Skip to content

uvhttp_validation.h ​

Input validation module.

This module provides validation functions for HTTP input data including URL paths, headers, and query strings. All functions are inline-optimized for zero runtime overhead.

Functions ​

uvhttp_validate_string_length(const char *str, size_t min_len, size_t max_len) ​

Return Type: int

Validate string length is within specified range.

Parameters:

  • str: String to validate (NULL returns FALSE)
  • min_len: Minimum allowed length
  • max_len: Maximum allowed length

Returns: int TRUE if length is valid, FALSE otherwise

Note: This function is inline-optimized for performance Note: NULL string returns FALSE

uvhttp_validate_url_path(const char *path) ​

Return Type: int

Validate URL path is safe.

Parameters:

  • path: URL path to validate

Returns: int TRUE if path is safe, FALSE otherwise

Note: Checks for dangerous characters: < > : " | *\r Note: Path length must be between 1 and UVHTTP_MAX_PATH_SIZE Note: Path must start with / Note: Checks for path traversal attacks (../, .., %2e%2e, etc.) Note: Validates URL encoding sequences (must be properly encoded XX) Note: NULL path returns FALSE Note: Does NOT check for '?' as it's valid in query strings

uvhttp_validate_header_name(const char *name) ​

Return Type: int

Validate HTTP header name is valid.

Parameters:

  • name: HTTP header name to validate

Returns: int TRUE if name is valid, FALSE otherwise

Note: Valid characters: alphanumeric and hyphen (-) Note: Name length must be between 1 and UVHTTP_MAX_HEADER_NAME_SIZE Note: NULL name returns FALSE

uvhttp_validate_header_value_safe(const char *value) ​

Return Type: int

Validate HTTP header value is safe.

Parameters:

  • value: HTTP header value to validate

Returns: int TRUE if value is safe, FALSE otherwise

Note: Checks for dangerous characters:\r (header injection) Note: Value length must be between 0 and UVHTTP_MAX_HEADER_VALUE_SIZE Note: NULL value returns FALSE Note: Empty string ("") is considered safe

uvhttp_validate_query_string(const char *query) ​

Return Type: int

Validate query string is safe.

Parameters:

  • query: Query string to validate

Returns: int TRUE if query is safe, FALSE otherwise

Note: Checks for dangerous characters: < > " '\r Note: Query length must be between 0 and UVHTTP_MAX_URL_SIZE Note: NULL query returns TRUE (empty query is valid)

Released under MIT License