XMLHttpRequest.js 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643
  1. /**
  2. * Wrapper for built-in http.js to emulate the browser XMLHttpRequest object.
  3. *
  4. * This can be used with JS designed for browsers to improve reuse of code and
  5. * allow the use of existing libraries.
  6. *
  7. * Usage: include("XMLHttpRequest.js") and use XMLHttpRequest per W3C specs.
  8. *
  9. * @author Dan DeFelippi <dan@driverdan.com>
  10. * @contributor David Ellis <d.f.ellis@ieee.org>
  11. * @license MIT
  12. */
  13. var fs = require('fs');
  14. var Url = require('url');
  15. var spawn = require('child_process').spawn;
  16. /**
  17. * Module exports.
  18. */
  19. module.exports = XMLHttpRequest;
  20. // backwards-compat
  21. XMLHttpRequest.XMLHttpRequest = XMLHttpRequest;
  22. /**
  23. * `XMLHttpRequest` constructor.
  24. *
  25. * Supported options for the `opts` object are:
  26. *
  27. * - `agent`: An http.Agent instance; http.globalAgent may be used; if 'undefined', agent usage is disabled
  28. *
  29. * @param {Object} opts optional "options" object
  30. */
  31. function XMLHttpRequest(opts) {
  32. /**
  33. * Private variables
  34. */
  35. var self = this;
  36. var http = require('http');
  37. var https = require('https');
  38. // Holds http.js objects
  39. var request;
  40. var response;
  41. // Request settings
  42. var settings = {};
  43. // Disable header blacklist.
  44. // Not part of XHR specs.
  45. var disableHeaderCheck = false;
  46. // Set some default headers
  47. var defaultHeaders = {
  48. "User-Agent": "node-XMLHttpRequest",
  49. "Accept": "*/*"
  50. };
  51. var headers = defaultHeaders;
  52. // These headers are not user setable.
  53. // The following are allowed but banned in the spec:
  54. // * user-agent
  55. var forbiddenRequestHeaders = [
  56. "accept-charset",
  57. "accept-encoding",
  58. "access-control-request-headers",
  59. "access-control-request-method",
  60. "connection",
  61. "content-length",
  62. "content-transfer-encoding",
  63. "cookie",
  64. "cookie2",
  65. "date",
  66. "expect",
  67. "host",
  68. "keep-alive",
  69. "origin",
  70. "referer",
  71. "te",
  72. "trailer",
  73. "transfer-encoding",
  74. "upgrade",
  75. "via"
  76. ];
  77. // These request methods are not allowed
  78. var forbiddenRequestMethods = [
  79. "TRACE",
  80. "TRACK",
  81. "CONNECT"
  82. ];
  83. // Send flag
  84. var sendFlag = false;
  85. // Error flag, used when errors occur or abort is called
  86. var errorFlag = false;
  87. // Event listeners
  88. var listeners = {};
  89. /**
  90. * Constants
  91. */
  92. this.UNSENT = 0;
  93. this.OPENED = 1;
  94. this.HEADERS_RECEIVED = 2;
  95. this.LOADING = 3;
  96. this.DONE = 4;
  97. /**
  98. * Public vars
  99. */
  100. // Current state
  101. this.readyState = this.UNSENT;
  102. // default ready state change handler in case one is not set or is set late
  103. this.onreadystatechange = null;
  104. // Result & response
  105. this.responseText = "";
  106. this.responseXML = "";
  107. this.status = null;
  108. this.statusText = null;
  109. /**
  110. * Private methods
  111. */
  112. /**
  113. * Check if the specified header is allowed.
  114. *
  115. * @param string header Header to validate
  116. * @return boolean False if not allowed, otherwise true
  117. */
  118. var isAllowedHttpHeader = function(header) {
  119. return disableHeaderCheck || (header && forbiddenRequestHeaders.indexOf(header.toLowerCase()) === -1);
  120. };
  121. /**
  122. * Check if the specified method is allowed.
