1 // Output an HTML message, modifying it slightly to make sure it plays nice
2 // with the rest of our web framework.
4 // Copyright (c) 2005-2022 by the citadel.org team
6 // This program is open source software. Use, duplication, or
7 // disclosure is subject to the GNU General Public License v3.
12 // Strip surrounding single or double quotes from a string.
13 void stripquotes(char *s) {
25 if (((s[0] == '\"') && (s[len - 1] == '\"')) || ((s[0] == '\'') && (s[len - 1] == '\''))) {
32 // Check to see if a META tag has overridden the declared MIME character set.
34 // charset Character set name (left unchanged if we don't do anything)
35 // meta_http_equiv Content of the "http-equiv" portion of the META tag
36 // meta_content Content of the "content" portion of the META tag
37 void extract_charset_from_meta(char *charset, char *meta_http_equiv, char *meta_content) {
44 if (!meta_http_equiv) {
51 if (strcasecmp(meta_http_equiv, "Content-type")) {
55 ptr = strchr(meta_content, ';');
60 safestrncpy(buf, ++ptr, sizeof buf);
62 if (!strncasecmp(buf, "charset=", 8)) {
63 strcpy(charset, &buf[8]);
65 // The brain-damaged webmail program in Microsoft Exchange declares
66 // a charset of "unicode" when they really mean "UTF-8". GNU iconv
67 // treats "unicode" as an alias for "UTF-16" so we have to manually
68 // fix this here, otherwise messages generated in Exchange webmail
69 // show up as a big pile of weird characters.
70 if (!strcasecmp(charset, "unicode")) {
71 strcpy(charset, "UTF-8");
74 // Remove wandering punctuation
75 if ((ptr = strchr(charset, '\"'))) {
83 // Sanitize and enhance an HTML message for display.
84 // Also convert weird character sets to UTF-8 if necessary.
85 // Also fixup img src="cid:..." type inline images to fetch the image
86 StrBuf *html2html(const char *supplied_charset, int treat_as_wiki, char *roomname, long msgnum, StrBuf *Source) {
92 StrBuf *converted_msg;
93 int buffer_length = 1;
95 int content_length = 0;
100 int script_start_pos = (-1);
104 StrBuf *BodyArea = NULL;
106 iconv_t ic = (iconv_t) (-1);
107 char *ibuf; // Buffer of characters to be converted
108 char *obuf; // Buffer for converted characters
109 size_t ibuflen; // Length of input buffer
110 size_t obuflen; // Length of output buffer
111 char *osav; // Saved pointer to output buffer
113 StrBuf *Target = NewStrBuf();
114 if (Target == NULL) {
118 safestrncpy(charset, supplied_charset, sizeof charset);
119 sprintf(new_window, "<a target=\"%s\" href=", TARGET);
121 content_length = StrLength(Source);
122 msg = (char *) ChrPtr(Source);
123 buffer_length = content_length;
125 // Do a first pass to isolate the message body
128 msgend = &msg[content_length];
130 while (ptr < msgend) {
132 // Advance to next tag
133 ptr = strchr(ptr, '<');
134 if ((ptr == NULL) || (ptr >= msgend))
137 if ((ptr == NULL) || (ptr >= msgend))
140 // Look for META tags. Some messages (particularly in
141 // Asian locales) illegally declare a message's character
142 // set in the HTML instead of in the MIME headers. This
143 // is wrong but we have to work around it anyway.
144 if (!strncasecmp(ptr, "META", 4)) {
150 char *meta_http_equiv;
154 meta_start = &ptr[4];
155 meta_end = strchr(ptr, '>');
156 if ((meta_end != NULL) && (meta_end <= msgend)) {
157 meta_length = meta_end - meta_start + 1;
158 meta = malloc(meta_length + 1);
159 safestrncpy(meta, meta_start, meta_length);
160 meta[meta_length] = 0;
162 if (!strncasecmp(meta, "HTTP-EQUIV=", 11)) {
163 meta_http_equiv = strdup(&meta[11]);
164 spaceptr = strchr(meta_http_equiv, ' ');
165 if (spaceptr != NULL) {
167 meta_content = strdup(++spaceptr);
168 if (!strncasecmp(meta_content, "content=", 8)) {
169 strcpy(meta_content, &meta_content[8]);
170 stripquotes(meta_http_equiv);
171 stripquotes(meta_content);
172 extract_charset_from_meta(charset, meta_http_equiv, meta_content);
176 free(meta_http_equiv);
182 // Any of these tags cause everything up to and including
183 // the tag to be removed.
