2008-05-17 17:23:37 +04:00
|
|
|
/*
|
2014-08-22 23:08:44 +04:00
|
|
|
* Bittorrent Client using Qt and libtorrent.
|
|
|
|
* Copyright (C) 2014 Vladimir Golovnev <glassez@yandex.ru>
|
|
|
|
* Copyright (C) 2006 Christophe Dumez <chris@qbittorrent.org>
|
|
|
|
* Copyright (C) 2006 Ishan Arora <ishan@qbittorrent.org>
|
2008-05-17 17:23:37 +04:00
|
|
|
*
|
2009-04-05 22:48:45 +04:00
|
|
|
* This program is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU General Public License
|
|
|
|
* as published by the Free Software Foundation; either version 2
|
|
|
|
* of the License, or (at your option) any later version.
|
2008-05-17 17:23:37 +04:00
|
|
|
*
|
2009-04-05 22:48:45 +04:00
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
2008-05-17 17:23:37 +04:00
|
|
|
*
|
2009-04-05 22:48:45 +04:00
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program; if not, write to the Free Software
|
|
|
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
|
|
|
*
|
|
|
|
* In addition, as a special exception, the copyright holders give permission to
|
|
|
|
* link this program with the OpenSSL project's "OpenSSL" library (or with
|
|
|
|
* modified versions of it that use the same license as the "OpenSSL" library),
|
|
|
|
* and distribute the linked executables. You must obey the GNU General Public
|
|
|
|
* License in all respects for all of the code used other than "OpenSSL". If you
|
|
|
|
* modify file(s), you may extend this exception to your version of the file(s),
|
|
|
|
* but you are not obligated to do so. If you do not wish to do so, delete this
|
|
|
|
* exception statement from your version.
|
2008-05-17 17:23:37 +04:00
|
|
|
*/
|
|
|
|
|
2017-03-04 10:03:39 +03:00
|
|
|
#include "server.h"
|
|
|
|
|
2017-04-11 07:07:17 +03:00
|
|
|
#include <QMutableListIterator>
|
2017-03-04 10:03:39 +03:00
|
|
|
#include <QNetworkProxy>
|
|
|
|
#include <QStringList>
|
2017-04-11 07:07:17 +03:00
|
|
|
#include <QTimer>
|
2011-06-05 20:08:30 +04:00
|
|
|
#ifndef QT_NO_OPENSSL
|
2011-05-07 17:48:42 +04:00
|
|
|
#include <QSslSocket>
|
2011-06-05 20:08:30 +04:00
|
|
|
#else
|
|
|
|
#include <QTcpSocket>
|
|
|
|
#endif
|
2017-03-04 10:03:39 +03:00
|
|
|
|
2015-01-28 12:03:22 +03:00
|
|
|
#include "connection.h"
|
2010-03-13 15:21:15 +03:00
|
|
|
|
2017-06-03 17:25:44 +03:00
|
|
|
static const int KEEP_ALIVE_DURATION = 7 * 1000; // milliseconds
|
2017-04-11 07:07:17 +03:00
|
|
|
static const int CONNECTIONS_LIMIT = 500;
|
|
|
|
static const int CONNECTIONS_SCAN_INTERVAL = 2; // seconds
|
|
|
|
|
2015-01-28 12:03:22 +03:00
|
|
|
using namespace Http;
|
|
|
|
|
2015-05-13 18:39:48 +03:00
|
|
|
Server::Server(IRequestHandler *requestHandler, QObject *parent)
|
2015-02-05 19:54:15 +03:00
|
|
|
: QTcpServer(parent)
|
|
|
|
, m_requestHandler(requestHandler)
|
2011-06-05 20:08:30 +04:00
|
|
|
#ifndef QT_NO_OPENSSL
|
2014-08-22 23:08:44 +04:00
|
|
|
, m_https(false)
|
2011-06-05 20:08:30 +04:00
|
|
|
#endif
|
2014-08-22 23:08:44 +04:00
|
|
|
{
|
2017-02-21 01:57:49 +03:00
|
|
|
setProxy(QNetworkProxy::NoProxy);
|
2017-02-05 10:00:58 +03:00
|
|
|
#ifndef QT_NO_OPENSSL
|
|
|
|
QSslSocket::setDefaultCiphers(safeCipherList());
|
|
|
|
#endif
|
2017-04-11 07:07:17 +03:00
|
|
|
|
|
|
|
QTimer *dropConnectionTimer = new QTimer(this);
|
|
|
|
connect(dropConnectionTimer, &QTimer::timeout, this, &Server::dropTimedOutConnection);
|
|
|
|
dropConnectionTimer->start(CONNECTIONS_SCAN_INTERVAL * 1000);
|
2008-05-17 17:23:37 +04:00
|
|
|
}
|
|
|
|
|
2015-01-28 12:03:22 +03:00
|
|
|
Server::~Server()
|
2014-08-22 23:08:44 +04:00
|
|
|
{
|
2008-05-17 17:23:37 +04:00
|
|
|
}
|
|
|
|
|
2017-04-10 15:10:48 +03:00
|
|
|
void Server::incomingConnection(qintptr socketDescriptor)
