ntopng/include/HTTPserver.h
emanuele-f a70dce4301 Secure ntopng cookies with SameSite and HttpOnly
HttpOnly prevents the cookie from being accessed by javascript code and restricts XMLHttpObject utilization.
See https://blog.codinghorror.com/protecting-your-cookies-httponly/ .

SameSite=lax restricts cookie utilization in iframes, images or XMLHttpRequests, but still allows external
sites to link to the ntopng webserver and use the existing authenticated user session.
See https://www.sjoerdlangkemper.nl/2016/04/14/preventing-csrf-with-samesite-cookie-attribute/ .
2018-05-16 11:43:23 +02:00

55 lines
1.8 KiB
C++

/*
*
* (C) 2013-18 - ntop.org
*
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software Foundation,
* Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
*
*/
#ifndef _HTTP_SERVER_H_
#define _HTTP_SERVER_H_
#include "ntop_includes.h"
/* Global used for enabling/disabling user authentication */
extern bool enable_users_login;
class HTTPserver {
private:
char *docs_dir, *scripts_dir;
struct mg_context *httpd_v4;
bool ssl_enabled;
u_int16_t http_splash_port;
public:
HTTPserver(const char *_docs_dir, const char *_scripts_dir);
~HTTPserver();
bool valid_user_pwd(char *user, char *pass);
inline char* get_docs_dir() { return(docs_dir); };
inline char* get_scripts_dir() { return(scripts_dir); };
inline bool is_ssl_enabled() { return(ssl_enabled); };
inline u_int16_t getSplashPort() { return(http_splash_port); };
};
extern int send_error(struct mg_connection *conn, int status, const char *reason, const char *fmt, ...);
const char *get_secure_cookie_attributes(const struct mg_request_info *request_info);
/* mongoose */
extern int url_decode(const char *src, int src_len, char *dst, int dst_len, int is_form_url_encoded);
#endif /* _HTTP_SERVER_H_ */