FreeRDP
Loading...
Searching...
No Matches
pf_config.c
1
23#include <stdio.h>
24#include <string.h>
25#include <winpr/crt.h>
26#include <winpr/path.h>
27#include <winpr/collections.h>
28#include <winpr/cmdline.h>
29
30#include "pf_server.h"
31#include <freerdp/server/proxy/proxy_config.h>
32
33#include <freerdp/server/proxy/proxy_log.h>
34
35#include <freerdp/crypto/crypto.h>
36#include <freerdp/channels/cliprdr.h>
37#include <freerdp/channels/rdpsnd.h>
38#include <freerdp/channels/audin.h>
39#include <freerdp/channels/rdpdr.h>
40#include <freerdp/channels/disp.h>
41#include <freerdp/channels/rail.h>
42#include <freerdp/channels/rdpei.h>
43#include <freerdp/channels/tsmf.h>
44#include <freerdp/channels/video.h>
45#include <freerdp/channels/rdpecam.h>
46
47#include "pf_utils.h"
48
49#define TAG PROXY_TAG("config")
50
51#define CONFIG_PRINT_SECTION(section) WLog_INFO(TAG, "\t%s:", section)
52#define CONFIG_PRINT_SECTION_KEY(section, key) WLog_INFO(TAG, "\t%s/%s:", section, key)
53#define CONFIG_PRINT_STR(config, key) WLog_INFO(TAG, "\t\t%s: %s", #key, (config)->key)
54#define CONFIG_PRINT_SECRET_STR(config, key) \
55 WLog_INFO(TAG, "\t\t%s: %s", #key, (config)->key ? "********" : nullptr)
56#define CONFIG_PRINT_BOOL(config, key) WLog_INFO(TAG, "\t\t%s: %s", #key, boolstr((config)->key))
57#define CONFIG_PRINT_UINT16(config, key) WLog_INFO(TAG, "\t\t%s: %" PRIu16 "", #key, (config)->key)
58#define CONFIG_PRINT_UINT32(config, key) WLog_INFO(TAG, "\t\t%s: %" PRIu32 "", #key, (config)->key)
59
60static const char* bool_str_true = "true";
61static const char* bool_str_false = "false";
62
63WINPR_ATTR_NODISCARD
64static const char* boolstr(BOOL rc)
65{
66 return rc ? bool_str_true : bool_str_false;
67}
68
69static const char* section_server = "Server";
70static const char* key_host = "Host";
71static const char* key_port = "Port";
72static const char* key_sam_file = "SamFile";
73
74static const char* section_target = "Target";
75static const char* key_target_fixed = "FixedTarget";
76static const char* key_target_user = "User";
77static const char* key_target_pwd = "Password";
78static const char* key_target_domain = "Domain";
79static const char* key_target_tls_seclevel = "TlsSecLevel";
80static const char* key_target_scard_auth = "SmartcardAuth";
81static const char* key_target_scard_cert = "SmartcardCert";
82static const char* key_target_scard_key = "SmartcardKey";
83static const char* key_target_scard_pem_cert = "SmartcardCertPEMContent";
84static const char* key_target_scard_pem_key = "SmartcardKeyPEMContent";
85static const char* key_target_cert_policy = "CertificatePolicy";
86static const char* key_target_cert_pem = "CertificatePEM";
87static const char* key_target_cert_pem_content =
88 "CertificatePEMContent";
89static const char* key_target_cert_hash = "CertificateHash";
91static const char* section_plugins = "Plugins";
92static const char* key_plugins_modules = "Modules";
93static const char* key_plugins_required = "Required";
94
95static const char* section_codecs = "Codecs";
96static const char* key_codecs_rfx = "RFX";
97static const char* key_codecs_nsc = "NSC";
98
99static const char* section_channels = "Channels";
100static const char* key_channels_gfx = "GFX";
101static const char* key_channels_disp = "DisplayControl";
102static const char* key_channels_clip = "Clipboard";
103static const char* key_channels_mic = "AudioInput";
104static const char* key_channels_sound = "AudioOutput";
105static const char* key_channels_rdpdr = "DeviceRedirection";
106static const char* key_channels_video = "VideoRedirection";
107static const char* key_channels_camera = "CameraRedirection";
108static const char* key_channels_rails = "RemoteApp";
109static const char* key_channels_blacklist = "PassthroughIsBlacklist";
110static const char* key_channels_pass = "Passthrough";
111static const char* key_channels_intercept = "Intercept";
112
113static const char* section_input = "Input";
114static const char* key_input_kbd = "Keyboard";
115static const char* key_input_mouse = "Mouse";
116static const char* key_input_multitouch = "Multitouch";
117
118static const char* section_security = "Security";
119static const char* key_security_server_nla = "ServerNlaSecurity";
120static const char* key_security_server_ext = "ServerExtSecurity";
121static const char* key_security_server_tls = "ServerTlsSecurity";
122static const char* key_security_server_rdp = "ServerRdpSecurity";
123static const char* key_security_client_nla = "ClientNlaSecurity";
124static const char* key_security_client_ext = "ClientExtSecurity";
125static const char* key_security_client_tls = "ClientTlsSecurity";
126static const char* key_security_client_rdp = "ClientRdpSecurity";
127static const char* key_security_client_fallback = "ClientAllowFallbackToTls";
128
129static const char* section_certificates = "Certificates";
130static const char* key_private_key_file = "PrivateKeyFile";
131static const char* key_private_key_content = "PrivateKeyContent";
132static const char* key_cert_file = "CertificateFile";
133static const char* key_cert_content = "CertificateContent";
134
135WINPR_ATTR_MALLOC(free, 1)
136static char* pf_config_decode_base64(const char* data, const char* name, size_t* pLength);
137
138WINPR_ATTR_MALLOC(CommandLineParserFree, 1)
139WINPR_ATTR_NODISCARD
140static char** pf_config_parse_comma_separated_list(const char* list, size_t* count)
141{
142 if (!list || !count)
143 return nullptr;
144
145 if (strlen(list) == 0)
146 {
147 *count = 0;
148 return nullptr;
149 }
150
151 return CommandLineParseCommaSeparatedValues(list, count);
152}
153
154WINPR_ATTR_NODISCARD
155static BOOL pf_config_get_uint16(wIniFile* ini, const char* section, const char* key,
156 UINT16* result, BOOL required)
157{
158 int val = 0;
159 const char* strval = nullptr;
160
161 WINPR_ASSERT(result);
162
163 strval = IniFile_GetKeyValueString(ini, section, key);
164 if (!strval && required)
165 {
166 WLog_ERR(TAG, "key '%s.%s' does not exist.", section, key);
167 return FALSE;
168 }
169 else if (!strval)
170 goto out;
171
172 val = IniFile_GetKeyValueInt(ini, section, key);
173 if ((val <= 0) || (val > UINT16_MAX))
174 {
175 WLog_ERR(TAG, "invalid value %d for key '%s.%s'.", val, section, key);
176 return FALSE;
177 }
178
179out:
180 *result = (UINT16)val;
181 return TRUE;
182}
183
184WINPR_ATTR_NODISCARD
185static BOOL pf_config_get_uint32(wIniFile* ini, const char* section, const char* key,
186 UINT32* result, BOOL required)
187{
188 WINPR_ASSERT(result);
189
190 const char* strval = IniFile_GetKeyValueString(ini, section, key);
191 if (!strval)
192 {
193 if (required)
194 WLog_ERR(TAG, "key '%s.%s' does not exist.", section, key);
195 return !required;
196 }
197
198 const int val = IniFile_GetKeyValueInt(ini, section, key);
199 if (val < 0)
200 {
201 WLog_ERR(TAG, "invalid value %d for key '%s.%s'.", val, section, key);
202 return FALSE;
203 }
