Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(406)

Side by Side Diff: chrome/browser/renderer_host/chrome_resource_dispatcher_host_delegate.cc

Issue 141363006: Proof of concept of ignoring x-frame-options for sign-in webui. (Closed) Base URL: svn://chrome-svn/chrome/trunk/src/
Patch Set: fix crash Created 6 years, 10 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch | Annotate | Revision Log
« no previous file with comments | « chrome/browser/chrome_content_browser_client.cc ('k') | chrome/browser/resources/signin.html » ('j') | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "chrome/browser/renderer_host/chrome_resource_dispatcher_host_delegate. h" 5 #include "chrome/browser/renderer_host/chrome_resource_dispatcher_host_delegate. h"
6 6
7 #include <string> 7 #include <string>
8 8
9 #include "base/base64.h" 9 #include "base/base64.h"
10 #include "base/logging.h" 10 #include "base/logging.h"
(...skipping 19 matching lines...) Expand all
30 #include "chrome/browser/profiles/profile_io_data.h" 30 #include "chrome/browser/profiles/profile_io_data.h"
31 #include "chrome/browser/renderer_host/safe_browsing_resource_throttle_factory.h " 31 #include "chrome/browser/renderer_host/safe_browsing_resource_throttle_factory.h "
32 #include "chrome/browser/safe_browsing/safe_browsing_service.h" 32 #include "chrome/browser/safe_browsing/safe_browsing_service.h"
33 #include "chrome/browser/signin/signin_header_helper.h" 33 #include "chrome/browser/signin/signin_header_helper.h"
34 #include "chrome/browser/ui/auto_login_prompter.h" 34 #include "chrome/browser/ui/auto_login_prompter.h"
35 #include "chrome/browser/ui/login/login_prompt.h" 35 #include "chrome/browser/ui/login/login_prompt.h"
36 #include "chrome/browser/ui/sync/one_click_signin_helper.h" 36 #include "chrome/browser/ui/sync/one_click_signin_helper.h"
37 #include "chrome/common/extensions/extension_constants.h" 37 #include "chrome/common/extensions/extension_constants.h"
38 #include "chrome/common/extensions/mime_types_handler.h" 38 #include "chrome/common/extensions/mime_types_handler.h"
39 #include "chrome/common/render_messages.h" 39 #include "chrome/common/render_messages.h"
40 #include "chrome/common/url_constants.h"
40 #include "content/public/browser/browser_thread.h" 41 #include "content/public/browser/browser_thread.h"
41 #include "content/public/browser/notification_service.h" 42 #include "content/public/browser/notification_service.h"
42 #include "content/public/browser/render_process_host.h" 43 #include "content/public/browser/render_process_host.h"
43 #include "content/public/browser/render_view_host.h" 44 #include "content/public/browser/render_view_host.h"
44 #include "content/public/browser/resource_context.h" 45 #include "content/public/browser/resource_context.h"
45 #include "content/public/browser/resource_dispatcher_host.h" 46 #include "content/public/browser/resource_dispatcher_host.h"
46 #include "content/public/browser/resource_request_info.h" 47 #include "content/public/browser/resource_request_info.h"
47 #include "content/public/browser/stream_handle.h" 48 #include "content/public/browser/stream_handle.h"
48 #include "content/public/browser/web_contents.h" 49 #include "content/public/browser/web_contents.h"
49 #include "content/public/common/resource_response.h" 50 #include "content/public/common/resource_response.h"
(...skipping 534 matching lines...) Expand 10 before | Expand all | Expand 10 after
584 GURL webstore_url(extension_urls::GetWebstoreLaunchURL()); 585 GURL webstore_url(extension_urls::GetWebstoreLaunchURL());
585 if (request->url().DomainIs(webstore_url.host().c_str())) { 586 if (request->url().DomainIs(webstore_url.host().c_str())) {
586 net::HttpResponseHeaders* response_headers = request->response_headers(); 587 net::HttpResponseHeaders* response_headers = request->response_headers();
587 if (!response_headers->HasHeaderValue("x-frame-options", "deny") && 588 if (!response_headers->HasHeaderValue("x-frame-options", "deny") &&
588 !response_headers->HasHeaderValue("x-frame-options", "sameorigin")) { 589 !response_headers->HasHeaderValue("x-frame-options", "sameorigin")) {
589 response_headers->RemoveHeader("x-frame-options"); 590 response_headers->RemoveHeader("x-frame-options");
590 response_headers->AddHeader("x-frame-options: sameorigin"); 591 response_headers->AddHeader("x-frame-options: sameorigin");
591 } 592 }
592 } 593 }
593 594
595 if (request->first_party_for_cookies().SchemeIs(chrome::kChromeUIScheme) &&
596 request->first_party_for_cookies().host() == chrome::kChromeSigninHost) {
597 net::HttpResponseHeaders* response_headers = request->response_headers();
598 if (response_headers->HasHeader("x-frame-options"))
599 response_headers->RemoveHeader("x-frame-options");
600 }
601
594 prerender::URLRequestResponseStarted(request); 602 prerender::URLRequestResponseStarted(request);
595 } 603 }
596 604
597 void ChromeResourceDispatcherHostDelegate::OnRequestRedirected( 605 void ChromeResourceDispatcherHostDelegate::OnRequestRedirected(
598 const GURL& redirect_url, 606 const GURL& redirect_url,
599 net::URLRequest* request, 607 net::URLRequest* request,
600 content::ResourceContext* resource_context, 608 content::ResourceContext* resource_context,
601 content::ResourceResponse* response) { 609 content::ResourceResponse* response) {
602 ProfileIOData* io_data = ProfileIOData::FromResourceContext(resource_context); 610 ProfileIOData* io_data = ProfileIOData::FromResourceContext(resource_context);
603 const ResourceRequestInfo* info = ResourceRequestInfo::ForRequest(request); 611 const ResourceRequestInfo* info = ResourceRequestInfo::ForRequest(request);
(...skipping 16 matching lines...) Expand all
620 signin::AppendMirrorRequestHeaderIfPossible(request, redirect_url, io_data, 628 signin::AppendMirrorRequestHeaderIfPossible(request, redirect_url, io_data,
621 info->GetChildID(), info->GetRouteID()); 629 info->GetChildID(), info->GetRouteID());
622 } 630 }
623 631
624 // static 632 // static
625 void ChromeResourceDispatcherHostDelegate:: 633 void ChromeResourceDispatcherHostDelegate::
626 SetExternalProtocolHandlerDelegateForTesting( 634 SetExternalProtocolHandlerDelegateForTesting(
627 ExternalProtocolHandler::Delegate* delegate) { 635 ExternalProtocolHandler::Delegate* delegate) {
628 g_external_protocol_handler_delegate = delegate; 636 g_external_protocol_handler_delegate = delegate;
629 } 637 }
OLDNEW
« no previous file with comments | « chrome/browser/chrome_content_browser_client.cc ('k') | chrome/browser/resources/signin.html » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698