Code:
/ FXUpdate3074 / FXUpdate3074 / 1.1 / DEVDIV / depot / DevDiv / releases / whidbey / QFE / ndp / fx / src / xsp / System / Web / HttpResponseHeader.cs / 3 / HttpResponseHeader.cs
//------------------------------------------------------------------------------ //// Copyright (c) Microsoft Corporation. All rights reserved. // //----------------------------------------------------------------------------- /* * Single http header representation * * Copyright (c) 1998 Microsoft Corporation */ namespace System.Web { using System.Collections; using System.Text; /* * Response header (either known or unknown) */ internal class HttpResponseHeader { private String _unknownHeader; private int _knownHeaderIndex; private String _value; private static readonly string[] EncodingTable = new string[] { "%00", "%01", "%02", "%03", "%04", "%05", "%06", "%07", "%08", "%09", "%0a", "%0b", "%0c", "%0d", "%0e", "%0f", "%10", "%11", "%12", "%13", "%14", "%15", "%16", "%17", "%18", "%19", "%1a", "%1b", "%1c", "%1d", "%1e", "%1f" }; internal HttpResponseHeader(int knownHeaderIndex, String value) { _unknownHeader = null; _knownHeaderIndex = knownHeaderIndex; // encode header value if if(HttpRuntime.EnableHeaderChecking) { _value = MaybeEncodeHeader(value); } else { _value = value; } } internal HttpResponseHeader(String unknownHeader, String value) { if(HttpRuntime.EnableHeaderChecking) { _unknownHeader = MaybeEncodeHeader(unknownHeader); _knownHeaderIndex = HttpWorkerRequest.GetKnownResponseHeaderIndex(_unknownHeader); _value = MaybeEncodeHeader(value); } else { _unknownHeader = unknownHeader; _knownHeaderIndex = HttpWorkerRequest.GetKnownResponseHeaderIndex(_unknownHeader); _value = value; } } internal virtual String Name { get { if (_unknownHeader != null) return _unknownHeader; else return HttpWorkerRequest.GetKnownResponseHeaderName(_knownHeaderIndex); } } internal String Value { get { return _value;} } internal void Send(HttpWorkerRequest wr) { if (_knownHeaderIndex >= 0) wr.SendKnownResponseHeader(_knownHeaderIndex, _value); else wr.SendUnknownResponseHeader(_unknownHeader, _value); } // Encode the header if it contains a CRLF pair // internal static string MaybeEncodeHeader(string value) { string sanitizedHeader = value; if (NeedsEncoding(value)) { // DevDiv Bugs 146028 // Denial Of Service scenarios involving // control characters are possible. // We are encoding the following characters: // - All CTL characters except HT (horizontal tab) // - DEL character (\x7f) StringBuilder sb = new StringBuilder(); foreach (char c in value) { if (c < 32 && c != 9) { sb.Append(EncodingTable[c]); } else if (c == 127) { sb.Append("%7f"); } else { sb.Append(c); } } sanitizedHeader = sb.ToString(); } return sanitizedHeader; } // Returns true if the string contains a control character (other than horizontal tab) or the DEL character. internal static bool NeedsEncoding(string value) { foreach (char c in value) { if ((c < 32 && c != 9) || (c == 127)) { return true; } } return false; } } } // File provided for Reference Use Only by Microsoft Corporation (c) 2007. // Copyright (c) Microsoft Corporation. All rights reserved. //------------------------------------------------------------------------------ //// Copyright (c) Microsoft Corporation. All rights reserved. // //----------------------------------------------------------------------------- /* * Single http header representation * * Copyright (c) 1998 Microsoft Corporation */ namespace System.Web { using System.Collections; using System.Text; /* * Response header (either known or unknown) */ internal class HttpResponseHeader { private String _unknownHeader; private int _knownHeaderIndex; private String _value; private static readonly string[] EncodingTable = new string[] { "%00", "%01", "%02", "%03", "%04", "%05", "%06", "%07", "%08", "%09", "%0a", "%0b", "%0c", "%0d", "%0e", "%0f", "%10", "%11", "%12", "%13", "%14", "%15", "%16", "%17", "%18", "%19", "%1a", "%1b", "%1c", "%1d", "%1e", "%1f" }; internal HttpResponseHeader(int knownHeaderIndex, String value) { _unknownHeader = null; _knownHeaderIndex = knownHeaderIndex; // encode header value if if(HttpRuntime.EnableHeaderChecking) { _value = MaybeEncodeHeader(value); } else { _value = value; } } internal HttpResponseHeader(String unknownHeader, String value) { if(HttpRuntime.EnableHeaderChecking) { _unknownHeader = MaybeEncodeHeader(unknownHeader); _knownHeaderIndex = HttpWorkerRequest.GetKnownResponseHeaderIndex(_unknownHeader); _value = MaybeEncodeHeader(value); } else { _unknownHeader = unknownHeader; _knownHeaderIndex = HttpWorkerRequest.GetKnownResponseHeaderIndex(_unknownHeader); _value = value; } } internal virtual String Name { get { if (_unknownHeader != null) return _unknownHeader; else return HttpWorkerRequest.GetKnownResponseHeaderName(_knownHeaderIndex); } } internal String Value { get { return _value;} } internal void Send(HttpWorkerRequest wr) { if (_knownHeaderIndex >= 0) wr.SendKnownResponseHeader(_knownHeaderIndex, _value); else wr.SendUnknownResponseHeader(_unknownHeader, _value); } // Encode the header if it contains a CRLF pair // internal static string MaybeEncodeHeader(string value) { string sanitizedHeader = value; if (NeedsEncoding(value)) { // DevDiv Bugs 146028 // Denial Of Service scenarios involving // control characters are possible. // We are encoding the following characters: // - All CTL characters except HT (horizontal tab) // - DEL character (\x7f) StringBuilder sb = new StringBuilder(); foreach (char c in value) { if (c < 32 && c != 9) { sb.Append(EncodingTable[c]); } else if (c == 127) { sb.Append("%7f"); } else { sb.Append(c); } } sanitizedHeader = sb.ToString(); } return sanitizedHeader; } // Returns true if the string contains a control character (other than horizontal tab) or the DEL character. internal static bool NeedsEncoding(string value) { foreach (char c in value) { if ((c < 32 && c != 9) || (c == 127)) { return true; } } return false; } } } // File provided for Reference Use Only by Microsoft Corporation (c) 2007. // Copyright (c) Microsoft Corporation. All rights reserved.
