2020-01-19 20:33:07 +01:00
|
|
|
/*
|
|
|
|
This file is part of TALER
|
2021-08-08 00:00:05 +02:00
|
|
|
Copyright (C) 2019-2021 Taler Systems SA
|
2020-01-19 20:33:07 +01:00
|
|
|
|
|
|
|
TALER is free software; you can redistribute it and/or modify it under the
|
|
|
|
terms of the GNU General Public License as published by the Free Software
|
|
|
|
Foundation; either version 3, or (at your option) any later version.
|
|
|
|
|
|
|
|
TALER is distributed in the hope that it will be useful, but WITHOUT ANY
|
|
|
|
WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
|
|
|
|
A PARTICULAR PURPOSE. See the GNU General Public License for more details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License along with
|
|
|
|
TALER; see the file COPYING. If not, see <http://www.gnu.org/licenses/>
|
|
|
|
*/
|
|
|
|
/**
|
|
|
|
* @file payto.c
|
|
|
|
* @brief Common utility functions for dealing with payto://-URIs
|
|
|
|
* @author Florian Dold
|
|
|
|
*/
|
|
|
|
#include "platform.h"
|
|
|
|
#include "taler_util.h"
|
|
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Prefix of PAYTO URLs.
|
|
|
|
*/
|
|
|
|
#define PAYTO "payto://"
|
|
|
|
|
|
|
|
|
2020-07-27 12:48:48 +02:00
|
|
|
/**
|
2021-08-08 00:00:05 +02:00
|
|
|
* Extract the value under @a key from the URI parameters.
|
2020-07-27 12:48:48 +02:00
|
|
|
*
|
|
|
|
* @param payto_uri the URL to parse
|
2021-08-08 00:00:05 +02:00
|
|
|
* @param search_key key to look for, including "="
|
|
|
|
* @return NULL if the @a key parameter is not found.
|
2020-07-27 12:48:48 +02:00
|
|
|
* The caller should free the returned value.
|
|
|
|
*/
|
2021-08-08 00:00:05 +02:00
|
|
|
static char *
|
|
|
|
payto_get_key (const char *payto_uri,
|
|
|
|
const char *search_key)
|
2020-07-27 12:48:48 +02:00
|
|
|
{
|
|
|
|
const char *key;
|
|
|
|
const char *value_start;
|
|
|
|
const char *value_end;
|
|
|
|
|
|
|
|
key = strchr (payto_uri,
|
|
|
|
(unsigned char) '?');
|
|
|
|
if (NULL == key)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
do {
|
|
|
|
if (0 == strncasecmp (++key,
|
2021-08-08 00:00:05 +02:00
|
|
|
search_key,
|
|
|
|
strlen (search_key)))
|
2020-07-27 12:48:48 +02:00
|
|
|
{
|
|
|
|
value_start = strchr (key,
|
2020-12-04 20:29:18 +01:00
|
|
|
(unsigned char) '=');
|
2020-07-27 12:48:48 +02:00
|
|
|
if (NULL == value_start)
|
|
|
|
return NULL;
|
|
|
|
value_end = strchrnul (value_start,
|
2020-12-04 20:29:18 +01:00
|
|
|
(unsigned char) '&');
|
2020-07-27 12:48:48 +02:00
|
|
|
|
|
|
|
return GNUNET_strndup (value_start + 1,
|
2020-12-04 20:29:18 +01:00
|
|
|
value_end - value_start - 1);
|
2020-07-27 12:48:48 +02:00
|
|
|
}
|
|
|
|
} while ( (key = strchr (key,
|
2020-12-04 20:29:18 +01:00
|
|
|
(unsigned char) '&')) );
|
2020-07-27 12:48:48 +02:00
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
2020-12-04 20:29:18 +01:00
|
|
|
|
2021-08-08 00:00:05 +02:00
|
|
|
/**
|
|
|
|
* Extract the subject value from the URI parameters.
|
|
|
|
*
|
|
|
|
* @param payto_uri the URL to parse
|
|
|
|
* @return NULL if the subject parameter is not found.
|
|
|
|
* The caller should free the returned value.
