mshtml: Added more events tests.
[wine] / dlls / mshtml / navigate.c
1 /*
2  * Copyright 2006-2010 Jacek Caban for CodeWeavers
3  *
4  * This library is free software; you can redistribute it and/or
5  * modify it under the terms of the GNU Lesser General Public
6  * License as published by the Free Software Foundation; either
7  * version 2.1 of the License, or (at your option) any later version.
8  *
9  * This library is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
12  * Lesser General Public License for more details.
13  *
14  * You should have received a copy of the GNU Lesser General Public
15  * License along with this library; if not, write to the Free Software
16  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
17  */
18
19 #include "config.h"
20
21 #include <stdarg.h>
22 #include <assert.h>
23
24 #define COBJMACROS
25 #define NONAMELESSUNION
26 #define NONAMELESSSTRUCT
27
28 #include "windef.h"
29 #include "winbase.h"
30 #include "winuser.h"
31 #include "winreg.h"
32 #include "ole2.h"
33 #include "hlguids.h"
34 #include "shlguid.h"
35 #include "wininet.h"
36 #include "shlwapi.h"
37 #include "htiface.h"
38 #include "shdeprecated.h"
39
40 #include "wine/debug.h"
41
42 #include "mshtml_private.h"
43 #include "binding.h"
44
45 WINE_DEFAULT_DEBUG_CHANNEL(mshtml);
46
47 #define CONTENT_LENGTH "Content-Length"
48 #define UTF8_STR "utf-8"
49 #define UTF16_STR "utf-16"
50
51 static const WCHAR emptyW[] = {0};
52 static const WCHAR text_htmlW[] = {'t','e','x','t','/','h','t','m','l',0};
53
54 enum {
55     BOM_NONE,
56     BOM_UTF8,
57     BOM_UTF16
58 };
59
60 struct nsProtocolStream {
61     nsIInputStream nsIInputStream_iface;
62
63     LONG ref;
64
65     char buf[1024];
66     DWORD buf_size;
67 };
68
69 struct BSCallbackVtbl {
70     void (*destroy)(BSCallback*);
71     HRESULT (*init_bindinfo)(BSCallback*);
72     HRESULT (*start_binding)(BSCallback*);
73     HRESULT (*stop_binding)(BSCallback*,HRESULT);
74     HRESULT (*read_data)(BSCallback*,IStream*);
75     HRESULT (*on_progress)(BSCallback*,ULONG,LPCWSTR);
76     HRESULT (*on_response)(BSCallback*,DWORD,LPCWSTR);
77     HRESULT (*beginning_transaction)(BSCallback*,WCHAR**);
78 };
79
80 static inline nsProtocolStream *impl_from_nsIInputStream(nsIInputStream *iface)
81 {
82     return CONTAINING_RECORD(iface, nsProtocolStream, nsIInputStream_iface);
83 }
84
85 static nsresult NSAPI nsInputStream_QueryInterface(nsIInputStream *iface, nsIIDRef riid,
86         void **result)
87 {
88     nsProtocolStream *This = impl_from_nsIInputStream(iface);
89
90     *result = NULL;
91
92     if(IsEqualGUID(&IID_nsISupports, riid)) {
93         TRACE("(%p)->(IID_nsISupports %p)\n", This, result);
94         *result  = &This->nsIInputStream_iface;
95     }else if(IsEqualGUID(&IID_nsIInputStream, riid)) {
96         TRACE("(%p)->(IID_nsIInputStream %p)\n", This, result);
97         *result  = &This->nsIInputStream_iface;
98     }
99
100     if(*result) {
101         nsIInputStream_AddRef(&This->nsIInputStream_iface);
102         return NS_OK;
103     }
104
105     WARN("unsupported interface %s\n", debugstr_guid(riid));
106     return NS_NOINTERFACE;
107 }
108
109 static nsrefcnt NSAPI nsInputStream_AddRef(nsIInputStream *iface)
110 {
111     nsProtocolStream *This = impl_from_nsIInputStream(iface);
112     LONG ref = InterlockedIncrement(&This->ref);
113
114     TRACE("(%p) ref=%d\n", This, ref);
115
116     return ref;
117 }
118
119
120 static nsrefcnt NSAPI nsInputStream_Release(nsIInputStream *iface)
121 {
122     nsProtocolStream *This = impl_from_nsIInputStream(iface);
123     LONG ref = InterlockedDecrement(&This->ref);
124
125     TRACE("(%p) ref=%d\n", This, ref);
126
127     if(!ref)
128         heap_free(This);
129
130     return ref;
131 }
132
133 static nsresult NSAPI nsInputStream_Close(nsIInputStream *iface)
134 {
135     nsProtocolStream *This = impl_from_nsIInputStream(iface);
136     FIXME("(%p)\n", This);
137     return NS_ERROR_NOT_IMPLEMENTED;
138 }
139
140 static nsresult NSAPI nsInputStream_Available(nsIInputStream *iface, PRUint32 *_retval)
141 {
142     nsProtocolStream *This = impl_from_nsIInputStream(iface);
143     FIXME("(%p)->(%p)\n", This, _retval);
144     return NS_ERROR_NOT_IMPLEMENTED;
145 }
146
147 static nsresult NSAPI nsInputStream_Read(nsIInputStream *iface, char *aBuf, PRUint32 aCount,
148                                          PRUint32 *_retval)
149 {
150     nsProtocolStream *This = impl_from_nsIInputStream(iface);
151     DWORD read = aCount;
152
153     TRACE("(%p)->(%p %d %p)\n", This, aBuf, aCount, _retval);
154
155     if(read > This->buf_size)
156         read = This->buf_size;
157
158     if(read) {
159         memcpy(aBuf, This->buf, read);
160         if(read < This->buf_size)
161             memmove(This->buf, This->buf+read, This->buf_size-read);
162         This->buf_size -= read;
163     }
164
165     *_retval = read;
166     return NS_OK;
167 }
168
169 static nsresult NSAPI nsInputStream_ReadSegments(nsIInputStream *iface,
170         nsresult (WINAPI *aWriter)(nsIInputStream*,void*,const char*,PRUint32,PRUint32,PRUint32*),
171         void *aClousure, PRUint32 aCount, PRUint32 *_retval)
172 {
173     nsProtocolStream *This = impl_from_nsIInputStream(iface);
174     PRUint32 written = 0;
175     nsresult nsres;
176
177     TRACE("(%p)->(%p %p %d %p)\n", This, aWriter, aClousure, aCount, _retval);
178
179     if(!This->buf_size)
180         return S_OK;
181
182     if(aCount > This->buf_size)
183         aCount = This->buf_size;
184
185     nsres = aWriter(&This->nsIInputStream_iface, aClousure, This->buf, 0, aCount, &written);
186     if(NS_FAILED(nsres))
187         TRACE("aWritter failed: %08x\n", nsres);
188     else if(written != This->buf_size)
189         FIXME("written %d != buf_size %d\n", written, This->buf_size);
190
191     This->buf_size -= written; 
192
193     *_retval = written;
194     return nsres;
195 }
196
197 static nsresult NSAPI nsInputStream_IsNonBlocking(nsIInputStream *iface, cpp_bool *_retval)
198 {
199     nsProtocolStream *This = impl_from_nsIInputStream(iface);
200     FIXME("(%p)->(%p)\n", This, _retval);
201     return NS_ERROR_NOT_IMPLEMENTED;
202 }
203
204 static const nsIInputStreamVtbl nsInputStreamVtbl = {
205     nsInputStream_QueryInterface,
206     nsInputStream_AddRef,
207     nsInputStream_Release,
208     nsInputStream_Close,
209     nsInputStream_Available,
210     nsInputStream_Read,
211     nsInputStream_ReadSegments,
212     nsInputStream_IsNonBlocking
213 };
214
215 static nsProtocolStream *create_nsprotocol_stream(void)
216 {
217     nsProtocolStream *ret = heap_alloc(sizeof(nsProtocolStream));
218
219     ret->nsIInputStream_iface.lpVtbl = &nsInputStreamVtbl;
220     ret->ref = 1;
221     ret->buf_size = 0;
222
223     return ret;
224 }
225
226 static inline BSCallback *impl_from_IBindStatusCallback(IBindStatusCallback *iface)
227 {
228     return CONTAINING_RECORD(iface, BSCallback, IBindStatusCallback_iface);
229 }
230
231 static HRESULT WINAPI BindStatusCallback_QueryInterface(IBindStatusCallback *iface,
232         REFIID riid, void **ppv)
233 {
234     BSCallback *This = impl_from_IBindStatusCallback(iface);
235
236     *ppv = NULL;
237     if(IsEqualGUID(&IID_IUnknown, riid)) {
238         TRACE("(%p)->(IID_IUnknown, %p)\n", This, ppv);
239         *ppv = &This->IBindStatusCallback_iface;
240     }else if(IsEqualGUID(&IID_IBindStatusCallback, riid)) {
241         TRACE("(%p)->(IID_IBindStatusCallback, %p)\n", This, ppv);
242         *ppv = &This->IBindStatusCallback_iface;
243     }else if(IsEqualGUID(&IID_IServiceProvider, riid)) {
244         TRACE("(%p)->(IID_IServiceProvider %p)\n", This, ppv);
245         *ppv = &This->IServiceProvider_iface;
246     }else if(IsEqualGUID(&IID_IHttpNegotiate, riid)) {
247         TRACE("(%p)->(IID_IHttpNegotiate %p)\n", This, ppv);
248         *ppv = &This->IHttpNegotiate2_iface;
249     }else if(IsEqualGUID(&IID_IHttpNegotiate2, riid)) {
250         TRACE("(%p)->(IID_IHttpNegotiate2 %p)\n", This, ppv);
251         *ppv = &This->IHttpNegotiate2_iface;
252     }else if(IsEqualGUID(&IID_IInternetBindInfo, riid)) {
253         TRACE("(%p)->(IID_IInternetBindInfo %p)\n", This, ppv);
254         *ppv = &This->IInternetBindInfo_iface;
255     }
256
257     if(*ppv) {
258         IBindStatusCallback_AddRef(&This->IBindStatusCallback_iface);
259         return S_OK;
260     }
261
262     TRACE("Unsupported riid = %s\n", debugstr_guid(riid));
263     return E_NOINTERFACE;
264 }
265
266 static ULONG WINAPI BindStatusCallback_AddRef(IBindStatusCallback *iface)
267 {
268     BSCallback *This = impl_from_IBindStatusCallback(iface);
269     LONG ref = InterlockedIncrement(&This->ref);
270
271     TRACE("(%p) ref = %d\n", This, ref);
272
273     return ref;
274 }
275
276 static ULONG WINAPI BindStatusCallback_Release(IBindStatusCallback *iface)
277 {
278     BSCallback *This = impl_from_IBindStatusCallback(iface);
279     LONG ref = InterlockedDecrement(&This->ref);
280
281     TRACE("(%p) ref = %d\n", This, ref);
282
283     if(!ref) {
284         if(This->post_data)
285             GlobalFree(This->post_data);
286         if(This->mon)
287             IMoniker_Release(This->mon);