  123. *
  124. * @param string method Request method to validate
  125. * @return boolean False if not allowed, otherwise true
  126. */
  127. var isAllowedHttpMethod = function(method) {
  128. return (method && forbiddenRequestMethods.indexOf(method) === -1);
  129. };
  130. /**
  131. * Public methods
  132. */
  133. /**
  134. * Open the connection. Currently supports local server requests.
  135. *
  136. * @param string method Connection method (eg GET, POST)
  137. * @param string url URL for the connection.
  138. * @param boolean async Asynchronous connection. Default is true.
  139. * @param string user Username for basic authentication (optional)
  140. * @param string password Password for basic authentication (optional)
  141. */
  142. this.open = function(method, url, async, user, password) {
  143. this.abort();
  144. errorFlag = false;
  145. // Check for valid request method
  146. if (!isAllowedHttpMethod(method)) {
  147. throw "SecurityError: Request method not allowed";
  148. }
  149. settings = {
  150. "method": method,
  151. "url": url.toString(),
  152. "async": (typeof async !== "boolean" ? true : async),
  153. "user": user || null,
  154. "password": password || null
  155. };
  156. setState(this.OPENED);
  157. };
  158. /**
  159. * Disables or enables isAllowedHttpHeader() check the request. Enabled by default.
  160. * This does not conform to the W3C spec.
  161. *
  162. * @param boolean state Enable or disable header checking.
  163. */
  164. this.setDisableHeaderCheck = function(state) {
  165. disableHeaderCheck = state;
  166. };
  167. /**
  168. * Sets a header for the request.
  169. *
  170. * @param string header Header name
  171. * @param string value Header value
  172. */
  173. this.setRequestHeader = function(header, value) {
  174. if (this.readyState != this.OPENED) {
  175. throw "INVALID_STATE_ERR: setRequestHeader can only be called when state is OPEN";
  176. }
  177. if (!isAllowedHttpHeader(header)) {
  178. console.warn('Refused to set unsafe header "' + header + '"');
  179. return;
  180. }
  181. if (sendFlag) {
  182. throw "INVALID_STATE_ERR: send flag is true";
  183. }
  184. headers[header] = value;
  185. };
  186. /**
  187. * Gets a header from the server response.
  188. *
  189. * @param string header Name of header to get.
  190. * @return string Text of the header or null if it doesn't exist.
  191. */
  192. this.getResponseHeader = function(header) {
  193. if (typeof header === "string"
  194. && this.readyState > this.OPENED
  195. && response.headers[header.toLowerCase()]
  196. && !errorFlag
  197. ) {
  198. return response.headers[header.toLowerCase()];
  199. }
  200. return null;
  201. };
  202. /**
  203. * Gets all the response headers.
  204. *
  205. * @return string A string with all response headers separated by CR+LF
  206. */
  207. this.getAllResponseHeaders = function() {
  208. if (this.readyState < this.HEADERS_RECEIVED || errorFlag) {
  209. return "";
  210. }
  211. var result = "";
  212. for (var i in response.headers) {
  213. // Cookie headers are excluded
  214. if (i !== "set-cookie" && i !== "set-cookie2") {
  215. result += i + ": " + response.headers[i] + "\r\n";
  216. }
  217. }
  218. return result.substr(0, result.length - 2);
  219. };
  220. /**
  221. * Gets a request header
  222. *
  223. * @param string name Name of header to get
  224. * @return string Returns the request header or empty string if not set
  225. */
  226. this.getRequestHeader = function(name) {
  227. // @TODO Make this case insensitive
  228. if (typeof name === "string" && headers[name]) {
  229. return headers[name];
  230. }
  231. return "";
  232. };
  233. /**
  234. * Sends the request to the server.
  235. *
  236. * @param string data Optional data to send as request body.
  237. */
  238. this.send = function(data) {
  239. if (this.readyState != this.OPENED) {
  240. throw "INVALID_STATE_ERR: connection must be opened before send() is called";
  241. }
  242. if (sendFlag) {
  243. throw "INVALID_STATE_ERR: send has already been called";
  244. }
  245. var ssl = false, local = false;
  246. var url = Url.parse(settings.url);
  247. var host;
  248. // Determine the server
  249. switch (url.protocol) {
  250. case 'https:':
  251. ssl = true;
  252. // SSL & non-SSL both need host, no break here.