|
|
|
|
*/
|
|
|
|
char *
|
|
|
|
TALER_payto_get_subject (const char *payto_uri)
|
|
|
|
{
|
|
|
|
return payto_get_key (payto_uri,
|
|
|
|
"subject=");
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2020-01-19 20:33:07 +01:00
|
|
|
/**
|
2020-03-01 13:04:06 +01:00
|
|
|
* Obtain the payment method from a @a payto_uri. The
|
|
|
|
* format of a payto URI is 'payto://$METHOD/$SOMETHING'.
|
|
|
|
* We return $METHOD.
|
2020-01-19 20:33:07 +01:00
|
|
|
*
|
|
|
|
* @param payto_uri the URL to parse
|
|
|
|
* @return NULL on error (malformed @a payto_uri)
|
|
|
|
*/
|
|
|
|
char *
|
|
|
|
TALER_payto_get_method (const char *payto_uri)
|
|
|
|
{
|
|
|
|
const char *start;
|
|
|
|
const char *end;
|
|
|
|
|
2020-03-01 13:04:06 +01:00
|
|
|
if (0 != strncasecmp (payto_uri,
|
|
|
|
PAYTO,
|
|
|
|
strlen (PAYTO)))
|
2020-01-19 20:33:07 +01:00
|
|
|
return NULL;
|
|
|
|
start = &payto_uri[strlen (PAYTO)];
|
|
|
|
end = strchr (start,
|
|
|
|
(unsigned char) '/');
|
|
|
|
if (NULL == end)
|
|
|
|
return NULL;
|
|
|
|
return GNUNET_strndup (start,
|
|
|
|
end - start);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/**
|
2020-03-01 13:04:06 +01:00
|
|
|
* Obtain the account name from a payto URL. The format
|
|
|
|
* of the @a payto URL is 'payto://x-taler-bank/$HOSTNAME/$ACCOUNT[?PARAMS]'.
|
|
|
|
* We check the first part matches, skip over the $HOSTNAME
|
|
|
|
* and return the $ACCOUNT portion.
|
2020-01-19 20:33:07 +01:00
|
|
|
*
|
|
|
|
* @param payto an x-taler-bank payto URL
|
|
|
|
* @return only the account name from the @a payto URL, NULL if not an x-taler-bank
|
|
|
|
* payto URL
|
|
|
|
*/
|
|
|
|
char *
|
|
|
|
TALER_xtalerbank_account_from_payto (const char *payto)
|
|
|
|
{
|
|
|
|
const char *beg;
|
|
|
|
const char *end;
|
|
|
|
|
|
|
|
if (0 != strncasecmp (payto,
|
2020-03-01 13:04:06 +01:00
|
|
|
PAYTO "x-taler-bank/",
|
|
|
|
strlen (PAYTO "x-taler-bank/")))
|
2020-01-19 20:33:07 +01:00
|
|
|
return NULL;
|
2020-03-01 13:04:06 +01:00
|
|
|
beg = strchr (&payto[strlen (PAYTO "x-taler-bank/")],
|
2020-01-19 20:33:07 +01:00
|
|
|
'/');
|
|
|
|
if (NULL == beg)
|
|
|
|
return NULL;
|
2020-03-01 13:04:06 +01:00
|
|
|
beg++; /* now points to $ACCOUNT */
|
2020-01-19 20:33:07 +01:00
|
|
|
end = strchr (beg,
|
|
|
|
'?');
|
|
|
|
if (NULL == end)
|
2020-03-01 13:04:06 +01:00
|
|
|
return GNUNET_strdup (beg); /* optional part is missing */
|
2020-01-19 20:33:07 +01:00
|
|
|
return GNUNET_strndup (beg,
|
|
|
|
end - beg);
|
|
|
|
}
|
2021-08-02 19:38:23 +02:00
|
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Validate payto://iban/ account URL (only account information,
|
|
|
|
* wire subject and amount are ignored).
