quartz: Remove superfluous pointer casts.
[wine] / dlls / wininet / http.c
1 /*
2  * Wininet - Http Implementation
3  *
4  * Copyright 1999 Corel Corporation
5  * Copyright 2002 CodeWeavers Inc.
6  * Copyright 2002 TransGaming Technologies Inc.
7  * Copyright 2004 Mike McCormack for CodeWeavers
8  * Copyright 2005 Aric Stewart for CodeWeavers
9  * Copyright 2006 Robert Shearman for CodeWeavers
10  *
11  * Ulrich Czekalla
12  * David Hammerton
13  *
14  * This library is free software; you can redistribute it and/or
15  * modify it under the terms of the GNU Lesser General Public
16  * License as published by the Free Software Foundation; either
17  * version 2.1 of the License, or (at your option) any later version.
18  *
19  * This library is distributed in the hope that it will be useful,
20  * but WITHOUT ANY WARRANTY; without even the implied warranty of
21  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
22  * Lesser General Public License for more details.
23  *
24  * You should have received a copy of the GNU Lesser General Public
25  * License along with this library; if not, write to the Free Software
26  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
27  */
28
29 #include "config.h"
30 #include "wine/port.h"
31
32 #if defined(__MINGW32__) || defined (_MSC_VER)
33 #include <ws2tcpip.h>
34 #endif
35
36 #include <sys/types.h>
37 #ifdef HAVE_SYS_SOCKET_H
38 # include <sys/socket.h>
39 #endif
40 #ifdef HAVE_ARPA_INET_H
41 # include <arpa/inet.h>
42 #endif
43 #include <stdarg.h>
44 #include <stdio.h>
45 #include <stdlib.h>
46 #ifdef HAVE_UNISTD_H
47 # include <unistd.h>
48 #endif
49 #include <time.h>
50 #include <assert.h>
51
52 #include "windef.h"
53 #include "winbase.h"
54 #include "wininet.h"
55 #include "winerror.h"
56 #define NO_SHLWAPI_STREAM
57 #define NO_SHLWAPI_REG
58 #define NO_SHLWAPI_STRFCNS
59 #define NO_SHLWAPI_GDI
60 #include "shlwapi.h"
61 #include "sspi.h"
62 #include "wincrypt.h"
63
64 #include "internet.h"
65 #include "wine/debug.h"
66 #include "wine/exception.h"
67 #include "wine/unicode.h"
68
69 WINE_DEFAULT_DEBUG_CHANNEL(wininet);
70
71 static const WCHAR g_szHttp1_0[] = {'H','T','T','P','/','1','.','0',0};
72 static const WCHAR g_szHttp1_1[] = {'H','T','T','P','/','1','.','1',0};
73 static const WCHAR g_szReferer[] = {'R','e','f','e','r','e','r',0};
74 static const WCHAR g_szAccept[] = {'A','c','c','e','p','t',0};
75 static const WCHAR g_szUserAgent[] = {'U','s','e','r','-','A','g','e','n','t',0};
76 static const WCHAR szHost[] = { 'H','o','s','t',0 };
77 static const WCHAR szAuthorization[] = { 'A','u','t','h','o','r','i','z','a','t','i','o','n',0 };
78 static const WCHAR szProxy_Authorization[] = { 'P','r','o','x','y','-','A','u','t','h','o','r','i','z','a','t','i','o','n',0 };
79 static const WCHAR szStatus[] = { 'S','t','a','t','u','s',0 };
80 static const WCHAR szKeepAlive[] = {'K','e','e','p','-','A','l','i','v','e',0};
81 static const WCHAR szGET[] = { 'G','E','T', 0 };
82 static const WCHAR szCrLf[] = {'\r','\n', 0};
83
84 #define MAXHOSTNAME 100
85 #define MAX_FIELD_VALUE_LEN 256
86 #define MAX_FIELD_LEN 256
87
88 #define HTTP_REFERER    g_szReferer
89 #define HTTP_ACCEPT     g_szAccept
90 #define HTTP_USERAGENT  g_szUserAgent
91
92 #define HTTP_ADDHDR_FLAG_ADD                            0x20000000
93 #define HTTP_ADDHDR_FLAG_ADD_IF_NEW                     0x10000000
94 #define HTTP_ADDHDR_FLAG_COALESCE                       0x40000000
95 #define HTTP_ADDHDR_FLAG_COALESCE_WITH_COMMA            0x40000000
96 #define HTTP_ADDHDR_FLAG_COALESCE_WITH_SEMICOLON        0x01000000
97 #define HTTP_ADDHDR_FLAG_REPLACE                        0x80000000
98 #define HTTP_ADDHDR_FLAG_REQ                            0x02000000
99
100 #define ARRAYSIZE(array) (sizeof(array)/sizeof((array)[0]))
101
102 struct HttpAuthInfo
103 {
104     LPWSTR scheme;
105     CredHandle cred;
106     CtxtHandle ctx;
107     TimeStamp exp;
108     ULONG attr;
109     ULONG max_token;
110     void *auth_data;
111     unsigned int auth_data_len;
112     BOOL finished; /* finished authenticating */
113 };
114
115 static BOOL HTTP_OpenConnection(LPWININETHTTPREQW lpwhr);
116 static BOOL HTTP_GetResponseHeaders(LPWININETHTTPREQW lpwhr, BOOL clear);
117 static BOOL HTTP_ProcessHeader(LPWININETHTTPREQW lpwhr, LPCWSTR field, LPCWSTR value, DWORD dwModifier);
118 static LPWSTR * HTTP_InterpretHttpHeader(LPCWSTR buffer);
119 static BOOL HTTP_InsertCustomHeader(LPWININETHTTPREQW lpwhr, LPHTTPHEADERW lpHdr);
120 static INT HTTP_GetCustomHeaderIndex(LPWININETHTTPREQW lpwhr, LPCWSTR lpszField, INT index, BOOL Request);
121 static BOOL HTTP_DeleteCustomHeader(LPWININETHTTPREQW lpwhr, DWORD index);
122 static LPWSTR HTTP_build_req( LPCWSTR *list, int len );
123 static BOOL HTTP_HttpQueryInfoW(LPWININETHTTPREQW, DWORD, LPVOID, LPDWORD, LPDWORD);
124 static BOOL HTTP_HandleRedirect(LPWININETHTTPREQW lpwhr, LPCWSTR lpszUrl);
125 static UINT HTTP_DecodeBase64(LPCWSTR base64, LPSTR bin);
126 static BOOL HTTP_VerifyValidHeader(LPWININETHTTPREQW lpwhr, LPCWSTR field);
127 static void HTTP_DrainContent(WININETHTTPREQW *req);
128
129 LPHTTPHEADERW HTTP_GetHeader(LPWININETHTTPREQW req, LPCWSTR head)
130 {
131     int HeaderIndex = 0;
132     HeaderIndex = HTTP_GetCustomHeaderIndex(req, head, 0, TRUE);
133     if (HeaderIndex == -1)
134         return NULL;
135     else
136         return &req->pCustHeaders[HeaderIndex];
137 }
138
139 /***********************************************************************
140  *           HTTP_Tokenize (internal)
141  *
142  *  Tokenize a string, allocating memory for the tokens.
143  */
144 static LPWSTR * HTTP_Tokenize(LPCWSTR string, LPCWSTR token_string)
145 {
146     LPWSTR * token_array;
147     int tokens = 0;
148     int i;
149     LPCWSTR next_token;
150
151     if (string)
152     {
153         /* empty string has no tokens */
154         if (*string)
155             tokens++;
156         /* count tokens */
157         for (i = 0; string[i]; i++)
158         {
159             if (!strncmpW(string+i, token_string, strlenW(token_string)))
160             {
161                 DWORD j;
162                 tokens++;
163                 /* we want to skip over separators, but not the null terminator */
164                 for (j = 0; j < strlenW(token_string) - 1; j++)
165                     if (!string[i+j])
166                         break;
167                 i += j;
168             }
169         }
170     }
171
172     /* add 1 for terminating NULL */
173     token_array = HeapAlloc(GetProcessHeap(), 0, (tokens+1) * sizeof(*token_array));
174     token_array[tokens] = NULL;
175     if (!tokens)
176         return token_array;
177     for (i = 0; i < tokens; i++)
178     {
179         int len;
180         next_token = strstrW(string, token_string);
181         if (!next_token) next_token = string+strlenW(string);
182         len = next_token - string;
183         token_array[i] = HeapAlloc(GetProcessHeap(), 0, (len+1)*sizeof(WCHAR));
184         memcpy(token_array[i], string, len*sizeof(WCHAR));
185         token_array[i][len] = '\0';
186         string = next_token+strlenW(token_string);
187     }
188     return token_array;
189 }
190
191 /***********************************************************************
192  *           HTTP_FreeTokens (internal)
193  *
194  *  Frees memory returned from HTTP_Tokenize.
195  */
196 static void HTTP_FreeTokens(LPWSTR * token_array)
197 {
198     int i;
199     for (i = 0; token_array[i]; i++)
200         HeapFree(GetProcessHeap(), 0, token_array[i]);
201     HeapFree(GetProcessHeap(), 0, token_array);
202 }
203
204 /* **********************************************************************
205  * 
206  * Helper functions for the HttpSendRequest(Ex) functions
207  * 
208  */
209 static void AsyncHttpSendRequestProc(WORKREQUEST *workRequest)
210 {
211     struct WORKREQ_HTTPSENDREQUESTW const *req = &workRequest->u.HttpSendRequestW;
212     LPWININETHTTPREQW lpwhr = (LPWININETHTTPREQW) workRequest->hdr;
213
214     TRACE("%p\n", lpwhr);
215
216     HTTP_HttpSendRequestW(lpwhr, req->lpszHeader,
217             req->dwHeaderLength, req->lpOptional, req->dwOptionalLength,
218             req->dwContentLength, req->bEndRequest);
219
220     HeapFree(GetProcessHeap(), 0, req->lpszHeader);
221 }
222
223 static void HTTP_FixURL( LPWININETHTTPREQW lpwhr)
224 {
225     static const WCHAR szSlash[] = { '/',0 };
226     static const WCHAR szHttp[] = { 'h','t','t','p',':','/','/', 0 };
227
228     /* If we don't have a path we set it to root */
229     if (NULL == lpwhr->lpszPath)
230         lpwhr->lpszPath = WININET_strdupW(szSlash);
231     else /* remove \r and \n*/
232     {
233         int nLen = strlenW(lpwhr->lpszPath);
234         while ((nLen >0 ) && ((lpwhr->lpszPath[nLen-1] == '\r')||(lpwhr->lpszPath[nLen-1] == '\n')))
235         {
236             nLen--;
237             lpwhr->lpszPath[nLen]='\0';
238         }
239         /* Replace '\' with '/' */
240         while (nLen>0) {
241             nLen--;
242             if (lpwhr->lpszPath[nLen] == '\\') lpwhr->lpszPath[nLen]='/';
243         }
244     }
245
246     if(CSTR_EQUAL != CompareStringW( LOCALE_SYSTEM_DEFAULT, NORM_IGNORECASE,
247                        lpwhr->lpszPath, strlenW(lpwhr->lpszPath), szHttp, strlenW(szHttp) )
248        && lpwhr->lpszPath[0] != '/') /* not an absolute path ?? --> fix it !! */
249     {
250         WCHAR *fixurl = HeapAlloc(GetProcessHeap(), 0, 
251                              (strlenW(lpwhr->lpszPath) + 2)*sizeof(WCHAR));
252         *fixurl = '/';
253         strcpyW(fixurl + 1, lpwhr->lpszPath);
254         HeapFree( GetProcessHeap(), 0, lpwhr->lpszPath );
255         lpwhr->lpszPath = fixurl;
256     }
257 }
258
259 static LPWSTR HTTP_BuildHeaderRequestString( LPWININETHTTPREQW lpwhr, LPCWSTR verb, LPCWSTR path, LPCWSTR version )
260 {
261     LPWSTR requestString;
262     DWORD len, n;
263     LPCWSTR *req;
264     UINT i;
265     LPWSTR p;
266
267     static const WCHAR szSpace[] = { ' ',0 };
268     static const WCHAR szColon[] = { ':',' ',0 };
269     static const WCHAR sztwocrlf[] = {'\r','\n','\r','\n', 0};
270
271     /* allocate space for an array of all the string pointers to be added */
272     len = (lpwhr->nCustHeaders)*4 + 10;
273     req = HeapAlloc( GetProcessHeap(), 0, len*sizeof(LPCWSTR) );
274
275     /* add the verb, path and HTTP version string */
276     n = 0;
277     req[n++] = verb;
278     req[n++] = szSpace;
279     req[n++] = path;
280     req[n++] = szSpace;
281     req[n++] = version;
282
283     /* Append custom request headers */
284     for (i = 0; i < lpwhr->nCustHeaders; i++)
285     {
286         if (lpwhr->pCustHeaders[i].wFlags & HDR_ISREQUEST)
287         {
288             req[n++] = szCrLf;
289             req[n++] = lpwhr->pCustHeaders[i].lpszField;
290             req[n++] = szColon;
291             req[n++] = lpwhr->pCustHeaders[i].lpszValue;
292
293             TRACE("Adding custom header %s (%s)\n",
294                    debugstr_w(lpwhr->pCustHeaders[i].lpszField),
295                    debugstr_w(lpwhr->pCustHeaders[i].lpszValue));
296         }
297     }
298
299     if( n >= len )
300         ERR("oops. buffer overrun\n");
301
302     req[n] = NULL;
303     requestString = HTTP_build_req( req, 4 );
304     HeapFree( GetProcessHeap(), 0, req );
305
306     /*
307      * Set (header) termination string for request
308      * Make sure there's exactly two new lines at the end of the request
309      */
310     p = &requestString[strlenW(requestString)-1];
311     while ( (*p == '\n') || (*p == '\r') )
312        p--;
313     strcpyW( p+1, sztwocrlf );
314     
315     return requestString;
316 }
317
318 static void HTTP_ProcessCookies( LPWININETHTTPREQW lpwhr )
319 {
320     static const WCHAR szSet_Cookie[] = { 'S','e','t','-','C','o','o','k','i','e',0 };
321     int HeaderIndex;
322     int numCookies = 0;
323     LPHTTPHEADERW setCookieHeader;
324
325     while((HeaderIndex = HTTP_GetCustomHeaderIndex(lpwhr, szSet_Cookie, numCookies, FALSE)) != -1)
326     {
327         setCookieHeader = &lpwhr->pCustHeaders[HeaderIndex];
328
329         if (!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_COOKIES) && setCookieHeader->lpszValue)
330         {
331             int nPosStart = 0, nPosEnd = 0, len;
332             static const WCHAR szFmt[] = { 'h','t','t','p',':','/','/','%','s','/',0};
333
334             while (setCookieHeader->lpszValue[nPosEnd] != '\0')
335             {
336                 LPWSTR buf_cookie, cookie_name, cookie_data;
337                 LPWSTR buf_url;
338                 LPWSTR domain = NULL;
339                 LPHTTPHEADERW Host;
340
341                 int nEqualPos = 0;
342                 while (setCookieHeader->lpszValue[nPosEnd] != ';' && setCookieHeader->lpszValue[nPosEnd] != ',' &&
343                        setCookieHeader->lpszValue[nPosEnd] != '\0')
344                 {
345                     nPosEnd++;
346                 }
347                 if (setCookieHeader->lpszValue[nPosEnd] == ';')
348                 {
349                     /* fixme: not case sensitive, strcasestr is gnu only */
350                     int nDomainPosEnd = 0;
351                     int nDomainPosStart = 0, nDomainLength = 0;
352                     static const WCHAR szDomain[] = {'d','o','m','a','i','n','=',0};
353                     LPWSTR lpszDomain = strstrW(&setCookieHeader->lpszValue[nPosEnd], szDomain);
354                     if (lpszDomain)
355                     { /* they have specified their own domain, lets use it */
356                         while (lpszDomain[nDomainPosEnd] != ';' && lpszDomain[nDomainPosEnd] != ',' &&
357                                lpszDomain[nDomainPosEnd] != '\0')
358                         {
359                             nDomainPosEnd++;
360                         }
361                         nDomainPosStart = strlenW(szDomain);
362                         nDomainLength = (nDomainPosEnd - nDomainPosStart) + 1;
363                         domain = HeapAlloc(GetProcessHeap(), 0, (nDomainLength + 1)*sizeof(WCHAR));
364                         lstrcpynW(domain, &lpszDomain[nDomainPosStart], nDomainLength + 1);
365                     }
366                 }
367                 if (setCookieHeader->lpszValue[nPosEnd] == '\0') break;
368                 buf_cookie = HeapAlloc(GetProcessHeap(), 0, ((nPosEnd - nPosStart) + 1)*sizeof(WCHAR));
369                 lstrcpynW(buf_cookie, &setCookieHeader->lpszValue[nPosStart], (nPosEnd - nPosStart) + 1);
370                 TRACE("%s\n", debugstr_w(buf_cookie));
371                 while (buf_cookie[nEqualPos] != '=' && buf_cookie[nEqualPos] != '\0')
372                 {
373                     nEqualPos++;
374                 }
375                 if (buf_cookie[nEqualPos] == '\0' || buf_cookie[nEqualPos + 1] == '\0')
376                 {
377                     HeapFree(GetProcessHeap(), 0, buf_cookie);
378                     break;
379                 }
380
381                 cookie_name = HeapAlloc(GetProcessHeap(), 0, (nEqualPos + 1)*sizeof(WCHAR));
382                 lstrcpynW(cookie_name, buf_cookie, nEqualPos + 1);
383                 cookie_data = &buf_cookie[nEqualPos + 1];
384
385                 Host = HTTP_GetHeader(lpwhr,szHost);
386                 len = lstrlenW((domain ? domain : (Host?Host->lpszValue:NULL))) +
387                     strlenW(lpwhr->lpszPath) + 9;
388                 buf_url = HeapAlloc(GetProcessHeap(), 0, len*sizeof(WCHAR));
389                 sprintfW(buf_url, szFmt, (domain ? domain : (Host?Host->lpszValue:NULL))); /* FIXME PATH!!! */
390                 InternetSetCookieW(buf_url, cookie_name, cookie_data);
391
392                 HeapFree(GetProcessHeap(), 0, buf_url);
393                 HeapFree(GetProcessHeap(), 0, buf_cookie);
394                 HeapFree(GetProcessHeap(), 0, cookie_name);
395                 HeapFree(GetProcessHeap(), 0, domain);
396                 nPosStart = nPosEnd;
397             }
398         }
399         numCookies++;
400     }
401 }
402
403 static inline BOOL is_basic_auth_value( LPCWSTR pszAuthValue )
404 {
405     static const WCHAR szBasic[] = {'B','a','s','i','c'}; /* Note: not nul-terminated */
406     return !strncmpiW(pszAuthValue, szBasic, ARRAYSIZE(szBasic)) &&
407         ((pszAuthValue[ARRAYSIZE(szBasic)] == ' ') || !pszAuthValue[ARRAYSIZE(szBasic)]);
408 }
409
410 static BOOL HTTP_DoAuthorization( LPWININETHTTPREQW lpwhr, LPCWSTR pszAuthValue,
411                                   struct HttpAuthInfo **ppAuthInfo,
412                                   LPWSTR domain_and_username, LPWSTR password )
413 {
414     SECURITY_STATUS sec_status;
415     struct HttpAuthInfo *pAuthInfo = *ppAuthInfo;
416     BOOL first = FALSE;
417
418     TRACE("%s\n", debugstr_w(pszAuthValue));
419
420     if (!pAuthInfo)
421     {
422         TimeStamp exp;
423
424         first = TRUE;
425         pAuthInfo = HeapAlloc(GetProcessHeap(), 0, sizeof(*pAuthInfo));
426         if (!pAuthInfo)
427             return FALSE;
428
429         SecInvalidateHandle(&pAuthInfo->cred);
430         SecInvalidateHandle(&pAuthInfo->ctx);
431         memset(&pAuthInfo->exp, 0, sizeof(pAuthInfo->exp));
432         pAuthInfo->attr = 0;
433         pAuthInfo->auth_data = NULL;
434         pAuthInfo->auth_data_len = 0;
435         pAuthInfo->finished = FALSE;
436
437         if (is_basic_auth_value(pszAuthValue))
438         {
439             static const WCHAR szBasic[] = {'B','a','s','i','c',0};
440             pAuthInfo->scheme = WININET_strdupW(szBasic);
441             if (!pAuthInfo->scheme)
442             {
443                 HeapFree(GetProcessHeap(), 0, pAuthInfo);
444                 return FALSE;
445             }
446         }
447         else
448         {
449             PVOID pAuthData;
450             SEC_WINNT_AUTH_IDENTITY_W nt_auth_identity;
451
452             pAuthInfo->scheme = WININET_strdupW(pszAuthValue);
453             if (!pAuthInfo->scheme)
454             {
455                 HeapFree(GetProcessHeap(), 0, pAuthInfo);
456                 return FALSE;
457             }
458
459             if (domain_and_username)
460             {
461                 WCHAR *user = strchrW(domain_and_username, '\\');
462                 WCHAR *domain = domain_and_username;
463
464                 /* FIXME: make sure scheme accepts SEC_WINNT_AUTH_IDENTITY before calling AcquireCredentialsHandle */
465
466                 pAuthData = &nt_auth_identity;
467
468                 if (user) user++;
469                 else
470                 {
471                     user = domain_and_username;
472                     domain = NULL;
473                 }
474
475                 nt_auth_identity.Flags = SEC_WINNT_AUTH_IDENTITY_UNICODE;
476                 nt_auth_identity.User = user;
477                 nt_auth_identity.UserLength = strlenW(nt_auth_identity.User);
478                 nt_auth_identity.Domain = domain;
479                 nt_auth_identity.DomainLength = domain ? user - domain - 1 : 0;
480                 nt_auth_identity.Password = password;
481                 nt_auth_identity.PasswordLength = strlenW(nt_auth_identity.Password);
482             }
483             else
484                 /* use default credentials */
485                 pAuthData = NULL;
486
487             sec_status = AcquireCredentialsHandleW(NULL, pAuthInfo->scheme,
488                                                    SECPKG_CRED_OUTBOUND, NULL,
489                                                    pAuthData, NULL,
490                                                    NULL, &pAuthInfo->cred,
491                                                    &exp);
492             if (sec_status == SEC_E_OK)
493             {
494                 PSecPkgInfoW sec_pkg_info;
495                 sec_status = QuerySecurityPackageInfoW(pAuthInfo->scheme, &sec_pkg_info);
496                 if (sec_status == SEC_E_OK)
497                 {
498                     pAuthInfo->max_token = sec_pkg_info->cbMaxToken;
499                     FreeContextBuffer(sec_pkg_info);
500                 }
501             }
502             if (sec_status != SEC_E_OK)
503             {
504                 WARN("AcquireCredentialsHandleW for scheme %s failed with error 0x%08x\n",
505                      debugstr_w(pAuthInfo->scheme), sec_status);
506                 HeapFree(GetProcessHeap(), 0, pAuthInfo->scheme);
507                 HeapFree(GetProcessHeap(), 0, pAuthInfo);
508                 return FALSE;
509             }
510         }
511         *ppAuthInfo = pAuthInfo;
512     }
513     else if (pAuthInfo->finished)
514         return FALSE;
515
516     if ((strlenW(pszAuthValue) < strlenW(pAuthInfo->scheme)) ||
517         strncmpiW(pszAuthValue, pAuthInfo->scheme, strlenW(pAuthInfo->scheme)))
518     {
519         ERR("authentication scheme changed from %s to %s\n",
520             debugstr_w(pAuthInfo->scheme), debugstr_w(pszAuthValue));
521         return FALSE;
522     }
523
524     if (is_basic_auth_value(pszAuthValue))
525     {
526         int userlen;
527         int passlen;
528         char *auth_data;
529
530         TRACE("basic authentication\n");
531
532         /* we don't cache credentials for basic authentication, so we can't
533          * retrieve them if the application didn't pass us any credentials */
534         if (!domain_and_username) return FALSE;
535
536         userlen = WideCharToMultiByte(CP_UTF8, 0, domain_and_username, lstrlenW(domain_and_username), NULL, 0, NULL, NULL);
537         passlen = WideCharToMultiByte(CP_UTF8, 0, password, lstrlenW(password), NULL, 0, NULL, NULL);
538
539         /* length includes a nul terminator, which will be re-used for the ':' */
540         auth_data = HeapAlloc(GetProcessHeap(), 0, userlen + 1 + passlen);
541         if (!auth_data)
542             return FALSE;
543
544         WideCharToMultiByte(CP_UTF8, 0, domain_and_username, -1, auth_data, userlen, NULL, NULL);
545         auth_data[userlen] = ':';
546         WideCharToMultiByte(CP_UTF8, 0, password, -1, &auth_data[userlen+1], passlen, NULL, NULL);
547
548         pAuthInfo->auth_data = auth_data;
549         pAuthInfo->auth_data_len = userlen + 1 + passlen;
550         pAuthInfo->finished = TRUE;
551
552         return TRUE;
553     }
554     else
555     {
556         LPCWSTR pszAuthData;
557         SecBufferDesc out_desc, in_desc;
558         SecBuffer out, in;
559         unsigned char *buffer;
560         ULONG context_req = ISC_REQ_CONNECTION | ISC_REQ_USE_DCE_STYLE |
561             ISC_REQ_MUTUAL_AUTH | ISC_REQ_DELEGATE;
562
563         in.BufferType = SECBUFFER_TOKEN;
564         in.cbBuffer = 0;
565         in.pvBuffer = NULL;
566
567         in_desc.ulVersion = 0;
568         in_desc.cBuffers = 1;
569         in_desc.pBuffers = &in;
570
571         pszAuthData = pszAuthValue + strlenW(pAuthInfo->scheme);
572         if (*pszAuthData == ' ')
573         {
574             pszAuthData++;
575             in.cbBuffer = HTTP_DecodeBase64(pszAuthData, NULL);
576             in.pvBuffer = HeapAlloc(GetProcessHeap(), 0, in.cbBuffer);
577             HTTP_DecodeBase64(pszAuthData, in.pvBuffer);
578         }
579
580         buffer = HeapAlloc(GetProcessHeap(), 0, pAuthInfo->max_token);
581
582         out.BufferType = SECBUFFER_TOKEN;
583         out.cbBuffer = pAuthInfo->max_token;
584         out.pvBuffer = buffer;
585
586         out_desc.ulVersion = 0;
587         out_desc.cBuffers = 1;
588         out_desc.pBuffers = &out;
589
590         sec_status = InitializeSecurityContextW(first ? &pAuthInfo->cred : NULL,
591                                                 first ? NULL : &pAuthInfo->ctx,
592                                                 first ? lpwhr->lpHttpSession->lpszServerName : NULL,
593                                                 context_req, 0, SECURITY_NETWORK_DREP,
594                                                 in.pvBuffer ? &in_desc : NULL,
595                                                 0, &pAuthInfo->ctx, &out_desc,
596                                                 &pAuthInfo->attr, &pAuthInfo->exp);
597         if (sec_status == SEC_E_OK)
598         {
599             pAuthInfo->finished = TRUE;
600             pAuthInfo->auth_data = out.pvBuffer;
601             pAuthInfo->auth_data_len = out.cbBuffer;
602             TRACE("sending last auth packet\n");
603         }
604         else if (sec_status == SEC_I_CONTINUE_NEEDED)
605         {
606             pAuthInfo->auth_data = out.pvBuffer;
607             pAuthInfo->auth_data_len = out.cbBuffer;
608             TRACE("sending next auth packet\n");
609         }
610         else
611         {
612             ERR("InitializeSecurityContextW returned error 0x%08x\n", sec_status);
613             pAuthInfo->finished = TRUE;
614             HeapFree(GetProcessHeap(), 0, out.pvBuffer);
615             return FALSE;
616         }
617     }
618
619     return TRUE;
620 }
621
622 /***********************************************************************
623  *           HTTP_HttpAddRequestHeadersW (internal)
624  */
625 static BOOL HTTP_HttpAddRequestHeadersW(LPWININETHTTPREQW lpwhr,
626         LPCWSTR lpszHeader, DWORD dwHeaderLength, DWORD dwModifier)
627 {
628     LPWSTR lpszStart;
629     LPWSTR lpszEnd;
630     LPWSTR buffer;
631     BOOL bSuccess = FALSE;
632     DWORD len;
633
634     TRACE("copying header: %s\n", debugstr_wn(lpszHeader, dwHeaderLength));
635
636     if( dwHeaderLength == ~0U )
637         len = strlenW(lpszHeader);
638     else
639         len = dwHeaderLength;
640     buffer = HeapAlloc( GetProcessHeap(), 0, sizeof(WCHAR)*(len+1) );
641     lstrcpynW( buffer, lpszHeader, len + 1);
642
643     lpszStart = buffer;
644
645     do
646     {
647         LPWSTR * pFieldAndValue;
648
649         lpszEnd = lpszStart;
650
651         while (*lpszEnd != '\0')
652         {
653             if (*lpszEnd == '\r' && *(lpszEnd + 1) == '\n')
654                  break;
655             lpszEnd++;
656         }
657
658         if (*lpszStart == '\0')
659             break;
660
661         if (*lpszEnd == '\r')
662         {
663             *lpszEnd = '\0';
664             lpszEnd += 2; /* Jump over \r\n */
665         }
666         TRACE("interpreting header %s\n", debugstr_w(lpszStart));
667         pFieldAndValue = HTTP_InterpretHttpHeader(lpszStart);
668         if (pFieldAndValue)
669         {
670             bSuccess = HTTP_VerifyValidHeader(lpwhr, pFieldAndValue[0]);
671             if (bSuccess)
672                 bSuccess = HTTP_ProcessHeader(lpwhr, pFieldAndValue[0],
673                     pFieldAndValue[1], dwModifier | HTTP_ADDHDR_FLAG_REQ);
674             HTTP_FreeTokens(pFieldAndValue);
675         }
676
677         lpszStart = lpszEnd;
678     } while (bSuccess);
679
680     HeapFree(GetProcessHeap(), 0, buffer);
681
682     return bSuccess;
683 }
684
685 /***********************************************************************
686  *           HttpAddRequestHeadersW (WININET.@)
687  *
688  * Adds one or more HTTP header to the request handler
689  *
690  * NOTE
691  * On Windows if dwHeaderLength includes the trailing '\0', then
692  * HttpAddRequestHeadersW() adds it too. However this results in an
693  * invalid Http header which is rejected by some servers so we probably
694  * don't need to match Windows on that point.
695  *
696  * RETURNS
697  *    TRUE  on success
698  *    FALSE on failure
699  *
700  */
701 BOOL WINAPI HttpAddRequestHeadersW(HINTERNET hHttpRequest,
702         LPCWSTR lpszHeader, DWORD dwHeaderLength, DWORD dwModifier)
703 {
704     BOOL bSuccess = FALSE;
705     LPWININETHTTPREQW lpwhr;
706
707     TRACE("%p, %s, %i, %i\n", hHttpRequest, debugstr_wn(lpszHeader, dwHeaderLength), dwHeaderLength, dwModifier);
708
709     if (!lpszHeader) 
710       return TRUE;
711
712     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hHttpRequest );
713     if (NULL == lpwhr ||  lpwhr->hdr.htype != WH_HHTTPREQ)
714     {
715         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
716         goto lend;
717     }
718     bSuccess = HTTP_HttpAddRequestHeadersW( lpwhr, lpszHeader, dwHeaderLength, dwModifier );
719 lend:
720     if( lpwhr )
721         WININET_Release( &lpwhr->hdr );
722
723     return bSuccess;
724 }
725
726 /***********************************************************************
727  *           HttpAddRequestHeadersA (WININET.@)
728  *
729  * Adds one or more HTTP header to the request handler
730  *
731  * RETURNS
732  *    TRUE  on success
733  *    FALSE on failure
734  *
735  */
736 BOOL WINAPI HttpAddRequestHeadersA(HINTERNET hHttpRequest,
737         LPCSTR lpszHeader, DWORD dwHeaderLength, DWORD dwModifier)
738 {
739     DWORD len;
740     LPWSTR hdr;
741     BOOL r;
742
743     TRACE("%p, %s, %i, %i\n", hHttpRequest, debugstr_an(lpszHeader, dwHeaderLength), dwHeaderLength, dwModifier);
744
745     len = MultiByteToWideChar( CP_ACP, 0, lpszHeader, dwHeaderLength, NULL, 0 );
746     hdr = HeapAlloc( GetProcessHeap(), 0, len*sizeof(WCHAR) );
747     MultiByteToWideChar( CP_ACP, 0, lpszHeader, dwHeaderLength, hdr, len );
748     if( dwHeaderLength != ~0U )
749         dwHeaderLength = len;
750
751     r = HttpAddRequestHeadersW( hHttpRequest, hdr, dwHeaderLength, dwModifier );
752
753     HeapFree( GetProcessHeap(), 0, hdr );
754
755     return r;
756 }
757
758 /***********************************************************************
759  *           HttpEndRequestA (WININET.@)
760  *
761  * Ends an HTTP request that was started by HttpSendRequestEx
762  *
763  * RETURNS
764  *    TRUE      if successful
765  *    FALSE     on failure
766  *
767  */
768 BOOL WINAPI HttpEndRequestA(HINTERNET hRequest, 
769         LPINTERNET_BUFFERSA lpBuffersOut, DWORD dwFlags, DWORD_PTR dwContext)
770 {
771     LPINTERNET_BUFFERSA ptr;
772     LPINTERNET_BUFFERSW lpBuffersOutW,ptrW;
773     BOOL rc = FALSE;
774
775     TRACE("(%p, %p, %08x, %08lx): stub\n", hRequest, lpBuffersOut, dwFlags,
776             dwContext);
777
778     ptr = lpBuffersOut;
779     if (ptr)
780         lpBuffersOutW = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY,
781                 sizeof(INTERNET_BUFFERSW));
782     else
783         lpBuffersOutW = NULL;
784
785     ptrW = lpBuffersOutW;
786     while (ptr)
787     {
788         if (ptr->lpvBuffer && ptr->dwBufferLength)
789             ptrW->lpvBuffer = HeapAlloc(GetProcessHeap(),0,ptr->dwBufferLength);
790         ptrW->dwBufferLength = ptr->dwBufferLength;
791         ptrW->dwBufferTotal= ptr->dwBufferTotal;
792
793         if (ptr->Next)
794             ptrW->Next = HeapAlloc(GetProcessHeap(),HEAP_ZERO_MEMORY,
795                     sizeof(INTERNET_BUFFERSW));
796
797         ptr = ptr->Next;
798         ptrW = ptrW->Next;
799     }
800
801     rc = HttpEndRequestW(hRequest, lpBuffersOutW, dwFlags, dwContext);
802
803     if (lpBuffersOutW)
804     {
805         ptrW = lpBuffersOutW;
806         while (ptrW)
807         {
808             LPINTERNET_BUFFERSW ptrW2;
809
810             FIXME("Do we need to translate info out of these buffer?\n");
811
812             HeapFree(GetProcessHeap(),0,ptrW->lpvBuffer);
813             ptrW2 = ptrW->Next;
814             HeapFree(GetProcessHeap(),0,ptrW);
815             ptrW = ptrW2;
816         }
817     }
818
819     return rc;
820 }
821
822 /***********************************************************************
823  *           HttpEndRequestW (WININET.@)
824  *
825  * Ends an HTTP request that was started by HttpSendRequestEx
826  *
827  * RETURNS
828  *    TRUE      if successful
829  *    FALSE     on failure
830  *
831  */
832 BOOL WINAPI HttpEndRequestW(HINTERNET hRequest, 
833         LPINTERNET_BUFFERSW lpBuffersOut, DWORD dwFlags, DWORD_PTR dwContext)
834 {
835     BOOL rc = FALSE;
836     LPWININETHTTPREQW lpwhr;
837     INT responseLen;
838     DWORD dwBufferSize;
839
840     TRACE("-->\n");
841     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hRequest );
842
843     if (NULL == lpwhr || lpwhr->hdr.htype != WH_HHTTPREQ)
844     {
845         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
846         if (lpwhr)
847             WININET_Release( &lpwhr->hdr );
848         return FALSE;
849     }
850
851     lpwhr->hdr.dwFlags |= dwFlags;
852     lpwhr->hdr.dwContext = dwContext;
853
854     /* We appear to do nothing with lpBuffersOut.. is that correct? */
855
856     SendAsyncCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
857             INTERNET_STATUS_RECEIVING_RESPONSE, NULL, 0);
858
859     responseLen = HTTP_GetResponseHeaders(lpwhr, TRUE);
860     if (responseLen)
861             rc = TRUE;
862
863     SendAsyncCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
864             INTERNET_STATUS_RESPONSE_RECEIVED, &responseLen, sizeof(DWORD));
865
866     /* process cookies here. Is this right? */
867     HTTP_ProcessCookies(lpwhr);
868
869     dwBufferSize = sizeof(lpwhr->dwContentLength);
870     if (!HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_FLAG_NUMBER|HTTP_QUERY_CONTENT_LENGTH,
871                              &lpwhr->dwContentLength,&dwBufferSize,NULL))
872         lpwhr->dwContentLength = -1;
873
874     if (lpwhr->dwContentLength == 0)
875         HTTP_FinishedReading(lpwhr);
876
877     if(!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_AUTO_REDIRECT))
878     {
879         DWORD dwCode,dwCodeLength=sizeof(DWORD);
880         if(HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_FLAG_NUMBER|HTTP_QUERY_STATUS_CODE,&dwCode,&dwCodeLength,NULL) &&
881             (dwCode==302 || dwCode==301 || dwCode==303))
882         {
883             WCHAR szNewLocation[INTERNET_MAX_URL_LENGTH];
884             dwBufferSize=sizeof(szNewLocation);
885             if(HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_LOCATION,szNewLocation,&dwBufferSize,NULL))
886             {
887                 /* redirects are always GETs */
888                 HeapFree(GetProcessHeap(),0,lpwhr->lpszVerb);
889                 lpwhr->lpszVerb = WININET_strdupW(szGET);
890                 HTTP_DrainContent(lpwhr);
891                 INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
892                                       INTERNET_STATUS_REDIRECT, szNewLocation,
893                                       dwBufferSize);
894                 rc = HTTP_HandleRedirect(lpwhr, szNewLocation);
895                 if (rc)
896                     rc = HTTP_HttpSendRequestW(lpwhr, NULL, 0, NULL, 0, 0, TRUE);
897             }
898         }
899     }
900
901     WININET_Release( &lpwhr->hdr );
902     TRACE("%i <--\n",rc);
903     return rc;
904 }
905
906 /***********************************************************************
907  *           HttpOpenRequestW (WININET.@)
908  *
909  * Open a HTTP request handle
910  *
911  * RETURNS
912  *    HINTERNET  a HTTP request handle on success
913  *    NULL       on failure
914  *
915  */
916 HINTERNET WINAPI HttpOpenRequestW(HINTERNET hHttpSession,
917         LPCWSTR lpszVerb, LPCWSTR lpszObjectName, LPCWSTR lpszVersion,
918         LPCWSTR lpszReferrer , LPCWSTR *lpszAcceptTypes,
919         DWORD dwFlags, DWORD_PTR dwContext)
920 {
921     LPWININETHTTPSESSIONW lpwhs;
922     HINTERNET handle = NULL;
923
924     TRACE("(%p, %s, %s, %s, %s, %p, %08x, %08lx)\n", hHttpSession,
925           debugstr_w(lpszVerb), debugstr_w(lpszObjectName),
926           debugstr_w(lpszVersion), debugstr_w(lpszReferrer), lpszAcceptTypes,
927           dwFlags, dwContext);
928     if(lpszAcceptTypes!=NULL)
929     {
930         int i;
931         for(i=0;lpszAcceptTypes[i]!=NULL;i++)
932             TRACE("\taccept type: %s\n",debugstr_w(lpszAcceptTypes[i]));
933     }    
934
935     lpwhs = (LPWININETHTTPSESSIONW) WININET_GetObject( hHttpSession );
936     if (NULL == lpwhs ||  lpwhs->hdr.htype != WH_HHTTPSESSION)
937     {
938         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
939         goto lend;
940     }
941
942     /*
943      * My tests seem to show that the windows version does not
944      * become asynchronous until after this point. And anyhow
945      * if this call was asynchronous then how would you get the
946      * necessary HINTERNET pointer returned by this function.
947      *
948      */
949     handle = HTTP_HttpOpenRequestW(lpwhs, lpszVerb, lpszObjectName,
950                                    lpszVersion, lpszReferrer, lpszAcceptTypes,
951                                    dwFlags, dwContext);
952 lend:
953     if( lpwhs )
954         WININET_Release( &lpwhs->hdr );
955     TRACE("returning %p\n", handle);
956     return handle;
957 }
958
959
960 /***********************************************************************
961  *           HttpOpenRequestA (WININET.@)
962  *
963  * Open a HTTP request handle
964  *
965  * RETURNS
966  *    HINTERNET  a HTTP request handle on success
967  *    NULL       on failure
968  *
969  */
970 HINTERNET WINAPI HttpOpenRequestA(HINTERNET hHttpSession,
971         LPCSTR lpszVerb, LPCSTR lpszObjectName, LPCSTR lpszVersion,
972         LPCSTR lpszReferrer , LPCSTR *lpszAcceptTypes,
973         DWORD dwFlags, DWORD_PTR dwContext)
974 {
975     LPWSTR szVerb = NULL, szObjectName = NULL;
976     LPWSTR szVersion = NULL, szReferrer = NULL, *szAcceptTypes = NULL;
977     INT len, acceptTypesCount;
978     HINTERNET rc = FALSE;
979     LPCSTR *types;
980
981     TRACE("(%p, %s, %s, %s, %s, %p, %08x, %08lx)\n", hHttpSession,
982           debugstr_a(lpszVerb), debugstr_a(lpszObjectName),
983           debugstr_a(lpszVersion), debugstr_a(lpszReferrer), lpszAcceptTypes,
984           dwFlags, dwContext);
985
986     if (lpszVerb)
987     {
988         len = MultiByteToWideChar(CP_ACP, 0, lpszVerb, -1, NULL, 0 );
989         szVerb = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR) );
990         if ( !szVerb )
991             goto end;
992         MultiByteToWideChar(CP_ACP, 0, lpszVerb, -1, szVerb, len);
993     }
994
995     if (lpszObjectName)
996     {
997         len = MultiByteToWideChar(CP_ACP, 0, lpszObjectName, -1, NULL, 0 );
998         szObjectName = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR) );
999         if ( !szObjectName )
1000             goto end;
1001         MultiByteToWideChar(CP_ACP, 0, lpszObjectName, -1, szObjectName, len );
1002     }
1003
1004     if (lpszVersion)
1005     {
1006         len = MultiByteToWideChar(CP_ACP, 0, lpszVersion, -1, NULL, 0 );
1007         szVersion = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR));
1008         if ( !szVersion )
1009             goto end;
1010         MultiByteToWideChar(CP_ACP, 0, lpszVersion, -1, szVersion, len );
1011     }
1012
1013     if (lpszReferrer)
1014     {
1015         len = MultiByteToWideChar(CP_ACP, 0, lpszReferrer, -1, NULL, 0 );
1016         szReferrer = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR));
1017         if ( !szReferrer )
1018             goto end;
1019         MultiByteToWideChar(CP_ACP, 0, lpszReferrer, -1, szReferrer, len );
1020     }
1021
1022     if (lpszAcceptTypes)
1023     {
1024         acceptTypesCount = 0;
1025         types = lpszAcceptTypes;
1026         while (*types)
1027         {
1028             __TRY
1029             {
1030                 /* find out how many there are */
1031                 if (*types && **types)
1032                 {
1033                     TRACE("accept type: %s\n", debugstr_a(*types));
1034                     acceptTypesCount++;
1035                 }
1036             }
1037             __EXCEPT_PAGE_FAULT
1038             {
1039                 WARN("invalid accept type pointer\n");
1040             }
1041             __ENDTRY;
1042             types++;
1043         }
1044         szAcceptTypes = HeapAlloc(GetProcessHeap(), 0, sizeof(WCHAR *) * (acceptTypesCount+1));
1045         if (!szAcceptTypes) goto end;
1046
1047         acceptTypesCount = 0;
1048         types = lpszAcceptTypes;
1049         while (*types)
1050         {
1051             __TRY
1052             {
1053                 if (*types && **types)
1054                 {
1055                     len = MultiByteToWideChar(CP_ACP, 0, *types, -1, NULL, 0 );
1056                     szAcceptTypes[acceptTypesCount] = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR));
1057
1058                     MultiByteToWideChar(CP_ACP, 0, *types, -1, szAcceptTypes[acceptTypesCount], len);
1059                     acceptTypesCount++;
1060                 }
1061             }
1062             __EXCEPT_PAGE_FAULT
1063             {
1064                 /* ignore invalid pointer */
1065             }
1066             __ENDTRY;
1067             types++;
1068         }
1069         szAcceptTypes[acceptTypesCount] = NULL;
1070     }
1071
1072     rc = HttpOpenRequestW(hHttpSession, szVerb, szObjectName,
1073                           szVersion, szReferrer,
1074                           (LPCWSTR*)szAcceptTypes, dwFlags, dwContext);
1075
1076 end:
1077     if (szAcceptTypes)
1078     {
1079         acceptTypesCount = 0;
1080         while (szAcceptTypes[acceptTypesCount])
1081         {
1082             HeapFree(GetProcessHeap(), 0, szAcceptTypes[acceptTypesCount]);
1083             acceptTypesCount++;
1084         }
1085         HeapFree(GetProcessHeap(), 0, szAcceptTypes);
1086     }
1087     HeapFree(GetProcessHeap(), 0, szReferrer);
1088     HeapFree(GetProcessHeap(), 0, szVersion);
1089     HeapFree(GetProcessHeap(), 0, szObjectName);
1090     HeapFree(GetProcessHeap(), 0, szVerb);
1091
1092     return rc;
1093 }
1094
1095 /***********************************************************************
1096  *  HTTP_EncodeBase64
1097  */
1098 static UINT HTTP_EncodeBase64( LPCSTR bin, unsigned int len, LPWSTR base64 )
1099 {
1100     UINT n = 0, x;
1101     static const CHAR HTTP_Base64Enc[] =
1102         "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
1103
1104     while( len > 0 )
1105     {
1106         /* first 6 bits, all from bin[0] */
1107         base64[n++] = HTTP_Base64Enc[(bin[0] & 0xfc) >> 2];
1108         x = (bin[0] & 3) << 4;
1109
1110         /* next 6 bits, 2 from bin[0] and 4 from bin[1] */
1111         if( len == 1 )
1112         {
1113             base64[n++] = HTTP_Base64Enc[x];
1114             base64[n++] = '=';
1115             base64[n++] = '=';
1116             break;
1117         }
1118         base64[n++] = HTTP_Base64Enc[ x | ( (bin[1]&0xf0) >> 4 ) ];
1119         x = ( bin[1] & 0x0f ) << 2;
1120
1121         /* next 6 bits 4 from bin[1] and 2 from bin[2] */
1122         if( len == 2 )
1123         {
1124             base64[n++] = HTTP_Base64Enc[x];
1125             base64[n++] = '=';
1126             break;
1127         }
1128         base64[n++] = HTTP_Base64Enc[ x | ( (bin[2]&0xc0 ) >> 6 ) ];
1129
1130         /* last 6 bits, all from bin [2] */
1131         base64[n++] = HTTP_Base64Enc[ bin[2] & 0x3f ];
1132         bin += 3;
1133         len -= 3;
1134     }
1135     base64[n] = 0;
1136     return n;
1137 }
1138
1139 #define CH(x) (((x) >= 'A' && (x) <= 'Z') ? (x) - 'A' : \
1140                ((x) >= 'a' && (x) <= 'z') ? (x) - 'a' + 26 : \
1141                ((x) >= '0' && (x) <= '9') ? (x) - '0' + 52 : \
1142                ((x) == '+') ? 62 : ((x) == '/') ? 63 : -1)
1143 static const signed char HTTP_Base64Dec[256] =
1144 {
1145     CH( 0),CH( 1),CH( 2),CH( 3),CH( 4),CH( 5),CH( 6),CH( 7),CH( 8),CH( 9),
1146     CH(10),CH(11),CH(12),CH(13),CH(14),CH(15),CH(16),CH(17),CH(18),CH(19),
1147     CH(20),CH(21),CH(22),CH(23),CH(24),CH(25),CH(26),CH(27),CH(28),CH(29),
1148     CH(30),CH(31),CH(32),CH(33),CH(34),CH(35),CH(36),CH(37),CH(38),CH(39),
1149     CH(40),CH(41),CH(42),CH(43),CH(44),CH(45),CH(46),CH(47),CH(48),CH(49),
1150     CH(50),CH(51),CH(52),CH(53),CH(54),CH(55),CH(56),CH(57),CH(58),CH(59),
1151     CH(60),CH(61),CH(62),CH(63),CH(64),CH(65),CH(66),CH(67),CH(68),CH(69),
1152     CH(70),CH(71),CH(72),CH(73),CH(74),CH(75),CH(76),CH(77),CH(78),CH(79),
1153     CH(80),CH(81),CH(82),CH(83),CH(84),CH(85),CH(86),CH(87),CH(88),CH(89),
1154     CH(90),CH(91),CH(92),CH(93),CH(94),CH(95),CH(96),CH(97),CH(98),CH(99),
1155     CH(100),CH(101),CH(102),CH(103),CH(104),CH(105),CH(106),CH(107),CH(108),CH(109),
1156     CH(110),CH(111),CH(112),CH(113),CH(114),CH(115),CH(116),CH(117),CH(118),CH(119),
1157     CH(120),CH(121),CH(122),CH(123),CH(124),CH(125),CH(126),CH(127),CH(128),CH(129),
1158     CH(130),CH(131),CH(132),CH(133),CH(134),CH(135),CH(136),CH(137),CH(138),CH(139),
1159     CH(140),CH(141),CH(142),CH(143),CH(144),CH(145),CH(146),CH(147),CH(148),CH(149),
1160     CH(150),CH(151),CH(152),CH(153),CH(154),CH(155),CH(156),CH(157),CH(158),CH(159),
1161     CH(160),CH(161),CH(162),CH(163),CH(164),CH(165),CH(166),CH(167),CH(168),CH(169),
1162     CH(170),CH(171),CH(172),CH(173),CH(174),CH(175),CH(176),CH(177),CH(178),CH(179),
1163     CH(180),CH(181),CH(182),CH(183),CH(184),CH(185),CH(186),CH(187),CH(188),CH(189),
1164     CH(190),CH(191),CH(192),CH(193),CH(194),CH(195),CH(196),CH(197),CH(198),CH(199),
1165     CH(200),CH(201),CH(202),CH(203),CH(204),CH(205),CH(206),CH(207),CH(208),CH(209),
1166     CH(210),CH(211),CH(212),CH(213),CH(214),CH(215),CH(216),CH(217),CH(218),CH(219),
1167     CH(220),CH(221),CH(222),CH(223),CH(224),CH(225),CH(226),CH(227),CH(228),CH(229),
1168     CH(230),CH(231),CH(232),CH(233),CH(234),CH(235),CH(236),CH(237),CH(238),CH(239),
1169     CH(240),CH(241),CH(242),CH(243),CH(244),CH(245),CH(246),CH(247),CH(248), CH(249),
1170     CH(250),CH(251),CH(252),CH(253),CH(254),CH(255),
1171 };
1172 #undef CH
1173
1174 /***********************************************************************
1175  *  HTTP_DecodeBase64
1176  */
1177 static UINT HTTP_DecodeBase64( LPCWSTR base64, LPSTR bin )
1178 {
1179     unsigned int n = 0;
1180
1181     while(*base64)
1182     {
1183         signed char in[4];
1184
1185         if (base64[0] >= ARRAYSIZE(HTTP_Base64Dec) ||
1186             ((in[0] = HTTP_Base64Dec[base64[0]]) == -1) ||
1187             base64[1] >= ARRAYSIZE(HTTP_Base64Dec) ||
1188             ((in[1] = HTTP_Base64Dec[base64[1]]) == -1))
1189         {
1190             WARN("invalid base64: %s\n", debugstr_w(base64));
1191             return 0;
1192         }
1193         if (bin)
1194             bin[n] = (unsigned char) (in[0] << 2 | in[1] >> 4);
1195         n++;
1196
1197         if ((base64[2] == '=') && (base64[3] == '='))
1198             break;
1199         if (base64[2] > ARRAYSIZE(HTTP_Base64Dec) ||
1200             ((in[2] = HTTP_Base64Dec[base64[2]]) == -1))
1201         {
1202             WARN("invalid base64: %s\n", debugstr_w(&base64[2]));
1203             return 0;
1204         }
1205         if (bin)
1206             bin[n] = (unsigned char) (in[1] << 4 | in[2] >> 2);
1207         n++;
1208
1209         if (base64[3] == '=')
1210             break;
1211         if (base64[3] > ARRAYSIZE(HTTP_Base64Dec) ||
1212             ((in[3] = HTTP_Base64Dec[base64[3]]) == -1))
1213         {
1214             WARN("invalid base64: %s\n", debugstr_w(&base64[3]));
1215             return 0;
1216         }
1217         if (bin)
1218             bin[n] = (unsigned char) (((in[2] << 6) & 0xc0) | in[3]);
1219         n++;
1220
1221         base64 += 4;
1222     }
1223
1224     return n;
1225 }
1226
1227 /***********************************************************************
1228  *  HTTP_InsertAuthorization
1229  *
1230  *   Insert or delete the authorization field in the request header.
