Compare commits

...

13 Commits

12 changed files with 193 additions and 105 deletions
+6 -1
View File
@@ -1,3 +1,4 @@
sudo: false
language: node_js
node_js:
@@ -5,7 +6,11 @@ node_js:
- "0.8"
- "0.10"
- "0.12"
- "iojs"
- "iojs-1"
- "iojs-2"
- "iojs-3"
- "4"
- "5"
before_install:
- '[ "${TRAVIS_NODE_VERSION}" = "0.6" ] && npm conf set strict-ssl false || true'
+14
View File
@@ -1,3 +1,17 @@
### 0.6.3 / 2015-11-06
* Reject draft-76 handshakes if their Sec-WebSocket-Key headers are invalid
* Throw a more helpful error if a client is created with an invalid URL
### 0.6.2 / 2015-07-18
* When the peer sends a close frame with no error code, emit 1000
### 0.6.1 / 2015-07-13
* Use the `buffer.{read,write}UInt{16,32}BE` methods for reading/writing numbers
to buffers rather than including duplicate logic for this
### 0.6.0 / 2015-07-08
* Allow the parser to recover cleanly if event listeners raise an error
+8 -3
View File
@@ -20,6 +20,9 @@ var Client = function(_url, options) {
var uri = url.parse(this.url),
auth = uri.auth && new Buffer(uri.auth, 'utf8').toString('base64');
if (this.VALID_PROTOCOLS.indexOf(uri.protocol) < 0)
throw new Error(this.url + ' is not a valid WebSocket URL');
this._pathname = (uri.pathname || '/') + (uri.search || '');
this._headers.set('Host', uri.host);
@@ -41,6 +44,8 @@ Client.generateKey = function() {
};
var instance = {
VALID_PROTOCOLS: ['ws:', 'wss:'],
proxy: function(origin, options) {
return new Proxy(this, origin, options);
},
@@ -52,11 +57,11 @@ var instance = {
return true;
},
parse: function(data) {
parse: function(chunk) {
if (this.readyState === 3) return;
if (this.readyState > 0) return Hybi.prototype.parse.call(this, data);
if (this.readyState > 0) return Hybi.prototype.parse.call(this, chunk);
this._http.parse(data);
this._http.parse(chunk);
if (!this._http.isComplete()) return;
this._validateHandshake();
+22 -23
View File
@@ -5,7 +5,7 @@ var Base = require('./base'),
var Draft75 = function(request, url, options) {
Base.apply(this, arguments);
this._stage = 0;
this._stage = 0;
this.version = 'hixie-75';
this._headers.set('Upgrade', 'WebSocket');
@@ -23,44 +23,43 @@ var instance = {
return true;
},
parse: function(buffer) {
parse: function(chunk) {
if (this.readyState > 1) return;
this._reader.put(buffer);
this._reader.put(chunk);
this._reader.eachByte(function(data) {
var message, value;
this._reader.eachByte(function(octet) {
var message;
switch (this._stage) {
case -1:
this._body.push(data);
this._body.push(octet);
this._sendHandshakeBody();
break;
case 0:
this._parseLeadingByte(data);
this._parseLeadingByte(octet);
break;
case 1:
value = (data & 0x7F);
this._length = value + 128 * this._length;
this._length = (octet & 0x7F) + 128 * this._length;
if (this._closing && this._length === 0) {
return this.close();
}
else if ((0x80 & data) !== 0x80) {
else if ((octet & 0x80) !== 0x80) {
if (this._length === 0) {
this._stage = 0;
}
else {
this._skipped = 0;
this._stage = 2;
this._stage = 2;
}
}
break;
case 2:
if (data === 0xFF) {
if (octet === 0xFF) {
this._stage = 0;
message = new Buffer(this._buffer).toString('utf8', 0, this._buffer.length);
this.emit('message', new Base.MessageEvent(message));
