Add warning detection and improve
[src/app-framework-binder.git] / src / rest-api.c
index 83bb2d2..756dc6f 100644 (file)
  * along with this program.  If not, see <http://www.gnu.org/licenses/>.
  * 
  * Contain all generic part to handle REST/API
+ * 
+ *  https://www.gnu.org/software/libmicrohttpd/tutorial.html [search 'largepost.c']
  */
 
 #include "../include/local-def.h"
 
+#include <dirent.h>
+#include <dlfcn.h>
 #include <setjmp.h>
 #include <signal.h>
 
 #define AFB_MSG_JTYPE "AJB_reply"
 
 
-// handle to hold queryAll values
-typedef struct {
-     char    *msg;
-     int     idx;
-     size_t  len;
-} queryHandleT;
 
 static json_object     *afbJsonType;
 
 
-// Sample Generic Ping Debug API
-PUBLIC json_object* apiPingTest(AFB_request *request, void *pluginHandle) {
-    static pingcount = 0;
-    json_object *response;
-    char query [512];
-    int len;
-
-    // request all query key/value
-    len = getQueryAll (request, query, sizeof(query));
-    if (len == 0) strcpy (query,"NoSearchQueryList");
-    
-    // check if we have some post data
-    if (request->post == NULL)  request->post="NoData";  
-        
-    // return response to caller
-    response = jsonNewMessage(AFB_SUCCESS, "Ping Binder Daemon count=%d CtxtId=%d Loa=%d query={%s} Handle=0x%x PostData: \'%s\' "
-               , pingcount++, request->client->cid, request->loa, query, request->post, pluginHandle);
-    return (response);
-}
-
-// Helper to retrieve argument from  connection
-PUBLIC const char* getQueryValue(AFB_request * request, char *name) {
-    const char *value;
-
-    value = MHD_lookup_connection_value(request->connection, MHD_GET_ARGUMENT_KIND, name);
-    return (value);
-}
-
-STATIC int getQueryCB (void*handle, enum MHD_ValueKind kind, const char *key, const char *value) {
-    queryHandleT *query = (queryHandleT*)handle;
-        
-    query->idx += snprintf (&query->msg[query->idx],query->len," %s: \'%s\',", key, value);
-}
-
-// Helper to retrieve argument from  connection
-PUBLIC int getQueryAll(AFB_request * request, char *buffer, size_t len) {
-    queryHandleT query;
-    buffer[0] = '\0'; // start with an empty string
-    query.msg= buffer;
-    query.len= len;
-    query.idx= 0;
+// Because of POST call multiple time requestApi we need to free POST handle here
+// Note this method is called from http-svc just before closing session
+PUBLIC void endPostRequest(AFB_PostHandle *postHandle) {
 
-    MHD_get_connection_values (request->connection, MHD_GET_ARGUMENT_KIND, getQueryCB, &query);
-    return (len);
-}
+    if (postHandle->type == AFB_POST_JSON) {
+        // if (verbose) fprintf(stderr, "End PostJson Request UID=%d\n", postHandle->uid);
+    }
 
-// Because of POST call multiple time requestApi we need to free POST handle here
-STATIC void endRequest(void *cls, struct MHD_Connection *connection, void **con_cls, enum MHD_RequestTerminationCode toe) {
-    AFB_HttpPost *posthandle = *con_cls;
-
-    // if post handle was used let's free everything
-    if (posthandle) {
-        if (verbose) fprintf(stderr, "End Post Request UID=%d\n", posthandle->uid);
-        free(posthandle->data);
-        free(posthandle);
+    if (postHandle->type == AFB_POST_FORM) {
+         if (verbose) fprintf(stderr, "End PostForm Request UID=%d\n", postHandle->uid);
     }
+    if (postHandle->privatebuf) free(postHandle->privatebuf);
+    free(postHandle);
 }
 
 // Check of apiurl is declare in this plugin and call it
-STATIC AFB_error callPluginApi(AFB_plugin *plugin, AFB_request *request) {
-    json_object *jresp, *jcall;
+STATIC AFB_error callPluginApi(AFB_request *request, int plugidx, void *context) {
+    json_object *jresp, *jcall, *jreqt;
     int idx, status, sig;
+    AFB_clientCtx *clientCtx;
+    AFB_plugin *plugin = request->plugins[plugidx];
     int signals[]= {SIGALRM, SIGSEGV, SIGFPE, 0};
     
     /*---------------------------------------------------------------
@@ -105,8 +62,8 @@ STATIC AFB_error callPluginApi(AFB_plugin *plugin, AFB_request *request) {
     +---------------------------------------------------------------- */
     void pluginError (int signum) {
       sigset_t sigset;
-      AFB_clientCtx *context;
-              
+   
+      
       // unlock signal to allow a new signal to come
       sigemptyset (&sigset);
       sigaddset   (&sigset, signum);
@@ -121,6 +78,11 @@ STATIC AFB_error callPluginApi(AFB_plugin *plugin, AFB_request *request) {
     for (idx = 0; plugin->apis[idx].callback != NULL; idx++) {
         if (!strcmp(plugin->apis[idx].name, request->api)) {
             
