TRACE("full request -> %s\n", debugstr_a(ascii_req) );
3238
3239         INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3240                               INTERNET_STATUS_SENDING_REQUEST, NULL, 0);
3241
3242         NETCON_send(&lpwhr->netConnection, ascii_req, len, 0, &cnt);
3243         HeapFree( GetProcessHeap(), 0, ascii_req );
3244
3245         INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3246                               INTERNET_STATUS_REQUEST_SENT,
3247                               &len, sizeof(DWORD));
3248
3249         if (bEndRequest)
3250         {
3251             DWORD dwBufferSize;
3252             DWORD dwStatusCode;
3253             WCHAR encoding[20];
3254             static const WCHAR szChunked[] = {'c','h','u','n','k','e','d',0};
3255
3256             INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3257                                 INTERNET_STATUS_RECEIVING_RESPONSE, NULL, 0);
3258     
3259             if (cnt < 0)
3260                 goto lend;
3261     
3262             responseLen = HTTP_GetResponseHeaders(lpwhr, TRUE);
3263             if (responseLen)
3264                 bSuccess = TRUE;
3265     
3266             INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3267                                 INTERNET_STATUS_RESPONSE_RECEIVED, &responseLen,
3268                                 sizeof(DWORD));
3269
3270             HTTP_ProcessCookies(lpwhr);
3271
3272             dwBufferSize = sizeof(lpwhr->dwContentLength);
3273             if (!HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_FLAG_NUMBER|HTTP_QUERY_CONTENT_LENGTH,
3274                                      &lpwhr->dwContentLength,&dwBufferSize,NULL))
3275                 lpwhr->dwContentLength = -1;
3276
3277             if (lpwhr->dwContentLength == 0)
3278                 HTTP_FinishedReading(lpwhr);
3279
3280             /* Correct the case where both a Content-Length and Transfer-encoding = chunked are set */
3281
3282             dwBufferSize = sizeof(encoding);
3283             if (HTTP_HttpQueryInfoW(lpwhr, HTTP_QUERY_TRANSFER_ENCODING, encoding, &dwBufferSize, NULL) &&
3284                 !strcmpiW(encoding, szChunked))
3285             {
3286                 lpwhr->dwContentLength = -1;
3287             }
3288
3289             dwBufferSize = sizeof(dwStatusCode);
3290             if (!HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_FLAG_NUMBER|HTTP_QUERY_STATUS_CODE,
3291                                      &dwStatusCode,&dwBufferSize,NULL))
3292                 dwStatusCode = 0;
3293
3294             if (!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_AUTO_REDIRECT) && bSuccess)
3295             {
3296                 WCHAR szNewLocation[INTERNET_MAX_URL_LENGTH];
3297                 dwBufferSize=sizeof(szNewLocation);
3298                 if ((dwStatusCode==HTTP_STATUS_REDIRECT || dwStatusCode==HTTP_STATUS_MOVED) &&
3299                     HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_LOCATION,szNewLocation,&dwBufferSize,NULL))
3300                 {
3301                     HTTP_DrainContent(lpwhr);
3302                     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3303                                           INTERNET_STATUS_REDIRECT, szNewLocation,
3304                                           dwBufferSize);
3305                     bSuccess = HTTP_HandleRedirect(lpwhr, szNewLocation);
3306                     if (bSuccess)
3307                     {
3308                         HeapFree(GetProcessHeap(), 0, requestString);
3309                         loop_next = TRUE;
3310                     }
3311                 }
3312             }
3313             if (!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_AUTH) && bSuccess)
3314             {
3315                 WCHAR szAuthValue[2048];
3316                 dwBufferSize=2048;
3317                 if (dwStatusCode == HTTP_STATUS_DENIED)
3318                 {
3319                     DWORD dwIndex = 0;
3320                     while (HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_WWW_AUTHENTICATE,szAuthValue,&dwBufferSize,&dwIndex))
3321                     {
3322                         if (HTTP_DoAuthorization(lpwhr, szAuthValue,
3323                                                  &lpwhr->pAuthInfo,
