Change the SoupURI properties to SoupAddress properties.
[platform/upstream/libsoup.git] / libsoup / soup-session.c
index 633d443..2b9e5eb 100644 (file)
 #include <string.h>
 #include <stdlib.h>
 
+#include "soup-address.h"
 #include "soup-auth.h"
-#include "soup-session.h"
+#include "soup-auth-basic.h"
+#include "soup-auth-digest.h"
+#include "soup-auth-manager-ntlm.h"
 #include "soup-connection.h"
-#include "soup-connection-ntlm.h"
 #include "soup-marshal.h"
-#include "soup-message-filter.h"
 #include "soup-message-private.h"
 #include "soup-message-queue.h"
+#include "soup-session.h"
+#include "soup-session-feature.h"
+#include "soup-session-private.h"
+#include "soup-socket.h"
 #include "soup-ssl.h"
 #include "soup-uri.h"
 
-typedef struct {
-       SoupUri    *root_uri;
+/**
+ * SECTION:soup-session
+ * @short_description: Soup session state object
+ *
+ * #SoupSession is the object that controls client-side HTTP. A
+ * #SoupSession encapsulates all of the state that libsoup is keeping
+ * on behalf of your program; cached HTTP connections, authentication
+ * information, etc.
+ *
+ * Most applications will only need a single #SoupSession; the primary
+ * reason you might need multiple sessions is if you need to have
+ * multiple independent authentication contexts. (Eg, you are
+ * connecting to a server and authenticating as two different users at
+ * different times; the easiest way to ensure that each #SoupMessage
+ * is sent with the authentication information you intended is to use
+ * one session for the first user, and a second session for the other
+ * user.)
+ *
+ * #SoupSession itself is an abstract class, with two subclasses. If
+ * you are using the glib main loop, you will generally want to use
+ * #SoupSessionAsync, which uses non-blocking I/O and callbacks. On
+ * the other hand, if your application is threaded and you want to do
+ * synchronous I/O in a separate thread from the UI, use
+ * #SoupSessionSync.
+ **/
 
-       GSList     *connections;      /* CONTAINS: SoupConnection */
-       guint       num_conns;
+typedef struct {
+       SoupAddress *addr;
 
-       GHashTable *auth_realms;      /* path -> scheme:realm */
-       GHashTable *auths;            /* scheme:realm -> SoupAuth */
+       GSList      *connections;      /* CONTAINS: SoupConnection */
+       guint        num_conns;
 } SoupSessionHost;
 
 typedef struct {
-       SoupUri *proxy_uri;
-       guint max_conns, max_conns_per_host;
-       gboolean use_ntlm;
+       SoupURI *proxy_uri;
+       SoupAddress *proxy_addr;
+       SoupAuth *proxy_auth;
 
        char *ssl_ca_file;
-       gpointer ssl_creds;
+       SoupSSLCredentials *ssl_creds;
+
+       SoupMessageQueue *queue;
 
-       GSList *filters;
+       char *user_agent;
 
-       GHashTable *hosts; /* SoupUri -> SoupSessionHost */
+       GSList *features;
+       SoupAuthManager *auth_manager;
+
+       GHashTable *hosts; /* SoupAddress -> SoupSessionHost */
        GHashTable *conns; /* SoupConnection -> SoupSessionHost */
        guint num_conns;
-
-       SoupSessionHost *proxy_host;
+       guint max_conns, max_conns_per_host;
+       guint io_timeout, idle_timeout;
 
        /* Must hold the host_lock before potentially creating a
         * new SoupSessionHost, or adding/removing a connection.
@@ -57,38 +90,33 @@ typedef struct {
        GMutex *host_lock;
 
        GMainContext *async_context;
-
-       /* Holds the timeout value for the connection, when
-          no response is received.
-       */
-       guint timeout;
 } SoupSessionPrivate;
 #define SOUP_SESSION_GET_PRIVATE(o) (G_TYPE_INSTANCE_GET_PRIVATE ((o), SOUP_TYPE_SESSION, SoupSessionPrivate))
 
-static guint    host_uri_hash  (gconstpointer key);
-static gboolean host_uri_equal (gconstpointer v1, gconstpointer v2);
 static void     free_host      (SoupSessionHost *host);
 
-static void setup_message   (SoupMessageFilter *filter, SoupMessage *msg);
-
 static void queue_message   (SoupSession *session, SoupMessage *msg,
-                            SoupMessageCallbackFn callback,
-                            gpointer user_data);
+                            SoupSessionCallback callback, gpointer user_data);
 static void requeue_message (SoupSession *session, SoupMessage *msg);
-static void cancel_message  (SoupSession *session, SoupMessage *msg);
+static void cancel_message  (SoupSession *session, SoupMessage *msg,
+                            guint status_code);
+
+static void auth_manager_authenticate (SoupAuthManager *manager,
+                                      SoupMessage *msg, SoupAuth *auth,
+                                      gboolean retrying, gpointer user_data);
 
 #define SOUP_SESSION_MAX_CONNS_DEFAULT 10
-#define SOUP_SESSION_MAX_CONNS_PER_HOST_DEFAULT 4
+#define SOUP_SESSION_MAX_CONNS_PER_HOST_DEFAULT 2
 
-static void filter_iface_init (SoupMessageFilterClass *filter_class);
+#define SOUP_SESSION_USER_AGENT_BASE "libsoup/" PACKAGE_VERSION
 
-G_DEFINE_TYPE_EXTENDED (SoupSession, soup_session, G_TYPE_OBJECT, 0,
-                       G_IMPLEMENT_INTERFACE (SOUP_TYPE_MESSAGE_FILTER,
-                                              filter_iface_init))
+G_DEFINE_TYPE (SoupSession, soup_session, G_TYPE_OBJECT)
 
 enum {
+       REQUEST_QUEUED,
+       REQUEST_STARTED,
+       REQUEST_UNQUEUED,
        AUTHENTICATE,
-       REAUTHENTICATE,
        LAST_SIGNAL
 };
 
@@ -104,6 +132,11 @@ enum {
        PROP_SSL_CA_FILE,
        PROP_ASYNC_CONTEXT,
        PROP_TIMEOUT,
+       PROP_USER_AGENT,
+       PROP_IDLE_TIMEOUT,
+       PROP_ADD_FEATURE,
+       PROP_ADD_FEATURE_BY_TYPE,
+       PROP_REMOVE_FEATURE_BY_TYPE,
 
        LAST_PROP
 };
@@ -118,16 +151,24 @@ soup_session_init (SoupSession *session)
 {
        SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
 
-       session->queue = soup_message_queue_new ();
+       priv->queue = soup_message_queue_new (session);
 
        priv->host_lock = g_mutex_new ();
-       priv->hosts = g_hash_table_new (host_uri_hash, host_uri_equal);
+       priv->hosts = g_hash_table_new (soup_address_hash_by_ip,
+                                       soup_address_equal_by_ip);
        priv->conns = g_hash_table_new (NULL, NULL);
 
        priv->max_conns = SOUP_SESSION_MAX_CONNS_DEFAULT;
        priv->max_conns_per_host = SOUP_SESSION_MAX_CONNS_PER_HOST_DEFAULT;
 
-       priv->timeout = 0;
+       priv->auth_manager = g_object_new (SOUP_TYPE_AUTH_MANAGER_NTLM,
+                                          SOUP_AUTH_MANAGER_NTLM_USE_NTLM, FALSE,
+                                          NULL);
+       g_signal_connect (priv->auth_manager, "authenticate",
+                         G_CALLBACK (auth_manager_authenticate), session);
+       soup_auth_manager_add_type (priv->auth_manager, SOUP_TYPE_AUTH_BASIC);
+       soup_auth_manager_add_type (priv->auth_manager, SOUP_TYPE_AUTH_DIGEST);
+       soup_session_add_feature (session, SOUP_SESSION_FEATURE (priv->auth_manager));
 }
 
 static gboolean
@@ -144,7 +185,8 @@ cleanup_hosts (SoupSessionPrivate *priv)
 
        g_mutex_lock (priv->host_lock);
        old_hosts = priv->hosts;
-       priv->hosts = g_hash_table_new (host_uri_hash, host_uri_equal);
+       priv->hosts = g_hash_table_new (soup_address_hash_by_ip,
+                                       soup_address_equal_by_ip);
        g_mutex_unlock (priv->host_lock);
 
        g_hash_table_foreach_remove (old_hosts, foreach_free_host, NULL);
@@ -156,17 +198,12 @@ dispose (GObject *object)
 {
        SoupSession *session = SOUP_SESSION (object);
        SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
-       GSList *f;
 
        soup_session_abort (session);
        cleanup_hosts (priv);
 
