12#include "esp_tls_crypto.h"
13#include <freertos/FreeRTOS.h>
14#include <freertos/task.h>
19#ifdef USE_WEBSERVER_OTA
20#include <multipart_parser.h>
31#include <sys/socket.h>
36#define HTTPD_409 "409 Conflict"
39#define CRLF_STR "\r\n"
40#define CRLF_LEN (sizeof(CRLF_STR) - 1)
42static const char *
const TAG =
"web_server_idf";
48DefaultHeaders default_headers_instance;
69int nonblocking_send(httpd_handle_t hd,
int sockfd,
const char *buf,
size_t buf_len,
int flags) {
71 return HTTPD_SOCK_ERR_INVALID;
75 int ret = send(sockfd, buf, buf_len,
flags | MSG_DONTWAIT);
77 if (errno == EAGAIN || errno == EWOULDBLOCK) {
79 return HTTPD_SOCK_ERR_TIMEOUT;
82 ESP_LOGD(TAG,
"send error: errno %d", errno);
83 return HTTPD_SOCK_ERR_FAIL;
106 shutdown(sockfd, SHUT_RD);
123 httpd_config_t config = HTTPD_DEFAULT_CONFIG();
124 config.server_port = this->
port_;
125 config.uri_match_fn = [](
const char * ,
const char * ,
size_t ) {
return true; };
130 config.lru_purge_enable =
true;
133 if (httpd_start(&this->
server_, &config) == ESP_OK) {
134 const httpd_uri_t handler_get = {
140 httpd_register_uri_handler(this->
server_, &handler_get);
142 const httpd_uri_t handler_post = {
148 httpd_register_uri_handler(this->
server_, &handler_post);
150 const httpd_uri_t handler_options = {
152 .method = HTTP_OPTIONS,
156 httpd_register_uri_handler(this->
server_, &handler_options);
161 ESP_LOGVV(TAG,
"Enter AsyncWebServer::request_post_handler. uri=%s", r->uri);
165 ESP_LOGW(TAG,
"Content length is required for post: %s", r->uri);
166 httpd_resp_send_err(r, HTTPD_411_LENGTH_REQUIRED,
nullptr);
170 if (content_type.has_value()) {
171 const char *content_type_char = content_type.value().c_str();
174 size_t content_type_len = strlen(content_type_char);
175 if (
strcasestr_n(content_type_char, content_type_len,
"application/x-www-form-urlencoded") !=
nullptr) {
177#ifdef USE_WEBSERVER_OTA
178 }
else if (
strcasestr_n(content_type_char, content_type_len,
"multipart/form-data") !=
nullptr) {
183 ESP_LOGW(TAG,
"Unsupported content type for POST: %s", content_type_char);
190 if (r->content_len > CONFIG_HTTPD_MAX_REQ_HDR_LEN) {
191 ESP_LOGW(TAG,
"Request size is to big: %zu", r->content_len);
192 httpd_resp_send_err(r, HTTPD_400_BAD_REQUEST,
nullptr);
196 std::string post_query;
197 if (r->content_len > 0) {
198 post_query.resize(r->content_len);
199 const int ret = httpd_req_recv(r, &post_query[0], r->content_len + 1);
201 if (ret == HTTPD_SOCK_ERR_TIMEOUT) {
202 httpd_resp_send_err(r, HTTPD_408_REQ_TIMEOUT,
nullptr);
203 return ESP_ERR_TIMEOUT;
205 httpd_resp_send_err(r, HTTPD_400_BAD_REQUEST,
nullptr);
215 ESP_LOGVV(TAG,
"Enter AsyncWebServer::request_handler. method=%u, uri=%s", r->method, r->uri);
222 if (handler->canHandle(request)) {
225 handler->handleRequest(request);
233 return ESP_ERR_NOT_FOUND;
238 for (
auto *param : this->
params_) {
250 const char *uri = this->
req_->uri;
251 const char *query_start = strchr(uri,
'?');
252 size_t uri_len = query_start ?