@@ -71,7 +70,7 @@ var instance = {
if (this._skipped === this._length)
this._stage = 0;
} else {
this._buffer.push(data);
this._buffer.push(octet);
if (this._buffer.length > this._maxLength) return this.close();
}
}
@@ -80,16 +79,16 @@ var instance = {
}, this);
},
frame: function(data) {
if (this.readyState === 0) return this._queue([data]);
frame: function(buffer) {
if (this.readyState === 0) return this._queue([buffer]);
if (this.readyState > 1) return false;
var buffer = new Buffer(data, 'utf8'),
frame = new Buffer(buffer.length + 2);
var payload = new Buffer(buffer, 'utf8'),
frame = new Buffer(payload.length + 2);
frame[0] = 0x00;
frame[buffer.length + 1] = 0xFF;
buffer.copy(frame, 1);
frame[payload.length + 1] = 0xFF;
payload.copy(frame, 1);
this._write(frame);
return true;
@@ -102,15 +101,15 @@ var instance = {
return new Buffer(headers.join('\r\n'), 'utf8');
},
_parseLeadingByte: function(data) {
if ((0x80 & data) === 0x80) {
_parseLeadingByte: function(octet) {
if ((octet & 0x80) === 0x80) {
this._length = 0;
this._stage = 1;
this._stage = 1;
} else {
delete this._length;
delete this._skipped;
this._buffer = [];
this._stage = 2;
this._stage = 2;
}
}
};
+27 -21
View File
@@ -14,14 +14,6 @@ var spacesInKey = function(key) {
return key.match(/ /g).length;
};
var bigEndian = function(number) {
var string = '';
[24, 16, 8, 0].forEach(function(offset) {
string += String.fromCharCode(number >> offset & 0xFF);
});
return string;
};
var Draft76 = function(request, url, options) {
Draft75.apply(this, arguments);
@@ -57,6 +49,24 @@ var instance = {
},
_handshakeResponse: function() {
var headers = this._request.headers,
key1 = headers['sec-websocket-key1'],
number1 = numberFromKey(key1),
spaces1 = spacesInKey(key1),
key2 = headers['sec-websocket-key2'],
number2 = numberFromKey(key2),
spaces2 = spacesInKey(key2);
if (number1 % spaces1 !== 0 || number2 % spaces2 !== 0) {
this.emit('error', new Error('Client sent invalid Sec-WebSocket-Key headers'));
this.close();
return null;
}
this._keyValues = [number1 / spaces1, number2 / spaces2];
var start = 'HTTP/1.1 101 WebSocket Protocol Handshake',
headers = [start, this._headers.toString(), ''];
@@ -65,19 +75,15 @@ var instance = {
_handshakeSignature: function() {
if (this._body.length < this.BODY_SIZE) return null;
var body = new Buffer(this._body.slice(0, this.BODY_SIZE));
var headers = this._request.headers,
key1 = headers['sec-websocket-key1'],
value1 = numberFromKey(key1) / spacesInKey(key1),
key2 = headers['sec-websocket-key2'],
value2 = numberFromKey(key2) / spacesInKey(key2),
md5 = crypto.createHash('md5');
var md5 = crypto.createHash('md5'),
buffer = new Buffer(8 + this.BODY_SIZE);
md5.update(bigEndian(value1));
md5.update(bigEndian(value2));
md5.update(body.toString('binary'));
buffer.writeUInt32BE(this._keyValues[0], 0);
buffer.writeUInt32BE(this._keyValues[1], 4);
new Buffer(this._body).copy(buffer, 8, 0, this.BODY_SIZE);
md5.update(buffer);
return new Buffer(md5.digest('binary'), 'binary');
},
@@ -94,9 +100,9 @@ var instance = {
this.parse(this._body.slice(this.BODY_SIZE));
},
_parseLeadingByte: function(data) {
if (data !== 0xFF)
return Draft75.prototype._parseLeadingByte.call(this, data);
