1 /****************************************************************************
2 **
3 ** Copyright (C) 2016 The Qt Company Ltd.
4 ** Contact: https://www.qt.io/licensing/
5 **
6 ** This file is part of the QtNetwork module of the Qt Toolkit.
7 **
8 ** $QT_BEGIN_LICENSE:LGPL$
9 ** Commercial License Usage
10 ** Licensees holding valid commercial Qt licenses may use this file in
11 ** accordance with the commercial license agreement provided with the
12 ** Software or, alternatively, in accordance with the terms contained in
13 ** a written agreement between you and The Qt Company. For licensing terms
14 ** and conditions see https://www.qt.io/terms-conditions. For further
15 ** information use the contact form at https://www.qt.io/contact-us.
16 **
17 ** GNU Lesser General Public License Usage
18 ** Alternatively, this file may be used under the terms of the GNU Lesser
19 ** General Public License version 3 as published by the Free Software
20 ** Foundation and appearing in the file LICENSE.LGPL3 included in the
21 ** packaging of this file. Please review the following information to
22 ** ensure the GNU Lesser General Public License version 3 requirements
23 ** will be met: https://www.gnu.org/licenses/lgpl-3.0.html.
24 **
25 ** GNU General Public License Usage
26 ** Alternatively, this file may be used under the terms of the GNU
27 ** General Public License version 2.0 or (at your option) the GNU General
28 ** Public license version 3 or any later version approved by the KDE Free
29 ** Qt Foundation. The licenses are as published by the Free Software
30 ** Foundation and appearing in the file LICENSE.GPL2 and LICENSE.GPL3
31 ** included in the packaging of this file. Please review the following
32 ** information to ensure the GNU General Public License requirements will
33 ** be met: https://www.gnu.org/licenses/gpl-2.0.html and
34 ** https://www.gnu.org/licenses/gpl-3.0.html.
35 **
36 ** $QT_END_LICENSE$
37 **
38 ****************************************************************************/
39 
40 #ifndef QAUTHENTICATOR_P_H
41 #define QAUTHENTICATOR_P_H
42 
43 //
44 //  W A R N I N G
45 //  -------------
46 //
47 // This file is not part of the Qt API.  It exists purely as an
48 // implementation detail.  This header file may change from version to
49 // version without notice, or even be removed.
50 //
51 // We mean it.
52 //
53 
54 #include <QtNetwork/private/qtnetworkglobal_p.h>
55 #include <qhash.h>
56 #include <qbytearray.h>
57 #include <qscopedpointer.h>
58 #include <qstring.h>
59 #include <qauthenticator.h>
60 #include <qvariant.h>
61 
62 QT_BEGIN_NAMESPACE
63 
64 class QHttpResponseHeader;
65 #if QT_CONFIG(sspi) // SSPI
66 class QSSPIWindowsHandles;
67 #elif QT_CONFIG(gssapi) // GSSAPI
68 class QGssApiHandles;
69 #endif
70 
71 class Q_AUTOTEST_EXPORT QAuthenticatorPrivate
72 {
73 public:
74     enum Method { None, Basic, Negotiate, Ntlm, DigestMd5, };
75     QAuthenticatorPrivate();
76     ~QAuthenticatorPrivate();
77 
78     QString user;
79     QString extractedUser;
80     QString password;
81     QVariantHash options;
82     Method method;
83     QString realm;
84     QByteArray challenge;
85 #if QT_CONFIG(sspi) // SSPI
86     QScopedPointer<QSSPIWindowsHandles> sspiWindowsHandles;
87 #elif QT_CONFIG(gssapi) // GSSAPI
88     QScopedPointer<QGssApiHandles> gssApiHandles;
89 #endif
90     bool hasFailed; //credentials have been tried but rejected by server.
91 
92     enum Phase {
93         Start,
94         Phase2,
95         Done,
96         Invalid
97     };
98     Phase phase;
99 
100     // digest specific
101     QByteArray cnonce;
102     int nonceCount;
103 
104     // ntlm specific
105     QString workstation;
106     QString userDomain;
107 
108     QByteArray calculateResponse(const QByteArray &method, const QByteArray &path, const QString& host);
109 
getPrivate(QAuthenticator & auth)110     inline static QAuthenticatorPrivate *getPrivate(QAuthenticator &auth) { return auth.d; }
getPrivate(const QAuthenticator & auth)111     inline static const QAuthenticatorPrivate *getPrivate(const QAuthenticator &auth) { return auth.d; }
112 
113     QByteArray digestMd5Response(const QByteArray &challenge, const QByteArray &method, const QByteArray &path);
114     static QHash<QByteArray, QByteArray> parseDigestAuthenticationChallenge(const QByteArray &challenge);
115 
116     void parseHttpResponse(const QList<QPair<QByteArray, QByteArray> >&, bool isProxy, const QString &host);
117     void updateCredentials();
118 };
119 
120 
121 QT_END_NAMESPACE
122 
123 #endif
124