From 486e5e070c349beaa2d547d8b38b3c03fe4267be Mon Sep 17 00:00:00 2001 From: Acts1631 Date: Tue, 28 Jul 2026 17:02:14 -0400 Subject: [PATCH] Disable print by reference by default Print-URI and Send-URI are deprecated IPP operations that let clients provide a document URI for the server to retrieve. The printer application currently advertises and enables them by default. Disable print by reference and its related capability attributes by default. Allow an operator to enable the operations explicitly for development and testing with --print-by-reference. --- doc/ippeveprinter.html | 5 +++++ man/ippeveprinter.1 | 5 +++++ tools/ippeveprinter.c | 43 ++++++++++++++++++++++++++++++++---------- 3 files changed, 43 insertions(+), 10 deletions(-) diff --git a/doc/ippeveprinter.html b/doc/ippeveprinter.html index ab735f623..84f6c57dd 100644 --- a/doc/ippeveprinter.html +++ b/doc/ippeveprinter.html @@ -104,6 +104,8 @@

Synopsis

[ --help ] [ +--print-by-reference +] [ --no-web-forms ] [ --oauth-scopes @@ -194,6 +196,9 @@

Options

--help
Show program usage. +

+

--print-by-reference
+Enable the Print-URI and Send-URI operations.

--no-web-forms
Disable the web interface forms used to update the media, state, and supply levels. diff --git a/man/ippeveprinter.1 b/man/ippeveprinter.1 index 279b0f435..ae7383cb1 100644 --- a/man/ippeveprinter.1 +++ b/man/ippeveprinter.1 @@ -15,6 +15,8 @@ ippeveprinter \- an ipp everywhere printer application for cups [ .B \-\-help ] [ +.B \-\-print\-by\-reference +] [ .B \-\-no\-web\-forms ] [ .B \-\-oauth\-scopes @@ -104,6 +106,9 @@ The following options are recognized by .B \-\-help Show program usage. .TP 5 +.B \-\-print\-by\-reference +Enable the Print-URI and Send-URI operations. +.TP 5 .B \-\-no\-web\-forms Disable the web interface forms used to update the media, state, and supply levels. See the "WEB INTERFACE FORMS" section for more information. diff --git a/tools/ippeveprinter.c b/tools/ippeveprinter.c index 5ed4c2b7c..4856ecf8c 100644 --- a/tools/ippeveprinter.c +++ b/tools/ippeveprinter.c @@ -169,7 +169,8 @@ typedef struct ippeve_printer_s // Printer data *output_format, // Output format *command; // Command to run with job file int port; // Port - bool web_forms; // Enable web interface forms? + bool print_by_ref, // Enable Print-URI and Send-URI? + web_forms; // Enable web interface forms? size_t urilen; // Length of printer URI ipp_t *attrs; // Static attributes time_t start_time; // Startup time @@ -248,7 +249,7 @@ static int create_listener(const char *name, int port, int family); static ipp_t *create_media_col(const char *media, const char *source, const char *type, ipp_t *media_size, int bottom, int left, int right, int top); static ipp_t *create_media_size(int width, int length); static ipp_t *create_media_size_range(int min_width, int max_width, int min_length, int max_length); -static ippeve_printer_t *create_printer(const char *servername, int serverport, const char *name, const char *location, const char *icons, const char *strings, cups_array_t *docformats, const char *subtypes, const char *directory, const char *command, const char *device_uri, const char *output_format, ipp_t *attrs); +static ippeve_printer_t *create_printer(const char *servername, int serverport, const char *name, const char *location, const char *icons, const char *strings, cups_array_t *docformats, const char *subtypes, const char *directory, const char *command, const char *device_uri, const char *output_format, bool print_by_ref, ipp_t *attrs); static void debug_attributes(ippeve_client_t *client, const char *title, ipp_t *ipp, int response); static void delete_client(ippeve_client_t *client); static void delete_job(ippeve_job_t *job); @@ -361,7 +362,8 @@ main(int argc, // I - Number of command-line args *name = NULL, // Printer name *strings = NULL, // Strings file *subtypes = "_print"; // DNS-SD service subtype - bool legacy = false, // Legacy mode? + bool print_by_ref = false, // Enable Print-URI and Send-URI? + legacy = false, // Legacy mode? duplex = false, // Duplex mode web_forms = true; // Enable web site forms? int ppm = 10, // Pages per minute for mono @@ -409,6 +411,10 @@ main(int argc, // I - Number of command-line args OAuthScopes = argv[i]; } + else if (!strcmp(argv[i], "--print-by-reference")) + { + print_by_ref = true; + } #if HAVE_LIBPAM else if (!strcmp(argv[i], "--pam-service")) { @@ -797,7 +803,7 @@ main(int argc, // I - Number of command-line args