winhttp: Test secure connections. Fix a crash when no response is returned.
[wine] / dlls / winhttp / request.c
1 /*
2  * Copyright 2008 Hans Leidekker for CodeWeavers
3  *
4  * This library is free software; you can redistribute it and/or
5  * modify it under the terms of the GNU Lesser General Public
6  * License as published by the Free Software Foundation; either
7  * version 2.1 of the License, or (at your option) any later version.
8  *
9  * This library is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
12  * Lesser General Public License for more details.
13  *
14  * You should have received a copy of the GNU Lesser General Public
15  * License along with this library; if not, write to the Free Software
16  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
17  */
18
19 #include "config.h"
20 #include "wine/port.h"
21 #include "wine/debug.h"
22
23 #include <stdarg.h>
24 #ifdef HAVE_ARPA_INET_H
25 # include <arpa/inet.h>
26 #endif
27
28 #include "windef.h"
29 #include "winbase.h"
30 #include "winhttp.h"
31
32 #include "winhttp_private.h"
33
34 WINE_DEFAULT_DEBUG_CHANNEL(winhttp);
35
36 static const WCHAR attr_accept[] = {'A','c','c','e','p','t',0};
37 static const WCHAR attr_accept_charset[] = {'A','c','c','e','p','t','-','C','h','a','r','s','e','t', 0};
38 static const WCHAR attr_accept_encoding[] = {'A','c','c','e','p','t','-','E','n','c','o','d','i','n','g',0};
39 static const WCHAR attr_accept_language[] = {'A','c','c','e','p','t','-','L','a','n','g','u','a','g','e',0};
40 static const WCHAR attr_accept_ranges[] = {'A','c','c','e','p','t','-','R','a','n','g','e','s',0};
41 static const WCHAR attr_age[] = {'A','g','e',0};
42 static const WCHAR attr_allow[] = {'A','l','l','o','w',0};
43 static const WCHAR attr_authorization[] = {'A','u','t','h','o','r','i','z','a','t','i','o','n',0};
44 static const WCHAR attr_cache_control[] = {'C','a','c','h','e','-','C','o','n','t','r','o','l',0};
45 static const WCHAR attr_connection[] = {'C','o','n','n','e','c','t','i','o','n',0};
46 static const WCHAR attr_content_base[] = {'C','o','n','t','e','n','t','-','B','a','s','e',0};
47 static const WCHAR attr_content_encoding[] = {'C','o','n','t','e','n','t','-','E','n','c','o','d','i','n','g',0};
48 static const WCHAR attr_content_id[] = {'C','o','n','t','e','n','t','-','I','D',0};
49 static const WCHAR attr_content_language[] = {'C','o','n','t','e','n','t','-','L','a','n','g','u','a','g','e',0};
50 static const WCHAR attr_content_length[] = {'C','o','n','t','e','n','t','-','L','e','n','g','t','h',0};
51 static const WCHAR attr_content_location[] = {'C','o','n','t','e','n','t','-','L','o','c','a','t','i','o','n',0};
52 static const WCHAR attr_content_md5[] = {'C','o','n','t','e','n','t','-','M','D','5',0};
53 static const WCHAR attr_content_range[] = {'C','o','n','t','e','n','t','-','R','a','n','g','e',0};
54 static const WCHAR attr_content_transfer_encoding[] = {'C','o','n','t','e','n','t','-','T','r','a','n','s','f','e','r','-','E','n','c','o','d','i','n','g',0};
55 static const WCHAR attr_content_type[] = {'C','o','n','t','e','n','t','-','T','y','p','e',0};
56 static const WCHAR attr_cookie[] = {'C','o','o','k','i','e',0};
57 static const WCHAR attr_date[] = {'D','a','t','e',0};
58 static const WCHAR attr_from[] = {'F','r','o','m',0};
59 static const WCHAR attr_etag[] = {'E','T','a','g',0};
60 static const WCHAR attr_expect[] = {'E','x','p','e','c','t',0};
61 static const WCHAR attr_expires[] = {'E','x','p','i','r','e','s',0};
62 static const WCHAR attr_host[] = {'H','o','s','t',0};
63 static const WCHAR attr_if_match[] = {'I','f','-','M','a','t','c','h',0};
64 static const WCHAR attr_if_modified_since[] = {'I','f','-','M','o','d','i','f','i','e','d','-','S','i','n','c','e',0};
65 static const WCHAR attr_if_none_match[] = {'I','f','-','N','o','n','e','-','M','a','t','c','h',0};
66 static const WCHAR attr_if_range[] = {'I','f','-','R','a','n','g','e',0};
67 static const WCHAR attr_if_unmodified_since[] = {'I','f','-','U','n','m','o','d','i','f','i','e','d','-','S','i','n','c','e',0};
68 static const WCHAR attr_last_modified[] = {'L','a','s','t','-','M','o','d','i','f','i','e','d',0};
69 static const WCHAR attr_location[] = {'L','o','c','a','t','i','o','n',0};
70 static const WCHAR attr_max_forwards[] = {'M','a','x','-','F','o','r','w','a','r','d','s',0};
71 static const WCHAR attr_mime_version[] = {'M','i','m','e','-','V','e','r','s','i','o','n',0};
72 static const WCHAR attr_pragma[] = {'P','r','a','g','m','a',0};
73 static const WCHAR attr_proxy_authenticate[] = {'P','r','o','x','y','-','A','u','t','h','e','n','t','i','c','a','t','e',0};
74 static const WCHAR attr_proxy_authorization[] = {'P','r','o','x','y','-','A','u','t','h','o','r','i','z','a','t','i','o','n',0};
75 static const WCHAR attr_proxy_connection[] = {'P','r','o','x','y','-','C','o','n','n','e','c','t','i','o','n',0};
76 static const WCHAR attr_public[] = {'P','u','b','l','i','c',0};
77 static const WCHAR attr_range[] = {'R','a','n','g','e',0};
78 static const WCHAR attr_referer[] = {'R','e','f','e','r','e','r',0};
79 static const WCHAR attr_retry_after[] = {'R','e','t','r','y','-','A','f','t','e','r',0};
80 static const WCHAR attr_server[] = {'S','e','r','v','e','r',0};
81 static const WCHAR attr_set_cookie[] = {'S','e','t','-','C','o','o','k','i','e',0};
82 static const WCHAR attr_status[] = {'S','t','a','t','u','s',0};
83 static const WCHAR attr_transfer_encoding[] = {'T','r','a','n','s','f','e','r','-','E','n','c','o','d','i','n','g',0};
84 static const WCHAR attr_unless_modified_since[] = {'U','n','l','e','s','s','-','M','o','d','i','f','i','e','d','-','S','i','n','c','e',0};
85 static const WCHAR attr_upgrade[] = {'U','p','g','r','a','d','e',0};
86 static const WCHAR attr_uri[] = {'U','R','I',0};
87 static const WCHAR attr_user_agent[] = {'U','s','e','r','-','A','g','e','n','t',0};
88 static const WCHAR attr_vary[] = {'V','a','r','y',0};
89 static const WCHAR attr_via[] = {'V','i','a',0};
90 static const WCHAR attr_warning[] = {'W','a','r','n','i','n','g',0};
91 static const WCHAR attr_www_authenticate[] = {'W','W','W','-','A','u','t','h','e','n','t','i','c','a','t','e',0};
92
93 static const WCHAR *attribute_table[] =
94 {
95     attr_mime_version,              /* WINHTTP_QUERY_MIME_VERSION               = 0  */
96     attr_content_type,              /* WINHTTP_QUERY_CONTENT_TYPE               = 1  */
97     attr_content_transfer_encoding, /* WINHTTP_QUERY_CONTENT_TRANSFER_ENCODING  = 2  */
98     attr_content_id,                /* WINHTTP_QUERY_CONTENT_ID                 = 3  */
99     NULL,                           /* WINHTTP_QUERY_CONTENT_DESCRIPTION        = 4  */
100     attr_content_length,            /* WINHTTP_QUERY_CONTENT_LENGTH             = 5  */
101     attr_content_language,          /* WINHTTP_QUERY_CONTENT_LANGUAGE           = 6  */
102     attr_allow,                     /* WINHTTP_QUERY_ALLOW                      = 7  */
