From d1917db47e9d5a58501cfcee4b4207e201d37306 Mon Sep 17 00:00:00 2001 From: Andrew Hankinson Date: Thu, 4 Dec 2014 15:29:52 -0500 Subject: [PATCH] Fixed: Reworked withCredentials for XMLHTTPRequests Previously, the withCredentials parameter was accessed primarily through the CPURLConnection, which gave limited access to changing the request before it was sent off. This commit removes withCredentials from CPURLConnection and places it on CPURLRequest so that it may be more easily modified prior to sending the request. This also simplifies the logic in CPURLConnection for creating and establishing connections with credentials. In this commit, all CFHTTPRequests are assumed to not use withCredentials unless they are explicitly set. Setting [aURLRequest withCredentials] will set the withCredentials property on the underlying XMLHTTPRequest prior to the connection being opened. --- Foundation/CPURLConnection.j | 36 ++++-------------------------------- Foundation/CPURLRequest.j | 1 + Objective-J/CFHTTPRequest.js | 5 ++++- 3 files changed, 9 insertions(+), 33 deletions(-) diff --git a/Foundation/CPURLConnection.j b/Foundation/CPURLConnection.j index 88a1afbf8..7c4cfd81e 100644 --- a/Foundation/CPURLConnection.j +++ b/Foundation/CPURLConnection.j @@ -81,8 +81,6 @@ var CPURLConnectionDelegate = nil; BOOL _isCanceled; BOOL _isLocalFileConnection; - BOOL _withCredentials @accessors(property=withCredentials); - HTTPRequest _HTTPRequest; } @@ -99,25 +97,12 @@ var CPURLConnectionDelegate = nil; @return the data at the URL or \c nil if there was an error */ + (CPData)sendSynchronousRequest:(CPURLRequest)aRequest returningResponse:(/*{*/CPURLResponse/*}*/)aURLResponse -{ - var cfHTTPRequest = new CFHTTPRequest(); - - return [CPURLConnection _sendSynchronousRequest:aRequest returningResponse:aURLResponse withCFHTTPRequest:cfHTTPRequest]; -} - -+ (CPData)sendSynchronousRequest:(CPURLRequest)aRequest returningResponse:(/*{*/CPURLResponse/*}*/)aURLResponse withCredentials:(BOOL)withCredentials -{ - var cfHTTPRequest = new CFHTTPRequest(); - - cfHTTPRequest.setWithCredentials(withCredentials); - - return [CPURLConnection _sendSynchronousRequest:aRequest returningResponse:aURLResponse withCFHTTPRequest:cfHTTPRequest]; -} - -+ (CPData)_sendSynchronousRequest:(CPURLRequest)aRequest returningResponse:(/*{*/CPURLResponse/*}*/)aURLResponse withCFHTTPRequest:(CFHTTPRequest)aCFHTTPRequest { try { + var aCFHTTPRequest = new CFHTTPRequest(); + aCFHTTPRequest.setWithCredentials([aRequest withCredentials]); + aCFHTTPRequest.open([aRequest HTTPMethod], [[aRequest URL] absoluteString], NO); var fields = [aRequest allHTTPHeaderFields], @@ -152,17 +137,6 @@ var CPURLConnectionDelegate = nil; return [[self alloc] initWithRequest:aRequest delegate:aDelegate]; } -//overloaded method that allows user to set _withCredentials -+ (CPURLConnection)connectionWithRequest:(CPURLRequest)aRequest delegate:(id)aDelegate withCredentials:(BOOL)withCredentials -{ - var connection = [[self alloc] initWithRequest:aRequest delegate:aDelegate startImmediately:NO]; - - [connection setWithCredentials:withCredentials]; - [connection start]; - - return connection; -} - /* Default class initializer. Use one of the class methods instead. @param aRequest contains the URL to contact @@ -179,7 +153,6 @@ var CPURLConnectionDelegate = nil; _request = aRequest; _delegate = aDelegate; _isCanceled = NO; - _withCredentials = NO; var URL = [_request URL], scheme = [URL scheme]; @@ -191,6 +164,7 @@ var CPURLConnectionDelegate = nil; (window.location.protocol === "file:" || window.location.protocol === "app:")); _HTTPRequest = new CFHTTPRequest(); + _HTTPRequest.setWithCredentials([aRequest withCredentials]); if (shouldStartImmediately) [self start]; @@ -219,8 +193,6 @@ var CPURLConnectionDelegate = nil; { _isCanceled = NO; - _HTTPRequest.setWithCredentials(_withCredentials); - try { _HTTPRequest.open([_request HTTPMethod], [[_request URL] absoluteString], YES); diff --git a/Foundation/CPURLRequest.j b/Foundation/CPURLRequest.j index b643264a3..3b93b8d06 100644 --- a/Foundation/CPURLRequest.j +++ b/Foundation/CPURLRequest.j @@ -40,6 +40,7 @@ // FIXME: this should be CPData CPString _HTTPBody @accessors(property=HTTPBody); CPString _HTTPMethod @accessors(property=HTTPMethod); + BOOL _withCredentials @accessors(property=withCredentials); CPDictionary _HTTPHeaderFields @accessors(readonly, getter=allHTTPHeaderFields); } diff --git a/Objective-J/CFHTTPRequest.js b/Objective-J/CFHTTPRequest.js index 6186dc80f..37bdf61e8 100644 --- a/Objective-J/CFHTTPRequest.js +++ b/Objective-J/CFHTTPRequest.js @@ -103,6 +103,9 @@ GLOBAL(CFHTTPRequest) = function() this._eventDispatcher = new EventDispatcher(this); this._nativeRequest = new NativeRequest(); + // by default, all requests will assume that credentials should not be sent. + this._nativeRequest.withCredentials = false; + var self = this; this._stateChangeHandler = function() { @@ -279,7 +282,7 @@ CFHTTPRequest.prototype.setWithCredentials = function(/*Boolean*/ willSendWithCr this._nativeRequest.withCredentials = willSendWithCredentials; }; -CFHTTPRequest.prototype.getWithCredentials = function() +CFHTTPRequest.prototype.withCredentials = function() { return this._nativeRequest.withCredentials; };