184 if ((!strncasecmp(ptr, "HTML", 4))
185 || (!strncasecmp(ptr, "HEAD", 4))
186 || (!strncasecmp(ptr, "/HEAD", 5))
187 || (!strncasecmp(ptr, "BODY", 4))) {
190 if (!strncasecmp(ptr, "BODY", 4)) {
193 ptr = strchr(ptr, '>');
194 if ((ptr == NULL) || (ptr >= msgend))
196 if ((pBody != NULL) && (ptr - pBody > 4)) {
198 char *cid_start, *cid_end;
202 while ((isspace(*pBody)) && (pBody < ptr))
204 BodyArea = NewStrBufPlain(NULL, ptr - pBody);
207 src = strstr(pBody, "cid:");
211 while ((*cid_end != '"') && !isspace(*cid_end) && (cid_end < ptr))
214 // copy tag and attributes up to src="cid:
215 StrBufAppendBufPlain(BodyArea, pBody, src - pBody, 0);
217 // add in /webcit/mimepart/<msgno>/CID/
218 // trailing / stops dumb URL filters getting excited
219 StrBufAppendPrintf(BodyArea, "/webcit/mimepart/%ld/", msgnum);
220 StrBufAppendBufPlain(BodyArea, cid_start, cid_end - cid_start, 0);
222 if (ptr - cid_end > 0)
223 StrBufAppendBufPlain(BodyArea, cid_end + 1, ptr - cid_end, 0);
226 StrBufAppendBufPlain(BodyArea, pBody, ptr - pBody, 0);
232 if ((ptr == NULL) || (ptr >= msgend))
237 // Any of these tags cause everything including and following
238 // the tag to be removed.
239 if ((!strncasecmp(ptr, "/HTML", 5)) || (!strncasecmp(ptr, "/BODY", 5))) {
247 if (msgstart > msg) {
248 strcpy(msg, msgstart);
251 // Now go through the message, parsing tags as necessary.
252 converted_msg = NewStrBufPlain(NULL, content_length + 8192);
254 // Convert foreign character sets to UTF-8 if necessary
255 if ((strcasecmp(charset, "us-ascii"))
256 && (strcasecmp(charset, "UTF-8"))
257 && (strcasecmp(charset, ""))
259 syslog(LOG_DEBUG, "Converting %s to UTF-8", charset);
260 ctdl_iconv_open("UTF-8", charset, &ic);
261 if (ic == (iconv_t) (-1)) {
262 syslog(LOG_WARNING, "%s:%d iconv_open() failed: %s", __FILE__, __LINE__, strerror(errno));
265 if (Source == NULL) {
266 if (ic != (iconv_t) (-1)) {
268 ibuflen = content_length;
269 obuflen = content_length + (content_length / 2);
270 obuf = (char *) malloc(obuflen);
272 iconv(ic, &ibuf, &ibuflen, &obuf, &obuflen);
273 content_length = content_length + (content_length / 2) - obuflen;
274 osav[content_length] = 0;
281 if (ic != (iconv_t) (-1)) {
282 StrBuf *Buf = NewStrBufPlain(NULL, StrLength(Source) + 8096);;
283 StrBufConvert(Source, Buf, &ic);
286 msg = (char *) ChrPtr(Source); // TODO: get rid of this.
290 // At this point, the message has been stripped down to
291 // only the content inside the <BODY></BODY> tags, and has
292 // been converted to UTF-8 if it was originally in a foreign
293 // character set. The text is also guaranteed to be null
296 if (converted_msg == NULL) {
297 StrBufAppendPrintf(Target, "Error %d: %s<br>%s:%d", errno, strerror(errno), __FILE__, __LINE__);
301 if (BodyArea != NULL) { // Any attributes that were declared in the <body> tag
302 StrBufAppendBufPlain(converted_msg, HKEY("<div "), 0); // are instead declared in this <div> tag
303 StrBufAppendBuf(converted_msg, BodyArea, 0);
304 StrBufAppendBufPlain(converted_msg, HKEY(">"), 0);
307 msgend = strchr(msg, 0);
308 while (ptr < msgend) {
310 // Try to sanitize the html of any rogue scripts
311 if (!strncasecmp(ptr, "<script", 7)) {
312 if (scriptlevel == 0) {
313 script_start_pos = StrLength(converted_msg);
317 if (!strncasecmp(ptr, "</script", 8)) {
321 // Change mailto: links to WebCit mail, by replacing the
322 // link with one that points back to our mail room. Due to
323 // the way we parse URL's, it'll even handle mailto: links
324 // that have "?subject=" in them.