204
205 *result = (UINT32)val;
206 return TRUE;
207}
208
209WINPR_ATTR_NODISCARD
210static BOOL pf_config_get_bool(wIniFile* ini, const char* section, const char* key, BOOL fallback)
211{
212 int num_value = 0;
213 const char* str_value = nullptr;
214
215 str_value = IniFile_GetKeyValueString(ini, section, key);
216 if (!str_value)
217 {
218 WLog_WARN(TAG, "key '%s.%s' not found, value defaults to %s.", section, key,
219 fallback ? bool_str_true : bool_str_false);
220 return fallback;
221 }
222
223 if (_stricmp(str_value, bool_str_true) == 0)
224 return TRUE;
225 if (_stricmp(str_value, bool_str_false) == 0)
226 return FALSE;
227
228 num_value = IniFile_GetKeyValueInt(ini, section, key);
229
230 return (num_value != 0);
231}
232
233WINPR_ATTR_NODISCARD
234static const char* pf_config_get_str(wIniFile* ini, const char* section, const char* key,
235 BOOL required)
236{
237 const char* value = IniFile_GetKeyValueString(ini, section, key);
238
239 if (!value)
240 {
241 if (required)
242 WLog_ERR(TAG, "key '%s.%s' not found.", section, key);
243 return nullptr;
244 }
245
246 return value;
247}
248
249WINPR_ATTR_NODISCARD
250static BOOL pf_config_copy_string(char** dst, const char* src)
251{
252 WINPR_ASSERT(dst);
253 *dst = nullptr;
254 if (src)
255 *dst = _strdup(src);
256 return TRUE;
257}
258
259WINPR_ATTR_NODISCARD
260static BOOL pf_config_free_and_copy_string(char** dst, const char* src)
261{
262 WINPR_ASSERT(dst);
263 winpr_zfree(*dst);
264 return pf_config_copy_string(dst, src);
265}
266
267WINPR_ATTR_NODISCARD
268static BOOL pf_config_load_server(wIniFile* ini, proxyConfig* config)
269{
270 WINPR_ASSERT(config);
271 const char* host = pf_config_get_str(ini, section_server, key_host, FALSE);
272
273 if (host)
274 {
275 if (!pf_config_free_and_copy_string(&config->Host, host))
276 return FALSE;
277 }
278
279 if (!pf_config_get_uint16(ini, section_server, key_port, &config->Port, FALSE))
280 return FALSE;
281
282 const char* sam = pf_config_get_str(ini, section_server, key_sam_file, FALSE);
283 if (sam)
284 {
285 if (!pf_config_free_and_copy_string(&config->SamFile, sam))
286 return FALSE;
287 }
288
289 return TRUE;
290}
291
292WINPR_ATTR_NODISCARD
293static BOOL pf_config_load_target(wIniFile* ini, proxyConfig* config)
294{
295 const char* target_value = nullptr;
296
297 WINPR_ASSERT(config);
298 config->FixedTarget = pf_config_get_bool(ini, section_target, key_target_fixed, FALSE);
299
300 if (!pf_config_get_uint32(ini, section_target, key_target_tls_seclevel,
301 &config->TargetTlsSecLevel, FALSE))
302 return FALSE;
303
304 if (config->FixedTarget)
305 {
306 if (!pf_config_get_uint16(ini, section_target, key_port, &config->TargetPort, FALSE))
307 return FALSE;
308
309 target_value = pf_config_get_str(ini, section_target, key_host, FALSE);
310 if (target_value)
311 {
312 if (!pf_config_free_and_copy_string(&config->TargetHost, target_value))
313 return FALSE;
314 }
315 }
316
317 target_value = pf_config_get_str(ini, section_target, key_target_user, FALSE);
318 if (target_value)
319 {
320 if (!pf_config_free_and_copy_string(&config->TargetUser, target_value))
321 return FALSE;
322 }
323
324 target_value = pf_config_get_str(ini, section_target, key_target_pwd, FALSE);
325 if (target_value)
326 {
327 if (!pf_config_free_and_copy_string(&config->TargetPassword, target_value))
328 return FALSE;
329 }
330
331 target_value = pf_config_get_str(ini, section_target, key_target_domain, FALSE);
332 if (target_value)
333 {
334 if (!pf_config_free_and_copy_string(&config->TargetDomain, target_value))
335 return FALSE;
336 }
337
338 config->TargetSmartcardAuth =
339 pf_config_get_bool(ini, section_target, key_target_scard_auth, FALSE);
340
341 target_value = pf_config_get_str(ini, section_target, key_target_scard_cert, FALSE);
342 if (target_value)
343 {
344 size_t len = 0;
345 char* pem = crypto_read_pem(target_value, &len);
346 if (!pem)
347 return FALSE;
348 winpr_znfree(config->TargetSmartcardCert, config->TargetSmartcardCertLength);
349 config->TargetSmartcardCert = pem;
350 config->TargetSmartcardCertLength = len;
351 }
352
353 {
354 const char* pem_value =
355 pf_config_get_str(ini, section_target, key_target_scard_pem_cert, FALSE);
356 if (pem_value)
357 {
358 if (target_value)
359 WLog_WARN(TAG, "In section [%s] both, '%s' and '%s' are provided. Ignoring %s",
360 section_target, key_target_scard_cert, key_target_scard_pem_cert,
361 key_target_scard_cert);
362 winpr_znfree(config->TargetSmartcardCert, config->TargetSmartcardCertLength);
363 size_t len = 0;
364 config->TargetSmartcardCert =
365 pf_config_decode_base64(pem_value, key_target_scard_pem_cert, &len);
366 if (!config->TargetSmartcardCert)
367 return FALSE;
368 config->TargetSmartcardCertLength = len;
369 }
370 }
371
372 target_value = pf_config_get_str(ini, section_target, key_target_scard_key, FALSE);
373 if (target_value)
374 {
375 size_t len = 0;
376 char* pem = crypto_read_pem(target_value, &len);
377 if (!pem)
378 return FALSE;
379 winpr_znfree(config->TargetSmartcardKey, config->TargetSmartcardKeyLength);
380 config->TargetSmartcardKey = pem;
381 config->TargetSmartcardKeyLength = len;
382 }
383
384 {
385 const char* pem_value =
386 pf_config_get_str(ini, section_target, key_target_scard_pem_key, FALSE);
387 if (pem_value)
388 {
389 if (target_value)
390 WLog_WARN(TAG, "In section [%s] both, '%s' and '%s' are provided. Ignoring %s",
391 section_target, key_target_scard_key, key_target_scard_pem_key,
392 key_target_scard_key);
393 winpr_znfree(config->TargetSmartcardKey, config->TargetSmartcardKeyLength);
394
395 size_t len = 0;
396 config->TargetSmartcardKey =
397 pf_config_decode_base64(pem_value, key_target_scard_pem_key, &len);
398 if (!config->TargetSmartcardKey)
399 return FALSE;
400 config->TargetSmartcardKeyLength = len;
401 }
402 }
403
404 target_value = pf_config_get_str(ini, section_target, key_target_cert_pem, FALSE);
405 if (target_value)
406 {
407 size_t len = 0;
408 char* pem = crypto_read_pem(target_value, &len);
409 if (!pem)
410 return FALSE;
411 winpr_znfree(config->TargetCertPEM, config->TargetCertPEMLength);
412 config->TargetCertPEM = pem;
413 config->TargetCertPEMLength = len;
414 }
415
416 target_value = pf_config_get_str(ini, section_target, key_target_cert_pem_content, FALSE);
417 if (target_value)
418 {
419 const char* pem_value = pf_config_get_str(ini, section_target, key_target_cert_pem, FALSE);
420 if (pem_value)
421 WLog_WARN(TAG, "In section [%s] both, '%s' and '%s' are provided. Ignoring %s",
422 section_target, key_target_cert_pem, key_target_cert_pem_content,
423 key_target_cert_pem);
424
425 winpr_znfree(config->TargetCertPEM, config->TargetCertPEMLength);
426 config->TargetCertPEM = pf_config_decode_base64(target_value, "TargetCertificateContent",
427 &config->TargetCertPEMLength);
428
429 if (!config->TargetCertPEM || (config->TargetCertPEMLength == 0))
430 return FALSE;
431 }
432
433 target_value = pf_config_get_str(ini, section_target, key_target_cert_hash, FALSE);
434 if (target_value)
435 {
436 const char* sep = strchr(target_value, ':');
437 char hash[32] = WINPR_C_ARRAY_INIT;
438 if (sep)
439 {
440 const size_t len = WINPR_ASSERTING_INT_CAST(size_t, sep - target_value);
441 if (len < sizeof(hash))
442 {
443 memcpy(hash, target_value, len);
444 }
445 }
446 if (!sep || (winpr_md_type_from_string(hash) == WINPR_MD_NONE))
447 {
448 WLog_WARN(TAG,
449 "In section [%s] key %s value %s is invalid. Format required is '<hash "
450 "type>:<hash value>'.",
451 section_target, key_target_cert_hash, target_value);
452 return FALSE;
453 }
454 winpr_zfree(config->TargetCertHash);
455 config->TargetCertHash = _strdup(target_value);
456 if (!config->TargetCertHash)
457 return FALSE;
458 }
459
460 target_value = pf_config_get_str(ini, section_target, key_target_cert_policy, FALSE);
461 if (target_value)
462 {
463 config->TargetCertPolicy = pf_config_policy_from_str(target_value);
464 if (config->TargetCertPolicy == FREERDP_PROXY_CERT_POLICY_PINNED)
465 {
466 if (!config->TargetCertHash && !config->TargetCertPEM)
467 {
468 WLog_WARN(TAG, "In section [%s] key %s value %s requires one of %s, %s or %s set.",
469 section_target, key_target_cert_policy, target_value,
470 key_target_cert_hash, key_target_cert_pem, key_target_cert_pem_content);
471 return FALSE;
472 }
473 }
474 }
475
476 return TRUE;
477}
478
479WINPR_ATTR_NODISCARD
480static BOOL pf_config_load_codecs(wIniFile* ini, proxyConfig* config)
481{
482 WINPR_ASSERT(config);
483 config->RFX = pf_config_get_bool(ini, section_codecs, key_codecs_rfx, TRUE);
484 config->NSC = pf_config_get_bool(ini, section_codecs, key_codecs_nsc, TRUE);
485 return TRUE;
486}
487
488WINPR_ATTR_NODISCARD
489static BOOL pf_config_load_channels(wIniFile* ini, proxyConfig* config)
490{
491 WINPR_ASSERT(config);
492 config->GFX = pf_config_get_bool(ini, section_channels, key_channels_gfx, TRUE);
493 config->DisplayControl = pf_config_get_bool(ini, section_channels, key_channels_disp, TRUE);
494 config->Clipboard = pf_config_get_bool(ini, section_channels, key_channels_clip, FALSE);
495 config->AudioOutput = pf_config_get_bool(ini, section_channels, key_channels_sound, TRUE);
496 config->AudioInput = pf_config_get_bool(ini, section_channels, key_channels_mic, TRUE);
497 config->DeviceRedirection = pf_config_get_bool(ini, section_channels, key_channels_rdpdr, TRUE);
498 config->VideoRedirection = pf_config_get_bool(ini, section_channels, key_channels_video, TRUE);
499 config->CameraRedirection =
500 pf_config_get_bool(ini, section_channels, key_channels_camera, TRUE);
501 config->RemoteApp = pf_config_get_bool(ini, section_channels, key_channels_rails, FALSE);
502 config->PassthroughIsBlacklist =
503 pf_config_get_bool(ini, section_channels, key_channels_blacklist, FALSE);
504 config->Passthrough = pf_config_parse_comma_separated_list(
505 pf_config_get_str(ini, section_channels, key_channels_pass, FALSE),
506 &config->PassthroughCount);
507 config->Intercept = pf_config_parse_comma_separated_list(
508 pf_config_get_str(ini, section_channels, key_channels_intercept, FALSE),
509 &config->InterceptCount);
510
511 return TRUE;
512}
513
514WINPR_ATTR_NODISCARD
515static BOOL pf_config_load_input(wIniFile* ini, proxyConfig* config)
516{
517 WINPR_ASSERT(config);
518 config->Keyboard = pf_config_get_bool(ini, section_input, key_input_kbd, TRUE);
519 config->Mouse = pf_config_get_bool(ini, section_input, key_input_mouse, TRUE);
520 config->Multitouch = pf_config_get_bool(ini, section_input, key_input_multitouch, TRUE);
521 return TRUE;
522}
523
524WINPR_ATTR_NODISCARD
525static BOOL pf_config_load_security(wIniFile* ini, proxyConfig* config)
526{
527 WINPR_ASSERT(config);
528 config->ServerTlsSecurity =
529 pf_config_get_bool(ini, section_security, key_security_server_tls, TRUE);
530 config->ServerNlaSecurity =
531 pf_config_get_bool(ini, section_security, key_security_server_nla, FALSE);
532 config->ServerExtSecurity =
533 pf_config_get_bool(ini, section_security, key_security_server_ext, FALSE);
534 config->ServerRdpSecurity =
535 pf_config_get_bool(ini, section_security, key_security_server_rdp, TRUE);
536
537 config->ClientTlsSecurity =
538 pf_config_get_bool(ini, section_security, key_security_client_tls, TRUE);
539 config->ClientNlaSecurity =
540 pf_config_get_bool(ini, section_security, key_security_client_nla, TRUE);
541 config->ClientExtSecurity =
542 pf_config_get_bool(ini, section_security, key_security_client_ext, TRUE);
543 config->ClientRdpSecurity =
544 pf_config_get_bool(ini, section_security, key_security_client_rdp, TRUE);
545 config->ClientAllowFallbackToTls =
546 pf_config_get_bool(ini, section_security, key_security_client_fallback, TRUE);
547 return TRUE;
548}
549
550WINPR_ATTR_NODISCARD
551static BOOL pf_config_load_modules(wIniFile* ini, proxyConfig* config)
552{
553 const char* modules_to_load = nullptr;
554 const char* required_modules = nullptr;
555
556 modules_to_load = pf_config_get_str(ini, section_plugins, key_plugins_modules, FALSE);
557 required_modules = pf_config_get_str(ini, section_plugins, key_plugins_required, FALSE);
558
559 WINPR_ASSERT(config);
560 config->Modules = pf_config_parse_comma_separated_list(modules_to_load, &config->ModulesCount);
561
562 config->RequiredPlugins =
563 pf_config_parse_comma_separated_list(required_modules, &config->RequiredPluginsCount);
564 return TRUE;
565}
566
567char* pf_config_decode_base64(const char* data, const char* name, size_t* pLength)
568{
569 const char* headers[] = { "-----BEGIN PUBLIC KEY-----", "-----BEGIN RSA PUBLIC KEY-----",
570 "-----BEGIN CERTIFICATE-----", "-----BEGIN PRIVATE KEY-----",
571 "-----BEGIN RSA PRIVATE KEY-----" };
572
573 size_t decoded_length = 0;
574 char* decoded = nullptr;
575 if (!data)
576 {
577 WLog_ERR(TAG, "Invalid base64 data [nullptr] for %s", name);
578 return nullptr;
579 }
580
581 WINPR_ASSERT(name);
582 WINPR_ASSERT(pLength);
583
584 const size_t length = strlen(data);
585
586 if (strncmp(data, "-----", 5) == 0)
587 {
588 BOOL expected = FALSE;
589 for (size_t x = 0; x < ARRAYSIZE(headers); x++)
590 {
591 const char* header = headers[x];
592
593 if (strncmp(data, header, strlen(header)) == 0)
594 expected = TRUE;
595 }
596
597 if (!expected)
598 {
599 /* Extract header for log message
600 * expected format is '----- SOMETEXT -----'
601 */
602 char hdr[128] = WINPR_C_ARRAY_INIT;
603 const char* end = strchr(&data[5], '-');
604 if (end)
605 {
606 while (*end == '-')
607 end++;
608
609 const size_t s = MIN(ARRAYSIZE(hdr) - 1ULL, (size_t)(end - data));
610 memcpy(hdr, data, s);
611 }
612
613 WLog_WARN(TAG, "PEM has unexpected header '%s'. Known supported headers are:", hdr);
614 for (size_t x = 0; x < ARRAYSIZE(headers); x++)
615 {
616 const char* header = headers[x];
617 WLog_WARN(TAG, "%s", header);
618 }
619 }
620