Link Menu

This book is available now!
Buy at Amazon US or
Buy at Amazon UK
- MailMessageEventArgs.cs
- DefaultHttpHandler.cs
- CallbackValidatorAttribute.cs
- ActivityPreviewDesigner.cs
- IOThreadScheduler.cs
- OdbcError.cs
- WebEvents.cs
- DataObjectPastingEventArgs.cs
- PopupControlService.cs
- Brush.cs
- ConnectionConsumerAttribute.cs
- TypeElement.cs
- TypeNameConverter.cs
- ScriptingAuthenticationServiceSection.cs
- CorrelationManager.cs
- BinaryEditor.cs
- HostedHttpTransportManager.cs
- ToolStripContainerDesigner.cs
- PathSegmentCollection.cs
- ListDictionaryInternal.cs
- QueryStringHandler.cs
- OdbcParameter.cs
- InvalidOleVariantTypeException.cs
- TreeNodeEventArgs.cs
- SortedDictionary.cs
- AnnotationComponentChooser.cs
- XmlWriterTraceListener.cs
- BamlResourceDeserializer.cs
- HttpListenerElement.cs
- InputScope.cs
- CodeThrowExceptionStatement.cs
- ServiceNameElementCollection.cs
- RegexCaptureCollection.cs
- ByteAnimationUsingKeyFrames.cs
- Model3DGroup.cs
- IntSecurity.cs
- Gdiplus.cs
- ContentFileHelper.cs
- FileSystemInfo.cs
- SiteMapNode.cs
- CreateUserWizardDesigner.cs
- LocalizationComments.cs
- ComplexLine.cs
- OdbcConnection.cs
- SqlDataRecord.cs
- WebBaseEventKeyComparer.cs
- IdleTimeoutMonitor.cs
- Label.cs
- While.cs
- AsyncDataRequest.cs
- DBPropSet.cs
- CheckedListBox.cs
- StickyNoteContentControl.cs
- ScriptBehaviorDescriptor.cs
- Assembly.cs
- SafeIUnknown.cs
- XmlQueryStaticData.cs
- ImageCodecInfo.cs
- OuterGlowBitmapEffect.cs
- StoreItemCollection.cs
- DataGridViewCellPaintingEventArgs.cs
- XPathAxisIterator.cs
- StringConcat.cs
- MatcherBuilder.cs
- ThousandthOfEmRealDoubles.cs
- LayoutEvent.cs
- DataBoundControl.cs
- AutomationIdentifierGuids.cs
- TextUtf8RawTextWriter.cs
- ExtentJoinTreeNode.cs
- HttpTransportBindingElement.cs
- HttpModuleActionCollection.cs
- WasEndpointConfigContainer.cs
- ListBindingHelper.cs
- CaseExpr.cs
- SqlCharStream.cs
- RequestCache.cs
- ScriptManager.cs
- ActivityBindForm.cs
- AutoGeneratedField.cs
- OracleConnectionFactory.cs
- ListBindingConverter.cs
- HtmlTableCell.cs
- TriggerActionCollection.cs
- Input.cs
- TargetControlTypeAttribute.cs
- UnsafeNativeMethods.cs
- CompositeControl.cs
- ResXResourceWriter.cs
- FrameworkContextData.cs
- SystemGatewayIPAddressInformation.cs
- PnrpPermission.cs
- pingexception.cs
- SystemIcmpV4Statistics.cs
- XmlNamedNodeMap.cs
- XmlCountingReader.cs
- DuplicateWaitObjectException.cs
- ByteRangeDownloader.cs
- COM2PropertyDescriptor.cs
- Thickness.cs