288         if(This->binding)
289             IBinding_Release(This->binding);
290         list_remove(&This->entry);
291         list_init(&This->entry);
292         heap_free(This->headers);
293
294         This->vtbl->destroy(This);
295     }
296
297     return ref;
298 }
299
300 static HRESULT WINAPI BindStatusCallback_OnStartBinding(IBindStatusCallback *iface,
301         DWORD dwReserved, IBinding *pbind)
302 {
303     BSCallback *This = impl_from_IBindStatusCallback(iface);
304
305     TRACE("(%p)->(%d %p)\n", This, dwReserved, pbind);
306
307     IBinding_AddRef(pbind);
308     This->binding = pbind;
309
310     if(This->window)
311         list_add_head(&This->window->bindings, &This->entry);
312
313     return This->vtbl->start_binding(This);
314 }
315
316 static HRESULT WINAPI BindStatusCallback_GetPriority(IBindStatusCallback *iface, LONG *pnPriority)
317 {
318     BSCallback *This = impl_from_IBindStatusCallback(iface);
319     FIXME("(%p)->(%p)\n", This, pnPriority);
320     return E_NOTIMPL;
321 }
322
323 static HRESULT WINAPI BindStatusCallback_OnLowResource(IBindStatusCallback *iface, DWORD reserved)
324 {
325     BSCallback *This = impl_from_IBindStatusCallback(iface);
326     FIXME("(%p)->(%d)\n", This, reserved);
327     return E_NOTIMPL;
328 }
329
330 static HRESULT WINAPI BindStatusCallback_OnProgress(IBindStatusCallback *iface, ULONG ulProgress,
331         ULONG ulProgressMax, ULONG ulStatusCode, LPCWSTR szStatusText)
332 {
333     BSCallback *This = impl_from_IBindStatusCallback(iface);
334
335     TRACE("%p)->(%u %u %u %s)\n", This, ulProgress, ulProgressMax, ulStatusCode,
336             debugstr_w(szStatusText));
337
338     return This->vtbl->on_progress(This, ulStatusCode, szStatusText);
339 }
340
341 static HRESULT WINAPI BindStatusCallback_OnStopBinding(IBindStatusCallback *iface,
342         HRESULT hresult, LPCWSTR szError)
343 {
344     BSCallback *This = impl_from_IBindStatusCallback(iface);
345     HRESULT hres;
346
347     TRACE("(%p)->(%08x %s)\n", This, hresult, debugstr_w(szError));
348
349     /* NOTE: IE7 calls GetBindResult here */
350
351     hres = This->vtbl->stop_binding(This, hresult);
352
353     if(This->binding) {
354         IBinding_Release(This->binding);
355         This->binding = NULL;
356     }
357
358     list_remove(&This->entry);
359     list_init(&This->entry);
360     This->window = NULL;
361
362     return hres;
363 }
364
365 static HRESULT WINAPI BindStatusCallback_GetBindInfo(IBindStatusCallback *iface,
366         DWORD *grfBINDF, BINDINFO *pbindinfo)
367 {
368     BSCallback *This = impl_from_IBindStatusCallback(iface);
369     DWORD size;
370
371     TRACE("(%p)->(%p %p)\n", This, grfBINDF, pbindinfo);
372
373     if(!This->bindinfo_ready) {
374         HRESULT hres;
375
376         hres = This->vtbl->init_bindinfo(This);
377         if(FAILED(hres))
378             return hres;
379
380         This->bindinfo_ready = TRUE;
381     }
382
383     *grfBINDF = This->bindf;
384
385     size = pbindinfo->cbSize;
386     memset(pbindinfo, 0, size);
387     pbindinfo->cbSize = size;
388
389     pbindinfo->cbstgmedData = This->post_data_len;
390     pbindinfo->dwCodePage = CP_UTF8;
391     pbindinfo->dwOptions = 0x80000;
392
393     if(This->post_data) {
394         pbindinfo->dwBindVerb = BINDVERB_POST;
395
396         pbindinfo->stgmedData.tymed = TYMED_HGLOBAL;
397         pbindinfo->stgmedData.u.hGlobal = This->post_data;
398         pbindinfo->stgmedData.pUnkForRelease = (IUnknown*)&This->IBindStatusCallback_iface;
399         IBindStatusCallback_AddRef(&This->IBindStatusCallback_iface);
400     }
401
402     return S_OK;
403 }
404
405 static HRESULT WINAPI BindStatusCallback_OnDataAvailable(IBindStatusCallback *iface,
406         DWORD grfBSCF, DWORD dwSize, FORMATETC *pformatetc, STGMEDIUM *pstgmed)
407 {
408     BSCallback *This = impl_from_IBindStatusCallback(iface);
409
410     TRACE("(%p)->(%08x %d %p %p)\n", This, grfBSCF, dwSize, pformatetc, pstgmed);
411
412     return This->vtbl->read_data(This, pstgmed->u.pstm);
413 }
414
415 static HRESULT WINAPI BindStatusCallback_OnObjectAvailable(IBindStatusCallback *iface,
416         REFIID riid, IUnknown *punk)
417 {
418     BSCallback *This = impl_from_IBindStatusCallback(iface);
419     FIXME("(%p)->(%s %p)\n", This, debugstr_guid(riid), punk);
420     return E_NOTIMPL;
421 }
422
423 static const IBindStatusCallbackVtbl BindStatusCallbackVtbl = {
424     BindStatusCallback_QueryInterface,
425     BindStatusCallback_AddRef,
426     BindStatusCallback_Release,
427     BindStatusCallback_OnStartBinding,
428     BindStatusCallback_GetPriority,
429     BindStatusCallback_OnLowResource,
430     BindStatusCallback_OnProgress,
431     BindStatusCallback_OnStopBinding,
432     BindStatusCallback_GetBindInfo,
433     BindStatusCallback_OnDataAvailable,
434     BindStatusCallback_OnObjectAvailable
435 };
436
437 static inline BSCallback *impl_from_IHttpNegotiate2(IHttpNegotiate2 *iface)
438 {
439     return CONTAINING_RECORD(iface, BSCallback, IHttpNegotiate2_iface);
440 }
441
442 static HRESULT WINAPI HttpNegotiate_QueryInterface(IHttpNegotiate2 *iface,
443                                                    REFIID riid, void **ppv)
444 {
445     BSCallback *This = impl_from_IHttpNegotiate2(iface);
446     return IBindStatusCallback_QueryInterface(&This->IBindStatusCallback_iface, riid, ppv);
447 }
448
449 static ULONG WINAPI HttpNegotiate_AddRef(IHttpNegotiate2 *iface)
450 {
451     BSCallback *This = impl_from_IHttpNegotiate2(iface);
452     return IBindStatusCallback_AddRef(&This->IBindStatusCallback_iface);
453 }
454
455 static ULONG WINAPI HttpNegotiate_Release(IHttpNegotiate2 *iface)
456 {
457     BSCallback *This = impl_from_IHttpNegotiate2(iface);
458     return IBindStatusCallback_Release(&This->IBindStatusCallback_iface);
459 }
460
461 static HRESULT WINAPI HttpNegotiate_BeginningTransaction(IHttpNegotiate2 *iface,
462         LPCWSTR szURL, LPCWSTR szHeaders, DWORD dwReserved, LPWSTR *pszAdditionalHeaders)
463 {
464     BSCallback *This = impl_from_IHttpNegotiate2(iface);
465     HRESULT hres;
466
467     TRACE("(%p)->(%s %s %d %p)\n", This, debugstr_w(szURL), debugstr_w(szHeaders),
468           dwReserved, pszAdditionalHeaders);
469
470     *pszAdditionalHeaders = NULL;
471
472     hres = This->vtbl->beginning_transaction(This, pszAdditionalHeaders);
473     if(hres != S_FALSE)
474         return hres;
475
476     if(This->headers) {
477         DWORD size;
478
479         size = (strlenW(This->headers)+1)*sizeof(WCHAR);
480         *pszAdditionalHeaders = CoTaskMemAlloc(size);
481         if(!*pszAdditionalHeaders)
482             return E_OUTOFMEMORY;
483         memcpy(*pszAdditionalHeaders, This->headers, size);
484     }
485
486     return S_OK;
487 }
488
489 static HRESULT WINAPI HttpNegotiate_OnResponse(IHttpNegotiate2 *iface, DWORD dwResponseCode,
490         LPCWSTR szResponseHeaders, LPCWSTR szRequestHeaders, LPWSTR *pszAdditionalRequestHeaders)
491 {
492     BSCallback *This = impl_from_IHttpNegotiate2(iface);
493
494     TRACE("(%p)->(%d %s %s %p)\n", This, dwResponseCode, debugstr_w(szResponseHeaders),
495           debugstr_w(szRequestHeaders), pszAdditionalRequestHeaders);
496
497     return This->vtbl->on_response(This, dwResponseCode, szResponseHeaders);
498 }
499
500 static HRESULT WINAPI HttpNegotiate_GetRootSecurityId(IHttpNegotiate2 *iface,
501         BYTE *pbSecurityId, DWORD *pcbSecurityId, DWORD_PTR dwReserved)
502 {
503     BSCallback *This = impl_from_IHttpNegotiate2(iface);
504     FIXME("(%p)->(%p %p %ld)\n", This, pbSecurityId, pcbSecurityId, dwReserved);
505     return E_NOTIMPL;
506 }
507
508 static const IHttpNegotiate2Vtbl HttpNegotiate2Vtbl = {
509     HttpNegotiate_QueryInterface,
510     HttpNegotiate_AddRef,
511     HttpNegotiate_Release,
512     HttpNegotiate_BeginningTransaction,
513     HttpNegotiate_OnResponse,
514     HttpNegotiate_GetRootSecurityId
515 };
516
517 static inline BSCallback *impl_from_IInternetBindInfo(IInternetBindInfo *iface)
518 {
519     return CONTAINING_RECORD(iface, BSCallback, IInternetBindInfo_iface);
520 }
521
522 static HRESULT WINAPI InternetBindInfo_QueryInterface(IInternetBindInfo *iface,
523                                                       REFIID riid, void **ppv)
524 {
525     BSCallback *This = impl_from_IInternetBindInfo(iface);
526     return IBindStatusCallback_QueryInterface(&This->IBindStatusCallback_iface, riid, ppv);
527 }
528
529 static ULONG WINAPI InternetBindInfo_AddRef(IInternetBindInfo *iface)
530 {
531     BSCallback *This = impl_from_IInternetBindInfo(iface);
532     return IBindStatusCallback_AddRef(&This->IBindStatusCallback_iface);
533 }
534
535 static ULONG WINAPI InternetBindInfo_Release(IInternetBindInfo *iface)
536 {
537     BSCallback *This = impl_from_IInternetBindInfo(iface);
538     return IBindStatusCallback_Release(&This->IBindStatusCallback_iface);
539 }
540
541 static HRESULT WINAPI InternetBindInfo_GetBindInfo(IInternetBindInfo *iface,
542                                                    DWORD *grfBINDF, BINDINFO *pbindinfo)
543 {
544     BSCallback *This = impl_from_IInternetBindInfo(iface);
545     FIXME("(%p)->(%p %p)\n", This, grfBINDF, pbindinfo);
