|
20 | 20 | package org.elasticsearch.http.netty4; |
21 | 21 |
|
22 | 22 | import io.netty.buffer.Unpooled; |
| 23 | +import io.netty.channel.Channel; |
23 | 24 | import io.netty.channel.ChannelHandler; |
24 | 25 | import io.netty.channel.ChannelHandlerContext; |
25 | 26 | import io.netty.channel.SimpleChannelInboundHandler; |
26 | 27 | import io.netty.handler.codec.http.DefaultFullHttpRequest; |
| 28 | +import io.netty.handler.codec.http.DefaultHttpHeaders; |
27 | 29 | import io.netty.handler.codec.http.FullHttpRequest; |
| 30 | +import io.netty.handler.codec.http.HttpHeaders; |
28 | 31 | import org.elasticsearch.common.util.concurrent.ThreadContext; |
29 | 32 | import org.elasticsearch.http.netty4.pipelining.HttpPipelinedRequest; |
| 33 | +import org.elasticsearch.rest.RestRequest; |
30 | 34 | import org.elasticsearch.transport.netty4.Netty4Utils; |
31 | 35 |
|
| 36 | +import java.util.Collections; |
| 37 | + |
32 | 38 | @ChannelHandler.Sharable |
33 | 39 | class Netty4HttpRequestHandler extends SimpleChannelInboundHandler<Object> { |
34 | 40 |
|
@@ -56,32 +62,113 @@ protected void channelRead0(ChannelHandlerContext ctx, Object msg) throws Except |
56 | 62 | request = (FullHttpRequest) msg; |
57 | 63 | } |
58 | 64 |
|
59 | | - final FullHttpRequest copy = |
| 65 | + boolean success = false; |
| 66 | + try { |
| 67 | + |
| 68 | + final FullHttpRequest copy = |
| 69 | + new DefaultFullHttpRequest( |
| 70 | + request.protocolVersion(), |
| 71 | + request.method(), |
| 72 | + request.uri(), |
| 73 | + Unpooled.copiedBuffer(request.content()), |
| 74 | + request.headers(), |
| 75 | + request.trailingHeaders()); |
| 76 | + |
| 77 | + Exception badRequestCause = null; |
| 78 | + |
| 79 | + /* |
| 80 | + * We want to create a REST request from the incoming request from Netty. However, creating this request could fail if there |
| 81 | + * are incorrectly encoded parameters, or the Content-Type header is invalid. If one of these specific failures occurs, we |
| 82 | + * attempt to create a REST request again without the input that caused the exception (e.g., we remove the Content-Type header, |
| 83 | + * or skip decoding the parameters). Once we have a request in hand, we then dispatch the request as a bad request with the |
| 84 | + * underlying exception that caused us to treat the request as bad. |
| 85 | + */ |
| 86 | + final Netty4HttpRequest httpRequest; |
| 87 | + { |
| 88 | + Netty4HttpRequest innerHttpRequest; |
| 89 | + try { |
| 90 | + innerHttpRequest = new Netty4HttpRequest(serverTransport.xContentRegistry, copy, ctx.channel()); |
| 91 | + } catch (final RestRequest.ContentTypeHeaderException e) { |
| 92 | + badRequestCause = e; |
| 93 | + innerHttpRequest = requestWithoutContentTypeHeader(copy, ctx.channel(), badRequestCause); |
| 94 | + } catch (final RestRequest.BadParameterException e) { |
| 95 | + badRequestCause = e; |
| 96 | + innerHttpRequest = requestWithoutParameters(copy, ctx.channel()); |
| 97 | + } |
| 98 | + httpRequest = innerHttpRequest; |
| 99 | + } |
| 100 | + |
| 101 | + /* |
| 102 | + * We now want to create a channel used to send the response on. However, creating this channel can fail if there are invalid |
| 103 | + * parameter values for any of the filter_path, human, or pretty parameters. We detect these specific failures via an |
| 104 | + * IllegalArgumentException from the channel constructor and then attempt to create a new channel that bypasses parsing of these |
| 105 | + * parameter values. |
| 106 | + */ |
| 107 | + final Netty4HttpChannel channel; |
| 108 | + { |
| 109 | + Netty4HttpChannel innerChannel; |
| 110 | + try { |
| 111 | + innerChannel = |
| 112 | + new Netty4HttpChannel(serverTransport, httpRequest, pipelinedRequest, detailedErrorsEnabled, threadContext); |
| 113 | + } catch (final IllegalArgumentException e) { |