103     attr_public,                    /* WINHTTP_QUERY_PUBLIC                     = 8  */
104     attr_date,                      /* WINHTTP_QUERY_DATE                       = 9  */
105     attr_expires,                   /* WINHTTP_QUERY_EXPIRES                    = 10 */
106     attr_last_modified,             /* WINHTTP_QUERY_LAST_MODIFIEDcw            = 11 */
107     NULL,                           /* WINHTTP_QUERY_MESSAGE_ID                 = 12 */
108     attr_uri,                       /* WINHTTP_QUERY_URI                        = 13 */
109     attr_from,                      /* WINHTTP_QUERY_DERIVED_FROM               = 14 */
110     NULL,                           /* WINHTTP_QUERY_COST                       = 15 */
111     NULL,                           /* WINHTTP_QUERY_LINK                       = 16 */
112     attr_pragma,                    /* WINHTTP_QUERY_PRAGMA                     = 17 */
113     NULL,                           /* WINHTTP_QUERY_VERSION                    = 18 */
114     attr_status,                    /* WINHTTP_QUERY_STATUS_CODE                = 19 */
115     NULL,                           /* WINHTTP_QUERY_STATUS_TEXT                = 20 */
116     NULL,                           /* WINHTTP_QUERY_RAW_HEADERS                = 21 */
117     NULL,                           /* WINHTTP_QUERY_RAW_HEADERS_CRLF           = 22 */
118     attr_connection,                /* WINHTTP_QUERY_CONNECTION                 = 23 */
119     attr_accept,                    /* WINHTTP_QUERY_ACCEPT                     = 24 */
120     attr_accept_charset,            /* WINHTTP_QUERY_ACCEPT_CHARSET             = 25 */
121     attr_accept_encoding,           /* WINHTTP_QUERY_ACCEPT_ENCODING            = 26 */
122     attr_accept_language,           /* WINHTTP_QUERY_ACCEPT_LANGUAGE            = 27 */
123     attr_authorization,             /* WINHTTP_QUERY_AUTHORIZATION              = 28 */
124     attr_content_encoding,          /* WINHTTP_QUERY_CONTENT_ENCODING           = 29 */
125     NULL,                           /* WINHTTP_QUERY_FORWARDED                  = 30 */
126     NULL,                           /* WINHTTP_QUERY_FROM                       = 31 */
127     attr_if_modified_since,         /* WINHTTP_QUERY_IF_MODIFIED_SINCE          = 32 */
128     attr_location,                  /* WINHTTP_QUERY_LOCATION                   = 33 */
129     NULL,                           /* WINHTTP_QUERY_ORIG_URI                   = 34 */
130     attr_referer,                   /* WINHTTP_QUERY_REFERER                    = 35 */
131     attr_retry_after,               /* WINHTTP_QUERY_RETRY_AFTER                = 36 */
132     attr_server,                    /* WINHTTP_QUERY_SERVER                     = 37 */
133     NULL,                           /* WINHTTP_TITLE                            = 38 */
134     attr_user_agent,                /* WINHTTP_QUERY_USER_AGENT                 = 39 */
135     attr_www_authenticate,          /* WINHTTP_QUERY_WWW_AUTHENTICATE           = 40 */
136     attr_proxy_authenticate,        /* WINHTTP_QUERY_PROXY_AUTHENTICATE         = 41 */
137     attr_accept_ranges,             /* WINHTTP_QUERY_ACCEPT_RANGES              = 42 */
138     attr_set_cookie,                /* WINHTTP_QUERY_SET_COOKIE                 = 43 */
139     attr_cookie,                    /* WINHTTP_QUERY_COOKIE                     = 44 */
140     NULL,                           /* WINHTTP_QUERY_REQUEST_METHOD             = 45 */
141     NULL,                           /* WINHTTP_QUERY_REFRESH                    = 46 */
142     NULL,                           /* WINHTTP_QUERY_CONTENT_DISPOSITION        = 47 */
143     attr_age,                       /* WINHTTP_QUERY_AGE                        = 48 */
144     attr_cache_control,             /* WINHTTP_QUERY_CACHE_CONTROL              = 49 */
145     attr_content_base,              /* WINHTTP_QUERY_CONTENT_BASE               = 50 */
146     attr_content_location,          /* WINHTTP_QUERY_CONTENT_LOCATION           = 51 */
147     attr_content_md5,               /* WINHTTP_QUERY_CONTENT_MD5                = 52 */
148     attr_content_range,             /* WINHTTP_QUERY_CONTENT_RANGE              = 53 */
149     attr_etag,                      /* WINHTTP_QUERY_ETAG                       = 54 */
150     attr_host,                      /* WINHTTP_QUERY_HOST                       = 55 */
151     attr_if_match,                  /* WINHTTP_QUERY_IF_MATCH                   = 56 */
152     attr_if_none_match,             /* WINHTTP_QUERY_IF_NONE_MATCH              = 57 */
153     attr_if_range,                  /* WINHTTP_QUERY_IF_RANGE                   = 58 */
154     attr_if_unmodified_since,       /* WINHTTP_QUERY_IF_UNMODIFIED_SINCE        = 59 */
155     attr_max_forwards,              /* WINHTTP_QUERY_MAX_FORWARDS               = 60 */
156     attr_proxy_authorization,       /* WINHTTP_QUERY_PROXY_AUTHORIZATION        = 61 */
157     attr_range,                     /* WINHTTP_QUERY_RANGE                      = 62 */
158     attr_transfer_encoding,         /* WINHTTP_QUERY_TRANSFER_ENCODING          = 63 */
159     attr_upgrade,                   /* WINHTTP_QUERY_UPGRADE                    = 64 */
160     attr_vary,                      /* WINHTTP_QUERY_VARY                       = 65 */
161     attr_via,                       /* WINHTTP_QUERY_VIA                        = 66 */
162     attr_warning,                   /* WINHTTP_QUERY_WARNING                    = 67 */
163     attr_expect,                    /* WINHTTP_QUERY_EXPECT                     = 68 */
164     attr_proxy_connection,          /* WINHTTP_QUERY_PROXY_CONNECTION           = 69 */
165     attr_unless_modified_since,     /* WINHTTP_QUERY_UNLESS_MODIFIED_SINCE      = 70 */
166     NULL,                           /* WINHTTP_QUERY_PROXY_SUPPORT              = 75 */
167     NULL,                           /* WINHTTP_QUERY_AUTHENTICATION_INFO        = 76 */
168     NULL,                           /* WINHTTP_QUERY_PASSPORT_URLS              = 77 */
169     NULL                            /* WINHTTP_QUERY_PASSPORT_CONFIG            = 78 */
170 };
171
172 static void free_header( header_t *header )
173 {
174     heap_free( header->field );
175     heap_free( header->value );
176     heap_free( header );
177 }
178
179 static BOOL valid_token_char( WCHAR c )
180 {
181     if (c < 32 || c == 127) return FALSE;
182     switch (c)
183     {
184     case '(': case ')':
185     case '<': case '>':
186     case '@': case ',':
187     case ';': case ':':
188     case '\\': case '\"':
189     case '/': case '[':
190     case ']': case '?':
191     case '=': case '{':
192     case '}': case ' ':
193     case '\t':
194         return FALSE;
195     default:
196         return TRUE;
197     }
198 }
199
200 static header_t *parse_header( LPCWSTR string )