|
|
|
|
{
|
2017-04-11 07:07:17 +03:00
|
|
|
if (m_connections.size() >= CONNECTIONS_LIMIT) return;
|
|
|
|
|
2017-04-10 15:10:48 +03:00
|
|
|
QTcpSocket *serverSocket;
|
|
|
|
#ifndef QT_NO_OPENSSL
|
|
|
|
if (m_https)
|
|
|
|
serverSocket = new QSslSocket(this);
|
|
|
|
else
|
|
|
|
#endif
|
|
|
|
serverSocket = new QTcpSocket(this);
|
|
|
|
|
2017-04-11 07:07:17 +03:00
|
|
|
if (!serverSocket->setSocketDescriptor(socketDescriptor)) {
|
|
|
|
delete serverSocket;
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2017-04-10 15:10:48 +03:00
|
|
|
#ifndef QT_NO_OPENSSL
|
2017-04-11 07:07:17 +03:00
|
|
|
if (m_https) {
|
|
|
|
static_cast<QSslSocket *>(serverSocket)->setProtocol(QSsl::SecureProtocols);
|
|
|
|
static_cast<QSslSocket *>(serverSocket)->setPrivateKey(m_key);
|
|
|
|
static_cast<QSslSocket *>(serverSocket)->setLocalCertificateChain(m_certificates);
|
|
|
|
static_cast<QSslSocket *>(serverSocket)->setPeerVerifyMode(QSslSocket::VerifyNone);
|
|
|
|
static_cast<QSslSocket *>(serverSocket)->startServerEncryption();
|
2017-04-10 15:10:48 +03:00
|
|
|
}
|
2017-04-11 07:07:17 +03:00
|
|
|
#endif
|
|
|
|
|
|
|
|
Connection *c = new Connection(serverSocket, m_requestHandler, this);
|
|
|
|
m_connections.append(c);
|
|
|
|
}
|
|
|
|
|
|
|
|
void Server::dropTimedOutConnection()
|
|
|
|
{
|
|
|
|
QMutableListIterator<Connection *> i(m_connections);
|
|
|
|
while (i.hasNext()) {
|
|
|
|
auto connection = i.next();
|
|
|
|
if (connection->isClosed() || connection->hasExpired(KEEP_ALIVE_DURATION)) {
|
|
|
|
delete connection;
|
|
|
|
i.remove();
|
|
|
|
}
|
2017-04-10 15:10:48 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2011-06-05 20:08:30 +04:00
|
|
|
#ifndef QT_NO_OPENSSL
|
2017-04-10 15:04:02 +03:00
|
|
|
bool Server::setupHttps(const QByteArray &certificates, const QByteArray &key)
|
2014-08-22 23:08:44 +04:00
|
|
|
{
|
2017-04-10 15:04:02 +03:00
|
|
|
QSslKey sslKey(key, QSsl::Rsa);
|
|
|
|
if (sslKey.isNull())
|
|
|
|
sslKey = QSslKey(key, QSsl::Ec);
|
|
|
|
|
|
|
|
const QList<QSslCertificate> certs = QSslCertificate::fromData(certificates);
|
|
|
|
const bool areCertsValid = !certs.empty() && std::all_of(certs.begin(), certs.end(), [](const QSslCertificate &c) { return !c.isNull(); });
|
|
|
|
|
2017-09-07 03:00:04 +03:00
|
|
|
if (!sslKey.isNull() && areCertsValid) {
|
2017-04-10 15:04:02 +03:00
|
|
|
m_key = sslKey;
|
|
|
|
m_certificates = certs;
|
|
|
|
m_https = true;
|
|
|
|
return true;
|
|
|
|
}
|
2017-09-07 03:00:04 +03:00
|
|
|
else {
|
2017-04-10 15:04:02 +03:00
|
|
|
disableHttps();
|
|
|
|
return false;
|
|
|
|
}
|
2011-06-05 20:08:30 +04:00
|
|
|
}
|
|
|
|
|
2015-01-28 12:03:22 +03:00
|
|
|
void Server::disableHttps()
|
2014-08-22 23:08:44 +04:00
|
|
|
{
|
2015-02-05 19:54:15 +03:00
|
|
|
m_https = false;
|
2016-03-05 10:41:18 +03:00
|
|
|
m_certificates.clear();
|
2015-02-05 19:54:15 +03:00
|
|
|
m_key.clear();
|
2011-06-05 20:08:30 +04:00
|
|
|
}
|
2017-02-05 10:00:58 +03:00
|
|
|
|
|
|
|
QList<QSslCipher> Server::safeCipherList() const
|
|
|
|
{
|
|
|
|
const QStringList badCiphers = {"idea", "rc4"};
|
|
|
|
const QList<QSslCipher> allCiphers = QSslSocket::supportedCiphers();
|
|
|
|
QList<QSslCipher> safeCiphers;
|
|
|
|
foreach (const QSslCipher &cipher, allCiphers) {
|
|
|
|
bool isSafe = true;
|
|
|
|
foreach (const QString &badCipher, badCiphers) {
|
|
|
|
if (cipher.name().contains(badCipher, Qt::CaseInsensitive)) {
|
|
|
|
isSafe = false;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if (isSafe)
|
|
|
|
safeCiphers += cipher;
|
|
|
|
}
|
|
|
|
|
|
|
|
return safeCiphers;
|
|
|
|
}
|
2017-09-07 03:00:04 +03:00
|
|
|
#endif // QT_NO_OPENSSL
|