基于Qt实现HTTP服务器认证密钥的ASCII异或加解密问题
Let’s walk through your authentication key implementation, break down potential issues, and cover validation steps to make sure it works as expected:
You’re building an authentication key for an HTTP server that requires a specific generation logic: XOR a date string with a fixed secret key, then filter out unprintable/invalid ASCII characters to get the final usable key. The core flow is: date string → UTF-8 byte array → byte-wise XOR → convert back to string → filter allowed ASCII characters.
1. Critical: Key Index Out-of-Bounds Risk
In your getXorEncryptDecrypt function, you directly use key[i] for the XOR operation. If the date string is longer than the secret key, this will access memory beyond the key’s array bounds—this is undefined behavior that can cause crashes or incorrect results.
Fix: Use modulo to cycle through the key repeatedly:
// Replace the original XOR line with this byte[i] = byte[i] ^ key[i % strlen(key)];
2. Redundant Encoding Conversion
You’re converting the input const char* str to Unicode then back to a UTF-8 byte array—this is unnecessary if your input string is already UTF-8 encoded. Simplify it to:
// Replace the codec conversion code with this direct byte array construction QByteArray byte(str);
3. Improve Filter Rule Readability
The ASCII check logic in convertKey is scattered and hard to maintain. Refactor it into grouped, readable conditions, and use unsigned char to avoid sign-extension issues with high-value ASCII bytes:
QString Test::convertKey(std::string inputString) { QString new_key; for (unsigned char c : inputString) { bool isLetter = (c >= 'a' && c <= 'z') || (c >= 'A' && c <= 'Z'); bool isAllowedSymbol = (c == '"') || (c == '>') || (c == '\'') || (c == ','); bool isAllowedControl = (c == ' ') || (c == '\t') || (c == '\v') || (c == 0x1B) || (c == 0x1D) || (c == 0x15) || (c == 0x03) || (c == 0x05); if (isLetter || isAllowedSymbol || isAllowedControl) { new_key.append(QChar(c)); } } return new_key; }
4. Debug Output Enhancement
To make debugging easier, add the character representation of each byte alongside its numeric value:
qDebug() << i << byte[i] << QString::fromUtf8(&byte[i], 1);
- XOR Result Verification: Manually calculate a few byte pairs (e.g., 'M' (77) ^ 'a' (97) = 44, which is ',') and cross-check with your debug output to confirm the XOR logic works.
- Filter Rule Test: Create a test string containing allowed and disallowed characters (e.g., '\0', '\n', '!') and pass it to
convertKey—verify only your specified ASCII range is retained. - Boundary Test: Use a date string longer than your secret key (e.g., "Mon Jan 08 2018 12:34:56") to ensure the key cycles correctly without out-of-bounds access.
- Encoding Test: If your use case involves non-ASCII date strings, validate that the encoding conversion doesn’t introduce garbled characters.
- Unprintable Characters After XOR: This is expected—XOR can generate any ASCII value, which is exactly why the
convertKeyfilter exists. Just ensure your filter rules match the server’s allowed character set. - Authentication Failures: First confirm the date string format matches the server’s requirements (e.g., 3-letter weekday/month, zero-padded dates). Then verify the XOR logic and filtered key match the server’s expected output.
内容的提问来源于stack exchange,提问作者Sunmi

