mirror of
https://gitee.com/johng/gf
synced 2026-06-06 02:25:47 +08:00
## What does this PR do? Fixes #4156 When posting form data with file upload, if a field value contains `=` or `&`, the value was being truncated. ### Example ```go data := g.Map{ "file": "@file:/path/to/file.txt", "fieldName": "aaa=1&b=2", } client.Post(ctx, "/upload", data) ``` **Expected**: Server receives `fieldName = "aaa=1&b=2"` **Actual (before fix)**: Server receives `fieldName = "aaa"` (truncated) ## Root Cause Analysis The issue was caused by three problems in the original code: ### Problem 1: Global URL encoding disable (httputils.go) ```go // Original code - PROBLEMATIC if urlEncode { for k, v := range m { if gstr.Contains(k, fileUploadingKey) || gstr.Contains(gconv.String(v), fileUploadingKey) { urlEncode = false // Disables URL encoding for ALL values! break } } } ``` When any value contained `@file:`, URL encoding was disabled for ALL values, causing `"aaa=1&b=2"` to remain unencoded. The `&` character was then treated as a parameter separator. ### Problem 2: Split on all `=` characters (gclient_request.go) ```go // Original code - PROBLEMATIC array := strings.Split(item, "=") // Splits on ALL '=' characters ``` This caused `"fieldName=aaa=1"` to be split into `["fieldName", "aaa", "1"]`. ### Problem 3: No URL decoding for field values URL-encoded values were written directly to the multipart form without decoding. ## Solution ### Fix 1: Remove global URL encoding disable Only `@file:` prefixed values are kept unencoded for file upload detection. Other values are properly URL-encoded. ### Fix 2: Use SplitN to limit split count ```go array := strings.SplitN(item, "=", 2) // Only split on first '=' ``` ### Fix 3: Add URL decoding for field values ```go if v, err := gurl.Decode(fieldValue); err == nil { fieldValue = v } ``` ## Compatibility Analysis | Scenario | Before | After | Compatible | |----------|--------|-------|------------| | Normal form POST (no file upload) | ✅ Works | ✅ Works | ✅ Yes | | File upload + normal field values | ✅ Works | ✅ Works | ✅ Yes | | File upload + field values containing `=` or `&` | ❌ Truncated | ✅ Works | ✅ Fixed | | Field value is `@file:` (no path) | ✅ Works | ✅ Works | ✅ Yes | | Field value starts with `@file:` but file doesn't exist | ❌ Error | ❌ Error | ✅ Yes | | User sends pre-encoded value like `"aaa%3D1"` | ✅ Works | ✅ Works | ✅ Yes | | Content-Type: application/json | ✅ Works | ✅ Works | ✅ Yes | | Content-Type: application/xml | ✅ Works | ✅ Works | ✅ Yes | ### Breaking Change Assessment **No breaking changes.** The fix only affects the file upload scenario where field values contain special characters (`=`, `&`). Previously this scenario was broken, now it works correctly. ### Edge Cases 1. **Literal `@file:` value**: GoFrame treats `@file:` as a special marker for file upload. This is a framework design decision and remains unchanged. 2. **URL decode failure**: If URL decoding fails (e.g., invalid `%XX` sequence), the original value is preserved. ## Test Coverage Added comprehensive tests covering: - `Test_Issue4156` - Basic fix verification - `Test_Issue4156_MultipleSpecialChars` - Multiple `=`, `&`, `%`, `+`, spaces - `Test_Issue4156_MultipleFields` - Multiple fields with special characters - `Test_Issue4156_NoFileUpload` - Normal POST without file upload - `Test_Issue4156_PreEncodedValue` - Pre-encoded values like `%3D` - `Test_Issue4156_EmptyAndSpecialValues` - Edge cases (`=` at start/end, only special chars) - `TestBuildParams_*` - httputil.BuildParams comprehensive tests All tests pass, including existing `Test_Issue3748` which tests the `@file:` marker handling. ## Files Changed - `internal/httputil/httputils.go` - Remove global URL encoding disable, adjust `@file:` condition - `internal/httputil/httputils_test.go` - Add comprehensive BuildParams tests - `net/gclient/gclient_request.go` - Use SplitN, add URL decoding - `net/gclient/gclient_z_unit_issue_test.go` - Add Issue 4156 test cases
409 lines
13 KiB
Go
409 lines
13 KiB
Go
// Copyright GoFrame Author(https://goframe.org). All Rights Reserved.
