Commit 16768191 by Carlos Martín Nieto

ssl: match host names according to RFC 2818 (HTTP over TLS)

parent dbb36e1b
...@@ -194,13 +194,11 @@ int gitno_ssl_teardown(git_transport *t) ...@@ -194,13 +194,11 @@ int gitno_ssl_teardown(git_transport *t)
#ifdef GIT_OPENSSL #ifdef GIT_OPENSSL
/* /* Match host names according to RFC 2818 rules */
* This function is based on the one from the cURL project
*/
static int match_host(const char *pattern, const char *host) static int match_host(const char *pattern, const char *host)
{ {
for (;;) { for (;;) {
char c = *pattern++; char c = tolower(*pattern++);
if (c == '\0') if (c == '\0')
return *host ? -1 : 0; return *host ? -1 : 0;
...@@ -211,14 +209,24 @@ static int match_host(const char *pattern, const char *host) ...@@ -211,14 +209,24 @@ static int match_host(const char *pattern, const char *host)
if (c == '\0') if (c == '\0')
return 0; return 0;
while (*host) { /*
if (match_host(pattern, host++) == 0) * We've found a pattern, so move towards the next matching
return 0; * char. The '.' is handled specially because wildcards aren't
* allowed to cross subdomains.
*/
while(*host) {
char h = tolower(*host);
if (c == h)
return match_host(pattern, host++);
if (h == '.')
return match_host(pattern, host);
host++;
} }
break; return -1;
} }
if (tolower(c) != tolower(*host++)) if (c != tolower(*host++))
return -1; return -1;
} }
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment