crypt32: NULL ptr could leak into function (Coverity).
[wine] / dlls / mshtml / navigate.c
1 /*
2  * Copyright 2006-2010 Jacek Caban for CodeWeavers
3  *
4  * This library is free software; you can redistribute it and/or
5  * modify it under the terms of the GNU Lesser General Public
6  * License as published by the Free Software Foundation; either
7  * version 2.1 of the License, or (at your option) any later version.
8  *
9  * This library is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
12  * Lesser General Public License for more details.
13  *
14  * You should have received a copy of the GNU Lesser General Public
15  * License along with this library; if not, write to the Free Software
16  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
17  */
18
19 #include "config.h"
20
21 #include <stdarg.h>
22
23 #define COBJMACROS
24 #define NONAMELESSUNION
25 #define NONAMELESSSTRUCT
26
27 #include "windef.h"
28 #include "winbase.h"
29 #include "winuser.h"
30 #include "winreg.h"
31 #include "ole2.h"
32 #include "hlguids.h"
33 #include "shlguid.h"
34 #include "wininet.h"
35 #include "shlwapi.h"
36
37 #include "wine/debug.h"
38 #include "wine/unicode.h"
39
40 #include "mshtml_private.h"
41
42 WINE_DEFAULT_DEBUG_CHANNEL(mshtml);
43
44 #define CONTENT_LENGTH "Content-Length"
45 #define UTF16_STR "utf-16"
46
47 typedef struct {
48     const nsIInputStreamVtbl *lpInputStreamVtbl;
49
50     LONG ref;
51
52     char buf[1024];
53     DWORD buf_size;
54 } nsProtocolStream;
55
56 #define NSINSTREAM(x) ((nsIInputStream*) &(x)->lpInputStreamVtbl)
57
58 typedef struct {
59     void (*destroy)(BSCallback*);
60     HRESULT (*init_bindinfo)(BSCallback*);
61     HRESULT (*start_binding)(BSCallback*);
62     HRESULT (*stop_binding)(BSCallback*,HRESULT);
63     HRESULT (*read_data)(BSCallback*,IStream*);
64     HRESULT (*on_progress)(BSCallback*,ULONG,LPCWSTR);
65     HRESULT (*on_response)(BSCallback*,DWORD,LPCWSTR);
66     HRESULT (*beginning_transaction)(BSCallback*,WCHAR**);
67 } BSCallbackVtbl;
68
69 struct BSCallback {
70     const IBindStatusCallbackVtbl *lpBindStatusCallbackVtbl;
71     IServiceProvider    IServiceProvider_iface;
72     const IHttpNegotiate2Vtbl     *lpHttpNegotiate2Vtbl;
73     const IInternetBindInfoVtbl   *lpInternetBindInfoVtbl;
74
75     const BSCallbackVtbl          *vtbl;
76
77     LONG ref;
78
79     LPWSTR headers;
80     HGLOBAL post_data;
81     ULONG post_data_len;
82     ULONG readed;
83     DWORD bindf;
84     BOOL bindinfo_ready;
85
86     IMoniker *mon;
87     IBinding *binding;
88
89     HTMLDocumentNode *doc;
90
91     struct list entry;
92 };
93
94 #define NSINSTREAM_THIS(iface) DEFINE_THIS(nsProtocolStream, InputStream, iface)
95
96 static nsresult NSAPI nsInputStream_QueryInterface(nsIInputStream *iface, nsIIDRef riid,
97         void **result)
98 {
99     nsProtocolStream *This = NSINSTREAM_THIS(iface);
100
101     *result = NULL;
102
103     if(IsEqualGUID(&IID_nsISupports, riid)) {
104         TRACE("(%p)->(IID_nsISupports %p)\n", This, result);
105         *result  = NSINSTREAM(This);
106     }else if(IsEqualGUID(&IID_nsIInputStream, riid)) {
107         TRACE("(%p)->(IID_nsIInputStream %p)\n", This, result);
108         *result  = NSINSTREAM(This);
109     }
110
111     if(*result) {
112         nsIInputStream_AddRef(NSINSTREAM(This));
113         return NS_OK;
114     }
115
116     WARN("unsupported interface %s\n", debugstr_guid(riid));
117     return NS_NOINTERFACE;
118 }
119
120 static nsrefcnt NSAPI nsInputStream_AddRef(nsIInputStream *iface)
121 {
122     nsProtocolStream *This = NSINSTREAM_THIS(iface);
123     LONG ref = InterlockedIncrement(&This->ref);
124
125     TRACE("(%p) ref=%d\n", This, ref);
126
127     return ref;
128 }
129
130
131 static nsrefcnt NSAPI nsInputStream_Release(nsIInputStream *iface)
132 {
133     nsProtocolStream *This = NSINSTREAM_THIS(iface);
134     LONG ref = InterlockedDecrement(&This->ref);
135
136     TRACE("(%p) ref=%d\n", This, ref);
137
138     if(!ref)
139         heap_free(This);
140
141     return ref;
142 }
143
144 static nsresult NSAPI nsInputStream_Close(nsIInputStream *iface)
145 {
146     nsProtocolStream *This = NSINSTREAM_THIS(iface);
147     FIXME("(%p)\n", This);
148     return NS_ERROR_NOT_IMPLEMENTED;
149 }
150
151 static nsresult NSAPI nsInputStream_Available(nsIInputStream *iface, PRUint32 *_retval)
152 {
153     nsProtocolStream *This = NSINSTREAM_THIS(iface);
154     FIXME("(%p)->(%p)\n", This, _retval);
155     return NS_ERROR_NOT_IMPLEMENTED;
156 }
157
158 static nsresult NSAPI nsInputStream_Read(nsIInputStream *iface, char *aBuf, PRUint32 aCount,
159                                          PRUint32 *_retval)
160 {
161     nsProtocolStream *This = NSINSTREAM_THIS(iface);
162     DWORD read = aCount;
163
164     TRACE("(%p)->(%p %d %p)\n", This, aBuf, aCount, _retval);
165
166     if(read > This->buf_size)
167         read = This->buf_size;
168
169     if(read) {
170         memcpy(aBuf, This->buf, read);
171         if(read < This->buf_size)
172             memmove(This->buf, This->buf+read, This->buf_size-read);
173         This->buf_size -= read;
174     }
175
176     *_retval = read;
177     return NS_OK;
178 }
179
180 static nsresult NSAPI nsInputStream_ReadSegments(nsIInputStream *iface,
181         nsresult (WINAPI *aWriter)(nsIInputStream*,void*,const char*,PRUint32,PRUint32,PRUint32*),
182         void *aClousure, PRUint32 aCount, PRUint32 *_retval)
183 {
184     nsProtocolStream *This = NSINSTREAM_THIS(iface);
185     PRUint32 written = 0;
186     nsresult nsres;
187
188     TRACE("(%p)->(%p %p %d %p)\n", This, aWriter, aClousure, aCount, _retval);
189
190     if(!This->buf_size)
191         return S_OK;
192
193     if(aCount > This->buf_size)
194         aCount = This->buf_size;
195
196     nsres = aWriter(NSINSTREAM(This), aClousure, This->buf, 0, aCount, &written);
197     if(NS_FAILED(nsres))
198         TRACE("aWritter failed: %08x\n", nsres);
199     else if(written != This->buf_size)
200         FIXME("written %d != buf_size %d\n", written, This->buf_size);
201
202     This->buf_size -= written; 
203
204     *_retval = written;
205     return nsres;
206 }
207
208 static nsresult NSAPI nsInputStream_IsNonBlocking(nsIInputStream *iface, PRBool *_retval)
209 {
210     nsProtocolStream *This = NSINSTREAM_THIS(iface);
211     FIXME("(%p)->(%p)\n", This, _retval);
212     return NS_ERROR_NOT_IMPLEMENTED;
213 }
214
215 #undef NSINSTREAM_THIS
216
217 static const nsIInputStreamVtbl nsInputStreamVtbl = {
218     nsInputStream_QueryInterface,
219     nsInputStream_AddRef,
220     nsInputStream_Release,
221     nsInputStream_Close,
222     nsInputStream_Available,
223     nsInputStream_Read,
224     nsInputStream_ReadSegments,
225     nsInputStream_IsNonBlocking
226 };
227
228 static nsProtocolStream *create_nsprotocol_stream(void)
229 {
230     nsProtocolStream *ret = heap_alloc(sizeof(nsProtocolStream));
231
232     ret->lpInputStreamVtbl = &nsInputStreamVtbl;
233     ret->ref = 1;
234     ret->buf_size = 0;
235
236     return ret;
237 }
238
239 #define STATUSCLB_THIS(iface) DEFINE_THIS(BSCallback, BindStatusCallback, iface)
240
241 static HRESULT WINAPI BindStatusCallback_QueryInterface(IBindStatusCallback *iface,
242         REFIID riid, void **ppv)
243 {
244     BSCallback *This = STATUSCLB_THIS(iface);
245
246     *ppv = NULL;
247     if(IsEqualGUID(&IID_IUnknown, riid)) {
248         TRACE("(%p)->(IID_IUnknown, %p)\n", This, ppv);
249         *ppv = STATUSCLB(This);
250     }else if(IsEqualGUID(&IID_IBindStatusCallback, riid)) {
251         TRACE("(%p)->(IID_IBindStatusCallback, %p)\n", This, ppv);
252         *ppv = STATUSCLB(This);
253     }else if(IsEqualGUID(&IID_IServiceProvider, riid)) {
254         TRACE("(%p)->(IID_IServiceProvider %p)\n", This, ppv);
255         *ppv = &This->IServiceProvider_iface;
256     }else if(IsEqualGUID(&IID_IHttpNegotiate, riid)) {
257         TRACE("(%p)->(IID_IHttpNegotiate %p)\n", This, ppv);
258         *ppv = HTTPNEG(This);
259     }else if(IsEqualGUID(&IID_IHttpNegotiate2, riid)) {
260         TRACE("(%p)->(IID_IHttpNegotiate2 %p)\n", This, ppv);
261         *ppv = HTTPNEG(This);
262     }else if(IsEqualGUID(&IID_IInternetBindInfo, riid)) {
263         TRACE("(%p)->(IID_IInternetBindInfo %p)\n", This, ppv);
264         *ppv = BINDINFO(This);
265     }
266
267     if(*ppv) {
268         IBindStatusCallback_AddRef(STATUSCLB(This));
269         return S_OK;
270     }
271
272     TRACE("Unsupported riid = %s\n", debugstr_guid(riid));
273     return E_NOINTERFACE;
274 }
275
276 static ULONG WINAPI BindStatusCallback_AddRef(IBindStatusCallback *iface)
277 {
278     BSCallback *This = STATUSCLB_THIS(iface);
279     LONG ref = InterlockedIncrement(&This->ref);
280
281     TRACE("(%p) ref = %d\n", This, ref);
282
283     return ref;
284 }
285
286 static ULONG WINAPI BindStatusCallback_Release(IBindStatusCallback *iface)
287 {
288     BSCallback *This = STATUSCLB_THIS(iface);
289     LONG ref = InterlockedDecrement(&This->ref);
290
291     TRACE("(%p) ref = %d\n", This, ref);
292
293     if(!ref) {
294         if(This->post_data)
295             GlobalFree(This->post_data);
296         if(This->mon)
297             IMoniker_Release(This->mon);
298         if(This->binding)
299             IBinding_Release(This->binding);
300         list_remove(&This->entry);
301         heap_free(This->headers);
302
303         This->vtbl->destroy(This);
304     }
305
306     return ref;
307 }
308
309 static HRESULT WINAPI BindStatusCallback_OnStartBinding(IBindStatusCallback *iface,
310         DWORD dwReserved, IBinding *pbind)
311 {
312     BSCallback *This = STATUSCLB_THIS(iface);
313
314     TRACE("(%p)->(%d %p)\n", This, dwReserved, pbind);
315
316     IBinding_AddRef(pbind);
317     This->binding = pbind;
318
319     if(This->doc)
320         list_add_head(&This->doc->bindings, &This->entry);
321
322     return This->vtbl->start_binding(This);
323 }
324
325 static HRESULT WINAPI BindStatusCallback_GetPriority(IBindStatusCallback *iface, LONG *pnPriority)
326 {
327     BSCallback *This = STATUSCLB_THIS(iface);
328     FIXME("(%p)->(%p)\n", This, pnPriority);
329     return E_NOTIMPL;
330 }
331
332 static HRESULT WINAPI BindStatusCallback_OnLowResource(IBindStatusCallback *iface, DWORD reserved)
333 {
334     BSCallback *This = STATUSCLB_THIS(iface);
335     FIXME("(%p)->(%d)\n", This, reserved);
336     return E_NOTIMPL;
337 }
338
339 static HRESULT WINAPI BindStatusCallback_OnProgress(IBindStatusCallback *iface, ULONG ulProgress,
340         ULONG ulProgressMax, ULONG ulStatusCode, LPCWSTR szStatusText)
341 {
342     BSCallback *This = STATUSCLB_THIS(iface);
343
344     TRACE("%p)->(%u %u %u %s)\n", This, ulProgress, ulProgressMax, ulStatusCode,
345             debugstr_w(szStatusText));
346
347     return This->vtbl->on_progress(This, ulStatusCode, szStatusText);
348 }
349
350 static HRESULT WINAPI BindStatusCallback_OnStopBinding(IBindStatusCallback *iface,
351         HRESULT hresult, LPCWSTR szError)
352 {
353     BSCallback *This = STATUSCLB_THIS(iface);
354     HRESULT hres;
355
356     TRACE("(%p)->(%08x %s)\n", This, hresult, debugstr_w(szError));
357
358     /* NOTE: IE7 calls GetBindResult here */
359
360     hres = This->vtbl->stop_binding(This, hresult);
361
362     if(This->binding) {
363         IBinding_Release(This->binding);
364         This->binding = NULL;
365     }
366
367     list_remove(&This->entry);
368     This->doc = NULL;
369
370     return hres;
371 }
372
373 static HRESULT WINAPI BindStatusCallback_GetBindInfo(IBindStatusCallback *iface,
374         DWORD *grfBINDF, BINDINFO *pbindinfo)
375 {
376     BSCallback *This = STATUSCLB_THIS(iface);
377     DWORD size;
378
379     TRACE("(%p)->(%p %p)\n", This, grfBINDF, pbindinfo);
380
381     if(!This->bindinfo_ready) {
382         HRESULT hres;
383
