You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

142 line
4.2KB

  1. <?xml version="1.0"?>
  2. <?component error="true" debug="false"?>
  3. <component>
  4. <registration
  5. description="WscMvc explicit route table"
  6. progid="WscMvc.Router"
  7. version="1.00"
  8. classid="{C92F9338-B478-4EAD-B865-892FFB1E1C51}">
  9. </registration>
  10. <public>
  11. <method name="Match">
  12. <parameter name="ctx"/>
  13. <parameter name="applicationName"/>
  14. <parameter name="statusLine"/>
  15. <parameter name="contentType"/>
  16. <parameter name="body"/>
  17. <parameter name="allowHeader"/>
  18. <parameter name="handlerKey"/>
  19. </method>
  20. </public>
  21. <script language="VBScript">
  22. <![CDATA[
  23. Option Explicit
  24. ' Explicit allowlisted route table. This component decides only route
  25. ' metadata; Application.wsc performs the corresponding hardcoded handler
  26. ' calls. No URL segment is ever treated as a ProgID or method name.
  27. Sub Match(ctx, applicationName, statusLine, contentType, body, allowHeader, handlerKey)
  28. Dim rawPath, normalizedPath, httpMethod
  29. statusLine = ""
  30. contentType = ""
  31. body = ""
  32. allowHeader = ""
  33. handlerKey = ""
  34. rawPath = ctx.Path
  35. httpMethod = UCase(Trim(CStr(ctx.HttpMethod)))
  36. If Not TryNormalizePath(rawPath, normalizedPath) Then
  37. BadRequest statusLine, contentType, body
  38. Exit Sub
  39. End If
  40. ' Literal routes are intentionally listed directly. Parameterized routes,
  41. ' when added, must be checked after these literal comparisons.
  42. If applicationName = "production" Then
  43. If normalizedPath = "/hello" Then
  44. MatchMethod httpMethod, "GET", "Home.Hello", statusLine, contentType, body, allowHeader, handlerKey
  45. Exit Sub
  46. End If
  47. ElseIf applicationName = "tests" Then
  48. If normalizedPath = "/self-test" Then
  49. MatchMethod httpMethod, "GET, POST", "SelfTest.RunSelfTest", statusLine, contentType, body, allowHeader, handlerKey
  50. Exit Sub
  51. End If
  52. End If
  53. statusLine = "404 Not Found"
  54. contentType = "text/plain; charset=utf-8"
  55. body = "Not Found"
  56. End Sub
  57. Function TryNormalizePath(rawPath, normalizedPath)
  58. Dim path
  59. TryNormalizePath = False
  60. normalizedPath = ""
  61. If IsNull(rawPath) Or IsEmpty(rawPath) Then
  62. path = "/"
  63. Else
  64. path = Trim(CStr(rawPath))
  65. If Len(path) = 0 Then path = "/"
  66. End If
  67. If Left(path, 1) <> "/" Then Exit Function
  68. If InStr(path, "\") > 0 Then Exit Function
  69. If InStr(path, "%") > 0 Then Exit Function
  70. If InStr(path, "?") > 0 Then Exit Function
  71. If InStr(path, "#") > 0 Then Exit Function
  72. If InStr(path, "//") > 0 Then Exit Function
  73. If InStr(path, "/./") > 0 Then Exit Function
  74. If InStr(path, "/../") > 0 Then Exit Function
  75. If Right(path, 2) = "/." Then Exit Function
  76. If Right(path, 3) = "/.." Then Exit Function
  77. If ContainsControlCharacter(path) Then Exit Function
  78. If Len(path) > 1 And Right(path, 1) = "/" Then
  79. path = Left(path, Len(path) - 1)
  80. End If
  81. normalizedPath = LCase(path)
  82. TryNormalizePath = True
  83. End Function
  84. Function ContainsControlCharacter(value)
  85. Dim i, code
  86. ContainsControlCharacter = False
  87. For i = 1 To Len(value)
  88. code = Asc(Mid(value, i, 1))
  89. If code < 32 Or code = 127 Then
  90. ContainsControlCharacter = True
  91. Exit Function
  92. End If
  93. Next
  94. End Function
  95. Sub MatchMethod(httpMethod, allowedMethods, matchedHandlerKey, statusLine, contentType, body, allowHeader, handlerKey)
  96. If IsAllowedMethod(httpMethod, allowedMethods) Then
  97. handlerKey = matchedHandlerKey
  98. Else
  99. statusLine = "405 Method Not Allowed"
  100. contentType = "text/plain; charset=utf-8"
  101. body = "Method Not Allowed"
  102. allowHeader = allowedMethods
  103. End If
  104. End Sub
  105. Function IsAllowedMethod(httpMethod, allowedMethods)
  106. Dim methods, i
  107. methods = Split(allowedMethods, ",")
  108. IsAllowedMethod = False
  109. For i = 0 To UBound(methods)
  110. If httpMethod = Trim(methods(i)) Then
  111. IsAllowedMethod = True
  112. Exit Function
  113. End If
  114. Next
  115. End Function
  116. Sub BadRequest(statusLine, contentType, body)
  117. statusLine = "400 Bad Request"
  118. contentType = "text/plain; charset=utf-8"
  119. body = "Bad Request"
  120. End Sub
  121. ]]>
  122. </script>
  123. </component>

Powered by TurnKey Linux.