325 // FIXME change URL syntax for webcit-ng
326 if (!strncasecmp(ptr, "<a href=\"mailto:", 16)) {
327 content_length += 64;
328 StrBufAppendPrintf(converted_msg, "<a href=\"display_enter?force_room=_MAIL_?recp=");
334 // Make external links open in a separate window
335 else if (!strncasecmp(ptr, "<a href=\"", 9)) {
338 if (((strchr(ptr, ':') < strchr(ptr, '/'))) && ((strchr(ptr, '/') < strchr(ptr, '>')))) {
339 // open external links to new window
340 StrBufAppendPrintf(converted_msg, new_window);
343 else if ((treat_as_wiki)
344 && (strncasecmp(ptr, "<a href=\"wiki?", 14))
345 && (strncasecmp(ptr, "<a href=\"dotgoto?", 17))
346 && (strncasecmp(ptr, "<a href=\"knrooms?", 17))
348 content_length += 64;
349 StrBufAppendPrintf(converted_msg, "<a href=\"wiki?go=");
350 //StrBufUrlescAppend(converted_msg, "FIXME ROOM NAME", NULL); // FIXME make compatible with webcit-ng
351 StrBufAppendPrintf(converted_msg, "?page=");
355 StrBufAppendPrintf(converted_msg, "<a href=\"");
360 // Fixup <img src="cid:... ...> to fetch the mime part
361 else if (!strncasecmp(ptr, "<img ", 5)) {
362 char *cid_start, *cid_end;
363 char *tag_end = strchr(ptr, '>');
365 // FIXME - handle this situation (maybe someone opened an <img cid...
366 // and then ended the message)
368 syslog(LOG_DEBUG, "tag_end is null and ptr is:");
369 syslog(LOG_DEBUG, "%s", ptr);
370 syslog(LOG_DEBUG, "Theoretical bytes remaining: %d", (int) (msgend - ptr));
373 src = strstr(ptr, "src=\"cid:");
376 if (src && isspace(*(src - 1))
377 && tag_end && (cid_start = strchr(src, ':'))
378 && (cid_end = strchr(cid_start, '"'))
379 && (cid_end < tag_end)
381 // copy tag and attributes up to src="cid:
382 StrBufAppendBufPlain(converted_msg, ptr, src - ptr, 0);
385 // add in /webcit/mimepart/<msgnum>/CID/
386 // trailing / stops dumb URL filters getting excited
387 StrBufAppendPrintf(converted_msg, " src=\"/ctdl/r/");
388 StrBufXMLEscAppend(converted_msg, NULL, roomname, strlen(roomname), 0);
389 syslog(LOG_DEBUG, "room name is '%s'", roomname);
390 StrBufAppendPrintf(converted_msg, "/%ld/", msgnum);
391 StrBufAppendBufPlain(converted_msg, cid_start, cid_end - cid_start, 0);
392 StrBufAppendBufPlain(converted_msg, "\"", -1, 0);
395 StrBufAppendBufPlain(converted_msg, ptr, tag_end - ptr, 0);
399 // Turn anything that looks like a URL into a real link, as long
400 // as it's not inside a tag already
401 else if ((brak == 0) && (alevel == 0) && ((!strncasecmp(ptr, "http://", 7)) || (!strncasecmp(ptr, "https://", 8)))) {
402 // Find the end of the link
406 strlenptr = strlen(ptr);
407 for (i = 0; i <= strlenptr; ++i) {
424 if ((ptr[i + 2] == ';') ||
425 (ptr[i + 3] == ';') ||
426 (ptr[i + 5] == ';') || (ptr[i + 6] == ';') || (ptr[i + 7] == ';'))
439 linkedchar = ptr[len];
441 // spot for some subject strings tinymce tends to give us.
442 ltreviewptr = strchr(ptr, '<');
443 if (ltreviewptr != NULL) {
445 linklen = ltreviewptr - ptr;
448 nbspreviewptr = strstr(ptr, " ");
449 if (nbspreviewptr != NULL) {
450 // nbspreviewptr = '\0';
451 linklen = nbspreviewptr - ptr;
453 if (ltreviewptr != 0)
456 ptr[len] = linkedchar;
458 content_length += (32 + linklen);
459 StrBufAppendPrintf(converted_msg, "%s\"", new_window);
460 StrBufAppendBufPlain(converted_msg, ptr, linklen, 0);
461 StrBufAppendPrintf(converted_msg, "\">");
462 StrBufAppendBufPlain(converted_msg, ptr, linklen, 0);
464 StrBufAppendPrintf(converted_msg, "</a>");
468 StrBufAppendBufPlain(converted_msg, ptr, 1, 0);
472 if ((ptr >= msg) && (ptr <= msgend)) {
473 // We need to know when we're inside a tag,
474 // so we don't turn things that look like URL's into
475 // links, when they're already links - or image sources.
