script/dom/
xmlhttprequest.rs

1/* This Source Code Form is subject to the terms of the Mozilla Public
2 * License, v. 2.0. If a copy of the MPL was not distributed with this
3 * file, You can obtain one at https://mozilla.org/MPL/2.0/. */
4
5use std::borrow::ToOwned;
6use std::cell::Cell;
7use std::cmp;
8use std::default::Default;
9use std::str::{self, FromStr};
10use std::sync::{Arc, Mutex};
11use std::time::{Duration, Instant};
12
13use constellation_traits::BlobImpl;
14use data_url::mime::Mime;
15use dom_struct::dom_struct;
16use encoding_rs::{Encoding, UTF_8};
17use headers::{ContentLength, ContentType, HeaderMapExt};
18use html5ever::serialize;
19use html5ever::serialize::SerializeOpts;
20use http::Method;
21use http::header::{self, HeaderMap, HeaderName, HeaderValue};
22use hyper_serde::Serde;
23use js::jsapi::{Heap, JS_ClearPendingException};
24use js::jsval::{JSVal, NullValue};
25use js::rust::wrappers::JS_ParseJSON;
26use js::rust::{HandleObject, MutableHandleValue};
27use js::typedarray::{ArrayBuffer, ArrayBufferU8};
28use net_traits::fetch::headers::extract_mime_type_as_dataurl_mime;
29use net_traits::http_status::HttpStatus;
30use net_traits::request::{CredentialsMode, Referrer, RequestBuilder, RequestId, RequestMode};
31use net_traits::{
32    FetchMetadata, FetchResponseListener, FilteredMetadata, NetworkError, ReferrerPolicy,
33    ResourceFetchTiming, ResourceTimingType, trim_http_whitespace,
34};
35use script_bindings::conversions::SafeToJSValConvertible;
36use script_bindings::num::Finite;
37use script_traits::DocumentActivity;
38use servo_url::ServoUrl;
39use stylo_atoms::Atom;
40use url::Position;
41
42use crate::body::{BodySource, Extractable, ExtractedBody, decode_to_utf16_with_bom_removal};
43use crate::document_loader::DocumentLoader;
44use crate::dom::bindings::buffer_source::HeapBufferSource;
45use crate::dom::bindings::cell::DomRefCell;
46use crate::dom::bindings::codegen::Bindings::WindowBinding::WindowMethods;
47use crate::dom::bindings::codegen::Bindings::XMLHttpRequestBinding::{
48    XMLHttpRequestMethods, XMLHttpRequestResponseType,
49};
50use crate::dom::bindings::codegen::UnionTypes::DocumentOrBlobOrArrayBufferViewOrArrayBufferOrFormDataOrStringOrURLSearchParams as DocumentOrXMLHttpRequestBodyInit;
51use crate::dom::bindings::error::{Error, ErrorResult, Fallible};
52use crate::dom::bindings::inheritance::Castable;
53use crate::dom::bindings::refcounted::Trusted;
54use crate::dom::bindings::reflector::{DomGlobal, reflect_dom_object_with_proto};
55use crate::dom::bindings::root::{Dom, DomRoot, MutNullableDom};
56use crate::dom::bindings::str::{ByteString, DOMString, USVString, is_token};
57use crate::dom::blob::{Blob, normalize_type_string};
58use crate::dom::csp::{GlobalCspReporting, Violation};
59use crate::dom::document::{Document, DocumentSource, HasBrowsingContext, IsHTMLDocument};
60use crate::dom::event::{Event, EventBubbles, EventCancelable};
61use crate::dom::eventtarget::EventTarget;
62use crate::dom::globalscope::GlobalScope;
63use crate::dom::headers::is_forbidden_request_header;
64use crate::dom::node::Node;
65use crate::dom::performance::performanceresourcetiming::InitiatorType;
66use crate::dom::progressevent::ProgressEvent;
67use crate::dom::readablestream::ReadableStream;
68use crate::dom::servoparser::ServoParser;
69use crate::dom::window::Window;
70use crate::dom::workerglobalscope::WorkerGlobalScope;
71use crate::dom::xmlhttprequesteventtarget::XMLHttpRequestEventTarget;
72use crate::dom::xmlhttprequestupload::XMLHttpRequestUpload;
73use crate::fetch::FetchCanceller;
74use crate::mime::{APPLICATION, CHARSET, HTML, MimeExt, TEXT, XML};
75use crate::network_listener::{self, PreInvoke, ResourceTimingListener};
76use crate::script_runtime::{CanGc, JSContext};
77use crate::task_source::{SendableTaskSource, TaskSourceName};
78use crate::timers::{OneshotTimerCallback, OneshotTimerHandle};
79
80#[derive(Clone, Copy, Debug, JSTraceable, MallocSizeOf, PartialEq)]
81enum XMLHttpRequestState {
82    Unsent = 0,
83    Opened = 1,
84    HeadersReceived = 2,
85    Loading = 3,
86    Done = 4,
87}
88
89#[derive(Clone, Copy, JSTraceable, MallocSizeOf, PartialEq)]
90pub(crate) struct GenerationId(u32);
91
92/// Closure of required data for each async network event that comprises the
93/// XHR's response.
94struct XHRContext {
95    xhr: TrustedXHRAddress,
96    gen_id: GenerationId,
97    sync_status: DomRefCell<Option<ErrorResult>>,
98    resource_timing: ResourceFetchTiming,
99    url: ServoUrl,
100}
101
102impl FetchResponseListener for XHRContext {
103    fn process_request_body(&mut self, _: RequestId) {
104        // todo
105    }
106
107    fn process_request_eof(&mut self, _: RequestId) {
108        // todo
109    }
110
111    fn process_response(&mut self, _: RequestId, metadata: Result<FetchMetadata, NetworkError>) {
112        let xhr = self.xhr.root();
113        let rv = xhr.process_headers_available(self.gen_id, metadata, CanGc::note());
114        if rv.is_err() {
115            *self.sync_status.borrow_mut() = Some(rv);
116        }
117    }
118
119    fn process_response_chunk(&mut self, _: RequestId, chunk: Vec<u8>) {
120        self.xhr
121            .root()
122            .process_data_available(self.gen_id, chunk, CanGc::note());
123    }
124
125    fn process_response_eof(
126        &mut self,
127        _: RequestId,
128        response: Result<ResourceFetchTiming, NetworkError>,
129    ) {
130        let rv = self.xhr.root().process_response_complete(
131            self.gen_id,
132            response.map(|_| ()),
133            CanGc::note(),
134        );
135        *self.sync_status.borrow_mut() = Some(rv);
136    }
137
138    fn resource_timing_mut(&mut self) -> &mut ResourceFetchTiming {
139        &mut self.resource_timing
140    }
141
142    fn resource_timing(&self) -> &ResourceFetchTiming {
143        &self.resource_timing
144    }
145
146    fn submit_resource_timing(&mut self) {
147        network_listener::submit_timing(self, CanGc::note())
148    }
149
150    fn process_csp_violations(&mut self, _request_id: RequestId, violations: Vec<Violation>) {
151        let global = &self.resource_timing_global();
152        global.report_csp_violations(violations, None, None);
153    }
154}
155
156impl ResourceTimingListener for XHRContext {
157    fn resource_timing_information(&self) -> (InitiatorType, ServoUrl) {
158        (InitiatorType::XMLHttpRequest, self.url.clone())
159    }
160
161    fn resource_timing_global(&self) -> DomRoot<GlobalScope> {
162        self.xhr.root().global()
163    }
164}
165
166impl PreInvoke for XHRContext {
167    fn should_invoke(&self) -> bool {
168        self.xhr.root().generation_id.get() == self.gen_id
169    }
170}
171
172#[derive(Clone)]
173pub(crate) enum XHRProgress {
174    /// Notify that headers have been received
175    HeadersReceived(GenerationId, Option<HeaderMap>, HttpStatus),
176    /// Partial progress (after receiving headers), containing portion of the response
177    Loading(GenerationId, Vec<u8>),
178    /// Loading is done
179    Done(GenerationId),
180    /// There was an error (only Error::Abort, Error::Timeout or Error::Network is used)
181    Errored(GenerationId, Error),
182}
183
184impl XHRProgress {
185    fn generation_id(&self) -> GenerationId {
186        match *self {
187            XHRProgress::HeadersReceived(id, _, _) |
188            XHRProgress::Loading(id, _) |
189            XHRProgress::Done(id) |
190            XHRProgress::Errored(id, _) => id,
191        }
192    }
193}
194
195#[dom_struct]
196pub(crate) struct XMLHttpRequest {
197    eventtarget: XMLHttpRequestEventTarget,
198    ready_state: Cell<XMLHttpRequestState>,
199    timeout: Cell<Duration>,
200    with_credentials: Cell<bool>,
201    upload: Dom<XMLHttpRequestUpload>,
202    response_url: DomRefCell<String>,
203    #[no_trace]
204    status: DomRefCell<HttpStatus>,
205    response: DomRefCell<Vec<u8>>,
206    response_type: Cell<XMLHttpRequestResponseType>,
207    response_xml: MutNullableDom<Document>,
208    response_blob: MutNullableDom<Blob>,
209    #[ignore_malloc_size_of = "mozjs"]
210    response_arraybuffer: HeapBufferSource<ArrayBufferU8>,
211    #[ignore_malloc_size_of = "Defined in rust-mozjs"]
212    response_json: Heap<JSVal>,
213    #[ignore_malloc_size_of = "Defined in hyper"]
214    #[no_trace]
215    response_headers: DomRefCell<HeaderMap>,
216    #[ignore_malloc_size_of = "Defined in hyper"]
217    #[no_trace]
218    override_mime_type: DomRefCell<Option<Mime>>,
219
220    // Associated concepts
221    #[ignore_malloc_size_of = "Defined in hyper"]
222    #[no_trace]
223    request_method: DomRefCell<Method>,
224    #[no_trace]
225    request_url: DomRefCell<Option<ServoUrl>>,
226    #[ignore_malloc_size_of = "Defined in hyper"]
227    #[no_trace]
228    request_headers: DomRefCell<HeaderMap>,
229    request_body_len: Cell<usize>,
230    sync: Cell<bool>,
231    upload_complete: Cell<bool>,
232    upload_listener: Cell<bool>,
233    send_flag: Cell<bool>,
234
235    timeout_cancel: DomRefCell<Option<OneshotTimerHandle>>,
236    fetch_time: Cell<Instant>,
237    generation_id: Cell<GenerationId>,
238    response_status: Cell<Result<(), ()>>,
239    #[no_trace]
240    referrer: Referrer,
241    #[no_trace]
242    referrer_policy: ReferrerPolicy,
243    canceller: DomRefCell<FetchCanceller>,
244}
245
246impl XMLHttpRequest {
247    fn new_inherited(global: &GlobalScope, can_gc: CanGc) -> XMLHttpRequest {
248        XMLHttpRequest {
249            eventtarget: XMLHttpRequestEventTarget::new_inherited(),
250            ready_state: Cell::new(XMLHttpRequestState::Unsent),
251            timeout: Cell::new(Duration::ZERO),
252            with_credentials: Cell::new(false),
253            upload: Dom::from_ref(&*XMLHttpRequestUpload::new(global, can_gc)),
254            response_url: DomRefCell::new(String::new()),
255            status: DomRefCell::new(HttpStatus::new_error()),
256            response: DomRefCell::new(vec![]),
257            response_type: Cell::new(XMLHttpRequestResponseType::_empty),
258            response_xml: Default::default(),
259            response_blob: Default::default(),
260            response_arraybuffer: HeapBufferSource::default(),
261            response_json: Heap::default(),
262            response_headers: DomRefCell::new(HeaderMap::new()),
263            override_mime_type: DomRefCell::new(None),
264
265            request_method: DomRefCell::new(Method::GET),
266            request_url: DomRefCell::new(None),
267            request_headers: DomRefCell::new(HeaderMap::new()),
268            request_body_len: Cell::new(0),
269            sync: Cell::new(false),
270            upload_complete: Cell::new(false),
271            upload_listener: Cell::new(false),
272            send_flag: Cell::new(false),
273
274            timeout_cancel: DomRefCell::new(None),
275            fetch_time: Cell::new(Instant::now()),
276            generation_id: Cell::new(GenerationId(0)),
277            response_status: Cell::new(Ok(())),
278            referrer: global.get_referrer(),
279            referrer_policy: global.get_referrer_policy(),
280            canceller: DomRefCell::new(Default::default()),
281        }
282    }
283
284    fn new(
285        global: &GlobalScope,
286        proto: Option<HandleObject>,
287        can_gc: CanGc,
288    ) -> DomRoot<XMLHttpRequest> {
289        reflect_dom_object_with_proto(
290            Box::new(XMLHttpRequest::new_inherited(global, can_gc)),
291            global,
292            proto,
293            can_gc,
294        )
295    }
296
297    fn sync_in_window(&self) -> bool {
298        self.sync.get() && self.global().is::<Window>()
299    }
300}
301
302impl XMLHttpRequestMethods<crate::DomTypeHolder> for XMLHttpRequest {
303    /// <https://xhr.spec.whatwg.org/#constructors>
304    fn Constructor(
305        global: &GlobalScope,
306        proto: Option<HandleObject>,
307        can_gc: CanGc,
308    ) -> Fallible<DomRoot<XMLHttpRequest>> {
309        Ok(XMLHttpRequest::new(global, proto, can_gc))
310    }
311
312    // https://xhr.spec.whatwg.org/#handler-xhr-onreadystatechange
313    event_handler!(
314        readystatechange,
315        GetOnreadystatechange,
316        SetOnreadystatechange
317    );
318
319    /// <https://xhr.spec.whatwg.org/#dom-xmlhttprequest-readystate>
320    fn ReadyState(&self) -> u16 {
321        self.ready_state.get() as u16
322    }
323
324    /// <https://xhr.spec.whatwg.org/#the-open()-method>
325    fn Open(&self, method: ByteString, url: USVString) -> ErrorResult {
326        // Step 8
327        self.Open_(method, url, true, None, None)
328    }
329
330    /// <https://xhr.spec.whatwg.org/#the-open()-method>
331    fn Open_(
332        &self,
333        method: ByteString,
334        url: USVString,
335        asynch: bool,
336        username: Option<USVString>,
337        password: Option<USVString>,
338    ) -> ErrorResult {
339        // Step 1
340        if let Some(window) = DomRoot::downcast::<Window>(self.global()) {
341            if !window.Document().is_fully_active() {
342                return Err(Error::InvalidState(None));
343            }
344        }
345
346        // Step 5
347        // FIXME(seanmonstar): use a Trie instead?
348        let maybe_method = method.as_str().and_then(|s| {
349            // Note: hyper tests against the uppercase versions
350            // Since we want to pass methods not belonging to the short list above
351            // without changing capitalization, this will actually sidestep rust-http's type system
352            // since methods like "patch" or "PaTcH" will be considered extension methods
353            // despite the there being a rust-http method variant for them
354            let upper = s.to_ascii_uppercase();
355            match &*upper {
356                "DELETE" | "GET" | "HEAD" | "OPTIONS" | "POST" | "PUT" | "CONNECT" | "TRACE" |
357                "TRACK" => upper.parse().ok(),
358                _ => s.parse().ok(),
359            }
360        });
361
362        match maybe_method {
363            // Step 4
364            Some(Method::CONNECT) | Some(Method::TRACE) => Err(Error::Security),
365            Some(ref t) if t.as_str() == "TRACK" => Err(Error::Security),
366            Some(parsed_method) => {
367                // Step 3
368                if !is_token(&method) {
369                    return Err(Error::Syntax(None));
370                }
371
372                // Step 2
373                let base = self.global().api_base_url();
374                // Step 6
375                let mut parsed_url = match base.join(&url.0) {
376                    Ok(parsed) => parsed,
377                    // Step 7
378                    Err(_) => return Err(Error::Syntax(None)),
379                };
380
381                // Step 9
382                if parsed_url.host().is_some() {
383                    if let Some(user_str) = username {
384                        parsed_url.set_username(&user_str.0).unwrap();
385                    }
386                    if let Some(pass_str) = password {
387                        parsed_url.set_password(Some(&pass_str.0)).unwrap();
388                    }
389                }
390
391                // Step 10
392                if !asynch {
393                    // FIXME: This should only happen if the global environment is a document environment
394                    if !self.timeout.get().is_zero() ||
395                        self.response_type.get() != XMLHttpRequestResponseType::_empty
396                    {
397                        return Err(Error::InvalidAccess);
398                    }
399                }
400                // Step 11 - abort existing requests
401                self.terminate_ongoing_fetch();
402
403                // FIXME(#13767): In the WPT test: FileAPI/blob/Blob-XHR-revoke.html,
404                // the xhr.open(url) is expected to hold a reference to the URL,
405                // thus renders following revocations invalid. Though we won't
406                // implement this for now, if ever needed, we should check blob
407                // scheme and trigger corresponding actions here.
