Revert 223982 "Remove GetActiveEntry usage from content."
[chromium-blink-merge.git] / content / browser / ssl / ssl_manager.cc
blob42ee02fbb1cc90c4f22b3b9d46edc403cef9f245
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
5 #include "content/browser/ssl/ssl_manager.h"
7 #include <set>
9 #include "base/bind.h"
10 #include "base/strings/utf_string_conversions.h"
11 #include "base/supports_user_data.h"
12 #include "content/browser/loader/resource_dispatcher_host_impl.h"
13 #include "content/browser/loader/resource_request_info_impl.h"
14 #include "content/browser/ssl/ssl_cert_error_handler.h"
15 #include "content/browser/ssl/ssl_policy.h"
16 #include "content/browser/ssl/ssl_request_info.h"
17 #include "content/browser/web_contents/navigation_entry_impl.h"
18 #include "content/browser/web_contents/web_contents_impl.h"
19 #include "content/common/ssl_status_serialization.h"
20 #include "content/public/browser/browser_context.h"
21 #include "content/public/browser/browser_thread.h"
22 #include "content/public/browser/load_from_memory_cache_details.h"
23 #include "content/public/browser/navigation_details.h"
24 #include "content/public/browser/resource_request_details.h"
25 #include "content/public/common/ssl_status.h"
26 #include "net/url_request/url_request.h"
28 namespace content {
30 namespace {
32 const char kSSLManagerKeyName[] = "content_ssl_manager";
34 class SSLManagerSet : public base::SupportsUserData::Data {
35 public:
36 SSLManagerSet() {
39 std::set<SSLManager*>& get() { return set_; }
41 private:
42 std::set<SSLManager*> set_;
44 DISALLOW_COPY_AND_ASSIGN(SSLManagerSet);
47 } // namespace
49 // static
50 void SSLManager::OnSSLCertificateError(
51 const base::WeakPtr<SSLErrorHandler::Delegate>& delegate,
52 const GlobalRequestID& id,
53 const ResourceType::Type resource_type,
54 const GURL& url,
55 int render_process_id,
56 int render_view_id,
57 const net::SSLInfo& ssl_info,
58 bool fatal) {
59 DCHECK(delegate.get());
60 DVLOG(1) << "OnSSLCertificateError() cert_error: "
61 << net::MapCertStatusToNetError(ssl_info.cert_status) << " id: "
62 << id.child_id << "," << id.request_id << " resource_type: "
63 << resource_type << " url: " << url.spec() << " render_process_id: "
64 << render_process_id << " render_view_id: " << render_view_id
65 << " cert_status: " << std::hex << ssl_info.cert_status;
67 // A certificate error occurred. Construct a SSLCertErrorHandler object and
68 // hand it over to the UI thread for processing.
69 BrowserThread::PostTask(
70 BrowserThread::UI, FROM_HERE,
71 base::Bind(&SSLCertErrorHandler::Dispatch,
72 new SSLCertErrorHandler(delegate,
73 id,
74 resource_type,
75 url,
76 render_process_id,
77 render_view_id,
78 ssl_info,
79 fatal)));
82 // static
83 void SSLManager::NotifySSLInternalStateChanged(BrowserContext* context) {
84 SSLManagerSet* managers = static_cast<SSLManagerSet*>(
85 context->GetUserData(kSSLManagerKeyName));
87 for (std::set<SSLManager*>::iterator i = managers->get().begin();
88 i != managers->get().end(); ++i) {
89 (*i)->UpdateEntry(NavigationEntryImpl::FromNavigationEntry(
90 (*i)->controller()->GetActiveEntry()));
94 SSLManager::SSLManager(NavigationControllerImpl* controller)
95 : backend_(controller),
96 policy_(new SSLPolicy(&backend_)),
97 controller_(controller) {
98 DCHECK(controller_);
100 SSLManagerSet* managers = static_cast<SSLManagerSet*>(
101 controller_->GetBrowserContext()->GetUserData(kSSLManagerKeyName));
102 if (!managers) {
103 managers = new SSLManagerSet;
104 controller_->GetBrowserContext()->SetUserData(kSSLManagerKeyName, managers);
106 managers->get().insert(this);
109 SSLManager::~SSLManager() {
110 SSLManagerSet* managers = static_cast<SSLManagerSet*>(
111 controller_->GetBrowserContext()->GetUserData(kSSLManagerKeyName));
112 managers->get().erase(this);
115 void SSLManager::DidCommitProvisionalLoad(const LoadCommittedDetails& details) {
116 NavigationEntryImpl* entry =
117 NavigationEntryImpl::FromNavigationEntry(controller_->GetActiveEntry());
119 if (details.is_main_frame) {
120 if (entry) {
121 // Decode the security details.
