msvcp: Prevent overflows while operating on string sizes.
[wine] / dlls / ieframe / navigate.c
1 /*
2  * Copyright 2006-2007 Jacek Caban for CodeWeavers
3  *
4  * This library is free software; you can redistribute it and/or
5  * modify it under the terms of the GNU Lesser General Public
6  * License as published by the Free Software Foundation; either
7  * version 2.1 of the License, or (at your option) any later version.
8  *
9  * This library is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
12  * Lesser General Public License for more details.
13  *
14  * You should have received a copy of the GNU Lesser General Public
15  * License along with this library; if not, write to the Free Software
16  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
17  */
18
19 #define NONAMELESSUNION
20 #define NONAMELESSSTRUCT
21
22 #include "ieframe.h"
23
24 #include "exdispid.h"
25 #include "shellapi.h"
26 #include "winreg.h"
27 #include "shlwapi.h"
28 #include "wininet.h"
29 #include "mshtml.h"
30 #include "resource.h"
31
32 #include "wine/debug.h"
33
34 WINE_DEFAULT_DEBUG_CHANNEL(ieframe);
35
36 static const WCHAR emptyW[] = {0};
37
38 typedef struct {
39     IBindStatusCallback  IBindStatusCallback_iface;
40     IHttpNegotiate       IHttpNegotiate_iface;
41     IHttpSecurity        IHttpSecurity_iface;
42
43     LONG ref;
44
45     DocHost *doc_host;
46     IBinding *binding;
47
48     LPWSTR url;
49     HGLOBAL post_data;
50     BSTR headers;
51     ULONG post_data_len;
52 } BindStatusCallback;
53
54 static void dump_BINDINFO(BINDINFO *bi)
55 {
56     static const char * const BINDINFOF_str[] = {
57         "#0",
58         "BINDINFOF_URLENCODESTGMEDDATA",
59         "BINDINFOF_URLENCODEDEXTRAINFO"
60     };
61
62     static const char * const BINDVERB_str[] = {
63         "BINDVERB_GET",
64         "BINDVERB_POST",
65         "BINDVERB_PUT",
66         "BINDVERB_CUSTOM"
67     };
68
69     TRACE("\n"
70             "BINDINFO = {\n"
71             "    %d, %s,\n"
72             "    {%d, %p, %p},\n"
73             "    %s,\n"
74             "    %s,\n"
75             "    %s,\n"
76             "    %d, %08x, %d, %d\n"
77             "    {%d %p %x},\n"
78             "    %s\n"
79             "    %p, %d\n"
80             "}\n",
81
82             bi->cbSize, debugstr_w(bi->szExtraInfo),
83             bi->stgmedData.tymed, bi->stgmedData.u.hGlobal, bi->stgmedData.pUnkForRelease,
84             bi->grfBindInfoF > BINDINFOF_URLENCODEDEXTRAINFO
85                 ? "unknown" : BINDINFOF_str[bi->grfBindInfoF],
86             bi->dwBindVerb > BINDVERB_CUSTOM
87                 ? "unknown" : BINDVERB_str[bi->dwBindVerb],
88             debugstr_w(bi->szCustomVerb),
89             bi->cbstgmedData, bi->dwOptions, bi->dwOptionsFlags, bi->dwCodePage,
90             bi->securityAttributes.nLength,
91             bi->securityAttributes.lpSecurityDescriptor,
92             bi->securityAttributes.bInheritHandle,
93             debugstr_guid(&bi->iid),
94             bi->pUnk, bi->dwReserved
95             );
96 }
97
98 static void set_status_text(BindStatusCallback *This, ULONG statuscode, LPCWSTR str)
99 {
100     VARIANTARG arg;
101     DISPPARAMS dispparams = {&arg, NULL, 1, 0};
102     WCHAR fmt[IDS_STATUSFMT_MAXLEN];
103     WCHAR buffer[IDS_STATUSFMT_MAXLEN + INTERNET_MAX_URL_LENGTH];
104
105     if(!This->doc_host)
106         return;
107
108     TRACE("(%p, %d, %s)\n", This, statuscode, debugstr_w(str));
109     buffer[0] = 0;
110     if (statuscode && str && *str) {
111         fmt[0] = 0;
112         /* the format string must have one "%s" for the str */
113         LoadStringW(ieframe_instance, IDS_STATUSFMT_FIRST + statuscode, fmt, IDS_STATUSFMT_MAXLEN);
114         snprintfW(buffer, sizeof(buffer)/sizeof(WCHAR), fmt, str);
115     }
116
117     V_VT(&arg) = VT_BSTR;
118     V_BSTR(&arg) = str ? SysAllocString(buffer) : NULL;
119     TRACE("=> %s\n", debugstr_w(V_BSTR(&arg)));
120
121     call_sink(This->doc_host->cps.wbe2, DISPID_STATUSTEXTCHANGE, &dispparams);
122
123     if(This->doc_host->frame)
124         IOleInPlaceFrame_SetStatusText(This->doc_host->frame, buffer);
125
126     VariantClear(&arg);
127
128 }
129
130 HRESULT set_dochost_url(DocHost *This, const WCHAR *url)
131 {
132     WCHAR *new_url;
133
134     if(url) {
135         new_url = heap_strdupW(url);
136         if(!new_url)
137             return E_OUTOFMEMORY;
138     }else {
139         new_url = NULL;
140     }
141
142     heap_free(This->url);
143     This->url = new_url;
144
145     This->container_vtbl->SetURL(This, This->url);
146     return S_OK;
147 }
148
149 static inline BindStatusCallback *impl_from_IBindStatusCallback(IBindStatusCallback *iface)
150 {
151     return CONTAINING_RECORD(iface, BindStatusCallback, IBindStatusCallback_iface);
152 }
153
154 static HRESULT WINAPI BindStatusCallback_QueryInterface(IBindStatusCallback *iface,
155                                                         REFIID riid, void **ppv)
156 {
157     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
158
159     if(IsEqualGUID(&IID_IUnknown, riid)) {
160         TRACE("(%p)->(IID_IUnknown %p)\n", This, ppv);
161         *ppv = &This->IBindStatusCallback_iface;
162     }else if(IsEqualGUID(&IID_IBindStatusCallback, riid)) {
163         TRACE("(%p)->(IID_IBindStatusCallback %p)\n", This, ppv);
164         *ppv = &This->IBindStatusCallback_iface;
165     }else if(IsEqualGUID(&IID_IHttpNegotiate, riid)) {
166         TRACE("(%p)->(IID_IHttpNegotiate %p)\n", This, ppv);
167         *ppv = &This->IHttpNegotiate_iface;
168     }else if(IsEqualGUID(&IID_IWindowForBindingUI, riid)) {
169         TRACE("(%p)->(IID_IWindowForBindingUI %p)\n", This, ppv);
170         *ppv = &This->IHttpSecurity_iface;
171     }else if(IsEqualGUID(&IID_IHttpSecurity, riid)) {
172         TRACE("(%p)->(IID_IHttpSecurity %p)\n", This, ppv);
173         *ppv = &This->IHttpSecurity_iface;
174     }else {
175         *ppv = NULL;
176         WARN("(%p)->(%s %p)\n", This, debugstr_guid(riid), ppv);
177         return E_NOINTERFACE;
178     }
179
180     IUnknown_AddRef((IUnknown*)*ppv);
181     return S_OK;
182 }
183
184 static ULONG WINAPI BindStatusCallback_AddRef(IBindStatusCallback *iface)
185 {
186     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
187     LONG ref = InterlockedIncrement(&This->ref);
188
189     TRACE("(%p) ref=%d\n", This, ref);
190
191     return ref;
192 }
193
194 static ULONG WINAPI BindStatusCallback_Release(IBindStatusCallback *iface)
195 {
196     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
197     LONG ref = InterlockedDecrement(&This->ref);
198
199     TRACE("(%p) ref=%d\n", This, ref);
200
201     if(!ref) {
202         if(This->doc_host)
203             IOleClientSite_Release(&This->doc_host->IOleClientSite_iface);
204         if(This->binding)
205             IBinding_Release(This->binding);
206         if(This->post_data)
207             GlobalFree(This->post_data);
208         SysFreeString(This->headers);
209         heap_free(This->url);
210         heap_free(This);
211     }
212
213     return ref;
214 }
215
216 static HRESULT WINAPI BindStatusCallback_OnStartBinding(IBindStatusCallback *iface,
217        DWORD dwReserved, IBinding *pbind)
218 {
219     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
220
221     TRACE("(%p)->(%d %p)\n", This, dwReserved, pbind);
222
223     This->binding = pbind;
224     IBinding_AddRef(This->binding);
225
226     return S_OK;
227 }
228
229 static HRESULT WINAPI BindStatusCallback_GetPriority(IBindStatusCallback *iface,
230        LONG *pnPriority)
231 {
232     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
233     FIXME("(%p)->(%p)\n", This, pnPriority);
234     return E_NOTIMPL;
235 }
236
237 static HRESULT WINAPI BindStatusCallback_OnLowResource(IBindStatusCallback *iface,
238        DWORD reserved)
239 {
240     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
241     FIXME("(%p)->(%d)\n", This, reserved);
242     return E_NOTIMPL;
243 }
244
245 static DWORD get_http_status_code(IBinding *binding)
246 {
247     IWinInetHttpInfo *http_info;
248     DWORD status, size = sizeof(DWORD);
249     HRESULT hres;
250
251     hres = IBinding_QueryInterface(binding, &IID_IWinInetHttpInfo, (void**)&http_info);
252     if(FAILED(hres))
253         return HTTP_STATUS_OK;
254
255     hres = IWinInetHttpInfo_QueryInfo(http_info, HTTP_QUERY_STATUS_CODE|HTTP_QUERY_FLAG_NUMBER,
256             &status, &size, NULL, NULL);
257     IWinInetHttpInfo_Release(http_info);
258
259     if(FAILED(hres))
260         return HTTP_STATUS_OK;
261     return status;
262 }
263
264 static HRESULT WINAPI BindStatusCallback_OnProgress(IBindStatusCallback *iface,
265         ULONG ulProgress, ULONG ulProgressMax, ULONG ulStatusCode, LPCWSTR szStatusText)
266 {
267     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
268     DWORD status_code;
269
270     TRACE("(%p)->(%d %d %d %s)\n", This, ulProgress, ulProgressMax, ulStatusCode,
271           debugstr_w(szStatusText));
272
273     switch(ulStatusCode) {
274     case BINDSTATUS_REDIRECTING:
275         return set_dochost_url(This->doc_host, szStatusText);
276     case BINDSTATUS_BEGINDOWNLOADDATA:
277         set_status_text(This, ulStatusCode, szStatusText);
278         status_code = get_http_status_code(This->binding);
279         if(status_code != HTTP_STATUS_OK)
280             handle_navigation_error(This->doc_host, status_code, This->url, NULL);
281         return S_OK;
282
283     case BINDSTATUS_FINDINGRESOURCE:
284     case BINDSTATUS_ENDDOWNLOADDATA:
285     case BINDSTATUS_SENDINGREQUEST:
286         set_status_text(This, ulStatusCode, szStatusText);
287         return S_OK;
288
289     case BINDSTATUS_CONNECTING:
290     case BINDSTATUS_CACHEFILENAMEAVAILABLE:
291     case BINDSTATUS_CLASSIDAVAILABLE:
292     case BINDSTATUS_MIMETYPEAVAILABLE:
293     case BINDSTATUS_BEGINSYNCOPERATION:
294     case BINDSTATUS_ENDSYNCOPERATION:
295         return S_OK;
296     default:
297         FIXME("status code %u\n", ulStatusCode);
298     }
299
300     return S_OK;
301 }
302
303 void handle_navigation_error(DocHost* doc_host, HRESULT hres, BSTR url, IHTMLWindow2 *win2)
304 {
305     VARIANT var_status_code, var_frame_name, var_url;
306     DISPPARAMS dispparams;
307     VARIANTARG params[5];
308     VARIANT_BOOL cancel = VARIANT_FALSE;
309
310     dispparams.cArgs = 5;
311     dispparams.cNamedArgs = 0;
312     dispparams.rgdispidNamedArgs = NULL;
313     dispparams.rgvarg = params;
314
315     V_VT(params) = VT_BOOL|VT_BYREF;
316     V_BOOLREF(params) = &cancel;
317
318     V_VT(params+1) = VT_VARIANT|VT_BYREF;
319     V_VARIANTREF(params+1) = &var_status_code;
320     V_VT(&var_status_code) = VT_I4;
321     V_I4(&var_status_code) = hres;
322
323     V_VT(params+2) = VT_VARIANT|VT_BYREF;
324     V_VARIANTREF(params+2) = &var_frame_name;
325     V_VT(&var_frame_name) = VT_BSTR;
326     if(win2) {
327         hres = IHTMLWindow2_get_name(win2, &V_BSTR(&var_frame_name));
328         if(FAILED(hres))
329             V_BSTR(&var_frame_name) = NULL;
330     } else
331         V_BSTR(&var_frame_name) = NULL;
332
333     V_VT(params+3) = VT_VARIANT|VT_BYREF;
334     V_VARIANTREF(params+3) = &var_url;
335     V_VT(&var_url) = VT_BSTR;
336     V_BSTR(&var_url) = url;
337
338     V_VT(params+4) = VT_DISPATCH;
339     V_DISPATCH(params+4) = (IDispatch*)doc_host->wb;
340
341     call_sink(doc_host->cps.wbe2, DISPID_NAVIGATEERROR, &dispparams);
342     SysFreeString(V_BSTR(&var_frame_name));
343
344     if(!cancel)
345         FIXME("Navigate to error page\n");
346 }
347
348 static HRESULT WINAPI BindStatusCallback_OnStopBinding(IBindStatusCallback *iface,
349         HRESULT hresult, LPCWSTR szError)
350 {
351     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
352
353     TRACE("(%p)->(%08x %s)\n", This, hresult, debugstr_w(szError));
354
355     set_status_text(This, 0, emptyW);
356
357     if(!This->doc_host)
358         return S_OK;
359
360     if(FAILED(hresult))
361         handle_navigation_error(This->doc_host, hresult, This->url, NULL);
362
363     IOleClientSite_Release(&This->doc_host->IOleClientSite_iface);
364     This->doc_host = NULL;
365
366     IBinding_Release(This->binding);
367     This->binding = NULL;
368
369     return S_OK;
370 }
371
372 static HRESULT WINAPI BindStatusCallback_GetBindInfo(IBindStatusCallback *iface,
373         DWORD *grfBINDF, BINDINFO *pbindinfo)
374 {
375     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
376
377     TRACE("(%p)->(%p %p)\n", This, grfBINDF, pbindinfo);
378
379     *grfBINDF = BINDF_ASYNCHRONOUS;
380
381     if(This->post_data) {
382         pbindinfo->dwBindVerb = BINDVERB_POST;
383