1231  */
1232 static BOOL HTTP_InsertAuthorization( LPWININETHTTPREQW lpwhr, struct HttpAuthInfo *pAuthInfo, LPCWSTR header )
1233 {
1234     if (pAuthInfo)
1235     {
1236         static const WCHAR wszSpace[] = {' ',0};
1237         static const WCHAR wszBasic[] = {'B','a','s','i','c',0};
1238         unsigned int len;
1239         WCHAR *authorization = NULL;
1240
1241         if (pAuthInfo->auth_data_len)
1242         {
1243             /* scheme + space + base64 encoded data (3/2/1 bytes data -> 4 bytes of characters) */
1244             len = strlenW(pAuthInfo->scheme)+1+((pAuthInfo->auth_data_len+2)*4)/3;
1245             authorization = HeapAlloc(GetProcessHeap(), 0, (len+1)*sizeof(WCHAR));
1246             if (!authorization)
1247                 return FALSE;
1248
1249             strcpyW(authorization, pAuthInfo->scheme);
1250             strcatW(authorization, wszSpace);
1251             HTTP_EncodeBase64(pAuthInfo->auth_data,
1252                               pAuthInfo->auth_data_len,
1253                               authorization+strlenW(authorization));
1254
1255             /* clear the data as it isn't valid now that it has been sent to the
1256              * server, unless it's Basic authentication which doesn't do
1257              * connection tracking */
1258             if (strcmpiW(pAuthInfo->scheme, wszBasic))
1259             {
1260                 HeapFree(GetProcessHeap(), 0, pAuthInfo->auth_data);
1261                 pAuthInfo->auth_data = NULL;
1262                 pAuthInfo->auth_data_len = 0;
1263             }
1264         }
1265
1266         TRACE("Inserting authorization: %s\n", debugstr_w(authorization));
1267
1268         HTTP_ProcessHeader(lpwhr, header, authorization, HTTP_ADDHDR_FLAG_REQ | HTTP_ADDHDR_FLAG_REPLACE);
1269
1270         HeapFree(GetProcessHeap(), 0, authorization);
1271     }
1272     return TRUE;
1273 }
1274
1275 static WCHAR *HTTP_BuildProxyRequestUrl(WININETHTTPREQW *req)
1276 {
1277     WCHAR new_location[INTERNET_MAX_URL_LENGTH], *url;
1278     DWORD size;
1279
1280     size = sizeof(new_location);
1281     if (HTTP_HttpQueryInfoW(req, HTTP_QUERY_LOCATION, new_location, &size, NULL))
1282     {
1283         if (!(url = HeapAlloc( GetProcessHeap(), 0, size + sizeof(WCHAR) ))) return NULL;
1284         strcpyW( url, new_location );
1285     }
1286     else
1287     {
1288         static const WCHAR slash[] = { '/',0 };
1289         static const WCHAR format[] = { 'h','t','t','p',':','/','/','%','s',':','%','d',0 };
1290         static const WCHAR formatSSL[] = { 'h','t','t','p','s',':','/','/','%','s',':','%','d',0 };
1291         WININETHTTPSESSIONW *session = req->lpHttpSession;
1292
1293         size = 16; /* "https://" + sizeof(port#) + ":/\0" */
1294         size += strlenW( session->lpszHostName ) + strlenW( req->lpszPath );
1295
1296         if (!(url = HeapAlloc( GetProcessHeap(), 0, size * sizeof(WCHAR) ))) return NULL;
1297
1298         if (req->hdr.dwFlags & INTERNET_FLAG_SECURE)
1299             sprintfW( url, formatSSL, session->lpszHostName, session->nHostPort );
1300         else
1301             sprintfW( url, format, session->lpszHostName, session->nHostPort );
1302         if (req->lpszPath[0] != '/') strcatW( url, slash );
1303         strcatW( url, req->lpszPath );
1304     }
1305     TRACE("url=%s\n", debugstr_w(url));
1306     return url;
1307 }
1308
1309 /***********************************************************************
1310  *           HTTP_DealWithProxy
1311  */
1312 static BOOL HTTP_DealWithProxy( LPWININETAPPINFOW hIC,
1313     LPWININETHTTPSESSIONW lpwhs, LPWININETHTTPREQW lpwhr)
1314 {
1315     WCHAR buf[MAXHOSTNAME];
1316     WCHAR proxy[MAXHOSTNAME + 15]; /* 15 == "http://" + sizeof(port#) + ":/\0" */
1317     static WCHAR szNul[] = { 0 };
1318     URL_COMPONENTSW UrlComponents;
1319     static const WCHAR szHttp[] = { 'h','t','t','p',':','/','/',0 };
1320     static const WCHAR szFormat[] = { 'h','t','t','p',':','/','/','%','s',0 };
1321
1322     memset( &UrlComponents, 0, sizeof UrlComponents );
1323     UrlComponents.dwStructSize = sizeof UrlComponents;
1324     UrlComponents.lpszHostName = buf;
1325     UrlComponents.dwHostNameLength = MAXHOSTNAME;
1326
1327     if( CSTR_EQUAL != CompareStringW(LOCALE_SYSTEM_DEFAULT, NORM_IGNORECASE,
1328                                  hIC->lpszProxy,strlenW(szHttp),szHttp,strlenW(szHttp)) )
1329         sprintfW(proxy, szFormat, hIC->lpszProxy);
1330     else
1331         strcpyW(proxy, hIC->lpszProxy);
1332     if( !InternetCrackUrlW(proxy, 0, 0, &UrlComponents) )
1333         return FALSE;
1334     if( UrlComponents.dwHostNameLength == 0 )
1335         return FALSE;
1336
1337     if( !lpwhr->lpszPath )
1338         lpwhr->lpszPath = szNul;
1339
1340     if(UrlComponents.nPort == INTERNET_INVALID_PORT_NUMBER)
1341         UrlComponents.nPort = INTERNET_DEFAULT_HTTP_PORT;
1342
1343     HeapFree(GetProcessHeap(), 0, lpwhs->lpszServerName);
1344     lpwhs->lpszServerName = WININET_strdupW(UrlComponents.lpszHostName);
1345     lpwhs->nServerPort = UrlComponents.nPort;
1346
1347     TRACE("proxy server=%s port=%d\n", debugstr_w(lpwhs->lpszServerName), lpwhs->nServerPort);
1348     return TRUE;
1349 }
1350
1351 static BOOL HTTP_ResolveName(LPWININETHTTPREQW lpwhr)
1352 {
1353     char szaddr[32];
1354     LPWININETHTTPSESSIONW lpwhs = lpwhr->lpHttpSession;
1355
1356     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
1357                           INTERNET_STATUS_RESOLVING_NAME,
1358                           lpwhs->lpszServerName,
1359                           strlenW(lpwhs->lpszServerName)+1);
1360
1361     if (!GetAddress(lpwhs->lpszServerName, lpwhs->nServerPort,
1362                     &lpwhs->socketAddress))
1363     {
1364         INTERNET_SetLastError(ERROR_INTERNET_NAME_NOT_RESOLVED);
1365         return FALSE;
1366     }
1367
1368     inet_ntop(lpwhs->socketAddress.sin_family, &lpwhs->socketAddress.sin_addr,
1369               szaddr, sizeof(szaddr));
1370     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
1371                           INTERNET_STATUS_NAME_RESOLVED,
1372                           szaddr, strlen(szaddr)+1);
1373
1374     TRACE("resolved %s to %s\n", debugstr_w(lpwhs->lpszServerName), szaddr);
1375     return TRUE;
1376 }
1377
1378
1379 /***********************************************************************
1380  *           HTTPREQ_Destroy (internal)
1381  *
1382  * Deallocate request handle
1383  *
1384  */
1385 static void HTTPREQ_Destroy(WININETHANDLEHEADER *hdr)
1386 {
1387     LPWININETHTTPREQW lpwhr = (LPWININETHTTPREQW) hdr;
1388     DWORD i;
1389
1390     TRACE("\n");
1391
1392     if(lpwhr->hCacheFile)
1393         CloseHandle(lpwhr->hCacheFile);
1394
1395     if(lpwhr->lpszCacheFile) {
1396         DeleteFileW(lpwhr->lpszCacheFile); /* FIXME */
1397         HeapFree(GetProcessHeap(), 0, lpwhr->lpszCacheFile);
1398     }
1399
1400     WININET_Release(&lpwhr->lpHttpSession->hdr);
1401
1402     if (lpwhr->pAuthInfo)
1403     {
1404         if (SecIsValidHandle(&lpwhr->pAuthInfo->ctx))
1405             DeleteSecurityContext(&lpwhr->pAuthInfo->ctx);
1406         if (SecIsValidHandle(&lpwhr->pAuthInfo->cred))
1407             FreeCredentialsHandle(&lpwhr->pAuthInfo->cred);
1408
1409         HeapFree(GetProcessHeap(), 0, lpwhr->pAuthInfo->auth_data);
1410         HeapFree(GetProcessHeap(), 0, lpwhr->pAuthInfo->scheme);
1411         HeapFree(GetProcessHeap(), 0, lpwhr->pAuthInfo);
1412         lpwhr->pAuthInfo = NULL;
1413     }
1414
1415     if (lpwhr->pProxyAuthInfo)
1416     {
1417         if (SecIsValidHandle(&lpwhr->pProxyAuthInfo->ctx))
1418             DeleteSecurityContext(&lpwhr->pProxyAuthInfo->ctx);
1419         if (SecIsValidHandle(&lpwhr->pProxyAuthInfo->cred))
1420             FreeCredentialsHandle(&lpwhr->pProxyAuthInfo->cred);
1421
1422         HeapFree(GetProcessHeap(), 0, lpwhr->pProxyAuthInfo->auth_data);
1423         HeapFree(GetProcessHeap(), 0, lpwhr->pProxyAuthInfo->scheme);
1424         HeapFree(GetProcessHeap(), 0, lpwhr->pProxyAuthInfo);
1425         lpwhr->pProxyAuthInfo = NULL;
1426     }
1427
1428     HeapFree(GetProcessHeap(), 0, lpwhr->lpszPath);
1429     HeapFree(GetProcessHeap(), 0, lpwhr->lpszVerb);
1430     HeapFree(GetProcessHeap(), 0, lpwhr->lpszRawHeaders);
1431     HeapFree(GetProcessHeap(), 0, lpwhr->lpszVersion);
1432     HeapFree(GetProcessHeap(), 0, lpwhr->lpszStatusText);
1433
1434     for (i = 0; i < lpwhr->nCustHeaders; i++)
1435     {
1436         HeapFree(GetProcessHeap(), 0, lpwhr->pCustHeaders[i].lpszField);
1437         HeapFree(GetProcessHeap(), 0, lpwhr->pCustHeaders[i].lpszValue);
1438     }
1439
1440     HeapFree(GetProcessHeap(), 0, lpwhr->pCustHeaders);
1441     HeapFree(GetProcessHeap(), 0, lpwhr);
1442 }
1443
1444 static void HTTPREQ_CloseConnection(WININETHANDLEHEADER *hdr)
1445 {
1446     LPWININETHTTPREQW lpwhr = (LPWININETHTTPREQW) hdr;
1447
1448     TRACE("%p\n",lpwhr);
1449
1450     if (!NETCON_connected(&lpwhr->netConnection))
1451         return;
1452
1453     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
1454                           INTERNET_STATUS_CLOSING_CONNECTION, 0, 0);
1455
1456     NETCON_close(&lpwhr->netConnection);
1457
1458     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
1459                           INTERNET_STATUS_CONNECTION_CLOSED, 0, 0);
1460 }
1461
1462 static DWORD HTTPREQ_QueryOption(WININETHANDLEHEADER *hdr, DWORD option, void *buffer, DWORD *size, BOOL unicode)
1463 {
1464     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1465
1466     switch(option) {
1467     case INTERNET_OPTION_HANDLE_TYPE:
1468         TRACE("INTERNET_OPTION_HANDLE_TYPE\n");
1469
1470         if (*size < sizeof(ULONG))
1471             return ERROR_INSUFFICIENT_BUFFER;
1472
1473         *size = sizeof(DWORD);
1474         *(DWORD*)buffer = INTERNET_HANDLE_TYPE_HTTP_REQUEST;
1475         return ERROR_SUCCESS;
1476
1477     case INTERNET_OPTION_URL: {
1478         WCHAR url[INTERNET_MAX_URL_LENGTH];
1479         HTTPHEADERW *host;
1480         DWORD len;
1481         WCHAR *pch;
1482
1483         static const WCHAR httpW[] = {'h','t','t','p',':','/','/',0};
1484         static const WCHAR hostW[] = {'H','o','s','t',0};
1485
1486         TRACE("INTERNET_OPTION_URL\n");
1487
1488         host = HTTP_GetHeader(req, hostW);
1489         strcpyW(url, httpW);
1490         strcatW(url, host->lpszValue);
1491         if (NULL != (pch = strchrW(url + strlenW(httpW), ':')))
1492             *pch = 0;
1493         strcatW(url, req->lpszPath);
1494
1495         TRACE("INTERNET_OPTION_URL: %s\n",debugstr_w(url));
1496
1497         if(unicode) {
1498             len = (strlenW(url)+1) * sizeof(WCHAR);
1499             if(*size < len)
1500                 return ERROR_INSUFFICIENT_BUFFER;
1501
1502             *size = len;
1503             strcpyW(buffer, url);
1504             return ERROR_SUCCESS;
1505         }else {
1506             len = WideCharToMultiByte(CP_ACP, 0, url, -1, buffer, *size, NULL, NULL);
1507             if(len > *size)
1508                 return ERROR_INSUFFICIENT_BUFFER;
1509
1510             *size = len;
1511             return ERROR_SUCCESS;
1512         }
1513     }
1514
1515     case INTERNET_OPTION_DATAFILE_NAME: {
1516         DWORD req_size;
1517
1518         TRACE("INTERNET_OPTION_DATAFILE_NAME\n");
1519
1520         if(!req->lpszCacheFile) {
1521             *size = 0;
1522             return ERROR_INTERNET_ITEM_NOT_FOUND;
1523         }
1524
1525         if(unicode) {
1526             req_size = (lstrlenW(req->lpszCacheFile)+1) * sizeof(WCHAR);
1527             if(*size < req_size)
1528                 return ERROR_INSUFFICIENT_BUFFER;
1529
1530             *size = req_size;
1531             memcpy(buffer, req->lpszCacheFile, *size);
1532             return ERROR_SUCCESS;
1533         }else {
1534             req_size = WideCharToMultiByte(CP_ACP, 0, req->lpszCacheFile, -1, NULL, 0, NULL, NULL);
1535             if (req_size > *size)
1536                 return ERROR_INSUFFICIENT_BUFFER;
1537
1538             *size = WideCharToMultiByte(CP_ACP, 0, req->lpszCacheFile,
1539                     -1, buffer, *size, NULL, NULL);
1540             return ERROR_SUCCESS;
1541         }
1542     }
1543
1544     case INTERNET_OPTION_SECURITY_CERTIFICATE_STRUCT: {
1545         PCCERT_CONTEXT context;
1546
1547         if(*size < sizeof(INTERNET_CERTIFICATE_INFOW)) {
1548             *size = sizeof(INTERNET_CERTIFICATE_INFOW);
1549             return ERROR_INSUFFICIENT_BUFFER;
1550         }
1551
1552         context = (PCCERT_CONTEXT)NETCON_GetCert(&(req->netConnection));
1553         if(context) {
1554             INTERNET_CERTIFICATE_INFOW *info = (INTERNET_CERTIFICATE_INFOW*)buffer;
1555             DWORD len;
1556
1557             memset(info, 0, sizeof(INTERNET_CERTIFICATE_INFOW));
1558             info->ftExpiry = context->pCertInfo->NotAfter;
1559             info->ftStart = context->pCertInfo->NotBefore;
1560             if(unicode) {
1561                 len = CertNameToStrW(context->dwCertEncodingType,
1562                         &context->pCertInfo->Subject, CERT_SIMPLE_NAME_STR, NULL, 0);
1563                 info->lpszSubjectInfo = LocalAlloc(0, len*sizeof(WCHAR));
1564                 if(info->lpszSubjectInfo)
1565                     CertNameToStrW(context->dwCertEncodingType,
1566                              &context->pCertInfo->Subject, CERT_SIMPLE_NAME_STR,
1567                              info->lpszSubjectInfo, len);
1568                 len = CertNameToStrW(context->dwCertEncodingType,
1569                          &context->pCertInfo->Issuer, CERT_SIMPLE_NAME_STR, NULL, 0);
1570                 info->lpszIssuerInfo = LocalAlloc(0, len*sizeof(WCHAR));
1571                 if (info->lpszIssuerInfo)
1572                     CertNameToStrW(context->dwCertEncodingType,
1573                              &context->pCertInfo->Issuer, CERT_SIMPLE_NAME_STR,
1574                              info->lpszIssuerInfo, len);
1575             }else {
1576                 INTERNET_CERTIFICATE_INFOA *infoA = (INTERNET_CERTIFICATE_INFOA*)info;
1577
1578                 len = CertNameToStrA(context->dwCertEncodingType,
1579                          &context->pCertInfo->Subject, CERT_SIMPLE_NAME_STR, NULL, 0);
1580                 infoA->lpszSubjectInfo = LocalAlloc(0, len);
1581                 if(infoA->lpszSubjectInfo)
1582                     CertNameToStrA(context->dwCertEncodingType,
1583                              &context->pCertInfo->Subject, CERT_SIMPLE_NAME_STR,
1584                              infoA->lpszSubjectInfo, len);
1585                 len = CertNameToStrA(context->dwCertEncodingType,
1586                          &context->pCertInfo->Issuer, CERT_SIMPLE_NAME_STR, NULL, 0);
1587                 infoA->lpszIssuerInfo = LocalAlloc(0, len);
1588                 if(infoA->lpszIssuerInfo)
1589                     CertNameToStrA(context->dwCertEncodingType,
1590                              &context->pCertInfo->Issuer, CERT_SIMPLE_NAME_STR,
1591                              infoA->lpszIssuerInfo, len);
1592             }
1593
1594             /*
1595              * Contrary to MSDN, these do not appear to be set.