408
409                // Step 12
410                *self.request_method.borrow_mut() = parsed_method;
411                *self.request_url.borrow_mut() = Some(parsed_url);
412                self.sync.set(!asynch);
413                *self.request_headers.borrow_mut() = HeaderMap::new();
414                self.send_flag.set(false);
415                self.upload_listener.set(false);
416                *self.status.borrow_mut() = HttpStatus::new_error();
417
418                // Step 13
419                if self.ready_state.get() != XMLHttpRequestState::Opened {
420                    self.change_ready_state(XMLHttpRequestState::Opened, CanGc::note());
421                }
422                Ok(())
423            },
424            // Step 3
425            // This includes cases where as_str() returns None, and when is_token() returns false,
426            // both of which indicate invalid extension method names
427            _ => Err(Error::Syntax(None)),
428        }
429    }
430
431    /// <https://xhr.spec.whatwg.org/#the-setrequestheader()-method>
432    fn SetRequestHeader(&self, name: ByteString, value: ByteString) -> ErrorResult {
433        // Step 1: If this’s state is not opened, then throw an "InvalidStateError" DOMException.
434        // Step 2: If this’s send() flag is set, then throw an "InvalidStateError" DOMException.
435        if self.ready_state.get() != XMLHttpRequestState::Opened || self.send_flag.get() {
436            return Err(Error::InvalidState(None));
437        }
438
439        // Step 3: Normalize value.
440        let value = trim_http_whitespace(&value);
441
442        // Step 4: If name is not a header name or value is not a header value, then throw a
443        // "SyntaxError" DOMException.
444        if !is_token(&name) || !is_field_value(value) {
445            return Err(Error::Syntax(None));
446        }
447
448        let name_str = name.as_str().ok_or(Error::Syntax(None))?;
449
450        // Step 5: If (name, value) is a forbidden request-header, then return.
451        if is_forbidden_request_header(name_str, value) {
452            return Ok(());
453        }
454
455        debug!(
456            "SetRequestHeader: name={:?}, value={:?}",
457            name_str,
458            str::from_utf8(value).ok()
459        );
460        let mut headers = self.request_headers.borrow_mut();
461
462        // Step 6: Combine (name, value) in this’s author request headers.
463        // https://fetch.spec.whatwg.org/#concept-header-list-combine
464        let value = match headers.get(name_str).map(HeaderValue::as_bytes) {
465            Some(raw) => {
466                let mut buf = raw.to_vec();
467                buf.extend_from_slice(b", ");
468                buf.extend_from_slice(value);
469                buf
470            },
471            None => value.into(),
472        };
473
474        headers.insert(
475            HeaderName::from_str(name_str).unwrap(),
476            HeaderValue::from_bytes(&value).unwrap(),
477        );
478        Ok(())
479    }
480
481    /// <https://xhr.spec.whatwg.org/#the-timeout-attribute>
482    fn Timeout(&self) -> u32 {
483        self.timeout.get().as_millis() as u32
484    }
485
486    /// <https://xhr.spec.whatwg.org/#the-timeout-attribute>
487    fn SetTimeout(&self, timeout: u32) -> ErrorResult {
488        // Step 1
489        if self.sync_in_window() {
490            return Err(Error::InvalidAccess);
491        }
492
493        // Step 2
494        let timeout = Duration::from_millis(timeout as u64);
495        self.timeout.set(timeout);
496
497        if self.send_flag.get() {
498            if timeout.is_zero() {
499                self.cancel_timeout();
500                return Ok(());
501            }
502            let progress = Instant::now() - self.fetch_time.get();
503            if timeout > progress {
504                self.set_timeout(timeout - progress);
505            } else {
506                // Immediately execute the timeout steps
507                self.set_timeout(Duration::ZERO);
508            }
509        }
510        Ok(())
511    }
512
513    /// <https://xhr.spec.whatwg.org/#the-withcredentials-attribute>
514    fn WithCredentials(&self) -> bool {
515        self.with_credentials.get()
516    }
517
518    /// <https://xhr.spec.whatwg.org/#dom-xmlhttprequest-withcredentials>
519    fn SetWithCredentials(&self, with_credentials: bool) -> ErrorResult {
520        match self.ready_state.get() {
521            // Step 1
522            XMLHttpRequestState::HeadersReceived |
523            XMLHttpRequestState::Loading |
524            XMLHttpRequestState::Done => Err(Error::InvalidState(None)),
525            // Step 2
526            _ if self.send_flag.get() => Err(Error::InvalidState(None)),
527            // Step 3
528            _ => {
529                self.with_credentials.set(with_credentials);
530                Ok(())
531            },
532        }
533    }
534
535    /// <https://xhr.spec.whatwg.org/#the-upload-attribute>
536    fn Upload(&self) -> DomRoot<XMLHttpRequestUpload> {
537        DomRoot::from_ref(&*self.upload)
538    }
539
540    /// <https://xhr.spec.whatwg.org/#the-send()-method>
541    fn Send(&self, data: Option<DocumentOrXMLHttpRequestBodyInit>, can_gc: CanGc) -> ErrorResult {
542        // Step 1, 2
543        if self.ready_state.get() != XMLHttpRequestState::Opened || self.send_flag.get() {
544            return Err(Error::InvalidState(None));
545        }
546
547        // Step 3
548        let data = match *self.request_method.borrow() {
549            Method::GET | Method::HEAD => None,
550            _ => data,
551        };
552        // Step 4 (first half)
553        let mut extracted_or_serialized = match data {
554            Some(DocumentOrXMLHttpRequestBodyInit::Document(ref doc)) => {
555                let bytes = Vec::from(&*serialize_document(doc)?.as_bytes());
556                let content_type = if doc.is_html_document() {
557                    "text/html;charset=UTF-8"
558                } else {
559                    "application/xml;charset=UTF-8"
560                };
561                let total_bytes = bytes.len();
562                let global = self.global();
563                let stream = ReadableStream::new_from_bytes(&global, bytes, can_gc)?;
564                Some(ExtractedBody {
565                    stream,
566                    total_bytes: Some(total_bytes),
567                    content_type: Some(DOMString::from(content_type)),
568                    source: BodySource::Object,
569                })
570            },
571            Some(DocumentOrXMLHttpRequestBodyInit::Blob(ref b)) => {
572                let extracted_body = b
573                    .extract(&self.global(), can_gc)
574                    .expect("Couldn't extract body.");
575                if !extracted_body.in_memory() && self.sync.get() {
576                    warn!("Sync XHR with not in-memory Blob as body not supported");
577                    None
578                } else {
579                    Some(extracted_body)
580                }
581            },
582            Some(DocumentOrXMLHttpRequestBodyInit::FormData(ref formdata)) => Some(
583                formdata
584                    .extract(&self.global(), can_gc)
585                    .expect("Couldn't extract body."),
586            ),
587            Some(DocumentOrXMLHttpRequestBodyInit::String(ref str)) => Some(
588                str.extract(&self.global(), can_gc)
589                    .expect("Couldn't extract body."),
590            ),
591            Some(DocumentOrXMLHttpRequestBodyInit::URLSearchParams(ref urlsp)) => Some(
592                urlsp
593                    .extract(&self.global(), can_gc)
594                    .expect("Couldn't extract body."),
595            ),
596            Some(DocumentOrXMLHttpRequestBodyInit::ArrayBuffer(ref typedarray)) => {
597                let bytes = typedarray.to_vec();
598                let total_bytes = bytes.len();
599                let global = self.global();
600                let stream = ReadableStream::new_from_bytes(&global, bytes, can_gc)?;
601                Some(ExtractedBody {
602                    stream,
603                    total_bytes: Some(total_bytes),
604                    content_type: None,
605                    source: BodySource::Object,
606                })
607            },
608            Some(DocumentOrXMLHttpRequestBodyInit::ArrayBufferView(ref typedarray)) => {
609                let bytes = typedarray.to_vec();
610                let total_bytes = bytes.len();
611                let global = self.global();
612                let stream = ReadableStream::new_from_bytes(&global, bytes, can_gc)?;
613                Some(ExtractedBody {
614                    stream,
615                    total_bytes: Some(total_bytes),
616                    content_type: None,
617                    source: BodySource::Object,
618                })
619            },
620            None => None,
621        };
622
623        self.request_body_len.set(
624            extracted_or_serialized
625                .as_ref()
626                .map_or(0, |e| e.total_bytes.unwrap_or(0)),
627        );
628
629        // Step 5
630        // If we dont have data to upload, we dont want to emit events
631        let has_handlers = self.upload.upcast::<EventTarget>().has_handlers();
632        self.upload_listener.set(has_handlers && data.is_some());
633
634        // todo preserved headers?