3324                                                  lpwhr->lpHttpSession->lpszUserName,
3325                                                  lpwhr->lpHttpSession->lpszPassword))
3326                         {
3327                             loop_next = TRUE;
3328                             break;
3329                         }
3330                     }
3331                 }
3332                 if (dwStatusCode == HTTP_STATUS_PROXY_AUTH_REQ)
3333                 {
3334                     DWORD dwIndex = 0;
3335                     while (HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_PROXY_AUTHENTICATE,szAuthValue,&dwBufferSize,&dwIndex))
3336                     {
3337                         if (HTTP_DoAuthorization(lpwhr, szAuthValue,
3338                                                  &lpwhr->pProxyAuthInfo,
3339                                                  lpwhr->lpHttpSession->lpAppInfo->lpszProxyUsername,
3340                                                  lpwhr->lpHttpSession->lpAppInfo->lpszProxyPassword))
3341                         {
3342                             loop_next = TRUE;
3343                             break;
3344                         }
3345                     }
3346                 }
3347             }
3348         }
3349         else
3350             bSuccess = TRUE;
3351     }
3352     while (loop_next);
3353
3354     /* FIXME: Better check, when we have to create the cache file */
3355     if(bSuccess && (lpwhr->hdr.dwFlags & INTERNET_FLAG_NEED_FILE)) {
3356         WCHAR url[INTERNET_MAX_URL_LENGTH];
3357         WCHAR cacheFileName[MAX_PATH+1];
3358         BOOL b;
3359
3360         b = HTTP_GetRequestURL(lpwhr, url);
3361         if(!b) {
3362             WARN("Could not get URL\n");
3363             goto lend;
3364         }
3365
3366         b = CreateUrlCacheEntryW(url, lpwhr->dwContentLength > 0 ? lpwhr->dwContentLength : 0, NULL, cacheFileName, 0);
3367         if(b) {
3368             lpwhr->lpszCacheFile = WININET_strdupW(cacheFileName);
3369             lpwhr->hCacheFile = CreateFileW(lpwhr->lpszCacheFile, GENERIC_WRITE, FILE_SHARE_READ|FILE_SHARE_WRITE,
3370                       NULL, CREATE_ALWAYS, FILE_ATTRIBUTE_NORMAL, NULL);
3371             if(lpwhr->hCacheFile == INVALID_HANDLE_VALUE) {
3372                 WARN("Could not create file: %u\n", GetLastError());
3373                 lpwhr->hCacheFile = NULL;
3374             }
3375         }else {
3376             WARN("Could not create cache entry: %08x\n", GetLastError());
3377         }
3378     }
3379
3380 lend:
3381
3382     HeapFree(GetProcessHeap(), 0, requestString);
3383
3384     /* TODO: send notification for P3P header */
3385
3386     iar.dwResult = (DWORD)bSuccess;
3387     iar.dwError = bSuccess ? ERROR_SUCCESS : INTERNET_GetLastError();
3388
3389     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3390                           INTERNET_STATUS_REQUEST_COMPLETE, &iar,
3391                           sizeof(INTERNET_ASYNC_RESULT));
3392
3393     TRACE("<--\n");
3394     return bSuccess;
3395 }
3396
3397 /***********************************************************************
3398  *           HTTPSESSION_Destroy (internal)
3399  *
3400  * Deallocate session handle
3401  *
3402  */
3403 static void HTTPSESSION_Destroy(WININETHANDLEHEADER *hdr)
3404 {
3405     LPWININETHTTPSESSIONW lpwhs = (LPWININETHTTPSESSIONW) hdr;
3406
3407     TRACE("%p\n", lpwhs);
3408
3409     WININET_Release(&lpwhs->lpAppInfo->hdr);
3410
3411     HeapFree(GetProcessHeap(), 0, lpwhs->lpszHostName);
3412     HeapFree(GetProcessHeap(), 0, lpwhs->lpszServerName);
3413     HeapFree(GetProcessHeap(), 0, lpwhs->lpszPassword);
3414     HeapFree(GetProcessHeap(), 0, lpwhs->lpszUserName);
3415     HeapFree(GetProcessHeap(), 0, lpwhs);
3416 }
3417
3418 static DWORD HTTPSESSION_QueryOption(WININETHANDLEHEADER *hdr, DWORD option, void *buffer, DWORD *size, BOOL unicode)
3419 {
3420     switch(option) {
3421     case INTERNET_OPTION_HANDLE_TYPE:
3422         TRACE("INTERNET_OPTION_HANDLE_TYPE\n");
3423
3424         if (*size < sizeof(ULONG))
3425             return ERROR_INSUFFICIENT_BUFFER;
3426
3427         *size = sizeof(DWORD);
3428         *(DWORD*)buffer = INTERNET_HANDLE_TYPE_CONNECT_HTTP;
3429         return ERROR_SUCCESS;
3430     }
3431
3432     FIXME("Not implemented option %d\n", option);
