suricata
app-layer-htp-xff.c File Reference
#include "suricata-common.h"
#include "conf.h"
#include "app-layer-parser.h"
#include "app-layer-htp.h"
#include "app-layer-htp-xff.h"
#include "util-misc.h"
#include "util-unittest.h"
#include "app-layer-protos.h"
#include "htp/htp_rs.h"
#include "util-debug.h"
Include dependency graph for app-layer-htp-xff.c:

Go to the source code of this file.

Macros

#define XFF_DEFAULT   "X-Forwarded-For"
 

Functions

int HttpXFFGetIPFromTx (const Flow *f, uint64_t tx_id, HttpXFFCfg *xff_cfg, char *dstbuf, int dstbuflen)
 Function to return XFF IP if any in the selected transaction. The caller needs to lock the flow. More...
 
int HttpXFFGetIP (const Flow *f, HttpXFFCfg *xff_cfg, char *dstbuf, int dstbuflen)
 Function to return XFF IP if any. The caller needs to lock the flow. More...
 
void HttpXFFGetCfg (SCConfNode *conf, HttpXFFCfg *result)
 Function to return XFF configuration from a configuration node. More...
 

Detailed Description

Macro Definition Documentation

◆ XFF_DEFAULT

#define XFF_DEFAULT   "X-Forwarded-For"

Default XFF header name

Definition at line 40 of file app-layer-htp-xff.c.

Function Documentation

◆ HttpXFFGetCfg()

void HttpXFFGetCfg ( SCConfNode *  conf,
HttpXFFCfg *  result 
)

Function to return XFF configuration from a configuration node.

Definition at line 117 of file app-layer-htp-xff.c.

References BUG_ON, HttpXFFCfg_::flags, HttpXFFCfg_::header, SCConfNodeChildValueIsTrue(), SCConfNodeLookupChild(), SCConfNodeLookupChildValue(), SCLogWarning, XFF_DEFAULT, XFF_DISABLED, XFF_EXTRADATA, XFF_FORWARD, XFF_OVERWRITE, and XFF_REVERSE.

Here is the call graph for this function:

◆ HttpXFFGetIP()

int HttpXFFGetIP ( const Flow *  f,
HttpXFFCfg *  xff_cfg,
char *  dstbuf,
int  dstbuflen 
)

Function to return XFF IP if any. The caller needs to lock the flow.

Return values
1if the IP has been found and returned in dstbuf
0if the IP has not being found or error

Definition at line 84 of file app-layer-htp-xff.c.

◆ HttpXFFGetIPFromTx()

int HttpXFFGetIPFromTx ( const Flow *  f,
uint64_t  tx_id,
HttpXFFCfg *  xff_cfg,
char *  dstbuf,
int  dstbuflen 
)

Function to return XFF IP if any in the selected transaction. The caller needs to lock the flow.

Return values
1if the IP has been found and returned in dstbuf
0if the IP has not being found or error

Definition at line 53 of file app-layer-htp-xff.c.

Referenced by JsonBuildFileInfoRecord().

Here is the caller graph for this function: