2 eac9287d 2023-06-24 op * Copyright (c) 2021, 2022, 2023 Omar Polo <op@omarpolo.com>
4 8ad1c570 2021-05-09 op * Permission to use, copy, modify, and distribute this software for any
5 8ad1c570 2021-05-09 op * purpose with or without fee is hereby granted, provided that the above
6 8ad1c570 2021-05-09 op * copyright notice and this permission notice appear in all copies.
8 8ad1c570 2021-05-09 op * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 8ad1c570 2021-05-09 op * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 8ad1c570 2021-05-09 op * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 8ad1c570 2021-05-09 op * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 8ad1c570 2021-05-09 op * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 8ad1c570 2021-05-09 op * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 8ad1c570 2021-05-09 op * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 8ad1c570 2021-05-09 op #include "gmid.h"
19 8ad1c570 2021-05-09 op #include <assert.h>
20 0f7fdd21 2023-07-01 op #include <ctype.h>
21 8ad1c570 2021-05-09 op #include <errno.h>
22 8ad1c570 2021-05-09 op #include <string.h>
24 eae52ad4 2023-06-06 op #include "log.h"
26 8ad1c570 2021-05-09 op struct fcgi_header {
27 8ad1c570 2021-05-09 op unsigned char version;
28 8ad1c570 2021-05-09 op unsigned char type;
29 8ad1c570 2021-05-09 op unsigned char req_id1;
30 8ad1c570 2021-05-09 op unsigned char req_id0;
31 8ad1c570 2021-05-09 op unsigned char content_len1;
32 8ad1c570 2021-05-09 op unsigned char content_len0;
33 8ad1c570 2021-05-09 op unsigned char padding;
34 8ad1c570 2021-05-09 op unsigned char reserved;
38 8ad1c570 2021-05-09 op * number of bytes in a FCGI_HEADER. Future version of the protocol
39 8ad1c570 2021-05-09 op * will not reduce this number.
41 8ad1c570 2021-05-09 op #define FCGI_HEADER_LEN 8
44 8ad1c570 2021-05-09 op * values for the version component
46 8ad1c570 2021-05-09 op #define FCGI_VERSION_1 1
49 8ad1c570 2021-05-09 op * values for the type component
51 8ad1c570 2021-05-09 op #define FCGI_BEGIN_REQUEST 1
52 8ad1c570 2021-05-09 op #define FCGI_ABORT_REQUEST 2
53 8ad1c570 2021-05-09 op #define FCGI_END_REQUEST 3
54 8ad1c570 2021-05-09 op #define FCGI_PARAMS 4
55 8ad1c570 2021-05-09 op #define FCGI_STDIN 5
56 8ad1c570 2021-05-09 op #define FCGI_STDOUT 6
57 8ad1c570 2021-05-09 op #define FCGI_STDERR 7
58 8ad1c570 2021-05-09 op #define FCGI_DATA 8
59 8ad1c570 2021-05-09 op #define FCGI_GET_VALUES 9
60 8ad1c570 2021-05-09 op #define FCGI_GET_VALUES_RESULT 10
61 8ad1c570 2021-05-09 op #define FCGI_UNKNOWN_TYPE 11
62 8ad1c570 2021-05-09 op #define FCGI_MAXTYPE (FCGI_UNKNOWN_TYPE)
64 8ad1c570 2021-05-09 op struct fcgi_begin_req {
65 8ad1c570 2021-05-09 op unsigned char role1;
66 8ad1c570 2021-05-09 op unsigned char role0;
67 8ad1c570 2021-05-09 op unsigned char flags;
68 8ad1c570 2021-05-09 op unsigned char reserved[5];
71 8ad1c570 2021-05-09 op struct fcgi_begin_req_record {