  253. case 'http:':
  254. host = url.hostname;
  255. break;
  256. case 'file:':
  257. local = true;
  258. break;
  259. case undefined:
  260. case '':
  261. host = "localhost";
  262. break;
  263. default:
  264. throw "Protocol not supported.";
  265. }
  266. // Load files off the local filesystem (file://)
  267. if (local) {
  268. if (settings.method !== "GET") {
  269. throw "XMLHttpRequest: Only GET method is supported";
  270. }
  271. if (settings.async) {
  272. fs.readFile(url.pathname, 'utf8', function(error, data) {
  273. if (error) {
  274. self.handleError(error);
  275. } else {
  276. self.status = 200;
  277. self.responseText = data;
  278. setState(self.DONE);
  279. }
  280. });
  281. } else {
  282. try {
  283. this.responseText = fs.readFileSync(url.pathname, 'utf8');
  284. this.status = 200;
  285. setState(self.DONE);
  286. } catch(e) {
  287. this.handleError(e);
  288. }
  289. }
  290. return;
  291. }
  292. // Default to port 80. If accessing localhost on another port be sure
  293. // to use http://localhost:port/path
  294. var port = url.port || (ssl ? 443 : 80);
  295. // Add query string if one is used
  296. var uri = url.pathname + (url.search ? url.search : '');
  297. // Set the Host header or the server may reject the request
  298. headers["Host"] = host;
  299. if (!((ssl && port === 443) || port === 80)) {
  300. headers["Host"] += ':' + url.port;
  301. }
  302. // Set Basic Auth if necessary
  303. if (settings.user) {
  304. if (typeof settings.password == "undefined") {
  305. settings.password = "";
  306. }
  307. var authBuf = new Buffer(settings.user + ":" + settings.password);
  308. headers["Authorization"] = "Basic " + authBuf.toString("base64");
  309. }
  310. // Set content length header
  311. if (settings.method === "GET" || settings.method === "HEAD") {
  312. data = null;
  313. } else if (data) {
  314. headers["Content-Length"] = Buffer.isBuffer(data) ? data.length : Buffer.byteLength(data);
  315. if (!headers["Content-Type"]) {
  316. headers["Content-Type"] = "text/plain;charset=UTF-8";
  317. }
  318. } else if (settings.method === "POST") {
  319. // For a post with no data set Content-Length: 0.
  320. // This is required by buggy servers that don't meet the specs.
  321. headers["Content-Length"] = 0;
  322. }
  323. var agent = false;
  324. if (opts && opts.agent) {
  325. agent = opts.agent;
  326. }
  327. var options = {
  328. host: host,
  329. port: port,
  330. path: uri,
  331. method: settings.method,
  332. headers: headers,
  333. agent: agent
  334. };
  335. if (ssl) {
  336. options.pfx = opts.pfx;
  337. options.key = opts.key;
  338. options.passphrase = opts.passphrase;
  339. options.cert = opts.cert;
  340. options.ca = opts.ca;
  341. options.ciphers = opts.ciphers;
  342. options.rejectUnauthorized = opts.rejectUnauthorized;
  343. }
  344. // Reset error flag
  345. errorFlag = false;
  346. // Handle async requests
  347. if (settings.async) {
  348. // Use the proper protocol
  349. var doRequest = ssl ? https.request : http.request;
  350. // Request is being sent, set send flag
  351. sendFlag = true;
  352. // As per spec, this is called here for historical reasons.