384         pbindinfo->stgmedData.tymed = TYMED_HGLOBAL;
385         pbindinfo->stgmedData.u.hGlobal = This->post_data;
386         pbindinfo->cbstgmedData = This->post_data_len;
387         pbindinfo->stgmedData.pUnkForRelease = (IUnknown*)&This->IBindStatusCallback_iface;
388         IBindStatusCallback_AddRef(&This->IBindStatusCallback_iface);
389     }
390
391     return S_OK;
392 }
393
394 static HRESULT WINAPI BindStatusCallback_OnDataAvailable(IBindStatusCallback *iface,
395         DWORD grfBSCF, DWORD dwSize, FORMATETC *pformatetc, STGMEDIUM *pstgmed)
396 {
397     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
398     FIXME("(%p)->(%08x %d %p %p)\n", This, grfBSCF, dwSize, pformatetc, pstgmed);
399     return E_NOTIMPL;
400 }
401
402 static HRESULT WINAPI BindStatusCallback_OnObjectAvailable(IBindStatusCallback *iface,
403         REFIID riid, IUnknown *punk)
404 {
405     BindStatusCallback *This = impl_from_IBindStatusCallback(iface);
406
407     TRACE("(%p)->(%s %p)\n", This, debugstr_guid(riid), punk);
408
409     return dochost_object_available(This->doc_host, punk);
410 }
411
412 static const IBindStatusCallbackVtbl BindStatusCallbackVtbl = {
413     BindStatusCallback_QueryInterface,
414     BindStatusCallback_AddRef,
415     BindStatusCallback_Release,
416     BindStatusCallback_OnStartBinding,
417     BindStatusCallback_GetPriority,
418     BindStatusCallback_OnLowResource,
419     BindStatusCallback_OnProgress,
420     BindStatusCallback_OnStopBinding,
421     BindStatusCallback_GetBindInfo,
422     BindStatusCallback_OnDataAvailable,
423     BindStatusCallback_OnObjectAvailable
424 };
425
426 static inline BindStatusCallback *impl_from_IHttpNegotiate(IHttpNegotiate *iface)
427 {
428     return CONTAINING_RECORD(iface, BindStatusCallback, IHttpNegotiate_iface);
429 }
430
431 static HRESULT WINAPI HttpNegotiate_QueryInterface(IHttpNegotiate *iface,
432                                                    REFIID riid, void **ppv)
433 {
434     BindStatusCallback *This = impl_from_IHttpNegotiate(iface);
435     return IBindStatusCallback_QueryInterface(&This->IBindStatusCallback_iface, riid, ppv);
436 }
437
438 static ULONG WINAPI HttpNegotiate_AddRef(IHttpNegotiate *iface)
439 {
440     BindStatusCallback *This = impl_from_IHttpNegotiate(iface);
441     return IBindStatusCallback_AddRef(&This->IBindStatusCallback_iface);
442 }
443
444 static ULONG WINAPI HttpNegotiate_Release(IHttpNegotiate *iface)
445 {
446     BindStatusCallback *This = impl_from_IHttpNegotiate(iface);
447     return IBindStatusCallback_Release(&This->IBindStatusCallback_iface);
448 }
449
450 static HRESULT WINAPI HttpNegotiate_BeginningTransaction(IHttpNegotiate *iface,
451         LPCWSTR szURL, LPCWSTR szHeaders, DWORD dwReserved, LPWSTR *pszAdditionalHeaders)
452 {
453     BindStatusCallback *This = impl_from_IHttpNegotiate(iface);
454
455     TRACE("(%p)->(%s %s %d %p)\n", This, debugstr_w(szURL), debugstr_w(szHeaders),
456           dwReserved, pszAdditionalHeaders);
457
458     if(This->headers) {
459         int size = (strlenW(This->headers)+1)*sizeof(WCHAR);
460         *pszAdditionalHeaders = CoTaskMemAlloc(size);
461         memcpy(*pszAdditionalHeaders, This->headers, size);
462     }
463
464     return S_OK;
465 }
466
467 static HRESULT WINAPI HttpNegotiate_OnResponse(IHttpNegotiate *iface,
468         DWORD dwResponseCode, LPCWSTR szResponseHeaders, LPCWSTR szRequestHeaders,
469         LPWSTR *pszAdditionalRequestHeaders)
470 {
471     BindStatusCallback *This = impl_from_IHttpNegotiate(iface);
472     TRACE("(%p)->(%d %s %s %p)\n", This, dwResponseCode, debugstr_w(szResponseHeaders),
473           debugstr_w(szRequestHeaders), pszAdditionalRequestHeaders);
474     return S_OK;
475 }
476
477 static const IHttpNegotiateVtbl HttpNegotiateVtbl = {
478     HttpNegotiate_QueryInterface,
479     HttpNegotiate_AddRef,
480     HttpNegotiate_Release,
481     HttpNegotiate_BeginningTransaction,
482     HttpNegotiate_OnResponse
483 };
484
485 static inline BindStatusCallback *impl_from_IHttpSecurity(IHttpSecurity *iface)
486 {
487     return CONTAINING_RECORD(iface, BindStatusCallback, IHttpSecurity_iface);
488 }
489
490 static HRESULT WINAPI HttpSecurity_QueryInterface(IHttpSecurity *iface, REFIID riid, void **ppv)
491 {
492     BindStatusCallback *This = impl_from_IHttpSecurity(iface);
493     return IBindStatusCallback_QueryInterface(&This->IBindStatusCallback_iface, riid, ppv);
494 }
495
496 static ULONG WINAPI HttpSecurity_AddRef(IHttpSecurity *iface)
497 {
498     BindStatusCallback *This = impl_from_IHttpSecurity(iface);
499     return IBindStatusCallback_AddRef(&This->IBindStatusCallback_iface);
500 }
501
502 static ULONG WINAPI HttpSecurity_Release(IHttpSecurity *iface)
503 {
504     BindStatusCallback *This = impl_from_IHttpSecurity(iface);
505     return IBindStatusCallback_Release(&This->IBindStatusCallback_iface);
506 }
507
508 static HRESULT WINAPI HttpSecurity_GetWindow(IHttpSecurity *iface, REFGUID rguidReason, HWND *phwnd)
509 {
510     BindStatusCallback *This = impl_from_IHttpSecurity(iface);
511
512     TRACE("(%p)->(%s %p)\n", This, debugstr_guid(rguidReason), phwnd);
513
514     if(!This->doc_host)
515         return E_FAIL;
516
517     *phwnd = This->doc_host->frame_hwnd;
518     return S_OK;
519 }
520
521 static HRESULT WINAPI HttpSecurity_OnSecurityProblem(IHttpSecurity *iface, DWORD dwProblem)
522 {
523     BindStatusCallback *This = impl_from_IHttpSecurity(iface);
524     FIXME("(%p)->(%u)\n", This, dwProblem);
525     return S_FALSE;
526 }
527
528 static const IHttpSecurityVtbl HttpSecurityVtbl = {
529     HttpSecurity_QueryInterface,
530     HttpSecurity_AddRef,
531     HttpSecurity_Release,
532     HttpSecurity_GetWindow,
533     HttpSecurity_OnSecurityProblem
534 };
535
536 static BindStatusCallback *create_callback(DocHost *doc_host, LPCWSTR url, PBYTE post_data,
537         ULONG post_data_len, LPCWSTR headers)
538 {
539     BindStatusCallback *ret = heap_alloc(sizeof(BindStatusCallback));
540
541     ret->IBindStatusCallback_iface.lpVtbl = &BindStatusCallbackVtbl;
542     ret->IHttpNegotiate_iface.lpVtbl      = &HttpNegotiateVtbl;
543     ret->IHttpSecurity_iface.lpVtbl       = &HttpSecurityVtbl;
544
545     ret->ref = 1;
546     ret->url = heap_strdupW(url);
547     ret->post_data = NULL;
548     ret->post_data_len = post_data_len;
