|
cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
|
application/x-www-form-urlencoded field extraction. More...
#include <stddef.h>#include <stdio.h>#include <string.h>Go to the source code of this file.
Functions | |
| static int | form_hexval (char c) |
Hex nibble value, or -1 if c is not a hex digit. | |
| static size_t | form_field (const char *body, const char *key, char *out, size_t n) |
| Pull one field out of a urlencoded body, percent-decoding it. | |
application/x-www-form-urlencoded field extraction.
Header-only and free of ESP-IDF dependencies on purpose: this is the one piece of the setup portal that parses attacker-shaped input, so it is kept where a host-side test can reach it (tests/units/test_prov_form.cpp).
Definition in file form_parse.h.
|
inlinestatic |
Pull one field out of a urlencoded body, percent-decoding it.
| [in] | body | NUL-terminated request body. |
| [in] | key | Field name to find. |
| [out] | out | Decoded value; always NUL-terminated, empty if not found. |
| [in] | n | Capacity of out, including the NUL. |
strlen(out): a submitted "%00" decodes to a real NUL byte, so "12%003456" writes 9 bytes of which C sees 2. Validate with strlen, and never treat this return value as the length of a string — a length check that passes on 9 while the value in play is "12" is exactly the confusion an attacker submitting escapes is looking for. Definition at line 46 of file form_parse.h.
References form_hexval().
Referenced by clock_post(), fees_post(), network_post(), value_post(), and wifi_post().
|
inlinestatic |
Hex nibble value, or -1 if c is not a hex digit.
Definition at line 24 of file form_parse.h.
Referenced by form_field().