+            // Request was found and at least partially executed
+            jreqt  = json_object_new_object();
+            json_object_get (afbJsonType);  // increate jsontype reference count
+            json_object_object_add (jreqt, "jtype", afbJsonType);
+            
             // prepare an object to store calling values
             jcall=json_object_new_object();
             json_object_object_add(jcall, "prefix", json_object_new_string (plugin->prefix));
@@ -133,7 +95,7 @@ STATIC AFB_error callPluginApi(AFB_plugin *plugin, AFB_request *request) {
                 // Plugin aborted somewhere during its execution
                 json_object_object_add(jcall, "status", json_object_new_string ("abort"));
                 json_object_object_add(jcall, "info" ,  json_object_new_string ("Plugin broke during execution"));
-                json_object_object_add(request->jresp, "request", jcall);
+                json_object_object_add(jreqt, "request", jcall);
                 
             } else {
                 
@@ -141,31 +103,120 @@ STATIC AFB_error callPluginApi(AFB_plugin *plugin, AFB_request *request) {
                 if (request->config->apiTimeout > 0) {
                     for (sig=0; signals[sig] != 0; sig++) {
                        if (signal (signals[sig], pluginError) == SIG_ERR) {
-                           request->errcode = MHD_HTTP_UNPROCESSABLE_ENTITY;
-                           fprintf (stderr, "%s ERR: main no Signal/timeout handler installed.", configTime());
-                           return AFB_FAIL;
+                            request->errcode = MHD_HTTP_UNPROCESSABLE_ENTITY;
+                            json_object_object_add(jcall, "status", json_object_new_string ("fail"));
+                            json_object_object_add(jcall, "info", json_object_new_string ("Setting Timeout Handler Failed"));
+                            json_object_object_add(jreqt, "request", jcall);
+                            goto ExitOnDone;
                        }
                     }
                     // Trigger a timer to protect from unacceptable long time execution
-                    alarm (request->config->apiTimeout);
+                    alarm ((unsigned)request->config->apiTimeout);
                 }
+
+                // Out of SessionNone every call get a client context session
+                if (AFB_SESSION_NONE != plugin->apis[idx].session) {
+                    
+                    // add client context to request
+                    clientCtx = ctxClientGet(request, plugidx);
+                    if (clientCtx == NULL) {
+                        request->errcode=MHD_HTTP_INSUFFICIENT_STORAGE;
+                        json_object_object_add(jcall, "status", json_object_new_string ("fail"));
+                        json_object_object_add(jcall, "info", json_object_new_string ("Client Session Context Full !!!"));
+                        json_object_object_add(jreqt, "request", jcall);
+                        goto ExitOnDone;
+                    };
+                    
+                    if (verbose) fprintf(stderr, "Plugin=[%s] Api=[%s] Middleware=[%d] Client=[%p] Uuid=[%s] Token=[%s]\n"
+                           , request->prefix, request->api, plugin->apis[idx].session, clientCtx, clientCtx->uuid, clientCtx->token);                        
+                    
+                    switch(plugin->apis[idx].session) {
+
+                        case AFB_SESSION_CREATE: 
+                            if (clientCtx->token[0] != '\0' && request->config->token[0] != '\0') {
+                                request->errcode=MHD_HTTP_UNAUTHORIZED;
+                                json_object_object_add(jcall, "status", json_object_new_string ("exist"));
+                                json_object_object_add(jcall, "info", json_object_new_string ("AFB_SESSION_CREATE Session already exist"));
+                                json_object_object_add(jreqt, "request", jcall);
+                                goto ExitOnDone;
+                            }
+                        
+                            if (AFB_SUCCESS != ctxTokenCreate (clientCtx, request)) {
+                                request->errcode=MHD_HTTP_UNAUTHORIZED;
+                                json_object_object_add(jcall, "status", json_object_new_string ("fail"));
+                                json_object_object_add(jcall, "info", json_object_new_string ("AFB_SESSION_CREATE Invalid Initial Token"));
+                                json_object_object_add(jreqt, "request", jcall);
+                                goto ExitOnDone;
+                            } else {
+                                json_object_object_add(jcall, "uuid", json_object_new_string (clientCtx->uuid));                                
+                                json_object_object_add(jcall, "token", json_object_new_string (clientCtx->token));                                
+                                json_object_object_add(jcall, "timeout", json_object_new_int (request->config->cntxTimeout));                                
+                            }
+                            break;
+
+
+                        case AFB_SESSION_RENEW:
+                            if (AFB_SUCCESS != ctxTokenRefresh (clientCtx, request)) {
+                                request->errcode=MHD_HTTP_UNAUTHORIZED;
+                                json_object_object_add(jcall, "status", json_object_new_string ("fail"));
+                                json_object_object_add(jcall, "info", json_object_new_string ("AFB_SESSION_REFRESH Broken Exchange Token Chain"));
+                                json_object_object_add(jreqt, "request", jcall);
+                                goto ExitOnDone;
+                            } else {
+                                json_object_object_add(jcall, "uuid", json_object_new_string (clientCtx->uuid));                                
+                                json_object_object_add(jcall, "token", json_object_new_string (clientCtx->token));                                
+                                json_object_object_add(jcall, "timeout", json_object_new_int (request->config->cntxTimeout));                                
+                            }
+                            break;
+
+                        case AFB_SESSION_CLOSE:
+                            if (AFB_SUCCESS != ctxTokenCheck (clientCtx, request)) {
+                                request->errcode=MHD_HTTP_UNAUTHORIZED;
+                                json_object_object_add(jcall, "status", json_object_new_string ("empty"));
+                                json_object_object_add(jcall, "info", json_object_new_string ("AFB_SESSION_CLOSE Not a Valid Access Token"));
+                                json_object_object_add(jreqt, "request", jcall);
+                                goto ExitOnDone;
+                            } else {
+                                json_object_object_add(jcall, "uuid", json_object_new_string (clientCtx->uuid));                                
+                            }
+                            break;
+                        
+                        case AFB_SESSION_CHECK:
+                        default: 
+                            // default action is check
+                            if (AFB_SUCCESS != ctxTokenCheck (clientCtx, request)) {
+                                request->errcode=MHD_HTTP_UNAUTHORIZED;
+                                json_object_object_add(jcall, "status", json_object_new_string ("fail"));
+                                json_object_object_add(jcall, "info", json_object_new_string ("AFB_SESSION_CHECK Invalid Active Token"));
+                                json_object_object_add(jreqt, "request", jcall);
+                                goto ExitOnDone;
+                            }
+                            break;
+                    }
+                }
+                
+                // Effectively CALL PLUGIN API with a subset of the context
+                jresp = plugin->apis[idx].callback(request, context);
                 