549     ret->headers = headers ? SysAllocString(headers) : NULL;
550
551     ret->doc_host = doc_host;
552     IOleClientSite_AddRef(&doc_host->IOleClientSite_iface);
553
554     ret->binding = NULL;
555
556     if(post_data) {
557         ret->post_data = GlobalAlloc(0, post_data_len);
558         memcpy(ret->post_data, post_data, post_data_len);
559     }
560
561     return ret;
562 }
563
564 static void on_before_navigate2(DocHost *This, LPCWSTR url, SAFEARRAY *post_data, LPWSTR headers, VARIANT_BOOL *cancel)
565 {
566     VARIANT var_url, var_flags, var_frame_name, var_post_data, var_post_data2, var_headers;
567     DISPPARAMS dispparams;
568     VARIANTARG params[7];
569
570     dispparams.cArgs = 7;
571     dispparams.cNamedArgs = 0;
572     dispparams.rgdispidNamedArgs = NULL;
573     dispparams.rgvarg = params;
574
575     This->busy = VARIANT_TRUE;
576
577     V_VT(params) = VT_BOOL|VT_BYREF;
578     V_BOOLREF(params) = cancel;
579
580     V_VT(params+1) = (VT_BYREF|VT_VARIANT);
581     V_VARIANTREF(params+1) = &var_headers;
582     V_VT(&var_headers) = VT_BSTR;
583     V_BSTR(&var_headers) = headers;
584
585     V_VT(params+2) = (VT_BYREF|VT_VARIANT);
586     V_VARIANTREF(params+2) = &var_post_data2;
587     V_VT(&var_post_data2) = (VT_BYREF|VT_VARIANT);
588     V_VARIANTREF(&var_post_data2) = &var_post_data;
589
590     if(post_data) {
591         V_VT(&var_post_data) = VT_UI1|VT_ARRAY;
592         V_ARRAY(&var_post_data) = post_data;
593     }else {
594         V_VT(&var_post_data) = VT_EMPTY;
595     }
596
597     V_VT(params+3) = (VT_BYREF|VT_VARIANT);
598     V_VARIANTREF(params+3) = &var_frame_name;
599     V_VT(&var_frame_name) = VT_BSTR;
600     V_BSTR(&var_frame_name) = NULL;
601
602     V_VT(params+4) = (VT_BYREF|VT_VARIANT);
603     V_VARIANTREF(params+4) = &var_flags;
604     V_VT(&var_flags) = VT_I4;
605     V_I4(&var_flags) = 0;
606
607     V_VT(params+5) = (VT_BYREF|VT_VARIANT);
608     V_VARIANTREF(params+5) = &var_url;
609     V_VT(&var_url) = VT_BSTR;
610     V_BSTR(&var_url) = SysAllocString(url);
611
612     V_VT(params+6) = (VT_DISPATCH);
613     V_DISPATCH(params+6) = (IDispatch*)This->wb;
614
615     call_sink(This->cps.wbe2, DISPID_BEFORENAVIGATE2, &dispparams);
616
617     SysFreeString(V_BSTR(&var_url));
618 }
619
620 /* FIXME: urlmon should handle it */
621 static BOOL try_application_url(LPCWSTR url)
622 {
623     SHELLEXECUTEINFOW exec_info;
624     WCHAR app[64];
625     HKEY hkey;
626     DWORD res, type;
627     HRESULT hres;
628
629     static const WCHAR wszURLProtocol[] = {'U','R','L',' ','P','r','o','t','o','c','o','l',0};
630
631     hres = CoInternetParseUrl(url, PARSE_SCHEMA, 0, app, sizeof(app)/sizeof(WCHAR), NULL, 0);
632     if(FAILED(hres))
633         return FALSE;
634
635     res = RegOpenKeyW(HKEY_CLASSES_ROOT, app, &hkey);
636     if(res != ERROR_SUCCESS)
637         return FALSE;
638
639     res = RegQueryValueExW(hkey, wszURLProtocol, NULL, &type, NULL, NULL);
640     RegCloseKey(hkey);
641     if(res != ERROR_SUCCESS || type != REG_SZ)
642         return FALSE;
643
644     TRACE("opening application %s\n", debugstr_w(app));
645
646     memset(&exec_info, 0, sizeof(exec_info));
647     exec_info.cbSize = sizeof(exec_info);
648     exec_info.lpFile = url;
649     exec_info.nShow = SW_SHOW;
650
651     return ShellExecuteExW(&exec_info);
652 }
653
654 static HRESULT create_moniker(LPCWSTR url, IMoniker **mon)
655 {
656     WCHAR new_url[INTERNET_MAX_URL_LENGTH];
657     DWORD size;
658     HRESULT hres;
659
660     if(PathIsURLW(url))
661         return CreateURLMoniker(NULL, url, mon);
662
663     size = sizeof(new_url)/sizeof(WCHAR);
664     hres = UrlApplySchemeW(url, new_url, &size, URL_APPLY_GUESSSCHEME | URL_APPLY_GUESSFILE);
665     TRACE("was %s got %s\n", debugstr_w(url), debugstr_w(new_url));
666     if(FAILED(hres)) {
667         WARN("UrlApplyScheme failed: %08x\n", hres);
668         return hres;
669     }
670
671     return CreateURLMoniker(NULL, new_url, mon);
672 }
673
674 static HRESULT bind_to_object(DocHost *This, IMoniker *mon, LPCWSTR url, IBindCtx *bindctx,
675                               IBindStatusCallback *callback)
676 {
677     IUnknown *unk = NULL;
678     WCHAR *display_name;
679     HRESULT hres;
680
681     if(mon) {
682         IMoniker_AddRef(mon);
683     }else {
684         hres = create_moniker(url, &mon);
685         if(FAILED(hres))
686             return hres;
687     }
688
689     hres = IMoniker_GetDisplayName(mon, 0, NULL, &display_name);
690     if(FAILED(hres)) {
691         FIXME("GetDisplayName failed: %08x\n", hres);
692         return hres;
693     }
694
695     hres = set_dochost_url(This, display_name);
696     CoTaskMemFree(display_name);
697     if(FAILED(hres))
698         return hres;
699
700     IBindCtx_RegisterObjectParam(bindctx, (LPOLESTR)SZ_HTML_CLIENTSITE_OBJECTPARAM,
701                                  (IUnknown*)&This->IOleClientSite_iface);
702
703     hres = IMoniker_BindToObject(mon, bindctx, NULL, &IID_IUnknown, (void**)&unk);
704     if(SUCCEEDED(hres)) {
705         hres = S_OK;
706         if(unk)
707             IUnknown_Release(unk);
708     }else if(try_application_url(url)) {
709         hres = S_OK;
710     }else {
711         FIXME("BindToObject failed: %08x\n", hres);
712     }
713
714     IMoniker_Release(mon);
715     return S_OK;
716 }
717
718 static void html_window_navigate(DocHost *This, IHTMLPrivateWindow *window, BSTR url, BSTR headers, SAFEARRAY *post_data)
719 {
720     VARIANT headers_var, post_data_var;
721     BSTR empty_str;
722     HRESULT hres;
723
724     hres = set_dochost_url(This, url);
725     if(FAILED(hres))
726         return;
727
728     empty_str = SysAllocStringLen(NULL, 0);
729
730     if(headers) {
731         V_VT(&headers_var) = VT_BSTR;
732         V_BSTR(&headers_var) = headers;
733     }else {
734         V_VT(&headers_var) = VT_EMPTY;
735     }
736
737     if(post_data) {
738         V_VT(&post_data_var) = VT_UI1|VT_ARRAY;
739         V_ARRAY(&post_data_var) = post_data;
740     }else {
741         V_VT(&post_data_var) = VT_EMPTY;
742     }
743
744     set_doc_state(This, READYSTATE_LOADING);
745     hres = IHTMLPrivateWindow_SuperNavigate(window, url, empty_str, NULL, NULL, &post_data_var, &headers_var, 0);
746     SysFreeString(empty_str);
747     if(FAILED(hres))
748         WARN("SuprtNavigate failed: %08x\n", hres);