3433     return ERROR_INTERNET_INVALID_OPTION;
3434 }
3435
3436 static const HANDLEHEADERVtbl HTTPSESSIONVtbl = {
3437     HTTPSESSION_Destroy,
3438     NULL,
3439     HTTPSESSION_QueryOption,
3440     NULL,
3441     NULL,
3442     NULL,
3443     NULL,
3444     NULL,
3445     NULL
3446 };
3447
3448
3449 /***********************************************************************
3450  *           HTTP_Connect  (internal)
3451  *
3452  * Create http session handle
3453  *
3454  * RETURNS
3455  *   HINTERNET a session handle on success
3456  *   NULL on failure
3457  *
3458  */
3459 HINTERNET HTTP_Connect(LPWININETAPPINFOW hIC, LPCWSTR lpszServerName,
3460         INTERNET_PORT nServerPort, LPCWSTR lpszUserName,
3461         LPCWSTR lpszPassword, DWORD dwFlags, DWORD_PTR dwContext,
3462         DWORD dwInternalFlags)
3463 {
3464     LPWININETHTTPSESSIONW lpwhs = NULL;
3465     HINTERNET handle = NULL;
3466
3467     TRACE("-->\n");
3468
3469     if (!lpszServerName || !lpszServerName[0])
3470     {
3471         INTERNET_SetLastError(ERROR_INVALID_PARAMETER);
3472         goto lerror;
3473     }
3474
3475     assert( hIC->hdr.htype == WH_HINIT );
3476
3477     lpwhs = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sizeof(WININETHTTPSESSIONW));
3478     if (NULL == lpwhs)
3479     {
3480         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
3481         goto lerror;
3482     }
3483
3484    /*
3485     * According to my tests. The name is not resolved until a request is sent
3486     */
3487
3488     lpwhs->hdr.htype = WH_HHTTPSESSION;
3489     lpwhs->hdr.vtbl = &HTTPSESSIONVtbl;
3490     lpwhs->hdr.dwFlags = dwFlags;
3491     lpwhs->hdr.dwContext = dwContext;
3492     lpwhs->hdr.dwInternalFlags = dwInternalFlags | (hIC->hdr.dwInternalFlags & INET_CALLBACKW);
3493     lpwhs->hdr.refs = 1;
3494     lpwhs->hdr.lpfnStatusCB = hIC->hdr.lpfnStatusCB;
3495
3496     WININET_AddRef( &hIC->hdr );
3497     lpwhs->lpAppInfo = hIC;
3498     list_add_head( &hIC->hdr.children, &lpwhs->hdr.entry );
3499
3500     handle = WININET_AllocHandle( &lpwhs->hdr );
3501     if (NULL == handle)
3502     {
3503         ERR("Failed to alloc handle\n");
3504         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
3505         goto lerror;
3506     }
3507
3508     if(hIC->lpszProxy && hIC->dwAccessType == INTERNET_OPEN_TYPE_PROXY) {
3509         if(strchrW(hIC->lpszProxy, ' '))
3510             FIXME("Several proxies not implemented.\n");
3511         if(hIC->lpszProxyBypass)
3512             FIXME("Proxy bypass is ignored.\n");
3513     }
3514     if (lpszServerName && lpszServerName[0])
3515     {
3516         lpwhs->lpszServerName = WININET_strdupW(lpszServerName);
3517         lpwhs->lpszHostName = WININET_strdupW(lpszServerName);
3518     }
3519     if (lpszUserName && lpszUserName[0])
3520         lpwhs->lpszUserName = WININET_strdupW(lpszUserName);
3521     if (lpszPassword && lpszPassword[0])
3522         lpwhs->lpszPassword = WININET_strdupW(lpszPassword);
3523     lpwhs->nServerPort = nServerPort;
3524     lpwhs->nHostPort = nServerPort;
3525
3526     /* Don't send a handle created callback if this handle was created with InternetOpenUrl */
3527     if (!(lpwhs->hdr.dwInternalFlags & INET_OPENURL))
3528     {
3529         INTERNET_SendCallback(&hIC->hdr, dwContext,
3530                               INTERNET_STATUS_HANDLE_CREATED, &handle,
3531                               sizeof(handle));
3532     }
3533
3534 lerror:
3535     if( lpwhs )
3536         WININET_Release( &lpwhs->hdr );
3537
3538 /*
3539  * an INTERNET_STATUS_REQUEST_COMPLETE is NOT sent here as per my tests on
3540  * windows
3541  */
3542
3543     TRACE("%p --> %p (%p)\n", hIC, handle, lpwhs);
3544     return handle;
3545 }
3546
3547
3548 /***********************************************************************
3549  *           HTTP_OpenConnection (internal)
3550  *
3551  * Connect to a web server
3552  *
3553  * RETURNS
3554  *
3555  *   TRUE  on success
3556  *   FALSE on failure
3557  */
3558 static BOOL HTTP_OpenConnection(LPWININETHTTPREQW lpwhr)
3559 {
3560     BOOL bSuccess = FALSE;
3561     LPWININETHTTPSESSIONW lpwhs;
3562     LPWININETAPPINFOW hIC = NULL;
3563     char szaddr[32];
3564
3565     TRACE("-->\n");
3566
3567
3568     if (NULL == lpwhr ||  lpwhr->hdr.htype != WH_HHTTPREQ)
3569     {
3570         INTERNET_SetLastError(ERROR_INVALID_PARAMETER);
3571         goto lend;
3572     }
3573
3574     if (NETCON_connected(&lpwhr->netConnection))
3575     {
3576         bSuccess = TRUE;
3577         goto lend;
3578     }
3579
3580     lpwhs = lpwhr->lpHttpSession;
3581
3582     hIC = lpwhs->lpAppInfo;
3583     inet_ntop(lpwhs->socketAddress.sin_family, &lpwhs->socketAddress.sin_addr,
3584               szaddr, sizeof(szaddr));
3585     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3586                           INTERNET_STATUS_CONNECTING_TO_SERVER,
3587                           szaddr,
3588                           strlen(szaddr)+1);
3589
3590     if (!NETCON_create(&lpwhr->netConnection, lpwhs->socketAddress.sin_family,
3591                          SOCK_STREAM, 0))
3592     {
3593         WARN("Socket creation failed\n");
3594         goto lend;
3595     }
3596
3597     if (!NETCON_connect(&lpwhr->netConnection, (struct sockaddr *)&lpwhs->socketAddress,
3598                       sizeof(lpwhs->socketAddress)))
3599        goto lend;
3600
3601     if (lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE)
3602     {
3603         /* Note: we differ from Microsoft's WinINet here. they seem to have
3604          * a bug that causes no status callbacks to be sent when starting
3605          * a tunnel to a proxy server using the CONNECT verb. i believe our
3606          * behaviour to be more correct and to not cause any incompatibilities
3607          * because using a secure connection through a proxy server is a rare
3608          * case that would be hard for anyone to depend on */
3609         if (hIC->lpszProxy && !HTTP_SecureProxyConnect(lpwhr))
3610             goto lend;
3611
3612         if (!NETCON_secure_connect(&lpwhr->netConnection, lpwhs->lpszHostName))
3613         {
3614             WARN("Couldn't connect securely to host\n");
3615             goto lend;
3616         }
3617     }
3618
3619     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3620                           INTERNET_STATUS_CONNECTED_TO_SERVER,
3621                           szaddr, strlen(szaddr)+1);
3622
3623     bSuccess = TRUE;
3624
3625 lend:
3626     TRACE("%d <--\n", bSuccess);
3627     return bSuccess;
3628 }
3629
3630
3631 /***********************************************************************
3632  *           HTTP_clear_response_headers (internal)
3633  *
3634  * clear out any old response headers
3635  */
3636 static void HTTP_clear_response_headers( LPWININETHTTPREQW lpwhr )
3637 {
3638     DWORD i;
3639
3640     for( i=0; i<lpwhr->nCustHeaders; i++)
3641     {
3642         if( !lpwhr->pCustHeaders[i].lpszField )
3643             continue;
3644         if( !lpwhr->pCustHeaders[i].lpszValue )
3645             continue;
3646         if ( lpwhr->pCustHeaders[i].wFlags & HDR_ISREQUEST )
3647             continue;
3648         HTTP_DeleteCustomHeader( lpwhr, i );
3649         i--;
3650     }
3651 }
3652
3653 /***********************************************************************
3654  *           HTTP_GetResponseHeaders (internal)
3655  *
3656  * Read server response
3657  *
3658  * RETURNS
3659  *
3660  *   TRUE  on success
3661  *   FALSE on error
3662  */
3663 static INT HTTP_GetResponseHeaders(LPWININETHTTPREQW lpwhr, BOOL clear)
3664 {
3665     INT cbreaks = 0;
3666     WCHAR buffer[MAX_REPLY_LEN];
3667     DWORD buflen = MAX_REPLY_LEN;
3668     BOOL bSuccess = FALSE;
3669     INT  rc = 0;
3670     static const WCHAR szCrLf[] = {'\r','\n',0};
3671     static const WCHAR szHundred[] = {'1','0','0',0};
3672     char bufferA[MAX_REPLY_LEN];
3673     LPWSTR status_code, status_text;
3674     DWORD cchMaxRawHeaders = 1024;
3675     LPWSTR lpszRawHeaders = HeapAlloc(GetProcessHeap(), 0, (cchMaxRawHeaders+1)*sizeof(WCHAR));
3676     DWORD cchRawHeaders = 0;
3677
3678     TRACE("-->\n");
3679
3680     /* clear old response headers (eg. from a redirect response) */
3681     if (clear) HTTP_clear_response_headers( lpwhr );
3682
3683     if (!NETCON_connected(&lpwhr->netConnection))
3684         goto lend;
3685
3686     do {
3687         /*
3688          * HACK peek at the buffer
3689          */
3690         buflen = MAX_REPLY_LEN;
3691         NETCON_recv(&lpwhr->netConnection, buffer, buflen, MSG_PEEK, &rc);
3692
3693         /*
3694          * We should first receive 'HTTP/1.x nnn OK' where nnn is the status code.