  353. self.dispatchEvent("readystatechange");
  354. // Handler for the response
  355. function responseHandler(resp) {
  356. // Set response var to the response we got back
  357. // This is so it remains accessable outside this scope
  358. response = resp;
  359. // Check for redirect
  360. // @TODO Prevent looped redirects
  361. if (response.statusCode === 302 || response.statusCode === 303 || response.statusCode === 307) {
  362. // Change URL to the redirect location
  363. settings.url = response.headers.location;
  364. var url = Url.parse(settings.url);
  365. // Set host var in case it's used later
  366. host = url.hostname;
  367. // Options for the new request
  368. var newOptions = {
  369. hostname: url.hostname,
  370. port: url.port,
  371. path: url.path,
  372. method: response.statusCode === 303 ? 'GET' : settings.method,
  373. headers: headers
  374. };
  375. if (ssl) {
  376. options.pfx = opts.pfx;
  377. options.key = opts.key;
  378. options.passphrase = opts.passphrase;
  379. options.cert = opts.cert;
  380. options.ca = opts.ca;
  381. options.ciphers = opts.ciphers;
  382. options.rejectUnauthorized = opts.rejectUnauthorized;
  383. }
  384. // Issue the new request
  385. request = doRequest(newOptions, responseHandler).on('error', errorHandler);
  386. request.end();
  387. // @TODO Check if an XHR event needs to be fired here
  388. return;
  389. }
  390. response.setEncoding("utf8");
  391. setState(self.HEADERS_RECEIVED);
  392. self.status = response.statusCode;
  393. response.on('data', function(chunk) {
  394. // Make sure there's some data
  395. if (chunk) {
  396. self.responseText += chunk;
  397. }
  398. // Don't emit state changes if the connection has been aborted.
  399. if (sendFlag) {
  400. setState(self.LOADING);
  401. }
  402. });
  403. response.on('end', function() {
  404. if (sendFlag) {
  405. // Discard the 'end' event if the connection has been aborted
  406. setState(self.DONE);
  407. sendFlag = false;
  408. }
  409. });
  410. response.on('error', function(error) {
  411. self.handleError(error);
  412. });
  413. }
  414. // Error handler for the request
  415. function errorHandler(error) {
  416. self.handleError(error);
  417. }
  418. // Create the request
  419. request = doRequest(options, responseHandler).on('error', errorHandler);
  420. // Node 0.4 and later won't accept empty data. Make sure it's needed.
  421. if (data) {
  422. request.write(data);
  423. }
  424. request.end();
  425. self.dispatchEvent("loadstart");
  426. } else { // Synchronous
  427. // Create a temporary file for communication with the other Node process
  428. var contentFile = ".node-xmlhttprequest-content-" + process.pid;
  429. var syncFile = ".node-xmlhttprequest-sync-" + process.pid;
  430. fs.writeFileSync(syncFile, "", "utf8");
  431. // The async request the other Node process executes
  432. var execString = "var http = require('http'), https = require('https'), fs = require('fs');"
  433. + "var doRequest = http" + (ssl ? "s" : "") + ".request;"
  434. + "var options = " + JSON.stringify(options) + ";"
  435. + "var responseText = '';"
  436. + "var req = doRequest(options, function(response) {"
  437. + "response.setEncoding('utf8');"
  438. + "response.on('data', function(chunk) {"
  439. + " responseText += chunk;"
  440. + "});"
  441. + "response.on('end', function() {"
  442. + "fs.writeFileSync('" + contentFile + "', 'NODE-XMLHTTPREQUEST-STATUS:' + response.statusCode + ',' + responseText, 'utf8');"
  443. + "fs.unlinkSync('" + syncFile + "');"
  444. + "});"
  445. + "response.on('error', function(error) {"
  446. + "fs.writeFileSync('" + contentFile + "', 'NODE-XMLHTTPREQUEST-ERROR:' + JSON.stringify(error), 'utf8');"
  447. + "fs.unlinkSync('" + syncFile + "');"
  448. + "});"
  449. + "}).on('error', function(error) {"