201 {
202     const WCHAR *p, *q;
203     header_t *header;
204     int len;
205
206     p = string;
207     if (!(q = strchrW( p, ':' )))
208     {
209         WARN("no ':' in line %s\n", debugstr_w(string));
210         return NULL;
211     }
212     if (q == string)
213     {
214         WARN("empty field name in line %s\n", debugstr_w(string));
215         return NULL;
216     }
217     while (*p != ':')
218     {
219         if (!valid_token_char( *p ))
220         {
221             WARN("invalid character in field name %s\n", debugstr_w(string));
222             return NULL;
223         }
224         p++;
225     }
226     len = q - string;
227     if (!(header = heap_alloc_zero( sizeof(header_t) ))) return NULL;
228     if (!(header->field = heap_alloc( (len + 1) * sizeof(WCHAR) )))
229     {
230         heap_free( header );
231         return NULL;
232     }
233     memcpy( header->field, string, len * sizeof(WCHAR) );
234     header->field[len] = 0;
235
236     q++; /* skip past colon */
237     while (*q == ' ') q++;
238     if (!*q)
239     {
240         WARN("no value in line %s\n", debugstr_w(string));
241         return header;
242     }
243     len = strlenW( q );
244     if (!(header->value = heap_alloc( (len + 1) * sizeof(WCHAR) )))
245     {
246         free_header( header );
247         return NULL;
248     }
249     memcpy( header->value, q, len * sizeof(WCHAR) );
250     header->value[len] = 0;
251
252     return header;
253 }
254
255 static int get_header_index( request_t *request, LPCWSTR field, int requested_index, BOOL request_only )
256 {
257     int index;
258
259     TRACE("%s\n", debugstr_w(field));
260
261     for (index = 0; index < request->num_headers; index++)
262     {
263         if (strcmpiW( request->headers[index].field, field )) continue;
264         if (request_only && !request->headers[index].is_request) continue;
265         if (!request_only && request->headers[index].is_request) continue;
266
267         if (!requested_index) break;
268         requested_index--;
269     }
270     if (index >= request->num_headers) index = -1;
271     TRACE("returning %d\n", index);
272     return index;
273 }
274
275 static BOOL insert_header( request_t *request, header_t *header )
276 {
277     DWORD count;
278     header_t *hdrs;
279
280     count = request->num_headers + 1;
281     if (count > 1)
282         hdrs = heap_realloc_zero( request->headers, sizeof(header_t) * count );
283     else
284         hdrs = heap_alloc_zero( sizeof(header_t) * count );
285
286     if (hdrs)
287     {
288         request->headers = hdrs;
289         request->headers[count - 1].field = strdupW( header->field );
290         request->headers[count - 1].value = strdupW( header->value );
291         request->headers[count - 1].is_request = header->is_request;
292         request->num_headers++;
293         return TRUE;
294     }
295     return FALSE;
296 }
297
298 static BOOL delete_header( request_t *request, DWORD index )
299 {
300     if (!request->num_headers) return FALSE;
301     if (index >= request->num_headers) return FALSE;
302     request->num_headers--;
303
304     heap_free( request->headers[index].field );
305     heap_free( request->headers[index].value );
306
307     memmove( &request->headers[index], &request->headers[index + 1], (request->num_headers - index) * sizeof(header_t) );
308     memset( &request->headers[request->num_headers], 0, sizeof(header_t) );
309     return TRUE;
310 }
311
312 static BOOL process_header( request_t *request, LPCWSTR field, LPCWSTR value, DWORD flags, BOOL request_only )
313 {
314     int index;
315     header_t *header;
316
317     TRACE("%s: %s 0x%08x\n", debugstr_w(field), debugstr_w(value), flags);
318
319     /* replace wins out over add */
320     if (flags & WINHTTP_ADDREQ_FLAG_REPLACE) flags &= ~WINHTTP_ADDREQ_FLAG_ADD;
321
322     if (flags & WINHTTP_ADDREQ_FLAG_ADD) index = -1;
323     else
324         index = get_header_index( request, field, 0, request_only );
325
326     if (index >= 0)
327     {
328         if (flags & WINHTTP_ADDREQ_FLAG_ADD_IF_NEW) return FALSE;
329         header = &request->headers[index];
330     }
331     else if (value)
332     {
333         header_t hdr;
334
335         hdr.field = (LPWSTR)field;
336         hdr.value = (LPWSTR)value;
337         hdr.is_request = request_only;
338
339         return insert_header( request, &hdr );
340     }
341     /* no value to delete */
342     else return TRUE;
343
344     if (flags & WINHTTP_ADDREQ_FLAG_REPLACE)
345     {
346         delete_header( request, index );
347         if (value)
348         {
349             header_t hdr;
350
351             hdr.field = (LPWSTR)field;
352             hdr.value = (LPWSTR)value;
353             hdr.is_request = request_only;
354
355             return insert_header( request, &hdr );
356         }
357         return TRUE;
358     }
359     else if (flags & (WINHTTP_ADDREQ_FLAG_COALESCE_WITH_COMMA | WINHTTP_ADDREQ_FLAG_COALESCE_WITH_SEMICOLON))
360     {
361         WCHAR sep, *tmp;
362         int len, orig_len, value_len;
363
364         orig_len = strlenW( header->value );
365         value_len = strlenW( value );
366
367         if (flags & WINHTTP_ADDREQ_FLAG_COALESCE_WITH_COMMA) sep = ',';
368         else sep = ';';
369
370         len = orig_len + value_len + 2;
371         if ((tmp = heap_realloc( header->value, (len + 1) * sizeof(WCHAR) )))
372         {
373             header->value = tmp;
374
375             header->value[orig_len] = sep;
376             orig_len++;
377             header->value[orig_len] = ' ';
378             orig_len++;
379
380             memcpy( &header->value[orig_len], value, value_len * sizeof(WCHAR) );
381             header->value[len] = 0;
382             return TRUE;
383         }
384     }
385     return TRUE;
386 }
387
388 static BOOL add_request_headers( request_t *request, LPCWSTR headers, DWORD len, DWORD flags )
389 {
390     BOOL ret = FALSE;
391     WCHAR *buffer, *p, *q;
392     header_t *header;
393
394     if (len == ~0UL) len = strlenW( headers );
395     if (!(buffer = heap_alloc( (len + 1) * sizeof(WCHAR) ))) return FALSE;
396     strcpyW( buffer, headers );
397
398     p = buffer;
399     do
400     {
401         q = p;
402         while (*q)
403         {
404             if (q[0] == '\r' && q[1] == '\n') break;
405             q++;
406         }
407         if (!*p) break;
408         if (*q == '\r')
409         {
410             *q = 0;
411             q += 2; /* jump over \r\n */
412         }
413         if ((header = parse_header( p )))
414         {
415             ret = process_header( request, header->field, header->value, flags, TRUE );
416             free_header( header );
417         }
418         p = q;
419     } while (ret);
420
421     heap_free( buffer );
422     return ret;
423 }
424
425 /***********************************************************************
426  *          WinHttpAddRequestHeaders (winhttp.@)
427  */
428 BOOL WINAPI WinHttpAddRequestHeaders( HINTERNET hrequest, LPCWSTR headers, DWORD len, DWORD flags )
429 {
430     BOOL ret;
431     request_t *request;
432
433     TRACE("%p, %s, 0x%x, 0x%08x\n", hrequest, debugstr_w(headers), len, flags);
434
435     if (!headers)
436     {
437         set_last_error( ERROR_INVALID_PARAMETER );
438         return FALSE;
439     }
440     if (!(request = (request_t *)grab_object( hrequest )))
441     {
442         set_last_error( ERROR_INVALID_HANDLE );
443         return FALSE;
444     }
445     if (request->hdr.type != WINHTTP_HANDLE_TYPE_REQUEST)
446     {
447         release_object( &request->hdr );
448         set_last_error( ERROR_WINHTTP_INCORRECT_HANDLE_TYPE );
449         return FALSE;
450     }
451
452     ret = add_request_headers( request, headers, len, flags );
453
454     release_object( &request->hdr );
455     return ret;
456 }
457
458 static WCHAR *build_request_string( request_t *request, LPCWSTR verb, LPCWSTR path, LPCWSTR version )
459 {
460     static const WCHAR space[]   = {' ',0};
461     static const WCHAR crlf[]    = {'\r','\n',0};
462     static const WCHAR colon[]   = {':',' ',0};
463     static const WCHAR twocrlf[] = {'\r','\n','\r','\n',0};
464
465     WCHAR *ret;
466     const WCHAR **headers, **p;
467     unsigned int len, i = 0, j;
468
469     /* allocate space for an array of all the string pointers to be added */
470     len = request->num_headers * 4 + 7;
471     if (!(headers = heap_alloc( len * sizeof(LPCWSTR) ))) return NULL;
472
473     headers[i++] = verb;
474     headers[i++] = space;
475     headers[i++] = path;
476     headers[i++] = space;
477     headers[i++] = version;
478
479     for (j = 0; j < request->num_headers; j++)
480     {
481         if (request->headers[j].is_request)
482         {
483             headers[i++] = crlf;
484             headers[i++] = request->headers[j].field;
485             headers[i++] = colon;
486             headers[i++] = request->headers[j].value;
487
488             TRACE("adding header %s (%s)\n", debugstr_w(request->headers[j].field),
489                   debugstr_w(request->headers[j].value));
490         }
491     }
492     headers[i++] = twocrlf;
493     headers[i] = NULL;
494
495     len = 0;
496     for (p = headers; *p; p++) len += strlenW( *p );
497     len++;
498
499     if (!(ret = heap_alloc( len * sizeof(WCHAR) )))
500     {
501         heap_free( headers );
502         return NULL;
503     }
504     *ret = 0;
505     for (p = headers; *p; p++) strcatW( ret, *p );
506
507     heap_free( headers );
508     return ret;
509 }
510
511 #define QUERY_MODIFIER_MASK (WINHTTP_QUERY_FLAG_REQUEST_HEADERS | WINHTTP_QUERY_FLAG_SYSTEMTIME | WINHTTP_QUERY_FLAG_NUMBER)
512
513 static BOOL query_headers( request_t *request, DWORD level, LPCWSTR name, LPVOID buffer, LPDWORD buflen, LPDWORD index )
514 {
515     header_t *header = NULL;
516     BOOL request_only, ret = FALSE;
517     int requested_index, header_index = -1;
518     DWORD attr;
519
520     request_only = level & WINHTTP_QUERY_FLAG_REQUEST_HEADERS;
521     requested_index = index ? *index : 0;
522
523     attr = level & ~QUERY_MODIFIER_MASK;
524     switch (attr)
525     {
526     case WINHTTP_QUERY_CUSTOM:
527     {
528         header_index = get_header_index( request, name, requested_index, request_only );
529         break;
530     }
531     case WINHTTP_QUERY_RAW_HEADERS_CRLF:
532     {
533         WCHAR *headers;
534         DWORD len;
535
536         if (request_only)
537             headers = build_request_string( request, request->verb, request->path, request->version );
538         else
539             headers = request->raw_headers;
540
541         if (!headers) return FALSE;
542         len = strlenW( headers ) * sizeof(WCHAR);
543         if (len + sizeof(WCHAR) > *buflen)
544         {
545             len += sizeof(WCHAR);
546             set_last_error( ERROR_INSUFFICIENT_BUFFER );
547         }
548         else if (buffer)
549         {
550             memcpy( buffer, headers, len + sizeof(WCHAR) );
551             TRACE("returning data: %s\n", debugstr_wn(buffer, len / sizeof(WCHAR)));
552             ret = TRUE;
553         }
554         *buflen = len;
555         if (request_only) heap_free( headers );
556         return ret;
557     }
558     default:
559     {
560         if (attr > sizeof(attribute_table)/sizeof(attribute_table[0]) || !attribute_table[attr])
561         {
562             FIXME("attribute %u not implemented\n", attr);
563             return FALSE;
564         }
565         TRACE("attribute %s\n", debugstr_w(attribute_table[attr]));
566         header_index = get_header_index( request, attribute_table[attr], requested_index, request_only );
567     }
568     }
569
570     if (header_index >= 0)
571     {
572         header = &request->headers[header_index];
573     }
574     if (!header || (request_only && !header->is_request))
575     {
576         set_last_error( ERROR_WINHTTP_HEADER_NOT_FOUND );
577         return FALSE;
578     }
579     if (index) *index += 1;
580     if (level & WINHTTP_QUERY_FLAG_NUMBER)
581     {
582         int *number = buffer;
583         if (sizeof(int) > *buflen)
584         {
585             set_last_error( ERROR_INSUFFICIENT_BUFFER );
586         }
587         else if (number)
588         {
589             *number = atoiW( header->value );
590             TRACE("returning number: %d\n", *number);
591             ret = TRUE;
592         }
593         *buflen = sizeof(int);
594     }
595     else if (level & WINHTTP_QUERY_FLAG_SYSTEMTIME)
596     {
597         SYSTEMTIME *st = buffer;
598         if (sizeof(SYSTEMTIME) > *buflen)
599         {
600             set_last_error( ERROR_INSUFFICIENT_BUFFER );
601         }
602         else if (st && (ret = WinHttpTimeToSystemTime( header->value, st )))
603         {
604             TRACE("returning time: %04d/%02d/%02d - %d - %02d:%02d:%02d.%02d\n",
605                   st->wYear, st->wMonth, st->wDay, st->wDayOfWeek,
606                   st->wHour, st->wMinute, st->wSecond, st->wMilliseconds);
607         }
608         *buflen = sizeof(SYSTEMTIME);
609     }
610     else if (header->value)
611     {
612         WCHAR *string = buffer;
613         DWORD len = (strlenW( header->value ) + 1) * sizeof(WCHAR);
614         if (len > *buflen)
615         {
616             set_last_error( ERROR_INSUFFICIENT_BUFFER );
617             *buflen = len;
618             return FALSE;
619         }
620         else if (string)
621         {
622             strcpyW( string, header->value );
623             TRACE("returning string: %s\n", debugstr_w(string));
624             ret = TRUE;
625         }
626         *buflen = len - sizeof(WCHAR);
627     }
628     return ret;
629 }
630
631 /***********************************************************************
632  *          WinHttpQueryHeaders (winhttp.@)
633  */
634 BOOL WINAPI WinHttpQueryHeaders( HINTERNET hrequest, DWORD level, LPCWSTR name, LPVOID buffer, LPDWORD buflen, LPDWORD index )
635 {
636     BOOL ret;
637     request_t *request;
638
639     TRACE("%p, 0x%08x, %s, %p, %p, %p\n", hrequest, level, debugstr_w(name), buffer, buflen, index);
640
641     if (!(request = (request_t *)grab_object( hrequest )))
642     {
643         set_last_error( ERROR_INVALID_HANDLE );
644         return FALSE;
645     }
646     if (request->hdr.type != WINHTTP_HANDLE_TYPE_REQUEST)
647     {
648         release_object( &request->hdr );
649         set_last_error( ERROR_WINHTTP_INCORRECT_HANDLE_TYPE );
650         return FALSE;
651     }
652
653     ret = query_headers( request, level, name, buffer, buflen, index );
654
655     release_object( &request->hdr );
656     return ret;
657 }
658
659 static BOOL open_connection( request_t *request )
660 {
661     connect_t *connect;
662     char address[32];
663     WCHAR *addressW;
664
665     if (netconn_connected( &request->netconn )) return TRUE;
666
667     connect = request->connect;
668     if (!netconn_resolve( connect->servername, connect->serverport, &connect->sockaddr )) return FALSE;
669
670     inet_ntop( connect->sockaddr.sin_family, &connect->sockaddr.sin_addr, address, sizeof(address) );
671     TRACE("connecting to %s:%u\n", address, ntohs(connect->sockaddr.sin_port));
672     addressW = strdupAW( address );
673
674     send_callback( &request->hdr, WINHTTP_CALLBACK_STATUS_CONNECTING_TO_SERVER, addressW, 0 );
675
676     if (!netconn_create( &request->netconn, connect->sockaddr.sin_family, SOCK_STREAM, 0 ))
677     {
678         heap_free( addressW );
679         return FALSE;
680     }
681     if (!netconn_connect( &request->netconn, (struct sockaddr *)&connect->sockaddr, sizeof(struct sockaddr_in) ))
682     {
683         netconn_close( &request->netconn );
684         heap_free( addressW );
685         return FALSE;
686     }
687     if (request->hdr.flags & WINHTTP_FLAG_SECURE && !netconn_secure_connect( &request->netconn ))
688     {
689         netconn_close( &request->netconn );
690         heap_free( addressW );
691         return FALSE;
692     }
693
694     send_callback( &request->hdr, WINHTTP_CALLBACK_STATUS_CONNECTED_TO_SERVER, addressW, 0 );
695
696     heap_free( addressW );
697     return TRUE;
698 }
699
700 void close_connection( request_t *request )
701 {
702     if (!netconn_connected( &request->netconn )) return;
703
704     send_callback( &request->hdr, WINHTTP_CALLBACK_STATUS_CLOSING_CONNECTION, 0, 0 );
705     netconn_close( &request->netconn );
706     send_callback( &request->hdr, WINHTTP_CALLBACK_STATUS_CONNECTION_CLOSED, 0, 0 );
707 }
708
709 static BOOL send_request( request_t *request, LPCWSTR headers, DWORD headers_len, LPVOID optional,
710                           DWORD optional_len, DWORD total_len, DWORD_PTR context )
711 {
712     static const WCHAR keep_alive[] = {'K','e','e','p','-','A','l','i','v','e',0};
713     static const WCHAR no_cache[]   = {'n','o','-','c','a','c','h','e',0};
714     static const WCHAR length_fmt[] = {'%','l','d',0};
715
716     BOOL ret = FALSE;
717     connect_t *connect = request->connect;
718     session_t *session = connect->session;
719     WCHAR *req = NULL;
720     char *req_ascii;
721     int bytes_sent;
722     DWORD len;
723
724     if (session->agent)
725         process_header( request, attr_user_agent, session->agent, WINHTTP_ADDREQ_FLAG_ADD_IF_NEW, TRUE );
726
727     if (connect->hostname)
728         process_header( request, attr_host, connect->hostname, WINHTTP_ADDREQ_FLAG_ADD_IF_NEW, TRUE );
729
730     if (optional_len)
731     {
732         WCHAR length[21]; /* decimal long int + null */
733         sprintfW( length, length_fmt, optional_len );
734         process_header( request, attr_content_length, length, WINHTTP_ADDREQ_FLAG_ADD_IF_NEW, TRUE );
735     }
736     if (!(request->hdr.flags & WINHTTP_DISABLE_KEEP_ALIVE))
737     {
738         process_header( request, attr_connection, keep_alive, WINHTTP_ADDREQ_FLAG_ADD_IF_NEW, TRUE );
739     }
740     if (request->hdr.flags & WINHTTP_FLAG_REFRESH)
741     {
742         process_header( request, attr_pragma, no_cache, WINHTTP_ADDREQ_FLAG_ADD_IF_NEW, TRUE );
743         process_header( request, attr_cache_control, no_cache, WINHTTP_ADDREQ_FLAG_ADD_IF_NEW, TRUE );
744     }
745     if (headers && !add_request_headers( request, headers, headers_len, WINHTTP_ADDREQ_FLAG_ADD | WINHTTP_ADDREQ_FLAG_REPLACE ))
746     {
747         TRACE("failed to add request headers\n");
748         return FALSE;
749     }
750
751     if (!(ret = open_connection( request ))) goto end;
752     if (!(req = build_request_string( request, request->verb, request->path, request->version ))) goto end;
753
754     if (!(req_ascii = strdupWA( req ))) goto end;
755     TRACE("full request: %s\n", debugstr_a(req_ascii));
756     len = strlen(req_ascii);
757
758     send_callback( &request->hdr, WINHTTP_CALLBACK_STATUS_SENDING_REQUEST, NULL, 0 );
759
760     ret = netconn_send( &request->netconn, req_ascii, len, 0, &bytes_sent );
761     heap_free( req_ascii );
762     if (!ret) goto end;
763
764     if (optional_len && !netconn_send( &request->netconn, optional, optional_len, 0, &bytes_sent )) goto end;
765     len += optional_len;
766
767     send_callback( &request->hdr, WINHTTP_CALLBACK_STATUS_REQUEST_SENT, &len, sizeof(DWORD) );
768
769 end:
770     heap_free( req );
771     return ret;
772 }
773
774 /***********************************************************************
775  *          WinHttpSendRequest (winhttp.@)
776  */
777 BOOL WINAPI WinHttpSendRequest( HINTERNET hrequest, LPCWSTR headers, DWORD headers_len,
778                                 LPVOID optional, DWORD optional_len, DWORD total_len, DWORD_PTR context )
779 {
780     BOOL ret;
781     request_t *request;
782
783     TRACE("%p, %s, 0x%x, %u, %u, %lx\n",
784           hrequest, debugstr_w(headers), headers_len, optional_len, total_len, context);
785
786     if (!(request = (request_t *)grab_object( hrequest )))
787     {
788         set_last_error( ERROR_INVALID_HANDLE );
789         return FALSE;
790     }
791     if (request->hdr.type != WINHTTP_HANDLE_TYPE_REQUEST)
792     {
793         release_object( &request->hdr );
794         set_last_error( ERROR_WINHTTP_INCORRECT_HANDLE_TYPE );
795         return FALSE;
796     }
797
798     ret = send_request( request, headers, headers_len, optional, optional_len, total_len, context );
799
800     release_object( &request->hdr );
801     return ret;
802 }
803
804 static void clear_response_headers( request_t *request )
805 {
806     unsigned int i;
807
808     for (i = 0; i < request->num_headers; i++)
809     {