-                // add client context to request
-                ctxClientGet(request);      
+                // Store context in case it was updated by plugins
+                if (request->context != NULL) clientCtx->contexts[plugidx] = request->context;               
                 
-                // Effectively call the API with a subset of the context
-                jresp = plugin->apis[idx].callback(request, plugin->handle);
+                // handle intermediary Post Iterates out of band
+                if ((jresp == NULL) && (request->errcode == MHD_HTTP_OK)) return (AFB_SUCCESS);
 
+                // Session close is done after the API call so API can still use session in closing API
+                if (AFB_SESSION_CLOSE == plugin->apis[idx].session) ctxTokenReset (clientCtx, request);                    
+                
                 // API should return NULL of a valid Json Object
                 if (jresp == NULL) {
                     json_object_object_add(jcall, "status", json_object_new_string ("null"));
-                    json_object_object_add(request->jresp, "request", jcall);
+                    json_object_object_add(jreqt, "request", jcall);
                     request->errcode = MHD_HTTP_NO_RESPONSE;
                     
                 } else {
                     json_object_object_add(jcall, "status", json_object_new_string ("processed"));
-                    json_object_object_add(request->jresp, "request", jcall);
-                    json_object_object_add(request->jresp, "response", jresp);
+                    json_object_object_add(jreqt, "request", jcall);
+                    json_object_object_add(jreqt, "response", jresp);
                 }
                 // cancel timeout and plugin signal handle before next call
                 if (request->config->apiTimeout > 0) {
@@ -175,166 +226,314 @@ STATIC AFB_error callPluginApi(AFB_plugin *plugin, AFB_request *request) {
                     }
                 }              
             }       
-            return (AFB_DONE);
+            goto ExitOnDone; 
+        }
+    }   
+    return (AFB_FAIL);
+    
+ExitOnDone:
+    request->jresp = jreqt;
+    return (AFB_DONE);                        
+}
+
+STATIC AFB_error findAndCallApi (AFB_request *request, void *context) {
+    int idx;
+    AFB_error status;
+    
+    if (!request->api || !request->prefix) return (AFB_FAIL);
+   
+    // Search for a plugin with this urlpath
+    for (idx = 0; request->plugins[idx] != NULL; idx++) {
+        if (!strcmp(request->plugins[idx]->prefix, request->prefix)) {
+            status =callPluginApi(request, idx, context);
+            break;
         }
     }
+    // No plugin was found
+    if (request->plugins[idx] == NULL) {
+        request->jresp = jsonNewMessage(AFB_FATAL, "No Plugin=[%s] Url=%s", request->prefix, request->url);
+        goto ExitOnError;
+    }  
+    
+    // plugin callback did not return a valid Json Object
+    if (status == AFB_FAIL) {
+        request->jresp = jsonNewMessage(AFB_FATAL, "No API=[%s] for Plugin=[%s] url=[%s]", request->api, request->prefix, request->url);
+        goto ExitOnError;
+    }
+    
+    // Everything look OK
+    return (status);
+    
+ExitOnError:
+    request->errcode = MHD_HTTP_UNPROCESSABLE_ENTITY;
     return (AFB_FAIL);
 }
 