384         hres = This->vtbl->init_bindinfo(This);
385         if(FAILED(hres))
386             return hres;
387
388         This->bindinfo_ready = TRUE;
389     }
390
391     *grfBINDF = This->bindf;
392
393     size = pbindinfo->cbSize;
394     memset(pbindinfo, 0, size);
395     pbindinfo->cbSize = size;
396
397     pbindinfo->cbstgmedData = This->post_data_len;
398     pbindinfo->dwCodePage = CP_UTF8;
399     pbindinfo->dwOptions = 0x80000;
400
401     if(This->post_data) {
402         pbindinfo->dwBindVerb = BINDVERB_POST;
403
404         pbindinfo->stgmedData.tymed = TYMED_HGLOBAL;
405         pbindinfo->stgmedData.u.hGlobal = This->post_data;
406         pbindinfo->stgmedData.pUnkForRelease = (IUnknown*)STATUSCLB(This);
407         IBindStatusCallback_AddRef(STATUSCLB(This));
408     }
409
410     return S_OK;
411 }
412
413 static HRESULT WINAPI BindStatusCallback_OnDataAvailable(IBindStatusCallback *iface,
414         DWORD grfBSCF, DWORD dwSize, FORMATETC *pformatetc, STGMEDIUM *pstgmed)
415 {
416     BSCallback *This = STATUSCLB_THIS(iface);
417
418     TRACE("(%p)->(%08x %d %p %p)\n", This, grfBSCF, dwSize, pformatetc, pstgmed);
419
420     return This->vtbl->read_data(This, pstgmed->u.pstm);
421 }
422
423 static HRESULT WINAPI BindStatusCallback_OnObjectAvailable(IBindStatusCallback *iface,
424         REFIID riid, IUnknown *punk)
425 {
426     BSCallback *This = STATUSCLB_THIS(iface);
427     FIXME("(%p)->(%s %p)\n", This, debugstr_guid(riid), punk);
428     return E_NOTIMPL;
429 }
430
431 #undef STATUSCLB_THIS
432
433 static const IBindStatusCallbackVtbl BindStatusCallbackVtbl = {
434     BindStatusCallback_QueryInterface,
435     BindStatusCallback_AddRef,
436     BindStatusCallback_Release,
437     BindStatusCallback_OnStartBinding,
438     BindStatusCallback_GetPriority,
439     BindStatusCallback_OnLowResource,
440     BindStatusCallback_OnProgress,
441     BindStatusCallback_OnStopBinding,
442     BindStatusCallback_GetBindInfo,
443     BindStatusCallback_OnDataAvailable,
444     BindStatusCallback_OnObjectAvailable
445 };
446
447 #define HTTPNEG_THIS(iface) DEFINE_THIS(BSCallback, HttpNegotiate2, iface)
448
449 static HRESULT WINAPI HttpNegotiate_QueryInterface(IHttpNegotiate2 *iface,
450                                                    REFIID riid, void **ppv)
451 {
452     BSCallback *This = HTTPNEG_THIS(iface);
453     return IBindStatusCallback_QueryInterface(STATUSCLB(This), riid, ppv);
454 }
455
456 static ULONG WINAPI HttpNegotiate_AddRef(IHttpNegotiate2 *iface)
457 {
458     BSCallback *This = HTTPNEG_THIS(iface);
459     return IBindStatusCallback_AddRef(STATUSCLB(This));
460 }
461
462 static ULONG WINAPI HttpNegotiate_Release(IHttpNegotiate2 *iface)
463 {
464     BSCallback *This = HTTPNEG_THIS(iface);
465     return IBindStatusCallback_Release(STATUSCLB(This));
466 }
467
468 static HRESULT WINAPI HttpNegotiate_BeginningTransaction(IHttpNegotiate2 *iface,
469         LPCWSTR szURL, LPCWSTR szHeaders, DWORD dwReserved, LPWSTR *pszAdditionalHeaders)
470 {
471     BSCallback *This = HTTPNEG_THIS(iface);
472     HRESULT hres;
473
474     TRACE("(%p)->(%s %s %d %p)\n", This, debugstr_w(szURL), debugstr_w(szHeaders),
475           dwReserved, pszAdditionalHeaders);
476
477     *pszAdditionalHeaders = NULL;
478
479     hres = This->vtbl->beginning_transaction(This, pszAdditionalHeaders);
480     if(hres != S_FALSE)
481         return hres;
482
483     if(This->headers) {
484         DWORD size;
485
486         size = (strlenW(This->headers)+1)*sizeof(WCHAR);
487         *pszAdditionalHeaders = CoTaskMemAlloc(size);
488         if(!*pszAdditionalHeaders)
489             return E_OUTOFMEMORY;
490         memcpy(*pszAdditionalHeaders, This->headers, size);
491     }
492
493     return S_OK;
494 }
495
496 static HRESULT WINAPI HttpNegotiate_OnResponse(IHttpNegotiate2 *iface, DWORD dwResponseCode,
497         LPCWSTR szResponseHeaders, LPCWSTR szRequestHeaders, LPWSTR *pszAdditionalRequestHeaders)
498 {
499     BSCallback *This = HTTPNEG_THIS(iface);
500
501     TRACE("(%p)->(%d %s %s %p)\n", This, dwResponseCode, debugstr_w(szResponseHeaders),
502           debugstr_w(szRequestHeaders), pszAdditionalRequestHeaders);
503
504     return This->vtbl->on_response(This, dwResponseCode, szResponseHeaders);
505 }
506
507 static HRESULT WINAPI HttpNegotiate_GetRootSecurityId(IHttpNegotiate2 *iface,
508         BYTE *pbSecurityId, DWORD *pcbSecurityId, DWORD_PTR dwReserved)
509 {
510     BSCallback *This = HTTPNEG_THIS(iface);
511     FIXME("(%p)->(%p %p %ld)\n", This, pbSecurityId, pcbSecurityId, dwReserved);
512     return E_NOTIMPL;
513 }
514
515 #undef HTTPNEG
516
517 static const IHttpNegotiate2Vtbl HttpNegotiate2Vtbl = {
518     HttpNegotiate_QueryInterface,
519     HttpNegotiate_AddRef,
520     HttpNegotiate_Release,
521     HttpNegotiate_BeginningTransaction,
522     HttpNegotiate_OnResponse,
523     HttpNegotiate_GetRootSecurityId
524 };
525
526 #define BINDINFO_THIS(iface) DEFINE_THIS(BSCallback, InternetBindInfo, iface)
527
528 static HRESULT WINAPI InternetBindInfo_QueryInterface(IInternetBindInfo *iface,
529                                                       REFIID riid, void **ppv)
530 {
531     BSCallback *This = BINDINFO_THIS(iface);
532     return IBindStatusCallback_QueryInterface(STATUSCLB(This), riid, ppv);
533 }
534
535 static ULONG WINAPI InternetBindInfo_AddRef(IInternetBindInfo *iface)
536 {
537     BSCallback *This = BINDINFO_THIS(iface);
538     return IBindStatusCallback_AddRef(STATUSCLB(This));
539 }
540
541 static ULONG WINAPI InternetBindInfo_Release(IInternetBindInfo *iface)
542 {
543     BSCallback *This = BINDINFO_THIS(iface);
544     return IBindStatusCallback_Release(STATUSCLB(This));
545 }
546
547 static HRESULT WINAPI InternetBindInfo_GetBindInfo(IInternetBindInfo *iface,
548                                                    DWORD *grfBINDF, BINDINFO *pbindinfo)
549 {
550     BSCallback *This = BINDINFO_THIS(iface);