621 *pLength = length + 1;
622 return _strdup(data);
623 }
624
625 crypto_base64_decode(data, length, (BYTE**)&decoded, &decoded_length);
626 if (!decoded || decoded_length == 0)
627 {
628 WLog_ERR(TAG, "Failed to decode base64 data of length %" PRIuz " for %s", length, name);
629 winpr_zfree(decoded);
630 return nullptr;
631 }
632
633 *pLength = strnlen(decoded, decoded_length) + 1;
634 return decoded;
635}
636
637WINPR_ATTR_NODISCARD
638static BOOL pf_config_load_certificates(wIniFile* ini, proxyConfig* config)
639{
640 const char* tmp1 = nullptr;
641 const char* tmp2 = nullptr;
642
643 WINPR_ASSERT(ini);
644 WINPR_ASSERT(config);
645
646 tmp1 = pf_config_get_str(ini, section_certificates, key_cert_file, FALSE);
647 if (tmp1)
648 {
649 if (!winpr_PathFileExists(tmp1))
650 {
651 WLog_ERR(TAG, "%s/%s file %s does not exist", section_certificates, key_cert_file,
652 tmp1);
653 return FALSE;
654 }
655 config->CertificateFile = _strdup(tmp1);
656 config->CertificatePEM =
657 crypto_read_pem(config->CertificateFile, &config->CertificatePEMLength);
658 if (!config->CertificatePEM)
659 return FALSE;
660 config->CertificatePEMLength += 1;
661 }
662 tmp2 = pf_config_get_str(ini, section_certificates, key_cert_content, FALSE);
663 if (tmp2)
664 {
665 if (strlen(tmp2) < 1)
666 {
667 WLog_ERR(TAG, "%s/%s has invalid empty value", section_certificates, key_cert_content);
668 return FALSE;
669 }
670 config->CertificateContent = _strdup(tmp2);
671 config->CertificatePEM = pf_config_decode_base64(
672 config->CertificateContent, "CertificateContent", &config->CertificatePEMLength);
673 if (!config->CertificatePEM)
674 return FALSE;
675 }
676 if (tmp1 && tmp2)
677 {
678 WLog_ERR(TAG,
679 "%s/%s and %s/%s are "
680 "mutually exclusive options",
681 section_certificates, key_cert_file, section_certificates, key_cert_content);
682 return FALSE;
683 }
684 else if (!tmp1 && !tmp2)
685 {
686 WLog_ERR(TAG,
687 "%s/%s or %s/%s are "
688 "required settings",
689 section_certificates, key_cert_file, section_certificates, key_cert_content);
690 return FALSE;
691 }
692
693 tmp1 = pf_config_get_str(ini, section_certificates, key_private_key_file, FALSE);
694 if (tmp1)
695 {
696 if (!winpr_PathFileExists(tmp1))
697 {
698 WLog_ERR(TAG, "%s/%s file %s does not exist", section_certificates,
699 key_private_key_file, tmp1);
700 return FALSE;
701 }
702 config->PrivateKeyFile = _strdup(tmp1);
703 config->PrivateKeyPEM =
704 crypto_read_pem(config->PrivateKeyFile, &config->PrivateKeyPEMLength);
705 if (!config->PrivateKeyPEM)
706 return FALSE;
707 config->PrivateKeyPEMLength += 1;
708 }
709 tmp2 = pf_config_get_str(ini, section_certificates, key_private_key_content, FALSE);
710 if (tmp2)
711 {
712 if (strlen(tmp2) < 1)
713 {
714 WLog_ERR(TAG, "%s/%s has invalid empty value", section_certificates,
715 key_private_key_content);
716 return FALSE;
717 }
718 config->PrivateKeyContent = _strdup(tmp2);
719 config->PrivateKeyPEM = pf_config_decode_base64(
720 config->PrivateKeyContent, "PrivateKeyContent", &config->PrivateKeyPEMLength);
721 if (!config->PrivateKeyPEM)
722 return FALSE;
723 }
724
725 if (tmp1 && tmp2)
726 {
727 WLog_ERR(TAG,
728 "%s/%s and %s/%s are "
729 "mutually exclusive options",
730 section_certificates, key_private_key_file, section_certificates,
731 key_private_key_content);
732 return FALSE;
733 }
734 else if (!tmp1 && !tmp2)
735 {
736 WLog_ERR(TAG,
737 "%s/%s or %s/%s are "
738 "are required settings",
739 section_certificates, key_private_key_file, section_certificates,
740 key_private_key_content);
741 return FALSE;
742 }
743
744 return TRUE;
745}
746
747proxyConfig* server_config_load_ini(wIniFile* ini)
748{
749 proxyConfig* config = nullptr;
750
751 WINPR_ASSERT(ini);
752
753 config = calloc(1, sizeof(proxyConfig));
754 if (config)
755 {
756 /* Set default values != 0 */
757 config->TargetTlsSecLevel = 1;
758
759 /* Load from ini */
760 if (!pf_config_load_server(ini, config))
761 goto out;
762
763 if (!pf_config_load_target(ini, config))
764 goto out;
765
766 if (!pf_config_load_codecs(ini, config))
767 goto out;
768
769 if (!pf_config_load_channels(ini, config))
770 goto out;
771
772 if (!pf_config_load_input(ini, config))
773 goto out;
774
775 if (!pf_config_load_security(ini, config))
776 goto out;
777
778 if (!pf_config_load_modules(ini, config))
779 goto out;
780
781 if (!pf_config_load_certificates(ini, config))
782 goto out;
783 config->ini = IniFile_Clone(ini);
784 if (!config->ini)
785 goto out;
786 }
787 return config;
788out:
789 WINPR_PRAGMA_DIAG_PUSH
790 WINPR_PRAGMA_DIAG_IGNORED_MISMATCHED_DEALLOC
791 pf_server_config_free(config);
792 WINPR_PRAGMA_DIAG_POP
793
794 return nullptr;
795}
796
797BOOL pf_server_config_dump(const char* file)
798{
799 BOOL rc = FALSE;
800 wIniFile* ini = IniFile_New();
801 if (!ini)
802 return FALSE;
803
804 /* Proxy server configuration */
805 if (IniFile_SetKeyValueString(ini, section_server, key_host, "0.0.0.0") < 0)
806 goto fail;
807 if (IniFile_SetKeyValueInt(ini, section_server, key_port, 3389) < 0)
808 goto fail;
809 if (IniFile_SetKeyValueString(ini, section_server, key_sam_file,
810 "optional/path/some/file.sam") < 0)
811 goto fail;
812
813 /* Target configuration */
814 if (IniFile_SetKeyValueString(ini, section_target, key_host, "somehost.example.com") < 0)
815 goto fail;
816 if (IniFile_SetKeyValueInt(ini, section_target, key_port, 3389) < 0)
817 goto fail;
818 if (IniFile_SetKeyValueString(ini, section_target, key_target_fixed, bool_str_true) < 0)
819 goto fail;
820 if (IniFile_SetKeyValueInt(ini, section_target, key_target_tls_seclevel, 1) < 0)
821 goto fail;
822 if (IniFile_SetKeyValueString(ini, section_target, key_target_user, "optionaltargetuser") < 0)
823 goto fail;
824 if (IniFile_SetKeyValueString(ini, section_target, key_target_domain, "optionaltargetdomain") <
825 0)
826 goto fail;
827 if (IniFile_SetKeyValueString(ini, section_target, key_target_pwd, "optionaltargetpassword") <
828 0)
829 goto fail;
830 if (IniFile_SetKeyValueString(ini, section_target, key_target_scard_auth, bool_str_false) < 0)
831 goto fail;
832 if (IniFile_SetKeyValueString(ini, section_target, key_target_scard_cert,
833 "optional/path/some/file.pem.crt") < 0)
834 goto fail;
835 if (IniFile_SetKeyValueString(ini, section_target, key_target_scard_pem_cert,
836 "<base64 encoded PEM>") < 0)
837 goto fail;
838 if (IniFile_SetKeyValueString(ini, section_target, key_target_scard_key,
839 "optional/path/some/file.pem.key") < 0)
840 goto fail;
841
842 if (IniFile_SetKeyValueString(ini, section_target, key_target_scard_pem_key,
843 "<base64 encoded PEM>") < 0)
844 goto fail;
845 if (IniFile_SetKeyValueString(ini, section_target, key_target_cert_policy,
846 "[deny|allow|pinned]") < 0)
847 goto fail;
848 if (IniFile_SetKeyValueString(ini, section_target, key_target_cert_pem,
849 "optional/path/some/file.pem.crt") < 0)
850 goto fail;