546     return E_NOTIMPL;
547 }
548
549 static HRESULT WINAPI InternetBindInfo_GetBindString(IInternetBindInfo *iface,
550         ULONG ulStringType, LPOLESTR *ppwzStr, ULONG cEl, ULONG *pcElFetched)
551 {
552     BSCallback *This = impl_from_IInternetBindInfo(iface);
553     FIXME("(%p)->(%u %p %u %p)\n", This, ulStringType, ppwzStr, cEl, pcElFetched);
554     return E_NOTIMPL;
555 }
556
557 static const IInternetBindInfoVtbl InternetBindInfoVtbl = {
558     InternetBindInfo_QueryInterface,
559     InternetBindInfo_AddRef,
560     InternetBindInfo_Release,
561     InternetBindInfo_GetBindInfo,
562     InternetBindInfo_GetBindString
563 };
564
565 static inline BSCallback *impl_from_IServiceProvider(IServiceProvider *iface)
566 {
567     return CONTAINING_RECORD(iface, BSCallback, IServiceProvider_iface);
568 }
569
570 static HRESULT WINAPI BSCServiceProvider_QueryInterface(IServiceProvider *iface,
571                                                         REFIID riid, void **ppv)
572 {
573     BSCallback *This = impl_from_IServiceProvider(iface);
574     return IBindStatusCallback_QueryInterface(&This->IBindStatusCallback_iface, riid, ppv);
575 }
576
577 static ULONG WINAPI BSCServiceProvider_AddRef(IServiceProvider *iface)
578 {
579     BSCallback *This = impl_from_IServiceProvider(iface);
580     return IBindStatusCallback_AddRef(&This->IBindStatusCallback_iface);
581 }
582
583 static ULONG WINAPI BSCServiceProvider_Release(IServiceProvider *iface)
584 {
585     BSCallback *This = impl_from_IServiceProvider(iface);
586     return IBindStatusCallback_Release(&This->IBindStatusCallback_iface);
587 }
588
589 static HRESULT WINAPI BSCServiceProvider_QueryService(IServiceProvider *iface,
590         REFGUID guidService, REFIID riid, void **ppv)
591 {
592     BSCallback *This = impl_from_IServiceProvider(iface);
593
594     TRACE("(%p)->(%s %s %p)\n", This, debugstr_guid(guidService), debugstr_guid(riid), ppv);
595
596     if(This->window && IsEqualGUID(guidService, &IID_IWindowForBindingUI))
597         return IServiceProvider_QueryService(&This->window->base.IServiceProvider_iface, guidService, riid, ppv);
598     return E_NOINTERFACE;
599 }
600
601 static const IServiceProviderVtbl ServiceProviderVtbl = {
602     BSCServiceProvider_QueryInterface,
603     BSCServiceProvider_AddRef,
604     BSCServiceProvider_Release,
605     BSCServiceProvider_QueryService
606 };
607
608 static void init_bscallback(BSCallback *This, const BSCallbackVtbl *vtbl, IMoniker *mon, DWORD bindf)
609 {
610     This->IBindStatusCallback_iface.lpVtbl = &BindStatusCallbackVtbl;
611     This->IServiceProvider_iface.lpVtbl = &ServiceProviderVtbl;
612     This->IHttpNegotiate2_iface.lpVtbl = &HttpNegotiate2Vtbl;
613     This->IInternetBindInfo_iface.lpVtbl = &InternetBindInfoVtbl;
614     This->vtbl = vtbl;
615     This->ref = 1;
616     This->bindf = bindf;
617     This->bom = BOM_NONE;
618
619     list_init(&This->entry);
620
621     if(mon)
622         IMoniker_AddRef(mon);
623     This->mon = mon;
624 }
625
626 static HRESULT read_stream(BSCallback *This, IStream *stream, void *buf, DWORD size, DWORD *ret_size)
627 {
628     DWORD read_size = 0, skip=0;
629     BYTE *data = buf;
630     HRESULT hres;
631
632     hres = IStream_Read(stream, buf, size, &read_size);
633
634     if(!This->readed && This->bom == BOM_NONE) {
635         if(read_size >= 2 && data[0] == 0xff && data[1] == 0xfe) {
636             This->bom = BOM_UTF16;
637             skip = 2;
638         }else if(read_size >= 3 && data[0] == 0xef && data[1] == 0xbb && data[2] == 0xbf) {
639             This->bom = BOM_UTF8;
640             skip = 3;
641         }
642         if(skip) {
643             read_size -= skip;
644             if(read_size)
645                 memmove(data, data+skip, read_size);
646         }
647     }
648
649     This->readed += read_size;
650     *ret_size = read_size;
651     return hres;
652 }
653
654 static void parse_content_type(nsChannelBSC *This, const WCHAR *value)
655 {
656     const WCHAR *ptr;
657     size_t len;
658
659     static const WCHAR charsetW[] = {'c','h','a','r','s','e','t','='};
660
661     ptr = strchrW(value, ';');
662     if(!ptr)
663         return;
664
665     ptr++;
666     while(*ptr && isspaceW(*ptr))
667         ptr++;
668
669     len = strlenW(value);
670     if(ptr + sizeof(charsetW)/sizeof(WCHAR) < value+len && !memicmpW(ptr, charsetW, sizeof(charsetW)/sizeof(WCHAR))) {
671         size_t charset_len, lena;
672         nsACString charset_str;
673         const WCHAR *charset;
674         char *charseta;
675
676         ptr += sizeof(charsetW)/sizeof(WCHAR);
677
678         if(*ptr == '\'') {
679             FIXME("Quoted value\n");
680             return;
681         }else {
682             charset = ptr;
683             while(*ptr && *ptr != ',')
684                 ptr++;
685             charset_len = ptr-charset;
686         }
687
688         lena = WideCharToMultiByte(CP_ACP, 0, charset, charset_len, NULL, 0, NULL, NULL);
689         charseta = heap_alloc(lena+1);
690         if(!charseta)
691             return;
692
693         WideCharToMultiByte(CP_ACP, 0, charset, charset_len, charseta, lena, NULL, NULL);
694         charseta[lena] = 0;
695
696         nsACString_InitDepend(&charset_str, charseta);
697         nsIHttpChannel_SetContentCharset(&This->nschannel->nsIHttpChannel_iface, &charset_str);
698         nsACString_Finish(&charset_str);
699         heap_free(charseta);
700     }else {
701         FIXME("unhandled: %s\n", debugstr_wn(ptr, len - (ptr-value)));
702     }
703 }
704
705 static HRESULT parse_headers(const WCHAR *headers, struct list *headers_list)
706 {
707     const WCHAR *header, *header_end, *colon, *value;
708     HRESULT hres;
709
710     header = headers;
711     while(*header) {
712         if(header[0] == '\r' && header[1] == '\n' && !header[2])
713             break;
714         for(colon = header; *colon && *colon != ':' && *colon != '\r'; colon++);
715         if(*colon != ':')
716             return E_FAIL;
717
718         value = colon+1;
719         while(*value == ' ')
720             value++;
721         if(!*value)
722             return E_FAIL;
723
724         for(header_end = value+1; *header_end && *header_end != '\r'; header_end++);
725
726         hres = set_http_header(headers_list, header, colon-header, value, header_end-value);
727         if(FAILED(hres))
728             return hres;
729
730         header = header_end;
731         if(header[0] == '\r' && header[1] == '\n')
732             header += 2;
733     }
734
735     return S_OK;
736 }
737
738 static HRESULT process_response_headers(nsChannelBSC *This, const WCHAR *headers)
739 {
740     http_header_t *iter;
741     HRESULT hres;
742
743     static const WCHAR content_typeW[] = {'c','o','n','t','e','n','t','-','t','y','p','e',0};
744
745     hres = parse_headers(headers, &This->nschannel->response_headers);
746     if(FAILED(hres))
747         return hres;
748
749     LIST_FOR_EACH_ENTRY(iter, &This->nschannel->response_headers, http_header_t, entry) {
750         if(!strcmpiW(iter->header, content_typeW))
751             parse_content_type(This, iter->data);
752     }
753
754     return S_OK;
755 }
756
757 HRESULT start_binding(HTMLInnerWindow *inner_window, BSCallback *bscallback, IBindCtx *bctx)
758 {
759     IStream *str = NULL;
760     HRESULT hres;
761
762     TRACE("(%p %p %p)\n", inner_window, bscallback, bctx);
763
764     bscallback->window = inner_window;
765
766     /* NOTE: IE7 calls IsSystemMoniker here*/
767
768     if(bctx) {
769         RegisterBindStatusCallback(bctx, &bscallback->IBindStatusCallback_iface, NULL, 0);
770         IBindCtx_AddRef(bctx);
771     }else {
772         hres = CreateAsyncBindCtx(0, &bscallback->IBindStatusCallback_iface, NULL, &bctx);
773         if(FAILED(hres)) {
774             WARN("CreateAsyncBindCtx failed: %08x\n", hres);
775             bscallback->vtbl->stop_binding(bscallback, hres);
776             return hres;
777         }
778     }
779
780     hres = IMoniker_BindToStorage(bscallback->mon, bctx, NULL, &IID_IStream, (void**)&str);
781     IBindCtx_Release(bctx);
782     if(FAILED(hres)) {
783         WARN("BindToStorage failed: %08x\n", hres);
784         bscallback->vtbl->stop_binding(bscallback, hres);
785         return hres;
786     }
787
788     if(str)
789         IStream_Release(str);
790
791     IMoniker_Release(bscallback->mon);
792     bscallback->mon = NULL;
793
794     return S_OK;
795 }
796
797 typedef struct {
798     BSCallback bsc;
799
800     DWORD size;
801     char *buf;
802     HRESULT hres;
803 } BufferBSC;
804
805 static inline BufferBSC *BufferBSC_from_BSCallback(BSCallback *iface)
806 {
807     return CONTAINING_RECORD(iface, BufferBSC, bsc);
808 }
809
810 static void BufferBSC_destroy(BSCallback *bsc)
811 {
812     BufferBSC *This = BufferBSC_from_BSCallback(bsc);
813
814     heap_free(This->buf);
815     heap_free(This);
816 }
817
818 static HRESULT BufferBSC_init_bindinfo(BSCallback *bsc)
819 {
820     return S_OK;
821 }
822
823 static HRESULT BufferBSC_start_binding(BSCallback *bsc)
824 {
825     return S_OK;
826 }
827
828 static HRESULT BufferBSC_stop_binding(BSCallback *bsc, HRESULT result)
829 {