  450. + "fs.writeFileSync('" + contentFile + "', 'NODE-XMLHTTPREQUEST-ERROR:' + JSON.stringify(error), 'utf8');"
  451. + "fs.unlinkSync('" + syncFile + "');"
  452. + "});"
  453. + (data ? "req.write('" + data.replace(/'/g, "\\'") + "');":"")
  454. + "req.end();";
  455. // Start the other Node Process, executing this string
  456. var syncProc = spawn(process.argv[0], ["-e", execString]);
  457. var statusText;
  458. while(fs.existsSync(syncFile)) {
  459. // Wait while the sync file is empty
  460. }
  461. self.responseText = fs.readFileSync(contentFile, 'utf8');
  462. // Kill the child process once the file has data
  463. syncProc.stdin.end();
  464. // Remove the temporary file
  465. fs.unlinkSync(contentFile);
  466. if (self.responseText.match(/^NODE-XMLHTTPREQUEST-ERROR:/)) {
  467. // If the file returned an error, handle it
  468. var errorObj = self.responseText.replace(/^NODE-XMLHTTPREQUEST-ERROR:/, "");
  469. self.handleError(errorObj);
  470. } else {
  471. // If the file returned okay, parse its data and move to the DONE state
  472. self.status = self.responseText.replace(/^NODE-XMLHTTPREQUEST-STATUS:([0-9]*),.*/, "$1");
  473. self.responseText = self.responseText.replace(/^NODE-XMLHTTPREQUEST-STATUS:[0-9]*,(.*)/, "$1");
  474. setState(self.DONE);
  475. }
  476. }
  477. };
  478. /**
  479. * Called when an error is encountered to deal with it.
  480. */
  481. this.handleError = function(error) {
  482. this.status = 503;
  483. this.statusText = error;
  484. this.responseText = error.stack;
  485. errorFlag = true;
  486. setState(this.DONE);
  487. };
  488. /**
  489. * Aborts a request.
  490. */
  491. this.abort = function() {
  492. if (request) {
  493. request.abort();
  494. request = null;
  495. }
  496. headers = defaultHeaders;
  497. this.responseText = "";
  498. this.responseXML = "";
  499. errorFlag = true;
  500. if (this.readyState !== this.UNSENT
  501. && (this.readyState !== this.OPENED || sendFlag)
  502. && this.readyState !== this.DONE) {
  503. sendFlag = false;
  504. setState(this.DONE);
  505. }
  506. this.readyState = this.UNSENT;
  507. };
  508. /**
  509. * Adds an event listener. Preferred method of binding to events.
  510. */
  511. this.addEventListener = function(event, callback) {
  512. if (!(event in listeners)) {
  513. listeners[event] = [];
  514. }
  515. // Currently allows duplicate callbacks. Should it?
  516. listeners[event].push(callback);
  517. };
  518. /**
  519. * Remove an event callback that has already been bound.
  520. * Only works on the matching funciton, cannot be a copy.
  521. */
  522. this.removeEventListener = function(event, callback) {
  523. if (event in listeners) {
  524. // Filter will return a new array with the callback removed
  525. listeners[event] = listeners[event].filter(function(ev) {
  526. return ev !== callback;
  527. });
  528. }
  529. };
  530. /**
  531. * Dispatch any events, including both "on" methods and events attached using addEventListener.
  532. */
  533. this.dispatchEvent = function(event) {
  534. if (typeof self["on" + event] === "function") {
  535. self["on" + event]();
  536. }
  537. if (event in listeners) {
  538. for (var i = 0, len = listeners[event].length; i < len; i++) {
  539. listeners[event][i].call(self);
  540. }
  541. }
  542. };
  543. /**
  544. * Changes readyState and calls onreadystatechange.
  545. *
  546. * @param int state New state
  547. */
  548. var setState = function(state) {
  549. if (self.readyState !== state) {
  550. self.readyState = state;
  551. if (settings.async || self.readyState < self.OPENED || self.readyState === self.DONE) {
  552. self.dispatchEvent("readystatechange");
  553. }
  554. if (self.readyState === self.DONE && !errorFlag) {
  555. self.dispatchEvent("load");
  556. // @TODO figure out InspectorInstrumentation::didLoadXHR(cookie)
  557. self.dispatchEvent("loadend");
  558. }
  559. }
  560. };
  561. };