| OLD | NEW |
| 1 // Copyright 2013 The Chromium Authors. All rights reserved. | 1 // Copyright 2013 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "extensions/common/csp_validator.h" | 5 #include "extensions/common/csp_validator.h" |
| 6 | 6 |
| 7 #include <vector> | 7 #include <vector> |
| 8 | 8 |
| 9 #include "base/strings/string_split.h" | 9 #include "base/strings/string_split.h" |
| 10 #include "base/strings/string_tokenizer.h" | 10 #include "base/strings/string_tokenizer.h" |
| (...skipping 65 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 76 | 76 |
| 77 size_t start_of_port = url.rfind(":", end_of_host); | 77 size_t start_of_port = url.rfind(":", end_of_host); |
| 78 // The ":" check at the end of the following condition is used to avoid | 78 // The ":" check at the end of the following condition is used to avoid |
| 79 // treating the last part of an IPv6 address as a port. | 79 // treating the last part of an IPv6 address as a port. |
| 80 if (start_of_port > start_of_host && url[start_of_port - 1] != ':') { | 80 if (start_of_port > start_of_host && url[start_of_port - 1] != ':') { |
| 81 bool is_valid_port = false; | 81 bool is_valid_port = false; |
| 82 // Do a quick sanity check. The following check could mistakenly flag | 82 // Do a quick sanity check. The following check could mistakenly flag |
| 83 // ":123456" or ":****" as valid, but that does not matter because the | 83 // ":123456" or ":****" as valid, but that does not matter because the |
| 84 // relaxing CSP directive will just be ignored by Blink. | 84 // relaxing CSP directive will just be ignored by Blink. |
| 85 for (size_t i = start_of_port + 1; i < end_of_host; ++i) { | 85 for (size_t i = start_of_port + 1; i < end_of_host; ++i) { |
| 86 is_valid_port = IsAsciiDigit(url[i]) || url[i] == '*'; | 86 is_valid_port = base::IsAsciiDigit(url[i]) || url[i] == '*'; |
| 87 if (!is_valid_port) | 87 if (!is_valid_port) |
| 88 break; | 88 break; |
| 89 } | 89 } |
| 90 if (is_valid_port) | 90 if (is_valid_port) |
| 91 end_of_host = start_of_port; | 91 end_of_host = start_of_port; |
| 92 } | 92 } |
| 93 | 93 |
| 94 std::string host(url, start_of_host, end_of_host - start_of_host); | 94 std::string host(url, start_of_host, end_of_host - start_of_host); |
| 95 // Global wildcards are not allowed. | 95 // Global wildcards are not allowed. |
| 96 if (host.empty() || host.find("*") != std::string::npos) | 96 if (host.empty() || host.find("*") != std::string::npos) |
| (...skipping 240 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 337 } | 337 } |
| 338 } | 338 } |
| 339 } | 339 } |
| 340 | 340 |
| 341 return seen_sandbox; | 341 return seen_sandbox; |
| 342 } | 342 } |
| 343 | 343 |
| 344 } // namespace csp_validator | 344 } // namespace csp_validator |
| 345 | 345 |
| 346 } // namespace extensions | 346 } // namespace extensions |
| OLD | NEW |