|
|
//
|
|
// This Source Code Form is subject to the terms of the MIT License.
|
|
// If a copy of the MIT was not distributed with this file,
|
|
// You can obtain one at https://github.com/gogf/gf.
|
|
|
|
package gclient
|
|
|
|
import (
|
|
"bytes"
|
|
"context"
|
|
"io"
|
|
"mime"
|
|
"mime/multipart"
|
|
"net/http"
|
|
"os"
|
|
"strings"
|
|
"time"
|
|
|
|
"github.com/gogf/gf/v2/encoding/gjson"
|
|
"github.com/gogf/gf/v2/encoding/gurl"
|
|
"github.com/gogf/gf/v2/errors/gcode"
|
|
"github.com/gogf/gf/v2/errors/gerror"
|
|
"github.com/gogf/gf/v2/internal/httputil"
|
|
"github.com/gogf/gf/v2/internal/json"
|
|
"github.com/gogf/gf/v2/internal/utils"
|
|
"github.com/gogf/gf/v2/os/gfile"
|
|
"github.com/gogf/gf/v2/os/gtime"
|
|
"github.com/gogf/gf/v2/text/gregex"
|
|
"github.com/gogf/gf/v2/text/gstr"
|
|
"github.com/gogf/gf/v2/util/gconv"
|
|
)
|
|
|
|
// Get send GET request and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) Get(ctx context.Context, url string, data ...any) (*Response, error) {
|
|
return c.DoRequest(ctx, http.MethodGet, url, data...)
|
|
}
|
|
|
|
// Put send PUT request and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) Put(ctx context.Context, url string, data ...any) (*Response, error) {
|
|
return c.DoRequest(ctx, http.MethodPut, url, data...)
|
|
}
|
|
|
|
// Post sends request using HTTP method POST and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) Post(ctx context.Context, url string, data ...any) (*Response, error) {
|
|
return c.DoRequest(ctx, http.MethodPost, url, data...)
|
|
}
|
|
|
|
// Delete send DELETE request and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) Delete(ctx context.Context, url string, data ...any) (*Response, error) {
|
|
return c.DoRequest(ctx, http.MethodDelete, url, data...)
|
|
}
|
|
|
|
// Head send HEAD request and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) Head(ctx context.Context, url string, data ...any) (*Response, error) {
|
|
return c.DoRequest(ctx, http.MethodHead, url, data...)
|
|
}
|
|
|
|
// Patch send PATCH request and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) Patch(ctx context.Context, url string, data ...any) (*Response, error) {
|
|
return c.DoRequest(ctx, http.MethodPatch, url, data...)
|
|
}
|
|
|
|
// Connect send CONNECT request and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) Connect(ctx context.Context, url string, data ...any) (*Response, error) {
|
|
return c.DoRequest(ctx, http.MethodConnect, url, data...)
|
|
}
|
|
|
|
// Options send OPTIONS request and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) Options(ctx context.Context, url string, data ...any) (*Response, error) {
|
|
return c.DoRequest(ctx, http.MethodOptions, url, data...)
|
|
}
|
|
|
|
// Trace send TRACE request and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) Trace(ctx context.Context, url string, data ...any) (*Response, error) {
|
|
return c.DoRequest(ctx, http.MethodTrace, url, data...)
|
|
}
|
|
|
|
// PostForm is different from net/http.PostForm.
|
|
// It's a wrapper of Post method, which sets the Content-Type as "multipart/form-data;".
|
|
// and It will automatically set boundary characters for the request body and Content-Type.