| 114 | + if (badRequestCause == null) { |
| 115 | + badRequestCause = e; |
| 116 | + } else { |
| 117 | + badRequestCause.addSuppressed(e); |
| 118 | + } |
| 119 | + final Netty4HttpRequest innerRequest = |
| 120 | + new Netty4HttpRequest( |
| 121 | + serverTransport.xContentRegistry, |
| 122 | + Collections.emptyMap(), // we are going to dispatch the request as a bad request, drop all parameters |
| 123 | + copy.uri(), |
| 124 | + copy, |
| 125 | + ctx.channel()); |
| 126 | + innerChannel = |
| 127 | + new Netty4HttpChannel(serverTransport, innerRequest, pipelinedRequest, detailedErrorsEnabled, threadContext); |
| 128 | + } |
| 129 | + channel = innerChannel; |
| 130 | + } |
| 131 | + |
| 132 | + if (request.decoderResult().isFailure()) { |
| 133 | + serverTransport.dispatchBadRequest(httpRequest, channel, request.decoderResult().cause()); |
| 134 | + } else if (badRequestCause != null) { |
| 135 | + serverTransport.dispatchBadRequest(httpRequest, channel, badRequestCause); |
| 136 | + } else { |
| 137 | + serverTransport.dispatchRequest(httpRequest, channel); |
| 138 | + } |
| 139 | + success = true; |
| 140 | + } finally { |
| 141 | + // the request is otherwise released in case of dispatch |
| 142 | + if (success == false && pipelinedRequest != null) { |
| 143 | + pipelinedRequest.release(); |
| 144 | + } |
| 145 | + } |
| 146 | + } |
| 147 | + |
| 148 | + private Netty4HttpRequest requestWithoutContentTypeHeader( |
| 149 | + final FullHttpRequest request, final Channel channel, final Exception badRequestCause) { |
| 150 | + final HttpHeaders headersWithoutContentTypeHeader = new DefaultHttpHeaders(); |
| 151 | + headersWithoutContentTypeHeader.add(request.headers()); |
| 152 | + headersWithoutContentTypeHeader.remove("Content-Type"); |
| 153 | + final FullHttpRequest requestWithoutContentTypeHeader = |
60 | 154 | new DefaultFullHttpRequest( |
61 | 155 | request.protocolVersion(), |
62 | 156 | request.method(), |
63 | 157 | request.uri(), |
64 | | - Unpooled.copiedBuffer(request.content()), |
65 | | - request.headers(), |
66 | | - request.trailingHeaders()); |
67 | | - final Netty4HttpRequest httpRequest; |
| 158 | + request.content(), |
| 159 | + headersWithoutContentTypeHeader, // remove the Content-Type header so as to not parse it again |
| 160 | + request.trailingHeaders()); // Content-Type can not be a trailing header |
68 | 161 | try { |
69 | | - httpRequest = new Netty4HttpRequest(serverTransport.xContentRegistry, copy, ctx.channel()); |
70 | | - } catch (Exception ex) { |
71 | | - if (pipelinedRequest != null) { |
72 | | - pipelinedRequest.release(); |
73 | | - } |
74 | | - throw ex; |
| 162 | + return new Netty4HttpRequest(serverTransport.xContentRegistry, requestWithoutContentTypeHeader, channel); |
| 163 | + } catch (final RestRequest.BadParameterException e) { |
| 164 | + badRequestCause.addSuppressed(e); |
| 165 | + return requestWithoutParameters(requestWithoutContentTypeHeader, channel); |
75 | 166 | } |
76 | | - final Netty4HttpChannel channel = |
77 | | - new Netty4HttpChannel(serverTransport, httpRequest, pipelinedRequest, detailedErrorsEnabled, threadContext); |
| 167 | + } |
78 | 168 |
|
79 | | - if (request.decoderResult().isSuccess()) { |
80 | | - serverTransport.dispatchRequest(httpRequest, channel); |
81 | | - } else { |
82 | | - assert request.decoderResult().isFailure(); |
83 | | - serverTransport.dispatchBadRequest(httpRequest, channel, request.decoderResult().cause()); |
84 | | - } |
| 169 | + private Netty4HttpRequest requestWithoutParameters(final FullHttpRequest request, final Channel channel) { |
| 170 | + // remove all parameters as at least one is incorrectly encoded |
| 171 | + return new Netty4HttpRequest(serverTransport.xContentRegistry, Collections.emptyMap(), request.uri(), request, channel); |
85 | 172 | } |
86 | 173 |
|
87 | 174 | @Override |
|
0 commit comments