|
1.分析:函數首先擷取認證欄位的長度,然後動態記憶體分配,將osip_www_authenticate_t類型的資料複製成為一個字串,目標地址是dest,但是導致的記憶體泄露也是一大隱患。
2.分析:函數首先將認證資訊添加到資料報文中,然後將認證資訊添加到osip_list鏈表,這將會大大方便函數的釋放。
原始碼1:
int
osip_www_authenticate_to_str (const osip_www_authenticate_t * wwwa, char **dest)
{
size_t len;
char *tmp;
*dest = NULL;
if ((wwwa == NULL) || (wwwa->auth_type == NULL))
return OSIP_BADPARAMETER;
len = strlen (wwwa->auth_type) + 1;
if (wwwa->realm != NULL)
len = len + strlen (wwwa->realm) + 7;
if (wwwa->nonce != NULL)
len = len + strlen (wwwa->nonce) + 8;
len = len + 2;
if (wwwa->domain != NULL)
len = len + strlen (wwwa->domain) + 9;
if (wwwa->opaque != NULL)
len = len + strlen (wwwa->opaque) + 9;
if (wwwa->stale != NULL)
len = len + strlen (wwwa->stale) + 8;
if (wwwa->algorithm != NULL)
len = len + strlen (wwwa->algorithm) + 12;
if (wwwa->qop_options != NULL)
len = len + strlen (wwwa->qop_options) + 6;
tmp = (char *) osip_malloc (len);
if (tmp == NULL)
return OSIP_NOMEM;
*dest = tmp;
tmp = osip_str_append (tmp, wwwa->auth_type);
if (wwwa->realm != NULL)
{
tmp = osip_strn_append (tmp, " realm=", 7);
tmp = osip_str_append (tmp, wwwa->realm);
}
if (wwwa->domain != NULL)
{
tmp = osip_strn_append (tmp, ", domain=", 9);
tmp = osip_str_append (tmp, wwwa->domain);
}
if (wwwa->nonce != NULL)
{
tmp = osip_strn_append (tmp, ", nonce=", 8);
tmp = osip_str_append (tmp, wwwa->nonce);
}
if (wwwa->opaque != NULL)
{
tmp = osip_strn_append (tmp, ", opaque=", 9);
tmp = osip_str_append (tmp, wwwa->opaque);
}
if (wwwa->stale != NULL)
{
tmp = osip_strn_append (tmp, ", stale=", 8);
tmp = osip_str_append (tmp, wwwa->stale);
}
if (wwwa->algorithm != NULL)
{
tmp = osip_strn_append (tmp, ", algorithm=", 12);
tmp = osip_str_append (tmp, wwwa->algorithm);
}
if (wwwa->qop_options != NULL)
{
tmp = osip_strn_append (tmp, ", qop=", 6);
tmp = osip_str_append (tmp, wwwa->qop_options);
}
if (wwwa->realm == NULL)
{
/* remove comma */
len = strlen (wwwa->auth_type);
if ((*dest)[len] == ‘,‘)
(*dest)[len] = ‘ ‘;
}
return OSIP_SUCCESS;
}
原始碼2:
int
osip_message_set_www_authenticate (osip_message_t * sip, const char *hvalue)
{
osip_www_authenticate_t *www_authenticate;
int i;
if (hvalue == NULL || hvalue[0] == ‘\0‘)
return OSIP_SUCCESS;
if (sip == NULL)
return OSIP_BADPARAMETER;
i = osip_www_authenticate_init (&www_authenticate);
if (i != 0)
return i;
i = osip_www_authenticate_parse (www_authenticate, hvalue);
if (i != 0)
{
osip_www_authenticate_free (www_authenticate);
return i;
}
sip->message_property = 2;
osip_list_add (&sip->www_authenticates, www_authenticate, -1);
return OSIP_SUCCESS;
} |