_parseLeadingByte: function(octet) {
if (octet !== 0xFF)
return Draft75.prototype._parseLeadingByte.call(this, octet);
this._closing = true;
this._length = 0;
+38 -49
View File
@@ -60,14 +60,13 @@ Hybi.generateAccept = function(key) {
Hybi.GUID = '258EAFA5-E914-47DA-95CA-C5AB0DC85B11';
var instance = {
BYTE: 255,
FIN: 128,
MASK: 128,
RSV1: 64,
RSV2: 32,
RSV3: 16,
OPCODE: 15,
LENGTH: 127,
FIN: 0x80,
MASK: 0x80,
RSV1: 0x40,
RSV2: 0x20,
RSV3: 0x10,
OPCODE: 0x0F,
LENGTH: 0x7F,
OPCODES: {
continuation: 0,
@@ -82,8 +81,6 @@ var instance = {
MESSAGE_OPCODES: [0, 1, 2],
OPENING_OPCODES: [1, 2],
TWO_POWERS: [0, 1, 2, 3, 4, 5, 6, 7].map(function(n) { return Math.pow(2, 8 * n) }),
ERRORS: {
normal_closure: 1000,
going_away: 1001,
@@ -97,6 +94,7 @@ var instance = {
},
ERROR_CODES: [1000, 1001, 1002, 1003, 1007, 1008, 1009, 1010, 1011],
DEFAULT_ERROR_CODE: 1000,
MIN_RESERVED_ERROR: 3000,
MAX_RESERVED_ERROR: 4999,
@@ -108,8 +106,8 @@ var instance = {
return true;
},
parse: function(data) {
this._reader.put(data);
parse: function(chunk) {
this._reader.put(chunk);
var buffer = true;
while (buffer) {
switch (this._stage) {
@@ -190,27 +188,26 @@ var instance = {
}
},
frame: function(data, type, code) {
if (this.readyState <= 0) return this._queue([data, type, code]);
frame: function(buffer, type, code) {
if (this.readyState <= 0) return this._queue([buffer, type, code]);
if (this.readyState > 2) return false;
if (data instanceof Array) data = new Buffer(data);
if (buffer instanceof Array) buffer = new Buffer(buffer);
var message = new Message(),
isText = (typeof data === 'string'),
payload, buffer;
isText = (typeof buffer === 'string'),
payload, copy;
message.rsv1 = message.rsv2 = message.rsv3 = false;
message.opcode = this.OPCODES[type || (isText ? 'text' : 'binary')];
payload = isText ? new Buffer(data, 'utf8') : data;
payload = isText ? new Buffer(buffer, 'utf8') : buffer;
if (code) {
buffer = payload;
payload = new Buffer(2 + buffer.length);
payload[0] = ~~(code / 256) & this.BYTE;
payload[1] = code & this.BYTE;
buffer.copy(payload, 2);
copy = payload;
payload = new Buffer(2 + copy.length);
payload.writeUInt16BE(code, 0);
copy.copy(payload, 2);
}
message.data = payload;
@@ -247,7 +244,6 @@ var instance = {
header = (length <= 125) ? 2 : (length <= 65535 ? 4 : 10),
offset = header + (frame.masked ? 4 : 0),
buffer = new Buffer(offset + length),
BYTE = this.BYTE,
masked = frame.masked ? this.MASK : 0;
buffer[0] = (frame.final ? this.FIN : 0) |
@@ -260,18 +256,11 @@ var instance = {
buffer[1] = masked | length;
} else if (length <= 65535) {
buffer[1] = masked | 126;
buffer[2] = ~~(length / 256);
buffer[3] = length & BYTE;
buffer.writeUInt16BE(length, 2);
} else {
buffer[1] = masked | 127;
buffer[2] = ~~(length / Math.pow(2, 56)) & BYTE;
buffer[3] = ~~(length / Math.pow(2, 48)) & BYTE;
buffer[4] = ~~(length / Math.pow(2, 40)) & BYTE;
buffer[5] = ~~(length / Math.pow(2, 32)) & BYTE;
buffer[6] = ~~(length / Math.pow(2, 24)) & BYTE;
buffer[7] = ~~(length / Math.pow(2, 16)) & BYTE;
buffer[8] = ~~(length / Math.pow(2, 8)) & BYTE;
buffer[9] = length & BYTE;
buffer.writeUInt32BE(Math.floor(length / 0x100000000), 2);
buffer.writeUInt32BE(length % 0x100000000, 6);
}
if (frame.masked) {
@@ -320,18 +309,18 @@ var instance = {
this._shutdown(this.ERRORS[type], message, true);
},
_parseOpcode: function(data) {
_parseOpcode: function(octet) {
var rsvs = [this.RSV1, this.RSV2, this.RSV3].map(function(rsv) {
return (data & rsv) === rsv;
return (octet & rsv) === rsv;
});
var frame = this._frame = new Frame();
frame.final = (data & this.FIN) === this.FIN;
frame.final = (octet & this.FIN) === this.FIN;
frame.rsv1 = rsvs[0];
frame.rsv2 = rsvs[1];
frame.rsv3 = rsvs[2];
frame.opcode = (data & this.OPCODE);
frame.opcode = (octet & this.OPCODE);
this._stage = 1;
@@ -351,10 +340,10 @@ var instance = {
return this._fail('protocol_error', 'Received new data frame but previous continuous frame is unfinished');
},
_parseLength: function(data) {
_parseLength: function(octet) {
var frame = this._frame;
frame.masked = (data & this.MASK) === this.MASK;
frame.length = (data & this.LENGTH);
frame.masked = (octet & this.MASK) === this.MASK;
frame.length = (octet & this.LENGTH);
if (frame.length >= 0 && frame.length <= 125) {
this._stage = frame.masked ? 3 : 4;
@@ -370,7 +359,7 @@ var instance = {
_parseExtendedLength: function(buffer) {
var frame = this._frame;
frame.length = this._getInteger(buffer);
frame.length = this._readUInt(buffer);
this._stage = frame.masked ? 3 : 4;
@@ -415,7 +404,7 @@ var instance = {
return this._emitMessage(this._message);
if (opcode === this.OPCODES.close) {
code = (payload.length >= 2) ? 256 * payload[0] + payload[1] : null;
code = (payload.length >= 2) ? payload.readUInt16BE(0) : null;
reason = (payload.length > 2) ? this._encode(payload.slice(2)) : null;
if (!(payload.length === 0) &&
@@ -426,7 +415,7 @@ var instance = {
if (payload.length > 125 || (payload.length > 2 && !reason))
code = this.ERRORS.protocol_error;
this._shutdown(code, reason || '');
this._shutdown(code || this.DEFAULT_ERROR_CODE, reason || '');
}
if (opcode === this.OPCODES.ping) {
@@ -470,11 +459,11 @@ var instance = {
return buffer.toString('utf8', 0, buffer.length);
},
_getInteger: function(bytes) {
var number = 0;
for (var i = 0, n = bytes.length; i < n; i++)
number += bytes[i] * this.TWO_POWERS[n - 1 - i];
return number;
_readUInt: function(buffer) {
if (buffer.length === 2) return buffer.readUInt16BE(0);
return buffer.readUInt32BE(0) * 0x100000000 +
buffer.readUInt32BE(4);
}
};
+3 -3
View File
@@ -21,10 +21,10 @@ var instance = {
this.on('error', function() {});
},
parse: function(data) {
if (this._delegate) return this._delegate.parse(data);
parse: function(chunk) {
if (this._delegate) return this._delegate.parse(chunk);
this._http.parse(data);
this._http.parse(chunk);
if (!this._http.isComplete()) return;
this.method = this._http.method;
+4 -4
View File
@@ -87,13 +87,13 @@ HttpParser.prototype.isComplete = function() {
return this._complete;
};
HttpParser.prototype.parse = function(data) {
HttpParser.prototype.parse = function(chunk) {
var offset = (version < 6) ? 1 : 0,
consumed = this._parser.execute(data, 0, data.length) + offset;
consumed = this._parser.execute(chunk, 0, chunk.length) + offset;
if (this._complete)
this.body = (consumed < data.length)
? data.slice(consumed)
this.body = (consumed < chunk.length)
? chunk.slice(consumed)