830     BufferBSC *This = BufferBSC_from_BSCallback(bsc);
831
832     This->hres = result;
833
834     if(FAILED(result)) {
835         heap_free(This->buf);
836         This->buf = NULL;
837         This->size = 0;
838     }
839
840     return S_OK;
841 }
842
843 static HRESULT BufferBSC_read_data(BSCallback *bsc, IStream *stream)
844 {
845     BufferBSC *This = BufferBSC_from_BSCallback(bsc);
846     DWORD readed;
847     HRESULT hres;
848
849     if(!This->buf) {
850         This->size = 128;
851         This->buf = heap_alloc(This->size);
852     }
853
854     do {
855         if(This->bsc.readed >= This->size) {
856             This->size <<= 1;
857             This->buf = heap_realloc(This->buf, This->size);
858         }
859
860         hres = read_stream(&This->bsc, stream, This->buf+This->bsc.readed, This->size-This->bsc.readed, &readed);
861     }while(hres == S_OK);
862
863     return S_OK;
864 }
865
866 static HRESULT BufferBSC_on_progress(BSCallback *bsc, ULONG status_code, LPCWSTR status_text)
867 {
868     return S_OK;
869 }
870
871 static HRESULT BufferBSC_on_response(BSCallback *bsc, DWORD response_code,
872         LPCWSTR response_headers)
873 {
874     return S_OK;
875 }
876
877 static HRESULT BufferBSC_beginning_transaction(BSCallback *bsc, WCHAR **additional_headers)
878 {
879     return S_FALSE;
880 }
881
882 static const BSCallbackVtbl BufferBSCVtbl = {
883     BufferBSC_destroy,
884     BufferBSC_init_bindinfo,
885     BufferBSC_start_binding,
886     BufferBSC_stop_binding,
887     BufferBSC_read_data,
888     BufferBSC_on_progress,
889     BufferBSC_on_response,
890     BufferBSC_beginning_transaction
891 };
892
893
894 static BufferBSC *create_bufferbsc(IMoniker *mon)
895 {
896     BufferBSC *ret = heap_alloc_zero(sizeof(*ret));
897
898     init_bscallback(&ret->bsc, &BufferBSCVtbl, mon, 0);
899     ret->hres = E_FAIL;
900
901     return ret;
902 }
903
904 HRESULT bind_mon_to_wstr(HTMLInnerWindow *window, IMoniker *mon, WCHAR **ret)
905 {
906     BufferBSC *bsc = create_bufferbsc(mon);
907     int cp = CP_ACP;
908     WCHAR *text;
909     HRESULT hres;
910
911     hres = start_binding(window, &bsc->bsc, NULL);
912     if(SUCCEEDED(hres))
913         hres = bsc->hres;
914     if(FAILED(hres)) {
915         IBindStatusCallback_Release(&bsc->bsc.IBindStatusCallback_iface);
916         return hres;
917     }
918
919     if(!bsc->bsc.readed) {
920         *ret = NULL;
921         return S_OK;
922     }
923
924     switch(bsc->bsc.bom) {
925     case BOM_UTF16:
926         if(bsc->bsc.readed % sizeof(WCHAR)) {
927             FIXME("The buffer is not a valid utf16 string\n");
928             hres = E_FAIL;
929             break;
930         }
931
932         text = heap_alloc(bsc->bsc.readed+sizeof(WCHAR));
933         if(!text) {
934             hres = E_OUTOFMEMORY;
935             break;
936         }
937
938         memcpy(text, bsc->buf, bsc->bsc.readed);
939         text[bsc->bsc.readed/sizeof(WCHAR)] = 0;
940         break;
941
942     case BOM_UTF8:
943         cp = CP_UTF8;
944         /* fallthrough */
945     default: {
946         DWORD len;
947
948         len = MultiByteToWideChar(cp, 0, bsc->buf, bsc->bsc.readed, NULL, 0);
949         text = heap_alloc((len+1)*sizeof(WCHAR));
950         if(!text) {
951             hres = E_OUTOFMEMORY;
952             break;
953         }
954
955         MultiByteToWideChar(CP_ACP, 0, bsc->buf, bsc->bsc.readed, text, len);
956         text[len] = 0;
957     }
958     }
959
960     IBindStatusCallback_Release(&bsc->bsc.IBindStatusCallback_iface);
961     if(FAILED(hres))
962         return hres;
963
964     *ret = text;
965     return S_OK;
966 }
967
968 static HRESULT read_post_data_stream(nsChannelBSC *This, nsChannel *nschannel)
969 {
970     PRUint32 data_len = 0, available = 0;
971     char *data, *post_data;
972     nsresult nsres;
973     HRESULT hres = S_OK;
974
975     if(!nschannel->post_data_stream)
976         return S_OK;
977
978     nsres =  nsIInputStream_Available(nschannel->post_data_stream, &available);
979     if(NS_FAILED(nsres))
980         return E_FAIL;
981
982     post_data = data = GlobalAlloc(0, available);
983     if(!data)
984         return E_OUTOFMEMORY;
985
986     nsres = nsIInputStream_Read(nschannel->post_data_stream, data, available, &data_len);
987     if(NS_FAILED(nsres)) {
988         GlobalFree(data);
989         return E_FAIL;
990     }
991
992     if(nschannel->post_data_contains_headers) {
993         if(data_len >= 2 && data[0] == '\r' && data[1] == '\n') {
994             post_data = data+2;
995             data_len -= 2;
996         }else {
997             WCHAR *headers;
998             DWORD size;
999             char *ptr;
1000
1001             post_data += data_len;
1002             for(ptr = data; ptr+4 < data+data_len; ptr++) {
1003                 if(!memcmp(ptr, "\r\n\r\n", 4)) {
1004                     post_data = ptr+4;
1005                     break;
1006                 }
1007             }
1008
1009             data_len -= post_data-data;
1010
1011             size = MultiByteToWideChar(CP_ACP, 0, data, post_data-data, NULL, 0);
1012             headers = heap_alloc((size+1)*sizeof(WCHAR));
1013             if(headers) {
1014                 MultiByteToWideChar(CP_ACP, 0, data, post_data-data, headers, size);
1015                 headers[size] = 0;
1016                 hres = parse_headers(headers , &nschannel->request_headers);
1017                 if(SUCCEEDED(hres))
1018                     This->bsc.headers = headers;
1019                 else
1020                     heap_free(headers);
1021             }else {
1022                 hres = E_OUTOFMEMORY;
1023             }
1024         }
1025     }
1026
1027     if(FAILED(hres)) {
1028         GlobalFree(data);
1029         return hres;
1030     }
1031
1032     if(!data_len) {
1033         GlobalFree(data);
1034         post_data = NULL;
1035     }else if(post_data != data) {
1036         char *new_data;
1037
1038         new_data = GlobalAlloc(0, data_len);
1039         if(new_data)
1040             memcpy(new_data, post_data, data_len);
1041         GlobalFree(data);
1042         if(!new_data)
1043             return E_OUTOFMEMORY;
1044         post_data = new_data;
1045     }
1046
1047     This->bsc.post_data = post_data;
1048     This->bsc.post_data_len = data_len;
1049     TRACE("post_data = %s\n", debugstr_a(This->bsc.post_data));
1050     return S_OK;
1051 }
1052
1053 static HRESULT on_start_nsrequest(nsChannelBSC *This)
1054 {
1055     nsresult nsres;
1056
1057     /* FIXME: it's needed for http connections from BindToObject. */
1058     if(!This->nschannel->response_status)
1059         This->nschannel->response_status = 200;
1060
1061     nsres = nsIStreamListener_OnStartRequest(This->nslistener,
1062             (nsIRequest*)&This->nschannel->nsIHttpChannel_iface, This->nscontext);
1063     if(NS_FAILED(nsres)) {
1064         FIXME("OnStartRequest failed: %08x\n", nsres);
1065         return E_FAIL;
1066     }
1067
1068     if(This->is_doc_channel) {
1069         update_window_doc(This->bsc.window);
1070         if(This->bsc.window->base.outer_window->readystate != READYSTATE_LOADING)
1071             set_ready_state(This->bsc.window->base.outer_window, READYSTATE_LOADING);
1072     }
1073
1074     return S_OK;
1075 }
1076
1077 static void on_stop_nsrequest(nsChannelBSC *This, HRESULT result)
1078 {
1079     nsresult nsres, request_result;
1080
1081     switch(result) {
1082     case S_OK:
1083         request_result = NS_OK;
1084         break;
1085     case E_ABORT:
1086         request_result = NS_BINDING_ABORTED;
1087         break;
1088     default:
1089         request_result = NS_ERROR_FAILURE;
1090     }
1091
1092     if(This->nslistener) {
1093         nsres = nsIStreamListener_OnStopRequest(This->nslistener,
1094                  (nsIRequest*)&This->nschannel->nsIHttpChannel_iface, This->nscontext,
1095                  request_result);
1096         if(NS_FAILED(nsres))
1097             WARN("OnStopRequest failed: %08x\n", nsres);
1098     }
1099
1100     if(This->nschannel->load_group) {
1101         nsres = nsILoadGroup_RemoveRequest(This->nschannel->load_group,
1102                 (nsIRequest*)&This->nschannel->nsIHttpChannel_iface, NULL, request_result);
1103         if(NS_FAILED(nsres))
1104             ERR("RemoveRequest failed: %08x\n", nsres);
1105     }
1106 }
1107
1108 static HRESULT read_stream_data(nsChannelBSC *This, IStream *stream)
1109 {
1110     DWORD read;
1111     nsresult nsres;
1112     HRESULT hres;
1113
1114     if(!This->nslistener) {
1115         BYTE buf[1024];
1116
1117         do {
1118             hres = read_stream(&This->bsc, stream, buf, sizeof(buf), &read);
1119         }while(hres == S_OK && read);
1120
1121         return S_OK;
1122     }
1123
1124     if(!This->nsstream)
1125         This->nsstream = create_nsprotocol_stream();
1126
1127     do {
1128         BOOL first_read = !This->bsc.readed;
1129
1130         hres = read_stream(&This->bsc, stream, This->nsstream->buf+This->nsstream->buf_size,
1131                 sizeof(This->nsstream->buf)-This->nsstream->buf_size, &read);
1132         if(!read)
1133             break;
1134
1135         This->nsstream->buf_size += read;
1136
1137         if(first_read) {
1138             switch(This->bsc.bom) {
1139             case BOM_UTF8:
1140                 This->nschannel->charset = heap_strdupA(UTF8_STR);
1141                 break;
1142             case BOM_UTF16:
1143                 This->nschannel->charset = heap_strdupA(UTF16_STR);
1144             }
1145
1146             if(!This->nschannel->content_type) {
1147                 WCHAR *mime;
1148
1149                 hres = FindMimeFromData(NULL, NULL, This->nsstream->buf, This->nsstream->buf_size,
1150                         This->is_doc_channel ? text_htmlW : NULL, 0, &mime, 0);
1151                 if(FAILED(hres))
1152                     return hres;
1153
1154                 TRACE("Found MIME %s\n", debugstr_w(mime));
1155
1156                 This->nschannel->content_type = heap_strdupWtoA(mime);
1157                 CoTaskMemFree(mime);
1158                 if(!This->nschannel->content_type)
1159                     return E_OUTOFMEMORY;
1160             }
1161
1162             on_start_nsrequest(This);
1163         }
1164
1165         nsres = nsIStreamListener_OnDataAvailable(This->nslistener,
1166                 (nsIRequest*)&This->nschannel->nsIHttpChannel_iface, This->nscontext,
1167                 &This->nsstream->nsIInputStream_iface, This->bsc.readed-This->nsstream->buf_size,
1168                 This->nsstream->buf_size);
1169         if(NS_FAILED(nsres))
1170             ERR("OnDataAvailable failed: %08x\n", nsres);
1171
1172         if(This->nsstream->buf_size == sizeof(This->nsstream->buf)) {
1173             ERR("buffer is full\n");
1174             break;
1175         }
1176     }while(hres == S_OK);
1177
1178     return S_OK;
1179 }
1180
1181 typedef struct {
1182     nsIAsyncVerifyRedirectCallback nsIAsyncVerifyRedirectCallback_iface;
1183
1184     LONG ref;
1185
1186     nsChannel *nschannel;
1187     nsChannelBSC *bsc;
1188 } nsRedirectCallback;
1189
1190 static nsRedirectCallback *impl_from_nsIAsyncVerifyRedirectCallback(nsIAsyncVerifyRedirectCallback *iface)
1191 {
1192     return CONTAINING_RECORD(iface, nsRedirectCallback, nsIAsyncVerifyRedirectCallback_iface);
1193 }
1194
1195 static nsresult NSAPI nsAsyncVerifyRedirectCallback_QueryInterface(nsIAsyncVerifyRedirectCallback *iface,
1196         nsIIDRef riid, void **result)
1197 {
1198     nsRedirectCallback *This = impl_from_nsIAsyncVerifyRedirectCallback(iface);
1199
1200     if(IsEqualGUID(&IID_nsISupports, riid)) {
1201         TRACE("(%p)->(IID_nsISuports %p)\n", This, result);
1202         *result = &This->nsIAsyncVerifyRedirectCallback_iface;
1203     }else if(IsEqualGUID(&IID_nsIAsyncVerifyRedirectCallback, riid)) {
1204         TRACE("(%p)->(IID_nsIAsyncVerifyRedirectCallback %p)\n", This, result);
1205         *result = &This->nsIAsyncVerifyRedirectCallback_iface;
1206     }else {
1207         *result = NULL;
1208         WARN("unimplemented iface %s\n", debugstr_guid(riid));
1209         return NS_NOINTERFACE;
1210     }
1211
1212     nsISupports_AddRef((nsISupports*)*result);
1213     return NS_OK;
1214 }
1215
1216 static nsrefcnt NSAPI nsAsyncVerifyRedirectCallback_AddRef(nsIAsyncVerifyRedirectCallback *iface)
1217 {
1218     nsRedirectCallback *This = impl_from_nsIAsyncVerifyRedirectCallback(iface);
1219     LONG ref = InterlockedIncrement(&This->ref);
1220
1221     TRACE("(%p) ref=%d\n", This, ref);
1222
1223     return ref;
1224 }
1225
1226 static nsrefcnt NSAPI nsAsyncVerifyRedirectCallback_Release(nsIAsyncVerifyRedirectCallback *iface)
1227 {
1228     nsRedirectCallback *This = impl_from_nsIAsyncVerifyRedirectCallback(iface);
1229     LONG ref = InterlockedDecrement(&This->ref);
1230
1231     TRACE("(%p) ref=%d\n", This, ref);
1232
1233     if(!ref) {
1234         IBindStatusCallback_Release(&This->bsc->bsc.IBindStatusCallback_iface);
1235         nsIHttpChannel_Release(&This->nschannel->nsIHttpChannel_iface);
1236         heap_free(This);
1237     }
1238
1239     return ref;
1240 }
1241
1242 static nsresult NSAPI nsAsyncVerifyRedirectCallback_AsyncOnChannelRedirect(nsIAsyncVerifyRedirectCallback *iface, nsresult result)
1243 {
1244     nsRedirectCallback *This = impl_from_nsIAsyncVerifyRedirectCallback(iface);
1245     nsChannel *old_nschannel;
1246     nsresult nsres;
1247
1248     TRACE("(%p)->(%08x)\n", This, result);
1249
1250     old_nschannel = This->bsc->nschannel;
1251     nsIHttpChannel_AddRef(&This->nschannel->nsIHttpChannel_iface);
1252     This->bsc->nschannel = This->nschannel;
1253
1254     if(This->nschannel->load_group) {
1255         nsres = nsILoadGroup_AddRequest(This->nschannel->load_group, (nsIRequest*)&This->nschannel->nsIHttpChannel_iface,
1256                 NULL);
1257         if(NS_FAILED(nsres))
1258             ERR("AddRequest failed: %08x\n", nsres);
1259     }
1260
1261     if(This->bsc->is_doc_channel) {
1262         IUri *uri = nsuri_get_uri(This->nschannel->uri);
1263
1264         if(uri) {
1265             set_current_uri(This->bsc->bsc.window->base.outer_window, uri);
1266             IUri_Release(uri);
1267         }else {
1268             WARN("Could not get IUri from nsWineURI\n");
1269         }
1270     }
1271
1272     if(old_nschannel) {
1273         nsres = nsILoadGroup_RemoveRequest(old_nschannel->load_group,
1274                 (nsIRequest*)&old_nschannel->nsIHttpChannel_iface, NULL, NS_OK);
1275         if(NS_FAILED(nsres))
1276             ERR("RemoveRequest failed: %08x\n", nsres);
1277         nsIHttpChannel_Release(&old_nschannel->nsIHttpChannel_iface);
1278     }
1279
1280     return NS_OK;
1281 }
1282
1283 static const nsIAsyncVerifyRedirectCallbackVtbl nsAsyncVerifyRedirectCallbackVtbl = {
1284     nsAsyncVerifyRedirectCallback_QueryInterface,
1285     nsAsyncVerifyRedirectCallback_AddRef,
1286     nsAsyncVerifyRedirectCallback_Release,
1287     nsAsyncVerifyRedirectCallback_AsyncOnChannelRedirect
1288 };
1289
1290 static HRESULT create_redirect_callback(nsChannel *nschannel, nsChannelBSC *bsc, nsRedirectCallback **ret)
1291 {
1292     nsRedirectCallback *callback;
1293
1294     callback = heap_alloc(sizeof(*callback));
1295     if(!callback)
1296         return E_OUTOFMEMORY;
1297
1298     callback->nsIAsyncVerifyRedirectCallback_iface.lpVtbl = &nsAsyncVerifyRedirectCallbackVtbl;
1299     callback->ref = 1;
1300
1301     nsIHttpChannel_AddRef(&nschannel->nsIHttpChannel_iface);
1302     callback->nschannel = nschannel;
1303
1304     IBindStatusCallback_AddRef(&bsc->bsc.IBindStatusCallback_iface);
1305     callback->bsc = bsc;
1306
1307     *ret = callback;
1308     return S_OK;
1309 }
1310
1311 static inline nsChannelBSC *nsChannelBSC_from_BSCallback(BSCallback *iface)
1312 {
1313     return CONTAINING_RECORD(iface, nsChannelBSC, bsc);
1314 }
1315
1316 static void nsChannelBSC_destroy(BSCallback *bsc)
1317 {
1318     nsChannelBSC *This = nsChannelBSC_from_BSCallback(bsc);
1319
1320     if(This->nschannel)
1321         nsIHttpChannel_Release(&This->nschannel->nsIHttpChannel_iface);
1322     if(This->nslistener)
1323         nsIStreamListener_Release(This->nslistener);
1324     if(This->nscontext)
1325         nsISupports_Release(This->nscontext);
1326     if(This->nsstream)
1327         nsIInputStream_Release(&This->nsstream->nsIInputStream_iface);
1328     heap_free(This);
1329 }
1330
1331 static HRESULT nsChannelBSC_start_binding(BSCallback *bsc)
1332 {
1333     nsChannelBSC *This = nsChannelBSC_from_BSCallback(bsc);
1334
1335     if(This->is_doc_channel)
1336         This->bsc.window->base.outer_window->base.inner_window->doc->skip_mutation_notif = FALSE;
1337
1338     return S_OK;
1339 }
1340
1341 static HRESULT nsChannelBSC_init_bindinfo(BSCallback *bsc)
1342 {
1343     nsChannelBSC *This = nsChannelBSC_from_BSCallback(bsc);
1344     HRESULT hres;
1345
1346     if(This->nschannel && This->nschannel->post_data_stream) {
1347         hres = read_post_data_stream(This, This->nschannel);
1348         if(FAILED(hres))
1349             return hres;
1350     }
1351
1352     return S_OK;
1353 }
1354
1355 typedef struct {
1356     task_t header;
1357     nsChannelBSC *bsc;
1358 } stop_request_task_t;
1359
1360 static void stop_request_proc(task_t *_task)
1361 {
1362     stop_request_task_t *task = (stop_request_task_t*)_task;
1363
1364     TRACE("(%p)\n", task->bsc);
1365
1366     list_remove(&task->bsc->bsc.entry);
1367     list_init(&task->bsc->bsc.entry);
1368     on_stop_nsrequest(task->bsc, S_OK);
1369 }
1370
1371 static void stop_request_task_destr(task_t *_task)
1372 {
1373     stop_request_task_t *task = (stop_request_task_t*)_task;
1374
1375     IBindStatusCallback_Release(&task->bsc->bsc.IBindStatusCallback_iface);
1376     heap_free(task);
1377 }
1378
1379 static HRESULT async_stop_request(nsChannelBSC *This)
1380 {
1381     stop_request_task_t *task;
1382
1383     if(!This->bsc.readed) {
1384         TRACE("No data read, calling OnStartRequest\n");
1385         on_start_nsrequest(This);
1386     }
1387
1388     task = heap_alloc(sizeof(*task));
1389     if(!task)
1390         return E_OUTOFMEMORY;
1391
1392     IBindStatusCallback_AddRef(&This->bsc.IBindStatusCallback_iface);
1393     task->bsc = This;
1394
1395     push_task(&task->header, stop_request_proc, stop_request_task_destr, This->bsc.window->task_magic);