+// This CB is call for every item with a form post it reformat iterator values
+// and callback Plugin API for each Item within PostForm.
+STATIC int doPostIterate (void *cls, enum MHD_ValueKind kind, const char *key,
+              const char *filename, const char *mimetype,
+              const char *encoding, const char *data, uint64_t offset,
+              size_t size) {
+  
+  AFB_error    status;
+  AFB_PostItem item;
+    
+  // retrieve API request from Post iterator handle  
+  AFB_PostHandle *postHandle  = (AFB_PostHandle*)cls;
+  AFB_request *request = (AFB_request*)postHandle->privatebuf;
+  AFB_PostRequest postRequest;
+  
+  if (verbose)
+    fprintf (stderr, "postHandle key=%s filename=%s len=%zu mime=%s\n", key, filename, size, mimetype);
+   
+  // Create and Item value for Plugin API
+  item.kind     = kind;
+  item.key      = key;
+  item.filename = filename;
+  item.mimetype = mimetype;
+  item.encoding = encoding;
+  item.len      = size;
+  item.data     = data;
+  item.offset   = offset;
+  
+  // Reformat Request to make it somehow similar to GET/PostJson case
+  postRequest.data= (char*) postHandle;
+  postRequest.len = size;
+  postRequest.type= AFB_POST_FORM;;
+  request->post = &postRequest;
+  
+  // effectively call plugin API                 
+  status = findAndCallApi (request, &item);
+  // when returning no processing of postform stop
+  if (status != AFB_SUCCESS) return MHD_NO;
+  
+  // let's allow iterator to move to next item
+  return MHD_YES;
+}
+
+STATIC void freeRequest (AFB_request *request) {
 
-// process rest API query
-PUBLIC int doRestApi(struct MHD_Connection *connection, AFB_session *session, const char* url, const char *method
-    , const char *upload_data, size_t *upload_data_size, void **con_cls) {
+ free (request->prefix);    
+ free (request->api);    
+ free (request);    
+}
+
+STATIC AFB_request *createRequest (struct MHD_Connection *connection, AFB_session *session, const char* url) {
     
-    static int postcount = 0; // static counter to debug POST protocol
-    char *baseurl, *baseapi, *urlcpy1, *urlcpy2, *query, *token, *uuid;
-    json_object *errMessage;
-    AFB_error status;
-    struct MHD_Response *webResponse;
-    const char *serialized, parsedurl;
-    AFB_request request;
-    AFB_HttpPost *posthandle = *con_cls;
-    AFB_clientCtx clientCtx;
-    int idx, ret;
+    AFB_request *request;
 
+    // Start with a clean request
+    request = calloc (1, sizeof (AFB_request));
+    char *urlcpy1, *urlcpy2;
+    char *baseapi, *baseurl;
+      
     // Extract plugin urlpath from request and make two copy because strsep overload copy
     urlcpy1 = urlcpy2 = strdup(url);
     baseurl = strsep(&urlcpy2, "/");
     if (baseurl == NULL) {
-        errMessage = jsonNewMessage(AFB_FATAL, "Invalid API call url=[%s]", url);
-        goto ExitOnError;
+        request->jresp = jsonNewMessage(AFB_FATAL, "Invalid API call url=[%s]", url);
+        request->errcode = MHD_HTTP_BAD_REQUEST;
+        goto Done;
     }
 
+    // let's compute URL and call API
     baseapi = strsep(&urlcpy2, "/");
     if (baseapi == NULL) {
-        errMessage = jsonNewMessage(AFB_FATAL, "Invalid API call url=[%s]", url);
-        goto ExitOnError;
+        request->jresp = jsonNewMessage(AFB_FATAL, "Invalid API call plugin=[%s] url=[%s]", baseurl, url);
+        request->errcode = MHD_HTTP_BAD_REQUEST;
+        goto Done;
     }
     
+    // build request structure
+    request->connection = connection;
+    request->config = session->config;
+    request->url    = url;
+    request->prefix = strdup (baseurl);
+    request->api    = strdup (baseapi);
+    request->plugins= session->plugins;
+    // note request->handle is fed with request->context in ctxClientGet
+
+Done:    
+    free(urlcpy1);
+    return (request);
+}
 