static_cast<size_t>(query_start - uri) : strlen(uri);
254 memcpy(buffer.data(), uri, copy_len);
255 buffer[copy_len] =
'\0';
257 size_t decoded_len =
url_decode(buffer.data());
258 return StringRef(buffer.data(), decoded_len);
268 httpd_resp_send(*
this, content, HTTPD_RESP_USE_STRLEN);
270 httpd_resp_send(*
this,
nullptr, 0);
275 httpd_resp_set_status(*
this,
"302 Found");
276 httpd_resp_set_hdr(*
this,
"Location", url.c_str());
277 httpd_resp_set_hdr(*
this,
"Connection",
"close");
278 httpd_resp_send(*
this,
nullptr, 0);
298 httpd_resp_set_status(*
this,
status);
300 if (content_type && *content_type) {
301 httpd_resp_set_type(*
this, content_type);
303 httpd_resp_set_hdr(*
this,
"Accept-Ranges",
"none");
306 httpd_resp_set_hdr(*
this, header.name, header.value);
313#ifdef USE_WEBSERVER_AUTH
314bool AsyncWebServerRequest::authenticate(
const char *username,
const char *password)
const {
315 if (username ==
nullptr || password ==
nullptr || *username == 0) {
318 auto auth = this->
get_header(
"Authorization");
319 if (!auth.has_value()) {
323 auto *auth_str = auth.value().c_str();
325 const auto auth_prefix_len =
sizeof(
"Basic ") - 1;
326 if (strncmp(
"Basic ", auth_str, auth_prefix_len) != 0) {
327 ESP_LOGW(TAG,
"Only Basic authorization supported yet");
332 constexpr size_t max_user_info_len = 256;
333 char user_info[max_user_info_len];
334 size_t user_len = strlen(username);
335 size_t pass_len = strlen(password);
336 size_t user_info_len = user_len + 1 + pass_len;
338 if (user_info_len >= max_user_info_len) {
339 ESP_LOGW(TAG,
"Credentials too long for authentication");
343 memcpy(user_info, username, user_len);
344 user_info[user_len] =
':';
345 memcpy(user_info + user_len + 1, password, pass_len);
346 user_info[user_info_len] =
'\0';
350 constexpr size_t max_digest_len = 350;
351 char digest[max_digest_len];
353 esp_crypto_base64_encode(
reinterpret_cast<uint8_t *
>(digest), max_digest_len, &out,
354 reinterpret_cast<const uint8_t *
>(user_info), user_info_len);
359 const char *provided = auth_str + auth_prefix_len;
360 size_t digest_len = out;
363 size_t provided_len = auth.value().size() - auth_prefix_len;
367 volatile size_t result = digest_len ^ provided_len;
371 for (
size_t i = 0; i < digest_len; i++) {
372 char provided_ch = (i < provided_len) ? provided[i] : 0;
373 result |=
static_cast<uint8_t
>(digest[i] ^ provided_ch);
379 httpd_resp_set_hdr(*
this,
"Connection",
"keep-alive");
382 httpd_resp_set_hdr(*
this,
"WWW-Authenticate",
"Basic realm=\"Login Required\"");
383 httpd_resp_send_err(*
this, HTTPD_401_UNAUTHORIZED,
nullptr);
389 for (
auto *param : this->
params_) {
390 if (param->name() == name) {
400 if (!