1396     return S_OK;
1397 }
1398
1399 static void handle_navigation_error(nsChannelBSC *This, DWORD result)
1400 {
1401     HTMLOuterWindow *outer_window;
1402     HTMLDocumentObj *doc;
1403     IOleCommandTarget *olecmd;
1404     BOOL is_error_url;
1405     SAFEARRAY *sa;
1406     SAFEARRAYBOUND bound;
1407     VARIANT var, varOut;
1408     LONG ind;
1409     BSTR unk;
1410     HRESULT hres;
1411
1412     if(!This->is_doc_channel || !This->bsc.window)
1413         return;
1414
1415     outer_window = This->bsc.window->base.outer_window;
1416
1417     doc = outer_window->doc_obj;
1418     if(!doc || !doc->doc_object_service || !doc->client)
1419         return;
1420
1421     hres = IDocObjectService_IsErrorUrl(doc->doc_object_service,
1422             outer_window->url, &is_error_url);
1423     if(FAILED(hres) || is_error_url)
1424         return;
1425
1426     hres = IOleClientSite_QueryInterface(doc->client,
1427             &IID_IOleCommandTarget, (void**)&olecmd);
1428     if(FAILED(hres))
1429         return;
1430
1431     bound.lLbound = 0;
1432     bound.cElements = 8;
1433     sa = SafeArrayCreate(VT_VARIANT, 1, &bound);
1434     if(!sa) {
1435         IOleCommandTarget_Release(olecmd);
1436         return;
1437     }
1438
1439     ind = 0;
1440     V_VT(&var) = VT_I4;
1441     V_I4(&var) = result;
1442     SafeArrayPutElement(sa, &ind, &var);
1443
1444     ind = 1;
1445     V_VT(&var) = VT_BSTR;
1446     V_BSTR(&var) = outer_window->url;
1447     SafeArrayPutElement(sa, &ind, &var);
1448
1449     ind = 3;
1450     V_VT(&var) = VT_UNKNOWN;
1451     V_UNKNOWN(&var) = (IUnknown*)&outer_window->base.IHTMLWindow2_iface;
1452     SafeArrayPutElement(sa, &ind, &var);
1453
1454     /* FIXME: what are the following fields for? */
1455     ind = 2;
1456     V_VT(&var) = VT_UNKNOWN;
1457     V_UNKNOWN(&var) = NULL;
1458     SafeArrayPutElement(sa, &ind, &var);
1459
1460     ind = 4;
1461     V_VT(&var) = VT_BOOL;
1462     V_BOOL(&var) = FALSE;
1463     SafeArrayPutElement(sa, &ind, &var);
1464
1465     ind = 5;
1466     V_VT(&var) = VT_BOOL;
1467     V_BOOL(&var) = FALSE;
1468     SafeArrayPutElement(sa, &ind, &var);
1469
1470     ind = 6;
1471     V_VT(&var) = VT_BSTR;
1472     unk = SysAllocString(NULL);
1473     V_BSTR(&var) = unk;
1474     SafeArrayPutElement(sa, &ind, &var);
1475
1476     ind = 7;
1477     V_VT(&var) = VT_UNKNOWN;
1478     V_UNKNOWN(&var) = NULL;
1479     SafeArrayPutElement(sa, &ind, &var);
1480
1481     V_VT(&var) = VT_ARRAY;
1482     V_ARRAY(&var) = sa;
1483     V_VT(&varOut) = VT_BOOL;
1484     V_BOOL(&varOut) = VARIANT_TRUE;
1485     IOleCommandTarget_Exec(olecmd, &CGID_DocHostCmdPriv, 1, 0, &var, FAILED(hres)?NULL:&varOut);
1486
1487     SysFreeString(unk);
1488     SafeArrayDestroy(sa);
1489     IOleCommandTarget_Release(olecmd);
1490 }
1491
1492 static HRESULT nsChannelBSC_stop_binding(BSCallback *bsc, HRESULT result)
1493 {
1494     nsChannelBSC *This = nsChannelBSC_from_BSCallback(bsc);
1495
1496     if(result != E_ABORT) {
1497         if(FAILED(result))
1498             handle_navigation_error(This, result);
1499         else if(This->is_doc_channel) {
1500             result = async_stop_request(This);
1501             if(SUCCEEDED(result))
1502                 return S_OK;
1503         }
1504     }
1505
1506     on_stop_nsrequest(This, result);
1507     return S_OK;
1508 }
1509
1510 static HRESULT nsChannelBSC_read_data(BSCallback *bsc, IStream *stream)
1511 {
1512     nsChannelBSC *This = nsChannelBSC_from_BSCallback(bsc);
1513
1514     return read_stream_data(This, stream);
1515 }
1516
1517 static HRESULT handle_redirect(nsChannelBSC *This, const WCHAR *new_url)
1518 {
1519     nsRedirectCallback *callback;
1520     nsIChannelEventSink *sink;
1521     nsChannel *new_channel;
1522     nsresult nsres;
1523     HRESULT hres;
1524
1525     TRACE("(%p)->(%s)\n", This, debugstr_w(new_url));
1526
1527     if(!This->nschannel || !This->nschannel->notif_callback)
1528         return S_OK;
1529
1530     nsres = nsIInterfaceRequestor_GetInterface(This->nschannel->notif_callback, &IID_nsIChannelEventSink, (void**)&sink);
1531     if(NS_FAILED(nsres))
1532         return S_OK;
1533
1534     hres = create_redirect_nschannel(new_url, This->nschannel, &new_channel);
1535     if(SUCCEEDED(hres)) {
1536         TRACE("%p %p->%p\n", This, This->nschannel, new_channel);
1537
1538         hres = create_redirect_callback(new_channel, This, &callback);
1539         nsIHttpChannel_Release(&new_channel->nsIHttpChannel_iface);
1540     }
1541
1542     if(SUCCEEDED(hres)) {
1543         nsres = nsIChannelEventSink_AsyncOnChannelRedirect(sink, (nsIChannel*)&This->nschannel->nsIHttpChannel_iface,
1544                 (nsIChannel*)&callback->nschannel->nsIHttpChannel_iface, REDIRECT_TEMPORARY, /* FIXME */
1545                 &callback->nsIAsyncVerifyRedirectCallback_iface);
1546
1547         if(NS_FAILED(nsres))
1548             FIXME("AsyncOnChannelRedirect failed: %08x\n", hres);
1549         else if(This->nschannel != callback->nschannel)
1550             FIXME("nschannel not updated\n");
1551
1552         nsIAsyncVerifyRedirectCallback_Release(&callback->nsIAsyncVerifyRedirectCallback_iface);
1553     }
1554
1555     nsIChannelEventSink_Release(sink);
1556     return hres;
1557 }
1558
1559 static HRESULT nsChannelBSC_on_progress(BSCallback *bsc, ULONG status_code, LPCWSTR status_text)
1560 {
1561     nsChannelBSC *This = nsChannelBSC_from_BSCallback(bsc);
1562
1563     switch(status_code) {
1564     case BINDSTATUS_MIMETYPEAVAILABLE:
1565         if(!This->nschannel)
1566             return S_OK;
1567
1568         heap_free(This->nschannel->content_type);
1569         This->nschannel->content_type = heap_strdupWtoA(status_text);
1570         break;
1571     case BINDSTATUS_REDIRECTING:
1572         return handle_redirect(This, status_text);
1573     case BINDSTATUS_BEGINDOWNLOADDATA: {
1574         IWinInetHttpInfo *http_info;
1575         DWORD status, size = sizeof(DWORD);
1576         HRESULT hres;
1577
1578         if(!This->bsc.binding)
1579             break;
1580
1581         hres = IBinding_QueryInterface(This->bsc.binding, &IID_IWinInetHttpInfo, (void**)&http_info);
1582         if(FAILED(hres))
1583             break;
1584
1585         hres = IWinInetHttpInfo_QueryInfo(http_info,
1586                 HTTP_QUERY_STATUS_CODE|HTTP_QUERY_FLAG_NUMBER, &status, &size, NULL, NULL);
1587         IWinInetHttpInfo_Release(http_info);
1588         if(FAILED(hres) || status == HTTP_STATUS_OK)
1589             break;
1590
1591         handle_navigation_error(This, status);
1592     }
1593     }
1594
1595     return S_OK;
1596 }
1597
1598 static HRESULT nsChannelBSC_on_response(BSCallback *bsc, DWORD response_code,
1599         LPCWSTR response_headers)
1600 {
1601     nsChannelBSC *This = nsChannelBSC_from_BSCallback(bsc);
1602     HRESULT hres;
1603
1604     This->nschannel->response_status = response_code;
1605
1606     if(response_headers) {
1607         const WCHAR *headers;
1608
1609         headers = strchrW(response_headers, '\r');
1610         if(headers && headers[1] == '\n') {
1611             headers += 2;
1612             hres = process_response_headers(This, headers);
1613             if(FAILED(hres)) {
1614                 WARN("parsing headers failed: %08x\n", hres);
1615                 return hres;
1616             }
1617         }
1618     }
1619
1620     return S_OK;
1621 }
1622
1623 static HRESULT nsChannelBSC_beginning_transaction(BSCallback *bsc, WCHAR **additional_headers)
1624 {
1625     nsChannelBSC *This = nsChannelBSC_from_BSCallback(bsc);
1626     http_header_t *iter;
1627     DWORD len = 0;
1628     WCHAR *ptr;
1629
1630     static const WCHAR content_lengthW[] =
1631         {'C','o','n','t','e','n','t','-','L','e','n','g','t','h',0};
1632
1633     if(!This->nschannel)
1634         return S_FALSE;
1635
1636     LIST_FOR_EACH_ENTRY(iter, &This->nschannel->request_headers, http_header_t, entry) {
1637         if(strcmpW(iter->header, content_lengthW))
1638             len += strlenW(iter->header) + 2 /* ": " */ + strlenW(iter->data) + 2 /* "\r\n" */;
1639     }
1640
1641     if(!len)
1642         return S_OK;
1643
1644     *additional_headers = ptr = CoTaskMemAlloc((len+1)*sizeof(WCHAR));
1645     if(!ptr)
1646         return E_OUTOFMEMORY;
1647
1648     LIST_FOR_EACH_ENTRY(iter, &This->nschannel->request_headers, http_header_t, entry) {
1649         if(!strcmpW(iter->header, content_lengthW))
1650             continue;
1651
1652         len = strlenW(iter->header);
1653         memcpy(ptr, iter->header, len*sizeof(WCHAR));
1654         ptr += len;
1655
1656         *ptr++ = ':';
1657         *ptr++ = ' ';
1658
1659         len = strlenW(iter->data);
1660         memcpy(ptr, iter->data, len*sizeof(WCHAR));
1661         ptr += len;
1662
1663         *ptr++ = '\r';
1664         *ptr++ = '\n';
1665     }
1666
1667     *ptr = 0;
1668
1669     return S_OK;
1670 }
1671
1672 static const BSCallbackVtbl nsChannelBSCVtbl = {
1673     nsChannelBSC_destroy,
1674     nsChannelBSC_init_bindinfo,
1675     nsChannelBSC_start_binding,
1676     nsChannelBSC_stop_binding,
1677     nsChannelBSC_read_data,
1678     nsChannelBSC_on_progress,