+// process rest API query
+PUBLIC int doRestApi(struct MHD_Connection *connection, AFB_session *session, const char* url, const char *method
+    , const char *upload_data, size_t *upload_data_size, void **con_cls) {
+    
+    static int postcount = 0; // static counter to debug POST protocol
+    json_object *errMessage;
+    AFB_error status;
+    struct MHD_Response *webResponse;
+    const char *serialized;
+    AFB_request *request;
+    AFB_PostHandle *postHandle;
+    AFB_PostRequest postRequest;
+    int ret;
+    
+    // fprintf (stderr, "doRestAPI method=%s posthandle=%p\n", method, con_cls);
+    
     // if post data may come in multiple calls
     if (0 == strcmp(method, MHD_HTTP_METHOD_POST)) {
         const char *encoding, *param;
         int contentlen = -1;
-        AFB_HttpPost *posthandle = *con_cls;
+        postHandle = *con_cls;
 
-        // Let make sure we have the right encoding and a valid length
-        encoding = MHD_lookup_connection_value(connection, MHD_HEADER_KIND, MHD_HTTP_HEADER_CONTENT_TYPE);
-        param = MHD_lookup_connection_value(connection, MHD_HEADER_KIND, MHD_HTTP_HEADER_CONTENT_LENGTH);
-        if (param) sscanf(param, "%i", &contentlen);
+        // This is the initial post event let's create form post structure POST data come in multiple events
+        if (postHandle == NULL) {
 
-        // POST datas may come in multiple chunk. Even when it never happen on AFB, we still have to handle the case
-        if (strcasestr(encoding, JSON_CONTENT) == 0) {
-            errMessage = jsonNewMessage(AFB_FATAL, "Post Date wrong type encoding=%s != %s", encoding, JSON_CONTENT);
-            goto ExitOnError;
-        }
+            // allocate application POST processor handle to zero
+            postHandle = calloc(1, sizeof (AFB_PostHandle));
+            postHandle->uid = postcount++; // build a UID for DEBUG
+            *con_cls = postHandle;  // update context with posthandle
+            
+            // Let make sure we have the right encoding and a valid length
+            encoding = MHD_lookup_connection_value(connection, MHD_HEADER_KIND, MHD_HTTP_HEADER_CONTENT_TYPE);
+            
+            // We are facing an empty post let's process it as a get
+            if (encoding == NULL) {
+                postHandle->type   = AFB_POST_EMPTY;
+                return MHD_YES;
+            }
+        
+            // Form post is handle through a PostProcessor and call API once per form key
+            if (strcasestr(encoding, FORM_CONTENT) != NULL) {
+                if (verbose) fprintf(stderr, "Create doPostIterate[uid=%d posthandle=%p]\n", postHandle->uid, postHandle);
+
+                request = createRequest (connection, session, url);
+                if (request->jresp != NULL) goto ProcessApiCall;
+                postHandle->type   = AFB_POST_FORM;
+                postHandle->privatebuf = (void*)request;
+                postHandle->pp     = MHD_create_post_processor (connection, MAX_POST_SIZE, &doPostIterate, postHandle);
+                
+                if (NULL == postHandle->pp) {
+                    fprintf(stderr,"OOPS: Internal error fail to allocate MHD_create_post_processor\n");
+                    free (postHandle);
+                    return MHD_NO;
+                }
+                return MHD_YES;
+            }           
+        
+            // POST json is store into a buffer and present in one piece to API
+            if (strcasestr(encoding, JSON_CONTENT) != NULL) {
 
-        if (contentlen > MAX_POST_SIZE) {
-            errMessage = jsonNewMessage(AFB_FATAL, "Post Date to big %d > %d", contentlen, MAX_POST_SIZE);
-            goto ExitOnError;
-        }
+                param = MHD_lookup_connection_value(connection, MHD_HEADER_KIND, MHD_HTTP_HEADER_CONTENT_LENGTH);
+                if (param) sscanf(param, "%i", &contentlen);
+
+                // Because PostJson are build in RAM size is constrained
+                if (contentlen > MAX_POST_SIZE) {
+                    errMessage = jsonNewMessage(AFB_FATAL, "Post Date to big %d > %d", contentlen, MAX_POST_SIZE);
+                    goto ExitOnError;
+                }
 
-        // In POST mode first libmicrohttp call only establishes POST handling.
-        if (posthandle == NULL) {
-            posthandle = malloc(sizeof (AFB_HttpPost)); // allocate application POST processor handle
-            posthandle->uid = postcount++; // build a UID for DEBUG
-            posthandle->len = 0; // effective length within POST handler
-            posthandle->data = malloc(contentlen + 1); // allocate memory for full POST data + 1 for '\0' enf of string
-            *con_cls = posthandle; // attache POST handle to current HTTP session
+                // Size is OK, let's allocate a buffer to hold post data
+                postHandle->type = AFB_POST_JSON;
+                postHandle->privatebuf = malloc((unsigned)contentlen + 1); // allocate memory for full POST data + 1 for '\0' enf of string
 