-       if (priv->filters) {
-               for (f = priv->filters; f; f = f->next)
-                       g_object_unref (f->data);
-               g_slist_free (priv->filters);
-               priv->filters = NULL;
-       }
+       while (priv->features)
+               soup_session_remove_feature (session, priv->features->data);
 
        G_OBJECT_CLASS (soup_session_parent_class)->dispose (object);
 }
@@ -177,12 +214,22 @@ finalize (GObject *object)
        SoupSession *session = SOUP_SESSION (object);
        SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
 
-       soup_message_queue_destroy (session->queue);
+       soup_message_queue_destroy (priv->queue);
 
        g_mutex_free (priv->host_lock);
        g_hash_table_destroy (priv->hosts);
        g_hash_table_destroy (priv->conns);
 
+       g_free (priv->user_agent);
+
+       if (priv->auth_manager)
+               g_object_unref (priv->auth_manager);
+
+       if (priv->proxy_uri)
+               soup_uri_free (priv->proxy_uri);
+       if (priv->proxy_addr)
+               g_object_unref (priv->proxy_addr);
+
        if (priv->ssl_creds)
                soup_ssl_free_client_credentials (priv->ssl_creds);
 
@@ -213,92 +260,140 @@ soup_session_class_init (SoupSessionClass *session_class)
        /* signals */
 
        /**
-        * SoupSession::authenticate:
+        * SoupSession::request-queued:
         * @session: the session
-        * @msg: the #SoupMessage being sent
-        * @auth_type: the authentication type
-        * @auth_realm: the realm being authenticated to
-        * @username: the signal handler should set this to point to
-        * the provided username
-        * @password: the signal handler should set this to point to
-        * the provided password
+        * @msg: the request that was queued
+        *
+        * Emitted when a request is queued on @session. (Note that
+        * "queued" doesn't just mean soup_session_queue_message();
+        * soup_session_send_message() implicitly queues the message
+        * as well.)
+        *
+        * When sending a request, first #SoupSession::request_queued
+        * is emitted, indicating that the session has become aware of
+        * the request.
+        *
+        * Once a connection is available to send the request on, the
+        * session emits #SoupSession::request_started. Then, various
+        * #SoupMessage signals are emitted as the message is
+        * processed. If the message is requeued, it will emit
+        * #SoupMessage::restarted, which will then be followed by
+        * another #SoupSession::request_started and another set of
+        * #SoupMessage signals when the message is re-sent.
         *
-        * Emitted when the session requires authentication. The
-        * credentials may come from the user, or from cached
-        * information. If no credentials are available, leave
-        * @username and @password unchanged.
+        * Eventually, the message will emit #SoupMessage::finished.
+        * Normally, this signals the completion of message
+        * processing. However, it is possible that the application
+        * will requeue the message from the "finished" handler (or
+        * equivalently, from the soup_session_queue_message()
+        * callback). In that case, the process will loop back to
+        * #SoupSession::request_started.
         *
-        * If the provided credentials fail, the #reauthenticate
-        * signal will be emitted.
+        * Eventually, a message will reach "finished" and not be
+        * requeued. At that point, the session will emit
+        * #SoupSession::request_unqueued to indicate that it is done
+        * with the message.
+        *
+        * To sum up: #SoupSession::request_queued and
+        * #SoupSession::request_unqueued are guaranteed to be emitted
+        * exactly once, but #SoupSession::request_started and
+        * #SoupMessage::finished (and all of the other #SoupMessage
+        * signals) may be invoked multiple times for a given message.
         **/
-       signals[AUTHENTICATE] =
-               g_signal_new ("authenticate",
+       signals[REQUEST_QUEUED] =
+               g_signal_new ("request-queued",
                              G_OBJECT_CLASS_TYPE (object_class),
                              G_SIGNAL_RUN_FIRST,
-                             G_STRUCT_OFFSET (SoupSessionClass, authenticate),
+                             0, /* FIXME? */
+                             NULL, NULL,
+                             soup_marshal_NONE__OBJECT,
+                             G_TYPE_NONE, 1,
+                             SOUP_TYPE_MESSAGE);
+
+       /**
+        * SoupSession::request-started:
+        * @session: the session
+        * @msg: the request being sent
+        * @socket: the socket the request is being sent on
+        *
+        * Emitted just before a request is sent. See
+        * #SoupSession::request_queued for a detailed description of
+        * the message lifecycle within a session.
+        **/
+       signals[REQUEST_STARTED] =
+               g_signal_new ("request-started",
+                             G_OBJECT_CLASS_TYPE (object_class),
+                             G_SIGNAL_RUN_FIRST,
+                             G_STRUCT_OFFSET (SoupSessionClass, request_started),
                              NULL, NULL,
-                             soup_marshal_NONE__OBJECT_STRING_STRING_POINTER_POINTER,
-                             G_TYPE_NONE, 5,
+                             soup_marshal_NONE__OBJECT_OBJECT,
+                             G_TYPE_NONE, 2,
                              SOUP_TYPE_MESSAGE,
-                             G_TYPE_STRING,
-                             G_TYPE_STRING,
-                             G_TYPE_POINTER,
-                             G_TYPE_POINTER);
+                             SOUP_TYPE_SOCKET);
 
        /**
-        * SoupSession::reauthenticate:
+        * SoupSession::request-unqueued:
         * @session: the session
-        * @msg: the #SoupMessage being sent
-        * @auth_type: the authentication type
-        * @auth_realm: the realm being authenticated to
-        * @username: the signal handler should set this to point to
-        * the provided username
-        * @password: the signal handler should set this to point to
-        * the provided password
+        * @msg: the request that was unqueued
         *
-        * Emitted when the credentials provided by the application to
-        * the #authenticate signal have failed. This gives the
-        * application a second chance to provide authentication
-        * credentials. If the new credentials also fail, #SoupSession
-        * will emit #reauthenticate again, and will continue doing so
-        * until the provided credentials work, or a #reauthenticate
-        * signal emission "fails" (because the handler left @username
-        * and @password unchanged). At that point, the 401 or 407
-        * error status will be returned to the caller.
+        * Emitted when a request is removed from @session's queue,
+        * indicating that @session is done with it. See
+        * #SoupSession::request_queued for a detailed description of the
+        * message lifecycle within a session.
+        **/
+       signals[REQUEST_UNQUEUED] =
+               g_signal_new ("request-unqueued",
+                             G_OBJECT_CLASS_TYPE (object_class),
+                             G_SIGNAL_RUN_FIRST,
+                             0, /* FIXME? */
+                             NULL, NULL,
+                             soup_marshal_NONE__OBJECT,
+                             G_TYPE_NONE, 1,
+                             SOUP_TYPE_MESSAGE);
+
+       /**
+        * SoupSession::authenticate:
+        * @session: the session
+        * @msg: the #SoupMessage being sent
+        * @auth: the #SoupAuth to authenticate
+        * @retrying: %TRUE if this is the second (or later) attempt
         *
-        * If your application only uses cached passwords, it should
-        * only connect to #authenticate, and not #reauthenticate.
+        * Emitted when the session requires authentication. If
+        * credentials are available call soup_auth_authenticate() on
+        * @auth. If these credentials fail, the signal will be
+        * emitted again, with @retrying set to %TRUE, which will
+        * continue until you return without calling
+        * soup_auth_authenticate() on @auth.
         *
-        * If your application always prompts the user for a password,
-        * and never uses cached information, then you can connect the
-        * same handler to #authenticate and #reauthenticate.
+        * Note that this may be emitted before @msg's body has been
+        * fully read.
         *
-        * To get standard web-browser behavior, return either cached
-        * information or a user-provided password (whichever is
-        * available) from the #authenticate handler, but return only
-        * user-provided information from the #reauthenticate handler.
+        * If you call soup_session_pause_message() on @msg before
+        * returning, then you can authenticate @auth asynchronously
+        * (as long as you g_object_ref() it to make sure it doesn't
+        * get destroyed), and then unpause @msg when you are ready
+        * for it to continue.
         **/
-       signals[REAUTHENTICATE] =
-               g_signal_new ("reauthenticate",
+       signals[AUTHENTICATE] =
+               g_signal_new ("authenticate",
                              G_OBJECT_CLASS_TYPE (object_class),
                              G_SIGNAL_RUN_FIRST,
-                             G_STRUCT_OFFSET (SoupSessionClass, reauthenticate),
+                             G_STRUCT_OFFSET (SoupSessionClass, authenticate),
                              NULL, NULL,
-                             soup_marshal_NONE__OBJECT_STRING_STRING_POINTER_POINTER,
-                             G_TYPE_NONE, 5,
+                             soup_marshal_NONE__OBJECT_OBJECT_BOOLEAN,
+                             G_TYPE_NONE, 3,
                              SOUP_TYPE_MESSAGE,
-                             G_TYPE_STRING,
-                             G_TYPE_STRING,
-                             G_TYPE_POINTER,
-                             G_TYPE_POINTER);
+                             SOUP_TYPE_AUTH,
+                             G_TYPE_BOOLEAN);
 
        /* properties */
        g_object_class_install_property (
                object_class, PROP_PROXY_URI,
-               g_param_spec_pointer (SOUP_SESSION_PROXY_URI,
-                                     "Proxy URI",
-                                     "The HTTP Proxy to use for this session",
-                                     G_PARAM_READWRITE));
+               g_param_spec_boxed (SOUP_SESSION_PROXY_URI,
+                                   "Proxy URI",
+                                   "The HTTP Proxy to use for this session",
+                                   SOUP_TYPE_URI,
+                                   G_PARAM_READWRITE));
        g_object_class_install_property (
                object_class, PROP_MAX_CONNS,
                g_param_spec_int (SOUP_SESSION_MAX_CONNS,
@@ -306,7 +401,7 @@ soup_session_class_init (SoupSessionClass *session_class)
                                  "The maximum number of connections that the session can open at once",
                                  1,
                                  G_MAXINT,
-                                 10,
+                                 SOUP_SESSION_MAX_CONNS_DEFAULT,
                                  G_PARAM_READWRITE));
        g_object_class_install_property (
                object_class, PROP_MAX_CONNS_PER_HOST,
@@ -315,9 +410,16 @@ soup_session_class_init (SoupSessionClass *session_class)
                                  "The maximum number of connections that the session can open at once to a given host",
                                  1,
                                  G_MAXINT,
-                                 4,
+                                 SOUP_SESSION_MAX_CONNS_PER_HOST_DEFAULT,
                                  G_PARAM_READWRITE));
        g_object_class_install_property (
+               object_class, PROP_IDLE_TIMEOUT,
+               g_param_spec_uint (SOUP_SESSION_IDLE_TIMEOUT,
+                                  "Idle Timeout",
+                                  "Connection lifetime when idle",
+                                  0, G_MAXUINT, 0,
+                                  G_PARAM_READWRITE));
+       g_object_class_install_property (
                object_class, PROP_USE_NTLM,
                g_param_spec_boolean (SOUP_SESSION_USE_NTLM,
                                      "Use NTLM",
@@ -344,18 +446,67 @@ soup_session_class_init (SoupSessionClass *session_class)
                                   "Value in seconds to timeout a blocking I/O",
                                   0, G_MAXUINT, 0,
                                   G_PARAM_READWRITE));
-}
 
-static void
-filter_iface_init (SoupMessageFilterClass *filter_class)
-{
-       /* interface implementation */
-       filter_class->setup_message = setup_message;
-}
+       /**
+        * SoupSession:user-agent:
+        *
+        * If non-%NULL, the value to use for the "User-Agent" header
+        * on #SoupMessage<!-- -->s sent from this session.
+        *
+        * RFC 2616 says: "The User-Agent request-header field
+        * contains information about the user agent originating the
+        * request. This is for statistical purposes, the tracing of
+        * protocol violations, and automated recognition of user
+        * agents for the sake of tailoring responses to avoid
+        * particular user agent limitations. User agents SHOULD
+        * include this field with requests."
+        *
+        * The User-Agent header contains a list of one or more
+        * product tokens, separated by whitespace, with the most
+        * significant product token coming first. The tokens must be
+        * brief, ASCII, and mostly alphanumeric (although "-", "_",
+        * and "." are also allowed), and may optionally include a "/"
+        * followed by a version string. You may also put comments,
+        * enclosed in parentheses, between or after the tokens.
+        *
+        * If you set a %user_agent property that has trailing
+        * whitespace, #SoupSession will append its own product token
+        * (eg, "<literal>libsoup/2.3.2</literal>") to the end of the
+        * header for you.
+        **/
+       g_object_class_install_property (
+               object_class, PROP_USER_AGENT,
+               g_param_spec_string (SOUP_SESSION_USER_AGENT,
+                                    "User-Agent string",
+                                    "User-Agent string",
+                                    NULL,
+                                    G_PARAM_READWRITE));
 
+       g_object_class_install_property (
+               object_class, PROP_ADD_FEATURE,
+               g_param_spec_object (SOUP_SESSION_ADD_FEATURE,
+                                    "Add Feature",
+                                    "Add a feature object to the session",
+                                    SOUP_TYPE_SESSION_FEATURE,
+                                    G_PARAM_READWRITE));
+       g_object_class_install_property (
+               object_class, PROP_ADD_FEATURE_BY_TYPE,
+               g_param_spec_gtype (SOUP_SESSION_ADD_FEATURE_BY_TYPE,
+                                   "Add Feature By Type",
+                                   "Add a feature object of the given type to the session",
+                                   SOUP_TYPE_SESSION_FEATURE,
+                                   G_PARAM_READWRITE));
+       g_object_class_install_property (
+               object_class, PROP_REMOVE_FEATURE_BY_TYPE,
+               g_param_spec_gtype (SOUP_SESSION_REMOVE_FEATURE_BY_TYPE,
+                                   "Remove Feature By Type",
+                                   "Remove features of the given type from the session",
+                                   SOUP_TYPE_SESSION_FEATURE,
+                                   G_PARAM_READWRITE));
+}
 
 static gboolean
-safe_uri_equal (const SoupUri *a, const SoupUri *b)
+safe_uri_equal (SoupURI *a, SoupURI *b)
 {
        if (!a && !b)
                return TRUE;
@@ -384,22 +535,27 @@ set_property (GObject *object, guint prop_id,
 {
        SoupSession *session = SOUP_SESSION (object);
        SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
-       gpointer pval;
+       SoupURI *uri;
        gboolean need_abort = FALSE;
        gboolean ca_file_changed = FALSE;
-       const char *new_ca_file;
+       const char *new_ca_file, *user_agent;
 
        switch (prop_id) {
        case PROP_PROXY_URI:
-               pval = g_value_get_pointer (value);
+               uri = g_value_get_boxed (value);
 
-               if (!safe_uri_equal (priv->proxy_uri, pval))
+               if (!safe_uri_equal (priv->proxy_uri, uri))
                        need_abort = TRUE;
 
                if (priv->proxy_uri)
                        soup_uri_free (priv->proxy_uri);
+               if (priv->proxy_addr)
+                       g_object_unref (priv->proxy_addr);
 