635
636        // Step 7
637        self.upload_complete.set(false);
638        // Step 8
639        // FIXME handle the 'timed out flag'
640        // Step 9
641        self.upload_complete.set(extracted_or_serialized.is_none());
642        // Step 10
643        self.send_flag.set(true);
644
645        // Step 11
646        if !self.sync.get() {
647            // If one of the event handlers below aborts the fetch by calling
648            // abort or open we will need the current generation id to detect it.
649            // Substep 1
650            let gen_id = self.generation_id.get();
651            self.dispatch_response_progress_event(atom!("loadstart"), can_gc);
652            if self.generation_id.get() != gen_id {
653                return Ok(());
654            }
655            // Substep 2
656            if !self.upload_complete.get() && self.upload_listener.get() {
657                self.dispatch_upload_progress_event(atom!("loadstart"), Ok(Some(0)), can_gc);
658                if self.generation_id.get() != gen_id {
659                    return Ok(());
660                }
661            }
662        }
663
664        // Step 6
665        // TODO - set referrer_policy/referrer_url in request
666        let credentials_mode = if self.with_credentials.get() {
667            CredentialsMode::Include
668        } else {
669            CredentialsMode::CredentialsSameOrigin
670        };
671        let use_url_credentials = if let Some(ref url) = *self.request_url.borrow() {
672            !url.username().is_empty() || url.password().is_some()
673        } else {
674            unreachable!()
675        };
676
677        let content_type = match extracted_or_serialized.as_mut() {
678            Some(body) => body.content_type.take(),
679            None => None,
680        };
681
682        let global = self.global();
683        let mut request = RequestBuilder::new(
684            global.webview_id(),
685            self.request_url.borrow().clone().unwrap(),
686            self.referrer.clone(),
687        )
688        .method(self.request_method.borrow().clone())
689        .headers((*self.request_headers.borrow()).clone())
690        .unsafe_request(true)
691        // XXXManishearth figure out how to avoid this clone
692        .body(extracted_or_serialized.map(|e| e.into_net_request_body().0))
693        .synchronous(self.sync.get())
694        .mode(RequestMode::CorsMode)
695        .use_cors_preflight(self.upload_listener.get())
696        .credentials_mode(credentials_mode)
697        .use_url_credentials(use_url_credentials)
698        .origin(global.origin().immutable().clone())
699        .referrer_policy(self.referrer_policy)
700        .insecure_requests_policy(global.insecure_requests_policy())
701        .has_trustworthy_ancestor_origin(global.has_trustworthy_ancestor_or_current_origin())
702        .policy_container(global.policy_container())
703        .pipeline_id(Some(global.pipeline_id()));
704
705        // step 4 (second half)
706        if let Some(content_type) = content_type {
707            let encoding = match data {
708                Some(DocumentOrXMLHttpRequestBodyInit::String(_)) |
709                Some(DocumentOrXMLHttpRequestBodyInit::Document(_)) =>
710                // XHR spec differs from http, and says UTF-8 should be in capitals,
711                // instead of "utf-8", which is what Hyper defaults to. So not
712                // using content types provided by Hyper.
713                {
714                    Some("UTF-8")
715                },
716                _ => None,
717            };
718
719            let mut content_type_set = false;
720            if !request.headers.contains_key(header::CONTENT_TYPE) {
721                request.headers.insert(
722                    header::CONTENT_TYPE,
723                    HeaderValue::from_str(&content_type.str()).unwrap(),
724                );
725                content_type_set = true;
726            }
727
728            if !content_type_set {
729                let ct = request.headers.typed_get::<ContentType>();
730                if let Some(ct) = ct {
731                    if let Some(encoding) = encoding {
732                        let mime: Mime = ct.to_string().parse().unwrap();
733                        for param in mime.parameters.iter() {
734                            if param.0 == CHARSET && !param.1.eq_ignore_ascii_case(encoding) {
735                                let params_iter = mime.parameters.iter();
736                                let new_params: Vec<(String, String)> = params_iter
737                                    .filter(|p| p.0 != CHARSET)
738                                    .map(|p| (p.0.clone(), p.1.clone()))
739                                    .collect();
740
741                                let new_mime = format!(
742                                    "{}/{};charset={}{}{}",
743                                    mime.type_,
744                                    mime.subtype,
745                                    encoding,
746                                    if new_params.is_empty() { "" } else { "; " },
747                                    new_params
748                                        .iter()
749                                        .map(|p| format!("{}={}", p.0, p.1))
750                                        .collect::<Vec<String>>()
751                                        .join("; ")
752                                );
753
754                                request.headers.insert(
755                                    header::CONTENT_TYPE,
756                                    HeaderValue::from_str(&new_mime).unwrap(),
757                                );
758                            }
759                        }
760                    }
761                }
762            }
763        }
764
765        self.fetch_time.set(Instant::now());
766
767        let rv = self.fetch(request, &self.global(), can_gc);
768        // Step 10
769        if self.sync.get() {
770            return rv;
771        }
772
773        let timeout = self.timeout.get();
774        if timeout > Duration::ZERO {
775            self.set_timeout(timeout);
776        }
777        Ok(())
778    }
779
780    /// <https://xhr.spec.whatwg.org/#the-abort()-method>
781    fn Abort(&self, can_gc: CanGc) {
782        // Step 1
783        self.terminate_ongoing_fetch();
784        // Step 2
785        let state = self.ready_state.get();
786        if (state == XMLHttpRequestState::Opened && self.send_flag.get()) ||
787            state == XMLHttpRequestState::HeadersReceived ||
788            state == XMLHttpRequestState::Loading
789        {
790            let gen_id = self.generation_id.get();
791            self.process_partial_response(XHRProgress::Errored(gen_id, Error::Abort), can_gc);
792            // If open was called in one of the handlers invoked by the
793            // above call then we should terminate the abort sequence
794            if self.generation_id.get() != gen_id {
795                return;
796            }
797        }
798        // Step 3
799        if self.ready_state.get() == XMLHttpRequestState::Done {
800            self.change_ready_state(XMLHttpRequestState::Unsent, can_gc);
801            self.response_status.set(Err(()));
802            *self.status.borrow_mut() = HttpStatus::new_error();
803            self.response.borrow_mut().clear();
804            self.response_headers.borrow_mut().clear();
805        }
806    }
807
808    /// <https://xhr.spec.whatwg.org/#the-responseurl-attribute>
809    fn ResponseURL(&self) -> USVString {
810        USVString(self.response_url.borrow().clone())
811    }
812
813    /// <https://xhr.spec.whatwg.org/#the-status-attribute>
814    fn Status(&self) -> u16 {
815        self.status.borrow().raw_code()
816    }
817
818    /// <https://xhr.spec.whatwg.org/#the-statustext-attribute>
819    fn StatusText(&self) -> ByteString {
820        ByteString::new(self.status.borrow().message().to_vec())
821    }
822
823    /// <https://xhr.spec.whatwg.org/#the-getresponseheader()-method>
824    fn GetResponseHeader(&self, name: ByteString) -> Option<ByteString> {
825        let headers = self.filter_response_headers();
826        let headers = headers.get_all(HeaderName::from_str(&name.as_str()?.to_lowercase()).ok()?);
827        let mut first = true;
828        let s = headers.iter().fold(Vec::new(), |mut vec, value| {
829            if !first {
830                vec.extend(", ".as_bytes());
831            }
832            if let Ok(v) = str::from_utf8(value.as_bytes()).map(|s| s.trim().as_bytes()) {
833                vec.extend(v);
834                first = false;
835            }
836            vec
837        });
838
839        // There was no header with that name so we never got to change that value
840        if first {
841            None
842        } else {
843            Some(ByteString::new(s))
844        }
845    }
846
847    /// <https://xhr.spec.whatwg.org/#the-getallresponseheaders()-method>
848    fn GetAllResponseHeaders(&self) -> ByteString {
849        let headers = self.filter_response_headers();
850        let keys = headers.keys();
851        let v = keys.fold(Vec::new(), |mut vec, k| {
852            let values = headers.get_all(k);
853            vec.extend(k.as_str().as_bytes());
854            vec.extend(": ".as_bytes());
855            let mut first = true;
856            for value in values {
857                if !first {
858                    vec.extend(", ".as_bytes());
859                    first = false;
860                }
861                vec.extend(value.as_bytes());
862            }
863            vec.extend("\r\n".as_bytes());
864            vec
865        });
866
867        ByteString::new(v)
868    }
869
870    /// <https://xhr.spec.whatwg.org/#the-overridemimetype()-method>
871    fn OverrideMimeType(&self, mime: DOMString) -> ErrorResult {
872        // 1. If this’s state is loading or done, then throw an "InvalidStateError"
873        //   DOMException.