-            if (verbose) fprintf(stderr, "Create Post[%d] Size=%d\n", posthandle->uid, contentlen);
-            return MHD_YES;
+                // if (verbose) fprintf(stderr, "Create PostJson[uid=%d] Size=%d\n", postHandle->uid, contentlen);
+                return MHD_YES;
+
+            } else {
+                // We only support Json and Form Post format
+                errMessage = jsonNewMessage(AFB_FATAL, "Post Date wrong type encoding=%s != %s", encoding, JSON_CONTENT);
+                goto ExitOnError;                
+            }   
         }
 
         // This time we receive partial/all Post data. Note that even if we get all POST data. We should nevertheless
         // return MHD_YES and not process the request directly. Otherwise Libmicrohttpd is unhappy and fails with
-        // 'Internal application error, closing connection'.
+        // 'Internal application error, closing connection'.            
         if (*upload_data_size) {
-            if (verbose) fprintf(stderr, "Update Post[%d]\n", posthandle->uid);
-
-            memcpy(&posthandle->data[posthandle->len], upload_data, *upload_data_size);
-            posthandle->len = posthandle->len + *upload_data_size;
+    
+            if (postHandle->type == AFB_POST_FORM) {
+                // if (verbose) fprintf(stderr, "Processing PostForm[uid=%d]\n", postHandle->uid);
+                MHD_post_process (postHandle->pp, upload_data, *upload_data_size);
+            }
+            
+            // Process JsonPost request when buffer is completed let's call API    
+            if (postHandle->type == AFB_POST_JSON) {
+                // if (verbose) fprintf(stderr, "Updating PostJson[uid=%d]\n", postHandle->uid);
+                memcpy(&postHandle->privatebuf[postHandle->len], upload_data, *upload_data_size);
+                postHandle->len = postHandle->len + *upload_data_size;
+            }
+            
             *upload_data_size = 0;
             return MHD_YES;
-        }
+            
+        } else {  // we have finish with Post reception let's finish the work
+            
+            // Create a request structure to finalise the request
+            request= createRequest (connection, session, url);
+            if (request->jresp != NULL) {
+                errMessage = request->jresp;
+                goto ExitOnError;
+            }
+            postRequest.type = postHandle->type;
+            
+            // Postform add application context handle to request
+            if (postHandle->type == AFB_POST_FORM) {
+               postRequest.data = (char*) postHandle;
+               request->post = &postRequest;
+            }
+            
+            if (postHandle->type == AFB_POST_JSON) {
+                // if (verbose) fprintf(stderr, "Processing PostJson[uid=%d]\n", postHandle->uid);
 
-        // We should only start to process DATA after Libmicrohttpd call or application handler with *upload_data_size==0
-        // At this level we're may verify that we got everything and process DATA
-        if (posthandle->len != contentlen) {
-            errMessage = jsonNewMessage(AFB_FATAL, "Post Data Incomplete UID=%d Len %d != %s", posthandle->uid, contentlen, posthandle->len);
-            goto ExitOnError;
-        }
+                param = MHD_lookup_connection_value(connection, MHD_HEADER_KIND, MHD_HTTP_HEADER_CONTENT_LENGTH);
+                if (param) sscanf(param, "%i", &contentlen);
 
-        // Before processing data, make sure buffer string is properly ended
-        posthandle->data[posthandle->len] = '\0';
-        request.post = posthandle->data;
+                // At this level we're may verify that we got everything and process DATA
+                if (postHandle->len != contentlen) {
+                    errMessage = jsonNewMessage(AFB_FATAL, "Post Data Incomplete UID=%d Len %d != %d", postHandle->uid, contentlen, postHandle->len);
+                    goto ExitOnError;
+                }
 
-        if (verbose) fprintf(stderr, "Close Post[%d] Buffer=%s\n", posthandle->uid, request.post);
+                // Before processing data, make sure buffer string is properly ended
+                postHandle->privatebuf[postHandle->len] = '\0';
+                postRequest.data = postHandle->privatebuf;
+                request->post = &postRequest;
 
+                // if (verbose) fprintf(stderr, "Close Post[%d] Buffer=%s\n", postHandle->uid, request->post->data);
+            }
+        }
     } else {
-        request.post = NULL;
+        // this is a get we only need a request
+        request= createRequest (connection, session, url);
     };
-        
-    // build request structure
-    memset(&request, 0, sizeof (request));
-    request.connection = connection;
-    request.config = session->config;
-    request.url    = url;
-    request.plugin = baseurl;
-    request.api    = baseapi;
-    request.jresp  = json_object_new_object();
-    
-    // increase reference count and add jtype to response    
-    json_object_get (afbJsonType);
-    json_object_object_add (request.jresp, "jtype", afbJsonType);
-    
-    // Search for a plugin with this urlpath
-    for (idx = 0; session->plugins[idx] != NULL; idx++) {
-        if (!strcmp(session->plugins[idx]->prefix, baseurl)) {
-            status =callPluginApi(session->plugins[idx], &request);
-            break;
-        }
-    }
-    // No plugin was found
-    if (session->plugins[idx] == NULL) {
-        errMessage = jsonNewMessage(AFB_FATAL, "No Plugin=[%s]", request.plugin);
-        goto ExitOnError;
-    }
 