-               priv->proxy_uri = pval ? soup_uri_copy (pval) : NULL;
+               priv->proxy_uri = uri ? soup_uri_copy (uri) : NULL;
+               priv->proxy_addr = uri ?
+                       soup_address_new (uri->host, uri->port) :
+                       NULL;
 
                if (need_abort) {
                        soup_session_abort (session);
@@ -414,7 +570,9 @@ set_property (GObject *object, guint prop_id,
                priv->max_conns_per_host = g_value_get_int (value);
                break;
        case PROP_USE_NTLM:
-               priv->use_ntlm = g_value_get_boolean (value);
+               g_object_set_property (G_OBJECT (priv->auth_manager),
+                                      SOUP_AUTH_MANAGER_NTLM_USE_NTLM,
+                                      value);
                break;
        case PROP_SSL_CA_FILE:
                new_ca_file = g_value_get_string (value);
@@ -441,9 +599,37 @@ set_property (GObject *object, guint prop_id,
                        g_main_context_ref (priv->async_context);
                break;
        case PROP_TIMEOUT:
-               priv->timeout = g_value_get_uint (value);
+               priv->io_timeout = g_value_get_uint (value);
+               break;
+       case PROP_USER_AGENT:
+               g_free (priv->user_agent);
+               user_agent = g_value_get_string (value);
+               if (!user_agent)
+                       priv->user_agent = NULL;
+               else if (!*user_agent) {
+                       priv->user_agent =
+                               g_strdup (SOUP_SESSION_USER_AGENT_BASE);
+               } else if (g_str_has_suffix (user_agent, " ")) {
+                       priv->user_agent =
+                               g_strdup_printf ("%s%s", user_agent,
+                                                SOUP_SESSION_USER_AGENT_BASE);
+               } else
+                       priv->user_agent = g_strdup (user_agent);
+               break;
+       case PROP_IDLE_TIMEOUT:
+               priv->idle_timeout = g_value_get_uint (value);
+               break;
+       case PROP_ADD_FEATURE:
+               soup_session_add_feature (session, g_value_get_object (value));
+               break;
+       case PROP_ADD_FEATURE_BY_TYPE:
+               soup_session_add_feature_by_type (session, g_value_get_gtype (value));
+               break;
+       case PROP_REMOVE_FEATURE_BY_TYPE:
+               soup_session_remove_feature_by_type (session, g_value_get_gtype (value));
                break;
        default:
+               G_OBJECT_WARN_INVALID_PROPERTY_ID (object, prop_id, pspec);
                break;
        }
 }
@@ -457,9 +643,7 @@ get_property (GObject *object, guint prop_id,
 
        switch (prop_id) {
        case PROP_PROXY_URI:
-               g_value_set_pointer (value, priv->proxy_uri ?
-                                    soup_uri_copy (priv->proxy_uri) :
-                                    NULL);
+               g_value_set_boxed (value, priv->proxy_uri);
                break;
        case PROP_MAX_CONNS:
                g_value_set_int (value, priv->max_conns);
@@ -468,7 +652,9 @@ get_property (GObject *object, guint prop_id,
                g_value_set_int (value, priv->max_conns_per_host);
                break;
        case PROP_USE_NTLM:
-               g_value_set_boolean (value, priv->use_ntlm);
+               g_object_get_property (G_OBJECT (priv->auth_manager),
+                                      SOUP_AUTH_MANAGER_NTLM_USE_NTLM,
+                                      value);
                break;
        case PROP_SSL_CA_FILE:
                g_value_set_string (value, priv->ssl_ca_file);
@@ -477,94 +663,51 @@ get_property (GObject *object, guint prop_id,
                g_value_set_pointer (value, priv->async_context ? g_main_context_ref (priv->async_context) : NULL);
                break;
        case PROP_TIMEOUT:
-               g_value_set_uint (value, priv->timeout);
+               g_value_set_uint (value, priv->io_timeout);
+               break;
+       case PROP_USER_AGENT:
+               g_value_set_string (value, priv->user_agent);
+               break;
+       case PROP_IDLE_TIMEOUT:
+               g_value_set_uint (value, priv->idle_timeout);
                break;
        default:
+               G_OBJECT_WARN_INVALID_PROPERTY_ID (object, prop_id, pspec);
                break;
        }
 }
 
 
 /**
- * soup_session_add_filter:
+ * soup_session_get_async_context:
  * @session: a #SoupSession
- * @filter: an object implementing the #SoupMessageFilter interface
  *
- * Adds @filter to @session's list of message filters to be applied to
- * all messages.
- **/
-void
-soup_session_add_filter (SoupSession *session, SoupMessageFilter *filter)
-{
-       SoupSessionPrivate *priv;
-
-       g_return_if_fail (SOUP_IS_SESSION (session));
-       g_return_if_fail (SOUP_IS_MESSAGE_FILTER (filter));
-       priv = SOUP_SESSION_GET_PRIVATE (session);
-
-       g_object_ref (filter);
-       priv->filters = g_slist_prepend (priv->filters, filter);
-}
-
-/**
- * soup_session_remove_filter:
- * @session: a #SoupSession
- * @filter: an object implementing the #SoupMessageFilter interface
+ * Gets @session's async_context. This does not add a ref to the
+ * context, so you will need to ref it yourself if you want it to
+ * outlive its session.
  *
- * Removes @filter from @session's list of message filters
+ * Return value: @session's #GMainContext, which may be %NULL
  **/
-void
-soup_session_remove_filter (SoupSession *session, SoupMessageFilter *filter)
+GMainContext *
+soup_session_get_async_context (SoupSession *session)
 {
        SoupSessionPrivate *priv;
 
-       g_return_if_fail (SOUP_IS_SESSION (session));
-       g_return_if_fail (SOUP_IS_MESSAGE_FILTER (filter));
+       g_return_val_if_fail (SOUP_IS_SESSION (session), NULL);
        priv = SOUP_SESSION_GET_PRIVATE (session);
 
-       priv->filters = g_slist_remove (priv->filters, filter);
-       g_object_unref (filter);
+       return priv->async_context;
 }
 
-
 /* Hosts */
-static guint
-host_uri_hash (gconstpointer key)
-{
-       const SoupUri *uri = key;
-
-       return (uri->protocol << 16) + uri->port + g_str_hash (uri->host);
-}
-
-static gboolean
-host_uri_equal (gconstpointer v1, gconstpointer v2)
-{
-       const SoupUri *one = v1;
-       const SoupUri *two = v2;
-
-       if (one->protocol != two->protocol)
-               return FALSE;
-       if (one->port != two->port)
-               return FALSE;
-
-       return strcmp (one->host, two->host) == 0;
-}
 
 static SoupSessionHost *
-soup_session_host_new (SoupSession *session, const SoupUri *source_uri)
+soup_session_host_new (SoupSession *session, SoupAddress *addr)
 {
-       SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
        SoupSessionHost *host;
 
-       host = g_new0 (SoupSessionHost, 1);
-       host->root_uri = soup_uri_copy_root (source_uri);
-
-       if (host->root_uri->protocol == SOUP_PROTOCOL_HTTPS &&
-           !priv->ssl_creds) {
-               priv->ssl_creds =
-                       soup_ssl_get_client_credentials (priv->ssl_ca_file);
-       }
-
+       host = g_slice_new0 (SoupSessionHost);
+       host->addr = g_object_ref (addr);
        return host;
 }
 
@@ -577,48 +720,18 @@ get_host_for_message (SoupSession *session, SoupMessage *msg)
 {
        SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
        SoupSessionHost *host;
-       const SoupUri *source = soup_message_get_uri (msg);
+       SoupAddress *addr = soup_message_get_address (msg);
 
-       host = g_hash_table_lookup (priv->hosts, source);
+       host = g_hash_table_lookup (priv->hosts, addr);
        if (host)
                return host;
 
-       host = soup_session_host_new (session, source);
-       g_hash_table_insert (priv->hosts, host->root_uri, host);
+       host = soup_session_host_new (session, addr);
+       g_hash_table_insert (priv->hosts, host->addr, host);
 
        return host;
 }
 
-/* Note: get_proxy_host doesn't lock the host_lock. The caller must do
- * it itself if there's a chance the host doesn't already exist.
- */
-static SoupSessionHost *
-get_proxy_host (SoupSession *session)
-{
-       SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
-
-       if (priv->proxy_host || !priv->proxy_uri)
-               return priv->proxy_host;
-
-       priv->proxy_host =
-               soup_session_host_new (session, priv->proxy_uri);
-       return priv->proxy_host;
-}
-
-static void
-free_realm (gpointer path, gpointer scheme_realm, gpointer data)
-{
-       g_free (path);
-       g_free (scheme_realm);
-}
-
-static void
-free_auth (gpointer scheme_realm, gpointer auth, gpointer data)
-{
-       g_free (scheme_realm);
-       g_object_unref (auth);
-}
-
 static void
 free_host (SoupSessionHost *host)
 {
@@ -629,273 +742,70 @@ free_host (SoupSessionHost *host)
                soup_connection_disconnect (conn);
        }
 
-       if (host->auth_realms) {
-               g_hash_table_foreach (host->auth_realms, free_realm, NULL);
-               g_hash_table_destroy (host->auth_realms);
-       }
-       if (host->auths) {
-               g_hash_table_foreach (host->auths, free_auth, NULL);
-               g_hash_table_destroy (host->auths);
-       }
-
-       soup_uri_free (host->root_uri);
-       g_free (host);
+       g_object_unref (host->addr);
+       g_slice_free (SoupSessionHost, host);
 }      
 