3695          */
3696         memset(buffer, 0, MAX_REPLY_LEN);
3697         if (!NETCON_getNextLine(&lpwhr->netConnection, bufferA, &buflen))
3698             goto lend;
3699         MultiByteToWideChar( CP_ACP, 0, bufferA, buflen, buffer, MAX_REPLY_LEN );
3700
3701         /* split the version from the status code */
3702         status_code = strchrW( buffer, ' ' );
3703         if( !status_code )
3704             goto lend;
3705         *status_code++=0;
3706
3707         /* split the status code from the status text */
3708         status_text = strchrW( status_code, ' ' );
3709         if( !status_text )
3710             goto lend;
3711         *status_text++=0;
3712
3713         TRACE("version [%s] status code [%s] status text [%s]\n",
3714            debugstr_w(buffer), debugstr_w(status_code), debugstr_w(status_text) );
3715
3716     } while (!strcmpW(status_code, szHundred)); /* ignore "100 Continue" responses */
3717
3718     /* Add status code */
3719     HTTP_ProcessHeader(lpwhr, szStatus, status_code,
3720             HTTP_ADDHDR_FLAG_REPLACE);
3721
3722     HeapFree(GetProcessHeap(),0,lpwhr->lpszVersion);
3723     HeapFree(GetProcessHeap(),0,lpwhr->lpszStatusText);
3724
3725     lpwhr->lpszVersion= WININET_strdupW(buffer);
3726     lpwhr->lpszStatusText = WININET_strdupW(status_text);
3727
3728     /* Restore the spaces */
3729     *(status_code-1) = ' ';
3730     *(status_text-1) = ' ';
3731
3732     /* regenerate raw headers */
3733     while (cchRawHeaders + buflen + strlenW(szCrLf) > cchMaxRawHeaders)
3734     {
3735         cchMaxRawHeaders *= 2;
3736         lpszRawHeaders = HeapReAlloc(GetProcessHeap(), 0, lpszRawHeaders, (cchMaxRawHeaders+1)*sizeof(WCHAR));
3737     }
3738     memcpy(lpszRawHeaders+cchRawHeaders, buffer, (buflen-1)*sizeof(WCHAR));
3739     cchRawHeaders += (buflen-1);
3740     memcpy(lpszRawHeaders+cchRawHeaders, szCrLf, sizeof(szCrLf));
3741     cchRawHeaders += sizeof(szCrLf)/sizeof(szCrLf[0])-1;
3742     lpszRawHeaders[cchRawHeaders] = '\0';
3743
3744     /* Parse each response line */
3745     do
3746     {
3747         buflen = MAX_REPLY_LEN;
3748         if (NETCON_getNextLine(&lpwhr->netConnection, bufferA, &buflen))
3749         {
3750             LPWSTR * pFieldAndValue;
3751
3752             TRACE("got line %s, now interpreting\n", debugstr_a(bufferA));
3753             MultiByteToWideChar( CP_ACP, 0, bufferA, buflen, buffer, MAX_REPLY_LEN );
3754
3755             while (cchRawHeaders + buflen + strlenW(szCrLf) > cchMaxRawHeaders)
3756             {
3757                 cchMaxRawHeaders *= 2;
3758                 lpszRawHeaders = HeapReAlloc(GetProcessHeap(), 0, lpszRawHeaders, (cchMaxRawHeaders+1)*sizeof(WCHAR));
3759             }
3760             memcpy(lpszRawHeaders+cchRawHeaders, buffer, (buflen-1)*sizeof(WCHAR));
3761             cchRawHeaders += (buflen-1);
3762             memcpy(lpszRawHeaders+cchRawHeaders, szCrLf, sizeof(szCrLf));
3763             cchRawHeaders += sizeof(szCrLf)/sizeof(szCrLf[0])-1;
3764             lpszRawHeaders[cchRawHeaders] = '\0';
3765
3766             pFieldAndValue = HTTP_InterpretHttpHeader(buffer);
3767             if (!pFieldAndValue)
3768                 break;
3769
3770             HTTP_ProcessHeader(lpwhr, pFieldAndValue[0], pFieldAndValue[1], 
3771                 HTTP_ADDREQ_FLAG_ADD );
3772
3773             HTTP_FreeTokens(pFieldAndValue);
3774         }
3775         else
3776         {
3777             cbreaks++;
3778             if (cbreaks >= 2)
3779                break;
3780         }
3781     }while(1);
3782
3783     HeapFree(GetProcessHeap(), 0, lpwhr->lpszRawHeaders);
3784     lpwhr->lpszRawHeaders = lpszRawHeaders;
3785     TRACE("raw headers: %s\n", debugstr_w(lpszRawHeaders));
3786     bSuccess = TRUE;
3787
3788 lend:
3789
3790     TRACE("<--\n");
3791     if (bSuccess)
3792         return rc;
3793     else
3794         return 0;
3795 }
3796
3797
3798 static void strip_spaces(LPWSTR start)
3799 {
3800     LPWSTR str = start;
3801     LPWSTR end;
3802
3803     while (*str == ' ' && *str != '\0')
3804         str++;
3805
3806     if (str != start)
3807         memmove(start, str, sizeof(WCHAR) * (strlenW(str) + 1));
3808
3809     end = start + strlenW(start) - 1;
3810     while (end >= start && *end == ' ')
3811     {
3812         *end = '\0';
3813         end--;
3814     }
3815 }
3816
3817
3818 /***********************************************************************
3819  *           HTTP_InterpretHttpHeader (internal)
3820  *
3821  * Parse server response
3822  *
3823  * RETURNS
3824  *
3825  *   Pointer to array of field, value, NULL on success.