476 if ((ptr > msg) && (*(ptr - 1) == '<')) {
479 if ((ptr > msg) && (*(ptr - 1) == '>')) {
481 if ((scriptlevel == 0) && (script_start_pos >= 0)) {
482 StrBufCutRight(converted_msg, StrLength(converted_msg) - script_start_pos);
483 script_start_pos = (-1);
486 if (!strncasecmp(ptr, "</a>", 3))
491 if (BodyArea != NULL) {
492 StrBufAppendBufPlain(converted_msg, HKEY("</div>"), 0); // Close the div where we declared attributes copied
493 FreeStrBuf(&BodyArea); // from the original <body> tag
496 // uncomment these two lines to override conversion
497 // memcpy(converted_msg, msg, content_length);
498 // output_length = content_length;
500 // Output our big pile of markup
501 StrBufAppendBuf(Target, converted_msg, 0);
503 BAIL: // A little trailing vertical whitespace...
504 StrBufAppendPrintf(Target, "<br>\n");
506 // Now give back the memory
507 FreeStrBuf(&converted_msg);
508 if ((msg != NULL) && (Source == NULL))
514 // Look for URL's embedded in a buffer and make them linkable. We use a
515 // target window in order to keep the Citadel session in its own window.
516 void UrlizeText(StrBuf * Target, StrBuf * Source, StrBuf * WrkBuf) {
517 int len, UrlLen, Offset, TrailerLen;
518 const char *start, *end, *pos;
522 len = StrLength(Source);
523 end = ChrPtr(Source) + len;
524 for (pos = ChrPtr(Source); (pos < end) && (start == NULL); ++pos) {
525 if (!strncasecmp(pos, "http://", 7))
527 else if (!strncasecmp(pos, "ftp://", 6))
532 StrBufAppendBuf(Target, Source, 0);
537 for (pos = ChrPtr(Source) + len; pos > start; --pos) {
557 UrlLen = end - start;
558 StrBufAppendBufPlain(WrkBuf, start, UrlLen, 0);
560 Offset = start - ChrPtr(Source);
562 StrBufAppendBufPlain(Target, ChrPtr(Source), Offset, 0);
563 StrBufAppendPrintf(Target, "%ca href=%c%s%c TARGET=%c%s%c%c%s%c/A%c",
564 LB, QU, ChrPtr(WrkBuf), QU, QU, TARGET, QU, RB, ChrPtr(WrkBuf), LB, RB);
566 TrailerLen = StrLength(Source) - (end - ChrPtr(Source));
568 StrBufAppendBufPlain(Target, end, TrailerLen, 0);
572 void url(char *buf, size_t bufsize) {
573 int len, UrlLen, Offset, TrailerLen, outpos;
574 char *start, *end, *pos;
581 syslog(LOG_WARNING, "URL: content longer than buffer!");
585 for (pos = buf; (pos < end) && (start == NULL); ++pos) {
586 if (!strncasecmp(pos, "http://", 7))
588 if (!strncasecmp(pos, "ftp://", 6))
595 for (pos = buf + len; pos > start; --pos) {
615 UrlLen = end - start;
616 if (UrlLen > sizeof(urlbuf)) {
617 syslog(LOG_WARNING, "URL: content longer than buffer!");
620 memcpy(urlbuf, start, UrlLen);
621 urlbuf[UrlLen] = '\0';
623 Offset = start - buf;
624 if ((Offset != 0) && (Offset < sizeof(outbuf)))
625 memcpy(outbuf, buf, Offset);
626 outpos = snprintf(&outbuf[Offset], sizeof(outbuf) - Offset,
627 "%ca href=%c%s%c TARGET=%c%s%c%c%s%c/A%c", LB, QU, urlbuf, QU, QU, TARGET, QU, RB, urlbuf, LB, RB);
628 if (outpos >= sizeof(outbuf) - Offset) {
629 syslog(LOG_WARNING, "URL: content longer than buffer!");
633 TrailerLen = len - (end - start);
635 memcpy(outbuf + Offset + outpos, end, TrailerLen);
636 if (Offset + outpos + TrailerLen > bufsize) {
637 syslog(LOG_WARNING, "URL: content longer than buffer!");
640 memcpy(buf, outbuf, Offset + outpos + TrailerLen);
641 *(buf + Offset + outpos + TrailerLen) = '\0';