551     FIXME("(%p)->(%p %p)\n", This, grfBINDF, pbindinfo);
552     return E_NOTIMPL;
553 }
554
555 static HRESULT WINAPI InternetBindInfo_GetBindString(IInternetBindInfo *iface,
556         ULONG ulStringType, LPOLESTR *ppwzStr, ULONG cEl, ULONG *pcElFetched)
557 {
558     BSCallback *This = BINDINFO_THIS(iface);
559     FIXME("(%p)->(%u %p %u %p)\n", This, ulStringType, ppwzStr, cEl, pcElFetched);
560     return E_NOTIMPL;
561 }
562
563 #undef BINDINFO_THIS
564
565 static const IInternetBindInfoVtbl InternetBindInfoVtbl = {
566     InternetBindInfo_QueryInterface,
567     InternetBindInfo_AddRef,
568     InternetBindInfo_Release,
569     InternetBindInfo_GetBindInfo,
570     InternetBindInfo_GetBindString
571 };
572
573 static inline BSCallback *impl_from_IServiceProvider(IServiceProvider *iface)
574 {
575     return CONTAINING_RECORD(iface, BSCallback, IServiceProvider_iface);
576 }
577
578 static HRESULT WINAPI BSCServiceProvider_QueryInterface(IServiceProvider *iface,
579                                                         REFIID riid, void **ppv)
580 {
581     BSCallback *This = impl_from_IServiceProvider(iface);
582     return IBindStatusCallback_QueryInterface(STATUSCLB(This), riid, ppv);
583 }
584
585 static ULONG WINAPI BSCServiceProvider_AddRef(IServiceProvider *iface)
586 {
587     BSCallback *This = impl_from_IServiceProvider(iface);
588     return IBindStatusCallback_AddRef(STATUSCLB(This));
589 }
590
591 static ULONG WINAPI BSCServiceProvider_Release(IServiceProvider *iface)
592 {
593     BSCallback *This = impl_from_IServiceProvider(iface);
594     return IBindStatusCallback_Release(STATUSCLB(This));
595 }
596
597 static HRESULT WINAPI BSCServiceProvider_QueryService(IServiceProvider *iface,
598         REFGUID guidService, REFIID riid, void **ppv)
599 {
600     BSCallback *This = impl_from_IServiceProvider(iface);
601     TRACE("(%p)->(%s %s %p)\n", This, debugstr_guid(guidService), debugstr_guid(riid), ppv);
602     return E_NOINTERFACE;
603 }
604
605 static const IServiceProviderVtbl ServiceProviderVtbl = {
606     BSCServiceProvider_QueryInterface,
607     BSCServiceProvider_AddRef,
608     BSCServiceProvider_Release,
609     BSCServiceProvider_QueryService
610 };
611
612 static void init_bscallback(BSCallback *This, const BSCallbackVtbl *vtbl, IMoniker *mon, DWORD bindf)
613 {
614     This->lpBindStatusCallbackVtbl = &BindStatusCallbackVtbl;
615     This->IServiceProvider_iface.lpVtbl = &ServiceProviderVtbl;
616     This->lpHttpNegotiate2Vtbl     = &HttpNegotiate2Vtbl;
617     This->lpInternetBindInfoVtbl   = &InternetBindInfoVtbl;
618     This->vtbl = vtbl;
619     This->ref = 1;
620     This->bindf = bindf;
621
622     list_init(&This->entry);
623
624     if(mon)
625         IMoniker_AddRef(mon);
626     This->mon = mon;
627 }
628
629 /* Calls undocumented 84 cmd of CGID_ShellDocView */
630 static void call_docview_84(HTMLDocumentObj *doc)
631 {
632     IOleCommandTarget *olecmd;
633     VARIANT var;
634     HRESULT hres;
635
636     if(!doc->client)
637         return;
638
639     hres = IOleClientSite_QueryInterface(doc->client, &IID_IOleCommandTarget, (void**)&olecmd);
640     if(FAILED(hres))
641         return;
642
643     VariantInit(&var);
644     hres = IOleCommandTarget_Exec(olecmd, &CGID_ShellDocView, 84, 0, NULL, &var);
645     IOleCommandTarget_Release(olecmd);
646     if(SUCCEEDED(hres) && V_VT(&var) != VT_NULL)
647         FIXME("handle result\n");
648 }
649
650 static HRESULT parse_headers(const WCHAR *headers, struct list *headers_list)
651 {
652     const WCHAR *header, *header_end, *colon, *value;
653     HRESULT hres;
654
655     header = headers;
656     while(*header) {
657         if(header[0] == '\r' && header[1] == '\n' && !header[2])
658             break;
659         for(colon = header; *colon && *colon != ':' && *colon != '\r'; colon++);
660         if(*colon != ':')
661             return E_FAIL;
662
663         value = colon+1;
664         while(*value == ' ')
665             value++;
666         if(!*value)
667             return E_FAIL;
668
669         for(header_end = value+1; *header_end && *header_end != '\r'; header_end++);
670
671         hres = set_http_header(headers_list, header, colon-header, value, header_end-value);
672         if(FAILED(hres))
673             return hres;
674
675         header = header_end;
676         if(header[0] == '\r' && header[1] == '\n')
677             header += 2;
678     }
679
680     return S_OK;
681 }
682
683 static HRESULT read_post_data_stream(nsIInputStream *stream, HGLOBAL *post_data,
684         ULONG *post_data_len)
685 {
686     PRUint32 data_len = 0, available = 0;
687     char *data;
688     nsresult nsres;
689
690     nsres =  nsIInputStream_Available(stream, &available);
691     if(NS_FAILED(nsres))
692         return E_FAIL;
693
694     data = GlobalAlloc(0, available+1);
695     if(!data)
696         return E_OUTOFMEMORY;
697
698     nsres = nsIInputStream_Read(stream, data, available, &data_len);
699     if(NS_FAILED(nsres)) {
700         GlobalFree(data);
701         return E_FAIL;
702     }
703
704     data[data_len] = 0;
705     *post_data = data;
706     *post_data_len = data_len;
707     return S_OK;
708 }
709
710 HRESULT start_binding(HTMLWindow *window, HTMLDocumentNode *doc, BSCallback *bscallback, IBindCtx *bctx)
711 {
712     IStream *str = NULL;
713     HRESULT hres;
714
715     bscallback->doc = doc;
716
717     /* NOTE: IE7 calls IsSystemMoniker here*/
718
719     if(window) {
720         if(bscallback->mon != window->mon)
721             set_current_mon(window, bscallback->mon);
722         call_docview_84(window->doc_obj);
723     }
724
725     if(bctx) {
726         RegisterBindStatusCallback(bctx, STATUSCLB(bscallback), NULL, 0);
727         IBindCtx_AddRef(bctx);
728     }else {
729         hres = CreateAsyncBindCtx(0, STATUSCLB(bscallback), NULL, &bctx);
730         if(FAILED(hres)) {