851 if (IniFile_SetKeyValueString(ini, section_target, key_target_cert_pem_content,
852 "<base64 encoded PEM>") < 0)
853 goto fail;
854 if (IniFile_SetKeyValueString(ini, section_target, key_target_cert_hash,
855 "<hash type>:<hash hex string>") < 0)
856 goto fail;
857 /* Codec configuration */
858 if (IniFile_SetKeyValueString(ini, section_codecs, key_codecs_rfx, bool_str_true) < 0)
859 goto fail;
860 if (IniFile_SetKeyValueString(ini, section_codecs, key_codecs_nsc, bool_str_true) < 0)
861 goto fail;
862
863 /* Channel configuration */
864 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_gfx, bool_str_true) < 0)
865 goto fail;
866 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_disp, bool_str_true) < 0)
867 goto fail;
868 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_clip, bool_str_true) < 0)
869 goto fail;
870 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_mic, bool_str_true) < 0)
871 goto fail;
872 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_sound, bool_str_true) < 0)
873 goto fail;
874 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_rdpdr, bool_str_true) < 0)
875 goto fail;
876 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_video, bool_str_true) < 0)
877 goto fail;
878 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_camera, bool_str_true) < 0)
879 goto fail;
880 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_rails, bool_str_false) < 0)
881 goto fail;
882
883 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_blacklist, bool_str_true) < 0)
884 goto fail;
885 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_pass, "") < 0)
886 goto fail;
887 if (IniFile_SetKeyValueString(ini, section_channels, key_channels_intercept, "") < 0)
888 goto fail;
889
890 /* Input configuration */
891 if (IniFile_SetKeyValueString(ini, section_input, key_input_kbd, bool_str_true) < 0)
892 goto fail;
893 if (IniFile_SetKeyValueString(ini, section_input, key_input_mouse, bool_str_true) < 0)
894 goto fail;
895 if (IniFile_SetKeyValueString(ini, section_input, key_input_multitouch, bool_str_true) < 0)
896 goto fail;
897
898 /* Security settings */
899 if (IniFile_SetKeyValueString(ini, section_security, key_security_server_tls, bool_str_true) <
900 0)
901 goto fail;
902 if (IniFile_SetKeyValueString(ini, section_security, key_security_server_nla, bool_str_false) <
903 0)
904 goto fail;
905 if (IniFile_SetKeyValueString(ini, section_security, key_security_server_ext, bool_str_false) <
906 0)
907 goto fail;
908 if (IniFile_SetKeyValueString(ini, section_security, key_security_server_rdp, bool_str_true) <
909 0)
910 goto fail;
911
912 if (IniFile_SetKeyValueString(ini, section_security, key_security_client_tls, bool_str_true) <
913 0)
914 goto fail;
915 if (IniFile_SetKeyValueString(ini, section_security, key_security_client_nla, bool_str_true) <
916 0)
917 goto fail;
918 if (IniFile_SetKeyValueString(ini, section_security, key_security_client_ext, bool_str_true) <
919 0)
920 goto fail;
921 if (IniFile_SetKeyValueString(ini, section_security, key_security_client_rdp, bool_str_true) <
922 0)
923 goto fail;
924 if (IniFile_SetKeyValueString(ini, section_security, key_security_client_fallback,
925 bool_str_true) < 0)
926 goto fail;
927
928 /* Module configuration */
929 if (IniFile_SetKeyValueString(ini, section_plugins, key_plugins_modules,
930 "module1,module2,...") < 0)
931 goto fail;
932 if (IniFile_SetKeyValueString(ini, section_plugins, key_plugins_required,
933 "module1,module2,...") < 0)
934 goto fail;
935
936 /* Certificate configuration */
937 if (IniFile_SetKeyValueString(ini, section_certificates, key_cert_file,
938 "<absolute path to some certificate file> OR") < 0)
939 goto fail;
940 if (IniFile_SetKeyValueString(ini, section_certificates, key_cert_content,
941 "<base64 encoded PEM>") < 0)
942 goto fail;
943
944 if (IniFile_SetKeyValueString(ini, section_certificates, key_private_key_file,
945 "<absolute path to some private key file> OR") < 0)
946 goto fail;
947 if (IniFile_SetKeyValueString(ini, section_certificates, key_private_key_content,
948 "<base64 encoded PEM>") < 0)
949 goto fail;
950
951 if ((strcmp("stdout", file) == 0) || (strcmp("stderr", file) == 0))
952 {
953 char* buffer = IniFile_WriteBuffer(ini);
954 if (!buffer)
955 goto fail;
956 FILE* fp = stderr;
957 if (strcmp("stdout", file) == 0)
958 fp = stdout;
959 (void)fprintf(fp, "%s", buffer);
960 winpr_zfree(buffer);
961 }
962 else
963 {
964 /* store configuration */
965 if (IniFile_WriteFile(ini, file) < 0)
966 goto fail;
967 }
968
969 rc = TRUE;
970
971fail:
972 IniFile_Free(ini);
973 return rc;
974}
975
976proxyConfig* pf_server_config_load_buffer(const char* buffer)
977{
978 proxyConfig* config = nullptr;
979 wIniFile* ini = nullptr;
980
981 ini = IniFile_New();
982
983 if (!ini)
984 {
985 WLog_ERR(TAG, "IniFile_New() failed!");
986 return nullptr;
987 }
988
989 if (IniFile_ReadBuffer(ini, buffer) < 0)
990 {
991 WLog_ERR(TAG, "failed to parse ini: '%s'", buffer);
992 goto out;
993 }
994
995 config = server_config_load_ini(ini);
996out:
997 IniFile_Free(ini);
998 return config;
999}
1000
1001proxyConfig* pf_server_config_load_file(const char* path)
1002{
1003 proxyConfig* config = nullptr;
1004 wIniFile* ini = IniFile_New();
1005
1006 if (!ini)
1007 {
1008 WLog_ERR(TAG, "IniFile_New() failed!");
1009 return nullptr;
1010 }
1011
1012 if (IniFile_ReadFile(ini, path) < 0)
1013 {
1014 WLog_ERR(TAG, "failed to parse ini file: '%s'", path);
1015 goto out;
1016 }
1017
1018 config = server_config_load_ini(ini);
1019out:
1020 IniFile_Free(ini);
1021 return config;
1022}
1023
1024static void pf_server_config_print_list(char** list, size_t count)
1025{
1026 WINPR_ASSERT(list);
1027 for (size_t i = 0; i < count; i++)
1028 WLog_INFO(TAG, "\t\t- %s", list[i]);
1029}
1030
1031void pf_server_config_print(const proxyConfig* config)
1032{
1033 WINPR_ASSERT(config);
1034 WLog_INFO(TAG, "Proxy configuration:");
1035
1036 CONFIG_PRINT_SECTION(section_server);
1037 CONFIG_PRINT_STR(config, Host);
1038 CONFIG_PRINT_STR(config, SamFile);
1039 CONFIG_PRINT_UINT16(config, Port);
1040
1041 if (config->FixedTarget)
1042 {
1043 CONFIG_PRINT_SECTION(section_target);
1044 CONFIG_PRINT_STR(config, TargetHost);
1045 CONFIG_PRINT_UINT16(config, TargetPort);
1046 CONFIG_PRINT_UINT32(config, TargetTlsSecLevel);
1047
1048 CONFIG_PRINT_STR(config, TargetUser);
1049 CONFIG_PRINT_STR(config, TargetDomain);
1050 CONFIG_PRINT_SECRET_STR(config, TargetPassword);
1051
1052 CONFIG_PRINT_BOOL(config, TargetSmartcardAuth);
1053 CONFIG_PRINT_SECRET_STR(config, TargetSmartcardCert);
1054 CONFIG_PRINT_SECRET_STR(config, TargetSmartcardKey);
1055
1056 WLog_INFO(TAG, "\t\t%s%s: %s", section_target, key_target_cert_policy,
1057 pf_config_policy_to_str(config->TargetCertPolicy));
1058 CONFIG_PRINT_SECRET_STR(config, TargetCertPEM);
1059 CONFIG_PRINT_SECRET_STR(config, TargetCertHash);
1060 }
1061
1062 CONFIG_PRINT_SECTION(section_input);