-    // plugin callback did not return a valid Json Object
-    if (status != AFB_DONE) {
-        errMessage = jsonNewMessage(AFB_FATAL, "No API=[%s] for Plugin=[%s]", request.api, request.plugin);
-        goto ExitOnError;
-    }
+ProcessApiCall:    
+    // Request is ready let's call API without any extra handle
+    status = findAndCallApi (request, NULL);
 
-    serialized = json_object_to_json_string(request.jresp);
+    serialized = json_object_to_json_string(request->jresp);
     webResponse = MHD_create_response_from_buffer(strlen(serialized), (void*) serialized, MHD_RESPMEM_MUST_COPY);
-    free(urlcpy1);
     
     // client did not pass token on URI let's use cookies 
-    if ((!request.restfull) && (request.client != NULL)) {
-       char cookie[64]; 
-       snprintf (cookie, sizeof (cookie), "%s=%s", COOKIE_NAME,  request.client->uuid); 
+    if ((!request->restfull) && (request->context != NULL)) {
+       char cookie[256]; 
+       snprintf (cookie, sizeof (cookie), "%s-%d=%s; Path=%s; Max-Age=%d; HttpOnly", COOKIE_NAME, request->config->httpdPort, request->uuid, request->config->rootapi,request->config->cntxTimeout); 
        MHD_add_response_header (webResponse, MHD_HTTP_HEADER_SET_COOKIE, cookie);
-       // if(verbose) fprintf(stderr,"Cookie: [%s]\n", cookie);
     }
     
     // if requested add an error status
-    if (request.errcode != 0)  ret=MHD_queue_response (connection, request.errcode, webResponse);
-    else ret = MHD_queue_response(connection, MHD_HTTP_OK, webResponse);
+    if (request->errcode != 0)  ret=MHD_queue_response (connection, request->errcode, webResponse);
+    else MHD_queue_response(connection, MHD_HTTP_OK, webResponse);
     
     MHD_destroy_response(webResponse);
-    json_object_put(request.jresp); // decrease reference rqtcount to free the json object
-    return ret;
+    json_object_put(request->jresp); // decrease reference rqtcount to free the json object
+    freeRequest (request);
+    return MHD_YES;
 
 ExitOnError:
-    free(urlcpy1);
+    freeRequest (request);
     serialized = json_object_to_json_string(errMessage);
     webResponse = MHD_create_response_from_buffer(strlen(serialized), (void*) serialized, MHD_RESPMEM_MUST_COPY);
-    ret = MHD_queue_response(connection, MHD_HTTP_BAD_REQUEST, webResponse);
+    MHD_queue_response(connection, MHD_HTTP_BAD_REQUEST, webResponse);
     MHD_destroy_response(webResponse);
     json_object_put(errMessage); // decrease reference rqtcount to free the json object
-    return ret;
+    return MHD_YES;
 }
 
 
@@ -364,34 +563,122 @@ STATIC AFB_plugin ** RegisterJsonPlugins(AFB_plugin **plugins) {
               
             // Prebuild each API jtype to boost API json response
             for (jdx = 0; plugins[idx]->apis[jdx].name != NULL; jdx++) {
-                AFB_privateApi *private = malloc (sizeof (AFB_privateApi));
-                if (plugins[idx]->apis[jdx].private != NULL) {
-                    fprintf (stderr, "WARNING: plugin=%s api=%s private handle should be NULL=0x%x\n"
-                            ,plugins[idx]->prefix,plugins[idx]->apis[jdx].name, plugins[idx]->apis[jdx].private);
+                AFB_privateApi *privateapi = malloc (sizeof (AFB_privateApi));
+                if (plugins[idx]->apis[jdx].privateapi != NULL) {
+                    fprintf (stderr, "WARNING: plugin=%s api=%s private handle should be NULL=%p\n"
+                            ,plugins[idx]->prefix,plugins[idx]->apis[jdx].name, plugins[idx]->apis[jdx].privateapi);
                 }
-                private->len = strlen (plugins[idx]->apis[jdx].name);
-                private->jtype=json_object_new_string(plugins[idx]->apis[jdx].name);
-                json_object_get(private->jtype); // increase reference count to make it permanent
-                plugins[idx]->apis[jdx].private = private;
+                privateapi->len = (int)strlen (plugins[idx]->apis[jdx].name);
+                privateapi->jtype=json_object_new_string(plugins[idx]->apis[jdx].name);
+                json_object_get(privateapi->jtype); // increase reference count to make it permanent
+                plugins[idx]->apis[jdx].privateapi = privateapi;
             }
         }
     }
     return (plugins);
 }
 