810         if (!request->headers[i].field) continue;
811         if (!request->headers[i].value) continue;
812         if (request->headers[i].is_request) continue;
813         delete_header( request, i );
814         i--;
815     }
816 }
817
818 #define MAX_REPLY_LEN   1460
819 #define INITIAL_HEADER_BUFFER_SIZE  512
820
821 static BOOL receive_response( request_t *request, BOOL clear )
822 {
823     static const WCHAR crlf[] = {'\r','\n',0};
824
825     char buffer[MAX_REPLY_LEN];
826     DWORD buflen, len, offset, received_len, crlf_len = 2; /* strlenW(crlf) */
827     char *status_code, *status_text;
828     WCHAR *versionW, *status_textW, *raw_headers;
829     WCHAR status_codeW[4]; /* sizeof("nnn") */
830
831     if (!netconn_connected( &request->netconn )) return FALSE;
832
833     /* clear old response headers (eg. from a redirect response) */
834     if (clear) clear_response_headers( request );
835
836     send_callback( &request->hdr, WINHTTP_CALLBACK_STATUS_RECEIVING_RESPONSE, NULL, 0 );
837
838     received_len = 0;
839     do
840     {
841         buflen = MAX_REPLY_LEN;
842         if (!netconn_get_next_line( &request->netconn, buffer, &buflen )) return FALSE;
843         received_len += buflen;
844
845         /* first line should look like 'HTTP/1.x nnn OK' where nnn is the status code */
846         if (!(status_code = strchr( buffer, ' ' ))) return FALSE;
847         status_code++;
848         if (!(status_text = strchr( status_code, ' ' ))) return FALSE;
849         if ((len = status_text - status_code) != sizeof("nnn") - 1) return FALSE;
850         status_text++;
851
852         TRACE("version [%s] status code [%s] status text [%s]\n",
853               debugstr_an(buffer, status_code - buffer - 1),
854               debugstr_an(status_code, len),
855               debugstr_a(status_text));
856
857     } while (!memcmp( status_code, "100", len )); /* ignore "100 Continue" responses */
858
859     /*  we rely on the fact that the protocol is ascii */
860     MultiByteToWideChar( CP_ACP, 0, status_code, len, status_codeW, len );
861     status_codeW[len] = 0;
862     if (!(process_header( request, attr_status, status_codeW, WINHTTP_ADDREQ_FLAG_REPLACE, FALSE ))) return FALSE;
863
864     len = status_code - buffer;
865     if (!(versionW = heap_alloc( len * sizeof(WCHAR) ))) return FALSE;
866     MultiByteToWideChar( CP_ACP, 0, buffer, len - 1, versionW, len -1 );
867     versionW[len - 1] = 0;
868
869     heap_free( request->version );
870     request->version = versionW;
871
872     len = buflen - (status_text - buffer);
873     if (!(status_textW = heap_alloc( len * sizeof(WCHAR) ))) return FALSE;
874     MultiByteToWideChar( CP_ACP, 0, status_text, len, status_textW, len );
875
876     heap_free( request->status_text );
877     request->status_text = status_textW;
878
879     len = max( buflen + crlf_len, INITIAL_HEADER_BUFFER_SIZE );
880     if (!(raw_headers = heap_alloc( len * sizeof(WCHAR) ))) return FALSE;
881     MultiByteToWideChar( CP_ACP, 0, buffer, buflen, raw_headers, buflen );
882     memcpy( raw_headers + buflen - 1, crlf, sizeof(crlf) );
883
884     heap_free( request->raw_headers );
885     request->raw_headers = raw_headers;
886
887     offset = buflen + crlf_len - 1;
888     for (;;)
889     {
890         header_t *header;
891
892         buflen = MAX_REPLY_LEN;
893         if (!netconn_get_next_line( &request->netconn, buffer, &buflen )) goto end;
894         received_len += buflen;
895         if (!*buffer) break;
896
897         while (len - offset < buflen + crlf_len)
898         {
899             WCHAR *tmp;
900             len *= 2;
901             if (!(tmp = heap_realloc( raw_headers, len * sizeof(WCHAR) ))) return FALSE;
902             request->raw_headers = raw_headers = tmp;
903         }
904         MultiByteToWideChar( CP_ACP, 0, buffer, buflen, raw_headers + offset, buflen );
905
906         if (!(header = parse_header( raw_headers + offset ))) break;
907         if (!(process_header( request, header->field, header->value, WINHTTP_ADDREQ_FLAG_ADD, FALSE )))
908         {
909             free_header( header );
910             break;
911         }
912         free_header( header );
913         memcpy( raw_headers + offset + buflen - 1, crlf, sizeof(crlf) );
914         offset += buflen + crlf_len - 1;
915     }
916
917     TRACE("raw headers: %s\n", debugstr_w(raw_headers));
918
919 end:
920     send_callback( &request->hdr, WINHTTP_CALLBACK_STATUS_RESPONSE_RECEIVED, &received_len, sizeof(DWORD) );
921     return TRUE;
922 }
923
924 /***********************************************************************
925  *          WinHttpReceiveResponse (winhttp.@)
926  */
927 BOOL WINAPI WinHttpReceiveResponse( HINTERNET hrequest, LPVOID reserved )
928 {
929     BOOL ret = TRUE;
930     request_t *request;
931     DWORD size, query;
932
933     TRACE("%p, %p\n", hrequest, reserved);
934
935     if (!(request = (request_t *)grab_object( hrequest )))
936     {
937         set_last_error( ERROR_INVALID_HANDLE );
938         return FALSE;
939     }
940     if (request->hdr.type != WINHTTP_HANDLE_TYPE_REQUEST)
941     {
942         release_object( &request->hdr );
943         set_last_error( ERROR_WINHTTP_INCORRECT_HANDLE_TYPE );
944         return FALSE;
945     }
946
947     ret = receive_response( request, TRUE );
948
949     size = sizeof(DWORD);
950     query = WINHTTP_QUERY_CONTENT_LENGTH | WINHTTP_QUERY_FLAG_NUMBER;
951     if (!query_headers( request, query, NULL, &request->content_length, &size, NULL ))
952         request->content_length = ~0UL;
953
954     release_object( &request->hdr );
955     return ret;
956 }
957
958 /***********************************************************************
959  *          WinHttpQueryDataAvailable (winhttp.@)
960  */
961 BOOL WINAPI WinHttpQueryDataAvailable( HINTERNET hrequest, LPDWORD available )
962 {
963     BOOL ret;
964     request_t *request;
965
966     TRACE("%p, %p\n", hrequest, available);
967
968     if (!(request = (request_t *)grab_object( hrequest )))
969     {
970         set_last_error( ERROR_INVALID_HANDLE );
971         return FALSE;
972     }
973     if (request->hdr.type != WINHTTP_HANDLE_TYPE_REQUEST)
974     {
975         release_object( &request->hdr );
976         set_last_error( ERROR_WINHTTP_INCORRECT_HANDLE_TYPE );
977         return FALSE;
978     }
979
980     ret = netconn_query_data_available( &request->netconn, available );
981
982     release_object( &request->hdr );
983     return ret;
984 }
985
986 static BOOL read_data( request_t *request, void *buffer, DWORD size, DWORD *read, BOOL async )
987 {
988     DWORD to_read;
989     int bytes_read;
990
991     to_read = min( size, request->content_length - request->content_read );
992     if (!netconn_recv( &request->netconn, buffer, to_read, async ? 0 : MSG_WAITALL, &bytes_read ))
993     {
994         if (bytes_read != to_read)