874        match self.ready_state.get() {
875            XMLHttpRequestState::Loading | XMLHttpRequestState::Done => {
876                return Err(Error::InvalidState(None));
877            },
878            _ => {},
879        }
880
881        // 2. Set this’s override MIME type to the result of parsing mime.
882        // 3. If this’s override MIME type is failure, then set this’s override MIME type
883        //    to application/octet-stream.
884        let override_mime = match mime.parse::<Mime>() {
885            Ok(mime) => mime,
886            Err(_) => "application/octet-stream"
887                .parse::<Mime>()
888                .map_err(|_| Error::Syntax(None))?,
889        };
890
891        *self.override_mime_type.borrow_mut() = Some(override_mime);
892        Ok(())
893    }
894
895    /// <https://xhr.spec.whatwg.org/#the-responsetype-attribute>
896    fn ResponseType(&self) -> XMLHttpRequestResponseType {
897        self.response_type.get()
898    }
899
900    /// <https://xhr.spec.whatwg.org/#the-responsetype-attribute>
901    fn SetResponseType(&self, response_type: XMLHttpRequestResponseType) -> ErrorResult {
902        // Step 1
903        if self.global().is::<WorkerGlobalScope>() &&
904            response_type == XMLHttpRequestResponseType::Document
905        {
906            return Ok(());
907        }
908        match self.ready_state.get() {
909            // Step 2
910            XMLHttpRequestState::Loading | XMLHttpRequestState::Done => {
911                Err(Error::InvalidState(None))
912            },
913            _ => {
914                if self.sync_in_window() {
915                    // Step 3
916                    Err(Error::InvalidAccess)
917                } else {
918                    // Step 4
919                    self.response_type.set(response_type);
920                    Ok(())
921                }
922            },
923        }
924    }
925
926    /// <https://xhr.spec.whatwg.org/#the-response-attribute>
927    fn Response(&self, cx: JSContext, can_gc: CanGc, mut rval: MutableHandleValue) {
928        match self.response_type.get() {
929            XMLHttpRequestResponseType::_empty | XMLHttpRequestResponseType::Text => {
930                let ready_state = self.ready_state.get();
931                // Step 2
932                if ready_state == XMLHttpRequestState::Done ||
933                    ready_state == XMLHttpRequestState::Loading
934                {
935                    self.text_response().safe_to_jsval(cx, rval, can_gc);
936                } else {
937                    // Step 1
938                    "".safe_to_jsval(cx, rval, can_gc);
939                }
940            },
941            // Step 1
942            _ if self.ready_state.get() != XMLHttpRequestState::Done => {
943                rval.set(NullValue());
944            },
945            // Step 2
946            XMLHttpRequestResponseType::Document => self
947                .document_response(can_gc)
948                .safe_to_jsval(cx, rval, can_gc),
949            XMLHttpRequestResponseType::Json => self.json_response(cx, rval),
950            XMLHttpRequestResponseType::Blob => {
951                self.blob_response(can_gc).safe_to_jsval(cx, rval, can_gc)
952            },
953            XMLHttpRequestResponseType::Arraybuffer => {
954                match self.arraybuffer_response(cx, can_gc) {
955                    Some(array_buffer) => array_buffer.safe_to_jsval(cx, rval, can_gc),
956                    None => rval.set(NullValue()),
957                }
958            },
959        }
960    }
961
962    /// <https://xhr.spec.whatwg.org/#the-responsetext-attribute>
963    fn GetResponseText(&self) -> Fallible<USVString> {
964        match self.response_type.get() {
965            XMLHttpRequestResponseType::_empty | XMLHttpRequestResponseType::Text => {
966                Ok(USVString(match self.ready_state.get() {
967                    // Step 3
968                    XMLHttpRequestState::Loading | XMLHttpRequestState::Done => {
969                        self.text_response()
970                    },
971                    // Step 2
972                    _ => "".to_owned(),
973                }))
974            },
975            // Step 1
976            _ => Err(Error::InvalidState(None)),
977        }
978    }
979
980    /// <https://xhr.spec.whatwg.org/#the-responsexml-attribute>
981    fn GetResponseXML(&self, can_gc: CanGc) -> Fallible<Option<DomRoot<Document>>> {
982        match self.response_type.get() {
983            XMLHttpRequestResponseType::_empty | XMLHttpRequestResponseType::Document => {
984                // Step 3
985                if let XMLHttpRequestState::Done = self.ready_state.get() {
986                    Ok(self.document_response(can_gc))
987                } else {
988                    // Step 2
989                    Ok(None)
990                }
991            },
992            // Step 1
993            _ => Err(Error::InvalidState(None)),
994        }
995    }
996}
997
998pub(crate) type TrustedXHRAddress = Trusted<XMLHttpRequest>;
999
1000impl XMLHttpRequest {
1001    fn change_ready_state(&self, rs: XMLHttpRequestState, can_gc: CanGc) {
1002        assert_ne!(self.ready_state.get(), rs);
1003        self.ready_state.set(rs);
1004        if rs != XMLHttpRequestState::Unsent {
1005            let event = Event::new(
1006                &self.global(),
1007                atom!("readystatechange"),
1008                EventBubbles::DoesNotBubble,
1009                EventCancelable::Cancelable,
1010                can_gc,
1011            );
1012            event.fire(self.upcast(), can_gc);
1013        }
1014    }
1015
1016    fn process_headers_available(
1017        &self,
1018        gen_id: GenerationId,
1019        metadata: Result<FetchMetadata, NetworkError>,
1020        can_gc: CanGc,
1021    ) -> Result<(), Error> {
1022        let metadata = match metadata {
1023            Ok(meta) => match meta {
1024                FetchMetadata::Unfiltered(m) => m,
1025                FetchMetadata::Filtered { filtered, .. } => match filtered {
1026                    FilteredMetadata::Basic(m) => m,
1027                    FilteredMetadata::Cors(m) => m,
1028                    FilteredMetadata::Opaque => return Err(Error::Network),
1029                    FilteredMetadata::OpaqueRedirect(_) => return Err(Error::Network),
1030                },
1031            },
1032            Err(_) => {
1033                self.process_partial_response(XHRProgress::Errored(gen_id, Error::Network), can_gc);
1034                return Err(Error::Network);
1035            },
1036        };
1037
1038        metadata.final_url[..Position::AfterQuery].clone_into(&mut self.response_url.borrow_mut());
1039
1040        // XXXManishearth Clear cache entries in case of a network error
1041        self.process_partial_response(
1042            XHRProgress::HeadersReceived(
1043                gen_id,
1044                metadata.headers.map(Serde::into_inner),
1045                metadata.status,
1046            ),
1047            can_gc,
1048        );
1049        Ok(())
1050    }
1051
1052    fn process_data_available(&self, gen_id: GenerationId, payload: Vec<u8>, can_gc: CanGc) {
1053        self.process_partial_response(XHRProgress::Loading(gen_id, payload), can_gc);
1054    }
1055
1056    fn process_response_complete(
1057        &self,
1058        gen_id: GenerationId,
1059        status: Result<(), NetworkError>,
1060        can_gc: CanGc,
1061    ) -> ErrorResult {
1062        match status {
1063            Ok(()) => {
1064                self.process_partial_response(XHRProgress::Done(gen_id), can_gc);
1065                Ok(())
1066            },
1067            Err(_) => {
1068                self.process_partial_response(XHRProgress::Errored(gen_id, Error::Network), can_gc);
1069                Err(Error::Network)
1070            },
1071        }
1072    }
1073
1074    fn process_partial_response(&self, progress: XHRProgress, can_gc: CanGc) {
1075        let msg_id = progress.generation_id();
1076
1077        // Aborts processing if abort() or open() was called
1078        // (including from one of the event handlers called below)
1079        macro_rules! return_if_fetch_was_terminated(
1080            () => (
1081                if msg_id != self.generation_id.get() {
1082                    return
1083                }
1084            );
1085        );
1086
1087        // Ignore message if it belongs to a terminated fetch
1088        return_if_fetch_was_terminated!();
1089
1090        // Ignore messages coming from previously-errored responses or requests that have timed out
1091        if self.response_status.get().is_err() {
1092            return;
1093        }
1094
1095        match progress {
1096            XHRProgress::HeadersReceived(_, headers, status) => {
1097                assert!(self.ready_state.get() == XMLHttpRequestState::Opened);
1098                // For synchronous requests, this should not fire any events, and just store data
1099                // XXXManishearth Find a way to track partial progress of the send (onprogresss for XHRUpload)
1100
1101                // Part of step 13, send() (processing request end of file)
1102                // Substep 1
1103                self.upload_complete.set(true);
1104                // Substeps 2-4
1105                if !self.sync.get() && self.upload_listener.get() {
1106                    self.dispatch_upload_progress_event(atom!("progress"), Ok(None), can_gc);
1107                    return_if_fetch_was_terminated!();
1108                    self.dispatch_upload_progress_event(atom!("load"), Ok(None), can_gc);
1109                    return_if_fetch_was_terminated!();
1110                    self.dispatch_upload_progress_event(atom!("loadend"), Ok(None), can_gc);
1111                    return_if_fetch_was_terminated!();
1112                }
1113                // Part of step 13, send() (processing response)
1114                // XXXManishearth handle errors, if any (substep 1)
1115                // Substep 2
1116                if !status.is_error() {
1117                    *self.status.borrow_mut() = status.clone();
1118                }
1119                if let Some(h) = headers.as_ref() {
1120                    *self.response_headers.borrow_mut() = h.clone();
1121                }
1122                {
1123                    let len = headers.and_then(|h| h.typed_get::<ContentLength>());
1124                    let mut response = self.response.borrow_mut();
1125                    response.clear();
1126                    if let Some(len) = len {
1127                        // don't attempt to prereserve more than 4 MB of memory,
1128                        // to avoid giving servers the ability to DOS the client by
1129                        // providing arbitrarily large content-lengths.