-/* Authentication */
-
-static SoupAuth *
-lookup_auth (SoupSession *session, SoupMessage *msg, gboolean proxy)
-{
-       SoupSessionHost *host;
-       char *path, *dir;
-       const char *realm, *const_path;
-
-       if (proxy) {
-               host = get_proxy_host (session);
-               const_path = "/";
-       } else {
-               host = get_host_for_message (session, msg);
-               const_path = soup_message_get_uri (msg)->path;
-
-               if (!const_path)
-                       const_path = "/";
-       }
-       g_return_val_if_fail (host != NULL, NULL);
-
-       if (!host->auth_realms)
-               return NULL;
-
-       path = g_strdup (const_path);
-       dir = path;
-        do {
-                realm = g_hash_table_lookup (host->auth_realms, path);
-                if (realm)
-                       break;
-
-                dir = strrchr (path, '/');
-                if (dir) {
-                       if (dir[1])
-                               dir[1] = '\0';
-                       else
-                               *dir = '\0';
-               }
-        } while (dir);
-
-       g_free (path);
-       if (realm)
-               return g_hash_table_lookup (host->auths, realm);
-       else
-               return NULL;
-}
-
-static void
-invalidate_auth (SoupSessionHost *host, SoupAuth *auth)
-{
-       char *realm;
-       gpointer key, value;
-
-       realm = g_strdup_printf ("%s:%s",
-                                soup_auth_get_scheme_name (auth),
-                                soup_auth_get_realm (auth));
-
-       if (g_hash_table_lookup_extended (host->auths, realm, &key, &value) &&
-           auth == (SoupAuth *)value) {
-               g_hash_table_remove (host->auths, realm);
-               g_free (key);
-               g_object_unref (auth);
-       }
-       g_free (realm);
-}
-
-static gboolean
-authenticate_auth (SoupSession *session, SoupAuth *auth,
-                  SoupMessage *msg, gboolean prior_auth_failed,
-                  gboolean proxy)
-{
-       SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
-       const SoupUri *uri;
-       char *username = NULL, *password = NULL;
-
-       if (proxy)
-               uri = priv->proxy_uri;
-       else
-               uri = soup_message_get_uri (msg);
-
-       if (uri->passwd && !prior_auth_failed) {
-               soup_auth_authenticate (auth, uri->user, uri->passwd);
-               return TRUE;
-       }
-
-       g_signal_emit (session, signals[prior_auth_failed ? REAUTHENTICATE : AUTHENTICATE], 0,
-                      msg, soup_auth_get_scheme_name (auth),
-                      soup_auth_get_realm (auth),
-                      &username, &password);
-       if (username || password)
-               soup_auth_authenticate (auth, username, password);
-       if (username)
-               g_free (username);
-       if (password) {
-               memset (password, 0, strlen (password));
-               g_free (password);
-       }
-
-       return soup_auth_is_authenticated (auth);
-}
-
-static gboolean
-update_auth_internal (SoupSession *session, SoupMessage *msg,
-                     const GSList *headers, gboolean proxy)
-{
-       SoupSessionHost *host;
-       SoupAuth *new_auth, *prior_auth, *old_auth;
-       gpointer old_path, old_realm;
-       const SoupUri *msg_uri;
-       const char *path;
-       char *realm;
-       GSList *pspace, *p;
-       gboolean prior_auth_failed = FALSE;
-
-       if (proxy)
-               host = get_proxy_host (session);
-       else
-               host = get_host_for_message (session, msg);
-
-       g_return_val_if_fail (host != NULL, FALSE);
-
-       /* Try to construct a new auth from the headers; if we can't,
-        * there's no way we'll be able to authenticate.
-        */
-       msg_uri = soup_message_get_uri (msg);
-       new_auth = soup_auth_new_from_header_list (headers);
-       if (!new_auth)
-               return FALSE;
-
-       /* See if this auth is the same auth we used last time */
-       prior_auth = proxy ? soup_message_get_proxy_auth (msg) : soup_message_get_auth (msg);
-       if (prior_auth &&
-           G_OBJECT_TYPE (prior_auth) == G_OBJECT_TYPE (new_auth) &&
-           !strcmp (soup_auth_get_realm (prior_auth),
-                    soup_auth_get_realm (new_auth))) {
-               /* The server didn't like the username/password we
-                * provided before. Invalidate it and note this fact.
-                */
-               invalidate_auth (host, prior_auth);
-               prior_auth_failed = TRUE;
-       }
-
-       if (!host->auth_realms) {
-               host->auth_realms = g_hash_table_new (g_str_hash, g_str_equal);
-               host->auths = g_hash_table_new (g_str_hash, g_str_equal);
-       }
-
-       /* Record where this auth realm is used */
-       realm = g_strdup_printf ("%s:%s",
-                                soup_auth_get_scheme_name (new_auth),
-                                soup_auth_get_realm (new_auth));
-
-       /* 
-        * RFC 2617 is somewhat unclear about the scope of protection
-        * spaces with regard to proxies.  The only mention of it is
-        * as an aside in section 3.2.1, where it is defining the fields
-        * of a Digest challenge and says that the protection space is
-        * always the entire proxy.  Is this the case for all authentication
-        * schemes or just Digest?  Who knows, but we're assuming all.
-        */
-       if (proxy)
-               pspace = g_slist_prepend (NULL, g_strdup (""));
-       else
-               pspace = soup_auth_get_protection_space (new_auth, msg_uri);
-
-       for (p = pspace; p; p = p->next) {
-               path = p->data;
-               if (g_hash_table_lookup_extended (host->auth_realms, path,
-                                                 &old_path, &old_realm)) {
-                       g_hash_table_remove (host->auth_realms, old_path);
-                       g_free (old_path);
-                       g_free (old_realm);
-               }
-
-               g_hash_table_insert (host->auth_realms,
-                                    g_strdup (path), g_strdup (realm));
-       }
-       soup_auth_free_protection_space (new_auth, pspace);
-
-       /* Now, make sure the auth is recorded. (If there's a
-        * pre-existing auth, we keep that rather than the new one,
-        * since the old one might already be authenticated.)
-        */
-       old_auth = g_hash_table_lookup (host->auths, realm);
-       if (old_auth) {
-               g_free (realm);
-               g_object_unref (new_auth);
-               new_auth = old_auth;
-       } else 
-               g_hash_table_insert (host->auths, realm, new_auth);
-
-       /* If we need to authenticate, try to do it. */
-       if (!soup_auth_is_authenticated (new_auth)) {
-               return authenticate_auth (session, new_auth,
-                                         msg, prior_auth_failed, proxy);
-       }
-
-       /* Otherwise we're good. */
-       return TRUE;
-}
-
 static void
-connection_authenticate (SoupConnection *conn, SoupMessage *msg,
-                        const char *auth_type, const char *auth_realm,
-                        char **username, char **password, gpointer session)
+auth_manager_authenticate (SoupAuthManager *manager, SoupMessage *msg,
+                          SoupAuth *auth, gboolean retrying,
+                          gpointer session)
 {
-       g_signal_emit (session, signals[AUTHENTICATE], 0,
-                      msg, auth_type, auth_realm, username, password);
+       g_signal_emit (session, signals[AUTHENTICATE], 0, msg, auth, retrying);
 }
 