731             WARN("CreateAsyncBindCtx failed: %08x\n", hres);
732             bscallback->vtbl->stop_binding(bscallback, hres);
733             return hres;
734         }
735     }
736
737     hres = IMoniker_BindToStorage(bscallback->mon, bctx, NULL, &IID_IStream, (void**)&str);
738     IBindCtx_Release(bctx);
739     if(FAILED(hres)) {
740         WARN("BindToStorage failed: %08x\n", hres);
741         bscallback->vtbl->stop_binding(bscallback, hres);
742         return hres;
743     }
744
745     if(str)
746         IStream_Release(str);
747
748     IMoniker_Release(bscallback->mon);
749     bscallback->mon = NULL;
750
751     return S_OK;
752 }
753
754 typedef struct {
755     BSCallback bsc;
756
757     DWORD size;
758     BYTE *buf;
759     HRESULT hres;
760 } BufferBSC;
761
762 #define BUFFERBSC_THIS(bsc) ((BufferBSC*) bsc)
763
764 static void BufferBSC_destroy(BSCallback *bsc)
765 {
766     BufferBSC *This = BUFFERBSC_THIS(bsc);
767
768     heap_free(This->buf);
769     heap_free(This);
770 }
771
772 static HRESULT BufferBSC_init_bindinfo(BSCallback *bsc)
773 {
774     return S_OK;
775 }
776
777 static HRESULT BufferBSC_start_binding(BSCallback *bsc)
778 {
779     return S_OK;
780 }
781
782 static HRESULT BufferBSC_stop_binding(BSCallback *bsc, HRESULT result)
783 {
784     BufferBSC *This = BUFFERBSC_THIS(bsc);
785
786     This->hres = result;
787
788     if(FAILED(result)) {
789         heap_free(This->buf);
790         This->buf = NULL;
791         This->size = 0;
792     }
793
794     return S_OK;
795 }
796
797 static HRESULT BufferBSC_read_data(BSCallback *bsc, IStream *stream)
798 {
799     BufferBSC *This = BUFFERBSC_THIS(bsc);
800     DWORD readed;
801     HRESULT hres;
802
803     if(!This->buf) {
804         This->size = 128;
805         This->buf = heap_alloc(This->size);
806     }
807
808     do {
809         if(This->bsc.readed == This->size) {
810             This->size <<= 1;
811             This->buf = heap_realloc(This->buf, This->size);
812         }
813
814         readed = 0;
815         hres = IStream_Read(stream, This->buf+This->bsc.readed, This->size-This->bsc.readed, &readed);
816         This->bsc.readed += readed;
817     }while(hres == S_OK);
818
819     return S_OK;
820 }
821
822 static HRESULT BufferBSC_on_progress(BSCallback *bsc, ULONG status_code, LPCWSTR status_text)
823 {
824     return S_OK;
825 }
826
827 static HRESULT BufferBSC_on_response(BSCallback *bsc, DWORD response_code,
828         LPCWSTR response_headers)
829 {
830     return S_OK;
831 }
832
833 static HRESULT BufferBSC_beginning_transaction(BSCallback *bsc, WCHAR **additional_headers)
834 {
835     return S_FALSE;
836 }
837
838 #undef BUFFERBSC_THIS
839
840 static const BSCallbackVtbl BufferBSCVtbl = {
841     BufferBSC_destroy,
842     BufferBSC_init_bindinfo,
843     BufferBSC_start_binding,
844     BufferBSC_stop_binding,
845     BufferBSC_read_data,
846     BufferBSC_on_progress,
847     BufferBSC_on_response,
848     BufferBSC_beginning_transaction
849 };
850
851
852 static BufferBSC *create_bufferbsc(IMoniker *mon)
853 {
854     BufferBSC *ret = heap_alloc_zero(sizeof(*ret));
855
856     init_bscallback(&ret->bsc, &BufferBSCVtbl, mon, 0);
857     ret->hres = E_FAIL;
858
859     return ret;
860 }
861
862 HRESULT bind_mon_to_buffer(HTMLDocumentNode *doc, IMoniker *mon, void **buf, DWORD *size)
863 {
864     BufferBSC *bsc = create_bufferbsc(mon);
865     HRESULT hres;
866
867     *buf = NULL;
868
869     hres = start_binding(NULL, doc, &bsc->bsc, NULL);
870     if(SUCCEEDED(hres)) {
871         hres = bsc->hres;
872         if(SUCCEEDED(hres)) {
873             *buf = bsc->buf;
874             bsc->buf = NULL;
875             *size = bsc->bsc.readed;
876             bsc->size = 0;
877         }
878     }
879
880     IBindStatusCallback_Release(STATUSCLB(&bsc->bsc));
881
882     return hres;
883 }
884
885 struct nsChannelBSC {
886     BSCallback bsc;
887
888     HTMLWindow *window;
889
890     nsChannel *nschannel;
891     nsIStreamListener *nslistener;
892     nsISupports *nscontext;
893
894     nsProtocolStream *nsstream;
895 };
896
897 static HRESULT on_start_nsrequest(nsChannelBSC *This)
898 {
899     nsresult nsres;
900
901     /* FIXME: it's needed for http connections from BindToObject. */
902     if(!This->nschannel->response_status)
903         This->nschannel->response_status = 200;
904
905     nsres = nsIStreamListener_OnStartRequest(This->nslistener,
906             (nsIRequest*)&This->nschannel->nsIHttpChannel_iface, This->nscontext);
907     if(NS_FAILED(nsres)) {
908         FIXME("OnStartRequest failed: %08x\n", nsres);
909         return E_FAIL;
910     }
911
912     if(This->window) {
913         update_window_doc(This->window);
914         if(This->window->doc != This->bsc.doc)
915             This->bsc.doc = This->window->doc;
916         if(This->window->readystate != READYSTATE_LOADING)
917             set_ready_state(This->window, READYSTATE_LOADING);
918     }
919
920     return S_OK;
921 }
922
923 static void on_stop_nsrequest(nsChannelBSC *This, HRESULT result)
924 {
925     nsresult nsres, request_result;
926
927     switch(result) {
928     case S_OK:
929         request_result = NS_OK;
930         break;
931     case E_ABORT:
932         request_result = NS_BINDING_ABORTED;
933         break;
934     default:
935         request_result = NS_ERROR_FAILURE;
936     }
937
938     if(!This->bsc.readed && SUCCEEDED(result)) {
939         TRACE("No data read! Calling OnStartRequest\n");
940         on_start_nsrequest(This);
941     }
942
943     if(This->nslistener) {
944         nsres = nsIStreamListener_OnStopRequest(This->nslistener,
945                  (nsIRequest*)&This->nschannel->nsIHttpChannel_iface, This->nscontext,
946                  request_result);
947         if(NS_FAILED(nsres))
948             WARN("OnStopRequet failed: %08x\n", nsres);
949     }
950
951     if(This->nschannel->load_group) {
