+get_cnonce(char *dest)
+{
+ uint32_t val = 0;
+ FILE *f;
+ size_t n;
+
+ f = fopen("/dev/urandom", "r");
+ if (f) {
+ n = fread(&val, sizeof(val), 1, f);
+ fclose(f);
+ if (n != 1)
+ return;
+ }
+
+ bin_to_hex(dest, &val, sizeof(val));
+}
+
+static void add_field(char **buf, int *ofs, int *len, const char *name, const char *val)
+{
+ int available = *len - *ofs;
+ int required;
+ const char *next;
+ char *cur;
+
+ if (*len && !*buf)
+ return;
+
+ required = strlen(name) + 4 + strlen(val) * 2;
+ if (required > available)
+ *len += required - available + 64;
+
+ *buf = realloc(*buf, *len);
+ if (!*buf)
+ return;
+
+ cur = *buf + *ofs;
+ cur += sprintf(cur, ", %s=\"", name);
+
+ while ((next = strchr(val, '"'))) {
+ if (next > val) {
+ memcpy(cur, val, next - val);
+ cur += next - val;
+ }
+
+ cur += sprintf(cur, "\\\"");
+ val = next + 1;
+ }
+
+ cur += sprintf(cur, "%s\"", val);
+ *ofs = cur - *buf;
+}
+
+static int
+uclient_http_add_auth_digest(struct uclient_http *uh)
+{
+ struct uclient_url *url = uh->uc.url;
+ const char *realm = NULL, *opaque = NULL;
+ const char *user, *password;
+ char *buf, *next;
+ int len, ofs;
+ int err = 0;
+
+ char cnonce_str[9];
+ char nc_str[9];
+ char ahash[33];
+ char hash[33];
+
+ struct http_digest_data data = {
+ .nc = nc_str,
+ .cnonce = cnonce_str,
+ .auth_hash = ahash,
+ };
+
+ len = strlen(uh->auth_str) + 1;
+ if (len > 512) {
+ err = -EINVAL;
+ goto fail;
+ }
+
+ buf = alloca(len);
+ if (!buf) {
+ err = -ENOMEM;
+ goto fail;
+ }
+
+ strcpy(buf, uh->auth_str);
+
+ /* skip auth type */
+ strsep(&buf, " ");
+
+ next = buf;
+ while (*next) {
+ const char **dest = NULL;
+ const char *tmp;
+
+ while (*next && isspace(*next))
+ next++;
+
+ if (strmatch(&next, "realm"))
+ dest = &realm;
+ else if (strmatch(&next, "qop"))
+ dest = &data.qop;
+ else if (strmatch(&next, "nonce"))
+ dest = &data.nonce;
+ else if (strmatch(&next, "opaque"))
+ dest = &opaque;
+ else if (strmatch(&next, "stale") ||
+ strmatch(&next, "algorithm") ||
+ strmatch(&next, "auth-param")) {
+ digest_sep(&next);
+ continue;
+ } else if (strmatch(&next, "domain") ||
+ strmatch(&next, "qop-options"))
+ dest = &tmp;
+ else {
+ digest_sep(&next);
+ continue;
+ }
+
+ *dest = digest_unquote_sep(&next);
+ }
+
+ if (!realm || !data.qop || !data.nonce) {
+ err = -EINVAL;
+ goto fail;
+ }
+
+ sprintf(nc_str, "%08x", uh->nc++);
+ get_cnonce(cnonce_str);
+
+ data.qop = "auth";
+ data.uri = url->location;
+ data.method = request_types[uh->req_type];
+
+ password = strchr(url->auth, ':');
+ if (password) {
+ char *user_buf;
+
+ len = password - url->auth;
+ if (len > 256) {
+ err = -EINVAL;
+ goto fail;
+ }
+
+ user_buf = alloca(len + 1);
+ if (!user_buf) {
+ err = -ENOMEM;
+ goto fail;
+ }
+
+ strncpy(user_buf, url->auth, len);
+ user_buf[len] = 0;
+ user = user_buf;
+ password++;
+ } else {
+ user = url->auth;
+ password = "";
+ }
+
+ http_digest_calculate_auth_hash(ahash, user, realm, password);
+ http_digest_calculate_response(hash, &data);
+
+ buf = NULL;
+ len = 0;
+ ofs = 0;
+
+ add_field(&buf, &ofs, &len, "username", user);
+ add_field(&buf, &ofs, &len, "realm", realm);
+ add_field(&buf, &ofs, &len, "nonce", data.nonce);
+ add_field(&buf, &ofs, &len, "uri", data.uri);
+ add_field(&buf, &ofs, &len, "cnonce", data.cnonce);
+ add_field(&buf, &ofs, &len, "response", hash);
+ if (opaque)
+ add_field(&buf, &ofs, &len, "opaque", opaque);
+
+ ustream_printf(uh->us, "Authorization: Digest nc=%s, qop=%s%s\r\n", data.nc, data.qop, buf);
+
+ free(buf);
+
+ return 0;
+
+fail:
+ return err;
+}
+
+static int
+uclient_http_add_auth_header(struct uclient_http *uh)
+{
+ if (!uh->uc.url->auth)
+ return 0;
+
+ switch (uh->auth_type) {
+ case AUTH_TYPE_UNKNOWN:
+ case AUTH_TYPE_NONE:
+ break;
+ case AUTH_TYPE_BASIC:
+ return uclient_http_add_auth_basic(uh);
+ case AUTH_TYPE_DIGEST:
+ return uclient_http_add_auth_digest(uh);
+ }
+
+ return 0;
+}
+
+static int