Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(167)

Unified Diff: chrome/browser/content_settings/permission_context_uma_util.cc

Issue 1197853005: Collecting statistics on iframe permissions use. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Reworded bias comment and fixed naming. Created 5 years, 6 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: chrome/browser/content_settings/permission_context_uma_util.cc
diff --git a/chrome/browser/content_settings/permission_context_uma_util.cc b/chrome/browser/content_settings/permission_context_uma_util.cc
index cb2af3914f54879d57b0553bdedfc76ea0cd9d43..a047cfff74aea65fd1179781231c7af7189f17d7 100644
--- a/chrome/browser/content_settings/permission_context_uma_util.cc
+++ b/chrome/browser/content_settings/permission_context_uma_util.cc
@@ -6,6 +6,7 @@
#include "base/strings/stringprintf.h"
#include "chrome/browser/browser_process.h"
#include "chrome/browser/content_settings/permission_context_uma_util.h"
+#include "components/content_settings/core/browser/host_content_settings_map.h"
#include "components/rappor/rappor_utils.h"
#include "content/public/browser/permission_type.h"
#include "content/public/common/origin_util.h"
@@ -139,8 +140,30 @@ void RecordPermissionAction(ContentSettingsType permission,
requesting_origin);
}
-void RecordPermissionRequest(ContentSettingsType permission,
- const GURL& requesting_origin) {
+std::string PermissionTypeToString(PermissionType permission_type) {
+ switch (permission_type) {
+ case PermissionType::MIDI_SYSEX:
+ return "MidiSysex";
+ case PermissionType::PUSH_MESSAGING:
+ return "PushMessaging";
+ case PermissionType::NOTIFICATIONS:
+ return "Notifications";
+ case PermissionType::GEOLOCATION:
+ return "Geolocation";
+ case PermissionType::PROTECTED_MEDIA_IDENTIFIER:
+ return "ProtectedMediaIdentifier";
+ case PermissionType::NUM:
+ break;
+ }
+ return std::string();
+ NOTREACHED();
+}
+
+void RecordPermissionRequest(
+ ContentSettingsType permission,
+ const GURL& requesting_origin,
+ const GURL& embedding_origin,
+ HostContentSettingsMap* host_content_settings_map) {
bool secure_origin = content::IsOriginSecure(requesting_origin);
PermissionType type;
switch (permission) {
@@ -188,6 +211,25 @@ void RecordPermissionRequest(ContentSettingsType permission,
static_cast<base::HistogramBase::Sample>(type),
static_cast<base::HistogramBase::Sample>(PermissionType::NUM));
}
+
+ // In order to gauge the compatibility risk of implementing an improved
+ // iframe permissions security model, we would like to know the ratio of
+ // same-origin to cross-origin permission requests. Our estimate of this
+ // ratio could be somewhat biased by repeated requests coming from a
+ // single frame, but we expect it to be insignificant.
+ if (requesting_origin.GetOrigin() != embedding_origin.GetOrigin()) {
+ ContentSetting embedding_content_setting =
+ host_content_settings_map->GetContentSetting(
+ embedding_origin, embedding_origin, permission, std::string());
+ UMA_HISTOGRAM_ENUMERATION(
+ "Permissions.Requested.CrossOrigin_" + PermissionTypeToString(type),
+ embedding_content_setting, CONTENT_SETTING_NUM_SETTINGS);
+ } else {
+ UMA_HISTOGRAM_ENUMERATION(
+ "Permissions.Requested.SameOrigin",
+ static_cast<base::HistogramBase::Sample>(type),
+ static_cast<base::HistogramBase::Sample>(PermissionType::NUM));
+ }
}
} // namespace
@@ -195,8 +237,12 @@ void RecordPermissionRequest(ContentSettingsType permission,
// Make sure you update histograms.xml permission histogram_suffix if you
// add new permission
void PermissionContextUmaUtil::PermissionRequested(
- ContentSettingsType permission, const GURL& requesting_origin) {
- RecordPermissionRequest(permission, requesting_origin);
+ ContentSettingsType permission,
+ const GURL& requesting_origin,
+ const GURL& embedding_origin,
+ HostContentSettingsMap* host_content_settings_map) {
+ RecordPermissionRequest(permission, requesting_origin, embedding_origin,
+ host_content_settings_map);
}
void PermissionContextUmaUtil::PermissionGranted(

Powered by Google App Engine
This is Rietveld 408576698