1596              * lpszProtocolName
1597              * lpszSignatureAlgName
1598              * lpszEncryptionAlgName
1599              * dwKeySize
1600              */
1601             CertFreeCertificateContext(context);
1602             return ERROR_SUCCESS;
1603         }
1604     }
1605     }
1606
1607     return INET_QueryOption(option, buffer, size, unicode);
1608 }
1609
1610 static DWORD HTTPREQ_SetOption(WININETHANDLEHEADER *hdr, DWORD option, void *buffer, DWORD size)
1611 {
1612     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1613
1614     switch(option) {
1615     case INTERNET_OPTION_SEND_TIMEOUT:
1616     case INTERNET_OPTION_RECEIVE_TIMEOUT:
1617         TRACE("INTERNET_OPTION_SEND/RECEIVE_TIMEOUT\n");
1618
1619         if (size != sizeof(DWORD))
1620             return ERROR_INVALID_PARAMETER;
1621
1622         return NETCON_set_timeout(&req->netConnection, option == INTERNET_OPTION_SEND_TIMEOUT,
1623                     *(DWORD*)buffer);
1624
1625     case INTERNET_OPTION_USERNAME:
1626         HeapFree(GetProcessHeap(), 0, req->lpHttpSession->lpszUserName);
1627         if (!(req->lpHttpSession->lpszUserName = WININET_strdupW(buffer))) return ERROR_OUTOFMEMORY;
1628         return ERROR_SUCCESS;
1629
1630     case INTERNET_OPTION_PASSWORD:
1631         HeapFree(GetProcessHeap(), 0, req->lpHttpSession->lpszPassword);
1632         if (!(req->lpHttpSession->lpszPassword = WININET_strdupW(buffer))) return ERROR_OUTOFMEMORY;
1633         return ERROR_SUCCESS;
1634     }
1635
1636     return ERROR_INTERNET_INVALID_OPTION;
1637 }
1638
1639 static void HTTP_ReceiveRequestData(WININETHTTPREQW *req, BOOL first_notif)
1640 {
1641     INTERNET_ASYNC_RESULT iar;
1642     BYTE buffer[4096];
1643     int available;
1644     BOOL res;
1645
1646     TRACE("%p\n", req);
1647
1648     res = NETCON_recv(&req->netConnection, buffer,
1649                 min(sizeof(buffer), req->dwContentLength - req->dwContentRead),
1650                 MSG_PEEK, &available);
1651
1652     if(res) {
1653         iar.dwResult = (DWORD_PTR)req->hdr.hInternet;
1654         iar.dwError = first_notif ? 0 : available;
1655     }else {
1656         iar.dwResult = 0;
1657         iar.dwError = INTERNET_GetLastError();
1658     }
1659
1660     INTERNET_SendCallback(&req->hdr, req->hdr.dwContext, INTERNET_STATUS_REQUEST_COMPLETE, &iar,
1661                           sizeof(INTERNET_ASYNC_RESULT));
1662 }
1663
1664 static DWORD HTTP_Read(WININETHTTPREQW *req, void *buffer, DWORD size, DWORD *read, BOOL sync)
1665 {
1666     int bytes_read;
1667
1668     if(!NETCON_recv(&req->netConnection, buffer, min(size, req->dwContentLength - req->dwContentRead),
1669                      sync ? MSG_WAITALL : 0, &bytes_read)) {
1670         if(req->dwContentLength != -1 && req->dwContentRead != req->dwContentLength)
1671             ERR("not all data received %d/%d\n", req->dwContentRead, req->dwContentLength);
1672
1673         /* always return success, even if the network layer returns an error */
1674         *read = 0;
1675         HTTP_FinishedReading(req);
1676         return ERROR_SUCCESS;
1677     }
1678
1679     req->dwContentRead += bytes_read;
1680     *read = bytes_read;
1681
1682     if(req->lpszCacheFile) {
1683         BOOL res;
1684         DWORD dwBytesWritten;
1685
1686         res = WriteFile(req->hCacheFile, buffer, bytes_read, &dwBytesWritten, NULL);
1687         if(!res)
1688             WARN("WriteFile failed: %u\n", GetLastError());
1689     }
1690
1691     if(!bytes_read && (req->dwContentRead == req->dwContentLength))
1692         HTTP_FinishedReading(req);
1693
1694     return ERROR_SUCCESS;
1695 }
1696
1697 static DWORD get_chunk_size(const char *buffer)
1698 {
1699     const char *p;
1700     DWORD size = 0;
1701
1702     for (p = buffer; *p; p++)
1703     {
1704         if (*p >= '0' && *p <= '9') size = size * 16 + *p - '0';
1705         else if (*p >= 'a' && *p <= 'f') size = size * 16 + *p - 'a' + 10;
1706         else if (*p >= 'A' && *p <= 'F') size = size * 16 + *p - 'A' + 10;
1707         else if (*p == ';') break;
1708     }
1709     return size;
1710 }
1711
1712 static DWORD HTTP_ReadChunked(WININETHTTPREQW *req, void *buffer, DWORD size, DWORD *read, BOOL sync)
1713 {
1714     char reply[MAX_REPLY_LEN], *p = buffer;
1715     DWORD buflen, to_read, to_write = size;
1716     int bytes_read;
1717
1718     *read = 0;
1719     for (;;)
1720     {
1721         if (*read == size) break;
1722
1723         if (req->dwContentLength == ~0u) /* new chunk */
1724         {
1725             buflen = sizeof(reply);
1726             if (!NETCON_getNextLine(&req->netConnection, reply, &buflen)) break;
1727
1728             if (!(req->dwContentLength = get_chunk_size(reply)))
1729             {
1730                 /* zero sized chunk marks end of transfer; read any trailing headers and return */
1731                 HTTP_GetResponseHeaders(req, FALSE);
1732                 break;
1733             }
1734         }
1735         to_read = min(to_write, req->dwContentLength - req->dwContentRead);
1736
1737         if (!NETCON_recv(&req->netConnection, p, to_read, sync ? MSG_WAITALL : 0, &bytes_read))
1738         {
1739             if (bytes_read != to_read)
1740                 ERR("Not all data received %d/%d\n", bytes_read, to_read);
1741
1742             /* always return success, even if the network layer returns an error */
1743             *read = 0;
1744             break;
1745         }
1746         if (!bytes_read) break;
1747
1748         req->dwContentRead += bytes_read;
1749         to_write -= bytes_read;
1750         *read += bytes_read;
1751
1752         if (req->lpszCacheFile)
1753         {
1754             DWORD dwBytesWritten;
1755
1756             if (!WriteFile(req->hCacheFile, p, bytes_read, &dwBytesWritten, NULL))
1757                 WARN("WriteFile failed: %u\n", GetLastError());
1758         }
1759         p += bytes_read;
1760
1761         if (req->dwContentRead == req->dwContentLength) /* chunk complete */
1762         {
1763             req->dwContentRead = 0;
1764             req->dwContentLength = ~0u;
1765
1766             buflen = sizeof(reply);
1767             if (!NETCON_getNextLine(&req->netConnection, reply, &buflen))
1768             {
1769                 ERR("Malformed chunk\n");
1770                 *read = 0;
1771                 break;
1772             }
1773         }
1774     }
1775     if (!*read) HTTP_FinishedReading(req);
1776     return ERROR_SUCCESS;
1777 }
1778
1779 static DWORD HTTPREQ_Read(WININETHTTPREQW *req, void *buffer, DWORD size, DWORD *read, BOOL sync)
1780 {
1781     WCHAR encoding[20];
1782     DWORD buflen = sizeof(encoding);
1783     static const WCHAR szChunked[] = {'c','h','u','n','k','e','d',0};
1784
1785     if (HTTP_HttpQueryInfoW(req, HTTP_QUERY_TRANSFER_ENCODING, encoding, &buflen, NULL) &&
1786         !strcmpiW(encoding, szChunked))
1787     {
1788         return HTTP_ReadChunked(req, buffer, size, read, sync);
1789     }
1790     else
1791         return HTTP_Read(req, buffer, size, read, sync);
1792 }
1793
1794 static DWORD HTTPREQ_ReadFile(WININETHANDLEHEADER *hdr, void *buffer, DWORD size, DWORD *read)
1795 {
1796     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1797     return HTTPREQ_Read(req, buffer, size, read, TRUE);
1798 }
1799
1800 static void HTTPREQ_AsyncReadFileExAProc(WORKREQUEST *workRequest)
1801 {
1802     struct WORKREQ_INTERNETREADFILEEXA const *data = &workRequest->u.InternetReadFileExA;
1803     WININETHTTPREQW *req = (WININETHTTPREQW*)workRequest->hdr;
1804     INTERNET_ASYNC_RESULT iar;
1805     DWORD res;
1806
1807     TRACE("INTERNETREADFILEEXA %p\n", workRequest->hdr);
1808
1809     res = HTTPREQ_Read(req, data->lpBuffersOut->lpvBuffer,
1810             data->lpBuffersOut->dwBufferLength, &data->lpBuffersOut->dwBufferLength, TRUE);
1811
1812     iar.dwResult = res == ERROR_SUCCESS;
1813     iar.dwError = res;
1814
1815     INTERNET_SendCallback(&req->hdr, req->hdr.dwContext,
1816                           INTERNET_STATUS_REQUEST_COMPLETE, &iar,
1817                           sizeof(INTERNET_ASYNC_RESULT));
1818 }
1819
1820 static DWORD HTTPREQ_ReadFileExA(WININETHANDLEHEADER *hdr, INTERNET_BUFFERSA *buffers,
1821         DWORD flags, DWORD_PTR context)
1822 {
1823
1824     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1825     DWORD res;
1826
1827     if (flags & ~(IRF_ASYNC|IRF_NO_WAIT))
1828         FIXME("these dwFlags aren't implemented: 0x%x\n", flags & ~(IRF_ASYNC|IRF_NO_WAIT));
1829
1830     if (buffers->dwStructSize != sizeof(*buffers))
1831         return ERROR_INVALID_PARAMETER;
1832
1833     INTERNET_SendCallback(&req->hdr, req->hdr.dwContext, INTERNET_STATUS_RECEIVING_RESPONSE, NULL, 0);
1834
1835     if (hdr->dwFlags & INTERNET_FLAG_ASYNC) {
1836         DWORD available = 0;
1837
1838         NETCON_query_data_available(&req->netConnection, &available);
1839         if (!available)
1840         {
1841             WORKREQUEST workRequest;
1842
1843             workRequest.asyncproc = HTTPREQ_AsyncReadFileExAProc;
1844             workRequest.hdr = WININET_AddRef(&req->hdr);
1845             workRequest.u.InternetReadFileExA.lpBuffersOut = buffers;
1846
1847             INTERNET_AsyncCall(&workRequest);
1848
1849             return ERROR_IO_PENDING;
1850         }
1851     }
1852
1853     res = HTTPREQ_Read(req, buffers->lpvBuffer, buffers->dwBufferLength, &buffers->dwBufferLength,
1854             !(flags & IRF_NO_WAIT));
1855
1856     if (res == ERROR_SUCCESS) {
1857         DWORD size = buffers->dwBufferLength;
1858         INTERNET_SendCallback(&req->hdr, req->hdr.dwContext, INTERNET_STATUS_RESPONSE_RECEIVED,
1859                 &size, sizeof(size));
1860     }
1861
1862     return res;
1863 }
1864
1865 static void HTTPREQ_AsyncReadFileExWProc(WORKREQUEST *workRequest)
1866 {
1867     struct WORKREQ_INTERNETREADFILEEXW const *data = &workRequest->u.InternetReadFileExW;
1868     WININETHTTPREQW *req = (WININETHTTPREQW*)workRequest->hdr;
1869     INTERNET_ASYNC_RESULT iar;
1870     DWORD res;
1871
1872     TRACE("INTERNETREADFILEEXW %p\n", workRequest->hdr);
1873
1874     res = HTTPREQ_Read(req, data->lpBuffersOut->lpvBuffer,
1875             data->lpBuffersOut->dwBufferLength, &data->lpBuffersOut->dwBufferLength, TRUE);
1876
1877     iar.dwResult = res == ERROR_SUCCESS;
1878     iar.dwError = res;
1879
1880     INTERNET_SendCallback(&req->hdr, req->hdr.dwContext,
1881                           INTERNET_STATUS_REQUEST_COMPLETE, &iar,
1882                           sizeof(INTERNET_ASYNC_RESULT));
1883 }
1884
1885 static DWORD HTTPREQ_ReadFileExW(WININETHANDLEHEADER *hdr, INTERNET_BUFFERSW *buffers,
1886         DWORD flags, DWORD_PTR context)
1887 {
1888
1889     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1890     DWORD res;
1891
1892     if (flags & ~(IRF_ASYNC|IRF_NO_WAIT))
1893         FIXME("these dwFlags aren't implemented: 0x%x\n", flags & ~(IRF_ASYNC|IRF_NO_WAIT));
1894
1895     if (buffers->dwStructSize != sizeof(*buffers))
1896         return ERROR_INVALID_PARAMETER;
1897
1898     INTERNET_SendCallback(&req->hdr, req->hdr.dwContext, INTERNET_STATUS_RECEIVING_RESPONSE, NULL, 0);
1899
1900     if (hdr->dwFlags & INTERNET_FLAG_ASYNC) {
1901         DWORD available = 0;
1902
1903         NETCON_query_data_available(&req->netConnection, &available);
1904         if (!available)
1905         {
1906             WORKREQUEST workRequest;
1907
1908             workRequest.asyncproc = HTTPREQ_AsyncReadFileExWProc;
1909             workRequest.hdr = WININET_AddRef(&req->hdr);
1910             workRequest.u.InternetReadFileExW.lpBuffersOut = buffers;
1911
1912             INTERNET_AsyncCall(&workRequest);
1913
1914             return ERROR_IO_PENDING;
1915         }
1916     }
1917
1918     res = HTTPREQ_Read(req, buffers->lpvBuffer, buffers->dwBufferLength, &buffers->dwBufferLength,
1919             !(flags & IRF_NO_WAIT));
1920
1921     if (res == ERROR_SUCCESS) {
1922         DWORD size = buffers->dwBufferLength;
1923         INTERNET_SendCallback(&req->hdr, req->hdr.dwContext, INTERNET_STATUS_RESPONSE_RECEIVED,
1924                 &size, sizeof(size));
1925     }
1926
1927     return res;
1928 }
1929
1930 static BOOL HTTPREQ_WriteFile(WININETHANDLEHEADER *hdr, const void *buffer, DWORD size, DWORD *written)
1931 {
1932     LPWININETHTTPREQW lpwhr = (LPWININETHTTPREQW)hdr;
1933
1934     return NETCON_send(&lpwhr->netConnection, buffer, size, 0, (LPINT)written);
1935 }
1936
1937 static void HTTPREQ_AsyncQueryDataAvailableProc(WORKREQUEST *workRequest)
1938 {
1939     WININETHTTPREQW *req = (WININETHTTPREQW*)workRequest->hdr;
1940
1941     HTTP_ReceiveRequestData(req, FALSE);
1942 }
1943
1944 static DWORD HTTPREQ_QueryDataAvailable(WININETHANDLEHEADER *hdr, DWORD *available, DWORD flags, DWORD_PTR ctx)
1945 {
1946     WININETHTTPREQW *req = (WININETHTTPREQW*)hdr;
1947     BYTE buffer[4048];
1948     BOOL async;
1949
1950     TRACE("(%p %p %x %lx)\n", req, available, flags, ctx);
1951
1952     if(!NETCON_query_data_available(&req->netConnection, available) || *available)
1953         return ERROR_SUCCESS;
1954
1955     /* Even if we are in async mode, we need to determine whether
1956      * there is actually more data available. We do this by trying
1957      * to peek only a single byte in async mode. */
1958     async = (req->lpHttpSession->lpAppInfo->hdr.dwFlags & INTERNET_FLAG_ASYNC) != 0;
1959
1960     if (NETCON_recv(&req->netConnection, buffer,
1961                     min(async ? 1 : sizeof(buffer), req->dwContentLength - req->dwContentRead),
1962                     MSG_PEEK, (int *)available) && async && *available)
1963     {
1964         WORKREQUEST workRequest;
1965
1966         *available = 0;
1967         workRequest.asyncproc = HTTPREQ_AsyncQueryDataAvailableProc;
1968         workRequest.hdr = WININET_AddRef( &req->hdr );
1969
1970         INTERNET_AsyncCall(&workRequest);
1971
1972         return ERROR_IO_PENDING;
1973     }
1974
1975     return ERROR_SUCCESS;
1976 }
1977
1978 static const HANDLEHEADERVtbl HTTPREQVtbl = {
1979     HTTPREQ_Destroy,
1980     HTTPREQ_CloseConnection,
1981     HTTPREQ_QueryOption,
1982     HTTPREQ_SetOption,
1983     HTTPREQ_ReadFile,
1984     HTTPREQ_ReadFileExA,
1985     HTTPREQ_ReadFileExW,
1986     HTTPREQ_WriteFile,
1987     HTTPREQ_QueryDataAvailable,
1988     NULL
1989 };
1990
1991 /***********************************************************************
1992  *           HTTP_HttpOpenRequestW (internal)
1993  *
1994  * Open a HTTP request handle
1995  *
1996  * RETURNS
1997  *    HINTERNET  a HTTP request handle on success
1998  *    NULL       on failure
1999  *
2000  */
2001 HINTERNET WINAPI HTTP_HttpOpenRequestW(LPWININETHTTPSESSIONW lpwhs,
2002         LPCWSTR lpszVerb, LPCWSTR lpszObjectName, LPCWSTR lpszVersion,
2003         LPCWSTR lpszReferrer , LPCWSTR *lpszAcceptTypes,
2004         DWORD dwFlags, DWORD_PTR dwContext)
2005 {
2006     LPWININETAPPINFOW hIC = NULL;
2007     LPWININETHTTPREQW lpwhr;
2008     LPWSTR lpszHostName = NULL;
2009     HINTERNET handle = NULL;
2010     static const WCHAR szHostForm[] = {'%','s',':','%','u',0};
2011     DWORD len;
2012
2013     TRACE("-->\n");
2014
2015     assert( lpwhs->hdr.htype == WH_HHTTPSESSION );
2016     hIC = lpwhs->lpAppInfo;
2017
2018     lpwhr = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sizeof(WININETHTTPREQW));
2019     if (NULL == lpwhr)
2020     {
2021         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
2022         goto lend;
2023     }
2024     lpwhr->hdr.htype = WH_HHTTPREQ;
2025     lpwhr->hdr.vtbl = &HTTPREQVtbl;
2026     lpwhr->hdr.dwFlags = dwFlags;
2027     lpwhr->hdr.dwContext = dwContext;
2028     lpwhr->hdr.refs = 1;
2029     lpwhr->hdr.lpfnStatusCB = lpwhs->hdr.lpfnStatusCB;
2030     lpwhr->hdr.dwInternalFlags = lpwhs->hdr.dwInternalFlags & INET_CALLBACKW;
2031
2032     WININET_AddRef( &lpwhs->hdr );
2033     lpwhr->lpHttpSession = lpwhs;
2034     list_add_head( &lpwhs->hdr.children, &lpwhr->hdr.entry );
2035
2036     lpszHostName = HeapAlloc(GetProcessHeap(), 0, sizeof(WCHAR) *
2037             (strlenW(lpwhs->lpszHostName) + 7 /* length of ":65535" + 1 */));
2038     if (NULL == lpszHostName)
2039     {
2040         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
2041         goto lend;
2042     }
2043
2044     handle = WININET_AllocHandle( &lpwhr->hdr );
2045     if (NULL == handle)
2046     {
2047         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
2048         goto lend;
2049     }
2050
2051     if (!NETCON_init(&lpwhr->netConnection, dwFlags & INTERNET_FLAG_SECURE))
2052     {
2053         InternetCloseHandle( handle );
2054         handle = NULL;
2055         goto lend;
2056     }
2057
2058     if (lpszObjectName && *lpszObjectName) {
2059         HRESULT rc;
2060
2061         len = 0;
2062         rc = UrlEscapeW(lpszObjectName, NULL, &len, URL_ESCAPE_SPACES_ONLY);
2063         if (rc != E_POINTER)
2064             len = strlenW(lpszObjectName)+1;
2065         lpwhr->lpszPath = HeapAlloc(GetProcessHeap(), 0, len*sizeof(WCHAR));
2066         rc = UrlEscapeW(lpszObjectName, lpwhr->lpszPath, &len,
2067                    URL_ESCAPE_SPACES_ONLY);
2068         if (rc != S_OK)
2069         {
2070             ERR("Unable to escape string!(%s) (%d)\n",debugstr_w(lpszObjectName),rc);
2071             strcpyW(lpwhr->lpszPath,lpszObjectName);
2072         }
2073     }
2074
2075     if (lpszReferrer && *lpszReferrer)
2076         HTTP_ProcessHeader(lpwhr, HTTP_REFERER, lpszReferrer, HTTP_ADDREQ_FLAG_ADD | HTTP_ADDHDR_FLAG_REQ);
2077
2078     if (lpszAcceptTypes)
2079     {
2080         int i;
2081         for (i = 0; lpszAcceptTypes[i]; i++)
2082         {
2083             if (!*lpszAcceptTypes[i]) continue;
2084             HTTP_ProcessHeader(lpwhr, HTTP_ACCEPT, lpszAcceptTypes[i],
2085                                HTTP_ADDHDR_FLAG_COALESCE_WITH_COMMA |
2086                                HTTP_ADDHDR_FLAG_REQ |
2087                                (i == 0 ? HTTP_ADDHDR_FLAG_REPLACE : 0));
2088         }
2089     }
2090
2091     lpwhr->lpszVerb = WININET_strdupW(lpszVerb && *lpszVerb ? lpszVerb : szGET);
2092
2093     if (lpszVersion)
2094         lpwhr->lpszVersion = WININET_strdupW(lpszVersion);
2095     else
2096         lpwhr->lpszVersion = WININET_strdupW(g_szHttp1_1);
2097
2098     if (lpwhs->nHostPort != INTERNET_INVALID_PORT_NUMBER &&
2099         lpwhs->nHostPort != INTERNET_DEFAULT_HTTP_PORT &&
2100         lpwhs->nHostPort != INTERNET_DEFAULT_HTTPS_PORT)
2101     {
2102         sprintfW(lpszHostName, szHostForm, lpwhs->lpszHostName, lpwhs->nHostPort);
2103         HTTP_ProcessHeader(lpwhr, szHost, lpszHostName,
2104                 HTTP_ADDREQ_FLAG_ADD | HTTP_ADDHDR_FLAG_REQ);
2105     }
2106     else
2107         HTTP_ProcessHeader(lpwhr, szHost, lpwhs->lpszHostName,
2108                 HTTP_ADDREQ_FLAG_ADD | HTTP_ADDHDR_FLAG_REQ);
2109
2110     if (lpwhs->nServerPort == INTERNET_INVALID_PORT_NUMBER)
2111         lpwhs->nServerPort = (dwFlags & INTERNET_FLAG_SECURE ?
2112                         INTERNET_DEFAULT_HTTPS_PORT :
2113                         INTERNET_DEFAULT_HTTP_PORT);
2114
2115     if (lpwhs->nHostPort == INTERNET_INVALID_PORT_NUMBER)
2116         lpwhs->nHostPort = (dwFlags & INTERNET_FLAG_SECURE ?