995         {
996             ERR("not all data received %d/%d\n", bytes_read, to_read);
997         }
998         /* always return success, even if the network layer returns an error */
999         *read = 0;
1000         return TRUE;
1001     }
1002     request->content_read += bytes_read;
1003     *read = bytes_read;
1004     return TRUE;
1005 }
1006
1007 static DWORD get_chunk_size( const char *buffer )
1008 {
1009     const char *p;
1010     DWORD size = 0;
1011
1012     for (p = buffer; *p; p++)
1013     {
1014         if (*p >= '0' && *p <= '9') size = size * 16 + *p - '0';
1015         else if (*p >= 'a' && *p <= 'f') size = size * 16 + *p - 'a' + 10;
1016         else if (*p >= 'A' && *p <= 'F') size = size * 16 + *p - 'A' + 10;
1017         else if (*p == ';') break;
1018     }
1019     return size;
1020 }
1021
1022 static BOOL read_data_chunked( request_t *request, void *buffer, DWORD size, DWORD *read, BOOL async )
1023 {
1024     char reply[MAX_REPLY_LEN], *p = buffer;
1025     DWORD buflen, to_read, to_write = size;
1026     int bytes_read;
1027
1028     *read = 0;
1029     for (;;)
1030     {
1031         if (*read == size) break;
1032
1033         if (request->content_length == ~0UL) /* new chunk */
1034         {
1035             buflen = sizeof(reply);
1036             if (!netconn_get_next_line( &request->netconn, reply, &buflen )) break;
1037
1038             if (!(request->content_length = get_chunk_size( reply )))
1039             {
1040                 /* zero sized chunk marks end of transfer; read any trailing headers and return */
1041                 receive_response( request, FALSE );
1042                 break;
1043             }
1044         }
1045         to_read = min( to_write, request->content_length - request->content_read );
1046
1047         if (!netconn_recv( &request->netconn, p, to_read, async ? 0 : MSG_WAITALL, &bytes_read ))
1048         {
1049             if (bytes_read != to_read)
1050             {
1051                 ERR("Not all data received %d/%d\n", bytes_read, to_read);
1052             }
1053             /* always return success, even if the network layer returns an error */
1054             *read = 0;
1055             break;
1056         }
1057         if (!bytes_read) break;
1058
1059         request->content_read += bytes_read;
1060         to_write -= bytes_read;
1061         *read += bytes_read;
1062         p += bytes_read;
1063
1064         if (request->content_read == request->content_length) /* chunk complete */
1065         {
1066             request->content_read = 0;
1067             request->content_length = ~0UL;
1068
1069             buflen = sizeof(reply);
1070             if (!netconn_get_next_line( &request->netconn, reply, &buflen ))
1071             {
1072                 ERR("Malformed chunk\n");
1073                 *read = 0;
1074                 break;
1075             }
1076         }
1077     }
1078     return TRUE;
1079 }
1080
1081 /***********************************************************************
1082  *          WinHttpReadData (winhttp.@)
1083  */
1084 BOOL WINAPI WinHttpReadData( HINTERNET hrequest, LPVOID buffer, DWORD to_read, LPDWORD read )
1085 {
1086     static const WCHAR chunked[] = {'c','h','u','n','k','e','d',0};
1087
1088     BOOL ret;
1089     request_t *request;
1090     WCHAR encoding[20];
1091     DWORD buflen = sizeof(encoding);
1092
1093     TRACE("%p, %p, %d, %p\n", hrequest, buffer, to_read, read);
1094
1095     if (!(request = (request_t *)grab_object( hrequest )))
1096     {
1097         set_last_error( ERROR_INVALID_HANDLE );
1098         return FALSE;
1099     }
1100     if (request->hdr.type != WINHTTP_HANDLE_TYPE_REQUEST)
1101     {
1102         release_object( &request->hdr );
1103         set_last_error( ERROR_WINHTTP_INCORRECT_HANDLE_TYPE );
1104         return FALSE;
1105     }
1106
1107     if (query_headers( request, WINHTTP_QUERY_TRANSFER_ENCODING, NULL, encoding, &buflen, NULL ) &&
1108         !strcmpiW( encoding, chunked ))
1109     {
1110         ret = read_data_chunked( request, buffer, to_read, read, request->hdr.flags & WINHTTP_FLAG_ASYNC );
1111     }
1112     else
1113         ret = read_data( request, buffer, to_read, read, request->hdr.flags & WINHTTP_FLAG_ASYNC );
1114
1115     release_object( &request->hdr );
1116     return ret;
1117 }
1118
1119 /***********************************************************************
1120  *          WinHttpWriteData (winhttp.@)
1121  */
1122 BOOL WINAPI WinHttpWriteData( HINTERNET hrequest, LPCVOID buffer, DWORD to_write, LPDWORD written )
1123 {
1124     BOOL ret;
1125     request_t *request;
1126
1127     TRACE("%p, %p, %d, %p\n", hrequest, buffer, to_write, written);
1128
1129     if (!(request = (request_t *)grab_object( hrequest )))
1130     {
1131         set_last_error( ERROR_INVALID_HANDLE );
1132         return FALSE;
1133     }
1134     if (request->hdr.type != WINHTTP_HANDLE_TYPE_REQUEST)
1135     {
1136         release_object( &request->hdr );
1137         set_last_error( ERROR_WINHTTP_INCORRECT_HANDLE_TYPE );
1138         return FALSE;
1139     }
1140
1141     ret = netconn_send( &request->netconn, buffer, to_write, 0, (int *)written );
1142
1143     release_object( &request->hdr );
1144     return ret;
1145 }
1146
1147 #define ARRAYSIZE(array) (sizeof(array) / sizeof((array)[0]))
1148
1149 static DWORD auth_scheme_from_header( WCHAR *header )
1150 {
1151     static const WCHAR basic[]     = {'B','a','s','i','c'};
1152     static const WCHAR ntlm[]      = {'N','T','L','M'};
1153     static const WCHAR passport[]  = {'P','a','s','s','p','o','r','t'};
1154     static const WCHAR digest[]    = {'D','i','g','e','s','t'};
1155     static const WCHAR negotiate[] = {'N','e','g','o','t','i','a','t','e'};
1156
1157     if (!strncmpiW( header, basic, ARRAYSIZE(basic) ) &&
1158         (header[ARRAYSIZE(basic)] == ' ' || !header[ARRAYSIZE(basic)])) return WINHTTP_AUTH_SCHEME_BASIC;
1159
1160     if (!strncmpiW( header, ntlm, ARRAYSIZE(ntlm) ) &&
1161         (header[ARRAYSIZE(ntlm)] == ' ' || !header[ARRAYSIZE(ntlm)])) return WINHTTP_AUTH_SCHEME_NTLM;
1162
1163     if (!strncmpiW( header, passport, ARRAYSIZE(passport) ) &&
1164         (header[ARRAYSIZE(passport)] == ' ' || !header[ARRAYSIZE(passport)])) return WINHTTP_AUTH_SCHEME_PASSPORT;
1165
1166     if (!strncmpiW( header, digest, ARRAYSIZE(digest) ) &&
1167         (header[ARRAYSIZE(digest)] == ' ' || !header[ARRAYSIZE(digest)])) return WINHTTP_AUTH_SCHEME_DIGEST;
1168
1169     if (!strncmpiW( header, negotiate, ARRAYSIZE(negotiate) ) &&
1170         (header[ARRAYSIZE(negotiate)] == ' ' || !header[ARRAYSIZE(negotiate)])) return WINHTTP_AUTH_SCHEME_NEGOTIATE;
1171
1172     return 0;
1173 }
1174
1175 static BOOL query_auth_schemes( request_t *request, DWORD level, LPDWORD supported, LPDWORD first )
1176 {
1177     DWORD index = 0;