-static void
-connection_reauthenticate (SoupConnection *conn, SoupMessage *msg,
-                          const char *auth_type, const char *auth_realm,
-                          char **username, char **password,
-                          gpointer user_data)
-{
-       g_signal_emit (conn, signals[REAUTHENTICATE], 0,
-                      msg, auth_type, auth_realm, username, password);
-}
-
-
-static void
-authorize_handler (SoupMessage *msg, gpointer user_data)
-{
-       SoupSession *session = user_data;
-       const GSList *headers;
-       gboolean proxy;
-
-       if (msg->status_code == SOUP_STATUS_PROXY_AUTHENTICATION_REQUIRED) {
-               headers = soup_message_get_header_list (msg->response_headers,
-                                                       "Proxy-Authenticate");
-               proxy = TRUE;
-       } else {
-               headers = soup_message_get_header_list (msg->response_headers,
-                                                       "WWW-Authenticate");
-               proxy = FALSE;
-       }
-       if (!headers)
-               return;
-
-       if (update_auth_internal (session, msg, headers, proxy))
-               soup_session_requeue_message (session, msg);
-}
+#define SOUP_METHOD_IS_SAFE(method) (method == SOUP_METHOD_GET || \
+                                    method == SOUP_METHOD_HEAD || \
+                                    method == SOUP_METHOD_OPTIONS || \
+                                    method == SOUP_METHOD_PROPFIND)
 
 static void
 redirect_handler (SoupMessage *msg, gpointer user_data)
 {
        SoupSession *session = user_data;
        const char *new_loc;
-       SoupUri *new_uri;
-
-       new_loc = soup_message_get_header (msg->response_headers, "Location");
-       if (!new_loc)
+       SoupURI *new_uri;
+
+       new_loc = soup_message_headers_get (msg->response_headers, "Location");
+       g_return_if_fail (new_loc != NULL);
+
+       if (msg->status_code == SOUP_STATUS_SEE_OTHER ||
+           (msg->status_code == SOUP_STATUS_FOUND &&
+            !SOUP_METHOD_IS_SAFE (msg->method))) {
+               /* Redirect using a GET */
+               g_object_set (msg,
+                             SOUP_MESSAGE_METHOD, SOUP_METHOD_GET,
+                             NULL);
+               soup_message_set_request (msg, NULL,
+                                         SOUP_MEMORY_STATIC, NULL, 0);
+               soup_message_headers_set_encoding (msg->request_headers,
+                                                  SOUP_ENCODING_NONE);
+       } else if (msg->status_code == SOUP_STATUS_MOVED_PERMANENTLY ||
+                  msg->status_code == SOUP_STATUS_TEMPORARY_REDIRECT ||
+                  msg->status_code == SOUP_STATUS_FOUND) {
+               /* Don't redirect non-safe methods */
+               if (!SOUP_METHOD_IS_SAFE (msg->method))
+                       return;
+       } else {
+               /* Three possibilities:
+                *
+                *   1) This was a non-3xx response that happened to
+                *      have a "Location" header
+                *   2) It's a non-redirecty 3xx response (300, 304,
+                *      305, 306)
+                *   3) It's some newly-defined 3xx response (308+)
+                *
+                * We ignore all of these cases. In the first two,
+                * redirecting would be explicitly wrong, and in the
+                * last case, we have no clue if the 3xx response is
+                * supposed to be redirecty or non-redirecty. Plus,
+                * 2616 says unrecognized status codes should be
+                * treated as the equivalent to the x00 code, and we
+                * don't redirect on 300, so therefore we shouldn't
+                * redirect on 308+ either.
+                */
                return;
+       }
 
        /* Location is supposed to be an absolute URI, but some sites
         * are lame, so we use soup_uri_new_with_base().
@@ -915,98 +825,62 @@ redirect_handler (SoupMessage *msg, gpointer user_data)
 }
 
 static void
-add_auth (SoupSession *session, SoupMessage *msg, gboolean proxy)
-{
-       SoupAuth *auth;
-
-       auth = lookup_auth (session, msg, proxy);
-       if (auth && !soup_auth_is_authenticated (auth)) {
-               if (!authenticate_auth (session, auth, msg, FALSE, proxy))
-                       auth = NULL;
-       }
-
-       if (proxy)
-               soup_message_set_proxy_auth (msg, auth);
-       else
-               soup_message_set_auth (msg, auth);
-}
-
-static void
-setup_message (SoupMessageFilter *filter, SoupMessage *msg)
+connection_started_request (SoupConnection *conn, SoupMessage *msg,
+                           gpointer data)
 {
-       SoupSession *session = SOUP_SESSION (filter);
+       SoupSession *session = data;
        SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
-       GSList *f;
 
-       for (f = priv->filters; f; f = f->next) {
-               filter = f->data;
-               soup_message_filter_setup_message (filter, msg);
+       if (priv->user_agent) {
+               soup_message_headers_replace (msg->request_headers,
+                                             "User-Agent", priv->user_agent);
        }
 
-       add_auth (session, msg, FALSE);
-       soup_message_add_status_code_handler (
-               msg, SOUP_STATUS_UNAUTHORIZED,
-               SOUP_HANDLER_POST_BODY,
-               authorize_handler, session);
-
-       if (priv->proxy_uri) {
-               add_auth (session, msg, TRUE);
-               soup_message_add_status_code_handler  (
-                       msg, SOUP_STATUS_PROXY_UNAUTHORIZED,
-                       SOUP_HANDLER_POST_BODY,
-                       authorize_handler, session);
-       }
-}
-
-static void
-find_oldest_connection (gpointer key, gpointer host, gpointer data)
-{
-       SoupConnection *conn = key, **oldest = data;
-
-       /* Don't prune a connection that is currently in use, or
-        * hasn't been used yet.
+       /* Kludge to deal with the fact that CONNECT msgs come from the
+        * SoupConnection rather than being queued normally.
         */
-       if (soup_connection_is_in_use (conn) ||
-           soup_connection_last_used (conn) == 0)
-               return;
+       if (msg->method == SOUP_METHOD_CONNECT)
+               g_signal_emit (session, signals[REQUEST_QUEUED], 0, msg);
 
-       if (!*oldest || (soup_connection_last_used (conn) <
-                        soup_connection_last_used (*oldest)))
-               *oldest = conn;
+       g_signal_emit (session, signals[REQUEST_STARTED], 0,
+                      msg, soup_connection_get_socket (conn));
 }
 
-/**
- * soup_session_try_prune_connection:
- * @session: a #SoupSession
- *
- * Finds the least-recently-used idle connection in @session and closes
- * it.
- *
- * Return value: %TRUE if a connection was closed, %FALSE if there are
- * no idle connections.
- **/
 gboolean
 soup_session_try_prune_connection (SoupSession *session)
 {
        SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
-       SoupConnection *oldest = NULL;
+       GPtrArray *conns;
+       GHashTableIter iter;
+       gpointer conn, host;
+       int i;
+
+       conns = g_ptr_array_new ();
 
        g_mutex_lock (priv->host_lock);
-       g_hash_table_foreach (priv->conns, find_oldest_connection,
-                             &oldest);
-       if (oldest) {
-               /* Ref the connection before unlocking the mutex in
-                * case someone else tries to prune it too.
+       g_hash_table_iter_init (&iter, priv->conns);
+       while (g_hash_table_iter_next (&iter, &conn, &host)) {
+               /* Don't prune a connection that is currently in use,
+                * or hasn't been used yet.
                 */
-               g_object_ref (oldest);
-               g_mutex_unlock (priv->host_lock);
-               soup_connection_disconnect (oldest);
-               g_object_unref (oldest);
-               return TRUE;
-       } else {
-               g_mutex_unlock (priv->host_lock);
+               if (!soup_connection_is_in_use (conn) &&
+                   soup_connection_last_used (conn) > 0)
+                       g_ptr_array_add (conns, g_object_ref (conn));
+       }
+       g_mutex_unlock (priv->host_lock);
+
+       if (!conns->len) {
+               g_ptr_array_free (conns, TRUE);
                return FALSE;
        }
+
+       for (i = 0; i < conns->len; i++) {
+               soup_connection_disconnect (conns->pdata[i]);
+               g_object_unref (conns->pdata[i]);
+       }
+       g_ptr_array_free (conns, TRUE);
+
+       return TRUE;
 }
 
 static void
@@ -1038,7 +912,7 @@ connect_result (SoupConnection *conn, guint status, gpointer user_data)
        SoupSession *session = user_data;
        SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
        SoupSessionHost *host;
-       SoupMessageQueueIter iter;
+       SoupMessageQueueItem *item;
        SoupMessage *msg;
 
        g_mutex_lock (priv->host_lock);
@@ -1078,17 +952,20 @@ connect_result (SoupConnection *conn, guint status, gpointer user_data)
         * any messages waiting for this host, since they're out
         * of luck.
         */
-       for (msg = soup_message_queue_first (session->queue, &iter); msg; msg = soup_message_queue_next (session->queue, &iter)) {
+       g_object_ref (session);
+       for (item = soup_message_queue_first (priv->queue); item; item = soup_message_queue_next (priv->queue, item)) {
+               msg = item->msg;
                if (get_host_for_message (session, msg) == host) {
                        if (status == SOUP_STATUS_TRY_AGAIN) {
-                               if (msg->status == SOUP_MESSAGE_STATUS_CONNECTING)
-                                       msg->status = SOUP_MESSAGE_STATUS_QUEUED;
+                               if (soup_message_get_io_status (msg) == SOUP_MESSAGE_IO_STATUS_CONNECTING)
+                                       soup_message_set_io_status (msg, SOUP_MESSAGE_IO_STATUS_QUEUED);
                        } else {
-                               soup_message_set_status (msg, status);
-                               soup_session_cancel_message (session, msg);
+                               soup_session_cancel_message (session, msg,
+                                                            status);
                        }
                }
        }
+       g_object_unref (session);
 }
 