72 8ad1c570 2021-05-09 op struct fcgi_header header;
73 8ad1c570 2021-05-09 op struct fcgi_begin_req body;
77 8ad1c570 2021-05-09 op * mask for flags;
79 8ad1c570 2021-05-09 op #define FCGI_KEEP_CONN 1
82 8ad1c570 2021-05-09 op * values for the role
84 8ad1c570 2021-05-09 op #define FCGI_RESPONDER 1
85 8ad1c570 2021-05-09 op #define FCGI_AUTHORIZER 2
86 8ad1c570 2021-05-09 op #define FCGI_FILTER 3
88 8ad1c570 2021-05-09 op struct fcgi_end_req_body {
89 8ad1c570 2021-05-09 op unsigned char app_status3;
90 8ad1c570 2021-05-09 op unsigned char app_status2;
91 8ad1c570 2021-05-09 op unsigned char app_status1;
92 8ad1c570 2021-05-09 op unsigned char app_status0;
93 8ad1c570 2021-05-09 op unsigned char proto_status;
94 8ad1c570 2021-05-09 op unsigned char reserved[3];
98 8ad1c570 2021-05-09 op * values for proto_status
100 8ad1c570 2021-05-09 op #define FCGI_REQUEST_COMPLETE 0
101 8ad1c570 2021-05-09 op #define FCGI_CANT_MPX_CONN 1
102 8ad1c570 2021-05-09 op #define FCGI_OVERLOADED 2
103 8ad1c570 2021-05-09 op #define FCGI_UNKNOWN_ROLE 3
106 8ad1c570 2021-05-09 op * Variable names for FCGI_GET_VALUES / FCGI_GET_VALUES_RESULT
109 8ad1c570 2021-05-09 op #define FCGI_MAX_CONNS "FCGI_MAX_CONNS"
110 8ad1c570 2021-05-09 op #define FCGI_MAX_REQS "FCGI_MAX_REQS"
111 8ad1c570 2021-05-09 op #define FCGI_MPXS_CONNS "FCGI_MPXS_CONNS"
114 4cd25209 2021-10-07 op prepare_header(struct fcgi_header *h, int type, size_t size,
115 8ad1c570 2021-05-09 op size_t padding)
119 8ad1c570 2021-05-09 op memset(h, 0, sizeof(*h));
121 8ad1c570 2021-05-09 op h->version = FCGI_VERSION_1;
122 4842c72d 2021-10-18 op h->type = type;
123 8ad1c570 2021-05-09 op h->req_id1 = (id >> 8);
124 8ad1c570 2021-05-09 op h->req_id0 = (id & 0xFF);
125 8ad1c570 2021-05-09 op h->content_len1 = (size >> 8);
126 8ad1c570 2021-05-09 op h->content_len0 = (size & 0xFF);
127 8ad1c570 2021-05-09 op h->padding = padding;
133 4cd25209 2021-10-07 op fcgi_begin_request(struct bufferevent *bev)
135 8ad1c570 2021-05-09 op struct fcgi_begin_req_record r;
137 8ad1c570 2021-05-09 op memset(&r, 0, sizeof(r));
138 4cd25209 2021-10-07 op prepare_header(&r.header, FCGI_BEGIN_REQUEST, sizeof(r.body), 0);
139 8ad1c570 2021-05-09 op assert(sizeof(r.body) == FCGI_HEADER_LEN);
141 8ad1c570 2021-05-09 op r.body.role1 = 0;
142 8ad1c570 2021-05-09 op r.body.role0 = FCGI_RESPONDER;
143 8ad1c570 2021-05-09 op r.body.flags = FCGI_KEEP_CONN;
145 741b69be 2021-09-26 op if (bufferevent_write(bev, &r, sizeof(r)) == -1)
151 4cd25209 2021-10-07 op fcgi_send_param(struct bufferevent *bev, const char *name,
152 741b69be 2021-09-26 op const char *value)
154 8ad1c570 2021-05-09 op struct fcgi_header h;
155 4842c72d 2021-10-18 op uint32_t namlen, vallen, padlen;
156 8ad1c570 2021-05-09 op uint8_t s[8];
158 e5d82d94 2022-03-19 op const char padding[8] = { 0 };
160 8ad1c570 2021-05-09 op namlen = strlen(name);
161 8ad1c570 2021-05-09 op vallen = strlen(value);
162 8ad1c570 2021-05-09 op size = namlen + vallen + 8; /* 4 for the sizes */
