Code:
/ Dotnetfx_Win7_3.5.1 / Dotnetfx_Win7_3.5.1 / 3.5.1 / DEVDIV / depot / DevDiv / releases / whidbey / NetFXspW7 / ndp / fx / src / xsp / System / Web / HttpResponseHeader.cs / 1 / HttpResponseHeader.cs
//------------------------------------------------------------------------------ //// Copyright (c) Microsoft Corporation. All rights reserved. // //----------------------------------------------------------------------------- /* * Single http header representation * * Copyright (c) 1998 Microsoft Corporation */ namespace System.Web { using System.Collections; using System.Text; /* * Response header (either known or unknown) */ internal class HttpResponseHeader { private String _unknownHeader; private int _knownHeaderIndex; private String _value; private static readonly string[] EncodingTable = new string[] { "%00", "%01", "%02", "%03", "%04", "%05", "%06", "%07", "%08", "%09", "%0a", "%0b", "%0c", "%0d", "%0e", "%0f", "%10", "%11", "%12", "%13", "%14", "%15", "%16", "%17", "%18", "%19", "%1a", "%1b", "%1c", "%1d", "%1e", "%1f" }; internal HttpResponseHeader(int knownHeaderIndex, String value) { _unknownHeader = null; _knownHeaderIndex = knownHeaderIndex; // encode header value if if(HttpRuntime.EnableHeaderChecking) { _value = MaybeEncodeHeader(value); } else { _value = value; } } internal HttpResponseHeader(String unknownHeader, String value) { if(HttpRuntime.EnableHeaderChecking) { _unknownHeader = MaybeEncodeHeader(unknownHeader); _knownHeaderIndex = HttpWorkerRequest.GetKnownResponseHeaderIndex(_unknownHeader); _value = MaybeEncodeHeader(value); } else { _unknownHeader = unknownHeader; _knownHeaderIndex = HttpWorkerRequest.GetKnownResponseHeaderIndex(_unknownHeader); _value = value; } } internal virtual String Name { get { if (_unknownHeader != null) return _unknownHeader; else return HttpWorkerRequest.GetKnownResponseHeaderName(_knownHeaderIndex); } } internal String Value { get { return _value;} } internal void Send(HttpWorkerRequest wr) { if (_knownHeaderIndex >= 0) wr.SendKnownResponseHeader(_knownHeaderIndex, _value); else wr.SendUnknownResponseHeader(_unknownHeader, _value); } // Encode the header if it contains a CRLF pair // VSWhidbey 257154 internal static string MaybeEncodeHeader(string value) { string sanitizedHeader = value; if (NeedsEncoding(value)) { // DevDiv Bugs 146028 // Denial Of Service scenarios involving // control characters are possible. // We are encoding the following characters: // - All CTL characters except HT (horizontal tab) // - DEL character (\x7f) StringBuilder sb = new StringBuilder(); foreach (char c in value) { if (c < 32 && c != 9) { sb.Append(EncodingTable[c]); } else if (c == 127) { sb.Append("%7f"); } else { sb.Append(c); } } sanitizedHeader = sb.ToString(); } return sanitizedHeader; } // Returns true if the string contains a control character (other than horizontal tab) or the DEL character. internal static bool NeedsEncoding(string value) { foreach (char c in value) { if ((c < 32 && c != 9) || (c == 127)) { return true; } } return false; } } } // File provided for Reference Use Only by Microsoft Corporation (c) 2007. //------------------------------------------------------------------------------ //// Copyright (c) Microsoft Corporation. All rights reserved. // //----------------------------------------------------------------------------- /* * Single http header representation * * Copyright (c) 1998 Microsoft Corporation */ namespace System.Web { using System.Collections; using System.Text; /* * Response header (either known or unknown) */ internal class HttpResponseHeader { private String _unknownHeader; private int _knownHeaderIndex; private String _value; private static readonly string[] EncodingTable = new string[] { "%00", "%01", "%02", "%03", "%04", "%05", "%06", "%07", "%08", "%09", "%0a", "%0b", "%0c", "%0d", "%0e", "%0f", "%10", "%11", "%12", "%13", "%14", "%15", "%16", "%17", "%18", "%19", "%1a", "%1b", "%1c", "%1d", "%1e", "%1f" }; internal HttpResponseHeader(int knownHeaderIndex, String value) { _unknownHeader = null; _knownHeaderIndex = knownHeaderIndex; // encode header value if if(HttpRuntime.EnableHeaderChecking) { _value = MaybeEncodeHeader(value); } else { _value = value; } } internal HttpResponseHeader(String unknownHeader, String value) { if(HttpRuntime.EnableHeaderChecking) { _unknownHeader = MaybeEncodeHeader(unknownHeader); _knownHeaderIndex = HttpWorkerRequest.GetKnownResponseHeaderIndex(_unknownHeader); _value = MaybeEncodeHeader(value); } else { _unknownHeader = unknownHeader; _knownHeaderIndex = HttpWorkerRequest.GetKnownResponseHeaderIndex(_unknownHeader); _value = value; } } internal virtual String Name { get { if (_unknownHeader != null) return _unknownHeader; else return HttpWorkerRequest.GetKnownResponseHeaderName(_knownHeaderIndex); } } internal String Value { get { return _value;} } internal void Send(HttpWorkerRequest wr) { if (_knownHeaderIndex >= 0) wr.SendKnownResponseHeader(_knownHeaderIndex, _value); else wr.SendUnknownResponseHeader(_unknownHeader, _value); } // Encode the header if it contains a CRLF pair // VSWhidbey 257154 internal static string MaybeEncodeHeader(string value) { string sanitizedHeader = value; if (NeedsEncoding(value)) { // DevDiv Bugs 146028 // Denial Of Service scenarios involving // control characters are possible. // We are encoding the following characters: // - All CTL characters except HT (horizontal tab) // - DEL character (\x7f) StringBuilder sb = new StringBuilder(); foreach (char c in value) { if (c < 32 && c != 9) { sb.Append(EncodingTable[c]); } else if (c == 127) { sb.Append("%7f"); } else { sb.Append(c); } } sanitizedHeader = sb.ToString(); } return sanitizedHeader; } // Returns true if the string contains a control character (other than horizontal tab) or the DEL character. internal static bool NeedsEncoding(string value) { foreach (char c in value) { if ((c < 32 && c != 9) || (c == 127)) { return true; } } return false; } } } // File provided for Reference Use Only by Microsoft Corporation (c) 2007.