 /**
@@ -1136,7 +1013,9 @@ soup_session_get_connection (SoupSession *session, SoupMessage *msg,
        SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
        SoupConnection *conn;
        SoupSessionHost *host;
+       SoupSSLCredentials *ssl_creds;
        GSList *conns;
+       SoupURI *uri;
 
        g_mutex_lock (priv->host_lock);
 
@@ -1150,7 +1029,7 @@ soup_session_get_connection (SoupSession *session, SoupMessage *msg,
                }
        }
 
-       if (msg->status == SOUP_MESSAGE_STATUS_CONNECTING) {
+       if (soup_message_get_io_status (msg) == SOUP_MESSAGE_IO_STATUS_CONNECTING) {
                /* We already started a connection for this
                 * message, so don't start another one.
                 */
@@ -1169,21 +1048,21 @@ soup_session_get_connection (SoupSession *session, SoupMessage *msg,
                return NULL;
        }
 
-       /* Make sure priv->proxy_host gets set now while
-        * we have the host_lock.
-        */
-       if (priv->proxy_uri)
-               get_proxy_host (session);
-
-       conn = g_object_new (
-               (priv->use_ntlm ?
-                SOUP_TYPE_CONNECTION_NTLM : SOUP_TYPE_CONNECTION),
-               SOUP_CONNECTION_ORIGIN_URI, host->root_uri,
-               SOUP_CONNECTION_PROXY_URI, priv->proxy_uri,
-               SOUP_CONNECTION_SSL_CREDENTIALS, priv->ssl_creds,
-               SOUP_CONNECTION_MESSAGE_FILTER, session,
+       uri = soup_message_get_uri (msg);
+       if (uri->scheme == SOUP_URI_SCHEME_HTTPS) {
+               if (!priv->ssl_creds)
+                       priv->ssl_creds = soup_ssl_get_client_credentials (priv->ssl_ca_file);
+               ssl_creds = priv->ssl_creds;
+       } else
+               ssl_creds = NULL;
+
+       conn = soup_connection_new (
+               SOUP_CONNECTION_SERVER_ADDRESS, host->addr,
+               SOUP_CONNECTION_PROXY_ADDRESS, priv->proxy_addr,
+               SOUP_CONNECTION_SSL_CREDENTIALS, ssl_creds,
                SOUP_CONNECTION_ASYNC_CONTEXT, priv->async_context,
-               SOUP_CONNECTION_TIMEOUT, priv->timeout,
+               SOUP_CONNECTION_TIMEOUT, priv->io_timeout,
+               SOUP_CONNECTION_IDLE_TIMEOUT, priv->idle_timeout,
                NULL);
        g_signal_connect (conn, "connect_result",
                          G_CALLBACK (connect_result),
@@ -1191,11 +1070,8 @@ soup_session_get_connection (SoupSession *session, SoupMessage *msg,
        g_signal_connect (conn, "disconnected",
                          G_CALLBACK (connection_disconnected),
                          session);
-       g_signal_connect (conn, "authenticate",
-                         G_CALLBACK (connection_authenticate),
-                         session);
-       g_signal_connect (conn, "reauthenticate",
-                         G_CALLBACK (connection_reauthenticate),
+       g_signal_connect (conn, "request_started",
+                         G_CALLBACK (connection_started_request),
                          session);
 
        g_hash_table_insert (priv->conns, conn, host);
@@ -1210,47 +1086,74 @@ soup_session_get_connection (SoupSession *session, SoupMessage *msg,
        /* Mark the request as connecting, so we don't try to open
         * another new connection for it while waiting for this one.
         */
-       msg->status = SOUP_MESSAGE_STATUS_CONNECTING;
+       soup_message_set_io_status (msg, SOUP_MESSAGE_IO_STATUS_CONNECTING);
 
        g_mutex_unlock (priv->host_lock);
        *is_new = TRUE;
        return conn;
 }
 
+SoupMessageQueue *
+soup_session_get_queue (SoupSession *session)
+{
+       SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
+
+       return priv->queue;
+}
+
 static void
 message_finished (SoupMessage *msg, gpointer user_data)
 {
-       SoupSession *session = user_data;
+       SoupMessageQueueItem *item = user_data;
+       SoupSession *session = item->session;
+       SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
 
        if (!SOUP_MESSAGE_IS_STARTING (msg)) {
-               soup_message_queue_remove_message (session->queue, msg);
+               soup_message_queue_remove (priv->queue, item);
                g_signal_handlers_disconnect_by_func (msg, message_finished, session);
+               g_signal_handlers_disconnect_by_func (msg, redirect_handler, session);
+               g_signal_emit (session, signals[REQUEST_UNQUEUED], 0, msg);
+               soup_message_queue_item_unref (item);
        }
 }
 
 static void
 queue_message (SoupSession *session, SoupMessage *msg,
-              SoupMessageCallbackFn callback, gpointer user_data)
+              SoupSessionCallback callback, gpointer user_data)
 {
+       SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
+       SoupMessageQueueItem *item;
+
+       item = soup_message_queue_append (priv->queue, msg, callback, user_data);
+       soup_message_set_io_status (msg, SOUP_MESSAGE_IO_STATUS_QUEUED);
+
        g_signal_connect_after (msg, "finished",
-                               G_CALLBACK (message_finished), session);
+                               G_CALLBACK (message_finished), item);
 
        if (!(soup_message_get_flags (msg) & SOUP_MESSAGE_NO_REDIRECT)) {
-               soup_message_add_status_class_handler (
-                       msg, SOUP_STATUS_CLASS_REDIRECT,
-                       SOUP_HANDLER_POST_BODY,
-                       redirect_handler, session);
+               soup_message_add_header_handler (
+                       msg, "got_body", "Location",
+                       G_CALLBACK (redirect_handler), session);
        }
 
-       msg->status = SOUP_MESSAGE_STATUS_QUEUED;
-       soup_message_queue_append (session->queue, msg);
+       g_signal_emit (session, signals[REQUEST_QUEUED], 0, msg);
 }
 
 /**
+ * SoupSessionCallback:
+ * @session: the session
+ * @msg: the message that has finished
+ * @user_data: the data passed to soup_session_queue_message
+ *
+ * Prototype for the callback passed to soup_session_queue_message(),
+ * qv.
+ **/
+
+/**
  * soup_session_queue_message:
  * @session: a #SoupSession
  * @msg: the message to queue
- * @callback: a #SoupMessageCallbackFn which will be called after the
+ * @callback: a #SoupSessionCallback which will be called after the
  * message completes or when an unrecoverable error occurs.
  * @user_data: a pointer passed to @callback.
  * 
@@ -1265,7 +1168,7 @@ queue_message (SoupSession *session, SoupMessage *msg,
  */
 void
 soup_session_queue_message (SoupSession *session, SoupMessage *msg,
-                           SoupMessageCallbackFn callback, gpointer user_data)
+                           SoupSessionCallback callback, gpointer user_data)
 {
        g_return_if_fail (SOUP_IS_SESSION (session));
        g_return_if_fail (SOUP_IS_MESSAGE (msg));
@@ -1277,7 +1180,7 @@ soup_session_queue_message (SoupSession *session, SoupMessage *msg,
 static void
 requeue_message (SoupSession *session, SoupMessage *msg)
 {
-       msg->status = SOUP_MESSAGE_STATUS_QUEUED;
+       soup_message_set_io_status (msg, SOUP_MESSAGE_IO_STATUS_QUEUED);
 }
 
 /**
@@ -1321,10 +1224,63 @@ soup_session_send_message (SoupSession *session, SoupMessage *msg)
 }
 