749 }
750
751 typedef struct {
752     task_header_t header;
753     BSTR url;
754     BSTR headers;
755     SAFEARRAY *post_data;
756     BOOL async_notif;
757 } task_doc_navigate_t;
758
759 static void doc_navigate_task_destr(task_header_t *t)
760 {
761     task_doc_navigate_t *task = (task_doc_navigate_t*)t;
762
763     SysFreeString(task->url);
764     SysFreeString(task->headers);
765     if(task->post_data)
766         SafeArrayDestroy(task->post_data);
767     heap_free(task);
768 }
769
770 static void doc_navigate_proc(DocHost *This, task_header_t *t)
771 {
772     task_doc_navigate_t *task = (task_doc_navigate_t*)t;
773     IHTMLPrivateWindow *priv_window;
774     HRESULT hres;
775
776     if(!This->doc_navigate) {
777         ERR("Skip nav\n");
778         return;
779     }
780
781     if(task->async_notif) {
782         VARIANT_BOOL cancel = VARIANT_FALSE;
783         on_before_navigate2(This, task->url, task->post_data, task->headers, &cancel);
784         if(cancel) {
785             TRACE("Navigation canceled\n");
786             return;
787         }
788     }
789
790     hres = IUnknown_QueryInterface(This->doc_navigate, &IID_IHTMLPrivateWindow, (void**)&priv_window);
791     if(SUCCEEDED(hres)) {
792         html_window_navigate(This, priv_window, task->url, task->headers, task->post_data);
793         IHTMLPrivateWindow_Release(priv_window);
794     }else {
795         WARN("Could not get IHTMLPrivateWindow iface: %08x\n", hres);
796     }
797 }
798
799 static HRESULT async_doc_navigate(DocHost *This, LPCWSTR url, LPCWSTR headers, PBYTE post_data, ULONG post_data_size,
800         BOOL async_notif)
801 {
802     task_doc_navigate_t *task;
803
804     TRACE("%s\n", debugstr_w(url));
805
806     task = heap_alloc_zero(sizeof(*task));
807     if(!task)
808         return E_OUTOFMEMORY;
809
810     task->url = SysAllocString(url);
811     if(!task->url) {
812         doc_navigate_task_destr(&task->header);
813         return E_OUTOFMEMORY;
814     }
815
816     if(headers) {
817         task->headers = SysAllocString(headers);
818         if(!task->headers) {
819             doc_navigate_task_destr(&task->header);
820             return E_OUTOFMEMORY;
821         }
822     }
823
824     if(post_data) {
825         task->post_data = SafeArrayCreateVector(VT_UI1, 0, post_data_size);
826         if(!task->post_data) {
827             doc_navigate_task_destr(&task->header);
828             return E_OUTOFMEMORY;
829         }
830
831         memcpy(task->post_data->pvData, post_data, post_data_size);
832     }
833
834     if(!async_notif) {
835         VARIANT_BOOL cancel = VARIANT_FALSE;
836
837         on_before_navigate2(This, task->url, task->post_data, task->headers, &cancel);
838         if(cancel) {
839             TRACE("Navigation canceled\n");
840             doc_navigate_task_destr(&task->header);
841             return S_OK;
842         }
843     }
844
845     task->async_notif = async_notif;
846     abort_dochost_tasks(This, doc_navigate_proc);
847     push_dochost_task(This, &task->header, doc_navigate_proc, doc_navigate_task_destr, FALSE);
848     return S_OK;
849 }
850
851 static HRESULT navigate_bsc(DocHost *This, BindStatusCallback *bsc, IMoniker *mon)
852 {
853     VARIANT_BOOL cancel = VARIANT_FALSE;
854     SAFEARRAY *post_data = NULL;
855     IBindCtx *bindctx;
856     HRESULT hres;
857
858     set_doc_state(This, READYSTATE_LOADING);
859
860     if(bsc->post_data) {
861         post_data = SafeArrayCreateVector(VT_UI1, 0, bsc->post_data_len);
862         memcpy(post_data->pvData, post_data, bsc->post_data_len);
863     }
864
865     on_before_navigate2(This, bsc->url, post_data, bsc->headers, &cancel);
866     if(post_data)
867         SafeArrayDestroy(post_data);
868     if(cancel) {
869         FIXME("Navigation canceled\n");
870         return S_OK;
871     }
872
873     if(This->document)
874         deactivate_document(This);
875
876     CreateAsyncBindCtx(0, &bsc->IBindStatusCallback_iface, 0, &bindctx);
877
878     if(This->frame)
879         IOleInPlaceFrame_EnableModeless(This->frame, FALSE);
880
881     hres = bind_to_object(This, mon, bsc->url, bindctx, &bsc->IBindStatusCallback_iface);
882
883     if(This->frame)
884         IOleInPlaceFrame_EnableModeless(This->frame, TRUE);
885
886     IBindCtx_Release(bindctx);
887
888     return hres;
889 }
890
891 typedef struct {
892     task_header_t header;
893     BindStatusCallback *bsc;
894 } task_navigate_bsc_t;
895
896 static void navigate_bsc_task_destr(task_header_t *t)
897 {
898     task_navigate_bsc_t *task = (task_navigate_bsc_t*)t;
899
900     IBindStatusCallback_Release(&task->bsc->IBindStatusCallback_iface);
901     heap_free(task);
902 }
903
904 static void navigate_bsc_proc(DocHost *This, task_header_t *t)
905 {
906     task_navigate_bsc_t *task = (task_navigate_bsc_t*)t;
907
908     if(!This->hwnd)
909         create_doc_view_hwnd(This);
910
911     navigate_bsc(This, task->bsc, NULL);
912 }
913
914
915 HRESULT navigate_url(DocHost *This, LPCWSTR url, const VARIANT *Flags,
916                      const VARIANT *TargetFrameName, VARIANT *PostData, VARIANT *Headers)
917 {
918     PBYTE post_data = NULL;
919     ULONG post_data_len = 0;
920     LPWSTR headers = NULL;
921     HRESULT hres = S_OK;
922
923     TRACE("navigating to %s\n", debugstr_w(url));
924
925     if((Flags && V_VT(Flags) != VT_EMPTY)
926        || (TargetFrameName && V_VT(TargetFrameName) != VT_EMPTY))
927         FIXME("Unsupported args (Flags %p:%d; TargetFrameName %p:%d)\n",
928                 Flags, Flags ? V_VT(Flags) : -1, TargetFrameName,
929                 TargetFrameName ? V_VT(TargetFrameName) : -1);
930
931     if(PostData && V_VT(PostData) == (VT_ARRAY | VT_UI1) && V_ARRAY(PostData)) {
932         SafeArrayAccessData(V_ARRAY(PostData), (void**)&post_data);
933         post_data_len = V_ARRAY(PostData)->rgsabound[0].cElements;
934     }
935
936     if(Headers && V_VT(Headers) == VT_BSTR) {
937         headers = V_BSTR(Headers);
938         TRACE("Headers: %s\n", debugstr_w(headers));
939     }
940
941     set_doc_state(This, READYSTATE_LOADING);
942     This->ready_state = READYSTATE_LOADING;
943
944     if(This->doc_navigate) {
945         WCHAR new_url[INTERNET_MAX_URL_LENGTH];
946
947         if(PathIsURLW(url)) {
948             new_url[0] = 0;