1178     BOOL ret = FALSE;
1179
1180     for (;;)
1181     {
1182         WCHAR *buffer;
1183         DWORD size, scheme;
1184
1185         size = 0;
1186         query_headers( request, level, NULL, NULL, &size, &index );
1187         if (GetLastError() != ERROR_INSUFFICIENT_BUFFER) break;
1188
1189         index--;
1190         if (!(buffer = heap_alloc( size ))) return FALSE;
1191         if (!query_headers( request, level, NULL, buffer, &size, &index ))
1192         {
1193             heap_free( buffer );
1194             return FALSE;
1195         }
1196         scheme = auth_scheme_from_header( buffer );
1197         if (index == 1) *first = scheme;
1198         *supported |= scheme;
1199
1200         heap_free( buffer );
1201         ret = TRUE;
1202     }
1203     return ret;
1204 }
1205
1206 /***********************************************************************
1207  *          WinHttpQueryAuthSchemes (winhttp.@)
1208  */
1209 BOOL WINAPI WinHttpQueryAuthSchemes( HINTERNET hrequest, LPDWORD supported, LPDWORD first, LPDWORD target )
1210 {
1211     BOOL ret = FALSE;
1212     request_t *request;
1213
1214     TRACE("%p, %p, %p, %p\n", hrequest, supported, first, target);
1215
1216     if (!(request = (request_t *)grab_object( hrequest )))
1217     {
1218         set_last_error( ERROR_INVALID_HANDLE );
1219         return FALSE;
1220     }
1221     if (request->hdr.type != WINHTTP_HANDLE_TYPE_REQUEST)
1222     {
1223         release_object( &request->hdr );
1224         set_last_error( ERROR_WINHTTP_INCORRECT_HANDLE_TYPE );
1225         return FALSE;
1226     }
1227
1228     if (query_auth_schemes( request, WINHTTP_QUERY_WWW_AUTHENTICATE, supported, first ))
1229     {
1230         *target = WINHTTP_AUTH_TARGET_SERVER;
1231         ret = TRUE;
1232     }
1233     else if (query_auth_schemes( request, WINHTTP_QUERY_PROXY_AUTHENTICATE, supported, first ))
1234     {
1235         *target = WINHTTP_AUTH_TARGET_PROXY;
1236         ret = TRUE;
1237     }
1238
1239     release_object( &request->hdr );
1240     return ret;
1241 }
1242
1243 static UINT encode_base64( const char *bin, unsigned int len, WCHAR *base64 )
1244 {
1245     UINT n = 0, x;
1246     static const char base64enc[] =
1247         "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
1248
1249     while (len > 0)
1250     {
1251         /* first 6 bits, all from bin[0] */
1252         base64[n++] = base64enc[(bin[0] & 0xfc) >> 2];
1253         x = (bin[0] & 3) << 4;
1254
1255         /* next 6 bits, 2 from bin[0] and 4 from bin[1] */
1256         if (len == 1)
1257         {
1258             base64[n++] = base64enc[x];
1259             base64[n++] = '=';
1260             base64[n++] = '=';
1261             break;
1262         }
1263         base64[n++] = base64enc[x | ((bin[1] & 0xf0) >> 4)];
1264         x = (bin[1] & 0x0f) << 2;
1265
1266         /* next 6 bits 4 from bin[1] and 2 from bin[2] */
1267         if (len == 2)
1268         {
1269             base64[n++] = base64enc[x];
1270             base64[n++] = '=';
1271             break;
1272         }
1273         base64[n++] = base64enc[x | ((bin[2] & 0xc0) >> 6)];
1274
1275         /* last 6 bits, all from bin [2] */
1276         base64[n++] = base64enc[bin[2] & 0x3f];
1277         bin += 3;
1278         len -= 3;
1279     }
1280     base64[n] = 0;
1281     return n;
1282 }
1283
1284 static BOOL set_credentials( request_t *request, DWORD target, DWORD scheme, LPCWSTR username, LPCWSTR password )
1285 {
1286     static const WCHAR basic[] = {'B','a','s','i','c',' ',0};
1287
1288     const WCHAR *auth_scheme, *auth_target;
1289     WCHAR *auth_header;
1290     DWORD len, auth_data_len;
1291     char *auth_data;
1292     BOOL ret;
1293
1294     switch (target)
1295     {
1296     case WINHTTP_AUTH_TARGET_SERVER: auth_target = attr_authorization; break;
1297     case WINHTTP_AUTH_TARGET_PROXY:  auth_target = attr_proxy_authorization; break;
1298     default:
1299         WARN("unknown target %x\n", target);
1300         return FALSE;
1301     }
1302     switch (scheme)
1303     {
1304     case WINHTTP_AUTH_SCHEME_BASIC:
1305     {
1306         int userlen = WideCharToMultiByte( CP_UTF8, 0, username, strlenW( username ), NULL, 0, NULL, NULL );
1307         int passlen = WideCharToMultiByte( CP_UTF8, 0, password, strlenW( password ), NULL, 0, NULL, NULL );
1308
1309         TRACE("basic authentication\n");
1310
1311         auth_scheme = basic;
1312         auth_data_len = userlen + 1 + passlen;
1313         if (!(auth_data = heap_alloc( auth_data_len ))) return FALSE;
1314
1315         WideCharToMultiByte( CP_UTF8, 0, username, -1, auth_data, userlen, NULL, NULL );
1316         auth_data[userlen] = ':';
1317         WideCharToMultiByte( CP_UTF8, 0, password, -1, auth_data + userlen + 1, passlen, NULL, NULL );
1318         break;
1319     }
1320     case WINHTTP_AUTH_SCHEME_NTLM:
1321     case WINHTTP_AUTH_SCHEME_PASSPORT:
1322     case WINHTTP_AUTH_SCHEME_DIGEST:
1323     case WINHTTP_AUTH_SCHEME_NEGOTIATE:
1324         FIXME("unimplemented authentication scheme %x\n", scheme);
1325         return FALSE;
1326     default:
1327         WARN("unknown authentication scheme %x\n", scheme);
1328         return FALSE;
1329     }
1330
1331     len = strlenW( auth_scheme ) + ((auth_data_len + 2) * 4) / 3;
1332     if (!(auth_header = heap_alloc( (len + 1) * sizeof(WCHAR) )))
1333     {
1334         heap_free( auth_data );
1335         return FALSE;
1336     }
1337     strcpyW( auth_header, auth_scheme );
1338     encode_base64( auth_data, auth_data_len, auth_header + strlenW( auth_header ) );
1339
1340     ret = process_header( request, auth_target, auth_header, WINHTTP_ADDREQ_FLAG_ADD | WINHTTP_ADDREQ_FLAG_REPLACE, TRUE );
1341
1342     heap_free( auth_data );
1343     heap_free( auth_header );
1344     return ret;
1345 }
1346
1347 /***********************************************************************
1348  *          WinHttpSetCredentials (winhttp.@)
1349  */
1350 BOOL WINAPI WinHttpSetCredentials( HINTERNET hrequest, DWORD target, DWORD scheme, LPCWSTR username,
1351                                    LPCWSTR password, LPVOID params )
1352 {
1353     BOOL ret;
1354     request_t *request;
1355
1356     TRACE("%p, %x, 0x%08x, %s, %p, %p\n", hrequest, target, scheme, debugstr_w(username), password, params);
1357
1358     if (!(request = (request_t *)grab_object( hrequest )))
1359     {
1360         set_last_error( ERROR_INVALID_HANDLE );
1361         return FALSE;
1362     }
1363     if (request->hdr.type != WINHTTP_HANDLE_TYPE_REQUEST)
1364     {
1365         release_object( &request->hdr );
1366         set_last_error( ERROR_WINHTTP_INCORRECT_HANDLE_TYPE );
1367         return FALSE;
1368     }
1369
1370     ret = set_credentials( request, target, scheme, username, password );
1371
1372     release_object( &request->hdr );
1373     return ret;
1374 }