: new Buffer(0);
};
+1 -1
View File
@@ -5,7 +5,7 @@
, "keywords" : ["websocket"]
, "license" : "MIT"
, "version" : "0.6.0"
, "version" : "0.6.3"
, "engines" : {"node": ">=0.6.0"}
, "main" : "./lib/websocket/driver"
, "dependencies" : {"websocket-extensions": ">=0.1.1"}
+10
View File
@@ -109,6 +109,16 @@ test.describe("Client", function() { with(this) {
}})
}})
describe("with an invalid URL", function() { with(this) {
define("url", function() { return "stream.wikimedia.org/rc" })
it("throws an error", function() { with(this) {
var message
try { driver() } catch (e) { message = e.message }
assertEqual( "stream.wikimedia.org/rc is not a valid WebSocket URL", message )
}})
}})
describe("with custom headers", function() { with(this) {
before(function() { with(this) {
driver().setHeader("User-Agent", "Chrome")
+32
View File
@@ -34,6 +34,7 @@ test.describe("Draft76", function() { with(this) {
var self = this
this._driver.on('open', function(e) { self.open = true })
this._driver.on('message', function(e) { self.message += e.data })
this._driver.on('error', function(e) { self.error = e })
this._driver.on('close', function(e) { self.close = true })
this._driver.io.pipe(this.collector())
this._driver.io.write(this.body())
@@ -81,6 +82,37 @@ test.describe("Draft76", function() { with(this) {
driver().start()
assertEqual( "hixie-76", driver().version )
}})
describe("with an invalid key header", function() { with(this) {
before(function() { with(this) {
request().headers["sec-websocket-key1"] = "2 L785 8o% s9Sy9@V. 4<1P5"
}})
it("writes a closing frame to the socket", function() { with(this) {
expect(driver().io, "emit").given("data", buffer([0xff, 0x00]))
driver().start()
}})
it("does not trigger the onopen event", function() { with(this) {
driver().start()
assertEqual( false, open )
}})
it("triggers the onerror event", function() { with(this) {
driver().start()
assertEqual( "Client sent invalid Sec-WebSocket-Key headers", error.message )
}})
it("triggers the onclose event", function() { with(this) {
driver().start()
assertEqual( true, close )
}})
it("changes the state to closed", function() { with(this) {
driver().start()
assertEqual( "closed", driver().getState() )
}})
}})
}})
describe("frame", function() { with(this) {
+28
View File
@@ -595,6 +595,34 @@ test.describe("Hybi", function() { with(this) {
this.driver().parse([0x88, 0x04, 0x03, 0xe9, 0x4f, 0x4b])
}})
}})
describe("receiving a close frame with a too-short payload", function() { with(this) {
before(function() {
this.driver().parse([0x88, 0x01, 0x03])
})
it("triggers the onclose event with a protocol error", function() { with(this) {
assertEqual( [1002, ""], close )
}})
it("changes the state to closed", function() { with(this) {
assertEqual( "closed", driver().getState() )
}})
}})
describe("receiving a close frame with no code", function() { with(this) {
before(function() { with(this) {
this.driver().parse([0x88, 0x00])
}})
it("triggers the onclose event with code 1000", function() { with(this) {
assertEqual( [1000, ""], close )
}})
it("changes the state to closed", function() { with(this) {
assertEqual( "closed", driver().getState() )
}})
}})
}})
describe("in the closed state", function() { with(this) {