163 8ad1c570 2021-05-09 op padlen = (8 - (size & 0x7)) & 0x7;
165 8ad1c570 2021-05-09 op s[0] = ( namlen >> 24) | 0x80;
166 8ad1c570 2021-05-09 op s[1] = ((namlen >> 16) & 0xFF);
167 8ad1c570 2021-05-09 op s[2] = ((namlen >> 8) & 0xFF);
168 8ad1c570 2021-05-09 op s[3] = ( namlen & 0xFF);
170 8ad1c570 2021-05-09 op s[4] = ( vallen >> 24) | 0x80;
171 8ad1c570 2021-05-09 op s[5] = ((vallen >> 16) & 0xFF);
172 8ad1c570 2021-05-09 op s[6] = ((vallen >> 8) & 0xFF);
173 8ad1c570 2021-05-09 op s[7] = ( vallen & 0xFF);
175 4cd25209 2021-10-07 op prepare_header(&h, FCGI_PARAMS, size, padlen);
177 741b69be 2021-09-26 op if (bufferevent_write(bev, &h, sizeof(h)) == -1 ||
178 741b69be 2021-09-26 op bufferevent_write(bev, s, sizeof(s)) == -1 ||
179 741b69be 2021-09-26 op bufferevent_write(bev, name, namlen) == -1 ||
180 741b69be 2021-09-26 op bufferevent_write(bev, value, vallen) == -1 ||
181 741b69be 2021-09-26 op bufferevent_write(bev, padding, padlen) == -1)
188 4cd25209 2021-10-07 op fcgi_end_param(struct bufferevent *bev)
190 8ad1c570 2021-05-09 op struct fcgi_header h;
192 4cd25209 2021-10-07 op prepare_header(&h, FCGI_PARAMS, 0, 0);
193 741b69be 2021-09-26 op if (bufferevent_write(bev, &h, sizeof(h)) == -1)
196 4cd25209 2021-10-07 op prepare_header(&h, FCGI_STDIN, 0, 0);
197 741b69be 2021-09-26 op if (bufferevent_write(bev, &h, sizeof(h)) == -1)
203 8ad1c570 2021-05-09 op static inline int
204 8ad1c570 2021-05-09 op recid(struct fcgi_header *h)
206 4cd25209 2021-10-07 op return h->req_id0 + (h->req_id1 << 8);
209 8ad1c570 2021-05-09 op static inline int
210 8ad1c570 2021-05-09 op reclen(struct fcgi_header *h)
212 8ad1c570 2021-05-09 op return h->content_len0 + (h->content_len1 << 8);
216 0f7fdd21 2023-07-01 op fcgi_handle_stdout(struct client *c, struct evbuffer *src, size_t len)
218 0f7fdd21 2023-07-01 op struct bufferevent *bev = c->cgibev;
223 0f7fdd21 2023-07-01 op if (c->code == 0) {
225 0f7fdd21 2023-07-01 op if (l > sizeof(c->sbuf) - c->soff)
226 0f7fdd21 2023-07-01 op l = sizeof(c->sbuf) - c->soff;
228 0f7fdd21 2023-07-01 op memcpy(&c->sbuf[c->soff], EVBUFFER_DATA(src), l);
229 0f7fdd21 2023-07-01 op c->soff += l;
230 0f7fdd21 2023-07-01 op evbuffer_drain(src, l);
233 0f7fdd21 2023-07-01 op if ((t = memmem(c->sbuf, c->soff, "\r\n", 2)) == NULL) {
234 0f7fdd21 2023-07-01 op if (c->soff == sizeof(c->sbuf)) {
235 0f7fdd21 2023-07-01 op log_warnx("FastCGI application is trying to"
236 0f7fdd21 2023-07-01 op " send a header that's too long.");
237 0f7fdd21 2023-07-01 op fcgi_error(bev, EVBUFFER_ERROR, c);
240 0f7fdd21 2023-07-01 op /* wait a bit */
244 0f7fdd21 2023-07-01 op t += 2; /* skip CRLF */
246 0f7fdd21 2023-07-01 op if (!isdigit((unsigned char)c->sbuf[0]) ||
247 0f7fdd21 2023-07-01 op !isdigit((unsigned char)c->sbuf[1]) ||
248 0f7fdd21 2023-07-01 op c->sbuf[2] != ' ') {
249 0f7fdd21 2023-07-01 op fcgi_error(bev, EVBUFFER_ERROR, c);