3826  *   NULL on error.
3827  */
3828 static LPWSTR * HTTP_InterpretHttpHeader(LPCWSTR buffer)
3829 {
3830     LPWSTR * pTokenPair;
3831     LPWSTR pszColon;
3832     INT len;
3833
3834     pTokenPair = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sizeof(*pTokenPair)*3);
3835
3836     pszColon = strchrW(buffer, ':');
3837     /* must have two tokens */
3838     if (!pszColon)
3839     {
3840         HTTP_FreeTokens(pTokenPair);
3841         if (buffer[0])
3842             TRACE("No ':' in line: %s\n", debugstr_w(buffer));
3843         return NULL;
3844     }
3845
3846     pTokenPair[0] = HeapAlloc(GetProcessHeap(), 0, (pszColon - buffer + 1) * sizeof(WCHAR));
3847     if (!pTokenPair[0])
3848     {
3849         HTTP_FreeTokens(pTokenPair);
3850         return NULL;
3851     }
3852     memcpy(pTokenPair[0], buffer, (pszColon - buffer) * sizeof(WCHAR));
3853     pTokenPair[0][pszColon - buffer] = '\0';
3854
3855     /* skip colon */
3856     pszColon++;
3857     len = strlenW(pszColon);
3858     pTokenPair[1] = HeapAlloc(GetProcessHeap(), 0, (len + 1) * sizeof(WCHAR));
3859     if (!pTokenPair[1])
3860     {
3861         HTTP_FreeTokens(pTokenPair);
3862         return NULL;
3863     }
3864     memcpy(pTokenPair[1], pszColon, (len + 1) * sizeof(WCHAR));
3865
3866     strip_spaces(pTokenPair[0]);
3867     strip_spaces(pTokenPair[1]);
3868
3869     TRACE("field(%s) Value(%s)\n", debugstr_w(pTokenPair[0]), debugstr_w(pTokenPair[1]));
3870     return pTokenPair;
3871 }
3872
3873 /***********************************************************************
3874  *           HTTP_ProcessHeader (internal)
3875  *
3876  * Stuff header into header tables according to <dwModifier>
3877  *
3878  */
3879
3880 #define COALESCEFLAGS (HTTP_ADDHDR_FLAG_COALESCE|HTTP_ADDHDR_FLAG_COALESCE_WITH_COMMA|HTTP_ADDHDR_FLAG_COALESCE_WITH_SEMICOLON)
3881
3882 static BOOL HTTP_ProcessHeader(LPWININETHTTPREQW lpwhr, LPCWSTR field, LPCWSTR value, DWORD dwModifier)
3883 {
3884     LPHTTPHEADERW lphttpHdr = NULL;
3885     BOOL bSuccess = FALSE;
3886     INT index = -1;
3887     BOOL request_only = dwModifier & HTTP_ADDHDR_FLAG_REQ;
3888
3889     TRACE("--> %s: %s - 0x%08x\n", debugstr_w(field), debugstr_w(value), dwModifier);
3890
3891     /* REPLACE wins out over ADD */
3892     if (dwModifier & HTTP_ADDHDR_FLAG_REPLACE)
3893         dwModifier &= ~HTTP_ADDHDR_FLAG_ADD;
3894     
3895     if (dwModifier & HTTP_ADDHDR_FLAG_ADD)
3896         index = -1;
3897     else
3898         index = HTTP_GetCustomHeaderIndex(lpwhr, field, 0, request_only);
3899
3900     if (index >= 0)
3901     {
3902         if (dwModifier & HTTP_ADDHDR_FLAG_ADD_IF_NEW)
3903         {
3904             return FALSE;
3905         }
3906         lphttpHdr = &lpwhr->pCustHeaders[index];
3907     }
3908     else if (value)
3909     {
3910         HTTPHEADERW hdr;
3911
3912         hdr.lpszField = (LPWSTR)field;
3913         hdr.lpszValue = (LPWSTR)value;
3914         hdr.wFlags = hdr.wCount = 0;
3915
3916         if (dwModifier & HTTP_ADDHDR_FLAG_REQ)
3917             hdr.wFlags |= HDR_ISREQUEST;
3918
3919         return HTTP_InsertCustomHeader(lpwhr, &hdr);
3920     }
3921     /* no value to delete */
3922     else return TRUE;
3923
3924     if (dwModifier & HTTP_ADDHDR_FLAG_REQ)
3925             lphttpHdr->wFlags |= HDR_ISREQUEST;
3926     else
3927         lphttpHdr->wFlags &= ~HDR_ISREQUEST;
3928
3929     if (dwModifier & HTTP_ADDHDR_FLAG_REPLACE)
3930     {
3931         HTTP_DeleteCustomHeader( lpwhr, index );
3932
3933         if (value)
3934         {
3935             HTTPHEADERW hdr;
3936
3937             hdr.lpszField = (LPWSTR)field;
3938             hdr.lpszValue = (LPWSTR)value;
3939             hdr.wFlags = hdr.wCount = 0;
3940
