| OLD | NEW |
| 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright 2015 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "chrome/browser/net/chrome_fraudulent_certificate_reporter.h" | 5 #include "chrome/browser/ssl/chrome_fraudulent_certificate_reporter.h" |
| 6 | 6 |
| 7 #include "base/profiler/scoped_tracker.h" | 7 #include "base/profiler/scoped_tracker.h" |
| 8 #include "chrome/browser/net/certificate_error_reporter.h" | 8 #include "chrome/browser/net/certificate_error_reporter.h" |
| 9 #include "chrome/browser/ssl/certificate_error_report.h" |
| 9 #include "net/ssl/ssl_info.h" | 10 #include "net/ssl/ssl_info.h" |
| 10 #include "net/url_request/url_request_context.h" | 11 #include "net/url_request/url_request_context.h" |
| 11 #include "url/gurl.h" | 12 #include "url/gurl.h" |
| 12 | 13 |
| 13 namespace { | 14 namespace { |
| 14 | 15 |
| 15 // TODO(palmer): Switch to HTTPS when the error handling delegate is more | 16 // TODO(palmer): Switch to HTTPS when the error handling delegate is more |
| 16 // sophisticated. Ultimately we plan to attempt the report on many transports. | 17 // sophisticated. Ultimately we plan to attempt the report on many transports. |
| 17 const char kFraudulentCertificateUploadEndpoint[] = | 18 const char kFraudulentCertificateUploadEndpoint[] = |
| 18 "http://clients3.google.com/log_cert_error"; | 19 "http://clients3.google.com/log_cert_error"; |
| 19 | 20 |
| 20 } // namespace | 21 } // namespace |
| 21 | 22 |
| 22 namespace chrome_browser_net { | |
| 23 | |
| 24 ChromeFraudulentCertificateReporter::ChromeFraudulentCertificateReporter( | 23 ChromeFraudulentCertificateReporter::ChromeFraudulentCertificateReporter( |
| 25 net::URLRequestContext* request_context) | 24 net::URLRequestContext* request_context) |
| 26 : certificate_reporter_(new CertificateErrorReporter( | 25 : certificate_reporter_(new chrome_browser_net::CertificateErrorReporter( |
| 27 request_context, | 26 request_context, |
| 28 GURL(kFraudulentCertificateUploadEndpoint), | 27 GURL(kFraudulentCertificateUploadEndpoint), |
| 29 CertificateErrorReporter::DO_NOT_SEND_COOKIES)) { | 28 chrome_browser_net::CertificateErrorReporter::DO_NOT_SEND_COOKIES)) { |
| 30 } | 29 } |
| 31 | 30 |
| 32 ChromeFraudulentCertificateReporter::ChromeFraudulentCertificateReporter( | 31 ChromeFraudulentCertificateReporter::ChromeFraudulentCertificateReporter( |
| 33 scoped_ptr<CertificateErrorReporter> certificate_reporter) | 32 scoped_ptr<chrome_browser_net::CertificateErrorReporter> |
| 33 certificate_reporter) |
| 34 : certificate_reporter_(certificate_reporter.Pass()) { | 34 : certificate_reporter_(certificate_reporter.Pass()) { |
| 35 } | 35 } |
| 36 | 36 |
| 37 ChromeFraudulentCertificateReporter::~ChromeFraudulentCertificateReporter() { | 37 ChromeFraudulentCertificateReporter::~ChromeFraudulentCertificateReporter() { |
| 38 } | 38 } |
| 39 | 39 |
| 40 void ChromeFraudulentCertificateReporter::SendReport( | 40 void ChromeFraudulentCertificateReporter::SendReport( |
| 41 const std::string& hostname, | 41 const std::string& hostname, |
| 42 const net::SSLInfo& ssl_info) { | 42 const net::SSLInfo& ssl_info) { |
| 43 // Do silent/automatic reporting ONLY for Google properties. For other | 43 // Do silent/automatic reporting ONLY for Google properties. For other |
| 44 // domains (when that is supported), Chrome will ask for user permission. | 44 // domains (when that is supported), Chrome will ask for user permission. |
| 45 if (!net::TransportSecurityState::IsGooglePinnedProperty(hostname)) | 45 if (!net::TransportSecurityState::IsGooglePinnedProperty(hostname)) |
| 46 return; | 46 return; |
| 47 | 47 |
| 48 CertificateErrorReport report(hostname, ssl_info); |
| 49 std::string serialized_report; |
| 50 if (!report.Serialize(&serialized_report)) { |
| 51 LOG(ERROR) << "Failed to serialize pinning violation report."; |
| 52 return; |
| 53 } |
| 54 |
| 48 certificate_reporter_->SendReport( | 55 certificate_reporter_->SendReport( |
| 49 CertificateErrorReporter::REPORT_TYPE_PINNING_VIOLATION, hostname, | 56 chrome_browser_net::CertificateErrorReporter:: |
| 50 ssl_info); | 57 REPORT_TYPE_PINNING_VIOLATION, |
| 58 serialized_report); |
| 51 } | 59 } |
| 52 | |
| 53 } // namespace chrome_browser_net | |
| OLD | NEW |