|
|
//
|
|
// It's Seem like the following case:
|
|
//
|
|
// Content-Type: multipart/form-data; boundary=----Boundarye4Ghaog6giyQ9ncN
|
|
//
|
|
// And form data is like:
|
|
// ------Boundarye4Ghaog6giyQ9ncN
|
|
// Content-Disposition: form-data; name="checkType"
|
|
//
|
|
// none
|
|
//
|
|
// It's used for sending form data.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) PostForm(ctx context.Context, url string, data map[string]string) (resp *Response, err error) {
|
|
body := new(bytes.Buffer)
|
|
w := multipart.NewWriter(body)
|
|
for k, v := range data {
|
|
err := w.WriteField(k, v)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
}
|
|
err = w.Close()
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return c.ContentType(w.FormDataContentType()).Post(ctx, url, body)
|
|
}
|
|
|
|
// DoRequest sends request with given HTTP method and data and returns the response object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
//
|
|
// Note that it uses "multipart/form-data" as its Content-Type if it contains file uploading,
|
|
// else it uses "application/x-www-form-urlencoded". It also automatically detects the post
|
|
// content for JSON format, and for that it automatically sets the Content-Type as
|
|
// "application/json".
|
|
func (c *Client) DoRequest(
|
|
ctx context.Context, method, url string, data ...any,
|
|
) (resp *Response, err error) {
|
|
var requestStartTime = gtime.Now()
|
|
req, err := c.prepareRequest(ctx, method, url, data...)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
// Metrics.
|
|
c.handleMetricsBeforeRequest(req)
|
|
defer c.handleMetricsAfterRequestDone(req, requestStartTime)
|
|
|
|
// Client middleware.
|
|
if len(c.middlewareHandler) > 0 {
|
|
mdlHandlers := make([]HandlerFunc, 0, len(c.middlewareHandler)+1)
|
|
mdlHandlers = append(mdlHandlers, c.middlewareHandler...)
|
|
mdlHandlers = append(mdlHandlers, func(cli *Client, r *http.Request) (*Response, error) {
|
|
return cli.callRequest(r)
|
|
})
|
|
ctx = context.WithValue(req.Context(), clientMiddlewareKey, &clientMiddleware{
|
|
client: c,
|
|
handlers: mdlHandlers,
|
|
handlerIndex: -1,
|
|
})
|
|
req = req.WithContext(ctx)
|
|
resp, err = c.Next(req)
|
|
} else {
|
|
resp, err = c.callRequest(req)
|
|
}
|
|
if resp != nil && resp.Response != nil {
|
|
req.Response = resp.Response
|
|
}
|
|
return resp, err
|
|
}
|
|
|
|
// prepareRequest verifies request parameters, builds and returns http request.
|
|
func (c *Client) prepareRequest(ctx context.Context, method, url string, data ...any) (req *http.Request, err error) {
|
|
method = strings.ToUpper(method)
|
|
if len(c.prefix) > 0 {
|
|
url = c.prefix + gstr.Trim(url)
|
|
}
|
|
if !gstr.ContainsI(url, httpProtocolName) {
|
|
url = httpProtocolName + `://` + url
|
|
}
|
|
var (
|
|
params string
|
|
allowFileUploading = true
|
|
)
|
|
if len(data) > 0 {
|
|
mediaType, _, err := mime.ParseMediaType(c.header[httpHeaderContentType])
|
|
if err != nil {
|
|
// Fallback: use the raw header value if parsing fails.
|
|
mediaType = c.header[httpHeaderContentType]
|
|
}
|
|
switch mediaType {
|
|
case httpHeaderContentTypeJson:
|
|
switch data[0].(type) {
|
|
case string, []byte:
|
|
params = gconv.String(data[0])
|
|
default:
|
|
if b, err := json.Marshal(data[0]); err != nil {
|
|
return nil, err
|
|
} else {
|
|
params = string(b)
|
|
}
|
|
}
|
|
allowFileUploading = false
|
|
|
|
case httpHeaderContentTypeXml:
|
|
switch data[0].(type) {
|
|
case string, []byte:
|
|
params = gconv.String(data[0])
|
|
default:
|
|
if b, err := gjson.New(data[0]).ToXml(); err != nil {
|
|
return nil, err
|
|
} else {
|
|
params = string(b)
|
|
}
|
|
}
|
|
allowFileUploading = false
|
|
|
|
default:
|
|
params = httputil.BuildParams(data[0], c.noUrlEncode)
|
|
}
|
|
}
|
|
if method == http.MethodGet {
|
|
var bodyBuffer *bytes.Buffer
|
|
if params != "" {
|
|
mediaType, _, err := mime.ParseMediaType(c.header[httpHeaderContentType])
|
|
if err != nil {
|
|
// Fallback: use the raw header value if parsing fails.