1679     nsChannelBSC_on_response,
1680     nsChannelBSC_beginning_transaction
1681 };
1682
1683 HRESULT create_channelbsc(IMoniker *mon, const WCHAR *headers, BYTE *post_data, DWORD post_data_size,
1684         BOOL is_doc_binding, nsChannelBSC **retval)
1685 {
1686     nsChannelBSC *ret;
1687
1688     ret = heap_alloc_zero(sizeof(*ret));
1689     if(!ret)
1690         return E_OUTOFMEMORY;
1691
1692     init_bscallback(&ret->bsc, &nsChannelBSCVtbl, mon, BINDF_ASYNCHRONOUS | BINDF_ASYNCSTORAGE | BINDF_PULLDATA);
1693     ret->is_doc_channel = is_doc_binding;
1694
1695     if(headers) {
1696         ret->bsc.headers = heap_strdupW(headers);
1697         if(!ret->bsc.headers) {
1698             IBindStatusCallback_Release(&ret->bsc.IBindStatusCallback_iface);
1699             return E_OUTOFMEMORY;
1700         }
1701     }
1702
1703     if(post_data) {
1704         ret->bsc.post_data = GlobalAlloc(0, post_data_size);
1705         if(!ret->bsc.post_data) {
1706             heap_free(ret->bsc.headers);
1707             IBindStatusCallback_Release(&ret->bsc.IBindStatusCallback_iface);
1708             return E_OUTOFMEMORY;
1709         }
1710
1711         memcpy(ret->bsc.post_data, post_data, post_data_size);
1712         ret->bsc.post_data_len = post_data_size;
1713     }
1714
1715     *retval = ret;
1716     return S_OK;
1717 }
1718
1719 typedef struct {
1720     task_t header;
1721     HTMLOuterWindow *window;
1722     HTMLInnerWindow *pending_window;
1723 } start_doc_binding_task_t;
1724
1725 static void start_doc_binding_proc(task_t *_task)
1726 {
1727     start_doc_binding_task_t *task = (start_doc_binding_task_t*)_task;
1728
1729     set_current_mon(task->window, task->pending_window->bscallback->bsc.mon);
1730     start_binding(task->pending_window, &task->pending_window->bscallback->bsc, NULL);
1731 }
1732
1733 static void start_doc_binding_task_destr(task_t *_task)
1734 {
1735     start_doc_binding_task_t *task = (start_doc_binding_task_t*)_task;
1736
1737     IHTMLWindow2_Release(&task->pending_window->base.IHTMLWindow2_iface);
1738     heap_free(task);
1739 }
1740
1741 HRESULT async_start_doc_binding(HTMLOuterWindow *window, HTMLInnerWindow *pending_window)
1742 {
1743     start_doc_binding_task_t *task;
1744
1745     TRACE("%p\n", pending_window);
1746
1747     task = heap_alloc(sizeof(start_doc_binding_task_t));
1748     if(!task)
1749         return E_OUTOFMEMORY;
1750
1751     task->window = window;
1752     task->pending_window = pending_window;
1753     IHTMLWindow2_AddRef(&pending_window->base.IHTMLWindow2_iface);
1754
1755     push_task(&task->header, start_doc_binding_proc, start_doc_binding_task_destr, pending_window->task_magic);
1756     return S_OK;
1757 }
1758
1759 void abort_window_bindings(HTMLInnerWindow *window)
1760 {
1761     BSCallback *iter;
1762
1763     remove_target_tasks(window->task_magic);
1764
1765     while(!list_empty(&window->bindings)) {
1766         iter = LIST_ENTRY(window->bindings.next, BSCallback, entry);
1767
1768         TRACE("Aborting %p\n", iter);
1769
1770         IBindStatusCallback_AddRef(&iter->IBindStatusCallback_iface);
1771
1772         if(iter->binding)
1773             IBinding_Abort(iter->binding);
1774         else
1775             iter->vtbl->stop_binding(iter, E_ABORT);
1776
1777         iter->window = NULL;
1778         list_remove(&iter->entry);
1779         list_init(&iter->entry);
1780
1781         IBindStatusCallback_Release(&iter->IBindStatusCallback_iface);
1782     }
1783
1784     if(window->bscallback) {
1785         IBindStatusCallback_Release(&window->bscallback->bsc.IBindStatusCallback_iface);
1786         window->bscallback = NULL;
1787     }
1788
1789     if(window->mon) {
1790         IMoniker_Release(window->mon);
1791         window->mon = NULL;
1792     }
1793 }
1794
1795 HRESULT channelbsc_load_stream(HTMLInnerWindow *pending_window, IStream *stream)
1796 {
1797     nsChannelBSC *bscallback = pending_window->bscallback;
1798     HRESULT hres = S_OK;
1799
1800     if(!bscallback->nschannel) {
1801         ERR("NULL nschannel\n");
1802         return E_FAIL;
1803     }
1804
1805     bscallback->nschannel->content_type = heap_strdupA("text/html");
1806     if(!bscallback->nschannel->content_type)
1807         return E_OUTOFMEMORY;
1808
1809     bscallback->bsc.window = pending_window;
1810     if(stream)
1811         hres = read_stream_data(bscallback, stream);
1812     if(SUCCEEDED(hres))
1813         hres = async_stop_request(bscallback);
1814     if(FAILED(hres))
1815         IBindStatusCallback_OnStopBinding(&bscallback->bsc.IBindStatusCallback_iface, hres,
1816                 ERROR_SUCCESS);
1817
1818     return hres;
1819 }
1820
1821 void channelbsc_set_channel(nsChannelBSC *This, nsChannel *channel, nsIStreamListener *listener, nsISupports *context)
1822 {
1823     nsIHttpChannel_AddRef(&channel->nsIHttpChannel_iface);
1824     This->nschannel = channel;
1825
1826     nsIStreamListener_AddRef(listener);
1827     This->nslistener = listener;
1828
1829     if(context) {
1830         nsISupports_AddRef(context);
1831         This->nscontext = context;
1832     }
1833
1834     if(This->bsc.headers) {
1835         HRESULT hres;
1836
1837         hres = parse_headers(This->bsc.headers, &channel->request_headers);
1838         heap_free(This->bsc.headers);
1839         This->bsc.headers = NULL;
1840         if(FAILED(hres))
1841             WARN("parse_headers failed: %08x\n", hres);
1842     }
1843 }
1844
1845 typedef struct {
1846     task_t header;
1847     HTMLOuterWindow *window;
1848     IUri *uri;
1849 } navigate_javascript_task_t;
1850
1851 static void navigate_javascript_proc(task_t *_task)
1852 {
1853     navigate_javascript_task_t *task = (navigate_javascript_task_t*)_task;
1854     HTMLOuterWindow *window = task->window;
1855     VARIANT v;
1856     BSTR code;
1857     HRESULT hres;
1858
1859     static const WCHAR jscriptW[] = {'j','s','c','r','i','p','t',0};
1860
1861     task->window->readystate = READYSTATE_COMPLETE;
1862
1863     hres = IUri_GetPath(task->uri, &code);
1864     if(FAILED(hres))
1865         return;
1866
1867     hres = UrlUnescapeW(code, NULL, NULL, URL_UNESCAPE_INPLACE);
1868     if(FAILED(hres)) {
1869         SysFreeString(code);
1870         return;
1871     }
1872
1873     set_download_state(window->doc_obj, 1);
1874
1875     V_VT(&v) = VT_EMPTY;
1876     hres = exec_script(window->base.inner_window, code, jscriptW, &v);
1877     SysFreeString(code);
1878     if(SUCCEEDED(hres) && V_VT(&v) != VT_EMPTY) {
1879         FIXME("javascirpt URL returned %s\n", debugstr_variant(&v));
1880         VariantClear(&v);
1881     }
1882
1883     if(window->doc_obj->view_sink)
1884         IAdviseSink_OnViewChange(window->doc_obj->view_sink, DVASPECT_CONTENT, -1);
1885
1886     set_download_state(window->doc_obj, 0);
1887 }
1888
1889 static void navigate_javascript_task_destr(task_t *_task)
1890 {
1891     navigate_javascript_task_t *task = (navigate_javascript_task_t*)_task;
1892
1893     IUri_Release(task->uri);
1894     heap_free(task);
1895 }
1896
1897 typedef struct {
1898     task_t header;
1899     HTMLOuterWindow *window;
1900     nsChannelBSC *bscallback;
1901     IMoniker *mon;
1902 } navigate_task_t;
1903
1904 static void navigate_proc(task_t *_task)
1905 {
1906     navigate_task_t *task = (navigate_task_t*)_task;
1907     HRESULT hres;
1908
1909     hres = set_moniker(&task->window->doc_obj->basedoc, task->mon, NULL, task->bscallback, TRUE);
1910     if(SUCCEEDED(hres)) {
1911         set_current_mon(task->window, task->bscallback->bsc.mon);
1912         start_binding(task->window->pending_window, &task->bscallback->bsc, NULL);
1913     }
1914 }
1915
1916 static void navigate_task_destr(task_t *_task)
1917 {
1918     navigate_task_t *task = (navigate_task_t*)_task;
1919
1920     IBindStatusCallback_Release(&task->bscallback->bsc.IBindStatusCallback_iface);
1921     IMoniker_Release(task->mon);
1922     heap_free(task);
1923 }
1924
1925 static HRESULT navigate_fragment(HTMLOuterWindow *window, IUri *uri)
1926 {
1927     nsIDOMLocation *nslocation;
1928     nsAString nsfrag_str;
1929     WCHAR *selector;
1930     BSTR frag;
1931     nsresult nsres;
1932     HRESULT hres;
1933
1934     const WCHAR selector_formatW[] = {'a','[','i','d','=','"','%','s','"',']',0};
1935
1936     set_current_uri(window, uri);
1937
1938     nsres = nsIDOMWindow_GetLocation(window->nswindow, &nslocation);
1939     if(FAILED(nsres) || !nslocation)
1940         return E_FAIL;
1941
1942     hres = IUri_GetFragment(uri, &frag);
1943     if(FAILED(hres)) {
1944         nsIDOMLocation_Release(nslocation);
1945         return hres;
1946     }
1947
1948     nsAString_InitDepend(&nsfrag_str, frag);
1949     nsres = nsIDOMLocation_SetHash(nslocation, &nsfrag_str);
1950     nsAString_Finish(&nsfrag_str);
1951     nsIDOMLocation_Release(nslocation);
1952     if(NS_FAILED(nsres))
1953         ERR("SetHash failed: %08x\n", nsres);
1954
1955     /*
1956      * IE supports scrolling to anchor elements with "#hash" ids (note that '#' is part of the id),
1957      * while Gecko scrolls only to elements with "hash" ids. We scroll the page ourselves if
1958      * a[id="#hash"] element can be found.