2117                         INTERNET_DEFAULT_HTTPS_PORT :
2118                         INTERNET_DEFAULT_HTTP_PORT);
2119
2120     if (NULL != hIC->lpszProxy && hIC->lpszProxy[0] != 0)
2121         HTTP_DealWithProxy( hIC, lpwhs, lpwhr );
2122
2123     INTERNET_SendCallback(&lpwhs->hdr, dwContext,
2124                           INTERNET_STATUS_HANDLE_CREATED, &handle,
2125                           sizeof(handle));
2126
2127 lend:
2128     HeapFree(GetProcessHeap(), 0, lpszHostName);
2129     if( lpwhr )
2130         WININET_Release( &lpwhr->hdr );
2131
2132     TRACE("<-- %p (%p)\n", handle, lpwhr);
2133     return handle;
2134 }
2135
2136 /* read any content returned by the server so that the connection can be
2137  * reused */
2138 static void HTTP_DrainContent(WININETHTTPREQW *req)
2139 {
2140     DWORD bytes_read;
2141
2142     if (!NETCON_connected(&req->netConnection)) return;
2143
2144     if (req->dwContentLength == -1)
2145         NETCON_close(&req->netConnection);
2146
2147     do
2148     {
2149         char buffer[2048];
2150         if (HTTP_Read(req, buffer, sizeof(buffer), &bytes_read, TRUE) != ERROR_SUCCESS)
2151             return;
2152     } while (bytes_read);
2153 }
2154
2155 static const WCHAR szAccept[] = { 'A','c','c','e','p','t',0 };
2156 static const WCHAR szAccept_Charset[] = { 'A','c','c','e','p','t','-','C','h','a','r','s','e','t', 0 };
2157 static const WCHAR szAccept_Encoding[] = { 'A','c','c','e','p','t','-','E','n','c','o','d','i','n','g',0 };
2158 static const WCHAR szAccept_Language[] = { 'A','c','c','e','p','t','-','L','a','n','g','u','a','g','e',0 };
2159 static const WCHAR szAccept_Ranges[] = { 'A','c','c','e','p','t','-','R','a','n','g','e','s',0 };
2160 static const WCHAR szAge[] = { 'A','g','e',0 };
2161 static const WCHAR szAllow[] = { 'A','l','l','o','w',0 };
2162 static const WCHAR szCache_Control[] = { 'C','a','c','h','e','-','C','o','n','t','r','o','l',0 };
2163 static const WCHAR szConnection[] = { 'C','o','n','n','e','c','t','i','o','n',0 };
2164 static const WCHAR szContent_Base[] = { 'C','o','n','t','e','n','t','-','B','a','s','e',0 };
2165 static const WCHAR szContent_Encoding[] = { 'C','o','n','t','e','n','t','-','E','n','c','o','d','i','n','g',0 };
2166 static const WCHAR szContent_ID[] = { 'C','o','n','t','e','n','t','-','I','D',0 };
2167 static const WCHAR szContent_Language[] = { 'C','o','n','t','e','n','t','-','L','a','n','g','u','a','g','e',0 };
2168 static const WCHAR szContent_Length[] = { 'C','o','n','t','e','n','t','-','L','e','n','g','t','h',0 };
2169 static const WCHAR szContent_Location[] = { 'C','o','n','t','e','n','t','-','L','o','c','a','t','i','o','n',0 };
2170 static const WCHAR szContent_MD5[] = { 'C','o','n','t','e','n','t','-','M','D','5',0 };
2171 static const WCHAR szContent_Range[] = { 'C','o','n','t','e','n','t','-','R','a','n','g','e',0 };
2172 static const WCHAR szContent_Transfer_Encoding[] = { 'C','o','n','t','e','n','t','-','T','r','a','n','s','f','e','r','-','E','n','c','o','d','i','n','g',0 };
2173 static const WCHAR szContent_Type[] = { 'C','o','n','t','e','n','t','-','T','y','p','e',0 };
2174 static const WCHAR szCookie[] = { 'C','o','o','k','i','e',0 };
2175 static const WCHAR szDate[] = { 'D','a','t','e',0 };
2176 static const WCHAR szFrom[] = { 'F','r','o','m',0 };
2177 static const WCHAR szETag[] = { 'E','T','a','g',0 };
2178 static const WCHAR szExpect[] = { 'E','x','p','e','c','t',0 };
2179 static const WCHAR szExpires[] = { 'E','x','p','i','r','e','s',0 };
2180 static const WCHAR szIf_Match[] = { 'I','f','-','M','a','t','c','h',0 };
2181 static const WCHAR szIf_Modified_Since[] = { 'I','f','-','M','o','d','i','f','i','e','d','-','S','i','n','c','e',0 };
2182 static const WCHAR szIf_None_Match[] = { 'I','f','-','N','o','n','e','-','M','a','t','c','h',0 };
2183 static const WCHAR szIf_Range[] = { 'I','f','-','R','a','n','g','e',0 };
2184 static const WCHAR szIf_Unmodified_Since[] = { 'I','f','-','U','n','m','o','d','i','f','i','e','d','-','S','i','n','c','e',0 };
2185 static const WCHAR szLast_Modified[] = { 'L','a','s','t','-','M','o','d','i','f','i','e','d',0 };
2186 static const WCHAR szLocation[] = { 'L','o','c','a','t','i','o','n',0 };
2187 static const WCHAR szMax_Forwards[] = { 'M','a','x','-','F','o','r','w','a','r','d','s',0 };
2188 static const WCHAR szMime_Version[] = { 'M','i','m','e','-','V','e','r','s','i','o','n',0 };
2189 static const WCHAR szPragma[] = { 'P','r','a','g','m','a',0 };
2190 static const WCHAR szProxy_Authenticate[] = { 'P','r','o','x','y','-','A','u','t','h','e','n','t','i','c','a','t','e',0 };
2191 static const WCHAR szProxy_Connection[] = { 'P','r','o','x','y','-','C','o','n','n','e','c','t','i','o','n',0 };
2192 static const WCHAR szPublic[] = { 'P','u','b','l','i','c',0 };
2193 static const WCHAR szRange[] = { 'R','a','n','g','e',0 };
2194 static const WCHAR szReferer[] = { 'R','e','f','e','r','e','r',0 };
2195 static const WCHAR szRetry_After[] = { 'R','e','t','r','y','-','A','f','t','e','r',0 };
2196 static const WCHAR szServer[] = { 'S','e','r','v','e','r',0 };
2197 static const WCHAR szSet_Cookie[] = { 'S','e','t','-','C','o','o','k','i','e',0 };
2198 static const WCHAR szTransfer_Encoding[] = { 'T','r','a','n','s','f','e','r','-','E','n','c','o','d','i','n','g',0 };
2199 static const WCHAR szUnless_Modified_Since[] = { 'U','n','l','e','s','s','-','M','o','d','i','f','i','e','d','-','S','i','n','c','e',0 };
2200 static const WCHAR szUpgrade[] = { 'U','p','g','r','a','d','e',0 };
2201 static const WCHAR szURI[] = { 'U','R','I',0 };
2202 static const WCHAR szUser_Agent[] = { 'U','s','e','r','-','A','g','e','n','t',0 };
2203 static const WCHAR szVary[] = { 'V','a','r','y',0 };
2204 static const WCHAR szVia[] = { 'V','i','a',0 };
2205 static const WCHAR szWarning[] = { 'W','a','r','n','i','n','g',0 };
2206 static const WCHAR szWWW_Authenticate[] = { 'W','W','W','-','A','u','t','h','e','n','t','i','c','a','t','e',0 };
2207
2208 static const LPCWSTR header_lookup[] = {
2209     szMime_Version,             /* HTTP_QUERY_MIME_VERSION = 0 */
2210     szContent_Type,             /* HTTP_QUERY_CONTENT_TYPE = 1 */
2211     szContent_Transfer_Encoding,/* HTTP_QUERY_CONTENT_TRANSFER_ENCODING = 2 */
2212     szContent_ID,               /* HTTP_QUERY_CONTENT_ID = 3 */
2213     NULL,                       /* HTTP_QUERY_CONTENT_DESCRIPTION = 4 */
2214     szContent_Length,           /* HTTP_QUERY_CONTENT_LENGTH =  5 */
2215     szContent_Language,         /* HTTP_QUERY_CONTENT_LANGUAGE =  6 */
2216     szAllow,                    /* HTTP_QUERY_ALLOW = 7 */
2217     szPublic,                   /* HTTP_QUERY_PUBLIC = 8 */
2218     szDate,                     /* HTTP_QUERY_DATE = 9 */
2219     szExpires,                  /* HTTP_QUERY_EXPIRES = 10 */
2220     szLast_Modified,            /* HTTP_QUERY_LAST_MODIFIED = 11 */
2221     NULL,                       /* HTTP_QUERY_MESSAGE_ID = 12 */
2222     szURI,                      /* HTTP_QUERY_URI = 13 */
2223     szFrom,                     /* HTTP_QUERY_DERIVED_FROM = 14 */
2224     NULL,                       /* HTTP_QUERY_COST = 15 */
2225     NULL,                       /* HTTP_QUERY_LINK = 16 */
2226     szPragma,                   /* HTTP_QUERY_PRAGMA = 17 */
2227     NULL,                       /* HTTP_QUERY_VERSION = 18 */
2228     szStatus,                   /* HTTP_QUERY_STATUS_CODE = 19 */
2229     NULL,                       /* HTTP_QUERY_STATUS_TEXT = 20 */
2230     NULL,                       /* HTTP_QUERY_RAW_HEADERS = 21 */
2231     NULL,                       /* HTTP_QUERY_RAW_HEADERS_CRLF = 22 */
2232     szConnection,               /* HTTP_QUERY_CONNECTION = 23 */
2233     szAccept,                   /* HTTP_QUERY_ACCEPT = 24 */
2234     szAccept_Charset,           /* HTTP_QUERY_ACCEPT_CHARSET = 25 */
2235     szAccept_Encoding,          /* HTTP_QUERY_ACCEPT_ENCODING = 26 */
2236     szAccept_Language,          /* HTTP_QUERY_ACCEPT_LANGUAGE = 27 */
2237     szAuthorization,            /* HTTP_QUERY_AUTHORIZATION = 28 */
2238     szContent_Encoding,         /* HTTP_QUERY_CONTENT_ENCODING = 29 */
2239     NULL,                       /* HTTP_QUERY_FORWARDED = 30 */
2240     NULL,                       /* HTTP_QUERY_FROM = 31 */
2241     szIf_Modified_Since,        /* HTTP_QUERY_IF_MODIFIED_SINCE = 32 */
2242     szLocation,                 /* HTTP_QUERY_LOCATION = 33 */
2243     NULL,                       /* HTTP_QUERY_ORIG_URI = 34 */
2244     szReferer,                  /* HTTP_QUERY_REFERER = 35 */
2245     szRetry_After,              /* HTTP_QUERY_RETRY_AFTER = 36 */
2246     szServer,                   /* HTTP_QUERY_SERVER = 37 */
2247     NULL,                       /* HTTP_TITLE = 38 */
2248     szUser_Agent,               /* HTTP_QUERY_USER_AGENT = 39 */
2249     szWWW_Authenticate,         /* HTTP_QUERY_WWW_AUTHENTICATE = 40 */
2250     szProxy_Authenticate,       /* HTTP_QUERY_PROXY_AUTHENTICATE = 41 */
2251     szAccept_Ranges,            /* HTTP_QUERY_ACCEPT_RANGES = 42 */
2252     szSet_Cookie,               /* HTTP_QUERY_SET_COOKIE = 43 */
2253     szCookie,                   /* HTTP_QUERY_COOKIE = 44 */
2254     NULL,                       /* HTTP_QUERY_REQUEST_METHOD = 45 */
2255     NULL,                       /* HTTP_QUERY_REFRESH = 46 */
2256     NULL,                       /* HTTP_QUERY_CONTENT_DISPOSITION = 47 */
2257     szAge,                      /* HTTP_QUERY_AGE = 48 */
2258     szCache_Control,            /* HTTP_QUERY_CACHE_CONTROL = 49 */
2259     szContent_Base,             /* HTTP_QUERY_CONTENT_BASE = 50 */
2260     szContent_Location,         /* HTTP_QUERY_CONTENT_LOCATION = 51 */
2261     szContent_MD5,              /* HTTP_QUERY_CONTENT_MD5 = 52 */
2262     szContent_Range,            /* HTTP_QUERY_CONTENT_RANGE = 53 */
2263     szETag,                     /* HTTP_QUERY_ETAG = 54 */
2264     szHost,                     /* HTTP_QUERY_HOST = 55 */
2265     szIf_Match,                 /* HTTP_QUERY_IF_MATCH = 56 */
2266     szIf_None_Match,            /* HTTP_QUERY_IF_NONE_MATCH = 57 */
2267     szIf_Range,                 /* HTTP_QUERY_IF_RANGE = 58 */
2268     szIf_Unmodified_Since,      /* HTTP_QUERY_IF_UNMODIFIED_SINCE = 59 */
2269     szMax_Forwards,             /* HTTP_QUERY_MAX_FORWARDS = 60 */
2270     szProxy_Authorization,      /* HTTP_QUERY_PROXY_AUTHORIZATION = 61 */
2271     szRange,                    /* HTTP_QUERY_RANGE = 62 */
2272     szTransfer_Encoding,        /* HTTP_QUERY_TRANSFER_ENCODING = 63 */
2273     szUpgrade,                  /* HTTP_QUERY_UPGRADE = 64 */
2274     szVary,                     /* HTTP_QUERY_VARY = 65 */
2275     szVia,                      /* HTTP_QUERY_VIA = 66 */
2276     szWarning,                  /* HTTP_QUERY_WARNING = 67 */
2277     szExpect,                   /* HTTP_QUERY_EXPECT = 68 */
2278     szProxy_Connection,         /* HTTP_QUERY_PROXY_CONNECTION = 69 */
2279     szUnless_Modified_Since,    /* HTTP_QUERY_UNLESS_MODIFIED_SINCE = 70 */
2280 };
2281
2282 #define LAST_TABLE_HEADER (sizeof(header_lookup)/sizeof(header_lookup[0]))
2283
2284 /***********************************************************************
2285  *           HTTP_HttpQueryInfoW (internal)
2286  */
2287 static BOOL HTTP_HttpQueryInfoW( LPWININETHTTPREQW lpwhr, DWORD dwInfoLevel,
2288         LPVOID lpBuffer, LPDWORD lpdwBufferLength, LPDWORD lpdwIndex)
2289 {
2290     LPHTTPHEADERW lphttpHdr = NULL;
2291     BOOL bSuccess = FALSE;
2292     BOOL request_only = dwInfoLevel & HTTP_QUERY_FLAG_REQUEST_HEADERS;
2293     INT requested_index = lpdwIndex ? *lpdwIndex : 0;
2294     DWORD level = (dwInfoLevel & ~HTTP_QUERY_MODIFIER_FLAGS_MASK);
2295     INT index = -1;
2296
2297     /* Find requested header structure */
2298     switch (level)
2299     {
2300     case HTTP_QUERY_CUSTOM:
2301         if (!lpBuffer) return FALSE;
2302         index = HTTP_GetCustomHeaderIndex(lpwhr, lpBuffer, requested_index, request_only);
2303         break;
2304
2305     case HTTP_QUERY_RAW_HEADERS_CRLF:
2306         {
2307             LPWSTR headers;
2308             DWORD len = 0;
2309             BOOL ret = FALSE;
2310
2311             if (request_only)
2312                 headers = HTTP_BuildHeaderRequestString(lpwhr, lpwhr->lpszVerb, lpwhr->lpszPath, lpwhr->lpszVersion);
2313             else
2314                 headers = lpwhr->lpszRawHeaders;
2315
2316             if (headers)
2317                 len = strlenW(headers) * sizeof(WCHAR);
2318
2319             if (len + sizeof(WCHAR) > *lpdwBufferLength)
2320             {
2321                 len += sizeof(WCHAR);
2322                 INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2323                 ret = FALSE;
2324             }
2325             else if (lpBuffer)
2326             {
2327                 if (headers)
2328                     memcpy(lpBuffer, headers, len + sizeof(WCHAR));
2329                 else
2330                 {
2331                     len = strlenW(szCrLf) * sizeof(WCHAR);
2332                     memcpy(lpBuffer, szCrLf, sizeof(szCrLf));
2333                 }
2334                 TRACE("returning data: %s\n", debugstr_wn(lpBuffer, len / sizeof(WCHAR)));
2335                 ret = TRUE;
2336             }
2337             *lpdwBufferLength = len;
2338
2339             if (request_only)
2340                 HeapFree(GetProcessHeap(), 0, headers);
2341             return ret;
2342         }
2343     case HTTP_QUERY_RAW_HEADERS:
2344         {
2345             LPWSTR * ppszRawHeaderLines = HTTP_Tokenize(lpwhr->lpszRawHeaders, szCrLf);
2346             DWORD i, size = 0;
2347             LPWSTR pszString = lpBuffer;
2348
2349             for (i = 0; ppszRawHeaderLines[i]; i++)
2350                 size += strlenW(ppszRawHeaderLines[i]) + 1;
2351
2352             if (size + 1 > *lpdwBufferLength/sizeof(WCHAR))
2353             {
2354                 HTTP_FreeTokens(ppszRawHeaderLines);
2355                 *lpdwBufferLength = (size + 1) * sizeof(WCHAR);
2356                 INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2357                 return FALSE;
2358             }
2359             if (pszString)
2360             {
2361                 for (i = 0; ppszRawHeaderLines[i]; i++)
2362                 {
2363                     DWORD len = strlenW(ppszRawHeaderLines[i]);
2364                     memcpy(pszString, ppszRawHeaderLines[i], (len+1)*sizeof(WCHAR));
2365                     pszString += len+1;
2366                 }
2367                 *pszString = '\0';
2368                 TRACE("returning data: %s\n", debugstr_wn(lpBuffer, size));
2369             }
2370             *lpdwBufferLength = size * sizeof(WCHAR);
2371             HTTP_FreeTokens(ppszRawHeaderLines);
2372
2373             return TRUE;
2374         }
2375     case HTTP_QUERY_STATUS_TEXT:
2376         if (lpwhr->lpszStatusText)
2377         {
2378             DWORD len = strlenW(lpwhr->lpszStatusText);
2379             if (len + 1 > *lpdwBufferLength/sizeof(WCHAR))
2380             {
2381                 *lpdwBufferLength = (len + 1) * sizeof(WCHAR);
2382                 INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2383                 return FALSE;
2384             }
2385             if (lpBuffer)
2386             {
2387                 memcpy(lpBuffer, lpwhr->lpszStatusText, (len + 1) * sizeof(WCHAR));
2388                 TRACE("returning data: %s\n", debugstr_wn(lpBuffer, len));
2389             }
2390             *lpdwBufferLength = len * sizeof(WCHAR);
2391             return TRUE;
2392         }
2393         break;
2394     case HTTP_QUERY_VERSION:
2395         if (lpwhr->lpszVersion)
2396         {
2397             DWORD len = strlenW(lpwhr->lpszVersion);
2398             if (len + 1 > *lpdwBufferLength/sizeof(WCHAR))
2399             {
2400                 *lpdwBufferLength = (len + 1) * sizeof(WCHAR);
2401                 INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2402                 return FALSE;
2403             }
2404             if (lpBuffer)
2405             {
2406                 memcpy(lpBuffer, lpwhr->lpszVersion, (len + 1) * sizeof(WCHAR));
2407                 TRACE("returning data: %s\n", debugstr_wn(lpBuffer, len));
2408             }
2409             *lpdwBufferLength = len * sizeof(WCHAR);
2410             return TRUE;
2411         }
2412         break;
2413     default:
2414         assert (LAST_TABLE_HEADER == (HTTP_QUERY_UNLESS_MODIFIED_SINCE + 1));
2415
2416         if (level < LAST_TABLE_HEADER && header_lookup[level])
2417             index = HTTP_GetCustomHeaderIndex(lpwhr, header_lookup[level],
2418                                               requested_index,request_only);
2419     }
2420
2421     if (index >= 0)
2422         lphttpHdr = &lpwhr->pCustHeaders[index];
2423
2424     /* Ensure header satisfies requested attributes */
2425     if (!lphttpHdr ||
2426         ((dwInfoLevel & HTTP_QUERY_FLAG_REQUEST_HEADERS) &&
2427          (~lphttpHdr->wFlags & HDR_ISREQUEST)))
2428     {
2429         INTERNET_SetLastError(ERROR_HTTP_HEADER_NOT_FOUND);
2430         return bSuccess;
2431     }
2432
2433     if (lpdwIndex && level != HTTP_QUERY_STATUS_CODE) (*lpdwIndex)++;
2434
2435     /* coalesce value to requested type */
2436     if (dwInfoLevel & HTTP_QUERY_FLAG_NUMBER && lpBuffer)
2437     {
2438         *(int *)lpBuffer = atoiW(lphttpHdr->lpszValue);
2439         TRACE(" returning number: %d\n", *(int *)lpBuffer);
2440         bSuccess = TRUE;
2441     }
2442     else if (dwInfoLevel & HTTP_QUERY_FLAG_SYSTEMTIME && lpBuffer)
2443     {
2444         time_t tmpTime;
2445         struct tm tmpTM;
2446         SYSTEMTIME *STHook;
2447
2448         tmpTime = ConvertTimeString(lphttpHdr->lpszValue);
2449
2450         tmpTM = *gmtime(&tmpTime);
2451         STHook = (SYSTEMTIME *)lpBuffer;
2452         STHook->wDay = tmpTM.tm_mday;
2453         STHook->wHour = tmpTM.tm_hour;
2454         STHook->wMilliseconds = 0;
2455         STHook->wMinute = tmpTM.tm_min;
2456         STHook->wDayOfWeek = tmpTM.tm_wday;
2457         STHook->wMonth = tmpTM.tm_mon + 1;
2458         STHook->wSecond = tmpTM.tm_sec;
2459         STHook->wYear = tmpTM.tm_year;
2460         bSuccess = TRUE;
2461         
2462         TRACE(" returning time: %04d/%02d/%02d - %d - %02d:%02d:%02d.%02d\n",
2463               STHook->wYear, STHook->wMonth, STHook->wDay, STHook->wDayOfWeek,
2464               STHook->wHour, STHook->wMinute, STHook->wSecond, STHook->wMilliseconds);
2465     }
2466     else if (lphttpHdr->lpszValue)
2467     {
2468         DWORD len = (strlenW(lphttpHdr->lpszValue) + 1) * sizeof(WCHAR);
2469
2470         if (len > *lpdwBufferLength)
2471         {
2472             *lpdwBufferLength = len;
2473             INTERNET_SetLastError(ERROR_INSUFFICIENT_BUFFER);
2474             return bSuccess;
2475         }
2476         if (lpBuffer)
2477         {
2478             memcpy(lpBuffer, lphttpHdr->lpszValue, len);
2479             TRACE(" returning string: %s\n", debugstr_w(lpBuffer));
2480         }
2481         *lpdwBufferLength = len - sizeof(WCHAR);
2482         bSuccess = TRUE;
2483     }
2484     return bSuccess;
2485 }
2486
2487 /***********************************************************************
2488  *           HttpQueryInfoW (WININET.@)
2489  *
2490  * Queries for information about an HTTP request
2491  *
2492  * RETURNS
2493  *    TRUE  on success
2494  *    FALSE on failure
2495  *
2496  */
2497 BOOL WINAPI HttpQueryInfoW(HINTERNET hHttpRequest, DWORD dwInfoLevel,
2498         LPVOID lpBuffer, LPDWORD lpdwBufferLength, LPDWORD lpdwIndex)
2499 {
2500     BOOL bSuccess = FALSE;
2501     LPWININETHTTPREQW lpwhr;
2502
2503     if (TRACE_ON(wininet)) {
2504 #define FE(x) { x, #x }
2505         static const wininet_flag_info query_flags[] = {
2506             FE(HTTP_QUERY_MIME_VERSION),
2507             FE(HTTP_QUERY_CONTENT_TYPE),
2508             FE(HTTP_QUERY_CONTENT_TRANSFER_ENCODING),
2509             FE(HTTP_QUERY_CONTENT_ID),
2510             FE(HTTP_QUERY_CONTENT_DESCRIPTION),
2511             FE(HTTP_QUERY_CONTENT_LENGTH),
2512             FE(HTTP_QUERY_CONTENT_LANGUAGE),
2513             FE(HTTP_QUERY_ALLOW),
2514             FE(HTTP_QUERY_PUBLIC),
2515             FE(HTTP_QUERY_DATE),
2516             FE(HTTP_QUERY_EXPIRES),
2517             FE(HTTP_QUERY_LAST_MODIFIED),
2518             FE(HTTP_QUERY_MESSAGE_ID),
2519             FE(HTTP_QUERY_URI),
2520             FE(HTTP_QUERY_DERIVED_FROM),
2521             FE(HTTP_QUERY_COST),
2522             FE(HTTP_QUERY_LINK),
2523             FE(HTTP_QUERY_PRAGMA),
2524             FE(HTTP_QUERY_VERSION),
2525             FE(HTTP_QUERY_STATUS_CODE),
2526             FE(HTTP_QUERY_STATUS_TEXT),
2527             FE(HTTP_QUERY_RAW_HEADERS),
2528             FE(HTTP_QUERY_RAW_HEADERS_CRLF),
2529             FE(HTTP_QUERY_CONNECTION),
2530             FE(HTTP_QUERY_ACCEPT),
2531             FE(HTTP_QUERY_ACCEPT_CHARSET),
2532             FE(HTTP_QUERY_ACCEPT_ENCODING),
2533             FE(HTTP_QUERY_ACCEPT_LANGUAGE),
2534             FE(HTTP_QUERY_AUTHORIZATION),
2535             FE(HTTP_QUERY_CONTENT_ENCODING),
2536             FE(HTTP_QUERY_FORWARDED),
2537             FE(HTTP_QUERY_FROM),
2538             FE(HTTP_QUERY_IF_MODIFIED_SINCE),
2539             FE(HTTP_QUERY_LOCATION),
2540             FE(HTTP_QUERY_ORIG_URI),
2541             FE(HTTP_QUERY_REFERER),
2542             FE(HTTP_QUERY_RETRY_AFTER),
2543             FE(HTTP_QUERY_SERVER),
2544             FE(HTTP_QUERY_TITLE),
2545             FE(HTTP_QUERY_USER_AGENT),
2546             FE(HTTP_QUERY_WWW_AUTHENTICATE),
2547             FE(HTTP_QUERY_PROXY_AUTHENTICATE),
2548             FE(HTTP_QUERY_ACCEPT_RANGES),
2549         FE(HTTP_QUERY_SET_COOKIE),
2550         FE(HTTP_QUERY_COOKIE),
2551             FE(HTTP_QUERY_REQUEST_METHOD),
2552             FE(HTTP_QUERY_REFRESH),
2553             FE(HTTP_QUERY_CONTENT_DISPOSITION),
2554             FE(HTTP_QUERY_AGE),
2555             FE(HTTP_QUERY_CACHE_CONTROL),
2556             FE(HTTP_QUERY_CONTENT_BASE),
2557             FE(HTTP_QUERY_CONTENT_LOCATION),
2558             FE(HTTP_QUERY_CONTENT_MD5),
2559             FE(HTTP_QUERY_CONTENT_RANGE),
2560             FE(HTTP_QUERY_ETAG),
2561             FE(HTTP_QUERY_HOST),
2562             FE(HTTP_QUERY_IF_MATCH),
2563             FE(HTTP_QUERY_IF_NONE_MATCH),
2564             FE(HTTP_QUERY_IF_RANGE),
2565             FE(HTTP_QUERY_IF_UNMODIFIED_SINCE),
2566             FE(HTTP_QUERY_MAX_FORWARDS),
2567             FE(HTTP_QUERY_PROXY_AUTHORIZATION),
2568             FE(HTTP_QUERY_RANGE),
2569             FE(HTTP_QUERY_TRANSFER_ENCODING),
2570             FE(HTTP_QUERY_UPGRADE),
2571             FE(HTTP_QUERY_VARY),
2572             FE(HTTP_QUERY_VIA),
2573             FE(HTTP_QUERY_WARNING),
2574             FE(HTTP_QUERY_CUSTOM)
2575         };
2576         static const wininet_flag_info modifier_flags[] = {
2577             FE(HTTP_QUERY_FLAG_REQUEST_HEADERS),
2578             FE(HTTP_QUERY_FLAG_SYSTEMTIME),
2579             FE(HTTP_QUERY_FLAG_NUMBER),
2580             FE(HTTP_QUERY_FLAG_COALESCE)
2581         };
2582 #undef FE
2583         DWORD info_mod = dwInfoLevel & HTTP_QUERY_MODIFIER_FLAGS_MASK;
2584         DWORD info = dwInfoLevel & HTTP_QUERY_HEADER_MASK;
2585         DWORD i;
2586
2587         TRACE("(%p, 0x%08x)--> %d\n", hHttpRequest, dwInfoLevel, dwInfoLevel);
2588         TRACE("  Attribute:");
2589         for (i = 0; i < (sizeof(query_flags) / sizeof(query_flags[0])); i++) {
2590             if (query_flags[i].val == info) {
2591                 TRACE(" %s", query_flags[i].name);
2592                 break;
2593             }
2594         }
2595         if (i == (sizeof(query_flags) / sizeof(query_flags[0]))) {
2596             TRACE(" Unknown (%08x)", info);
2597         }
2598
2599         TRACE(" Modifier:");
2600         for (i = 0; i < (sizeof(modifier_flags) / sizeof(modifier_flags[0])); i++) {
2601             if (modifier_flags[i].val & info_mod) {
2602                 TRACE(" %s", modifier_flags[i].name);
2603                 info_mod &= ~ modifier_flags[i].val;
2604             }
2605         }
2606         
2607         if (info_mod) {
2608             TRACE(" Unknown (%08x)", info_mod);
2609         }
2610         TRACE("\n");
2611     }
2612     
2613     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hHttpRequest );
2614     if (NULL == lpwhr ||  lpwhr->hdr.htype != WH_HHTTPREQ)
2615     {
2616         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2617         goto lend;
2618     }
2619
2620     if (lpBuffer == NULL)
2621         *lpdwBufferLength = 0;
2622     bSuccess = HTTP_HttpQueryInfoW( lpwhr, dwInfoLevel,
2623                                     lpBuffer, lpdwBufferLength, lpdwIndex);
2624
2625 lend:
2626     if( lpwhr )
2627          WININET_Release( &lpwhr->hdr );
2628
2629     TRACE("%d <--\n", bSuccess);
2630     return bSuccess;
2631 }
2632
2633 /***********************************************************************
2634  *           HttpQueryInfoA (WININET.@)
2635  *
2636  * Queries for information about an HTTP request
2637  *
2638  * RETURNS
2639  *    TRUE  on success
2640  *    FALSE on failure
2641  *
2642  */
2643 BOOL WINAPI HttpQueryInfoA(HINTERNET hHttpRequest, DWORD dwInfoLevel,
2644         LPVOID lpBuffer, LPDWORD lpdwBufferLength, LPDWORD lpdwIndex)
2645 {
2646     BOOL result;
2647     DWORD len;
2648     WCHAR* bufferW;
2649
2650     if((dwInfoLevel & HTTP_QUERY_FLAG_NUMBER) ||
2651        (dwInfoLevel & HTTP_QUERY_FLAG_SYSTEMTIME))
2652     {
2653         return HttpQueryInfoW( hHttpRequest, dwInfoLevel, lpBuffer,
2654                                lpdwBufferLength, lpdwIndex );
2655     }
2656
2657     if (lpBuffer)
2658     {
2659         DWORD alloclen;
2660         len = (*lpdwBufferLength)*sizeof(WCHAR);
2661         if ((dwInfoLevel & HTTP_QUERY_HEADER_MASK) == HTTP_QUERY_CUSTOM)
2662         {
2663             alloclen = MultiByteToWideChar( CP_ACP, 0, lpBuffer, -1, NULL, 0 ) * sizeof(WCHAR);
2664             if (alloclen < len)
2665                 alloclen = len;
2666         }
2667         else
2668             alloclen = len;
2669         bufferW = HeapAlloc( GetProcessHeap(), 0, alloclen );
2670         /* buffer is in/out because of HTTP_QUERY_CUSTOM */
2671         if ((dwInfoLevel & HTTP_QUERY_HEADER_MASK) == HTTP_QUERY_CUSTOM)
2672             MultiByteToWideChar( CP_ACP, 0, lpBuffer, -1, bufferW, alloclen / sizeof(WCHAR) );
2673     } else
2674     {
2675         bufferW = NULL;
2676         len = 0;
2677     }
2678
2679     result = HttpQueryInfoW( hHttpRequest, dwInfoLevel, bufferW,
2680                            &len, lpdwIndex );
2681     if( result )
2682     {
2683         len = WideCharToMultiByte( CP_ACP,0, bufferW, len / sizeof(WCHAR) + 1,
2684                                      lpBuffer, *lpdwBufferLength, NULL, NULL );
2685         *lpdwBufferLength = len - 1;
2686
2687         TRACE("lpBuffer: %s\n", debugstr_a(lpBuffer));
2688     }
2689     else
2690         /* since the strings being returned from HttpQueryInfoW should be
2691          * only ASCII characters, it is reasonable to assume that all of
2692          * the Unicode characters can be reduced to a single byte */
2693         *lpdwBufferLength = len / sizeof(WCHAR);
2694
2695     HeapFree(GetProcessHeap(), 0, bufferW );
2696
2697     return result;
2698 }
2699
2700 /***********************************************************************
2701  *           HttpSendRequestExA (WININET.@)
2702  *
2703  * Sends the specified request to the HTTP server and allows chunked
2704  * transfers.