if (!docformats && !ippFindAttribute(attrs, "document-format-supported", IPP_TAG_MIMETYPE)) docformats = cupsArrayNewStrings(ppm_color > 0 ? "image/jpeg,image/pwg-raster,image/urf": "image/pwg-raster,image/urf", ','); - if ((printer = create_printer(servername, serverport, name, location, icon, strings, docformats, subtypes, directory, command, device_uri, output_format, attrs)) == NULL) + if ((printer = create_printer(servername, serverport, name, location, icon, strings, docformats, subtypes, directory, command, device_uri, output_format, print_by_ref, attrs)) == NULL) return (1); printer->web_forms = web_forms; @@ -1568,6 +1574,7 @@ create_printer( const char *command, // I - Command to run on job files, if any const char *device_uri, // I - Output device, if any const char *output_format, // I - Output format, if any + bool print_by_ref, // I - Enable Print-URI and Send-URI? ipp_t *attrs) // I - Capability attributes { ippeve_printer_t *printer; // Printer @@ -1610,11 +1617,9 @@ create_printer( static const int ops[] = // operations-supported values { IPP_OP_PRINT_JOB, - IPP_OP_PRINT_URI, IPP_OP_VALIDATE_JOB, IPP_OP_CREATE_JOB, IPP_OP_SEND_DOCUMENT, - IPP_OP_SEND_URI, IPP_OP_CANCEL_JOB, IPP_OP_GET_JOB_ATTRIBUTES, IPP_OP_GET_JOBS, @@ -1622,7 +1627,9 @@ create_printer( IPP_OP_CANCEL_JOBS, IPP_OP_CANCEL_MY_JOBS, IPP_OP_CLOSE_JOB, - IPP_OP_IDENTIFY_PRINTER + IPP_OP_IDENTIFY_PRINTER, + IPP_OP_PRINT_URI, + IPP_OP_SEND_URI }; static const char * const charsets[] =// charset-supported values { @@ -1814,6 +1821,7 @@ create_printer( printer->device_uri = device_uri ? strdup(device_uri) : NULL; printer->output_format = output_format ? strdup(output_format) : NULL; printer->directory = strdup(directory); + printer->print_by_ref = print_by_ref; printer->icons[0] = icons ? strdup(icons) : NULL; printer->strings = strings ? strdup(strings) : NULL; printer->port = serverport; @@ -2142,7 +2150,7 @@ create_printer( } // operations-supported - ippAddIntegers(printer->attrs, IPP_TAG_PRINTER, IPP_TAG_ENUM, "operations-supported", sizeof(ops) / sizeof(ops[0]), ops); + ippAddIntegers(printer->attrs, IPP_TAG_PRINTER, IPP_TAG_ENUM, "operations-supported", (int)(sizeof(ops) / sizeof(ops[0]) - (printer->print_by_ref ? 0 : 2)), ops); if (has_pdf) { @@ -2233,7 +2241,8 @@ create_printer( ippAddString(printer->attrs, IPP_TAG_PRINTER, IPP_TAG_URI, "printer-uuid", NULL, uuid); // reference-uri-schemes-supported - ippAddStrings(printer->attrs, IPP_TAG_PRINTER, IPP_CONST_TAG(IPP_TAG_URISCHEME), "reference-uri-schemes-supported", (int)(sizeof(reference_uri_schemes_supported) / sizeof(reference_uri_schemes_supported[0])), NULL, reference_uri_schemes_supported); + if (printer->print_by_ref) + ippAddStrings(printer->attrs, IPP_TAG_PRINTER, IPP_CONST_TAG(IPP_TAG_URISCHEME), "reference-uri-schemes-supported", (int)(sizeof(reference_uri_schemes_supported) / sizeof(reference_uri_schemes_supported[0])), NULL, reference_uri_schemes_supported); // requesting-user-uri-supported ippAddBoolean(printer->attrs, IPP_TAG_PRINTER, "requesting-user-uri-supported", true); @@ -3846,6 +3855,13 @@ ipp_print_uri(ippeve_client_t *client) // I - Client ippeve_job_t *job; // New job + if (!client->printer->print_by_ref) + { + flush_document_data(client); + respond_ipp(client, IPP_STATUS_ERROR_OPERATION_NOT_SUPPORTED, "Print by reference is disabled."); + return; + } + // Validate print job attributes... if (!valid_job_attributes(client)) { @@ -3964,6 +3980,13 @@ ipp_send_uri(ippeve_client_t *client) // I - Client ipp_attribute_t *attr; // Current attribute + if (!client->printer->print_by_ref) + { + flush_document_data(client); + respond_ipp(client, IPP_STATUS_ERROR_OPERATION_NOT_SUPPORTED, "Print by reference is disabled."); + return; + } + // Get the job... if ((job = find_job(client)) == NULL) { @@ -7695,6 +7718,7 @@ usage(FILE *out) // I - Output file cupsLangPuts(out, _("Usage: ippeveprinter [OPTIONS] \"NAME\"")); cupsLangPuts(out, _("Options:")); cupsLangPuts(out, _("--help Show this help")); + cupsLangPuts(out, _("--print-by-reference Enable the Print-URI and Send-URI operations.")); cupsLangPuts(out, _("--no-web-forms Disable web forms for media and supplies")); cupsLangPuts(out, _("--oauth-uri AS-URI Use the specified OAuth Authorization Server")); cupsLangPuts(out, _("--oauth-scopes SCOPE[,...] Use the specified OAuth scopes")); @@ -8407,4 +8431,3 @@ valid_oauth(ippeve_client_t *client, // I - Client connection return (true); } -