1130                        //
1131                        // this number is arbitrary, it's basically big enough that most
1132                        // XHR requests won't hit it, but not so big that it allows for DOS
1133                        let size = cmp::min(0b100_0000000000_0000000000, len.0 as usize);
1134
1135                        // preallocate the buffer
1136                        response.reserve(size);
1137                    }
1138                }
1139                // Substep 3
1140                if !self.sync.get() {
1141                    self.change_ready_state(XMLHttpRequestState::HeadersReceived, can_gc);
1142                }
1143            },
1144            XHRProgress::Loading(_, mut partial_response) => {
1145                // For synchronous requests, this should not fire any events, and just store data
1146                // Part of step 11, send() (processing response body)
1147                // XXXManishearth handle errors, if any (substep 2)
1148
1149                self.response.borrow_mut().append(&mut partial_response);
1150                if !self.sync.get() {
1151                    if self.ready_state.get() == XMLHttpRequestState::HeadersReceived {
1152                        self.ready_state.set(XMLHttpRequestState::Loading);
1153                    }
1154                    let event = Event::new(
1155                        &self.global(),
1156                        atom!("readystatechange"),
1157                        EventBubbles::DoesNotBubble,
1158                        EventCancelable::Cancelable,
1159                        can_gc,
1160                    );
1161                    event.fire(self.upcast(), can_gc);
1162                    return_if_fetch_was_terminated!();
1163                    self.dispatch_response_progress_event(atom!("progress"), can_gc);
1164                }
1165            },
1166            XHRProgress::Done(_) => {
1167                assert!(
1168                    self.ready_state.get() == XMLHttpRequestState::HeadersReceived ||
1169                        self.ready_state.get() == XMLHttpRequestState::Loading ||
1170                        self.sync.get()
1171                );
1172
1173                self.cancel_timeout();
1174                self.canceller.borrow_mut().ignore();
1175
1176                // Part of step 11, send() (processing response end of file)
1177                // XXXManishearth handle errors, if any (substep 2)
1178
1179                // Subsubsteps 6-8
1180                self.send_flag.set(false);
1181
1182                self.change_ready_state(XMLHttpRequestState::Done, can_gc);
1183                return_if_fetch_was_terminated!();
1184                // Subsubsteps 11-12
1185                self.dispatch_response_progress_event(atom!("load"), can_gc);
1186                return_if_fetch_was_terminated!();
1187                self.dispatch_response_progress_event(atom!("loadend"), can_gc);
1188            },
1189            XHRProgress::Errored(_, e) => {
1190                self.cancel_timeout();
1191                self.canceller.borrow_mut().ignore();
1192
1193                self.discard_subsequent_responses();
1194                self.send_flag.set(false);
1195                *self.status.borrow_mut() = HttpStatus::new_error();
1196                self.response_headers.borrow_mut().clear();
1197                // XXXManishearth set response to NetworkError
1198                self.change_ready_state(XMLHttpRequestState::Done, can_gc);
1199                return_if_fetch_was_terminated!();
1200
1201                let errormsg = match e {
1202                    Error::Abort => "abort",
1203                    Error::Timeout => "timeout",
1204                    _ => "error",
1205                };
1206
1207                let upload_complete = &self.upload_complete;
1208                if !upload_complete.get() {
1209                    upload_complete.set(true);
1210                    if self.upload_listener.get() {
1211                        self.dispatch_upload_progress_event(Atom::from(errormsg), Err(()), can_gc);
1212                        return_if_fetch_was_terminated!();
1213                        self.dispatch_upload_progress_event(atom!("loadend"), Err(()), can_gc);
1214                        return_if_fetch_was_terminated!();
1215                    }
1216                }
1217                self.dispatch_response_progress_event(Atom::from(errormsg), can_gc);
1218                return_if_fetch_was_terminated!();
1219                self.dispatch_response_progress_event(atom!("loadend"), can_gc);
1220            },
1221        }
1222    }
1223
1224    fn terminate_ongoing_fetch(&self) {
1225        self.canceller.borrow_mut().cancel();
1226        let GenerationId(prev_id) = self.generation_id.get();
1227        self.generation_id.set(GenerationId(prev_id + 1));
1228        self.response_status.set(Ok(()));
1229    }
1230
1231    fn dispatch_progress_event(
1232        &self,
1233        upload: bool,
1234        type_: Atom,
1235        loaded: u64,
1236        total: Option<u64>,
1237        can_gc: CanGc,
1238    ) {
1239        let (total_length, length_computable) = if self
1240            .response_headers
1241            .borrow()
1242            .contains_key(header::CONTENT_ENCODING)
1243        {
1244            (0, false)
1245        } else {
1246            (total.unwrap_or(0), total.is_some())
1247        };
1248        let progressevent = ProgressEvent::new(
1249            &self.global(),
1250            type_,
1251            EventBubbles::DoesNotBubble,
1252            EventCancelable::NotCancelable,
1253            length_computable,
1254            Finite::wrap(loaded as f64),
1255            Finite::wrap(total_length as f64),
1256            can_gc,
1257        );
1258        let target = if upload {
1259            self.upload.upcast()
1260        } else {
1261            self.upcast()
1262        };
1263        progressevent.upcast::<Event>().fire(target, can_gc);
1264    }
1265
1266    fn dispatch_upload_progress_event(
1267        &self,
1268        type_: Atom,
1269        partial_load: Result<Option<u64>, ()>,
1270        can_gc: CanGc,
1271    ) {
1272        // If partial_load is Ok(None), loading has completed and we can just use the value from the request body
1273        // If an error occured, we pass 0 for both loaded and total
1274
1275        let request_body_len = self.request_body_len.get() as u64;
1276        let (loaded, total) = match partial_load {
1277            Ok(l) => match l {
1278                Some(loaded) => (loaded, Some(request_body_len)),
1279                None => (request_body_len, Some(request_body_len)),
1280            },
1281            Err(()) => (0, None),
1282        };
1283        self.dispatch_progress_event(true, type_, loaded, total, can_gc);
1284    }
1285
1286    fn dispatch_response_progress_event(&self, type_: Atom, can_gc: CanGc) {
1287        let len = self.response.borrow().len() as u64;
1288        let total = self
1289            .response_headers
1290            .borrow()
1291            .typed_get::<ContentLength>()
1292            .map(|v| v.0);
1293        self.dispatch_progress_event(false, type_, len, total, can_gc);
1294    }
1295
1296    fn set_timeout(&self, duration: Duration) {
1297        // Sets up the object to timeout in a given number of milliseconds
1298        // This will cancel all previous timeouts
1299        let callback = OneshotTimerCallback::XhrTimeout(XHRTimeoutCallback {
1300            xhr: Trusted::new(self),
1301            generation_id: self.generation_id.get(),
1302        });
1303        *self.timeout_cancel.borrow_mut() =
1304            Some(self.global().schedule_callback(callback, duration));
1305    }
1306
1307    fn cancel_timeout(&self) {
1308        if let Some(handle) = self.timeout_cancel.borrow_mut().take() {
1309            self.global().unschedule_callback(handle);
1310        }
1311    }
1312
1313    /// <https://xhr.spec.whatwg.org/#text-response>
1314    fn text_response(&self) -> String {
1315        // Step 3, 5
1316        let charset = self.final_charset().unwrap_or(UTF_8);
1317        // TODO: Step 4 - add support for XML encoding guess stuff using XML spec
1318
1319        // According to Simon, decode() should never return an error, so unwrap()ing
1320        // the result should be fine. XXXManishearth have a closer look at this later
1321        // Step 1, 2, 6
1322        let response = self.response.borrow();
1323        let (text, _, _) = charset.decode(&response);
1324        text.into_owned()
1325    }
1326
1327    /// <https://xhr.spec.whatwg.org/#blob-response>
1328    fn blob_response(&self, can_gc: CanGc) -> DomRoot<Blob> {
1329        // Step 1
1330        if let Some(response) = self.response_blob.get() {
1331            return response;
1332        }
1333        // Step 2
1334        let mime = normalize_type_string(&self.final_mime_type().to_string());
1335
1336        // Step 3, 4
1337        let bytes = self.response.borrow().to_vec();
1338        let blob = Blob::new(
1339            &self.global(),
1340            BlobImpl::new_from_bytes(bytes, mime),
1341            can_gc,
1342        );
1343        self.response_blob.set(Some(&blob));
1344        blob
1345    }
1346
1347    /// <https://xhr.spec.whatwg.org/#arraybuffer-response>
1348    fn arraybuffer_response(&self, cx: JSContext, can_gc: CanGc) -> Option<ArrayBuffer> {
1349        // Step 5: Set the response object to a new ArrayBuffer with the received bytes
1350        // For caching purposes, skip this step if the response is already created
1351        if !self.response_arraybuffer.is_initialized() {
1352            let bytes = self.response.borrow();
1353
1354            // If this is not successful, the response won't be set and the function will return None
1355            self.response_arraybuffer
1356                .set_data(cx, &bytes, can_gc)
1357                .ok()?;
1358        }
1359
1360        // Return the correct ArrayBuffer
1361        self.response_arraybuffer.get_typed_array().ok()
1362    }
1363
1364    /// <https://xhr.spec.whatwg.org/#document-response>
1365    fn document_response(&self, can_gc: CanGc) -> Option<DomRoot<Document>> {
1366        // Caching: if we have existing response xml, redirect it directly
1367        let response = self.response_xml.get();
1368        if response.is_some() {
1369            return response;
1370        }
1371
1372        // Step 1: If xhr’s response’s body is null, then return.