2705  *
2706  * RETURNS
2707  *  Success: TRUE
2708  *  Failure: FALSE, call GetLastError() for more information.
2709  */
2710 BOOL WINAPI HttpSendRequestExA(HINTERNET hRequest,
2711                                LPINTERNET_BUFFERSA lpBuffersIn,
2712                                LPINTERNET_BUFFERSA lpBuffersOut,
2713                                DWORD dwFlags, DWORD_PTR dwContext)
2714 {
2715     INTERNET_BUFFERSW BuffersInW;
2716     BOOL rc = FALSE;
2717     DWORD headerlen;
2718     LPWSTR header = NULL;
2719
2720     TRACE("(%p, %p, %p, %08x, %08lx)\n", hRequest, lpBuffersIn,
2721             lpBuffersOut, dwFlags, dwContext);
2722
2723     if (lpBuffersIn)
2724     {
2725         BuffersInW.dwStructSize = sizeof(LPINTERNET_BUFFERSW);
2726         if (lpBuffersIn->lpcszHeader)
2727         {
2728             headerlen = MultiByteToWideChar(CP_ACP,0,lpBuffersIn->lpcszHeader,
2729                     lpBuffersIn->dwHeadersLength,0,0);
2730             header = HeapAlloc(GetProcessHeap(),0,headerlen*sizeof(WCHAR));
2731             if (!(BuffersInW.lpcszHeader = header))
2732             {
2733                 INTERNET_SetLastError(ERROR_OUTOFMEMORY);
2734                 return FALSE;
2735             }
2736             BuffersInW.dwHeadersLength = MultiByteToWideChar(CP_ACP, 0,
2737                     lpBuffersIn->lpcszHeader, lpBuffersIn->dwHeadersLength,
2738                     header, headerlen);
2739         }
2740         else
2741             BuffersInW.lpcszHeader = NULL;
2742         BuffersInW.dwHeadersTotal = lpBuffersIn->dwHeadersTotal;
2743         BuffersInW.lpvBuffer = lpBuffersIn->lpvBuffer;
2744         BuffersInW.dwBufferLength = lpBuffersIn->dwBufferLength;
2745         BuffersInW.dwBufferTotal = lpBuffersIn->dwBufferTotal;
2746         BuffersInW.Next = NULL;
2747     }
2748
2749     rc = HttpSendRequestExW(hRequest, lpBuffersIn ? &BuffersInW : NULL, NULL, dwFlags, dwContext);
2750
2751     HeapFree(GetProcessHeap(),0,header);
2752
2753     return rc;
2754 }
2755
2756 /***********************************************************************
2757  *           HttpSendRequestExW (WININET.@)
2758  *
2759  * Sends the specified request to the HTTP server and allows chunked
2760  * transfers
2761  *
2762  * RETURNS
2763  *  Success: TRUE
2764  *  Failure: FALSE, call GetLastError() for more information.
2765  */
2766 BOOL WINAPI HttpSendRequestExW(HINTERNET hRequest,
2767                    LPINTERNET_BUFFERSW lpBuffersIn,
2768                    LPINTERNET_BUFFERSW lpBuffersOut,
2769                    DWORD dwFlags, DWORD_PTR dwContext)
2770 {
2771     BOOL ret = FALSE;
2772     LPWININETHTTPREQW lpwhr;
2773     LPWININETHTTPSESSIONW lpwhs;
2774     LPWININETAPPINFOW hIC;
2775
2776     TRACE("(%p, %p, %p, %08x, %08lx)\n", hRequest, lpBuffersIn,
2777             lpBuffersOut, dwFlags, dwContext);
2778
2779     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hRequest );
2780
2781     if (NULL == lpwhr || lpwhr->hdr.htype != WH_HHTTPREQ)
2782     {
2783         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2784         goto lend;
2785     }
2786
2787     lpwhs = lpwhr->lpHttpSession;
2788     assert(lpwhs->hdr.htype == WH_HHTTPSESSION);
2789     hIC = lpwhs->lpAppInfo;
2790     assert(hIC->hdr.htype == WH_HINIT);
2791
2792     if (hIC->hdr.dwFlags & INTERNET_FLAG_ASYNC)
2793     {
2794         WORKREQUEST workRequest;
2795         struct WORKREQ_HTTPSENDREQUESTW *req;
2796
2797         workRequest.asyncproc = AsyncHttpSendRequestProc;
2798         workRequest.hdr = WININET_AddRef( &lpwhr->hdr );
2799         req = &workRequest.u.HttpSendRequestW;
2800         if (lpBuffersIn)
2801         {
2802             if (lpBuffersIn->lpcszHeader)
2803                 /* FIXME: this should use dwHeadersLength or may not be necessary at all */
2804                 req->lpszHeader = WININET_strdupW(lpBuffersIn->lpcszHeader);
2805             else
2806                 req->lpszHeader = NULL;
2807             req->dwHeaderLength = lpBuffersIn->dwHeadersLength;
2808             req->lpOptional = lpBuffersIn->lpvBuffer;
2809             req->dwOptionalLength = lpBuffersIn->dwBufferLength;
2810             req->dwContentLength = lpBuffersIn->dwBufferTotal;
2811         }
2812         else
2813         {
2814             req->lpszHeader = NULL;
2815             req->dwHeaderLength = 0;
2816             req->lpOptional = NULL;
2817             req->dwOptionalLength = 0;
2818             req->dwContentLength = 0;
2819         }
2820
2821         req->bEndRequest = FALSE;
2822
2823         INTERNET_AsyncCall(&workRequest);
2824         /*
2825          * This is from windows.
2826          */
2827         INTERNET_SetLastError(ERROR_IO_PENDING);
2828     }
2829     else
2830     {
2831         if (lpBuffersIn)
2832             ret = HTTP_HttpSendRequestW(lpwhr, lpBuffersIn->lpcszHeader, lpBuffersIn->dwHeadersLength,
2833                                         lpBuffersIn->lpvBuffer, lpBuffersIn->dwBufferLength,
2834                                         lpBuffersIn->dwBufferTotal, FALSE);
2835         else
2836             ret = HTTP_HttpSendRequestW(lpwhr, NULL, 0, NULL, 0, 0, FALSE);
2837     }
2838
2839 lend:
2840     if ( lpwhr )
2841         WININET_Release( &lpwhr->hdr );
2842
2843     TRACE("<---\n");
2844     return ret;
2845 }
2846
2847 /***********************************************************************
2848  *           HttpSendRequestW (WININET.@)
2849  *
2850  * Sends the specified request to the HTTP server
2851  *
2852  * RETURNS
2853  *    TRUE  on success
2854  *    FALSE on failure
2855  *
2856  */
2857 BOOL WINAPI HttpSendRequestW(HINTERNET hHttpRequest, LPCWSTR lpszHeaders,
2858         DWORD dwHeaderLength, LPVOID lpOptional ,DWORD dwOptionalLength)
2859 {
2860     LPWININETHTTPREQW lpwhr;
2861     LPWININETHTTPSESSIONW lpwhs = NULL;
2862     LPWININETAPPINFOW hIC = NULL;
2863     BOOL r;
2864
2865     TRACE("%p, %s, %i, %p, %i)\n", hHttpRequest,
2866             debugstr_wn(lpszHeaders, dwHeaderLength), dwHeaderLength, lpOptional, dwOptionalLength);
2867
2868     lpwhr = (LPWININETHTTPREQW) WININET_GetObject( hHttpRequest );
2869     if (NULL == lpwhr || lpwhr->hdr.htype != WH_HHTTPREQ)
2870     {
2871         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2872         r = FALSE;
2873         goto lend;
2874     }
2875
2876     lpwhs = lpwhr->lpHttpSession;
2877     if (NULL == lpwhs ||  lpwhs->hdr.htype != WH_HHTTPSESSION)
2878     {
2879         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2880         r = FALSE;
2881         goto lend;
2882     }
2883
2884     hIC = lpwhs->lpAppInfo;
2885     if (NULL == hIC ||  hIC->hdr.htype != WH_HINIT)
2886     {
2887         INTERNET_SetLastError(ERROR_INTERNET_INCORRECT_HANDLE_TYPE);
2888         r = FALSE;
2889         goto lend;
2890     }
2891
2892     if (hIC->hdr.dwFlags & INTERNET_FLAG_ASYNC)
2893     {
2894         WORKREQUEST workRequest;
2895         struct WORKREQ_HTTPSENDREQUESTW *req;
2896
2897         workRequest.asyncproc = AsyncHttpSendRequestProc;
2898         workRequest.hdr = WININET_AddRef( &lpwhr->hdr );
2899         req = &workRequest.u.HttpSendRequestW;
2900         if (lpszHeaders)
2901         {
2902             DWORD size;
2903
2904             if (dwHeaderLength == ~0u) size = (strlenW(lpszHeaders) + 1) * sizeof(WCHAR);
2905             else size = dwHeaderLength * sizeof(WCHAR);
2906
2907             req->lpszHeader = HeapAlloc(GetProcessHeap(), 0, size);
2908             memcpy(req->lpszHeader, lpszHeaders, size);
2909         }
2910         else
2911             req->lpszHeader = 0;
2912         req->dwHeaderLength = dwHeaderLength;
2913         req->lpOptional = lpOptional;
2914         req->dwOptionalLength = dwOptionalLength;
2915         req->dwContentLength = dwOptionalLength;
2916         req->bEndRequest = TRUE;
2917
2918         INTERNET_AsyncCall(&workRequest);
2919         /*
2920          * This is from windows.
2921          */
2922         INTERNET_SetLastError(ERROR_IO_PENDING);
2923         r = FALSE;
2924     }
2925     else
2926     {
2927         r = HTTP_HttpSendRequestW(lpwhr, lpszHeaders,
2928                 dwHeaderLength, lpOptional, dwOptionalLength,
2929                 dwOptionalLength, TRUE);
2930     }
2931 lend:
2932     if( lpwhr )
2933         WININET_Release( &lpwhr->hdr );
2934     return r;
2935 }
2936
2937 /***********************************************************************
2938  *           HttpSendRequestA (WININET.@)
2939  *
2940  * Sends the specified request to the HTTP server
2941  *
2942  * RETURNS
2943  *    TRUE  on success
2944  *    FALSE on failure
2945  *
2946  */
2947 BOOL WINAPI HttpSendRequestA(HINTERNET hHttpRequest, LPCSTR lpszHeaders,
2948         DWORD dwHeaderLength, LPVOID lpOptional ,DWORD dwOptionalLength)
2949 {
2950     BOOL result;
2951     LPWSTR szHeaders=NULL;
2952     DWORD nLen=dwHeaderLength;
2953     if(lpszHeaders!=NULL)
2954     {
2955         nLen=MultiByteToWideChar(CP_ACP,0,lpszHeaders,dwHeaderLength,NULL,0);
2956         szHeaders=HeapAlloc(GetProcessHeap(),0,nLen*sizeof(WCHAR));
2957         MultiByteToWideChar(CP_ACP,0,lpszHeaders,dwHeaderLength,szHeaders,nLen);
2958     }
2959     result=HttpSendRequestW(hHttpRequest, szHeaders, nLen, lpOptional, dwOptionalLength);
2960     HeapFree(GetProcessHeap(),0,szHeaders);
2961     return result;
2962 }
2963
2964 static BOOL HTTP_GetRequestURL(WININETHTTPREQW *req, LPWSTR buf)
2965 {
2966     LPHTTPHEADERW host_header;
2967
2968     static const WCHAR formatW[] = {'h','t','t','p',':','/','/','%','s','%','s',0};
2969
2970     host_header = HTTP_GetHeader(req, szHost);
2971     if(!host_header)
2972         return FALSE;
2973
2974     sprintfW(buf, formatW, host_header->lpszValue, req->lpszPath); /* FIXME */
2975     return TRUE;
2976 }
2977
2978 /***********************************************************************
2979  *           HTTP_HandleRedirect (internal)
2980  */
2981 static BOOL HTTP_HandleRedirect(LPWININETHTTPREQW lpwhr, LPCWSTR lpszUrl)
2982 {
2983     LPWININETHTTPSESSIONW lpwhs = lpwhr->lpHttpSession;
2984     LPWININETAPPINFOW hIC = lpwhs->lpAppInfo;
2985     BOOL using_proxy = hIC->lpszProxy && hIC->lpszProxy[0];
2986     WCHAR path[INTERNET_MAX_URL_LENGTH];
2987     int index;
2988
2989     if(lpszUrl[0]=='/')
2990     {
2991         /* if it's an absolute path, keep the same session info */
2992         lstrcpynW(path, lpszUrl, INTERNET_MAX_URL_LENGTH);
2993     }
2994     else
2995     {
2996         URL_COMPONENTSW urlComponents;
2997         WCHAR protocol[32], hostName[MAXHOSTNAME], userName[1024];
2998         static WCHAR szHttp[] = {'h','t','t','p',0};
2999         static WCHAR szHttps[] = {'h','t','t','p','s',0};
3000         DWORD url_length = 0;
3001         LPWSTR orig_url;
3002         LPWSTR combined_url;
3003
3004         urlComponents.dwStructSize = sizeof(URL_COMPONENTSW);
3005         urlComponents.lpszScheme = (lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE) ? szHttps : szHttp;
3006         urlComponents.dwSchemeLength = 0;
3007         urlComponents.lpszHostName = lpwhs->lpszHostName;
3008         urlComponents.dwHostNameLength = 0;
3009         urlComponents.nPort = lpwhs->nHostPort;
3010         urlComponents.lpszUserName = lpwhs->lpszUserName;
3011         urlComponents.dwUserNameLength = 0;
3012         urlComponents.lpszPassword = NULL;
3013         urlComponents.dwPasswordLength = 0;
3014         urlComponents.lpszUrlPath = lpwhr->lpszPath;
3015         urlComponents.dwUrlPathLength = 0;
3016         urlComponents.lpszExtraInfo = NULL;
3017         urlComponents.dwExtraInfoLength = 0;
3018
3019         if (!InternetCreateUrlW(&urlComponents, 0, NULL, &url_length) &&
3020             (GetLastError() != ERROR_INSUFFICIENT_BUFFER))
3021             return FALSE;
3022
3023         orig_url = HeapAlloc(GetProcessHeap(), 0, url_length);
3024
3025         /* convert from bytes to characters */
3026         url_length = url_length / sizeof(WCHAR) - 1;
3027         if (!InternetCreateUrlW(&urlComponents, 0, orig_url, &url_length))
3028         {
3029             HeapFree(GetProcessHeap(), 0, orig_url);
3030             return FALSE;
3031         }
3032
3033         url_length = 0;
3034         if (!InternetCombineUrlW(orig_url, lpszUrl, NULL, &url_length, ICU_ENCODE_SPACES_ONLY) &&
3035             (GetLastError() != ERROR_INSUFFICIENT_BUFFER))
3036         {
3037             HeapFree(GetProcessHeap(), 0, orig_url);
3038             return FALSE;
3039         }
3040         combined_url = HeapAlloc(GetProcessHeap(), 0, url_length * sizeof(WCHAR));
3041
3042         if (!InternetCombineUrlW(orig_url, lpszUrl, combined_url, &url_length, ICU_ENCODE_SPACES_ONLY))
3043         {
3044             HeapFree(GetProcessHeap(), 0, orig_url);
3045             HeapFree(GetProcessHeap(), 0, combined_url);
3046             return FALSE;
3047         }
3048         HeapFree(GetProcessHeap(), 0, orig_url);
3049
3050         userName[0] = 0;
3051         hostName[0] = 0;
3052         protocol[0] = 0;
3053
3054         urlComponents.dwStructSize = sizeof(URL_COMPONENTSW);
3055         urlComponents.lpszScheme = protocol;
3056         urlComponents.dwSchemeLength = 32;
3057         urlComponents.lpszHostName = hostName;
3058         urlComponents.dwHostNameLength = MAXHOSTNAME;
3059         urlComponents.lpszUserName = userName;
3060         urlComponents.dwUserNameLength = 1024;
3061         urlComponents.lpszPassword = NULL;
3062         urlComponents.dwPasswordLength = 0;
3063         urlComponents.lpszUrlPath = path;
3064         urlComponents.dwUrlPathLength = 2048;
3065         urlComponents.lpszExtraInfo = NULL;
3066         urlComponents.dwExtraInfoLength = 0;
3067         if(!InternetCrackUrlW(combined_url, strlenW(combined_url), 0, &urlComponents))
3068         {
3069             HeapFree(GetProcessHeap(), 0, combined_url);
3070             return FALSE;
3071         }
3072
3073         HeapFree(GetProcessHeap(), 0, combined_url);
3074
3075         if (!strncmpW(szHttp, urlComponents.lpszScheme, strlenW(szHttp)) &&
3076             (lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE))
3077         {
3078             TRACE("redirect from secure page to non-secure page\n");
3079             /* FIXME: warn about from secure redirect to non-secure page */
3080             lpwhr->hdr.dwFlags &= ~INTERNET_FLAG_SECURE;
3081         }
3082         if (!strncmpW(szHttps, urlComponents.lpszScheme, strlenW(szHttps)) &&
3083             !(lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE))
3084         {
3085             TRACE("redirect from non-secure page to secure page\n");
3086             /* FIXME: notify about redirect to secure page */
3087             lpwhr->hdr.dwFlags |= INTERNET_FLAG_SECURE;
3088         }
3089
3090         if (urlComponents.nPort == INTERNET_INVALID_PORT_NUMBER)
3091         {
3092             if (lstrlenW(protocol)>4) /*https*/
3093                 urlComponents.nPort = INTERNET_DEFAULT_HTTPS_PORT;
3094             else /*http*/
3095                 urlComponents.nPort = INTERNET_DEFAULT_HTTP_PORT;
3096         }
3097
3098 #if 0
3099         /*
3100          * This upsets redirects to binary files on sourceforge.net 
3101          * and gives an html page instead of the target file
3102          * Examination of the HTTP request sent by native wininet.dll
3103          * reveals that it doesn't send a referrer in that case.
3104          * Maybe there's a flag that enables this, or maybe a referrer
3105          * shouldn't be added in case of a redirect.