 
+/**
+ * soup_session_pause_message:
+ * @session: a #SoupSession
+ * @msg: a #SoupMessage currently running on @session
+ *
+ * Pauses HTTP I/O on @msg. Call soup_session_unpause_message() to
+ * resume I/O.
+ **/
+void
+soup_session_pause_message (SoupSession *session,
+                           SoupMessage *msg)
+{
+       g_return_if_fail (SOUP_IS_SESSION (session));
+       g_return_if_fail (SOUP_IS_MESSAGE (msg));
+
+       soup_message_io_pause (msg);
+}
+
+/**
+ * soup_session_unpause_message:
+ * @session: a #SoupSession
+ * @msg: a #SoupMessage currently running on @session
+ *
+ * Resumes HTTP I/O on @msg. Use this to resume after calling
+ * soup_sessino_pause_message().
+ *
+ * If @msg is being sent via blocking I/O, this will resume reading or
+ * writing immediately. If @msg is using non-blocking I/O, then
+ * reading or writing won't resume until you return to the main loop.
+ **/
+void
+soup_session_unpause_message (SoupSession *session,
+                             SoupMessage *msg)
+{
+       g_return_if_fail (SOUP_IS_SESSION (session));
+       g_return_if_fail (SOUP_IS_MESSAGE (msg));
+
+       soup_message_io_unpause (msg);
+}
+
+
 static void
-cancel_message (SoupSession *session, SoupMessage *msg)
+cancel_message (SoupSession *session, SoupMessage *msg, guint status_code)
 {
-       soup_message_queue_remove_message (session->queue, msg);
+       SoupSessionPrivate *priv = SOUP_SESSION_GET_PRIVATE (session);
+       SoupMessageQueueItem *item;
+
+       item = soup_message_queue_lookup (priv->queue, msg);
+       if (item) {
+               soup_message_queue_remove (priv->queue, item);
+               if (item->cancellable)
+                       g_cancellable_cancel (item->cancellable);
+               soup_message_queue_item_unref (item);
+       }
+
+       soup_message_io_stop (msg);
+       soup_message_set_status (msg, status_code);
        soup_message_finished (msg);
 }
 
@@ -1332,18 +1288,30 @@ cancel_message (SoupSession *session, SoupMessage *msg)
  * soup_session_cancel_message:
  * @session: a #SoupSession
  * @msg: the message to cancel
+ * @status_code: status code to set on @msg (generally
+ * %SOUP_STATUS_CANCELLED)
  *
- * Causes @session to immediately finish processing @msg. You should
- * set a status code on @msg with soup_message_set_status() before
- * calling this function.
+ * Causes @session to immediately finish processing @msg, with a final
+ * status_code of @status_code. Depending on when you cancel it, the
+ * response state may be incomplete or inconsistent.
  **/
 void
-soup_session_cancel_message (SoupSession *session, SoupMessage *msg)
+soup_session_cancel_message (SoupSession *session, SoupMessage *msg,
+                            guint status_code)
 {
        g_return_if_fail (SOUP_IS_SESSION (session));
        g_return_if_fail (SOUP_IS_MESSAGE (msg));
 
-       SOUP_SESSION_GET_CLASS (session)->cancel_message (session, msg);
+       SOUP_SESSION_GET_CLASS (session)->cancel_message (session, msg, status_code);
+}
+
+static void
+gather_conns (gpointer key, gpointer host, gpointer data)
+{
+       SoupConnection *conn = key;
+       GSList **conns = data;
+
+       *conns = g_slist_prepend (*conns, g_object_ref (conn));
 }
 
 /**
@@ -1355,13 +1323,126 @@ soup_session_cancel_message (SoupSession *session, SoupMessage *msg)
 void
 soup_session_abort (SoupSession *session)
 {
-       SoupMessageQueueIter iter;
-       SoupMessage *msg;
+       SoupSessionPrivate *priv;
+       SoupMessageQueueItem *item;
+       GSList *conns, *c;
 
        g_return_if_fail (SOUP_IS_SESSION (session));
+       priv = SOUP_SESSION_GET_PRIVATE (session);
+
+       for (item = soup_message_queue_first (priv->queue);
+            item;
+            item = soup_message_queue_next (priv->queue, item)) {
+               soup_session_cancel_message (session, item->msg,
+                                            SOUP_STATUS_CANCELLED);
+       }
+
+       /* Close all connections */
+       g_mutex_lock (priv->host_lock);
+       conns = NULL;
+       g_hash_table_foreach (priv->conns, gather_conns, &conns);
+
+       g_mutex_unlock (priv->host_lock);
+       for (c = conns; c; c = c->next) {
+               soup_connection_disconnect (c->data);
+               g_object_unref (c->data);
+       }
+
+       g_slist_free (conns);
+}
+
+/**
+ * soup_session_add_feature:
+ * @session: a #SoupSession
+ * @feature: an object that implements #SoupSessionFeature
+ *
+ * Adds @feature's functionality to @session. You can also add a
+ * feature to the session at construct time by using the
+ * %SOUP_SESSION_ADD_FEATURE property.
+ **/
+void
+soup_session_add_feature (SoupSession *session, SoupSessionFeature *feature)
+{
+       SoupSessionPrivate *priv;
 
-       for (msg = soup_message_queue_first (session->queue, &iter); msg; msg = soup_message_queue_next (session->queue, &iter)) {
-               soup_message_set_status (msg, SOUP_STATUS_CANCELLED);
-               soup_session_cancel_message (session, msg);
+       g_return_if_fail (SOUP_IS_SESSION (session));
+       g_return_if_fail (SOUP_IS_SESSION_FEATURE (feature));
+
+       priv = SOUP_SESSION_GET_PRIVATE (session);
+       priv->features = g_slist_prepend (priv->features, g_object_ref (feature));
+       soup_session_feature_attach (feature, session);
+}
+
+/**
+ * soup_session_add_feature_by_type:
+ * @session: a #SoupSession
+ * @feature_type: the #GType of a class that implements #SoupSessionFeature
+ *
+ * Creates a new feature of type @feature_type and adds it to
+ * @session. You can use this instead of soup_session_add_feature() in
+ * the case wher you don't need to customize the new feature in any
+ * way. You can also add a feature to the session at construct time by
+ * using the %SOUP_SESSION_ADD_FEATURE_BY_TYPE property.
+ **/
+void
+soup_session_add_feature_by_type (SoupSession *session, GType feature_type)
+{
+       SoupSessionFeature *feature;
+
+       g_return_if_fail (SOUP_IS_SESSION (session));
+       g_return_if_fail (g_type_is_a (feature_type, SOUP_TYPE_SESSION_FEATURE));
+
+       feature = g_object_new (feature_type, NULL);
+       soup_session_add_feature (session, feature);
+       g_object_unref (feature);
+}
+
+/**
+ * soup_session_remove_feature:
+ * @session: a #SoupSession
+ * @feature: a feature that has previously been added to @session
+ *
+ * Removes @feature's functionality from @session.
+ **/
+void
+soup_session_remove_feature (SoupSession *session, SoupSessionFeature *feature)
+{
+       SoupSessionPrivate *priv;
+
+       g_return_if_fail (SOUP_IS_SESSION (session));
+
+       priv = SOUP_SESSION_GET_PRIVATE (session);
+       if (g_slist_find (priv->features, feature)) {
+               priv->features = g_slist_remove (priv->features, feature);
+               soup_session_feature_detach (feature, session);
+               g_object_unref (feature);
+       }
+}
+
+/**
+ * soup_session_remove_feature_by_type:
+ * @session: a #SoupSession
+ * @feature_type: the #GType of a class that implements #SoupSessionFeature
+ *
+ * Removes all features of type @feature_type (or any subclass of
+ * @feature_type) from @session. You can also remove standard features
+ * from the session at construct time by using the
+ * %SOUP_SESSION_REMOVE_FEATURE_BY_TYPE property.
+ **/
+void
+soup_session_remove_feature_by_type (SoupSession *session, GType feature_type)
+{
+       SoupSessionPrivate *priv;
+       GSList *f;
+
+       g_return_if_fail (SOUP_IS_SESSION (session));
+
+       priv = SOUP_SESSION_GET_PRIVATE (session);
+restart:
+       for (f = priv->features; f; f = f->next) {
+               if (G_TYPE_CHECK_INSTANCE_TYPE (f->data, feature_type)) {
+                       soup_session_remove_feature (session, f->data);
+                       goto restart;
+               }
        }
 }