MCPcopy Create free account
hub / github.com/Bitcoin-ABC/bitcoin-abc / ProcessHTTPRequest

Method ProcessHTTPRequest

src/httprpc.cpp:289–401  ·  view source on GitHub ↗

Source from the content-addressed store, hash-verified

287}
288
289bool HTTPRPCRequestProcessor::ProcessHTTPRequest(HTTPRequest *req) {
290 // First, check and/or set CORS headers
291 if (checkCORS(req)) {
292 return true;
293 }
294
295 // JSONRPC handles only POST
296 if (req->GetRequestMethod() != HTTPRequest::POST) {
297 req->WriteReply(HTTP_BAD_METHOD,
298 "JSONRPC server handles only POST requests");
299 return false;
300 }
301 // Check authorization
302 std::pair<bool, std::string> authHeader = req->GetHeader("authorization");
303 if (!authHeader.first) {
304 req->WriteHeader("WWW-Authenticate", WWW_AUTH_HEADER_DATA);
305 req->WriteReply(HTTP_UNAUTHORIZED);
306 return false;
307 }
308
309 JSONRPCRequest jreq;
310 jreq.context = context;
311 jreq.peerAddr = req->GetPeer().ToStringAddrPort();
312 if (!RPCAuthorized(authHeader.second, jreq.authUser)) {
313 LogPrintf("ThreadRPCServer incorrect password attempt from %s\n",
314 jreq.peerAddr);
315
316 /**
317 * Deter brute-forcing.
318 * If this results in a DoS the user really shouldn't have their RPC
319 * port exposed.
320 */
321 UninterruptibleSleep(
322 std::chrono::milliseconds{RPC_AUTH_BRUTE_FORCE_DELAY});
323
324 req->WriteHeader("WWW-Authenticate", WWW_AUTH_HEADER_DATA);
325 req->WriteReply(HTTP_UNAUTHORIZED);
326 return false;
327 }
328
329 try {
330 // Parse request
331 UniValue valRequest;
332 if (!valRequest.read(req->ReadBody())) {
333 throw JSONRPCError(RPC_PARSE_ERROR, "Parse error");
334 }
335
336 // Set the URI
337 jreq.URI = req->GetURI();
338
339 std::string strReply;
340 bool user_has_whitelist = g_rpc_whitelist.count(jreq.authUser);
341 if (!user_has_whitelist && g_rpc_whitelist_default) {
342 LogPrintf("RPC User %s not allowed to call any methods\n",
343 jreq.authUser);
344 req->WriteReply(HTTP_FORBIDDEN);
345 return false;
346

Callers 1

DelegateHTTPRequestMethod · 0.80

Calls 15

checkCORSFunction · 0.85
RPCAuthorizedFunction · 0.85
UninterruptibleSleepFunction · 0.85
JSONRPCErrorFunction · 0.85
JSONRPCReplyFunction · 0.85
JSONRPCExecBatchFunction · 0.85
JSONErrorReplyFunction · 0.85
GetRequestMethodMethod · 0.80
WriteReplyMethod · 0.80
GetHeaderMethod · 0.80
WriteHeaderMethod · 0.80
ToStringAddrPortMethod · 0.80

Tested by

no test coverage detected