3941             if (dwModifier & HTTP_ADDHDR_FLAG_REQ)
3942                 hdr.wFlags |= HDR_ISREQUEST;
3943
3944             return HTTP_InsertCustomHeader(lpwhr, &hdr);
3945         }
3946
3947         return TRUE;
3948     }
3949     else if (dwModifier & COALESCEFLAGS)
3950     {
3951         LPWSTR lpsztmp;
3952         WCHAR ch = 0;
3953         INT len = 0;
3954         INT origlen = strlenW(lphttpHdr->lpszValue);
3955         INT valuelen = strlenW(value);
3956
3957         if (dwModifier & HTTP_ADDHDR_FLAG_COALESCE_WITH_COMMA)
3958         {
3959             ch = ',';
3960             lphttpHdr->wFlags |= HDR_COMMADELIMITED;
3961         }
3962         else if (dwModifier & HTTP_ADDHDR_FLAG_COALESCE_WITH_SEMICOLON)
3963         {
3964             ch = ';';
3965             lphttpHdr->wFlags |= HDR_COMMADELIMITED;
3966         }
3967
3968         len = origlen + valuelen + ((ch > 0) ? 2 : 0);
3969
3970         lpsztmp = HeapReAlloc(GetProcessHeap(), 0, lphttpHdr->lpszValue, (len+1)*sizeof(WCHAR));
3971         if (lpsztmp)
3972         {
3973             lphttpHdr->lpszValue = lpsztmp;
3974     /* FIXME: Increment lphttpHdr->wCount. Perhaps lpszValue should be an array */
3975             if (ch > 0)
3976             {
3977                 lphttpHdr->lpszValue[origlen] = ch;
3978                 origlen++;
3979                 lphttpHdr->lpszValue[origlen] = ' ';
3980                 origlen++;
3981             }
3982
3983             memcpy(&lphttpHdr->lpszValue[origlen], value, valuelen*sizeof(WCHAR));
3984             lphttpHdr->lpszValue[len] = '\0';
3985             bSuccess = TRUE;
3986         }
3987         else
3988         {
3989             WARN("HeapReAlloc (%d bytes) failed\n",len+1);
3990             INTERNET_SetLastError(ERROR_OUTOFMEMORY);
3991         }
3992     }
3993     TRACE("<-- %d\n",bSuccess);
3994     return bSuccess;
3995 }
3996
3997
3998 /***********************************************************************
3999  *           HTTP_FinishedReading (internal)
4000  *
4001  * Called when all content from server has been read by client.
4002  *
4003  */
4004 BOOL HTTP_FinishedReading(LPWININETHTTPREQW lpwhr)
4005 {
4006     WCHAR szVersion[10];
4007     DWORD dwBufferSize = sizeof(szVersion);
4008
4009     TRACE("\n");
4010
4011     /* as per RFC 2068, S8.1.2.1, if the client is HTTP/1.1 then assume that
4012      * the connection is keep-alive by default */
4013     if (!HTTP_HttpQueryInfoW(lpwhr, HTTP_QUERY_VERSION, szVersion,
4014                              &dwBufferSize, NULL) ||
4015         strcmpiW(szVersion, g_szHttp1_1))
4016     {
4017         WCHAR szConnectionResponse[20];
4018         dwBufferSize = sizeof(szConnectionResponse);
4019         if ((!HTTP_HttpQueryInfoW(lpwhr, HTTP_QUERY_CONNECTION, szConnectionResponse, &dwBufferSize, NULL) ||
4020              strcmpiW(szConnectionResponse, szKeepAlive)) &&
4021             (!HTTP_HttpQueryInfoW(lpwhr, HTTP_QUERY_PROXY_CONNECTION, szConnectionResponse, &dwBufferSize, NULL) ||
4022              strcmpiW(szConnectionResponse, szKeepAlive)))
4023         {
4024             HTTPREQ_CloseConnection(&lpwhr->hdr);
4025         }
4026     }
4027
4028     /* FIXME: store data in the URL cache here */
4029
4030     return TRUE;
4031 }
4032
4033
4034 /***********************************************************************
4035  *           HTTP_GetCustomHeaderIndex (internal)
4036  *
4037  * Return index of custom header from header array
4038  *
4039  */
4040 static INT HTTP_GetCustomHeaderIndex(LPWININETHTTPREQW lpwhr, LPCWSTR lpszField,
4041                                      int requested_index, BOOL request_only)
4042 {
4043     DWORD index;
4044
4045     TRACE("%s\n", debugstr_w(lpszField));
4046