val.has_value()) {
405 this->params_.push_back(param);
412template<
typename Func>
413static auto search_query_sources(httpd_req_t *req,
const std::string &post_query,
const char *name, Func func)
414 ->
decltype(func(
nullptr,
size_t{0}, name)) {
415 if (!post_query.empty()) {
416 auto result = func(post_query.c_str(), post_query.size(), name);
424 auto len = httpd_req_get_url_query_len(req);
428 const char *query = strchr(req->uri,
'?');
429 if (query ==
nullptr) {
433 return func(query,
len, name);
447 if (
val.has_value()) {
448 return std::move(
val.value());
454 httpd_resp_set_hdr(*this->
req_, name, value);
461 int len = snprintf(buf,
sizeof(buf),
"%f", value);
469 const int length = vsnprintf(
nullptr, 0,
fmt, args);
476 vsnprintf(&str[0],
length + 1,
fmt, args);
502 for (
size_t i = 0; i < this->
sessions_.size();) {
505 if (ses->fd_.load() == 0) {
506 ESP_LOGD(TAG,
"Removing dead event source session");
520 if (ses->fd_.load() != 0) {
521 ses->try_send_nodefer(
message, event,
id, reconnect);
532 if (ses->fd_.load() != 0) {
533 ses->deferrable_send_state(source, event_type, message_generator);
541 : server_(server), web_server_(ws), entities_iterator_(ws, server) {
542 httpd_req_t *req = *request;
544 httpd_resp_set_status(req, HTTPD_200);
545 httpd_resp_set_type(req,
"text/event-stream");
546 httpd_resp_set_hdr(req,
"Cache-Control",
"no-cache");
547 httpd_resp_set_hdr(req,
"Connection",
"keep-alive");
550 httpd_resp_set_hdr(req, header.name, header.value);
553 httpd_resp_send_chunk(req, CRLF_STR, CRLF_LEN);
555 req->sess_ctx =
this;
558 this->
hd_ = req->handle;
559 this->
fd_.store(httpd_req_to_sockfd(req));
562 httpd_sess_set_send_override(this->
hd_, this->
fd_.load(), nonblocking_send);
569#ifdef USE_WEBSERVER_SORTING
573 JsonObject root = builder.
root();
574 root[
"name"] = group.second.name;
575 root[
"sorting_weight"] = group.second.weight;
596 int fd = rsp->
fd_.exchange(0);
597 ESP_LOGD(TAG,
"Event source connection closed (fd: %d)", fd);
614 this->deferred_queue_.push_back(item);
643 if (bytes_sent == HTTPD_SOCK_ERR_TIMEOUT) {
652 ESP_LOGW(TAG,
"Closing stuck EventSource connection after %" PRIu16
" failed sends",
659 if (bytes_sent == HTTPD_SOCK_ERR_FAIL) {
663 if (bytes_sent <= 0) {
665 ESP_LOGW(TAG,
"Unexpected send result: %d", bytes_sent);
675 ESP_LOGV(TAG,
"Partial send: %d/%zu bytes (total: %zu/%zu)", bytes_sent, remaining,
event_bytes_sent_,
693 uint32_t reconnect) {
694 if (this->
fd_.load() == 0) {
705 const char chunk_len_header[] =
" " CRLF_STR;
706 const int chunk_len_header_len =
sizeof(chunk_len_header) - 1;
712 constexpr size_t num_buf_size = 32;
713 char num_buf[num_buf_size];
716 int len = snprintf(num_buf, num_buf_size,
"retry: %" PRIu32 CRLF_STR, reconnect);
721 int len = snprintf(num_buf, num_buf_size,
"id: %" PRIu32 CRLF_STR,
id);
725 if (event && *event) {
738 const char *first_n = strchr(
message,
'\n');
739 const char *first_r = strchr(
message,
'\r');
741 if (first_n ==
nullptr && first_r ==
nullptr) {
748 const char *line_start =
message;
749 size_t msg_len = strlen(
message);
750 const char *msg_end =
message + msg_len;
753 const char *next_n = first_n;
754 const char *next_r = first_r;