3106          */
3107
3108         /* consider the current host as the referrer */
3109         if (lpwhs->lpszServerName && *lpwhs->lpszServerName)
3110             HTTP_ProcessHeader(lpwhr, HTTP_REFERER, lpwhs->lpszServerName,
3111                            HTTP_ADDHDR_FLAG_REQ|HTTP_ADDREQ_FLAG_REPLACE|
3112                            HTTP_ADDHDR_FLAG_ADD_IF_NEW);
3113 #endif
3114         
3115         HeapFree(GetProcessHeap(), 0, lpwhs->lpszHostName);
3116         if (urlComponents.nPort != INTERNET_DEFAULT_HTTP_PORT &&
3117             urlComponents.nPort != INTERNET_DEFAULT_HTTPS_PORT)
3118         {
3119             int len;
3120             static const WCHAR fmt[] = {'%','s',':','%','i',0};
3121             len = lstrlenW(hostName);
3122             len += 7; /* 5 for strlen("65535") + 1 for ":" + 1 for '\0' */
3123             lpwhs->lpszHostName = HeapAlloc(GetProcessHeap(), 0, len*sizeof(WCHAR));
3124             sprintfW(lpwhs->lpszHostName, fmt, hostName, urlComponents.nPort);
3125         }
3126         else
3127             lpwhs->lpszHostName = WININET_strdupW(hostName);
3128
3129         HTTP_ProcessHeader(lpwhr, szHost, lpwhs->lpszHostName, HTTP_ADDREQ_FLAG_ADD | HTTP_ADDREQ_FLAG_REPLACE | HTTP_ADDHDR_FLAG_REQ);
3130
3131         HeapFree(GetProcessHeap(), 0, lpwhs->lpszUserName);
3132         lpwhs->lpszUserName = NULL;
3133         if (userName[0])
3134             lpwhs->lpszUserName = WININET_strdupW(userName);
3135
3136         if (!using_proxy)
3137         {
3138             if (strcmpiW(lpwhs->lpszServerName, hostName) || lpwhs->nServerPort != urlComponents.nPort)
3139             {
3140                 HeapFree(GetProcessHeap(), 0, lpwhs->lpszServerName);
3141                 lpwhs->lpszServerName = WININET_strdupW(hostName);
3142                 lpwhs->nServerPort = urlComponents.nPort;
3143
3144                 NETCON_close(&lpwhr->netConnection);
3145                 if (!HTTP_ResolveName(lpwhr)) return FALSE;
3146                 if (!NETCON_init(&lpwhr->netConnection, lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE)) return FALSE;
3147             }
3148         }
3149         else
3150             TRACE("Redirect through proxy\n");
3151     }
3152
3153     HeapFree(GetProcessHeap(), 0, lpwhr->lpszPath);
3154     lpwhr->lpszPath=NULL;
3155     if (*path)
3156     {
3157         DWORD needed = 0;
3158         HRESULT rc;
3159
3160         rc = UrlEscapeW(path, NULL, &needed, URL_ESCAPE_SPACES_ONLY);
3161         if (rc != E_POINTER)
3162             needed = strlenW(path)+1;
3163         lpwhr->lpszPath = HeapAlloc(GetProcessHeap(), 0, needed*sizeof(WCHAR));
3164         rc = UrlEscapeW(path, lpwhr->lpszPath, &needed,
3165                         URL_ESCAPE_SPACES_ONLY);
3166         if (rc != S_OK)
3167         {
3168             ERR("Unable to escape string!(%s) (%d)\n",debugstr_w(path),rc);
3169             strcpyW(lpwhr->lpszPath,path);
3170         }
3171     }
3172
3173     /* Remove custom content-type/length headers on redirects.  */
3174     index = HTTP_GetCustomHeaderIndex(lpwhr, szContent_Type, 0, TRUE);
3175     if (0 <= index)
3176         HTTP_DeleteCustomHeader(lpwhr, index);
3177     index = HTTP_GetCustomHeaderIndex(lpwhr, szContent_Length, 0, TRUE);
3178     if (0 <= index)
3179         HTTP_DeleteCustomHeader(lpwhr, index);
3180
3181     return TRUE;
3182 }
3183
3184 /***********************************************************************
3185  *           HTTP_build_req (internal)
3186  *
3187  *  concatenate all the strings in the request together
3188  */
3189 static LPWSTR HTTP_build_req( LPCWSTR *list, int len )
3190 {
3191     LPCWSTR *t;
3192     LPWSTR str;
3193
3194     for( t = list; *t ; t++  )
3195         len += strlenW( *t );
3196     len++;
3197
3198     str = HeapAlloc( GetProcessHeap(), 0, len*sizeof(WCHAR) );
3199     *str = 0;
3200
3201     for( t = list; *t ; t++ )
3202         strcatW( str, *t );
3203
3204     return str;
3205 }
3206
3207 static BOOL HTTP_SecureProxyConnect(LPWININETHTTPREQW lpwhr)
3208 {
3209     LPWSTR lpszPath;
3210     LPWSTR requestString;
3211     INT len;
3212     INT cnt;
3213     INT responseLen;
3214     char *ascii_req;
3215     BOOL ret;
3216     static const WCHAR szConnect[] = {'C','O','N','N','E','C','T',0};
3217     static const WCHAR szFormat[] = {'%','s',':','%','d',0};
3218     LPWININETHTTPSESSIONW lpwhs = lpwhr->lpHttpSession;
3219
3220     TRACE("\n");
3221
3222     lpszPath = HeapAlloc( GetProcessHeap(), 0, (lstrlenW( lpwhs->lpszHostName ) + 13)*sizeof(WCHAR) );
3223     sprintfW( lpszPath, szFormat, lpwhs->lpszHostName, lpwhs->nHostPort );
3224     requestString = HTTP_BuildHeaderRequestString( lpwhr, szConnect, lpszPath, g_szHttp1_1 );
3225     HeapFree( GetProcessHeap(), 0, lpszPath );
3226
3227     len = WideCharToMultiByte( CP_ACP, 0, requestString, -1,
3228                                 NULL, 0, NULL, NULL );
3229     len--; /* the nul terminator isn't needed */
3230     ascii_req = HeapAlloc( GetProcessHeap(), 0, len );
3231     WideCharToMultiByte( CP_ACP, 0, requestString, -1,
3232                             ascii_req, len, NULL, NULL );
3233     HeapFree( GetProcessHeap(), 0, requestString );
3234
3235     TRACE("full request -> %s\n", debugstr_an( ascii_req, len ) );
3236
3237     ret = NETCON_send( &lpwhr->netConnection, ascii_req, len, 0, &cnt );
3238     HeapFree( GetProcessHeap(), 0, ascii_req );
3239     if (!ret || cnt < 0)
3240         return FALSE;
3241
3242     responseLen = HTTP_GetResponseHeaders( lpwhr, TRUE );
3243     if (!responseLen)
3244         return FALSE;
3245
3246     return TRUE;
3247 }
3248
3249 static void HTTP_InsertCookies(LPWININETHTTPREQW lpwhr)
3250 {
3251     static const WCHAR szUrlForm[] = {'h','t','t','p',':','/','/','%','s',0};
3252     LPWSTR lpszCookies, lpszUrl = NULL;
3253     DWORD nCookieSize, size;
3254     LPHTTPHEADERW Host = HTTP_GetHeader(lpwhr,szHost);
3255
3256     size = (strlenW(Host->lpszValue) + strlenW(szUrlForm)) * sizeof(WCHAR);
3257     if (!(lpszUrl = HeapAlloc(GetProcessHeap(), 0, size))) return;
3258     sprintfW( lpszUrl, szUrlForm, Host->lpszValue );
3259
3260     if (InternetGetCookieW(lpszUrl, NULL, NULL, &nCookieSize))
3261     {
3262         int cnt = 0;
3263         static const WCHAR szCookie[] = {'C','o','o','k','i','e',':',' ',0};
3264
3265         size = sizeof(szCookie) + nCookieSize * sizeof(WCHAR) + sizeof(szCrLf);
3266         if ((lpszCookies = HeapAlloc(GetProcessHeap(), 0, size)))
3267         {
3268             cnt += sprintfW(lpszCookies, szCookie);
3269             InternetGetCookieW(lpszUrl, NULL, lpszCookies + cnt, &nCookieSize);
3270             strcatW(lpszCookies, szCrLf);
3271
3272             HTTP_HttpAddRequestHeadersW(lpwhr, lpszCookies, strlenW(lpszCookies), HTTP_ADDREQ_FLAG_ADD);
3273             HeapFree(GetProcessHeap(), 0, lpszCookies);
3274         }
3275     }
3276     HeapFree(GetProcessHeap(), 0, lpszUrl);
3277 }
3278
3279 /***********************************************************************
3280  *           HTTP_HttpSendRequestW (internal)
3281  *
3282  * Sends the specified request to the HTTP server
3283  *
3284  * RETURNS
3285  *    TRUE  on success
3286  *    FALSE on failure
3287  *
3288  */
3289 BOOL WINAPI HTTP_HttpSendRequestW(LPWININETHTTPREQW lpwhr, LPCWSTR lpszHeaders,
3290         DWORD dwHeaderLength, LPVOID lpOptional, DWORD dwOptionalLength,
3291         DWORD dwContentLength, BOOL bEndRequest)
3292 {
3293     INT cnt;
3294     BOOL bSuccess = FALSE;
3295     LPWSTR requestString = NULL;
3296     INT responseLen;
3297     BOOL loop_next;
3298     INTERNET_ASYNC_RESULT iar;
3299     static const WCHAR szPost[] = { 'P','O','S','T',0 };
3300     static const WCHAR szContentLength[] =
3301         { 'C','o','n','t','e','n','t','-','L','e','n','g','t','h',':',' ','%','l','i','\r','\n',0 };
3302     WCHAR contentLengthStr[sizeof szContentLength/2 /* includes \r\n */ + 20 /* int */ ];
3303
3304     TRACE("--> %p\n", lpwhr);
3305
3306     assert(lpwhr->hdr.htype == WH_HHTTPREQ);
3307
3308     /* if the verb is NULL default to GET */
3309     if (!lpwhr->lpszVerb)
3310         lpwhr->lpszVerb = WININET_strdupW(szGET);
3311
3312     if (dwContentLength || strcmpW(lpwhr->lpszVerb, szGET))
3313     {
3314         sprintfW(contentLengthStr, szContentLength, dwContentLength);
3315         HTTP_HttpAddRequestHeadersW(lpwhr, contentLengthStr, -1L, HTTP_ADDREQ_FLAG_ADD_IF_NEW);
3316     }
3317     if (lpwhr->lpHttpSession->lpAppInfo->lpszAgent)
3318     {
3319         WCHAR *agent_header;
3320         static const WCHAR user_agent[] = {'U','s','e','r','-','A','g','e','n','t',':',' ','%','s','\r','\n',0};
3321         int len;
3322
3323         len = strlenW(lpwhr->lpHttpSession->lpAppInfo->lpszAgent) + strlenW(user_agent);
3324         agent_header = HeapAlloc(GetProcessHeap(), 0, len * sizeof(WCHAR));
3325         sprintfW(agent_header, user_agent, lpwhr->lpHttpSession->lpAppInfo->lpszAgent);
3326
3327         HTTP_HttpAddRequestHeadersW(lpwhr, agent_header, strlenW(agent_header), HTTP_ADDREQ_FLAG_ADD_IF_NEW);
3328         HeapFree(GetProcessHeap(), 0, agent_header);
3329     }
3330     if (lpwhr->hdr.dwFlags & INTERNET_FLAG_PRAGMA_NOCACHE)
3331     {
3332         static const WCHAR pragma_nocache[] = {'P','r','a','g','m','a',':',' ','n','o','-','c','a','c','h','e','\r','\n',0};
3333         HTTP_HttpAddRequestHeadersW(lpwhr, pragma_nocache, strlenW(pragma_nocache), HTTP_ADDREQ_FLAG_ADD_IF_NEW);
3334     }
3335     if ((lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_CACHE_WRITE) && !strcmpW(lpwhr->lpszVerb, szPost))
3336     {
3337         static const WCHAR cache_control[] = {'C','a','c','h','e','-','C','o','n','t','r','o','l',':',
3338                                               ' ','n','o','-','c','a','c','h','e','\r','\n',0};
3339         HTTP_HttpAddRequestHeadersW(lpwhr, cache_control, strlenW(cache_control), HTTP_ADDREQ_FLAG_ADD_IF_NEW);
3340     }
3341
3342     do
3343     {
3344         DWORD len;
3345         char *ascii_req;
3346
3347         loop_next = FALSE;
3348
3349         /* like native, just in case the caller forgot to call InternetReadFile
3350          * for all the data */
3351         HTTP_DrainContent(lpwhr);
3352         lpwhr->dwContentRead = 0;
3353
3354         if (TRACE_ON(wininet))
3355         {
3356             LPHTTPHEADERW Host = HTTP_GetHeader(lpwhr,szHost);
3357             TRACE("Going to url %s %s\n", debugstr_w(Host->lpszValue), debugstr_w(lpwhr->lpszPath));
3358         }
3359
3360         HTTP_FixURL(lpwhr);
3361         if (lpwhr->hdr.dwFlags & INTERNET_FLAG_KEEP_CONNECTION)
3362         {
3363             HTTP_ProcessHeader(lpwhr, szConnection, szKeepAlive, HTTP_ADDHDR_FLAG_REQ | HTTP_ADDHDR_FLAG_REPLACE);
3364         }
3365         HTTP_InsertAuthorization(lpwhr, lpwhr->pAuthInfo, szAuthorization);
3366         HTTP_InsertAuthorization(lpwhr, lpwhr->pProxyAuthInfo, szProxy_Authorization);
3367
3368         if (!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_COOKIES))
3369             HTTP_InsertCookies(lpwhr);
3370
3371         /* add the headers the caller supplied */
3372         if( lpszHeaders && dwHeaderLength )
3373         {
3374             HTTP_HttpAddRequestHeadersW(lpwhr, lpszHeaders, dwHeaderLength,
3375                         HTTP_ADDREQ_FLAG_ADD | HTTP_ADDHDR_FLAG_REPLACE);
3376         }
3377
3378         if (lpwhr->lpHttpSession->lpAppInfo->lpszProxy && lpwhr->lpHttpSession->lpAppInfo->lpszProxy[0])
3379         {
3380             WCHAR *url = HTTP_BuildProxyRequestUrl(lpwhr);
3381             requestString = HTTP_BuildHeaderRequestString(lpwhr, lpwhr->lpszVerb, url, lpwhr->lpszVersion);
3382             HeapFree(GetProcessHeap(), 0, url);
3383         }
3384         else
3385             requestString = HTTP_BuildHeaderRequestString(lpwhr, lpwhr->lpszVerb, lpwhr->lpszPath, lpwhr->lpszVersion);
3386
3387  
3388         TRACE("Request header -> %s\n", debugstr_w(requestString) );
3389
3390         /* Send the request and store the results */
3391         if (!HTTP_OpenConnection(lpwhr))
3392             goto lend;
3393
3394         /* send the request as ASCII, tack on the optional data */
3395         if( !lpOptional )
3396             dwOptionalLength = 0;
3397         len = WideCharToMultiByte( CP_ACP, 0, requestString, -1,
3398                                    NULL, 0, NULL, NULL );
3399         ascii_req = HeapAlloc( GetProcessHeap(), 0, len + dwOptionalLength );
3400         WideCharToMultiByte( CP_ACP, 0, requestString, -1,
3401                              ascii_req, len, NULL, NULL );
3402         if( lpOptional )
3403             memcpy( &ascii_req[len-1], lpOptional, dwOptionalLength );
3404         len = (len + dwOptionalLength - 1);
3405         ascii_req[len] = 0;
3406         TRACE("full request -> %s\n", debugstr_a(ascii_req) );
3407
3408         INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3409                               INTERNET_STATUS_SENDING_REQUEST, NULL, 0);
3410
3411         NETCON_send(&lpwhr->netConnection, ascii_req, len, 0, &cnt);
3412         HeapFree( GetProcessHeap(), 0, ascii_req );
3413
3414         INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3415                               INTERNET_STATUS_REQUEST_SENT,
3416                               &len, sizeof(DWORD));
3417
3418         if (bEndRequest)
3419         {
3420             DWORD dwBufferSize;
3421             DWORD dwStatusCode;
3422             WCHAR encoding[20];
3423             static const WCHAR szChunked[] = {'c','h','u','n','k','e','d',0};
3424
3425             INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3426                                 INTERNET_STATUS_RECEIVING_RESPONSE, NULL, 0);
3427     
3428             if (cnt < 0)
3429                 goto lend;
3430     
3431             responseLen = HTTP_GetResponseHeaders(lpwhr, TRUE);
3432             if (responseLen)
3433                 bSuccess = TRUE;
3434     
3435             INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3436                                 INTERNET_STATUS_RESPONSE_RECEIVED, &responseLen,
3437                                 sizeof(DWORD));
3438
3439             HTTP_ProcessCookies(lpwhr);
3440
3441             dwBufferSize = sizeof(lpwhr->dwContentLength);
3442             if (!HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_FLAG_NUMBER|HTTP_QUERY_CONTENT_LENGTH,
3443                                      &lpwhr->dwContentLength,&dwBufferSize,NULL))
3444                 lpwhr->dwContentLength = -1;
3445
3446             if (lpwhr->dwContentLength == 0)
3447                 HTTP_FinishedReading(lpwhr);
3448
3449             /* Correct the case where both a Content-Length and Transfer-encoding = chunked are set */
3450
3451             dwBufferSize = sizeof(encoding);
3452             if (HTTP_HttpQueryInfoW(lpwhr, HTTP_QUERY_TRANSFER_ENCODING, encoding, &dwBufferSize, NULL) &&
3453                 !strcmpiW(encoding, szChunked))
3454             {
3455                 lpwhr->dwContentLength = -1;
3456             }
3457
3458             dwBufferSize = sizeof(dwStatusCode);
3459             if (!HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_FLAG_NUMBER|HTTP_QUERY_STATUS_CODE,
3460                                      &dwStatusCode,&dwBufferSize,NULL))
3461                 dwStatusCode = 0;
3462
3463             if (!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_AUTO_REDIRECT) && bSuccess)
3464             {
3465                 WCHAR szNewLocation[INTERNET_MAX_URL_LENGTH];
3466                 dwBufferSize=sizeof(szNewLocation);
3467                 if ((dwStatusCode==HTTP_STATUS_REDIRECT || dwStatusCode==HTTP_STATUS_MOVED) &&
3468                     HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_LOCATION,szNewLocation,&dwBufferSize,NULL))
3469                 {
3470                     HTTP_DrainContent(lpwhr);
3471                     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3472                                           INTERNET_STATUS_REDIRECT, szNewLocation,
3473                                           dwBufferSize);
3474                     bSuccess = HTTP_HandleRedirect(lpwhr, szNewLocation);
3475                     if (bSuccess)
3476                     {
3477                         HeapFree(GetProcessHeap(), 0, requestString);
3478                         loop_next = TRUE;
3479                     }
3480                 }
3481             }
3482             if (!(lpwhr->hdr.dwFlags & INTERNET_FLAG_NO_AUTH) && bSuccess)
3483             {
3484                 WCHAR szAuthValue[2048];
3485                 dwBufferSize=2048;
3486                 if (dwStatusCode == HTTP_STATUS_DENIED)
3487                 {
3488                     DWORD dwIndex = 0;
3489                     while (HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_WWW_AUTHENTICATE,szAuthValue,&dwBufferSize,&dwIndex))
3490                     {
3491                         if (HTTP_DoAuthorization(lpwhr, szAuthValue,
3492                                                  &lpwhr->pAuthInfo,
3493                                                  lpwhr->lpHttpSession->lpszUserName,
3494                                                  lpwhr->lpHttpSession->lpszPassword))
3495                         {
3496                             loop_next = TRUE;
3497                             break;
3498                         }
3499                     }
3500                 }
3501                 if (dwStatusCode == HTTP_STATUS_PROXY_AUTH_REQ)
3502                 {
3503                     DWORD dwIndex = 0;
3504                     while (HTTP_HttpQueryInfoW(lpwhr,HTTP_QUERY_PROXY_AUTHENTICATE,szAuthValue,&dwBufferSize,&dwIndex))
3505                     {
3506                         if (HTTP_DoAuthorization(lpwhr, szAuthValue,
3507                                                  &lpwhr->pProxyAuthInfo,
3508                                                  lpwhr->lpHttpSession->lpAppInfo->lpszProxyUsername,
3509                                                  lpwhr->lpHttpSession->lpAppInfo->lpszProxyPassword))
3510                         {
3511                             loop_next = TRUE;
3512                             break;
3513                         }
3514                     }
3515                 }
3516             }
3517         }
3518         else
3519             bSuccess = TRUE;
3520     }
3521     while (loop_next);
3522
3523     /* FIXME: Better check, when we have to create the cache file */
3524     if(bSuccess && (lpwhr->hdr.dwFlags & INTERNET_FLAG_NEED_FILE)) {
3525         WCHAR url[INTERNET_MAX_URL_LENGTH];
3526         WCHAR cacheFileName[MAX_PATH+1];
3527         BOOL b;
3528
3529         b = HTTP_GetRequestURL(lpwhr, url);
3530         if(!b) {
3531             WARN("Could not get URL\n");
3532             goto lend;
3533         }
3534
3535         b = CreateUrlCacheEntryW(url, lpwhr->dwContentLength > 0 ? lpwhr->dwContentLength : 0, NULL, cacheFileName, 0);
3536         if(b) {
3537             lpwhr->lpszCacheFile = WININET_strdupW(cacheFileName);
3538             lpwhr->hCacheFile = CreateFileW(lpwhr->lpszCacheFile, GENERIC_WRITE, FILE_SHARE_READ|FILE_SHARE_WRITE,
3539                       NULL, CREATE_ALWAYS, FILE_ATTRIBUTE_NORMAL, NULL);
3540             if(lpwhr->hCacheFile == INVALID_HANDLE_VALUE) {
3541                 WARN("Could not create file: %u\n", GetLastError());
3542                 lpwhr->hCacheFile = NULL;
3543             }
3544         }else {
3545             WARN("Could not create cache entry: %08x\n", GetLastError());
3546         }
3547     }
3548
3549 lend:
3550
3551     HeapFree(GetProcessHeap(), 0, requestString);
3552
3553     /* TODO: send notification for P3P header */
3554
3555     if(lpwhr->lpHttpSession->lpAppInfo->hdr.dwFlags & INTERNET_FLAG_ASYNC) {
3556         if(bSuccess) {
3557             HTTP_ReceiveRequestData(lpwhr, TRUE);
3558         }else {
3559             iar.dwResult = (DWORD_PTR)lpwhr->hdr.hInternet;
3560             iar.dwError = INTERNET_GetLastError();
3561
3562             INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3563                                   INTERNET_STATUS_REQUEST_COMPLETE, &iar,
3564                                   sizeof(INTERNET_ASYNC_RESULT));
3565         }
3566     }
3567
3568     TRACE("<--\n");
3569     if (bSuccess) INTERNET_SetLastError(ERROR_SUCCESS);
3570     return bSuccess;
3571 }
3572
3573 /***********************************************************************
3574  *           HTTPSESSION_Destroy (internal)
3575  *
3576  * Deallocate session handle
3577  *
3578  */
3579 static void HTTPSESSION_Destroy(WININETHANDLEHEADER *hdr)
3580 {
3581     LPWININETHTTPSESSIONW lpwhs = (LPWININETHTTPSESSIONW) hdr;
3582
3583     TRACE("%p\n", lpwhs);
3584
3585     WININET_Release(&lpwhs->lpAppInfo->hdr);
3586
3587     HeapFree(GetProcessHeap(), 0, lpwhs->lpszHostName);
3588     HeapFree(GetProcessHeap(), 0, lpwhs->lpszServerName);
3589     HeapFree(GetProcessHeap(), 0, lpwhs->lpszPassword);
3590     HeapFree(GetProcessHeap(), 0, lpwhs->lpszUserName);
3591     HeapFree(GetProcessHeap(), 0, lpwhs);
3592 }
3593
3594 static DWORD HTTPSESSION_QueryOption(WININETHANDLEHEADER *hdr, DWORD option, void *buffer, DWORD *size, BOOL unicode)
3595 {
3596     switch(option) {
3597     case INTERNET_OPTION_HANDLE_TYPE:
3598         TRACE("INTERNET_OPTION_HANDLE_TYPE\n");
3599
3600         if (*size < sizeof(ULONG))
3601             return ERROR_INSUFFICIENT_BUFFER;
3602
3603         *size = sizeof(DWORD);
3604         *(DWORD*)buffer = INTERNET_HANDLE_TYPE_CONNECT_HTTP;
3605         return ERROR_SUCCESS;
3606     }
3607
3608     return INET_QueryOption(option, buffer, size, unicode);
3609 }
3610
3611 static DWORD HTTPSESSION_SetOption(WININETHANDLEHEADER *hdr, DWORD option, void *buffer, DWORD size)
3612 {
3613     WININETHTTPSESSIONW *ses = (WININETHTTPSESSIONW*)hdr;
3614
3615     switch(option) {
3616     case INTERNET_OPTION_USERNAME:
3617     {
3618         HeapFree(GetProcessHeap(), 0, ses->lpszUserName);
3619         if (!(ses->lpszUserName = WININET_strdupW(buffer))) return ERROR_OUTOFMEMORY;
3620         return ERROR_SUCCESS;
3621     }
3622     case INTERNET_OPTION_PASSWORD:
3623     {
3624         HeapFree(GetProcessHeap(), 0, ses->lpszPassword);
3625         if (!(ses->lpszPassword = WININET_strdupW(buffer))) return ERROR_OUTOFMEMORY;
3626         return ERROR_SUCCESS;
3627     }
3628     default: break;
3629     }
3630
3631     return ERROR_INTERNET_INVALID_OPTION;
3632 }
3633
3634 static const HANDLEHEADERVtbl HTTPSESSIONVtbl = {
3635     HTTPSESSION_Destroy,
3636     NULL,
3637     HTTPSESSION_QueryOption,
3638     HTTPSESSION_SetOption,
3639     NULL,
3640     NULL,
3641     NULL,
3642     NULL,
3643     NULL
3644 };
3645
3646
3647 /***********************************************************************
3648  *           HTTP_Connect  (internal)
3649  *
3650  * Create http session handle
3651  *
3652  * RETURNS
3653  *   HINTERNET a session handle on success
3654  *   NULL on failure
3655  *
3656  */
3657 HINTERNET HTTP_Connect(LPWININETAPPINFOW hIC, LPCWSTR lpszServerName,
3658         INTERNET_PORT nServerPort, LPCWSTR lpszUserName,
3659         LPCWSTR lpszPassword, DWORD dwFlags, DWORD_PTR dwContext,
3660         DWORD dwInternalFlags)
3661 {
3662     LPWININETHTTPSESSIONW lpwhs = NULL;
3663     HINTERNET handle = NULL;
3664
3665     TRACE("-->\n");
3666
3667     if (!lpszServerName || !lpszServerName[0])
3668     {
3669         INTERNET_SetLastError(ERROR_INVALID_PARAMETER);
3670         goto lerror;
3671     }
3672
3673     assert( hIC->hdr.htype == WH_HINIT );
3674
3675     lpwhs = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sizeof(WININETHTTPSESSIONW));
3676     if (NULL == lpwhs)
3677     {
3678         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
3679         goto lerror;
3680     }
3681
3682    /*
3683     * According to my tests. The name is not resolved until a request is sent
3684     */
3685
3686     lpwhs->hdr.htype = WH_HHTTPSESSION;
3687     lpwhs->hdr.vtbl = &HTTPSESSIONVtbl;
3688     lpwhs->hdr.dwFlags = dwFlags;
3689     lpwhs->hdr.dwContext = dwContext;
3690     lpwhs->hdr.dwInternalFlags = dwInternalFlags | (hIC->hdr.dwInternalFlags & INET_CALLBACKW);
3691     lpwhs->hdr.refs = 1;
3692     lpwhs->hdr.lpfnStatusCB = hIC->hdr.lpfnStatusCB;
3693
3694     WININET_AddRef( &hIC->hdr );
3695     lpwhs->lpAppInfo = hIC;
3696     list_add_head( &hIC->hdr.children, &lpwhs->hdr.entry );
3697
3698     handle = WININET_AllocHandle( &lpwhs->hdr );
3699     if (NULL == handle)
3700     {
3701         ERR("Failed to alloc handle\n");
3702         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
3703         goto lerror;
3704     }
3705
3706     if(hIC->lpszProxy && hIC->dwAccessType == INTERNET_OPEN_TYPE_PROXY) {
3707         if(strchrW(hIC->lpszProxy, ' '))
3708             FIXME("Several proxies not implemented.\n");
3709         if(hIC->lpszProxyBypass)
3710             FIXME("Proxy bypass is ignored.\n");
3711     }
3712     if (lpszServerName && lpszServerName[0])
3713     {
3714         lpwhs->lpszServerName = WININET_strdupW(lpszServerName);
3715         lpwhs->lpszHostName = WININET_strdupW(lpszServerName);
3716     }
3717     if (lpszUserName && lpszUserName[0])
3718         lpwhs->lpszUserName = WININET_strdupW(lpszUserName);
3719     if (lpszPassword && lpszPassword[0])
3720         lpwhs->lpszPassword = WININET_strdupW(lpszPassword);
3721     lpwhs->nServerPort = nServerPort;
3722     lpwhs->nHostPort = nServerPort;
3723
3724     /* Don't send a handle created callback if this handle was created with InternetOpenUrl */
3725     if (!(lpwhs->hdr.dwInternalFlags & INET_OPENURL))
3726     {
3727         INTERNET_SendCallback(&hIC->hdr, dwContext,
3728                               INTERNET_STATUS_HANDLE_CREATED, &handle,
3729                               sizeof(handle));
3730     }
3731
3732 lerror:
3733     if( lpwhs )
3734         WININET_Release( &lpwhs->hdr );
3735
3736 /*
3737  * an INTERNET_STATUS_REQUEST_COMPLETE is NOT sent here as per my tests on
3738  * windows
3739  */
3740
3741     TRACE("%p --> %p (%p)\n", hIC, handle, lpwhs);
3742     return handle;
3743 }
3744
3745
3746 /***********************************************************************
3747  *           HTTP_OpenConnection (internal)
3748  *
3749  * Connect to a web server
3750  *
3751  * RETURNS
3752  *
3753  *   TRUE  on success
3754  *   FALSE on failure
3755  */
3756 static BOOL HTTP_OpenConnection(LPWININETHTTPREQW lpwhr)
3757 {
3758     BOOL bSuccess = FALSE;
3759     LPWININETHTTPSESSIONW lpwhs;
3760     LPWININETAPPINFOW hIC = NULL;
3761     char szaddr[32];
3762
3763     TRACE("-->\n");
3764
3765
3766     if (NULL == lpwhr ||  lpwhr->hdr.htype != WH_HHTTPREQ)
3767     {
3768         INTERNET_SetLastError(ERROR_INVALID_PARAMETER);
3769         goto lend;
3770     }
3771
3772     if (NETCON_connected(&lpwhr->netConnection))
3773     {
3774         bSuccess = TRUE;
3775         goto lend;
3776     }
3777     if (!HTTP_ResolveName(lpwhr)) goto lend;
3778
3779     lpwhs = lpwhr->lpHttpSession;
3780
3781     hIC = lpwhs->lpAppInfo;
3782     inet_ntop(lpwhs->socketAddress.sin_family, &lpwhs->socketAddress.sin_addr,
3783               szaddr, sizeof(szaddr));
3784     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3785                           INTERNET_STATUS_CONNECTING_TO_SERVER,
3786                           szaddr,
3787                           strlen(szaddr)+1);
3788
3789     if (!NETCON_create(&lpwhr->netConnection, lpwhs->socketAddress.sin_family,
3790                          SOCK_STREAM, 0))
3791     {
3792         WARN("Socket creation failed: %u\n", INTERNET_GetLastError());
3793         goto lend;
3794     }
3795
3796     if (!NETCON_connect(&lpwhr->netConnection, (struct sockaddr *)&lpwhs->socketAddress,
3797                       sizeof(lpwhs->socketAddress)))
3798        goto lend;
3799
3800     if (lpwhr->hdr.dwFlags & INTERNET_FLAG_SECURE)
3801     {
3802         /* Note: we differ from Microsoft's WinINet here. they seem to have
3803          * a bug that causes no status callbacks to be sent when starting
3804          * a tunnel to a proxy server using the CONNECT verb. i believe our
3805          * behaviour to be more correct and to not cause any incompatibilities
3806          * because using a secure connection through a proxy server is a rare
3807          * case that would be hard for anyone to depend on */
3808         if (hIC->lpszProxy && !HTTP_SecureProxyConnect(lpwhr))
3809             goto lend;
3810
3811         if (!NETCON_secure_connect(&lpwhr->netConnection, lpwhs->lpszHostName))
3812         {
3813             WARN("Couldn't connect securely to host\n");
3814             goto lend;
3815         }
3816     }
3817
3818     INTERNET_SendCallback(&lpwhr->hdr, lpwhr->hdr.dwContext,
3819                           INTERNET_STATUS_CONNECTED_TO_SERVER,
3820                           szaddr, strlen(szaddr)+1);
3821
3822     bSuccess = TRUE;
3823
3824 lend:
3825     TRACE("%d <--\n", bSuccess);
3826     return bSuccess;
3827 }
3828
3829
3830 /***********************************************************************
3831  *           HTTP_clear_response_headers (internal)
3832  *
3833  * clear out any old response headers
3834  */
3835 static void HTTP_clear_response_headers( LPWININETHTTPREQW lpwhr )
3836 {
3837     DWORD i;
3838
3839     for( i=0; i<lpwhr->nCustHeaders; i++)
3840     {
3841         if( !lpwhr->pCustHeaders[i].lpszField )
3842             continue;
3843         if( !lpwhr->pCustHeaders[i].lpszValue )
3844             continue;
3845         if ( lpwhr->pCustHeaders[i].wFlags & HDR_ISREQUEST )
3846             continue;
3847         HTTP_DeleteCustomHeader( lpwhr, i );
3848         i--;
3849     }
3850 }
3851
3852 /***********************************************************************
3853  *           HTTP_GetResponseHeaders (internal)
3854  *
3855  * Read server response
3856  *
3857  * RETURNS
3858  *
3859  *   TRUE  on success
3860  *   FALSE on error
3861  */
3862 static INT HTTP_GetResponseHeaders(LPWININETHTTPREQW lpwhr, BOOL clear)
3863 {
3864     INT cbreaks = 0;
3865     WCHAR buffer[MAX_REPLY_LEN];
3866     DWORD buflen = MAX_REPLY_LEN;
3867     BOOL bSuccess = FALSE;
3868     INT  rc = 0;
3869     static const WCHAR szHundred[] = {'1','0','0',0};
3870     char bufferA[MAX_REPLY_LEN];
3871     LPWSTR status_code, status_text;
3872     DWORD cchMaxRawHeaders = 1024;
3873     LPWSTR lpszRawHeaders = HeapAlloc(GetProcessHeap(), 0, (cchMaxRawHeaders+1)*sizeof(WCHAR));
3874     DWORD cchRawHeaders = 0;
3875
3876     TRACE("-->\n");
3877
3878     /* clear old response headers (eg. from a redirect response) */
3879     if (clear) HTTP_clear_response_headers( lpwhr );
3880
3881     if (!NETCON_connected(&lpwhr->netConnection))
3882         goto lend;
3883
3884     do {
3885         /*
3886          * HACK peek at the buffer
3887          */
3888         buflen = MAX_REPLY_LEN;
3889         NETCON_recv(&lpwhr->netConnection, buffer, buflen, MSG_PEEK, &rc);
3890
3891         /*
3892          * We should first receive 'HTTP/1.x nnn OK' where nnn is the status code.