|
|
|
|
*
|
2021-08-08 00:00:05 +02:00
|
|
|
* @param account_url payto URL to parse
|
2021-08-02 19:38:23 +02:00
|
|
|
* @return NULL on success, otherwise an error message
|
|
|
|
* to be freed by the caller
|
|
|
|
*/
|
|
|
|
static char *
|
|
|
|
validate_payto_iban (const char *account_url)
|
|
|
|
{
|
|
|
|
const char *iban;
|
|
|
|
const char *q;
|
|
|
|
char *result;
|
|
|
|
char *err;
|
|
|
|
|
|
|
|
#define IBAN_PREFIX "payto://iban/"
|
|
|
|
if (0 != strncasecmp (account_url,
|
|
|
|
IBAN_PREFIX,
|
|
|
|
strlen (IBAN_PREFIX)))
|
|
|
|
return NULL; /* not an IBAN */
|
|
|
|
|
|
|
|
iban = strrchr (account_url, '/') + 1;
|
|
|
|
#undef IBAN_PREFIX
|
|
|
|
q = strchr (iban,
|
|
|
|
'?');
|
|
|
|
if (NULL != q)
|
|
|
|
{
|
|
|
|
result = GNUNET_strndup (iban,
|
|
|
|
q - iban);
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
result = GNUNET_strdup (iban);
|
|
|
|
}
|
|
|
|
if (NULL !=
|
2021-08-14 13:54:01 +02:00
|
|
|
(err = TALER_iban_validate (result)))
|
2021-08-02 19:38:23 +02:00
|
|
|
{
|
|
|
|
GNUNET_free (result);
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
GNUNET_free (result);
|
2021-08-08 00:00:05 +02:00
|
|
|
{
|
|
|
|
char *target;
|
|
|
|
|
|
|
|
target = payto_get_key (account_url,
|
|
|
|
"receiver-name=");
|
|
|
|
if (NULL == target)
|
|
|
|
return GNUNET_strdup ("'receiver-name' parameter missing");
|
|
|
|
GNUNET_free (target);
|
|
|
|
}
|
2021-08-02 19:38:23 +02:00
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Check that a payto:// URI is well-formed.
|
|
|
|
*
|
|
|
|
* @param payto_uri the URL to check
|
|
|
|
* @return NULL on success, otherwise an error
|
|
|
|
* message to be freed by the caller!
|
|
|
|
*/
|
|
|
|
char *
|
|
|
|
TALER_payto_validate (const char *payto_uri)
|
|
|
|
{
|
|
|
|
char *ret;
|
|
|
|
const char *start;
|
|
|
|
const char *end;
|
|
|
|
|
|
|
|
if (0 != strncasecmp (payto_uri,
|
|
|
|
PAYTO,
|
|
|
|
strlen (PAYTO)))
|
|
|
|
return GNUNET_strdup ("invalid prefix");
|
|
|
|
for (unsigned int i = 0; '\0' != payto_uri[i]; i++)
|
|
|
|
{
|
|
|
|
/* This is more strict than RFC 8905, alas we do not need to support messages/instructions/etc.,
|
|
|
|
and it is generally better to start with a narrow whitelist; we can be more permissive later ...*/
|
|
|
|
#define ALLOWED_CHARACTERS \
|
|
|
|
"abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789/:&?-.,="
|
|
|
|
if (NULL == strchr (ALLOWED_CHARACTERS,
|
|
|
|
(int) payto_uri[i]))
|
|
|
|
{
|
|
|
|
char *ret;
|
|
|
|
|
|
|
|
GNUNET_asprintf (&ret,
|
|
|
|
"Encountered invalid character `%c' at offset %u in payto URI `%s'",
|
|
|
|
payto_uri[i],
|
|
|
|
i,
|
|
|
|
payto_uri);
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
#undef ALLOWED_CHARACTERS
|
|
|
|
}
|
|
|
|
|
|
|
|
start = &payto_uri[strlen (PAYTO)];
|
|
|
|
end = strchr (start,
|
|
|
|
(unsigned char) '/');
|
|
|
|
if (NULL == end)
|
|
|
|
return GNUNET_strdup ("missing '/' in payload");
|
|
|
|
|
|
|
|
if (NULL != (ret = validate_payto_iban (payto_uri)))
|
|
|
|
return ret; /* got a definitive answer */
|
|
|
|
|
|
|
|
/* Insert other bank account validation methods here later! */
|
|
|
|
|
|
|
|
return NULL;
|
|
|
|
}
|