4047     for (index = 0; index < lpwhr->nCustHeaders; index++)
4048     {
4049         if (strcmpiW(lpwhr->pCustHeaders[index].lpszField, lpszField))
4050             continue;
4051
4052         if (request_only && !(lpwhr->pCustHeaders[index].wFlags & HDR_ISREQUEST))
4053             continue;
4054
4055         if (!request_only && (lpwhr->pCustHeaders[index].wFlags & HDR_ISREQUEST))
4056             continue;
4057
4058         if (requested_index == 0)
4059             break;
4060         requested_index --;
4061     }
4062
4063     if (index >= lpwhr->nCustHeaders)
4064         index = -1;
4065
4066     TRACE("Return: %d\n", index);
4067     return index;
4068 }
4069
4070
4071 /***********************************************************************
4072  *           HTTP_InsertCustomHeader (internal)
4073  *
4074  * Insert header into array
4075  *
4076  */
4077 static BOOL HTTP_InsertCustomHeader(LPWININETHTTPREQW lpwhr, LPHTTPHEADERW lpHdr)
4078 {
4079     INT count;
4080     LPHTTPHEADERW lph = NULL;
4081     BOOL r = FALSE;
4082
4083     TRACE("--> %s: %s\n", debugstr_w(lpHdr->lpszField), debugstr_w(lpHdr->lpszValue));
4084     count = lpwhr->nCustHeaders + 1;
4085     if (count > 1)
4086         lph = HeapReAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, lpwhr->pCustHeaders, sizeof(HTTPHEADERW) * count);
4087     else
4088         lph = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sizeof(HTTPHEADERW) * count);
4089
4090     if (NULL != lph)
4091     {
4092         lpwhr->pCustHeaders = lph;
4093         lpwhr->pCustHeaders[count-1].lpszField = WININET_strdupW(lpHdr->lpszField);
4094         lpwhr->pCustHeaders[count-1].lpszValue = WININET_strdupW(lpHdr->lpszValue);
4095         lpwhr->pCustHeaders[count-1].wFlags = lpHdr->wFlags;
4096         lpwhr->pCustHeaders[count-1].wCount= lpHdr->wCount;
4097         lpwhr->nCustHeaders++;
4098         r = TRUE;
4099     }
4100     else
4101     {
4102         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
4103     }
4104
4105     return r;
4106 }
4107
4108
4109 /***********************************************************************
4110  *           HTTP_DeleteCustomHeader (internal)
4111  *
4112  * Delete header from array
4113  *  If this function is called, the indexs may change.
4114  */
4115 static BOOL HTTP_DeleteCustomHeader(LPWININETHTTPREQW lpwhr, DWORD index)
4116 {
4117     if( lpwhr->nCustHeaders <= 0 )
4118         return FALSE;
4119     if( index >= lpwhr->nCustHeaders )
4120         return FALSE;
4121     lpwhr->nCustHeaders--;
4122
4123     memmove( &lpwhr->pCustHeaders[index], &lpwhr->pCustHeaders[index+1],
4124              (lpwhr->nCustHeaders - index)* sizeof(HTTPHEADERW) );
4125     memset( &lpwhr->pCustHeaders[lpwhr->nCustHeaders], 0, sizeof(HTTPHEADERW) );
4126
4127     return TRUE;
4128 }
4129
4130
4131 /***********************************************************************
4132  *           HTTP_VerifyValidHeader (internal)
4133  *
4134  * Verify the given header is not invalid for the given http request
4135  *
4136  */
4137 static BOOL HTTP_VerifyValidHeader(LPWININETHTTPREQW lpwhr, LPCWSTR field)
4138 {
4139     /* Accept-Encoding is stripped from HTTP/1.0 requests. It is invalid */
4140     if (!strcmpW(lpwhr->lpszVersion, g_szHttp1_0) && !strcmpiW(field, szAccept_Encoding))
4141         return FALSE;
4142
4143     return TRUE;
4144 }
4145
4146 /***********************************************************************
4147  *          IsHostInProxyBypassList (@)
4148  *
4149  * Undocumented
4150  *
4151  */
4152 BOOL WINAPI IsHostInProxyBypassList(DWORD flags, LPCSTR szHost, DWORD length)
4153 {
4154    FIXME("STUB: flags=%d host=%s length=%d\n",flags,szHost,length);
4155    return FALSE;
4156 }