3893          */
3894         memset(buffer, 0, MAX_REPLY_LEN);
3895         if (!NETCON_getNextLine(&lpwhr->netConnection, bufferA, &buflen))
3896             goto lend;
3897         MultiByteToWideChar( CP_ACP, 0, bufferA, buflen, buffer, MAX_REPLY_LEN );
3898
3899         /* split the version from the status code */
3900         status_code = strchrW( buffer, ' ' );
3901         if( !status_code )
3902             goto lend;
3903         *status_code++=0;
3904
3905         /* split the status code from the status text */
3906         status_text = strchrW( status_code, ' ' );
3907         if( !status_text )
3908             goto lend;
3909         *status_text++=0;
3910
3911         TRACE("version [%s] status code [%s] status text [%s]\n",
3912            debugstr_w(buffer), debugstr_w(status_code), debugstr_w(status_text) );
3913
3914     } while (!strcmpW(status_code, szHundred)); /* ignore "100 Continue" responses */
3915
3916     /* Add status code */
3917     HTTP_ProcessHeader(lpwhr, szStatus, status_code,
3918             HTTP_ADDHDR_FLAG_REPLACE);
3919
3920     HeapFree(GetProcessHeap(),0,lpwhr->lpszVersion);
3921     HeapFree(GetProcessHeap(),0,lpwhr->lpszStatusText);
3922
3923     lpwhr->lpszVersion= WININET_strdupW(buffer);
3924     lpwhr->lpszStatusText = WININET_strdupW(status_text);
3925
3926     /* Restore the spaces */
3927     *(status_code-1) = ' ';
3928     *(status_text-1) = ' ';
3929
3930     /* regenerate raw headers */
3931     while (cchRawHeaders + buflen + strlenW(szCrLf) > cchMaxRawHeaders)
3932     {
3933         cchMaxRawHeaders *= 2;
3934         lpszRawHeaders = HeapReAlloc(GetProcessHeap(), 0, lpszRawHeaders, (cchMaxRawHeaders+1)*sizeof(WCHAR));
3935     }
3936     memcpy(lpszRawHeaders+cchRawHeaders, buffer, (buflen-1)*sizeof(WCHAR));
3937     cchRawHeaders += (buflen-1);
3938     memcpy(lpszRawHeaders+cchRawHeaders, szCrLf, sizeof(szCrLf));
3939     cchRawHeaders += sizeof(szCrLf)/sizeof(szCrLf[0])-1;
3940     lpszRawHeaders[cchRawHeaders] = '\0';
3941
3942     /* Parse each response line */
3943     do
3944     {
3945         buflen = MAX_REPLY_LEN;
3946         if (NETCON_getNextLine(&lpwhr->netConnection, bufferA, &buflen))
3947         {
3948             LPWSTR * pFieldAndValue;
3949
3950             TRACE("got line %s, now interpreting\n", debugstr_a(bufferA));
3951             MultiByteToWideChar( CP_ACP, 0, bufferA, buflen, buffer, MAX_REPLY_LEN );
3952
3953             while (cchRawHeaders + buflen + strlenW(szCrLf) > cchMaxRawHeaders)
3954             {
3955                 cchMaxRawHeaders *= 2;
3956                 lpszRawHeaders = HeapReAlloc(GetProcessHeap(), 0, lpszRawHeaders, (cchMaxRawHeaders+1)*sizeof(WCHAR));
3957             }
3958             memcpy(lpszRawHeaders+cchRawHeaders, buffer, (buflen-1)*sizeof(WCHAR));
3959             cchRawHeaders += (buflen-1);
3960             memcpy(lpszRawHeaders+cchRawHeaders, szCrLf, sizeof(szCrLf));
3961             cchRawHeaders += sizeof(szCrLf)/sizeof(szCrLf[0])-1;
3962             lpszRawHeaders[cchRawHeaders] = '\0';
3963
3964             pFieldAndValue = HTTP_InterpretHttpHeader(buffer);
3965             if (!pFieldAndValue)
3966                 break;
3967
3968             HTTP_ProcessHeader(lpwhr, pFieldAndValue[0], pFieldAndValue[1], 
3969                 HTTP_ADDREQ_FLAG_ADD );
3970
3971             HTTP_FreeTokens(pFieldAndValue);
3972         }
3973         else
3974         {
3975             cbreaks++;
3976             if (cbreaks >= 2)
3977                break;
3978         }
3979     }while(1);
3980
3981     HeapFree(GetProcessHeap(), 0, lpwhr->lpszRawHeaders);
3982     lpwhr->lpszRawHeaders = lpszRawHeaders;
3983     TRACE("raw headers: %s\n", debugstr_w(lpszRawHeaders));
3984     bSuccess = TRUE;
3985
3986 lend:
3987
3988     TRACE("<--\n");
3989     if (bSuccess)
3990         return rc;
3991     else
3992     {
3993         HeapFree(GetProcessHeap(), 0, lpszRawHeaders);
3994         return 0;
3995     }
3996 }
3997
3998
3999 static void strip_spaces(LPWSTR start)
4000 {
4001     LPWSTR str = start;
4002     LPWSTR end;
4003
4004     while (*str == ' ' && *str != '\0')
4005         str++;
4006
4007     if (str != start)
4008         memmove(start, str, sizeof(WCHAR) * (strlenW(str) + 1));
4009
4010     end = start + strlenW(start) - 1;
4011     while (end >= start && *end == ' ')
4012     {
4013         *end = '\0';
4014         end--;
4015     }
4016 }
4017
4018
4019 /***********************************************************************
4020  *           HTTP_InterpretHttpHeader (internal)
4021  *
4022  * Parse server response
4023  *
4024  * RETURNS
4025  *
4026  *   Pointer to array of field, value, NULL on success.
4027  *   NULL on error.
4028  */
4029 static LPWSTR * HTTP_InterpretHttpHeader(LPCWSTR buffer)
4030 {
4031     LPWSTR * pTokenPair;
4032     LPWSTR pszColon;
4033     INT len;
4034
4035     pTokenPair = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sizeof(*pTokenPair)*3);
4036
4037     pszColon = strchrW(buffer, ':');
4038     /* must have two tokens */
4039     if (!pszColon)
4040     {
4041         HTTP_FreeTokens(pTokenPair);
4042         if (buffer[0])
4043             TRACE("No ':' in line: %s\n", debugstr_w(buffer));
4044         return NULL;
4045     }
4046
4047     pTokenPair[0] = HeapAlloc(GetProcessHeap(), 0, (pszColon - buffer + 1) * sizeof(WCHAR));
4048     if (!pTokenPair[0])
4049     {
4050         HTTP_FreeTokens(pTokenPair);
4051         return NULL;
4052     }
4053     memcpy(pTokenPair[0], buffer, (pszColon - buffer) * sizeof(WCHAR));
4054     pTokenPair[0][pszColon - buffer] = '\0';
4055
4056     /* skip colon */
4057     pszColon++;
4058     len = strlenW(pszColon);
4059     pTokenPair[1] = HeapAlloc(GetProcessHeap(), 0, (len + 1) * sizeof(WCHAR));
4060     if (!pTokenPair[1])
4061     {
4062         HTTP_FreeTokens(pTokenPair);
4063         return NULL;
4064     }
4065     memcpy(pTokenPair[1], pszColon, (len + 1) * sizeof(WCHAR));
4066
4067     strip_spaces(pTokenPair[0]);
4068     strip_spaces(pTokenPair[1]);
4069
4070     TRACE("field(%s) Value(%s)\n", debugstr_w(pTokenPair[0]), debugstr_w(pTokenPair[1]));
4071     return pTokenPair;
4072 }
4073
4074 /***********************************************************************
4075  *           HTTP_ProcessHeader (internal)
4076  *
4077  * Stuff header into header tables according to <dwModifier>
4078  *
4079  */
4080
4081 #define COALESCEFLAGS (HTTP_ADDHDR_FLAG_COALESCE|HTTP_ADDHDR_FLAG_COALESCE_WITH_COMMA|HTTP_ADDHDR_FLAG_COALESCE_WITH_SEMICOLON)
4082
4083 static BOOL HTTP_ProcessHeader(LPWININETHTTPREQW lpwhr, LPCWSTR field, LPCWSTR value, DWORD dwModifier)
4084 {
4085     LPHTTPHEADERW lphttpHdr = NULL;
4086     BOOL bSuccess = FALSE;
4087     INT index = -1;
4088     BOOL request_only = dwModifier & HTTP_ADDHDR_FLAG_REQ;
4089
4090     TRACE("--> %s: %s - 0x%08x\n", debugstr_w(field), debugstr_w(value), dwModifier);
4091
4092     /* REPLACE wins out over ADD */
4093     if (dwModifier & HTTP_ADDHDR_FLAG_REPLACE)
4094         dwModifier &= ~HTTP_ADDHDR_FLAG_ADD;
4095     
4096     if (dwModifier & HTTP_ADDHDR_FLAG_ADD)
4097         index = -1;
4098     else
4099         index = HTTP_GetCustomHeaderIndex(lpwhr, field, 0, request_only);
4100
4101     if (index >= 0)
4102     {
4103         if (dwModifier & HTTP_ADDHDR_FLAG_ADD_IF_NEW)
4104         {
4105             return FALSE;
4106         }
4107         lphttpHdr = &lpwhr->pCustHeaders[index];
4108     }
4109     else if (value)
4110     {
4111         HTTPHEADERW hdr;
4112
4113         hdr.lpszField = (LPWSTR)field;
4114         hdr.lpszValue = (LPWSTR)value;
4115         hdr.wFlags = hdr.wCount = 0;
4116
4117         if (dwModifier & HTTP_ADDHDR_FLAG_REQ)
4118             hdr.wFlags |= HDR_ISREQUEST;
4119
4120         return HTTP_InsertCustomHeader(lpwhr, &hdr);
4121     }
4122     /* no value to delete */
4123     else return TRUE;
4124
4125     if (dwModifier & HTTP_ADDHDR_FLAG_REQ)
4126             lphttpHdr->wFlags |= HDR_ISREQUEST;
4127     else
4128         lphttpHdr->wFlags &= ~HDR_ISREQUEST;
4129
4130     if (dwModifier & HTTP_ADDHDR_FLAG_REPLACE)
4131     {
4132         HTTP_DeleteCustomHeader( lpwhr, index );
4133
4134         if (value)
4135         {
4136             HTTPHEADERW hdr;
4137
4138             hdr.lpszField = (LPWSTR)field;
4139             hdr.lpszValue = (LPWSTR)value;
4140             hdr.wFlags = hdr.wCount = 0;
4141
4142             if (dwModifier & HTTP_ADDHDR_FLAG_REQ)
4143                 hdr.wFlags |= HDR_ISREQUEST;
4144
4145             return HTTP_InsertCustomHeader(lpwhr, &hdr);
4146         }
4147
4148         return TRUE;
4149     }
4150     else if (dwModifier & COALESCEFLAGS)
4151     {
4152         LPWSTR lpsztmp;
4153         WCHAR ch = 0;
4154         INT len = 0;
4155         INT origlen = strlenW(lphttpHdr->lpszValue);
4156         INT valuelen = strlenW(value);
4157
4158         if (dwModifier & HTTP_ADDHDR_FLAG_COALESCE_WITH_COMMA)
4159         {
4160             ch = ',';
4161             lphttpHdr->wFlags |= HDR_COMMADELIMITED;
4162         }
4163         else if (dwModifier & HTTP_ADDHDR_FLAG_COALESCE_WITH_SEMICOLON)
4164         {
4165             ch = ';';
4166             lphttpHdr->wFlags |= HDR_COMMADELIMITED;
4167         }
4168
4169         len = origlen + valuelen + ((ch > 0) ? 2 : 0);
4170
4171         lpsztmp = HeapReAlloc(GetProcessHeap(), 0, lphttpHdr->lpszValue, (len+1)*sizeof(WCHAR));
4172         if (lpsztmp)
4173         {
4174             lphttpHdr->lpszValue = lpsztmp;
4175     /* FIXME: Increment lphttpHdr->wCount. Perhaps lpszValue should be an array */
4176             if (ch > 0)
4177             {
4178                 lphttpHdr->lpszValue[origlen] = ch;
4179                 origlen++;
4180                 lphttpHdr->lpszValue[origlen] = ' ';
4181                 origlen++;
4182             }
4183
4184             memcpy(&lphttpHdr->lpszValue[origlen], value, valuelen*sizeof(WCHAR));
4185             lphttpHdr->lpszValue[len] = '\0';
4186             bSuccess = TRUE;
4187         }
4188         else
4189         {
4190             WARN("HeapReAlloc (%d bytes) failed\n",len+1);
4191             INTERNET_SetLastError(ERROR_OUTOFMEMORY);
4192         }
4193     }
4194     TRACE("<-- %d\n",bSuccess);
4195     return bSuccess;
4196 }
4197
4198
4199 /***********************************************************************
4200  *           HTTP_FinishedReading (internal)
4201  *
4202  * Called when all content from server has been read by client.
4203  *
4204  */
4205 BOOL HTTP_FinishedReading(LPWININETHTTPREQW lpwhr)
4206 {
4207     WCHAR szVersion[10];
4208     WCHAR szConnectionResponse[20];
4209     DWORD dwBufferSize = sizeof(szVersion);
4210     BOOL keepalive = FALSE;
4211
4212     TRACE("\n");
4213
4214     /* as per RFC 2068, S8.1.2.1, if the client is HTTP/1.1 then assume that
4215      * the connection is keep-alive by default */
4216     if (HTTP_HttpQueryInfoW(lpwhr, HTTP_QUERY_VERSION, szVersion,
4217                              &dwBufferSize, NULL) &&
4218         !strcmpiW(szVersion, g_szHttp1_1))
4219     {
4220         keepalive = TRUE;
4221     }
4222
4223     dwBufferSize = sizeof(szConnectionResponse);
4224     if (HTTP_HttpQueryInfoW(lpwhr, HTTP_QUERY_PROXY_CONNECTION, szConnectionResponse, &dwBufferSize, NULL) ||
4225         HTTP_HttpQueryInfoW(lpwhr, HTTP_QUERY_CONNECTION, szConnectionResponse, &dwBufferSize, NULL))
4226     {
4227         keepalive = !strcmpiW(szConnectionResponse, szKeepAlive);
4228     }
4229
4230     if (!keepalive)
4231     {
4232         HTTPREQ_CloseConnection(&lpwhr->hdr);
4233     }
4234
4235     /* FIXME: store data in the URL cache here */
4236
4237     return TRUE;
4238 }
4239
4240
4241 /***********************************************************************
4242  *           HTTP_GetCustomHeaderIndex (internal)
4243  *
4244  * Return index of custom header from header array
4245  *
4246  */
4247 static INT HTTP_GetCustomHeaderIndex(LPWININETHTTPREQW lpwhr, LPCWSTR lpszField,
4248                                      int requested_index, BOOL request_only)
4249 {
4250     DWORD index;
4251
4252     TRACE("%s\n", debugstr_w(lpszField));
4253
4254     for (index = 0; index < lpwhr->nCustHeaders; index++)
4255     {
4256         if (strcmpiW(lpwhr->pCustHeaders[index].lpszField, lpszField))
4257             continue;
4258
4259         if (request_only && !(lpwhr->pCustHeaders[index].wFlags & HDR_ISREQUEST))
4260             continue;
4261
4262         if (!request_only && (lpwhr->pCustHeaders[index].wFlags & HDR_ISREQUEST))
4263             continue;
4264
4265         if (requested_index == 0)
4266             break;
4267         requested_index --;
4268     }
4269
4270     if (index >= lpwhr->nCustHeaders)
4271         index = -1;
4272
4273     TRACE("Return: %d\n", index);
4274     return index;
4275 }
4276
4277
4278 /***********************************************************************
4279  *           HTTP_InsertCustomHeader (internal)
4280  *
4281  * Insert header into array
4282  *
4283  */
4284 static BOOL HTTP_InsertCustomHeader(LPWININETHTTPREQW lpwhr, LPHTTPHEADERW lpHdr)
4285 {
4286     INT count;
4287     LPHTTPHEADERW lph = NULL;
4288     BOOL r = FALSE;
4289
4290     TRACE("--> %s: %s\n", debugstr_w(lpHdr->lpszField), debugstr_w(lpHdr->lpszValue));
4291     count = lpwhr->nCustHeaders + 1;
4292     if (count > 1)
4293         lph = HeapReAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, lpwhr->pCustHeaders, sizeof(HTTPHEADERW) * count);
4294     else
4295         lph = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sizeof(HTTPHEADERW) * count);
4296
4297     if (NULL != lph)
4298     {
4299         lpwhr->pCustHeaders = lph;
4300         lpwhr->pCustHeaders[count-1].lpszField = WININET_strdupW(lpHdr->lpszField);
4301         lpwhr->pCustHeaders[count-1].lpszValue = WININET_strdupW(lpHdr->lpszValue);
4302         lpwhr->pCustHeaders[count-1].wFlags = lpHdr->wFlags;
4303         lpwhr->pCustHeaders[count-1].wCount= lpHdr->wCount;
4304         lpwhr->nCustHeaders++;
4305         r = TRUE;
4306     }
4307     else
4308     {
4309         INTERNET_SetLastError(ERROR_OUTOFMEMORY);
4310     }
4311
4312     return r;
4313 }
4314
4315
4316 /***********************************************************************
4317  *           HTTP_DeleteCustomHeader (internal)
4318  *
4319  * Delete header from array
4320  *  If this function is called, the indexs may change.
4321  */
4322 static BOOL HTTP_DeleteCustomHeader(LPWININETHTTPREQW lpwhr, DWORD index)
4323 {
4324     if( lpwhr->nCustHeaders <= 0 )
4325         return FALSE;
4326     if( index >= lpwhr->nCustHeaders )
4327         return FALSE;
4328     lpwhr->nCustHeaders--;
4329
4330     HeapFree(GetProcessHeap(), 0, lpwhr->pCustHeaders[index].lpszField);
4331     HeapFree(GetProcessHeap(), 0, lpwhr->pCustHeaders[index].lpszValue);
4332
4333     memmove( &lpwhr->pCustHeaders[index], &lpwhr->pCustHeaders[index+1],
4334              (lpwhr->nCustHeaders - index)* sizeof(HTTPHEADERW) );
4335     memset( &lpwhr->pCustHeaders[lpwhr->nCustHeaders], 0, sizeof(HTTPHEADERW) );
4336
4337     return TRUE;
4338 }
4339
4340
4341 /***********************************************************************
4342  *           HTTP_VerifyValidHeader (internal)
4343  *
4344  * Verify the given header is not invalid for the given http request
4345  *
4346  */
4347 static BOOL HTTP_VerifyValidHeader(LPWININETHTTPREQW lpwhr, LPCWSTR field)
4348 {
4349     /* Accept-Encoding is stripped from HTTP/1.0 requests. It is invalid */
4350     if (!strcmpW(lpwhr->lpszVersion, g_szHttp1_0) && !strcmpiW(field, szAccept_Encoding))
4351         return FALSE;
4352
4353     return TRUE;
4354 }
4355
4356 /***********************************************************************
4357  *          IsHostInProxyBypassList (@)
4358  *
4359  * Undocumented
4360  *
4361  */
4362 BOOL WINAPI IsHostInProxyBypassList(DWORD flags, LPCSTR szHost, DWORD length)
4363 {
4364    FIXME("STUB: flags=%d host=%s length=%d\n",flags,szHost,length);
4365    return FALSE;
4366 }