253 0f7fdd21 2023-07-01 op code = (c->sbuf[0] - '0') * 10 + (c->sbuf[1] - '0');
254 0f7fdd21 2023-07-01 op if (code < 10 || code >= 70) {
255 0f7fdd21 2023-07-01 op log_warnx("FastCGI application is trying to send an"
256 0f7fdd21 2023-07-01 op " invalid reply code: %d", code);
257 0f7fdd21 2023-07-01 op fcgi_error(bev, EVBUFFER_ERROR, c);
261 390d312b 2023-08-09 op if (start_reply(c, code, c->sbuf + 3) == -1 ||
262 390d312b 2023-08-09 op c->code < 20 || c->code > 29) {
263 0f7fdd21 2023-07-01 op fcgi_error(bev, EVBUFFER_EOF, c);
267 0f7fdd21 2023-07-01 op bufferevent_write(c->bev, t, &c->sbuf[c->soff] - t);
270 0f7fdd21 2023-07-01 op bufferevent_write(c->bev, EVBUFFER_DATA(src), len);
271 0f7fdd21 2023-07-01 op evbuffer_drain(src, len);
275 741b69be 2021-09-26 op fcgi_read(struct bufferevent *bev, void *d)
277 4cd25209 2021-10-07 op struct client *c = d;
278 741b69be 2021-09-26 op struct evbuffer *src = EVBUFFER_INPUT(bev);
279 741b69be 2021-09-26 op struct fcgi_header hdr;
280 8ad1c570 2021-05-09 op struct fcgi_end_req_body end;
283 390d312b 2023-08-09 op while (c->type != REQUEST_DONE) {
284 741b69be 2021-09-26 op if (EVBUFFER_LENGTH(src) < sizeof(hdr))
287 741b69be 2021-09-26 op memcpy(&hdr, EVBUFFER_DATA(src), sizeof(hdr));
289 4cd25209 2021-10-07 op if (recid(&hdr) != 1) {
290 eae52ad4 2023-06-06 op log_warnx("got invalid client id %d from fcgi backend",
291 4cd25209 2021-10-07 op recid(&hdr));
295 741b69be 2021-09-26 op len = reclen(&hdr);
297 741b69be 2021-09-26 op if (EVBUFFER_LENGTH(src) < sizeof(hdr) + len + hdr.padding)
300 741b69be 2021-09-26 op evbuffer_drain(src, sizeof(hdr));
302 741b69be 2021-09-26 op switch (hdr.type) {
303 741b69be 2021-09-26 op case FCGI_END_REQUEST:
304 741b69be 2021-09-26 op if (len != sizeof(end)) {
305 eae52ad4 2023-06-06 op log_warnx("got invalid end request"
306 eae52ad4 2023-06-06 op " record size");
309 741b69be 2021-09-26 op bufferevent_read(bev, &end, sizeof(end));
311 741b69be 2021-09-26 op /* TODO: do something with the status? */
312 efe7d180 2021-10-02 op c->type = REQUEST_DONE;
315 741b69be 2021-09-26 op case FCGI_STDERR:
316 741b69be 2021-09-26 op /* discard stderr (for now) */
317 741b69be 2021-09-26 op evbuffer_drain(src, len);
320 741b69be 2021-09-26 op case FCGI_STDOUT:
321 0f7fdd21 2023-07-01 op fcgi_handle_stdout(c, src, len);
325 eae52ad4 2023-06-06 op log_warnx("got invalid fcgi record (type=%d)",
330 741b69be 2021-09-26 op evbuffer_drain(src, hdr.padding);
334 4cd25209 2021-10-07 op fcgi_error(bev, EVBUFFER_ERROR, c);
335 390d312b 2023-08-09 op client_write(c->bev, c);
339 741b69be 2021-09-26 op fcgi_write(struct bufferevent *bev, void *d)
342 741b69be 2021-09-26 op * There's no much use for the write callback.
348 741b69be 2021-09-26 op fcgi_error(struct bufferevent *bev, short err, void *d)
350 4cd25209 2021-10-07 op struct client *c = d;
353 0f7fdd21 2023-07-01 op * If we're here it means that some kind of non-recoverable
354 0f7fdd21 2023-07-01 op * error happened.