1959      */
1960     selector = heap_alloc(sizeof(selector_formatW)+SysStringLen(frag)*sizeof(WCHAR));
1961     if(selector) {
1962         nsIDOMNodeSelector *node_selector;
1963         nsIDOMElement *nselem = NULL;
1964         nsAString selector_str;
1965
1966         nsres = nsIDOMHTMLDocument_QueryInterface(window->base.inner_window->doc->nsdoc, &IID_nsIDOMNodeSelector,
1967                 (void**)&node_selector);
1968         assert(nsres == NS_OK);
1969
1970         sprintfW(selector, selector_formatW, frag);
1971         nsAString_InitDepend(&selector_str, selector);
1972         /* NOTE: Gecko doesn't set result to NULL if there is no match, so nselem must be initialized */
1973         nsres = nsIDOMNodeSelector_QuerySelector(node_selector, &selector_str, &nselem);
1974         nsIDOMNodeSelector_Release(node_selector);
1975         nsAString_Finish(&selector_str);
1976         heap_free(selector);
1977         if(NS_SUCCEEDED(nsres) && nselem) {
1978             nsIDOMHTMLElement *html_elem;
1979
1980             nsres = nsIDOMElement_QueryInterface(nselem, &IID_nsIDOMHTMLElement, (void**)&html_elem);
1981             nsIDOMElement_Release(nselem);
1982             if(NS_SUCCEEDED(nsres)) {
1983                 nsIDOMHTMLElement_ScrollIntoView(html_elem, TRUE, 1);
1984                 nsIDOMHTMLElement_Release(html_elem);
1985             }
1986         }
1987     }
1988
1989     SysFreeString(frag);
1990
1991     if(window->doc_obj->doc_object_service) {
1992         IDocObjectService_FireNavigateComplete2(window->doc_obj->doc_object_service, &window->base.IHTMLWindow2_iface, 0x10);
1993         IDocObjectService_FireDocumentComplete(window->doc_obj->doc_object_service, &window->base.IHTMLWindow2_iface, 0);
1994
1995     }
1996
1997     return S_OK;
1998 }
1999
2000 HRESULT super_navigate(HTMLOuterWindow *window, IUri *uri, const WCHAR *headers, BYTE *post_data, DWORD post_data_size)
2001 {
2002     nsChannelBSC *bsc;
2003     IMoniker *mon;
2004     DWORD scheme;
2005     HRESULT hres;
2006
2007     if(window->doc_obj->client) {
2008         IOleCommandTarget *cmdtrg;
2009
2010         hres = IOleClientSite_QueryInterface(window->doc_obj->client, &IID_IOleCommandTarget, (void**)&cmdtrg);
2011         if(SUCCEEDED(hres)) {
2012             VARIANT in, out;
2013             BSTR url_str;
2014
2015             hres = IUri_GetDisplayUri(uri, &url_str);
2016             if(SUCCEEDED(hres)) {
2017                 V_VT(&in) = VT_BSTR;
2018                 V_BSTR(&in) = url_str;
2019                 V_VT(&out) = VT_BOOL;
2020                 V_BOOL(&out) = VARIANT_TRUE;
2021                 hres = IOleCommandTarget_Exec(cmdtrg, &CGID_ShellDocView, 67, 0, &in, &out);
2022                 IOleCommandTarget_Release(cmdtrg);
2023                 if(SUCCEEDED(hres))
2024                     VariantClear(&out);
2025                 SysFreeString(url_str);
2026             }
2027         }
2028     }
2029
2030     if(window->uri && !post_data_size && compare_ignoring_frag(window->uri, uri)) {
2031         TRACE("fragment navigate\n");
2032         return navigate_fragment(window, uri);
2033     }
2034
2035     hres = CreateURLMonikerEx2(NULL, uri, &mon, URL_MK_UNIFORM);
2036     if(FAILED(hres))
2037         return hres;
2038
2039     /* FIXME: Why not set_ready_state? */
2040     window->readystate = READYSTATE_UNINITIALIZED;
2041
2042     hres = create_channelbsc(mon, headers, post_data, post_data_size, TRUE, &bsc);
2043     if(FAILED(hres)) {
2044         IMoniker_Release(mon);
2045         return hres;
2046     }
2047
2048     prepare_for_binding(&window->doc_obj->basedoc, mon, TRUE);
2049
2050     hres = IUri_GetScheme(uri, &scheme);
2051     if(SUCCEEDED(hres) && scheme != URL_SCHEME_JAVASCRIPT) {
2052         navigate_task_t *task;
2053
2054         task = heap_alloc(sizeof(*task));
2055         if(!task) {
2056             IBindStatusCallback_Release(&bsc->bsc.IBindStatusCallback_iface);
2057             IMoniker_Release(mon);
2058             return E_OUTOFMEMORY;
2059         }
2060
2061         /* Silently and repeated when real loading starts? */
2062         window->readystate = READYSTATE_LOADING;
2063         call_docview_84(window->doc_obj);
2064
2065         task->window = window;
2066         task->bscallback = bsc;
2067         task->mon = mon;
2068         push_task(&task->header, navigate_proc, navigate_task_destr, window->task_magic);
2069
2070     }else {
2071         navigate_javascript_task_t *task;
2072
2073         IBindStatusCallback_Release(&bsc->bsc.IBindStatusCallback_iface);
2074         IMoniker_Release(mon);
2075
2076         task = heap_alloc(sizeof(*task));
2077         if(!task)
2078             return E_OUTOFMEMORY;
2079
2080         /* Why silently? */
2081         window->readystate = READYSTATE_COMPLETE;
2082         call_docview_84(window->doc_obj);
2083
2084         IUri_AddRef(uri);
2085         task->window = window;
2086         task->uri = uri;
2087         push_task(&task->header, navigate_javascript_proc, navigate_javascript_task_destr, window->task_magic);
2088     }
2089
2090     return S_OK;
2091 }
2092
2093 HRESULT navigate_new_window(HTMLOuterWindow *window, IUri *uri, const WCHAR *name, IHTMLWindow2 **ret)
2094 {
2095     IWebBrowser2 *web_browser;
2096     IHTMLWindow2 *new_window;
2097     IBindCtx *bind_ctx;
2098     nsChannelBSC *bsc;
2099     HRESULT hres;
2100
2101     hres = create_channelbsc(NULL, NULL, NULL, 0, FALSE, &bsc);
2102     if(FAILED(hres))
2103         return hres;
2104
2105     hres = CreateAsyncBindCtx(0, &bsc->bsc.IBindStatusCallback_iface, NULL, &bind_ctx);
2106     if(FAILED(hres)) {
2107         IBindStatusCallback_Release(&bsc->bsc.IBindStatusCallback_iface);
2108         return hres;
2109     }
2110
2111     hres = CoCreateInstance(&CLSID_InternetExplorer, NULL, CLSCTX_LOCAL_SERVER,
2112             &IID_IWebBrowser2, (void**)&web_browser);
2113     if(SUCCEEDED(hres)) {
2114         ITargetFramePriv2 *target_frame_priv;
2115
2116         hres = IWebBrowser2_QueryInterface(web_browser, &IID_ITargetFramePriv2, (void**)&target_frame_priv);
2117         if(SUCCEEDED(hres)) {
2118             hres = ITargetFramePriv2_AggregatedNavigation2(target_frame_priv,
2119                     HLNF_DISABLEWINDOWRESTRICTIONS|HLNF_OPENINNEWWINDOW, bind_ctx, &bsc->bsc.IBindStatusCallback_iface,
2120                     name, uri, emptyW);
2121             ITargetFramePriv2_Release(target_frame_priv);
2122
2123             if(SUCCEEDED(hres))
2124                 hres = do_query_service((IUnknown*)web_browser, &SID_SHTMLWindow, &IID_IHTMLWindow2, (void**)&new_window);
2125         }
2126         if(FAILED(hres)) {
2127             IWebBrowser2_Quit(web_browser);
2128             IWebBrowser2_Release(web_browser);
2129         }
2130     }else {
2131         WARN("Could not create InternetExplorer instance: %08x\n", hres);
2132     }
2133
2134     IBindStatusCallback_Release(&bsc->bsc.IBindStatusCallback_iface);
2135     IBindCtx_Release(bind_ctx);
2136     if(FAILED(hres))
2137         return hres;
2138
2139     IWebBrowser2_put_Visible(web_browser, VARIANT_TRUE);
2140     IWebBrowser2_Release(web_browser);
2141
2142     if(ret)
2143         *ret = new_window;
2144     else
2145         IHTMLWindow2_Release(new_window);
2146     return S_OK;
2147 }
2148
2149 HRESULT hlink_frame_navigate(HTMLDocument *doc, LPCWSTR url, nsChannel *nschannel, DWORD hlnf, BOOL *cancel)
2150 {
2151     IHlinkFrame *hlink_frame;
2152     nsChannelBSC *callback;
2153     IBindCtx *bindctx;
2154     IMoniker *mon;
2155     IHlink *hlink;
2156     HRESULT hres;
2157
2158     *cancel = FALSE;
2159
2160     hres = do_query_service((IUnknown*)doc->doc_obj->client, &IID_IHlinkFrame, &IID_IHlinkFrame,
2161             (void**)&hlink_frame);
2162     if(FAILED(hres))
2163         return S_OK;
2164
2165     hres = create_channelbsc(NULL, NULL, NULL, 0, FALSE, &callback);
2166     if(FAILED(hres)) {
2167         IHlinkFrame_Release(hlink_frame);
2168         return hres;
2169     }
2170
2171     if(nschannel)
2172         read_post_data_stream(callback, nschannel);
2173
2174     hres = CreateAsyncBindCtx(0, &callback->bsc.IBindStatusCallback_iface, NULL, &bindctx);
2175     if(SUCCEEDED(hres))
2176         hres = CoCreateInstance(&CLSID_StdHlink, NULL, CLSCTX_INPROC_SERVER,
2177                 &IID_IHlink, (LPVOID*)&hlink);
2178
2179     if(SUCCEEDED(hres))
2180         hres = CreateURLMoniker(NULL, url, &mon);
2181
2182     if(SUCCEEDED(hres)) {
2183         IHlink_SetMonikerReference(hlink, HLINKSETF_TARGET, mon, NULL);
2184
2185         if(hlnf & HLNF_OPENINNEWWINDOW) {
2186             static const WCHAR wszBlank[] = {'_','b','l','a','n','k',0};
2187             IHlink_SetTargetFrameName(hlink, wszBlank); /* FIXME */
2188         }
2189
2190         hres = IHlinkFrame_Navigate(hlink_frame, hlnf, bindctx,
2191                 &callback->bsc.IBindStatusCallback_iface, hlink);
2192         IMoniker_Release(mon);
2193         *cancel = hres == S_OK;
2194         hres = S_OK;
2195     }
2196
2197     IHlinkFrame_Release(hlink_frame);
2198     IBindCtx_Release(bindctx);
2199     IBindStatusCallback_Release(&callback->bsc.IBindStatusCallback_iface);
2200     return hres;
2201 }
2202
2203 HRESULT navigate_url(HTMLOuterWindow *window, const WCHAR *new_url, const WCHAR *base_url)
2204 {
2205     WCHAR url[INTERNET_MAX_URL_LENGTH];
2206     nsWineURI *uri;
2207     HRESULT hres;
2208
2209     if(!new_url) {
2210         *url = 0;
2211     }else if(base_url) {
2212         DWORD len = 0;
2213
2214         hres = CoInternetCombineUrl(base_url, new_url, URL_ESCAPE_SPACES_ONLY|URL_DONT_ESCAPE_EXTRA_INFO,
2215                 url, sizeof(url)/sizeof(WCHAR), &len, 0);
2216         if(FAILED(hres))
2217             return hres;
2218     }else {
2219         strcpyW(url, new_url);
2220     }
2221
2222     if(window->doc_obj && window->doc_obj->hostui) {
2223         OLECHAR *translated_url = NULL;
2224
2225         hres = IDocHostUIHandler_TranslateUrl(window->doc_obj->hostui, 0, url,
2226                 &translated_url);
2227         if(hres == S_OK) {
2228             TRACE("%08x %s -> %s\n", hres, debugstr_w(url), debugstr_w(translated_url));
2229             strcpyW(url, translated_url);
2230             CoTaskMemFree(translated_url);
2231         }
2232     }
2233
2234     if(window->doc_obj && window->doc_obj->is_webbrowser && window == window->doc_obj->basedoc.window) {
2235         BOOL cancel = FALSE;
2236         IUri *uri;
2237
2238         hres = IDocObjectService_FireBeforeNavigate2(window->doc_obj->doc_object_service, NULL, url, 0x40,
2239                 NULL, NULL, 0, NULL, TRUE, &cancel);
2240         if(SUCCEEDED(hres) && cancel) {
2241             TRACE("Navigation canceled\n");
2242             return S_OK;
2243         }
2244
2245         hres = CreateUri(url, 0, 0, &uri);
2246         if(FAILED(hres))
2247             return hres;
2248
2249         hres = super_navigate(window, uri, NULL, NULL, 0);
2250         IUri_Release(uri);
2251         return hres;
2252     }
2253
2254     if(window->doc_obj && window == window->doc_obj->basedoc.window) {
2255         BOOL cancel;
2256
2257         hres = hlink_frame_navigate(&window->base.inner_window->doc->basedoc, url, NULL, 0, &cancel);
2258         if(FAILED(hres))
2259             return hres;
2260
2261         if(cancel) {
2262             TRACE("Navigation handled by hlink frame\n");
2263             return S_OK;
2264         }
2265     }
2266
2267     hres = create_doc_uri(window, url, &uri);
2268     if(FAILED(hres))
2269         return hres;
2270
2271     hres = load_nsuri(window, uri, NULL, LOAD_FLAGS_NONE);
2272     nsISupports_Release((nsISupports*)uri);
2273     return hres;
2274 }