949         }else {
950             DWORD size;
951
952             size = sizeof(new_url)/sizeof(WCHAR);
953             hres = UrlApplySchemeW(url, new_url, &size,
954                     URL_APPLY_GUESSSCHEME | URL_APPLY_GUESSFILE | URL_APPLY_DEFAULT);
955             if(FAILED(hres)) {
956                 WARN("UrlApplyScheme failed: %08x\n", hres);
957                 new_url[0] = 0;
958             }
959         }
960
961         hres = async_doc_navigate(This, *new_url ? new_url : url, headers, post_data,
962                 post_data_len, TRUE);
963     }else {
964         task_navigate_bsc_t *task;
965
966         task = heap_alloc(sizeof(*task));
967         task->bsc = create_callback(This, url, post_data, post_data_len, headers);
968         push_dochost_task(This, &task->header, navigate_bsc_proc, navigate_bsc_task_destr, This->url == NULL);
969     }
970
971     if(post_data)
972         SafeArrayUnaccessData(V_ARRAY(PostData));
973
974     return hres;
975 }
976
977 static HRESULT navigate_hlink(DocHost *This, IMoniker *mon, IBindCtx *bindctx,
978                               IBindStatusCallback *callback)
979 {
980     IHttpNegotiate *http_negotiate;
981     BindStatusCallback *bsc;
982     PBYTE post_data = NULL;
983     ULONG post_data_len = 0;
984     LPWSTR headers = NULL, url;
985     BINDINFO bindinfo;
986     DWORD bindf = 0;
987     HRESULT hres;
988
989     TRACE("\n");
990
991     hres = IMoniker_GetDisplayName(mon, 0, NULL, &url);
992     if(FAILED(hres))
993         FIXME("GetDisplayName failed: %08x\n", hres);
994
995     hres = IBindStatusCallback_QueryInterface(callback, &IID_IHttpNegotiate,
996                                               (void**)&http_negotiate);
997     if(SUCCEEDED(hres)) {
998         static const WCHAR null_string[] = {0};
999
1000         IHttpNegotiate_BeginningTransaction(http_negotiate, null_string, null_string, 0,
1001                                             &headers);
1002         IHttpNegotiate_Release(http_negotiate);
1003     }
1004
1005     memset(&bindinfo, 0, sizeof(bindinfo));
1006     bindinfo.cbSize = sizeof(bindinfo);
1007
1008     hres = IBindStatusCallback_GetBindInfo(callback, &bindf, &bindinfo);
1009     dump_BINDINFO(&bindinfo);
1010     if(bindinfo.dwBindVerb == BINDVERB_POST) {
1011         post_data_len = bindinfo.cbstgmedData;
1012         if(post_data_len)
1013             post_data = bindinfo.stgmedData.u.hGlobal;
1014     }
1015
1016     if(This->doc_navigate) {
1017         hres = async_doc_navigate(This, url, headers, post_data, post_data_len, FALSE);
1018     }else {
1019         bsc = create_callback(This, url, post_data, post_data_len, headers);
1020         hres = navigate_bsc(This, bsc, mon);
1021         IBindStatusCallback_Release(&bsc->IBindStatusCallback_iface);
1022     }
1023
1024     CoTaskMemFree(url);
1025     CoTaskMemFree(headers);
1026     ReleaseBindInfo(&bindinfo);
1027
1028     return hres;
1029 }
1030
1031 HRESULT go_home(DocHost *This)
1032 {
1033     HKEY hkey;
1034     DWORD res, type, size;
1035     WCHAR wszPageName[MAX_PATH];
1036     static const WCHAR wszAboutBlank[] = {'a','b','o','u','t',':','b','l','a','n','k',0};
1037     static const WCHAR wszStartPage[] = {'S','t','a','r','t',' ','P','a','g','e',0};
1038     static const WCHAR wszSubKey[] = {'S','o','f','t','w','a','r','e','\\',
1039                                       'M','i','c','r','o','s','o','f','t','\\',
1040                                       'I','n','t','e','r','n','e','t',' ','E','x','p','l','o','r','e','r','\\',
1041                                       'M','a','i','n',0};
1042
1043     res = RegOpenKeyW(HKEY_CURRENT_USER, wszSubKey, &hkey);
1044     if (res != ERROR_SUCCESS)
1045         return navigate_url(This, wszAboutBlank, NULL, NULL, NULL, NULL);
1046
1047     size = sizeof(wszPageName);
1048     res = RegQueryValueExW(hkey, wszStartPage, NULL, &type, (LPBYTE)wszPageName, &size);
1049     RegCloseKey(hkey);
1050     if (res != ERROR_SUCCESS || type != REG_SZ)
1051         return navigate_url(This, wszAboutBlank, NULL, NULL, NULL, NULL);
1052
1053     return navigate_url(This, wszPageName, NULL, NULL, NULL, NULL);
1054 }
1055
1056 HRESULT go_back(DocHost *This)
1057 {
1058     WCHAR *url;
1059     HRESULT hres;
1060
1061     if(!This->travellog_position) {
1062         WARN("No history available\n");
1063         return E_FAIL;
1064     }
1065
1066     url = This->travellog[--This->travellog_position].url;
1067
1068     if(This->doc_navigate) {
1069         hres = async_doc_navigate(This, url, NULL, NULL, 0, FALSE);
1070     }else {
1071         FIXME("unsupported doc_navigate FALSE\n");
1072         hres = E_NOTIMPL;
1073     }
1074
1075     heap_free(url);
1076     return hres;
1077 }
1078
1079 HRESULT get_location_url(DocHost *This, BSTR *ret)
1080 {
1081     FIXME("semi-stub\n");
1082
1083     *ret = This->url ? SysAllocString(This->url) : SysAllocStringLen(NULL, 0);
1084     if(!*ret)
1085         return E_OUTOFMEMORY;
1086
1087     return This->url ? S_OK : S_FALSE;
1088 }
1089
1090 static inline HlinkFrame *impl_from_IHlinkFrame(IHlinkFrame *iface)
1091 {
1092     return CONTAINING_RECORD(iface, HlinkFrame, IHlinkFrame_iface);
1093 }
1094
1095 static HRESULT WINAPI HlinkFrame_QueryInterface(IHlinkFrame *iface, REFIID riid, void **ppv)
1096 {
1097     HlinkFrame *This = impl_from_IHlinkFrame(iface);
1098     return IUnknown_QueryInterface(This->outer, riid, ppv);
1099 }
1100
1101 static ULONG WINAPI HlinkFrame_AddRef(IHlinkFrame *iface)
1102 {
1103     HlinkFrame *This = impl_from_IHlinkFrame(iface);
1104     return IUnknown_AddRef(This->outer);
1105 }
1106
1107 static ULONG WINAPI HlinkFrame_Release(IHlinkFrame *iface)
1108 {
1109     HlinkFrame *This = impl_from_IHlinkFrame(iface);
1110     return IUnknown_Release(This->outer);
1111 }
1112
1113 static HRESULT WINAPI HlinkFrame_SetBrowseContext(IHlinkFrame *iface,
1114                                                   IHlinkBrowseContext *pihlbc)
1115 {
1116     HlinkFrame *This = impl_from_IHlinkFrame(iface);
1117     FIXME("(%p)->(%p)\n", This, pihlbc);
1118     return E_NOTIMPL;
1119 }
1120
1121 static HRESULT WINAPI HlinkFrame_GetBrowseContext(IHlinkFrame *iface,
1122                                                   IHlinkBrowseContext **ppihlbc)
1123 {
1124     HlinkFrame *This = impl_from_IHlinkFrame(iface);