356 390d312b 2023-08-09 op * Don't free bev as we might be called by a function that
357 390d312b 2023-08-09 op * still uses it.
360 390d312b 2023-08-09 op bufferevent_disable(bev, EVBUFFER_READ);
362 0f7fdd21 2023-07-01 op close(c->pfd);
365 0f7fdd21 2023-07-01 op /* EOF and no header */
366 0f7fdd21 2023-07-01 op if (c->code == 0) {
367 4cd25209 2021-10-07 op start_reply(c, CGI_ERROR, "CGI error");
371 0f7fdd21 2023-07-01 op c->type = REQUEST_DONE;
375 e872053b 2023-08-18 op path_translate(const char *path, struct location *loc, struct location *rloc,
376 e872053b 2023-08-18 op char *buf, size_t len)
378 e872053b 2023-08-18 op const char *root, *sufx;
380 e872053b 2023-08-18 op buf[0] = '\0';
382 e872053b 2023-08-18 op if (*loc->dir != '\0')
383 e872053b 2023-08-18 op root = loc->dir;
384 e872053b 2023-08-18 op else if (*rloc->dir != '\0')
385 e872053b 2023-08-18 op root = rloc->dir;
390 e872053b 2023-08-18 op if (*root != '\0')
391 e872053b 2023-08-18 op sufx = root[strlen(root) - 1] == '/' ? "" : "/";
393 e872053b 2023-08-18 op while (*path == '/')
396 e872053b 2023-08-18 op snprintf(buf, len, "%s%s%s", root, sufx, path);
400 a1ba9650 2023-07-23 op fcgi_req(struct client *c, struct location *loc)
402 e872053b 2023-08-18 op char buf[22], path[GEMINI_URL_LEN], path_tr[PATH_MAX];
403 a1e159c9 2023-08-08 op char *scriptname, *qs;
404 e872053b 2023-08-18 op const char *stripped, *port;
407 f740b61b 2021-06-11 op struct tm tminfo;
408 f740b61b 2021-06-11 op struct envlist *p;
410 a1e159c9 2023-08-08 op fcgi_begin_request(c->cgibev);
412 e872053b 2023-08-18 op stripped = strip_path(c->iri.path, loc->fcgi_strip);
413 e872053b 2023-08-18 op if (*stripped != '/')
414 e872053b 2023-08-18 op snprintf(path, sizeof(path), "/%s", stripped);
416 e872053b 2023-08-18 op strlcpy(path, stripped, sizeof(path));
418 e872053b 2023-08-18 op port = c->iri.host;
419 e872053b 2023-08-18 op if (port == NULL || *port == '\0')
420 e872053b 2023-08-18 op port = "1965";
422 a1e159c9 2023-08-08 op scriptname = "";
423 b27dc2b0 2023-08-08 op TAILQ_FOREACH(p, &loc->params, envs) {
424 b27dc2b0 2023-08-08 op if (!strcmp(p->name, "SCRIPT_NAME")) {
425 b27dc2b0 2023-08-08 op scriptname = p->value;
430 b27dc2b0 2023-08-08 op l = strlen(scriptname);
431 b27dc2b0 2023-08-08 op while (l > 0 && scriptname[l - 1] == '/')
433 a1e159c9 2023-08-08 op if (!strncmp(scriptname, path, l) && (path[l] == '/' ||
434 a1e159c9 2023-08-08 op path[l] == '\0')) {
435 a1e159c9 2023-08-08 op fcgi_send_param(c->cgibev, "PATH_INFO", &path[l]);
436 e872053b 2023-08-18 op path_translate(&path[l], loc, TAILQ_FIRST(&c->host->locations),
437 e872053b 2023-08-18 op path_tr, sizeof(path_tr));
438 a1e159c9 2023-08-08 op path[l] = '\0';
439 a1e159c9 2023-08-08 op fcgi_send_param(c->cgibev, "SCRIPT_NAME", path);
441 e872053b 2023-08-18 op path_translate(stripped, loc, TAILQ_FIRST(&c->host->locations),
442 e872053b 2023-08-18 op path_tr, sizeof(path_tr));
443 a1e159c9 2023-08-08 op fcgi_send_param(c->cgibev, "PATH_INFO", stripped);
444 a1e159c9 2023-08-08 op fcgi_send_param(c->cgibev, "SCRIPT_NAME", scriptname);
447 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "GATEWAY_INTERFACE", "CGI/1.1");