122 int ssl_cert_id;
123 net::CertStatus ssl_cert_status;
124 int ssl_security_bits;
125 int ssl_connection_status;
126 DeserializeSecurityInfo(details.serialized_security_info,
127 &ssl_cert_id,
128 &ssl_cert_status,
129 &ssl_security_bits,
130 &ssl_connection_status);
132 // We may not have an entry if this is a navigation to an initial blank
133 // page. Reset the SSL information and add the new data we have.
134 entry->GetSSL() = SSLStatus();
135 entry->GetSSL().cert_id = ssl_cert_id;
136 entry->GetSSL().cert_status = ssl_cert_status;
137 entry->GetSSL().security_bits = ssl_security_bits;
138 entry->GetSSL().connection_status = ssl_connection_status;
142 UpdateEntry(entry);
145 void SSLManager::DidDisplayInsecureContent() {
146 UpdateEntry(
147 NavigationEntryImpl::FromNavigationEntry(controller_->GetActiveEntry()));
150 void SSLManager::DidRunInsecureContent(const std::string& security_origin) {
151 NavigationEntryImpl* navigation_entry =
152 NavigationEntryImpl::FromNavigationEntry(controller_->GetActiveEntry());
153 policy()->DidRunInsecureContent(navigation_entry, security_origin);
154 UpdateEntry(navigation_entry);
157 void SSLManager::DidLoadFromMemoryCache(
158 const LoadFromMemoryCacheDetails& details) {
159 // Simulate loading this resource through the usual path.
160 // Note that we specify SUB_RESOURCE as the resource type as WebCore only
161 // caches sub-resources.
162 // This resource must have been loaded with no filtering because filtered
163 // resouces aren't cachable.
164 scoped_refptr<SSLRequestInfo> info(new SSLRequestInfo(
165 details.url,
166 ResourceType::SUB_RESOURCE,
167 details.pid,
168 details.cert_id,
169 details.cert_status));
171 // Simulate loading this resource through the usual path.
172 policy()->OnRequestStarted(info.get());
175 void SSLManager::DidStartResourceResponse(
176 const ResourceRequestDetails& details) {
177 scoped_refptr<SSLRequestInfo> info(new SSLRequestInfo(
178 details.url,
179 details.resource_type,
180 details.origin_child_id,
181 details.ssl_cert_id,
182 details.ssl_cert_status));
184 // Notify our policy that we started a resource request. Ideally, the
185 // policy should have the ability to cancel the request, but we can't do
186 // that yet.
187 policy()->OnRequestStarted(info.get());
190 void SSLManager::DidReceiveResourceRedirect(
191 const ResourceRedirectDetails& details) {
192 // TODO(abarth): Make sure our redirect behavior is correct. If we ever see a
193 // non-HTTPS resource in the redirect chain, we want to trigger
194 // insecure content, even if the redirect chain goes back to
195 // HTTPS. This is because the network attacker can redirect the
196 // HTTP request to https://attacker.com/payload.js.
199 void SSLManager::UpdateEntry(NavigationEntryImpl* entry) {
200 // We don't always have a navigation entry to update, for example in the
201 // case of the Web Inspector.
202 if (!entry)
203 return;
205 SSLStatus original_ssl_status = entry->GetSSL(); // Copy!
207 policy()->UpdateEntry(entry, controller_->web_contents());
209 if (!entry->GetSSL().Equals(original_ssl_status))
210 controller_->web_contents()->DidChangeVisibleSSLState();
213 } // namespace content