756 while (line_start <= msg_end) {
757 const char *line_end;
758 const char *next_line;
760 if (next_n ==
nullptr && next_r ==
nullptr) {
769 if (next_n !=
nullptr && next_r !=
nullptr) {
770 if (next_r + 1 == next_n) {
773 next_line = next_n + 1;
776 line_end = (next_r < next_n) ? next_r : next_n;
777 next_line = line_end + 1;
779 }
else if (next_n !=
nullptr) {
782 next_line = next_n + 1;
786 next_line = next_r + 1;
794 line_start = next_line;
797 if (line_start >= msg_end) {
802 next_n = strchr(line_start,
'\n');
803 next_r = strchr(line_start,
'\r');
811 if (
event_buffer_.size() ==
static_cast<size_t>(chunk_len_header_len)) {
820 int chunk_len =
event_buffer_.size() - CRLF_LEN - chunk_len_header_len;
821 char chunk_len_str[9];
822 snprintf(chunk_len_str, 9,
"%08x", chunk_len);
838 if (source ==
nullptr)
840 if (event_type ==
nullptr)
842 if (message_generator ==
nullptr)
845 if (0 != strcmp(event_type,
"state_detail_all") && 0 != strcmp(event_type,
"state")) {
846 ESP_LOGE(TAG,
"Can't defer non-state event");
865#ifdef USE_WEBSERVER_OTA
867 static constexpr size_t MULTIPART_CHUNK_SIZE = 1460;
868 static constexpr size_t YIELD_INTERVAL_BYTES = 16 * 1024;
871 const char *boundary_start;
874 ESP_LOGE(TAG,
"Failed to parse multipart boundary");
875 httpd_resp_send_err(r, HTTPD_400_BAD_REQUEST,
nullptr);
882 if (
h->canHandle(&req)) {
889 ESP_LOGW(TAG,
"No handler found for OTA request");
890 httpd_resp_send_err(r, HTTPD_404_NOT_FOUND,
nullptr);
895 std::string filename;
898 auto reader = std::make_unique<MultipartReader>(
"--" + std::string(boundary_start, boundary_len));
901 reader->set_data_callback([&](
const uint8_t *data,
size_t len) {
902 if (!reader->has_file() || !
len)
905 if (filename.empty()) {
906 filename = reader->get_current_part().filename;
907 ESP_LOGV(TAG,
"Processing file: '%s'", filename.c_str());
908 handler->
handleUpload(&req, filename, 0,
nullptr, 0,
false);
911 handler->
handleUpload(&req, filename, index,
const_cast<uint8_t *
>(data),
len,
false);
915 reader->set_part_complete_callback([&]() {
917 handler->
handleUpload(&req, filename, index,
nullptr, 0,
true);
924 auto buffer = std::make_unique_for_overwrite<char[]>(MULTIPART_CHUNK_SIZE);
925 size_t bytes_since_yield = 0;
927 for (
size_t remaining = r->content_len; remaining > 0;) {
928 int recv_len = httpd_req_recv(r, buffer.get(), std::min(remaining, MULTIPART_CHUNK_SIZE));
931 httpd_resp_send_err(r, recv_len == HTTPD_SOCK_ERR_TIMEOUT ? HTTPD_408_REQ_TIMEOUT : HTTPD_400_BAD_REQUEST,
933 return recv_len == HTTPD_SOCK_ERR_TIMEOUT ? ESP_ERR_TIMEOUT : ESP_FAIL;
936 if (reader->parse(buffer.get(), recv_len) !=
static_cast<size_t>(recv_len)) {
937 ESP_LOGW(TAG,
"Multipart parser error");
938 httpd_resp_send_err(r, HTTPD_400_BAD_REQUEST,
nullptr);
942 remaining -= recv_len;
943 bytes_since_yield += recv_len;
945 if (bytes_since_yield > YIELD_INTERVAL_BYTES) {
947 bytes_since_yield = 0;
void begin(bool include_internal=false)
StringRef is a reference to a string owned by something else.
Builder class for creating JSON documents without lambdas.
SerializationBuffer serialize()
Serialize the JSON document to a SerializationBuffer (stack-first allocation) Uses 512-byte stack buf...