1373        if self.response_status.get().is_err() {
1374            return None;
1375        }
1376
1377        // Step 2: Let finalMIME be the result of get a final MIME type for xhr.
1378        let final_mime = self.final_mime_type();
1379
1380        // Step 3: If finalMIME is not an HTML MIME type or an XML MIME type, then return.
1381        let is_xml_mime_type = final_mime.matches(TEXT, XML) ||
1382            final_mime.matches(APPLICATION, XML) ||
1383            final_mime.has_suffix(XML);
1384        if !final_mime.matches(TEXT, HTML) && !is_xml_mime_type {
1385            return None;
1386        }
1387
1388        // Step 4: If xhr’s response type is the empty string and finalMIME is an HTML MIME
1389        //         type, then return.
1390        let charset;
1391        let temp_doc;
1392        if final_mime.matches(TEXT, HTML) {
1393            if self.response_type.get() == XMLHttpRequestResponseType::_empty {
1394                return None;
1395            }
1396
1397            // Step 5: If finalMIME is an HTML MIME type, then:
1398            // Step 5.1: Let charset be the result of get a final encoding for xhr.
1399            // Step 5.2: If charset is null, prescan the first 1024 bytes of xhr’s received bytes
1400            // and if that does not terminate unsuccessfully then let charset be the return value.
1401            // TODO: This isn't happening right now.
1402            // Step 5.3. If charset is null, then set charset to UTF-8.
1403            charset = Some(self.final_charset().unwrap_or(UTF_8));
1404
1405            // Step 5.4: Let document be a document that represents the result parsing xhr’s
1406            // received bytes following the rules set forth in the HTML Standard for an HTML parser
1407            // with scripting disabled and a known definite encoding charset. [HTML]
1408            temp_doc = self.document_text_html(can_gc);
1409        } else {
1410            assert!(is_xml_mime_type);
1411
1412            // Step 6: Otherwise, let document be a document that represents the result of running
1413            // the XML parser with XML scripting support disabled on xhr’s received bytes. If that
1414            // fails (unsupported character encoding, namespace well-formedness error, etc.), then
1415            // return null. [HTML]
1416            //
1417            // TODO: The spec seems to suggest the charset should come from the XML parser here.
1418            temp_doc = self.handle_xml(can_gc);
1419            charset = self.final_charset();
1420
1421            // Not sure it the parser should throw an error for this case
1422            // The specification does not indicates this test,
1423            // but for now we check the document has no child nodes
1424            let has_no_child_nodes = temp_doc.upcast::<Node>().children().next().is_none();
1425            if has_no_child_nodes {
1426                return None;
1427            }
1428        }
1429
1430        // Step 7: If charset is null, then set charset to UTF-8.
1431        let charset = charset.unwrap_or(UTF_8);
1432
1433        // Step 8: Set document’s encoding to charset.
1434        temp_doc.set_encoding(charset);
1435
1436        // Step 9: Set document’s content type to finalMIME.
1437        // Step 10: Set document’s URL to xhr’s response’s URL.
1438        // Step 11: Set document’s origin to xhr’s relevant settings object’s origin.
1439        //
1440        // Done by `handle_text_html()` and `handle_xml()`.
1441
1442        // Step 12: Set xhr’s response object to document.
1443        self.response_xml.set(Some(&temp_doc));
1444        self.response_xml.get()
1445    }
1446
1447    #[allow(unsafe_code)]
1448    /// <https://xhr.spec.whatwg.org/#json-response>
1449    fn json_response(&self, cx: JSContext, mut rval: MutableHandleValue) {
1450        // Step 1
1451        let response_json = self.response_json.get();
1452        if !response_json.is_null_or_undefined() {
1453            return rval.set(response_json);
1454        }
1455        // Step 2
1456        let bytes = self.response.borrow();
1457        // Step 3
1458        if bytes.is_empty() {
1459            return rval.set(NullValue());
1460        }
1461        // Step 4
1462        // https://xhr.spec.whatwg.org/#json-response refers to
1463        // https://infra.spec.whatwg.org/#parse-json-from-bytes which refers to
1464        // https://encoding.spec.whatwg.org/#utf-8-decode which means
1465        // that the encoding is always UTF-8 and the UTF-8 BOM is removed,
1466        // if present, but UTF-16BE/LE BOM must not be honored.
1467        let json_text = decode_to_utf16_with_bom_removal(&bytes, UTF_8);
1468        // Step 5
1469        unsafe {
1470            if !JS_ParseJSON(
1471                *cx,
1472                json_text.as_ptr(),
1473                json_text.len() as u32,
1474                rval.reborrow(),
1475            ) {
1476                JS_ClearPendingException(*cx);
1477                return rval.set(NullValue());
1478            }
1479        }
1480        // Step 6
1481        self.response_json.set(rval.get());
1482    }
1483
1484    fn document_text_html(&self, can_gc: CanGc) -> DomRoot<Document> {
1485        let charset = self.final_charset().unwrap_or(UTF_8);
1486        let wr = self.global();
1487        let response = self.response.borrow();
1488        let (decoded, _, _) = charset.decode(&response);
1489        let document = self.new_doc(IsHTMLDocument::HTMLDocument, can_gc);
1490        // TODO: Disable scripting while parsing
1491        ServoParser::parse_html_document(
1492            &document,
1493            Some(DOMString::from(decoded)),
1494            wr.get_url(),
1495            can_gc,
1496        );
1497        document
1498    }
1499
1500    fn handle_xml(&self, can_gc: CanGc) -> DomRoot<Document> {
1501        let charset = self.final_charset().unwrap_or(UTF_8);
1502        let wr = self.global();
1503        let response = self.response.borrow();
1504        let (decoded, _, _) = charset.decode(&response);
1505        let document = self.new_doc(IsHTMLDocument::NonHTMLDocument, can_gc);
1506        // TODO: Disable scripting while parsing
1507        ServoParser::parse_xml_document(
1508            &document,
1509            Some(DOMString::from(decoded)),
1510            wr.get_url(),
1511            can_gc,
1512        );
1513        document
1514    }
1515
1516    fn new_doc(&self, is_html_document: IsHTMLDocument, can_gc: CanGc) -> DomRoot<Document> {
1517        let wr = self.global();
1518        let win = wr.as_window();
1519        let doc = win.Document();
1520        let docloader = DocumentLoader::new(&doc.loader());
1521        let base = wr.get_url();
1522        let parsed_url = base.join(&self.ResponseURL().0).ok();
1523        let content_type = Some(self.final_mime_type());
1524        Document::new(
1525            win,
1526            HasBrowsingContext::No,
1527            parsed_url,
1528            doc.origin().clone(),
1529            is_html_document,
1530            content_type,
1531            None,
1532            DocumentActivity::Inactive,
1533            DocumentSource::FromParser,
1534            docloader,
1535            None,
1536            None,
1537            Default::default(),
1538            false,
1539            false,
1540            Some(doc.insecure_requests_policy()),
1541            doc.has_trustworthy_ancestor_origin(),
1542            doc.custom_element_reaction_stack(),
1543            doc.creation_sandboxing_flag_set(),
1544            can_gc,
1545        )
1546    }
1547
1548    fn filter_response_headers(&self) -> HeaderMap {
1549        // https://fetch.spec.whatwg.org/#concept-response-header-list
1550        let mut headers = self.response_headers.borrow().clone();
1551        headers.remove(header::SET_COOKIE);
1552        headers.remove(HeaderName::from_static("set-cookie2"));
1553        // XXXManishearth additional CORS filtering goes here
1554        headers
1555    }
1556
1557    fn discard_subsequent_responses(&self) {
1558        self.response_status.set(Err(()));
1559    }
1560
1561    fn fetch(
1562        &self,
1563        request_builder: RequestBuilder,
1564        global: &GlobalScope,
1565        can_gc: CanGc,
1566    ) -> ErrorResult {
1567        let xhr = Trusted::new(self);
1568
1569        let context = Arc::new(Mutex::new(XHRContext {
1570            xhr,
1571            gen_id: self.generation_id.get(),
1572            sync_status: DomRefCell::new(None),
1573            resource_timing: ResourceFetchTiming::new(ResourceTimingType::Resource),
1574            url: request_builder.url.clone(),
1575        }));
1576
1577        let (task_source, script_port) = if self.sync.get() {
1578            let (sender, receiver) = global.new_script_pair();
1579            (
1580                SendableTaskSource {
1581                    sender,
1582                    pipeline_id: global.pipeline_id(),
1583                    name: TaskSourceName::Networking,
1584                    canceller: Default::default(),
1585                },
1586                Some(receiver),
1587            )
1588        } else {
1589            (
1590                global.task_manager().networking_task_source().to_sendable(),
1591                None,
1592            )
1593        };
1594
1595        *self.canceller.borrow_mut() =
1596            FetchCanceller::new(request_builder.id, global.core_resource_thread());
1597        global.fetch(request_builder, context.clone(), task_source);
1598
1599        if let Some(script_port) = script_port {
1600            loop {
1601                if !global.process_event(script_port.recv().unwrap(), can_gc) {
1602                    // We're exiting.
1603                    return Err(Error::Abort);
1604                }
1605                let context = context.lock().unwrap();
1606                let sync_status = context.sync_status.borrow();
1607                if let Some(ref status) = *sync_status {
1608                    return status.clone();
1609                }
1610            }
1611        }
1612        Ok(())
1613    }
1614
1615    /// <https://xhr.spec.whatwg.org/#final-charset>
1616    fn final_charset(&self) -> Option<&'static Encoding> {
1617        // 1. Let label be null.
1618        // 2. Let responseMIME be the result of get a response MIME type for xhr.
1619        // 3. If responseMIME’s parameters["charset"] exists, then set label to it.
1620        let response_charset = self
1621            .response_mime_type()
1622            .get_parameter(CHARSET)
1623            .map(ToString::to_string);
1624
1625        // 4. If xhr’s override MIME type’s parameters["charset"] exists, then set label to it.
1626        let override_charset = self
1627            .override_mime_type
1628            .borrow()
1629            .as_ref()
1630            .and_then(|mime| mime.get_parameter(CHARSET))
1631            .map(ToString::to_string);
1632
1633        // 5. If label is null, then return null.
1634        // 6. Let encoding be the result of getting an encoding from label.
1635        // 7. If encoding is failure, then return null.
1636        // 8. Return encoding.
1637        override_charset
1638            .or(response_charset)
1639            .and_then(|charset| Encoding::for_label(charset.as_bytes()))
1640    }
1641
1642    /// <https://xhr.spec.whatwg.org/#response-mime-type>
1643    fn response_mime_type(&self) -> Mime {
1644        // 1. Let mimeType be the result of extracting a MIME type from xhr’s response’s
1645        //    header list.
1646        // 2. If mimeType is failure, then set mimeType to text/xml.
1647        // 3. Return mimeType.
1648        extract_mime_type_as_dataurl_mime(&self.response_headers.borrow())
1649            .unwrap_or_else(|| Mime::new(TEXT, XML))
1650    }
1651
1652    /// <https://xhr.spec.whatwg.org/#final-mime-type>
1653    fn final_mime_type(&self) -> Mime {
1654        self.override_mime_type
1655            .borrow()
1656            .as_ref()
1657            .map(MimeExt::clone)
1658            .unwrap_or_else(|| self.response_mime_type())
1659    }
1660}
1661
1662#[derive(JSTraceable, MallocSizeOf)]
1663pub(crate) struct XHRTimeoutCallback {
1664    #[ignore_malloc_size_of = "Because it is non-owning"]
1665    xhr: Trusted<XMLHttpRequest>,
1666    generation_id: GenerationId,
1667}
1668
1669impl XHRTimeoutCallback {
1670    pub(crate) fn invoke(self, can_gc: CanGc) {
1671        let xhr = self.xhr.root();
1672        if xhr.ready_state.get() != XMLHttpRequestState::Done {
1673            xhr.process_partial_response(
1674                XHRProgress::Errored(self.generation_id, Error::Timeout),
1675                can_gc,
1676            );
1677        }
1678    }
1679}
1680
1681fn serialize_document(doc: &Document) -> Fallible<DOMString> {
1682    let mut writer = vec![];
1683    match serialize(&mut writer, &doc.upcast::<Node>(), SerializeOpts::default()) {
1684        Ok(_) => Ok(DOMString::from(String::from_utf8(writer).unwrap())),
1685        Err(_) => Err(Error::InvalidState(None)),
1686    }
1687}
1688
1689/// Returns whether `bs` is a `field-value`, as defined by
1690/// [RFC 2616](http://tools.ietf.org/html/rfc2616#page-32).
1691pub(crate) fn is_field_value(slice: &[u8]) -> bool {
1692    // Classifications of characters necessary for the [CRLF] (SP|HT) rule
1693    #[derive(PartialEq)]
1694    #[allow(clippy::upper_case_acronyms)]
1695    enum PreviousCharacter {
1696        Other,
1697        CR,
1698        LF,
1699        SPHT, // SP or HT
1700    }
1701    let mut prev = PreviousCharacter::Other; // The previous character
1702    slice.iter().all(|&x| {
1703        // http://tools.ietf.org/html/rfc2616#section-2.2
1704        match x {
1705            13 => {
1706                // CR
1707                if prev == PreviousCharacter::Other || prev == PreviousCharacter::SPHT {
1708                    prev = PreviousCharacter::CR;
1709                    true
1710                } else {
1711                    false
1712                }
1713            },
1714            10 => {
1715                // LF
1716                if prev == PreviousCharacter::CR {
1717                    prev = PreviousCharacter::LF;
1718                    true
1719                } else {
1720                    false
1721                }
1722            },
1723            32 => {
1724                // SP
1725                if prev == PreviousCharacter::LF || prev == PreviousCharacter::SPHT {
1726                    prev = PreviousCharacter::SPHT;
1727                    true
1728                } else if prev == PreviousCharacter::Other {
1729                    // Counts as an Other here, since it's not preceded by a CRLF
1730                    // SP is not a CTL, so it can be used anywhere
1731                    // though if used immediately after a CR the CR is invalid
1732                    // We don't change prev since it's already Other
1733                    true
1734                } else {
1735                    false
1736                }
1737            },
1738            9 => {
1739                // HT
1740                if prev == PreviousCharacter::LF || prev == PreviousCharacter::SPHT {
1741                    prev = PreviousCharacter::SPHT;
1742                    true
1743                } else {
1744                    false
1745                }
1746            },
1747            0..=31 | 127 => false, // CTLs
1748            x if x > 127 => false, // non ASCII
1749            _ if prev == PreviousCharacter::Other || prev == PreviousCharacter::SPHT => {
1750                prev = PreviousCharacter::Other;
1751                true
1752            },
1753            _ => false, // Previous character was a CR/LF but not part of the [CRLF] (SP|HT) rule
1754        }
1755    })
1756}