|
|
mediaType = c.header[httpHeaderContentType]
|
|
}
|
|
switch mediaType {
|
|
case
|
|
httpHeaderContentTypeJson,
|
|
httpHeaderContentTypeXml:
|
|
bodyBuffer = bytes.NewBuffer([]byte(params))
|
|
default:
|
|
// It appends the parameters to the url
|
|
// if http method is GET and Content-Type is not specified.
|
|
if gstr.Contains(url, "?") {
|
|
url = url + "&" + params
|
|
} else {
|
|
url = url + "?" + params
|
|
}
|
|
bodyBuffer = bytes.NewBuffer(nil)
|
|
}
|
|
} else {
|
|
bodyBuffer = bytes.NewBuffer(nil)
|
|
}
|
|
if req, err = http.NewRequest(method, url, bodyBuffer); err != nil {
|
|
err = gerror.Wrapf(err, `http.NewRequest failed with method "%s" and URL "%s"`, method, url)
|
|
return nil, err
|
|
}
|
|
} else {
|
|
if allowFileUploading && strings.Contains(params, httpParamFileHolder) {
|
|
// File uploading request.
|
|
var (
|
|
buffer = bytes.NewBuffer(nil)
|
|
writer = multipart.NewWriter(buffer)
|
|
isFileUploading = false
|
|
)
|
|
for _, item := range strings.Split(params, "&") {
|
|
array := strings.SplitN(item, "=", 2)
|
|
if len(array) < 2 {
|
|
continue
|
|
}
|
|
if len(array[1]) > 6 && strings.Compare(array[1][0:6], httpParamFileHolder) == 0 {
|
|
path := array[1][6:]
|
|
if !gfile.Exists(path) {
|
|
return nil, gerror.NewCodef(gcode.CodeInvalidParameter, `"%s" does not exist`, path)
|
|
}
|
|
var (
|
|
file io.Writer
|
|
formFileName = gfile.Basename(path)
|
|
formFieldName = array[0]
|
|
)
|
|
// it sets post content type as `application/octet-stream`
|
|
if file, err = writer.CreateFormFile(formFieldName, formFileName); err != nil {
|
|
return nil, gerror.Wrapf(
|
|
err, `CreateFormFile failed with "%s", "%s"`, formFieldName, formFileName,
|
|
)
|
|
}
|
|
var f *os.File
|
|
if f, err = gfile.Open(path); err != nil {
|
|
return nil, err
|
|
}
|
|
if _, err = io.Copy(file, f); err != nil {
|
|
_ = f.Close()
|
|
return nil, gerror.Wrapf(
|
|
err, `io.Copy failed from "%s" to form "%s"`, path, formFieldName,
|
|
)
|
|
}
|
|
if err = f.Close(); err != nil {
|
|
return nil, gerror.Wrapf(err, `close file descriptor failed for "%s"`, path)
|
|
}
|
|
isFileUploading = true
|
|
} else {
|
|
var (
|
|
fieldName = array[0]
|
|
fieldValue = array[1]
|
|
)
|
|
// Decode URL-encoded field name and value.
|
|
// If decoding fails, use the original value.
|
|
if v, err := gurl.Decode(fieldName); err == nil {
|
|
fieldName = v
|
|
}
|
|
if v, err := gurl.Decode(fieldValue); err == nil {
|
|
fieldValue = v
|
|
}
|
|
if err = writer.WriteField(fieldName, fieldValue); err != nil {
|
|
return nil, gerror.Wrapf(
|
|
err, `write form field failed with "%s", "%s"`, fieldName, fieldValue,
|
|
)
|
|
}
|
|
}
|
|
}
|
|
// Close finishes the multipart message and writes the trailing
|
|
// boundary end line to the output.