Link Menu

This book is available now!
Buy at Amazon US or
Buy at Amazon UK
- SqlComparer.cs
- InfoCardListRequest.cs
- ValidationHelpers.cs
- OleDbDataAdapter.cs
- LayoutEngine.cs
- PermissionSetEnumerator.cs
- CompiledRegexRunnerFactory.cs
- InputBuffer.cs
- SqlParameterCollection.cs
- SQLMembershipProvider.cs
- SafeFileMapViewHandle.cs
- XPathAxisIterator.cs
- XmlSchemas.cs
- DataGridViewTopLeftHeaderCell.cs
- SQLInt64.cs
- DetailsViewDeleteEventArgs.cs
- httpstaticobjectscollection.cs
- ResourceAttributes.cs
- Point3DCollection.cs
- NameGenerator.cs
- Command.cs
- HtmlWindow.cs
- WebPartAddingEventArgs.cs
- ByteStorage.cs
- WebPartDescriptionCollection.cs
- DataTableTypeConverter.cs
- DataExpression.cs
- IntranetCredentialPolicy.cs
- XmlIlGenerator.cs
- RandomNumberGenerator.cs
- NamedElement.cs
- LinkedList.cs
- ThreadStartException.cs
- XmlCollation.cs
- X509CertificateValidator.cs
- CodeDomSerializerBase.cs
- LowerCaseStringConverter.cs
- XmlSchemaComplexContentRestriction.cs
- SqlDataAdapter.cs
- WindowsPrincipal.cs
- XmlTextEncoder.cs
- InkCanvas.cs
- AliasedSlot.cs
- ContainerVisual.cs
- SqlTriggerContext.cs
- DataStorage.cs
- XmlHierarchyData.cs
- ModelItemCollection.cs
- SystemIPGlobalProperties.cs
- ExpressionParser.cs
- GenericUriParser.cs
- ConnectionConsumerAttribute.cs
- AttachedPropertyMethodSelector.cs
- NegatedCellConstant.cs
- CfgParser.cs
- XamlFrame.cs
- Utility.cs
- CommonDialog.cs
- DataSourceSelectArguments.cs
- FixedMaxHeap.cs
- Compilation.cs
- Queue.cs
- FileChangesMonitor.cs
- SymmetricSecurityBindingElement.cs
- PrincipalPermission.cs
- WebServiceAttribute.cs
- WorkflowElementDialog.cs
- TileBrush.cs
- SqlXmlStorage.cs
- WebPartUtil.cs
- UpdatePanelTrigger.cs
- SaveFileDialog.cs
- QuaternionAnimation.cs
- NotImplementedException.cs
- PtsCache.cs
- EastAsianLunisolarCalendar.cs
- updatecommandorderer.cs
- WebPartConnectionsCancelVerb.cs
- localization.cs
- InnerItemCollectionView.cs
- DataServiceHost.cs
- DetailsViewRow.cs
- RC2CryptoServiceProvider.cs
- TextDecoration.cs
- Int32KeyFrameCollection.cs
- SqlProviderServices.cs
- DataGridViewSelectedColumnCollection.cs
- CustomPopupPlacement.cs
- DurableDispatcherAddressingFault.cs
- FamilyTypefaceCollection.cs
- ListSortDescription.cs
- BitmapPalettes.cs
- util.cs
- AtlasWeb.Designer.cs
- DBPropSet.cs
- StructuredTypeInfo.cs
- CharEnumerator.cs
- SiteMap.cs
- SpotLight.cs
- SqlTypeConverter.cs