1125     FIXME("(%p)->(%p)\n", This, ppihlbc);
1126     return E_NOTIMPL;
1127 }
1128
1129 static HRESULT WINAPI HlinkFrame_Navigate(IHlinkFrame *iface, DWORD grfHLNF, LPBC pbc,
1130                                           IBindStatusCallback *pibsc, IHlink *pihlNavigate)
1131 {
1132     HlinkFrame *This = impl_from_IHlinkFrame(iface);
1133     IMoniker *mon;
1134     LPWSTR location = NULL;
1135
1136     TRACE("(%p)->(%08x %p %p %p)\n", This, grfHLNF, pbc, pibsc, pihlNavigate);
1137
1138     if(grfHLNF)
1139         FIXME("unsupported grfHLNF=%08x\n", grfHLNF);
1140
1141     /* Windows calls GetTargetFrameName here. */
1142
1143     IHlink_GetMonikerReference(pihlNavigate, 1, &mon, &location);
1144
1145     if(location) {
1146         FIXME("location = %s\n", debugstr_w(location));
1147         CoTaskMemFree(location);
1148     }
1149
1150     /* Windows calls GetHlinkSite here */
1151
1152     if(grfHLNF & HLNF_OPENINNEWWINDOW) {
1153         FIXME("Not supported HLNF_OPENINNEWWINDOW\n");
1154         return E_NOTIMPL;
1155     }
1156
1157     return navigate_hlink(This->doc_host, mon, pbc, pibsc);
1158 }
1159
1160 static HRESULT WINAPI HlinkFrame_OnNavigate(IHlinkFrame *iface, DWORD grfHLNF,
1161         IMoniker *pimkTarget, LPCWSTR pwzLocation, LPCWSTR pwzFriendlyName, DWORD dwreserved)
1162 {
1163     HlinkFrame *This = impl_from_IHlinkFrame(iface);
1164     FIXME("(%p)->(%08x %p %s %s %d)\n", This, grfHLNF, pimkTarget, debugstr_w(pwzLocation),
1165           debugstr_w(pwzFriendlyName), dwreserved);
1166     return E_NOTIMPL;
1167 }
1168
1169 static HRESULT WINAPI HlinkFrame_UpdateHlink(IHlinkFrame *iface, ULONG uHLID,
1170         IMoniker *pimkTarget, LPCWSTR pwzLocation, LPCWSTR pwzFriendlyName)
1171 {
1172     HlinkFrame *This = impl_from_IHlinkFrame(iface);
1173     FIXME("(%p)->(%u %p %s %s)\n", This, uHLID, pimkTarget, debugstr_w(pwzLocation),
1174           debugstr_w(pwzFriendlyName));
1175     return E_NOTIMPL;
1176 }
1177
1178 static const IHlinkFrameVtbl HlinkFrameVtbl = {
1179     HlinkFrame_QueryInterface,
1180     HlinkFrame_AddRef,
1181     HlinkFrame_Release,
1182     HlinkFrame_SetBrowseContext,
1183     HlinkFrame_GetBrowseContext,
1184     HlinkFrame_Navigate,
1185     HlinkFrame_OnNavigate,
1186     HlinkFrame_UpdateHlink
1187 };
1188
1189 static inline HlinkFrame *impl_from_ITargetFrame2(ITargetFrame2 *iface)
1190 {
1191     return CONTAINING_RECORD(iface, HlinkFrame, IHlinkFrame_iface);
1192 }
1193
1194 static HRESULT WINAPI TargetFrame2_QueryInterface(ITargetFrame2 *iface, REFIID riid, void **ppv)
1195 {
1196     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1197     return IUnknown_QueryInterface(This->outer, riid, ppv);
1198 }
1199
1200 static ULONG WINAPI TargetFrame2_AddRef(ITargetFrame2 *iface)
1201 {
1202     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1203     return IUnknown_AddRef(This->outer);
1204 }
1205
1206 static ULONG WINAPI TargetFrame2_Release(ITargetFrame2 *iface)
1207 {
1208     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1209     return IUnknown_Release(This->outer);
1210 }
1211
1212 static HRESULT WINAPI TargetFrame2_SetFrameName(ITargetFrame2 *iface, LPCWSTR pszFrameName)
1213 {
1214     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1215     FIXME("(%p)->(%s)\n", This, debugstr_w(pszFrameName));
1216     return E_NOTIMPL;
1217 }
1218
1219 static HRESULT WINAPI TargetFrame2_GetFrameName(ITargetFrame2 *iface, LPWSTR *ppszFrameName)
1220 {
1221     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1222     FIXME("(%p)->(%p)\n", This, ppszFrameName);
1223     return E_NOTIMPL;
1224 }
1225
1226 static HRESULT WINAPI TargetFrame2_GetParentFrame(ITargetFrame2 *iface, IUnknown **ppunkParent)
1227 {
1228     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1229     FIXME("(%p)->(%p)\n", This, ppunkParent);
1230     return E_NOTIMPL;
1231 }
1232
1233 static HRESULT WINAPI TargetFrame2_SetFrameSrc(ITargetFrame2 *iface, LPCWSTR pszFrameSrc)
1234 {
1235     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1236     FIXME("(%p)->(%s)\n", This, debugstr_w(pszFrameSrc));
1237     return E_NOTIMPL;
1238 }
1239
1240 static HRESULT WINAPI TargetFrame2_GetFrameSrc(ITargetFrame2 *iface, LPWSTR *ppszFrameSrc)
1241 {
1242     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1243     FIXME("(%p)->()\n", This);
1244     return E_NOTIMPL;
1245 }
1246
1247 static HRESULT WINAPI TargetFrame2_GetFramesContainer(ITargetFrame2 *iface, IOleContainer **ppContainer)
1248 {
1249     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1250     FIXME("(%p)->(%p)\n", This, ppContainer);
1251     return E_NOTIMPL;
1252 }
1253
1254 static HRESULT WINAPI TargetFrame2_SetFrameOptions(ITargetFrame2 *iface, DWORD dwFlags)
1255 {
1256     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1257     FIXME("(%p)->(%x)\n", This, dwFlags);
1258     return E_NOTIMPL;
1259 }
1260
1261 static HRESULT WINAPI TargetFrame2_GetFrameOptions(ITargetFrame2 *iface, DWORD *pdwFlags)
1262 {
1263     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1264     FIXME("(%p)->(%p)\n", This, pdwFlags);
1265     return E_NOTIMPL;
1266 }
1267
1268 static HRESULT WINAPI TargetFrame2_SetFrameMargins(ITargetFrame2 *iface, DWORD dwWidth, DWORD dwHeight)
1269 {
1270     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1271     FIXME("(%p)->(%d %d)\n", This, dwWidth, dwHeight);
1272     return E_NOTIMPL;
1273 }
1274
1275 static HRESULT WINAPI TargetFrame2_GetFrameMargins(ITargetFrame2 *iface, DWORD *pdwWidth, DWORD *pdwHeight)
1276 {
1277     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1278     FIXME("(%p)->(%p %p)\n", This, pdwWidth, pdwHeight);
1279     return E_NOTIMPL;
1280 }
1281
1282 static HRESULT WINAPI TargetFrame2_FindFrame(ITargetFrame2 *iface, LPCWSTR pszTargetName, DWORD dwFlags, IUnknown **ppunkTargetFrame)
1283 {
1284     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1285     FIXME("(%p)->(%s %x %p)\n", This, debugstr_w(pszTargetName), dwFlags, ppunkTargetFrame);
1286     return E_NOTIMPL;
1287 }
1288
1289 static HRESULT WINAPI TargetFrame2_GetTargetAlias(ITargetFrame2 *iface, LPCWSTR pszTargetName, LPWSTR *ppszTargetAlias)
1290 {
1291     HlinkFrame *This = impl_from_ITargetFrame2(iface);
1292     FIXME("(%p)->(%s %p)\n", This, debugstr_w(pszTargetName), ppszTargetAlias);
1293     return E_NOTIMPL;