952         nsres = nsILoadGroup_RemoveRequest(This->nschannel->load_group,
953                 (nsIRequest*)&This->nschannel->nsIHttpChannel_iface, NULL, request_result);
954         if(NS_FAILED(nsres))
955             ERR("RemoveRequest failed: %08x\n", nsres);
956     }
957 }
958
959 static HRESULT read_stream_data(nsChannelBSC *This, IStream *stream)
960 {
961     DWORD read;
962     nsresult nsres;
963     HRESULT hres;
964
965     if(!This->nslistener) {
966         BYTE buf[1024];
967
968         do {
969             read = 0;
970             hres = IStream_Read(stream, buf, sizeof(buf), &read);
971         }while(hres == S_OK && read);
972
973         return S_OK;
974     }
975
976     if(!This->nsstream)
977         This->nsstream = create_nsprotocol_stream();
978
979     do {
980         read = 0;
981         hres = IStream_Read(stream, This->nsstream->buf+This->nsstream->buf_size,
982                 sizeof(This->nsstream->buf)-This->nsstream->buf_size, &read);
983         if(!read)
984             break;
985
986         This->nsstream->buf_size += read;
987
988         if(!This->bsc.readed) {
989             if(This->nsstream->buf_size >= 2
990                && (BYTE)This->nsstream->buf[0] == 0xff
991                && (BYTE)This->nsstream->buf[1] == 0xfe)
992                 This->nschannel->charset = heap_strdupA(UTF16_STR);
993
994             if(!This->nschannel->content_type) {
995                 WCHAR *mime;
996
997                 hres = FindMimeFromData(NULL, NULL, This->nsstream->buf, This->nsstream->buf_size, NULL, 0, &mime, 0);
998                 if(FAILED(hres))
999                     return hres;
1000
1001                 TRACE("Found MIME %s\n", debugstr_w(mime));
1002
1003                 This->nschannel->content_type = heap_strdupWtoA(mime);
1004                 CoTaskMemFree(mime);
1005                 if(!This->nschannel->content_type)
1006                     return E_OUTOFMEMORY;
1007             }
1008
1009             on_start_nsrequest(This);
1010         }
1011
1012         This->bsc.readed += This->nsstream->buf_size;
1013
1014         nsres = nsIStreamListener_OnDataAvailable(This->nslistener,
1015                 (nsIRequest*)&This->nschannel->nsIHttpChannel_iface, This->nscontext,
1016                 NSINSTREAM(This->nsstream), This->bsc.readed-This->nsstream->buf_size,
1017                 This->nsstream->buf_size);
1018         if(NS_FAILED(nsres))
1019             ERR("OnDataAvailable failed: %08x\n", nsres);
1020
1021         if(This->nsstream->buf_size == sizeof(This->nsstream->buf)) {
1022             ERR("buffer is full\n");
1023             break;
1024         }
1025     }while(hres == S_OK);
1026
1027     return S_OK;
1028 }
1029
1030 #define NSCHANNELBSC_THIS(bsc) ((nsChannelBSC*) bsc)
1031
1032 static void nsChannelBSC_destroy(BSCallback *bsc)
1033 {
1034     nsChannelBSC *This = NSCHANNELBSC_THIS(bsc);
1035
1036     if(This->nschannel)
1037         nsIChannel_Release(&This->nschannel->nsIHttpChannel_iface);
1038     if(This->nslistener)
1039         nsIStreamListener_Release(This->nslistener);
1040     if(This->nscontext)
1041         nsISupports_Release(This->nscontext);
1042     if(This->nsstream)
1043         nsIInputStream_Release(NSINSTREAM(This->nsstream));
1044     heap_free(This);
1045 }
1046
1047 static HRESULT nsChannelBSC_start_binding(BSCallback *bsc)
1048 {
1049     nsChannelBSC *This = NSCHANNELBSC_THIS(bsc);
1050
1051     if(This->window)
1052         This->window->doc->skip_mutation_notif = FALSE;
1053
1054     return S_OK;
1055 }
1056
1057 static HRESULT nsChannelBSC_init_bindinfo(BSCallback *bsc)
1058 {
1059     nsChannelBSC *This = NSCHANNELBSC_THIS(bsc);
1060     HRESULT hres;
1061
1062     if(This->nschannel && This->nschannel->post_data_stream) {
1063         hres = read_post_data_stream(This->nschannel->post_data_stream,
1064                 &This->bsc.post_data, &This->bsc.post_data_len);
1065         if(FAILED(hres))
1066             return hres;
1067
1068         TRACE("post_data = %s\n", debugstr_an(This->bsc.post_data, This->bsc.post_data_len));
1069     }
1070
1071     return S_OK;
1072 }
1073
1074 typedef struct {
1075     task_t header;
1076     nsChannelBSC *bsc;
1077 } stop_request_task_t;
1078
1079 static void stop_request_proc(task_t *_task)
1080 {
1081     stop_request_task_t *task = (stop_request_task_t*)_task;
1082
1083     TRACE("(%p)\n", task->bsc);
1084
1085     on_stop_nsrequest(task->bsc, S_OK);
1086     IBindStatusCallback_Release(STATUSCLB(&task->bsc->bsc));
1087 }
1088
1089 static HRESULT async_stop_request(nsChannelBSC *This)
1090 {
1091     stop_request_task_t *task;
1092
1093     task = heap_alloc(sizeof(*task));
1094     if(!task)
1095         return E_OUTOFMEMORY;
1096
1097     IBindStatusCallback_AddRef(STATUSCLB(&This->bsc));
1098     task->bsc = This;
1099     push_task(&task->header, stop_request_proc, This->bsc.doc->basedoc.doc_obj->basedoc.task_magic);
1100     return S_OK;
1101 }
1102
1103 static HRESULT nsChannelBSC_stop_binding(BSCallback *bsc, HRESULT result)
1104 {
1105     nsChannelBSC *This = NSCHANNELBSC_THIS(bsc);
1106
1107     if(This->window && SUCCEEDED(result)) {
1108         result = async_stop_request(This);
1109         if(SUCCEEDED(result))
1110            return S_OK;
1111     }
1112
1113     on_stop_nsrequest(This, result);
1114     return S_OK;
1115 }
1116
1117 static HRESULT nsChannelBSC_read_data(BSCallback *bsc, IStream *stream)
1118 {
1119     nsChannelBSC *This = NSCHANNELBSC_THIS(bsc);
1120
1121     return read_stream_data(This, stream);
1122 }
1123
1124 static HRESULT nsChannelBSC_on_progress(BSCallback *bsc, ULONG status_code, LPCWSTR status_text)
1125 {
1126     nsChannelBSC *This = NSCHANNELBSC_THIS(bsc);
1127
1128     switch(status_code) {
1129     case BINDSTATUS_MIMETYPEAVAILABLE:
1130         if(!This->nschannel)
1131             return S_OK;
1132
1133         heap_free(This->nschannel->content_type);
1134         This->nschannel->content_type = heap_strdupWtoA(status_text);
1135         break;
1136     case BINDSTATUS_REDIRECTING:
1137         TRACE("redirect to %s\n", debugstr_w(status_text));
1138
1139         /* FIXME: We should find a better way to handle this */
1140         set_wine_url(This->nschannel->uri, status_text);
1141     }
1142
1143     return S_OK;
1144 }
1145
1146 static HRESULT nsChannelBSC_on_response(BSCallback *bsc, DWORD response_code,
1147         LPCWSTR response_headers)
1148 {
1149     nsChannelBSC *This = NSCHANNELBSC_THIS(bsc);
1150     HRESULT hres;
1151
1152     This->nschannel->response_status = response_code;
1153
1154     if(response_headers) {
1155         const WCHAR *headers;
1156
1157         headers = strchrW(response_headers, '\r');
1158         if(headers && headers[1] == '\n') {
1159             headers += 2;
1160             hres = parse_headers(headers, &This->nschannel->response_headers);
1161             if(FAILED(hres)) {
1162                 WARN("parsing headers failed: %08x\n", hres);
1163                 return hres;
1164             }
1165         }
1166     }
1167
1168     return S_OK;
1169 }
1170
1171 static HRESULT nsChannelBSC_beginning_transaction(BSCallback *bsc, WCHAR **additional_headers)
1172 {
1173     nsChannelBSC *This = NSCHANNELBSC_THIS(bsc);
1174     http_header_t *iter;
1175     DWORD len = 0;
1176     WCHAR *ptr;
1177
1178     static const WCHAR content_lengthW[] =
1179         {'C','o','n','t','e','n','t','-','L','e','n','g','t','h',0};
1180
1181     if(!This->nschannel)
1182         return S_FALSE;
1183
1184     LIST_FOR_EACH_ENTRY(iter, &This->nschannel->request_headers, http_header_t, entry) {
1185         if(strcmpW(iter->header, content_lengthW))
1186             len += strlenW(iter->header) + 2 /* ": " */ + strlenW(iter->data) + 2 /* "\r\n" */;
1187     }
1188
1189     if(!len)
1190         return S_OK;
1191
1192     *additional_headers = ptr = CoTaskMemAlloc((len+1)*sizeof(WCHAR));
1193     if(!ptr)
1194         return E_OUTOFMEMORY;
1195
1196     LIST_FOR_EACH_ENTRY(iter, &This->nschannel->request_headers, http_header_t, entry) {
1197         if(!strcmpW(iter->header, content_lengthW))
1198             continue;
1199
1200         len = strlenW(iter->header);
1201         memcpy(ptr, iter->header, len*sizeof(WCHAR));
1202         ptr += len;
1203
1204         *ptr++ = ':';
1205         *ptr++ = ' ';
1206
1207         len = strlenW(iter->data);
1208         memcpy(ptr, iter->data, len*sizeof(WCHAR));
1209         ptr += len;
1210
1211         *ptr++ = '\r';
1212         *ptr++ = '\n';
1213     }
1214
1215     *ptr = 0;
1216
1217     return S_OK;
1218 }
1219
1220 #undef NSCHANNELBSC_THIS
1221
1222 static const BSCallbackVtbl nsChannelBSCVtbl = {
1223     nsChannelBSC_destroy,
1224     nsChannelBSC_init_bindinfo,
1225     nsChannelBSC_start_binding,
1226     nsChannelBSC_stop_binding,
1227     nsChannelBSC_read_data,
1228     nsChannelBSC_on_progress,
1229     nsChannelBSC_on_response,
1230     nsChannelBSC_beginning_transaction
1231 };
1232
1233 HRESULT create_channelbsc(IMoniker *mon, WCHAR *headers, BYTE *post_data, DWORD post_data_size, nsChannelBSC **retval)
1234 {
1235     nsChannelBSC *ret;
1236
1237     ret = heap_alloc_zero(sizeof(*ret));
1238     if(!ret)
1239         return E_OUTOFMEMORY;
1240
1241     init_bscallback(&ret->bsc, &nsChannelBSCVtbl, mon, BINDF_ASYNCHRONOUS | BINDF_ASYNCSTORAGE | BINDF_PULLDATA);
1242
1243     if(headers) {
1244         ret->bsc.headers = heap_strdupW(headers);
1245         if(!ret->bsc.headers) {
1246             IBindStatusCallback_Release(STATUSCLB(&ret->bsc));
1247             return E_OUTOFMEMORY;
1248         }
1249     }
1250
1251     if(post_data) {
1252         ret->bsc.post_data = GlobalAlloc(0, post_data_size);
1253         if(!ret->bsc.post_data) {
1254             heap_free(ret->bsc.headers);
1255             IBindStatusCallback_Release(STATUSCLB(&ret->bsc));
1256             return E_OUTOFMEMORY;
1257         }
1258
1259         memcpy(ret->bsc.post_data, post_data, post_data_size);
1260         ret->bsc.post_data_len = post_data_size;
1261     }
1262
1263     *retval = ret;
1264     return S_OK;
1265 }
1266
1267 IMoniker *get_channelbsc_mon(nsChannelBSC *This)
1268 {
1269     if(This->bsc.mon)
1270         IMoniker_AddRef(This->bsc.mon);
1271     return This->bsc.mon;
1272 }
1273
1274 void set_window_bscallback(HTMLWindow *window, nsChannelBSC *callback)
1275 {
1276     if(window->bscallback) {
1277         if(window->bscallback->bsc.binding)
1278             IBinding_Abort(window->bscallback->bsc.binding);
1279         window->bscallback->bsc.doc = NULL;
1280         window->bscallback->window = NULL;
1281         IBindStatusCallback_Release(STATUSCLB(&window->bscallback->bsc));
1282     }
1283
1284     window->bscallback = callback;
1285
1286     if(callback) {
1287         callback->window = window;
1288         IBindStatusCallback_AddRef(STATUSCLB(&callback->bsc));
1289         callback->bsc.doc = window->doc;
1290     }
1291 }
1292
1293 typedef struct {
1294     task_t header;
1295     HTMLWindow *window;
1296     nsChannelBSC *bscallback;
1297 } start_doc_binding_task_t;
1298
1299 static void start_doc_binding_proc(task_t *_task)
1300 {
1301     start_doc_binding_task_t *task = (start_doc_binding_task_t*)_task;
1302
1303     start_binding(task->window, NULL, (BSCallback*)task->bscallback, NULL);
1304     IBindStatusCallback_Release(STATUSCLB(&task->bscallback->bsc));
1305 }
1306
1307 HRESULT async_start_doc_binding(HTMLWindow *window, nsChannelBSC *bscallback)
1308 {
1309     start_doc_binding_task_t *task;
1310
1311     task = heap_alloc(sizeof(start_doc_binding_task_t));
1312     if(!task)
1313         return E_OUTOFMEMORY;
1314
1315     task->window = window;
1316     task->bscallback = bscallback;
1317     IBindStatusCallback_AddRef(STATUSCLB(&bscallback->bsc));
1318
1319     push_task(&task->header, start_doc_binding_proc, window->task_magic);