448 e872053b 2023-08-18 op fcgi_send_param(c->cgibev, "PATH_TRANSLATED", path_tr);
449 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "QUERY_STRING", c->iri.query);
450 ed164e72 2023-06-26 op fcgi_send_param(c->cgibev, "REMOTE_ADDR", c->rhost);
451 ed164e72 2023-06-26 op fcgi_send_param(c->cgibev, "REMOTE_HOST", c->rhost);
452 e872053b 2023-08-18 op fcgi_send_param(c->cgibev, "REQUEST_METHOD", "GET");
453 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "SERVER_NAME", c->iri.host);
454 e872053b 2023-08-18 op fcgi_send_param(c->cgibev, "SERVER_PORT", port);
455 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "SERVER_PROTOCOL", "GEMINI");
456 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "SERVER_SOFTWARE", GMID_VERSION);
458 e872053b 2023-08-18 op fcgi_send_param(c->cgibev, "GEMINI_URL_PATH", c->iri.path);
460 97b306cb 2022-11-27 op if (*c->iri.query != '\0' &&
461 97b306cb 2022-11-27 op strchr(c->iri.query, '=') == NULL &&
462 97b306cb 2022-11-27 op (qs = strdup(c->iri.query)) != NULL) {
463 97b306cb 2022-11-27 op pct_decode_str(qs);
464 97b306cb 2022-11-27 op fcgi_send_param(c->cgibev, "GEMINI_SEARCH_STRING", qs);
468 a1ba9650 2023-07-23 op TAILQ_FOREACH(p, &loc->params, envs) {
469 b27dc2b0 2023-08-08 op if (!strcmp(p->name, "SCRIPT_NAME"))
471 50a8f910 2022-10-30 op fcgi_send_param(c->cgibev, p->name, p->value);
474 f740b61b 2021-06-11 op if (tls_peer_cert_provided(c->ctx)) {
475 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "AUTH_TYPE", "CERTIFICATE");
476 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "REMOTE_USER",
477 f740b61b 2021-06-11 op tls_peer_cert_subject(c->ctx));
478 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "TLS_CLIENT_ISSUER",
479 f740b61b 2021-06-11 op tls_peer_cert_issuer(c->ctx));
480 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "TLS_CLIENT_HASH",
481 f740b61b 2021-06-11 op tls_peer_cert_hash(c->ctx));
482 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "TLS_VERSION",
483 f740b61b 2021-06-11 op tls_conn_version(c->ctx));
484 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "TLS_CIPHER",
485 f740b61b 2021-06-11 op tls_conn_cipher(c->ctx));
487 f740b61b 2021-06-11 op snprintf(buf, sizeof(buf), "%d",
488 f740b61b 2021-06-11 op tls_conn_cipher_strength(c->ctx));
489 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "TLS_CIPHER_STRENGTH", buf);
491 f740b61b 2021-06-11 op tim = tls_peer_cert_notbefore(c->ctx);
492 f740b61b 2021-06-11 op strftime(buf, sizeof(buf), "%FT%TZ",
493 f740b61b 2021-06-11 op gmtime_r(&tim, &tminfo));
494 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "TLS_CLIENT_NOT_BEFORE", buf);
496 f740b61b 2021-06-11 op tim = tls_peer_cert_notafter(c->ctx);
497 f740b61b 2021-06-11 op strftime(buf, sizeof(buf), "%FT%TZ",
498 f740b61b 2021-06-11 op gmtime_r(&tim, &tminfo));
499 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "TLS_CLIENT_NOT_AFTER", buf);
502 4cd25209 2021-10-07 op fcgi_send_param(c->cgibev, "AUTH_TYPE", "");
504 4cd25209 2021-10-07 op if (fcgi_end_param(c->cgibev) == -1)
505 4cd25209 2021-10-07 op fcgi_error(c->cgibev, EVBUFFER_ERROR, c);