1294 }
1295
1296 static const ITargetFrame2Vtbl TargetFrame2Vtbl = {
1297     TargetFrame2_QueryInterface,
1298     TargetFrame2_AddRef,
1299     TargetFrame2_Release,
1300     TargetFrame2_SetFrameName,
1301     TargetFrame2_GetFrameName,
1302     TargetFrame2_GetParentFrame,
1303     TargetFrame2_SetFrameSrc,
1304     TargetFrame2_GetFrameSrc,
1305     TargetFrame2_GetFramesContainer,
1306     TargetFrame2_SetFrameOptions,
1307     TargetFrame2_GetFrameOptions,
1308     TargetFrame2_SetFrameMargins,
1309     TargetFrame2_GetFrameMargins,
1310     TargetFrame2_FindFrame,
1311     TargetFrame2_GetTargetAlias
1312 };
1313
1314 static inline HlinkFrame *impl_from_ITargetFramePriv2(ITargetFramePriv2 *iface)
1315 {
1316     return CONTAINING_RECORD(iface, HlinkFrame, ITargetFramePriv2_iface);
1317 }
1318
1319 static HRESULT WINAPI TargetFramePriv2_QueryInterface(ITargetFramePriv2 *iface, REFIID riid, void **ppv)
1320 {
1321     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1322     return IUnknown_QueryInterface(This->outer, riid, ppv);
1323 }
1324
1325 static ULONG WINAPI TargetFramePriv2_AddRef(ITargetFramePriv2 *iface)
1326 {
1327     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1328     return IUnknown_AddRef(This->outer);
1329 }
1330
1331 static ULONG WINAPI TargetFramePriv2_Release(ITargetFramePriv2 *iface)
1332 {
1333     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1334     return IUnknown_Release(This->outer);
1335 }
1336
1337 static HRESULT WINAPI TargetFramePriv2_FindFrameDownwards(ITargetFramePriv2 *iface,
1338         LPCWSTR pszTargetName, DWORD dwFlags, IUnknown **ppunkTargetFrame)
1339 {
1340     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1341     FIXME("(%p)->(%s %x %p)\n", This, debugstr_w(pszTargetName), dwFlags, ppunkTargetFrame);
1342     return E_NOTIMPL;
1343 }
1344
1345 static HRESULT WINAPI TargetFramePriv2_FindFrameInContext(ITargetFramePriv2 *iface,
1346         LPCWSTR pszTargetName, IUnknown *punkContextFrame, DWORD dwFlags, IUnknown **ppunkTargetFrame)
1347 {
1348     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1349     FIXME("(%p)->(%s %p %x %p)\n", This, debugstr_w(pszTargetName), punkContextFrame, dwFlags, ppunkTargetFrame);
1350     return E_NOTIMPL;
1351 }
1352
1353 static HRESULT WINAPI TargetFramePriv2_OnChildFrameActivate(ITargetFramePriv2 *iface, IUnknown *pUnkChildFrame)
1354 {
1355     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1356     FIXME("(%p)->(%p)\n", This, pUnkChildFrame);
1357     return E_NOTIMPL;
1358 }
1359
1360 static HRESULT WINAPI TargetFramePriv2_OnChildFrameDeactivate(ITargetFramePriv2 *iface, IUnknown *pUnkChildFrame)
1361 {
1362     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1363     FIXME("(%p)->(%p)\n", This, pUnkChildFrame);
1364     return E_NOTIMPL;
1365 }
1366
1367 static HRESULT WINAPI TargetFramePriv2_NavigateHack(ITargetFramePriv2 *iface, DWORD grfHLNF, LPBC pbc,
1368         IBindStatusCallback *pibsc, LPCWSTR pszTargetName, LPCWSTR pszUrl, LPCWSTR pszLocation)
1369 {
1370     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1371     FIXME("(%p)->(%x %p %p %s %s %s)\n", This, grfHLNF, pbc, pibsc, debugstr_w(pszTargetName),
1372           debugstr_w(pszUrl), debugstr_w(pszLocation));
1373     return E_NOTIMPL;
1374 }
1375
1376 static HRESULT WINAPI TargetFramePriv2_FindBrowserByIndex(ITargetFramePriv2 *iface, DWORD dwID, IUnknown **ppunkBrowser)
1377 {
1378     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1379     FIXME("(%p)->(%d %p)\n", This, dwID, ppunkBrowser);
1380     return E_NOTIMPL;
1381 }
1382
1383 static HRESULT WINAPI TargetFramePriv2_AggregatedNavigation2(ITargetFramePriv2 *iface, DWORD grfHLNF, LPBC pbc,
1384         IBindStatusCallback *pibsc, LPCWSTR pszTargetName, IUri *pUri, LPCWSTR pszLocation)
1385 {
1386     HlinkFrame *This = impl_from_ITargetFramePriv2(iface);
1387     IMoniker *mon;
1388     HRESULT hres;
1389
1390     TRACE("(%p)->(%x %p %p %s %p %s)\n", This, grfHLNF, pbc, pibsc, debugstr_w(pszTargetName),
1391           pUri, debugstr_w(pszLocation));
1392
1393     /*
1394      * NOTE: This is an undocumented function. It seems to be working the way it's implemented,
1395      * but I couldn't get its tests working. It's used by mshtml to load content in a new
1396      * instance of browser.
1397      */
1398
1399     hres = CreateURLMonikerEx2(NULL, pUri, &mon, 0);
1400     if(FAILED(hres))
1401         return hres;
1402
1403     hres = navigate_hlink(This->doc_host, mon, pbc, pibsc);
1404     IMoniker_Release(mon);
1405     return hres;
1406 }
1407
1408 static const ITargetFramePriv2Vtbl TargetFramePriv2Vtbl = {
1409     TargetFramePriv2_QueryInterface,
1410     TargetFramePriv2_AddRef,
1411     TargetFramePriv2_Release,
1412     TargetFramePriv2_FindFrameDownwards,
1413     TargetFramePriv2_FindFrameInContext,
1414     TargetFramePriv2_OnChildFrameActivate,
1415     TargetFramePriv2_OnChildFrameDeactivate,
1416     TargetFramePriv2_NavigateHack,
1417     TargetFramePriv2_FindBrowserByIndex,
1418     TargetFramePriv2_AggregatedNavigation2
1419 };
1420
1421 BOOL HlinkFrame_QI(HlinkFrame *This, REFIID riid, void **ppv)
1422 {
1423     if(IsEqualGUID(&IID_IHlinkFrame, riid)) {
1424         TRACE("(%p)->(IID_IHlinkFrame %p)\n", This, ppv);
1425         *ppv = &This->IHlinkFrame_iface;
1426     }else if(IsEqualGUID(&IID_ITargetFrame2, riid)) {
1427         TRACE("(%p)->(IID_ITargetFrame2 %p)\n", This, ppv);
1428         *ppv = &This->ITargetFrame2_iface;
1429     }else if(IsEqualGUID(&IID_ITargetFramePriv, riid)) {
1430         TRACE("(%p)->(IID_ITargetFramePriv %p)\n", This, ppv);
1431         *ppv = &This->ITargetFramePriv2_iface;
1432     }else if(IsEqualGUID(&IID_ITargetFramePriv2, riid)) {
1433         TRACE("(%p)->(IID_ITargetFramePriv2 %p)\n", This, ppv);
1434         *ppv = &This->ITargetFramePriv2_iface;
1435     }else {
1436         return FALSE;
1437     }
1438
1439     IUnknown_AddRef((IUnknown*)*ppv);
1440     return TRUE;
1441 }
1442
1443 void HlinkFrame_Init(HlinkFrame *This, IUnknown *outer, DocHost *doc_host)
1444 {
1445     This->IHlinkFrame_iface.lpVtbl   = &HlinkFrameVtbl;
1446     This->ITargetFrame2_iface.lpVtbl = &TargetFrame2Vtbl;
1447     This->ITargetFramePriv2_iface.lpVtbl = &TargetFramePriv2Vtbl;
1448
1449     This->outer = outer;
1450     This->doc_host = doc_host;
1451 }