+STATIC void scanDirectory(char *dirpath, int dirfd, AFB_plugin **plugins, int *count) {
+    DIR *dir;
+    void *libso;
+    struct dirent pluginDir, *result;
+    AFB_plugin* (*pluginRegisterFct)(void);
+    char pluginPath[255];   
+
+    // Open Directory to scan over it
+    dir = fdopendir (dirfd);
+    if (dir == NULL) {
+        fprintf(stderr, "ERROR in scanning directory\n");
+        return; 
+    }
+    if (verbose) fprintf (stderr, "Scanning dir=[%s] for plugins\n", dirpath);
+
+    for (;;) {
+         readdir_r(dir, &pluginDir, &result);
+         if (result == NULL) break;
+
+        // Loop on any contained directory
+        if ((pluginDir.d_type == DT_DIR) && (pluginDir.d_name[0] != '.')) {
+           int fd = openat (dirfd, pluginDir.d_name, O_DIRECTORY);
+           char newpath[255];
+           strncpy (newpath, dirpath, sizeof(newpath));
+           strncat (newpath, "/", sizeof(newpath));
+           strncat (newpath, pluginDir.d_name, sizeof(newpath));
+           
+           scanDirectory (newpath, fd, plugins, count);
+           close (fd);
+
+        } else {
+
+            // This is a file but not a plugin let's move to next directory element
+            if (!strstr (pluginDir.d_name, ".so")) continue;
+
+            // This is a loadable library let's check if it's a plugin
+            snprintf (pluginPath, sizeof(pluginPath), "%s/%s", dirpath, pluginDir.d_name);
+            libso = dlopen (pluginPath, RTLD_NOW | RTLD_LOCAL);
+
+            // Load fail we ignore this .so file            
+            if (!libso) {
+                fprintf(stderr, "[%s] is not loadable, continuing...\n", pluginDir.d_name);
+                continue;
+            }
+
+            pluginRegisterFct = dlsym (libso, "pluginRegister");
+
+            if (!pluginRegisterFct) {
+                fprintf(stderr, "[%s] is not an AFB plugin, continuing...\n", pluginDir.d_name);
+                continue;
+            }
+
+            // if max plugin is reached let's stop searching
+            if (*count == AFB_MAX_PLUGINS) {
+                fprintf(stderr, "[%s] is not loaded [Max Count=%d reached]\n", pluginDir.d_name, *count);
+                continue;
+            }
+
+            if (verbose) fprintf(stderr, "[%s] is a valid AFB plugin, loading pos[%d]\n", pluginDir.d_name, *count);
+            plugins[*count] = pluginRegisterFct();
+            if (!plugins[*count]) {
+                if (verbose) fprintf(stderr, "ERROR: plugin [%s] register function failed. continuing...\n", pluginDir.d_name);
+            } else
+                *count = *count +1;
+        }
+    }
+    closedir (dir);
+}
+
 void initPlugins(AFB_session *session) {
-    static AFB_plugin * plugins[10];
+    AFB_plugin **plugins;
+    
     afbJsonType = json_object_new_string (AFB_MSG_JTYPE);
-    int i = 0;
-
-    plugins[i++] = afsvRegister(session),
-    plugins[i++] = dbusRegister(session),
-    plugins[i++] = alsaRegister(session),
-#ifdef HAVE_RADIO_PLUGIN
-    plugins[i++] = radioRegister(session),
-#endif
-    plugins[i++] = NULL;
+    int count = 0;
+    char *dirpath;
+    int dirfd;
+
+    /* pre-allocate for AFB_MAX_PLUGINS plugins, we will downsize later */
+    plugins = (AFB_plugin **) malloc (AFB_MAX_PLUGINS *sizeof(AFB_plugin*));
+    
+    // Loop on every directory passed in --plugins=xxx
+    while ((dirpath = strsep(&session->config->ldpaths, ":"))) {
+            // Ignore any directory we fail to open
+        if ((dirfd = open(dirpath, O_DIRECTORY)) <= 0) {
+            fprintf(stderr, "Invalid directory path=[%s]\n", dirpath);
+            continue;
+        }
+        scanDirectory (dirpath, dirfd, plugins, &count);
+        close (dirfd);
+    }
+
+    if (count == 0) {
+        fprintf(stderr, "No plugins found, afb-daemon is unlikely to work in this configuration, exiting...\n");
+        exit (-1);
+    }
     
+    // downsize structure to effective number of loaded plugins
+    plugins = (AFB_plugin **)realloc (plugins, (unsigned)(count+1)*sizeof(AFB_plugin*));
+    plugins[count] = NULL;
+
     // complete plugins and save them within current sessions    
     session->plugins = RegisterJsonPlugins(plugins);
+    session->config->pluginCount = count;
 }