1320     return S_OK;
1321 }
1322
1323 void abort_document_bindings(HTMLDocumentNode *doc)
1324 {
1325     BSCallback *iter;
1326
1327     LIST_FOR_EACH_ENTRY(iter, &doc->bindings, BSCallback, entry) {
1328         if(iter->binding)
1329             IBinding_Abort(iter->binding);
1330         iter->doc = NULL;
1331         list_remove(&iter->entry);
1332     }
1333 }
1334
1335 HRESULT channelbsc_load_stream(nsChannelBSC *bscallback, IStream *stream)
1336 {
1337     HRESULT hres = S_OK;
1338
1339     if(!bscallback->nschannel) {
1340         ERR("NULL nschannel\n");
1341         return E_FAIL;
1342     }
1343
1344     bscallback->nschannel->content_type = heap_strdupA("text/html");
1345     if(!bscallback->nschannel->content_type)
1346         return E_OUTOFMEMORY;
1347
1348     if(stream)
1349         hres = read_stream_data(bscallback, stream);
1350     if(SUCCEEDED(hres))
1351         hres = async_stop_request(bscallback);
1352     if(FAILED(hres))
1353         IBindStatusCallback_OnStopBinding(STATUSCLB(&bscallback->bsc), hres, ERROR_SUCCESS);
1354
1355     return hres;
1356 }
1357
1358 void channelbsc_set_channel(nsChannelBSC *This, nsChannel *channel, nsIStreamListener *listener, nsISupports *context)
1359 {
1360     nsIChannel_AddRef(&channel->nsIHttpChannel_iface);
1361     This->nschannel = channel;
1362
1363     nsIStreamListener_AddRef(listener);
1364     This->nslistener = listener;
1365
1366     if(context) {
1367         nsISupports_AddRef(context);
1368         This->nscontext = context;
1369     }
1370
1371     if(This->bsc.headers) {
1372         HRESULT hres;
1373
1374         hres = parse_headers(This->bsc.headers, &channel->request_headers);
1375         heap_free(This->bsc.headers);
1376         This->bsc.headers = NULL;
1377         if(FAILED(hres))
1378             WARN("parse_headers failed: %08x\n", hres);
1379     }
1380 }
1381
1382 HRESULT hlink_frame_navigate(HTMLDocument *doc, LPCWSTR url,
1383         nsIInputStream *post_data_stream, DWORD hlnf, BOOL *cancel)
1384 {
1385     IHlinkFrame *hlink_frame;
1386     nsChannelBSC *callback;
1387     IServiceProvider *sp;
1388     IBindCtx *bindctx;
1389     IMoniker *mon;
1390     IHlink *hlink;
1391     HRESULT hres;
1392
1393     *cancel = FALSE;
1394
1395     hres = IOleClientSite_QueryInterface(doc->doc_obj->client, &IID_IServiceProvider,
1396             (void**)&sp);
1397     if(FAILED(hres))
1398         return S_OK;
1399
1400     hres = IServiceProvider_QueryService(sp, &IID_IHlinkFrame, &IID_IHlinkFrame,
1401             (void**)&hlink_frame);
1402     IServiceProvider_Release(sp);
1403     if(FAILED(hres))
1404         return S_OK;
1405
1406     hres = create_channelbsc(NULL, NULL, NULL, 0, &callback);
1407     if(FAILED(hres)) {
1408         IHlinkFrame_Release(hlink_frame);
1409         return hres;
1410     }
1411
1412     if(post_data_stream) {
1413         read_post_data_stream(post_data_stream, &callback->bsc.post_data, &callback->bsc.post_data_len);
1414         TRACE("post_data = %s\n", debugstr_an(callback->bsc.post_data, callback->bsc.post_data_len));
1415     }
1416
1417     hres = CreateAsyncBindCtx(0, STATUSCLB(&callback->bsc), NULL, &bindctx);
1418     if(SUCCEEDED(hres))
1419         hres = CoCreateInstance(&CLSID_StdHlink, NULL, CLSCTX_INPROC_SERVER,
1420                 &IID_IHlink, (LPVOID*)&hlink);
1421
1422     if(SUCCEEDED(hres))
1423         hres = CreateURLMoniker(NULL, url, &mon);
1424
1425     if(SUCCEEDED(hres)) {
1426         IHlink_SetMonikerReference(hlink, HLINKSETF_TARGET, mon, NULL);
1427
1428         if(hlnf & HLNF_OPENINNEWWINDOW) {
1429             static const WCHAR wszBlank[] = {'_','b','l','a','n','k',0};
1430             IHlink_SetTargetFrameName(hlink, wszBlank); /* FIXME */
1431         }
1432
1433         hres = IHlinkFrame_Navigate(hlink_frame, hlnf, bindctx, STATUSCLB(&callback->bsc), hlink);
1434         IMoniker_Release(mon);
1435         *cancel = hres == S_OK;
1436         hres = S_OK;
1437     }
1438
1439     IHlinkFrame_Release(hlink_frame);
1440     IBindCtx_Release(bindctx);
1441     IBindStatusCallback_Release(STATUSCLB(&callback->bsc));
1442     return hres;
1443 }
1444
1445 HRESULT navigate_url(HTMLWindow *window, const WCHAR *new_url, const WCHAR *base_url)
1446 {
1447     WCHAR url[INTERNET_MAX_URL_LENGTH];
1448     nsWineURI *uri;
1449     HRESULT hres;
1450
1451     if(!new_url) {
1452         *url = 0;
1453     }else if(base_url) {
1454         DWORD len = 0;
1455
1456         hres = CoInternetCombineUrl(base_url, new_url, URL_ESCAPE_SPACES_ONLY|URL_DONT_ESCAPE_EXTRA_INFO,
1457                 url, sizeof(url)/sizeof(WCHAR), &len, 0);
1458         if(FAILED(hres))
1459             return hres;
1460     }else {
1461         strcpyW(url, new_url);
1462     }
1463
1464     if(window->doc_obj && window->doc_obj->hostui) {
1465         OLECHAR *translated_url = NULL;
1466
1467         hres = IDocHostUIHandler_TranslateUrl(window->doc_obj->hostui, 0, url,
1468                 &translated_url);
1469         if(hres == S_OK) {
1470             TRACE("%08x %s -> %s\n", hres, debugstr_w(url), debugstr_w(translated_url));
1471             strcpyW(url, translated_url);
1472             CoTaskMemFree(translated_url);
1473         }
1474     }
1475
1476     if(window->doc_obj && window == window->doc_obj->basedoc.window) {
1477         BOOL cancel;
1478
1479         hres = hlink_frame_navigate(&window->doc->basedoc, url, NULL, 0, &cancel);
1480         if(FAILED(hres))
1481             return hres;
1482
1483         if(cancel) {
1484             TRACE("Navigation handled by hlink frame\n");
1485             return S_OK;
1486         }
1487     }
1488
1489     hres = create_doc_uri(window, url, &uri);
1490     if(FAILED(hres))
1491         return hres;
1492
1493     hres = load_nsuri(window, uri, NULL, LOAD_FLAGS_NONE);
1494     nsISupports_Release((nsISupports*)uri);
1495     return hres;
1496 }