1063 CONFIG_PRINT_BOOL(config, Keyboard);
1064 CONFIG_PRINT_BOOL(config, Mouse);
1065 CONFIG_PRINT_BOOL(config, Multitouch);
1066
1067 CONFIG_PRINT_SECTION(section_security);
1068 CONFIG_PRINT_BOOL(config, ServerNlaSecurity);
1069 CONFIG_PRINT_BOOL(config, ServerExtSecurity);
1070 CONFIG_PRINT_BOOL(config, ServerTlsSecurity);
1071 CONFIG_PRINT_BOOL(config, ServerRdpSecurity);
1072 CONFIG_PRINT_BOOL(config, ClientNlaSecurity);
1073 CONFIG_PRINT_BOOL(config, ClientExtSecurity);
1074 CONFIG_PRINT_BOOL(config, ClientTlsSecurity);
1075 CONFIG_PRINT_BOOL(config, ClientRdpSecurity);
1076 CONFIG_PRINT_BOOL(config, ClientAllowFallbackToTls);
1077
1078 CONFIG_PRINT_SECTION(section_codecs);
1079 CONFIG_PRINT_BOOL(config, RFX);
1080 CONFIG_PRINT_BOOL(config, NSC);
1081
1082 CONFIG_PRINT_SECTION(section_channels);
1083 CONFIG_PRINT_BOOL(config, GFX);
1084 CONFIG_PRINT_BOOL(config, DisplayControl);
1085 CONFIG_PRINT_BOOL(config, Clipboard);
1086 CONFIG_PRINT_BOOL(config, AudioOutput);
1087 CONFIG_PRINT_BOOL(config, AudioInput);
1088 CONFIG_PRINT_BOOL(config, DeviceRedirection);
1089 CONFIG_PRINT_BOOL(config, VideoRedirection);
1090 CONFIG_PRINT_BOOL(config, CameraRedirection);
1091 CONFIG_PRINT_BOOL(config, RemoteApp);
1092 CONFIG_PRINT_BOOL(config, PassthroughIsBlacklist);
1093
1094 if (config->PassthroughCount)
1095 {
1096 WLog_INFO(TAG, "\tStatic Channels Proxy:");
1097 pf_server_config_print_list(config->Passthrough, config->PassthroughCount);
1098 }
1099
1100 if (config->InterceptCount)
1101 {
1102 WLog_INFO(TAG, "\tStatic Channels Proxy-Intercept:");
1103 pf_server_config_print_list(config->Intercept, config->InterceptCount);
1104 }
1105
1106 /* modules */
1107 CONFIG_PRINT_SECTION_KEY(section_plugins, key_plugins_modules);
1108 for (size_t x = 0; x < config->ModulesCount; x++)
1109 CONFIG_PRINT_STR(config, Modules[x]);
1110
1111 /* Required plugins */
1112 CONFIG_PRINT_SECTION_KEY(section_plugins, key_plugins_required);
1113 for (size_t x = 0; x < config->RequiredPluginsCount; x++)
1114 CONFIG_PRINT_STR(config, RequiredPlugins[x]);
1115
1116 CONFIG_PRINT_SECTION(section_certificates);
1117 CONFIG_PRINT_STR(config, CertificateFile);
1118 CONFIG_PRINT_SECRET_STR(config, CertificateContent);
1119 CONFIG_PRINT_STR(config, PrivateKeyFile);
1120 CONFIG_PRINT_SECRET_STR(config, PrivateKeyContent);
1121}
1122
1123void pf_server_config_free(proxyConfig* config)
1124{
1125 if (config == nullptr)
1126 return;
1127
1128 winpr_zfree(config->Host);
1129 winpr_zfree(config->SamFile);
1130 winpr_zfree(config->TargetHost);
1131 winpr_zfree(config->TargetUser);
1132 winpr_zfree(config->TargetDomain);
1133 winpr_zfree(config->TargetPassword);
1134 winpr_znfree(config->TargetSmartcardCert, config->TargetSmartcardCertLength);
1135 winpr_znfree(config->TargetSmartcardKey, config->TargetSmartcardKeyLength);
1136 winpr_zfree(config->TargetCertHash);
1137 winpr_znfree(config->TargetCertPEM, config->TargetCertPEMLength);
1138
1139 CommandLineParserFree(config->Passthrough);
1140 CommandLineParserFree(config->Intercept);
1141 CommandLineParserFree(config->Modules);
1142 CommandLineParserFree(config->RequiredPlugins);
1143
1144 winpr_zfree(config->CertificateFile);
1145 winpr_zfree(config->CertificateContent);
1146 winpr_znfree(config->CertificatePEM, config->CertificatePEMLength);
1147 winpr_zfree(config->PrivateKeyFile);
1148 winpr_zfree(config->PrivateKeyContent);
1149 winpr_znfree(config->PrivateKeyPEM, config->PrivateKeyPEMLength);
1150 IniFile_Free(config->ini);
1151 free(config);
1152}
1153
1154size_t pf_config_required_plugins_count(const proxyConfig* config)
1155{
1156 WINPR_ASSERT(config);
1157 return config->RequiredPluginsCount;
1158}
1159
1160const char* pf_config_required_plugin(const proxyConfig* config, size_t index)
1161{
1162 WINPR_ASSERT(config);
1163 if (index >= config->RequiredPluginsCount)
1164 return nullptr;
1165
1166 return config->RequiredPlugins[index];
1167}
1168
1169size_t pf_config_modules_count(const proxyConfig* config)
1170{
1171 WINPR_ASSERT(config);
1172 return config->ModulesCount;
1173}
1174
1175const char** pf_config_modules(const proxyConfig* config)
1176{
1177 union
1178 {
1179 char** ppc;
1180 const char** cppc;
1181 } cnv;
1182
1183 WINPR_ASSERT(config);
1184
1185 cnv.ppc = config->Modules;
1186 return cnv.cppc;
1187}
1188
1189WINPR_ATTR_NODISCARD
1190static BOOL pf_config_copy_string_n(char** dst, const char* src, size_t size)
1191{
1192 *dst = nullptr;
1193
1194 if (src && (size > 0))
1195 {
1196 WINPR_ASSERT(strnlen(src, size) == size - 1);
1197 *dst = calloc(size, sizeof(char));
1198 if (!*dst)
1199 return FALSE;
1200 memcpy(*dst, src, size);
1201 }
1202
1203 return TRUE;
1204}
1205
1206WINPR_ATTR_NODISCARD
1207static BOOL pf_config_copy_string_list(char*** dst, size_t* size, char** src, size_t srcSize)
1208{
1209 WINPR_ASSERT(dst);
1210 WINPR_ASSERT(size);
1211 WINPR_ASSERT(src || (srcSize == 0));
1212
1213 *dst = nullptr;
1214 *size = 0;
1215 if (srcSize > INT32_MAX)
1216 return FALSE;
1217
1218 if (srcSize != 0)
1219 {
1220 char* csv = CommandLineToCommaSeparatedValues((INT32)srcSize, src);
1221 *dst = CommandLineParseCommaSeparatedValues(csv, size);
1222 winpr_zfree(csv);
1223 }
1224
1225 return TRUE;
1226}
1227
1228BOOL pf_config_clone(proxyConfig** dst, const proxyConfig* config)
1229{
1230 proxyConfig* tmp = calloc(1, sizeof(proxyConfig));
1231
1232 WINPR_ASSERT(dst);
1233 WINPR_ASSERT(config);
1234
1235 if (!tmp)
1236 return FALSE;
1237
1238 *tmp = *config;
1239
1240 if (!pf_config_copy_string(&tmp->Host, config->Host))
1241 goto fail;
1242 if (!pf_config_copy_string(&tmp->SamFile, config->SamFile))
1243 goto fail;
1244 if (!pf_config_copy_string(&tmp->TargetHost, config->TargetHost))
1245 goto fail;
1246 if (!pf_config_copy_string(&tmp->TargetUser, config->TargetUser))
1247 goto fail;
1248 if (!pf_config_copy_string(&tmp->TargetDomain, config->TargetDomain))
1249 goto fail;
1250 if (!pf_config_copy_string(&tmp->TargetPassword, config->TargetPassword))
1251 goto fail;
1252 if (!pf_config_copy_string_n(&tmp->TargetSmartcardCert, config->TargetSmartcardCert,
1253 config->TargetSmartcardCertLength))
1254 goto fail;
1255 if (!pf_config_copy_string_n(&tmp->TargetSmartcardKey, config->TargetSmartcardKey,
1256 config->TargetSmartcardKeyLength))
1257 goto fail;
1258 if (!pf_config_copy_string_list(&tmp->Passthrough, &tmp->PassthroughCount, config->Passthrough,
1259 config->PassthroughCount))
1260 goto fail;
1261 if (!pf_config_copy_string_list(&tmp->Intercept, &tmp->InterceptCount, config->Intercept,
1262 config->InterceptCount))
1263 goto fail;
1264 if (!pf_config_copy_string_list(&tmp->Modules, &tmp->ModulesCount, config->Modules,
1265 config->ModulesCount))
1266 goto fail;
1267 if (!pf_config_copy_string_list(&tmp->RequiredPlugins, &tmp->RequiredPluginsCount,
1268 config->RequiredPlugins, config->RequiredPluginsCount))
1269 goto fail;