This class allows users to create a web server with their ESP nodes.
json::SerializationBuffer get_config_json()
Return the webserver configuration as JSON.
std::map< uint64_t, SortingGroup > sorting_groups_
~AsyncEventSource() override
friend class AsyncEventSourceResponse
std::vector< AsyncEventSourceResponse * > sessions_
void deferrable_send_state(void *source, const char *event_type, message_generator_t *message_generator)
esphome::web_server::WebServer * web_server_
void try_send_nodefer(const char *message, const char *event=nullptr, uint32_t id=0, uint32_t reconnect=0)
void handleRequest(AsyncWebServerRequest *request) override
connect_handler_t on_connect_
static void destroy(void *p)
std::vector< DeferredEvent > deferred_queue_
void deferrable_send_state(void *source, const char *event_type, message_generator_t *message_generator)
esphome::web_server::WebServer * web_server_
void deq_push_back_with_dedup_(void *source, message_generator_t *message_generator)
void process_deferred_queue_()
AsyncEventSourceResponse(const AsyncWebServerRequest *request, esphome::web_server_idf::AsyncEventSource *server, esphome::web_server::WebServer *ws)
static constexpr uint16_t MAX_CONSECUTIVE_SEND_FAILURES
esphome::web_server::ListEntitiesIterator entities_iterator_
uint16_t consecutive_send_failures_
bool try_send_nodefer(const char *message, const char *event=nullptr, uint32_t id=0, uint32_t reconnect=0)
std::string event_buffer_
void print(const char *str)
void printf(const char *fmt,...) __attribute__((format(printf
virtual void handleRequest(AsyncWebServerRequest *request)
virtual void handleUpload(AsyncWebServerRequest *request, const std::string &filename, size_t index, uint8_t *data, size_t len, bool final)
std::function< void(AsyncWebServerRequest *request)> on_not_found_
static esp_err_t request_post_handler(httpd_req_t *r)
std::vector< AsyncWebHandler * > handlers_
esp_err_t request_handler_(AsyncWebServerRequest *request) const
esp_err_t handle_multipart_upload_(httpd_req_t *r, const char *content_type)
static void safe_close_with_shutdown(httpd_handle_t hd, int sockfd)
static esp_err_t request_handler(httpd_req_t *r)
AsyncWebParameter * getParam(const char *name)
optional< std::string > get_header(const char *name) const
bool hasArg(const char *name)
StringRef url_to(std::span< char, URL_BUF_SIZE > buffer) const
Write URL (without query string) to buffer, returns StringRef pointing to buffer.
void send(AsyncWebServerResponse *response)
bool hasHeader(const char *name) const
void init_response_(AsyncWebServerResponse *rsp, int code, const char *content_type)
static constexpr size_t URL_BUF_SIZE
Buffer size for url_to()
std::string arg(const char *name)
optional< std::string > find_query_value_(const char *name) const
ESPDEPRECATED("Use url_to() instead. Removed in 2026.9.0", "2026.3.0") std void requestAuthentication(const char *realm=nullptr) const
AsyncWebServerResponse * rsp_
std::vector< AsyncWebParameter * > params_
void redirect(const std::string &url)
const AsyncWebServerRequest * req_
virtual const char * get_content_data() const =0
virtual size_t get_content_size() const =0
void addHeader(const char *name, const char *value)
bool query_has_key(const char *query_url, size_t query_len, const char *key)
json::SerializationBuffer<>(esphome::web_server::WebServer *, void *) message_generator_t
optional< std::string > request_get_header(httpd_req_t *req, const char *name)
bool parse_multipart_boundary(const char *content_type, const char **boundary_start, size_t *boundary_len)
optional< std::string > query_key_value(const char *query_url, size_t query_len, const char *key)
const char * strcasestr_n(const char *haystack, size_t haystack_len, const char *needle)
size_t url_decode(char *str)
Decode URL-encoded string in-place (e.g., %20 -> space, + -> space) Returns the new length of the dec...
bool request_has_header(httpd_req_t *req, const char *name)
size_t size_t const char va_start(args, fmt)
size_t size_t const char * fmt
uint32_t IRAM_ATTR HOT millis()
message_generator_t * message_generator_