Index: net/base/cookie_monster.cc |
=================================================================== |
--- net/base/cookie_monster.cc (revision 110104) |
+++ net/base/cookie_monster.cc (working copy) |
@@ -61,7 +61,7 @@ |
#include "base/stringprintf.h" |
#include "googleurl/src/gurl.h" |
#include "googleurl/src/url_canon.h" |
-#include "net/base/cookie_utils.h" |
+#include "net/base/net_util.h" |
#include "net/base/registry_controlled_domain.h" |
using base::Time; |
@@ -188,6 +188,71 @@ |
std::string path; |
}; |
+// Returns the effective TLD+1 for a given host. This only makes sense for http |
+// and https schemes. For other schemes, the host will be returned unchanged |
+// (minus any leading period). |
+std::string GetEffectiveDomain(const std::string& scheme, |
+ const std::string& host) { |
+ if (scheme == "http" || scheme == "https") |
+ return RegistryControlledDomainService::GetDomainAndRegistry(host); |
+ |
+ if (!CookieMonster::DomainIsHostOnly(host)) |
+ return host.substr(1); |
+ return host; |
+} |
+ |
+// Determine the actual cookie domain based on the domain string passed |
+// (if any) and the URL from which the cookie came. |
+// On success returns true, and sets cookie_domain to either a |
+// -host cookie domain (ex: "google.com") |
+// -domain cookie domain (ex: ".google.com") |
+bool GetCookieDomainWithString(const GURL& url, |
+ const std::string& domain_string, |
+ std::string* result) { |
+ const std::string url_host(url.host()); |
+ |
+ // If no domain was specified in the domain string, default to a host cookie. |
+ // We match IE/Firefox in allowing a domain=IPADDR if it matches the url |
+ // ip address hostname exactly. It should be treated as a host cookie. |
+ if (domain_string.empty() || |
+ (url.HostIsIPAddress() && url_host == domain_string)) { |
+ *result = url_host; |
+ DCHECK(CookieMonster::DomainIsHostOnly(*result)); |
+ return true; |
+ } |
+ |
+ // Get the normalized domain specified in cookie line. |
+ url_canon::CanonHostInfo ignored; |
+ std::string cookie_domain(CanonicalizeHost(domain_string, &ignored)); |
+ if (cookie_domain.empty()) |
+ return false; |
+ if (cookie_domain[0] != '.') |
+ cookie_domain = "." + cookie_domain; |
+ |
+ // Ensure |url| and |cookie_domain| have the same domain+registry. |
+ const std::string url_scheme(url.scheme()); |
+ const std::string url_domain_and_registry( |
+ GetEffectiveDomain(url_scheme, url_host)); |
+ if (url_domain_and_registry.empty()) |
+ return false; // IP addresses/intranet hosts can't set domain cookies. |
+ const std::string cookie_domain_and_registry( |
+ GetEffectiveDomain(url_scheme, cookie_domain)); |
+ if (url_domain_and_registry != cookie_domain_and_registry) |
+ return false; // Can't set a cookie on a different domain + registry. |
+ |
+ // Ensure |url_host| is |cookie_domain| or one of its subdomains. Given that |
+ // we know the domain+registry are the same from the above checks, this is |
+ // basically a simple string suffix check. |
+ if ((url_host.length() < cookie_domain.length()) ? |
+ (cookie_domain != ("." + url_host)) : |
+ url_host.compare(url_host.length() - cookie_domain.length(), |
+ cookie_domain.length(), cookie_domain)) |
+ return false; |
+ |
+ *result = cookie_domain; |
+ return true; |
+} |
+ |
// Determine the cookie domain to use for setting the specified cookie. |
bool GetCookieDomain(const GURL& url, |
const CookieMonster::ParsedCookie& pc, |
@@ -195,7 +260,7 @@ |
std::string domain_string; |
if (pc.HasDomain()) |
domain_string = pc.Domain(); |
- return cookie_utils::GetCookieDomainWithString(url, domain_string, result); |
+ return GetCookieDomainWithString(url, domain_string, result); |
} |
std::string CanonPathWithString(const GURL& url, |
@@ -509,6 +574,10 @@ |
return Time(); |
} |
+bool CookieMonster::DomainIsHostOnly(const std::string& domain_string) { |
+ return (domain_string.empty() || domain_string[0] != '.'); |
+} |
+ |
// Task classes for queueing the coming request. |
class CookieMonster::CookieMonsterTask |
@@ -1059,8 +1128,7 @@ |
// then run the task, otherwise load from DB. |
if (!loaded_) { |
// Checks if the domain key has been loaded. |
- std::string key(cookie_utils::GetEffectiveDomain(url.scheme(), |
- url.host())); |
+ std::string key(GetEffectiveDomain(url.scheme(), url.host())); |
if (keys_loaded_.find(key) == keys_loaded_.end()) { |
std::map<std::string, std::deque<scoped_refptr<CookieMonsterTask> > > |
::iterator it = tasks_queued_.find(key); |
@@ -1666,8 +1734,7 @@ |
cookies); |
// See if we can search for domain cookies, i.e. if the host has a TLD + 1. |
- const std::string domain(cookie_utils::GetEffectiveDomain(url.scheme(), |
- key)); |
+ const std::string domain(GetEffectiveDomain(url.scheme(), key)); |
if (domain.empty()) |
return; |
DCHECK_LE(domain.length(), key.length()); |
@@ -2576,8 +2643,8 @@ |
domain_string = pc.Domain(); |
} |
bool result |
- = cookie_utils::GetCookieDomainWithString(url, domain_string, |
- &cookie_domain); |
+ = GetCookieDomainWithString(url, domain_string, |
+ &cookie_domain); |
// Caller is responsible for passing in good arguments. |
DCHECK(result); |
domain_ = cookie_domain; |
@@ -2660,10 +2727,8 @@ |
if (parsed_domain != domain) |
return NULL; |
std::string cookie_domain; |
- if (!cookie_utils::GetCookieDomainWithString(url, parsed_domain, |
- &cookie_domain)) { |
+ if (!GetCookieDomainWithString(url, parsed_domain, &cookie_domain)) |
return NULL; |
- } |
std::string parsed_path = ParsedCookie::ParseValueString(path); |
if (parsed_path != path) |