1270 if (!pf_config_copy_string(&tmp->CertificateFile, config->CertificateFile))
1271 goto fail;
1272 if (!pf_config_copy_string(&tmp->CertificateContent, config->CertificateContent))
1273 goto fail;
1274 if (!pf_config_copy_string_n(&tmp->CertificatePEM, config->CertificatePEM,
1275 config->CertificatePEMLength))
1276 goto fail;
1277 if (!pf_config_copy_string(&tmp->PrivateKeyFile, config->PrivateKeyFile))
1278 goto fail;
1279 if (!pf_config_copy_string(&tmp->PrivateKeyContent, config->PrivateKeyContent))
1280 goto fail;
1281 if (!pf_config_copy_string_n(&tmp->PrivateKeyPEM, config->PrivateKeyPEM,
1282 config->PrivateKeyPEMLength))
1283 goto fail;
1284 if (!pf_config_copy_string(&tmp->TargetCertPEM, config->TargetCertPEM))
1285 goto fail;
1286 if (!pf_config_copy_string(&tmp->TargetCertHash, config->TargetCertHash))
1287 goto fail;
1288 tmp->ini = IniFile_Clone(config->ini);
1289 if (!tmp->ini)
1290 goto fail;
1291
1292 *dst = tmp;
1293 return TRUE;
1294
1295fail:
1296 WINPR_PRAGMA_DIAG_PUSH
1297 WINPR_PRAGMA_DIAG_IGNORED_MISMATCHED_DEALLOC
1299 WINPR_PRAGMA_DIAG_POP
1300 return FALSE;
1301}
1302
1303struct config_plugin_data
1304{
1305 proxyPluginsManager* mgr;
1306 const proxyConfig* config;
1307};
1308
1309static const char config_plugin_name[] = "config";
1310static const char config_plugin_desc[] =
1311 "A plugin filtering according to proxy configuration file rules";
1312
1313WINPR_ATTR_NODISCARD
1314static BOOL config_plugin_unload(proxyPlugin* plugin)
1315{
1316 WINPR_ASSERT(plugin);
1317
1318 /* Here we have to free up our custom data storage. */
1319 if (plugin)
1320 {
1321 free(plugin->custom);
1322 plugin->custom = nullptr;
1323 }
1324
1325 return TRUE;
1326}
1327
1328WINPR_ATTR_NODISCARD
1329static BOOL config_plugin_keyboard_event(proxyPlugin* plugin, WINPR_ATTR_UNUSED proxyData* pdata,
1330 void* param)
1331{
1332 BOOL rc = 0;
1333 const struct config_plugin_data* custom = nullptr;
1334 const proxyConfig* cfg = nullptr;
1335 const proxyKeyboardEventInfo* event_data = (const proxyKeyboardEventInfo*)(param);
1336
1337 WINPR_ASSERT(plugin);
1338 WINPR_ASSERT(pdata);
1339 WINPR_ASSERT(event_data);
1340
1341 WINPR_UNUSED(event_data);
1342
1343 custom = plugin->custom;
1344 WINPR_ASSERT(custom);
1345
1346 cfg = custom->config;
1347 WINPR_ASSERT(cfg);
1348
1349 rc = cfg->Keyboard;
1350 WLog_DBG(TAG, "%s", boolstr(rc));
1351 return rc;
1352}
1353
1354WINPR_ATTR_NODISCARD
1355static BOOL config_plugin_unicode_event(proxyPlugin* plugin, WINPR_ATTR_UNUSED proxyData* pdata,
1356 void* param)
1357{
1358 BOOL rc = 0;
1359 const struct config_plugin_data* custom = nullptr;
1360 const proxyConfig* cfg = nullptr;
1361 const proxyUnicodeEventInfo* event_data = (const proxyUnicodeEventInfo*)(param);
1362
1363 WINPR_ASSERT(plugin);
1364 WINPR_ASSERT(pdata);
1365 WINPR_ASSERT(event_data);
1366
1367 WINPR_UNUSED(event_data);
1368
1369 custom = plugin->custom;
1370 WINPR_ASSERT(custom);
1371
1372 cfg = custom->config;
1373 WINPR_ASSERT(cfg);
1374
1375 rc = cfg->Keyboard;
1376 WLog_DBG(TAG, "%s", boolstr(rc));
1377 return rc;
1378}
1379
1380WINPR_ATTR_NODISCARD
1381static BOOL config_plugin_mouse_event(proxyPlugin* plugin, WINPR_ATTR_UNUSED proxyData* pdata,
1382 void* param)
1383{
1384 BOOL rc = 0;
1385 const struct config_plugin_data* custom = nullptr;
1386 const proxyConfig* cfg = nullptr;
1387 const proxyMouseEventInfo* event_data = (const proxyMouseEventInfo*)(param);
1388
1389 WINPR_ASSERT(plugin);
1390 WINPR_ASSERT(pdata);
1391 WINPR_ASSERT(event_data);
1392
1393 WINPR_UNUSED(event_data);
1394
1395 custom = plugin->custom;
1396 WINPR_ASSERT(custom);
1397
1398 cfg = custom->config;
1399 WINPR_ASSERT(cfg);
1400
1401 rc = cfg->Mouse;
1402 return rc;
1403}
1404
1405WINPR_ATTR_NODISCARD
1406static BOOL config_plugin_mouse_ex_event(proxyPlugin* plugin, WINPR_ATTR_UNUSED proxyData* pdata,
1407 void* param)
1408{
1409 BOOL rc = 0;
1410 const struct config_plugin_data* custom = nullptr;
1411 const proxyConfig* cfg = nullptr;
1412 const proxyMouseExEventInfo* event_data = (const proxyMouseExEventInfo*)(param);
1413
1414 WINPR_ASSERT(plugin);
1415 WINPR_ASSERT(pdata);
1416 WINPR_ASSERT(event_data);
1417
1418 WINPR_UNUSED(event_data);
1419
1420 custom = plugin->custom;
1421 WINPR_ASSERT(custom);
1422
1423 cfg = custom->config;
1424 WINPR_ASSERT(cfg);
1425
1426 rc = cfg->Mouse;
1427 return rc;
1428}
1429
1430WINPR_ATTR_NODISCARD
1431static BOOL config_plugin_client_channel_data(WINPR_ATTR_UNUSED proxyPlugin* plugin,
1432 WINPR_ATTR_UNUSED proxyData* pdata, void* param)
1433{
1434 const proxyChannelDataEventInfo* channel = (const proxyChannelDataEventInfo*)(param);
1435
1436 WINPR_ASSERT(plugin);
1437 WINPR_ASSERT(pdata);
1438 WINPR_ASSERT(channel);
1439
1440 WLog_DBG(TAG, "%s [0x%04" PRIx16 "] got %" PRIuz, channel->channel_name, channel->channel_id,
1441 channel->data_len);
1442 return TRUE;
1443}
1444
1445WINPR_ATTR_NODISCARD
1446static BOOL config_plugin_server_channel_data(WINPR_ATTR_UNUSED proxyPlugin* plugin,
1447 WINPR_ATTR_UNUSED proxyData* pdata, void* param)
1448{
1449 const proxyChannelDataEventInfo* channel = (const proxyChannelDataEventInfo*)(param);
1450
1451 WINPR_ASSERT(plugin);
1452 WINPR_ASSERT(pdata);
1453 WINPR_ASSERT(channel);
1454
1455 WLog_DBG(TAG, "%s [0x%04" PRIx16 "] got %" PRIuz, channel->channel_name, channel->channel_id,
1456 channel->data_len);
1457 return TRUE;
1458}
1459
1460WINPR_ATTR_NODISCARD
1461static BOOL config_plugin_dynamic_channel_create(proxyPlugin* plugin,
1462 WINPR_ATTR_UNUSED proxyData* pdata, void* param)
1463{
1464 BOOL accept = 0;
1465 const proxyChannelDataEventInfo* channel = (const proxyChannelDataEventInfo*)(param);
1466
1467 WINPR_ASSERT(plugin);
1468 WINPR_ASSERT(pdata);
1469 WINPR_ASSERT(channel);
1470
1471 const struct config_plugin_data* custom = plugin->custom;
1472 WINPR_ASSERT(custom);
1473
1474 const proxyConfig* cfg = custom->config;
1475 WINPR_ASSERT(cfg);
1476
1477 pf_utils_channel_mode rc = pf_utils_get_channel_mode(cfg, channel->channel_name);
1478 switch (rc)
1479 {
1480
1481 case PF_UTILS_CHANNEL_INTERCEPT:
1482 case PF_UTILS_CHANNEL_PASSTHROUGH:
1483 accept = TRUE;
1484 break;
1485 case PF_UTILS_CHANNEL_BLOCK:
1486 default:
1487 accept = FALSE;
1488 break;
1489 }
1490
1491 if (accept)
1492 {
1493 if (strncmp(RDPGFX_DVC_CHANNEL_NAME, channel->channel_name,
1494 sizeof(RDPGFX_DVC_CHANNEL_NAME)) == 0)
1495 accept = cfg->GFX;
1496 else if (strncmp(RDPSND_DVC_CHANNEL_NAME, channel->channel_name,
1497 sizeof(RDPSND_DVC_CHANNEL_NAME)) == 0)
1498 accept = cfg->AudioOutput;
1499 else if (strncmp(RDPSND_LOSSY_DVC_CHANNEL_NAME, channel->channel_name,
1500 sizeof(RDPSND_LOSSY_DVC_CHANNEL_NAME)) == 0)
1501 accept = cfg->AudioOutput;
1502 else if (strncmp(AUDIN_DVC_CHANNEL_NAME, channel->channel_name,
1503 sizeof(AUDIN_DVC_CHANNEL_NAME)) == 0)
1504 accept = cfg->AudioInput;
1505 else if (strncmp(RDPEI_DVC_CHANNEL_NAME, channel->channel_name,