|
|
if err = writer.Close(); err != nil {
|
|
return nil, gerror.Wrapf(err, `form writer close failed`)
|
|
}
|
|
|
|
if req, err = http.NewRequest(method, url, buffer); err != nil {
|
|
return nil, gerror.Wrapf(
|
|
err, `http.NewRequest failed for method "%s" and URL "%s"`, method, url,
|
|
)
|
|
}
|
|
if isFileUploading {
|
|
req.Header.Set(httpHeaderContentType, writer.FormDataContentType())
|
|
}
|
|
} else {
|
|
// Normal request.
|
|
paramBytes := []byte(params)
|
|
if req, err = http.NewRequest(method, url, bytes.NewReader(paramBytes)); err != nil {
|
|
err = gerror.Wrapf(err, `http.NewRequest failed for method "%s" and URL "%s"`, method, url)
|
|
return nil, err
|
|
}
|
|
if v, ok := c.header[httpHeaderContentType]; ok {
|
|
// Custom Content-Type.
|
|
req.Header.Set(httpHeaderContentType, v)
|
|
} else if len(paramBytes) > 0 {
|
|
if (paramBytes[0] == '[' || paramBytes[0] == '{') && json.Valid(paramBytes) {
|
|
// Auto-detecting and setting the post content format: JSON.
|
|
req.Header.Set(httpHeaderContentType, httpHeaderContentTypeJson)
|
|
} else if gregex.IsMatchString(httpRegexParamJson, params) {
|
|
// If the parameters passed like "name=value", it then uses form type.
|
|
req.Header.Set(httpHeaderContentType, httpHeaderContentTypeForm)
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
// Context.
|
|
if ctx != nil {
|
|
req = req.WithContext(ctx)
|
|
}
|
|
// Custom header.
|
|
if len(c.header) > 0 {
|
|
for k, v := range c.header {
|
|
req.Header.Set(k, v)
|
|
}
|
|
}
|
|
// It's necessary set the req.Host if you want to custom the host value of the request.
|
|
// It uses the "Host" value from header if it's not empty.
|
|
if reqHeaderHost := req.Header.Get(httpHeaderHost); reqHeaderHost != "" {
|
|
req.Host = reqHeaderHost
|
|
}
|
|
// Custom Cookie.
|
|
if len(c.cookies) > 0 {
|
|
headerCookie := ""
|
|
for k, v := range c.cookies {
|
|
if len(headerCookie) > 0 {
|
|
headerCookie += ";"
|
|
}
|
|
headerCookie += k + "=" + v
|
|
}
|
|
if len(headerCookie) > 0 {
|
|
req.Header.Set(httpHeaderCookie, headerCookie)
|
|
}
|
|
}
|
|
// HTTP basic authentication.
|
|
if len(c.authUser) > 0 {
|
|
req.SetBasicAuth(c.authUser, c.authPass)
|
|
}
|
|
return req, nil
|
|
}
|
|
|
|
// callRequest sends request with give http.Request, and returns the responses object.
|
|
// Note that the response object MUST be closed if it'll never be used.
|
|
func (c *Client) callRequest(req *http.Request) (resp *Response, err error) {
|
|
resp = &Response{
|
|
request: req,
|
|
}
|
|
// Dump feature.
|
|
// The request body can be reused for dumping
|
|
// raw HTTP request-response procedure.
|
|
reqBodyContent, _ := io.ReadAll(req.Body)
|
|
resp.requestBody = reqBodyContent
|
|
for {
|
|
req.Body = utils.NewReadCloser(reqBodyContent, false)
|
|
if resp.Response, err = c.Do(req); err != nil {
|
|
err = gerror.Wrapf(err, `request failed`)
|
|
// The response might not be nil when err != nil.
|
|
if resp.Response != nil {
|
|
_ = resp.Body.Close()
|
|
}
|
|
if c.retryCount > 0 {
|
|
c.retryCount--
|
|
time.Sleep(c.retryInterval)
|
|
} else {
|
|
// return resp, err
|
|
break
|
|
}
|
|
} else {
|
|
break
|
|
}
|
|
}
|
|
return resp, err
|
|
}
|