1506 sizeof(RDPEI_DVC_CHANNEL_NAME)) == 0)
1507 accept = cfg->Multitouch;
1508 else if (strncmp(TSMF_DVC_CHANNEL_NAME, channel->channel_name,
1509 sizeof(TSMF_DVC_CHANNEL_NAME)) == 0)
1510 accept = cfg->VideoRedirection;
1511 else if (strncmp(VIDEO_CONTROL_DVC_CHANNEL_NAME, channel->channel_name,
1512 sizeof(VIDEO_CONTROL_DVC_CHANNEL_NAME)) == 0)
1513 accept = cfg->VideoRedirection;
1514 else if (strncmp(VIDEO_DATA_DVC_CHANNEL_NAME, channel->channel_name,
1515 sizeof(VIDEO_DATA_DVC_CHANNEL_NAME)) == 0)
1516 accept = cfg->VideoRedirection;
1517 else if (strncmp(RDPECAM_DVC_CHANNEL_NAME, channel->channel_name,
1518 sizeof(RDPECAM_DVC_CHANNEL_NAME)) == 0)
1519 accept = cfg->CameraRedirection;
1520 }
1521
1522 WLog_DBG(TAG, "%s [0x%04" PRIx16 "]: %s", channel->channel_name, channel->channel_id,
1523 boolstr(accept));
1524 return accept;
1525}
1526
1527WINPR_ATTR_NODISCARD
1528static BOOL config_plugin_channel_create(proxyPlugin* plugin, WINPR_ATTR_UNUSED proxyData* pdata,
1529 void* param)
1530{
1531 BOOL accept = 0;
1532 const proxyChannelDataEventInfo* channel = (const proxyChannelDataEventInfo*)(param);
1533
1534 WINPR_ASSERT(plugin);
1535 WINPR_ASSERT(pdata);
1536 WINPR_ASSERT(channel);
1537
1538 const struct config_plugin_data* custom = plugin->custom;
1539 WINPR_ASSERT(custom);
1540
1541 const proxyConfig* cfg = custom->config;
1542 WINPR_ASSERT(cfg);
1543
1544 pf_utils_channel_mode rc = pf_utils_get_channel_mode(cfg, channel->channel_name);
1545 switch (rc)
1546 {
1547 case PF_UTILS_CHANNEL_INTERCEPT:
1548 case PF_UTILS_CHANNEL_PASSTHROUGH:
1549 accept = TRUE;
1550 break;
1551 case PF_UTILS_CHANNEL_BLOCK:
1552 default:
1553 accept = FALSE;
1554 break;
1555 }
1556 if (accept)
1557 {
1558 if (strncmp(CLIPRDR_SVC_CHANNEL_NAME, channel->channel_name,
1559 sizeof(CLIPRDR_SVC_CHANNEL_NAME)) == 0)
1560 accept = cfg->Clipboard;
1561 else if (strncmp(RDPSND_CHANNEL_NAME, channel->channel_name, sizeof(RDPSND_CHANNEL_NAME)) ==
1562 0)
1563 accept = cfg->AudioOutput;
1564 else if (strncmp(RDPDR_SVC_CHANNEL_NAME, channel->channel_name,
1565 sizeof(RDPDR_SVC_CHANNEL_NAME)) == 0)
1566 accept = cfg->DeviceRedirection;
1567 else if (strncmp(DISP_DVC_CHANNEL_NAME, channel->channel_name,
1568 sizeof(DISP_DVC_CHANNEL_NAME)) == 0)
1569 accept = cfg->DisplayControl;
1570 else if (strncmp(RAIL_SVC_CHANNEL_NAME, channel->channel_name,
1571 sizeof(RAIL_SVC_CHANNEL_NAME)) == 0)
1572 accept = cfg->RemoteApp;
1573 }
1574
1575 WLog_DBG(TAG, "%s [static]: %s", channel->channel_name, boolstr(accept));
1576 return accept;
1577}
1578
1579BOOL pf_config_plugin(proxyPluginsManager* plugins_manager, void* userdata)
1580{
1581 struct config_plugin_data* custom = nullptr;
1582 proxyPlugin plugin = WINPR_C_ARRAY_INIT;
1583
1584 plugin.name = config_plugin_name;
1585 plugin.description = config_plugin_desc;
1586 plugin.PluginUnload = config_plugin_unload;
1587
1588 plugin.KeyboardEvent = config_plugin_keyboard_event;
1589 plugin.UnicodeEvent = config_plugin_unicode_event;
1590 plugin.MouseEvent = config_plugin_mouse_event;
1591 plugin.MouseExEvent = config_plugin_mouse_ex_event;
1592 plugin.ClientChannelData = config_plugin_client_channel_data;
1593 plugin.ServerChannelData = config_plugin_server_channel_data;
1594 plugin.ChannelCreate = config_plugin_channel_create;
1595 plugin.DynamicChannelCreate = config_plugin_dynamic_channel_create;
1596 plugin.userdata = userdata;
1597
1598 custom = calloc(1, sizeof(struct config_plugin_data));
1599 if (!custom)
1600 return FALSE;
1601
1602 custom->mgr = plugins_manager;
1603 custom->config = userdata;
1604
1605 plugin.custom = custom;
1606 plugin.userdata = userdata;
1607
1608 return plugins_manager->RegisterPlugin(plugins_manager, &plugin);
1609}
1610
1611const char* pf_config_get(const proxyConfig* config, const char* section, const char* key)
1612{
1613 WINPR_ASSERT(config);
1614 WINPR_ASSERT(config->ini);
1615 WINPR_ASSERT(section);
1616 WINPR_ASSERT(key);
1617
1618 return IniFile_GetKeyValueString(config->ini, section, key);
1619}
1620
1621const char* pf_config_policy_to_str(FreeRDP_ProxyCertPolicy policy)
1622{
1623 switch (policy)
1624 {
1625 case FREERDP_PROXY_CERT_POLICY_ALLOW:
1626 return "allow";
1627 case FREERDP_PROXY_CERT_POLICY_PINNED:
1628 return "pinned";
1629 case FREERDP_PROXY_CERT_POLICY_DENY:
1630 default:
1631 return "deny";
1632 }
1633}
1634
1635FreeRDP_ProxyCertPolicy pf_config_policy_from_str(const char* val)
1636{
1637 if (!val)
1638 return FREERDP_PROXY_CERT_POLICY_DENY;
1639 if (_stricmp(val, "allow") == 0)
1640 return FREERDP_PROXY_CERT_POLICY_ALLOW;
1641 if (_stricmp(val, "pinned") == 0)
1642 return FREERDP_PROXY_CERT_POLICY_PINNED;
1643 return FREERDP_PROXY_CERT_POLICY_DENY;
1644}
proxyConfig * pf_server_config_load_buffer(const char *buffer)
pf_server_config_load_buffer Create a proxyConfig from a memory string buffer in INI file format
Definition pf_config.c:976
void pf_server_config_free(proxyConfig *config)
pf_server_config_free Releases all resources associated with proxyConfig
Definition pf_config.c:1123
void pf_server_config_print(const proxyConfig *config)
pf_server_config_print Print the configuration to stdout
Definition pf_config.c:1031
const char ** pf_config_modules(const proxyConfig *config)
pf_config_modules
Definition pf_config.c:1175
const char * pf_config_required_plugin(const proxyConfig *config, size_t index)
pf_config_required_plugin
Definition pf_config.c:1160
FreeRDP_ProxyCertPolicy pf_config_policy_from_str(const char *val)
Convert a string to a FreeRDP_ProxyCertPolicy value.
Definition pf_config.c:1635
size_t pf_config_modules_count(const proxyConfig *config)
pf_config_modules_count
Definition pf_config.c:1169
const char * pf_config_policy_to_str(FreeRDP_ProxyCertPolicy policy)
Convert a FreeRDP_ProxyCertPolicy value to a string.
Definition pf_config.c:1621
BOOL pf_config_clone(proxyConfig **dst, const proxyConfig *config)
pf_config_clone Create a copy of the configuration
Definition pf_config.c:1228
size_t pf_config_required_plugins_count(const proxyConfig *config)
pf_config_required_plugins_count
Definition pf_config.c:1154
proxyConfig * server_config_load_ini(wIniFile *ini)
server_config_load_ini Create a proxyConfig from a already loaded INI file.
Definition pf_config.c:747
proxyConfig * pf_server_config_load_file(const char *path)
pf_server_config_load_file Create a proxyConfig from a INI file found at path.
Definition pf_config.c:1001
BOOL pf_server_config_dump(const char *file)
pf_server_config_dump Dumps a default INI configuration file
Definition pf_config.c:797
BOOL pf_config_plugin(proxyPluginsManager *plugins_manager, void *userdata)
pf_config_plugin Register a proxy plugin handling event filtering defined in the configuration.
Definition pf_config.c:1579
const char * pf_config_get(const proxyConfig *config, const char *section, const char *key)
pf_config_get get a value for a section/key
Definition pf_config.c:1611