Chromium Code Reviews| Index: chrome/browser/io_thread.cc |
| diff --git a/chrome/browser/io_thread.cc b/chrome/browser/io_thread.cc |
| index 572e5348d66d00a57223f6f67433e5aa85d2beab..c64deb903e6d3fb6221b08769da485e967f60ae2 100644 |
| --- a/chrome/browser/io_thread.cc |
| +++ b/chrome/browser/io_thread.cc |
| @@ -458,16 +458,31 @@ IOThread::IOThread( |
| creation_time_(base::TimeTicks::Now()), |
| weak_factory_(this) { |
| auth_schemes_ = local_state->GetString(prefs::kAuthSchemes); |
| - negotiate_disable_cname_lookup_ = local_state->GetBoolean( |
| - prefs::kDisableAuthNegotiateCnameLookup); |
| - negotiate_enable_port_ = local_state->GetBoolean( |
| - prefs::kEnableAuthNegotiatePort); |
| - auth_server_whitelist_ = local_state->GetString(prefs::kAuthServerWhitelist); |
| - auth_delegate_whitelist_ = local_state->GetString( |
| - prefs::kAuthNegotiateDelegateWhitelist); |
| + negotiate_disable_cname_lookup_.Init( |
| + prefs::kDisableAuthNegotiateCnameLookup, local_state, |
| + base::Bind(&IOThread::UpdateNegotiateDisableCnameLookup, |
| + weak_factory_.GetWeakPtr())); |
| + scoped_refptr<base::SingleThreadTaskRunner> io_thread_proxy = |
| + BrowserThread::GetMessageLoopProxyForThread(BrowserThread::IO); |
| + negotiate_disable_cname_lookup_.MoveToThread(io_thread_proxy); |
| + negotiate_enable_port_.Init(prefs::kEnableAuthNegotiatePort, local_state, |
| + base::Bind(&IOThread::UpdateNegotiateEnablePort, |
| + weak_factory_.GetWeakPtr())); |
| + negotiate_enable_port_.MoveToThread(io_thread_proxy); |
| + auth_server_whitelist_.Init( |
| + prefs::kAuthServerWhitelist, local_state, |
| + base::Bind(&IOThread::UpdateSecurityManager, weak_factory_.GetWeakPtr())); |
| + auth_server_whitelist_.MoveToThread(io_thread_proxy); |
| + auth_delegate_whitelist_.Init( |
| + prefs::kAuthNegotiateDelegateWhitelist, local_state, |
| + base::Bind(&IOThread::UpdateSecurityManager, weak_factory_.GetWeakPtr())); |
| + auth_delegate_whitelist_.MoveToThread(io_thread_proxy); |
| gssapi_library_name_ = local_state->GetString(prefs::kGSSAPILibraryName); |
| - auth_android_negotiate_account_type_ = |
| - local_state->GetString(prefs::kAuthAndroidNegotiateAccountType); |
| + auth_android_negotiate_account_type_.Init( |
| + prefs::kAuthAndroidNegotiateAccountType, local_state, |
| + base::Bind(&IOThread::UpdateAndroidAuthNegotiateAccount, |
| + weak_factory_.GetWeakPtr())); |
| + auth_android_negotiate_account_type_.MoveToThread(io_thread_proxy); |
| pref_proxy_config_tracker_.reset( |
| ProxyServiceFactory::CreatePrefProxyConfigTrackerOfLocalState( |
| local_state)); |
| @@ -491,13 +506,11 @@ IOThread::IOThread( |
| local_state, |
| base::Bind(&IOThread::UpdateDnsClientEnabled, |
| base::Unretained(this))); |
| - dns_client_enabled_.MoveToThread( |
| - BrowserThread::GetMessageLoopProxyForThread(BrowserThread::IO)); |
| + dns_client_enabled_.MoveToThread(io_thread_proxy); |
| quick_check_enabled_.Init(prefs::kQuickCheckEnabled, |
| local_state); |
| - quick_check_enabled_.MoveToThread( |
| - BrowserThread::GetMessageLoopProxyForThread(BrowserThread::IO)); |
| + quick_check_enabled_.MoveToThread(io_thread_proxy); |
| #if defined(ENABLE_CONFIGURATION_POLICY) |
| is_spdy_disabled_by_policy_ = policy_service->GetPolicies( |
| @@ -718,8 +731,7 @@ void IOThread::Init() { |
| globals_->ssl_config_service = GetSSLConfigService(); |
| - globals_->http_auth_handler_factory.reset(CreateDefaultAuthHandlerFactory( |
| - globals_->host_resolver.get())); |
| + CreateDefaultAuthHandlerFactory(); |
| globals_->http_server_properties.reset(new net::HttpServerPropertiesImpl()); |
| // For the ProxyScriptFetcher, we use a direct ProxyService. |
| globals_->proxy_script_fetcher_proxy_service = |
| @@ -981,30 +993,51 @@ void IOThread::RegisterPrefs(PrefRegistrySimple* registry) { |
| registry->RegisterBooleanPref(prefs::kQuickCheckEnabled, true); |
| } |
| -net::HttpAuthHandlerFactory* IOThread::CreateDefaultAuthHandlerFactory( |
| - net::HostResolver* resolver) { |
| +void IOThread::UpdateSecurityManager() { |
| net::HttpAuthFilterWhitelist* auth_filter_default_credentials = NULL; |
| - if (!auth_server_whitelist_.empty()) { |
| + std::string server_whitelist = auth_server_whitelist_.GetValue(); |
| + if (!server_whitelist.empty()) { |
| auth_filter_default_credentials = |
| - new net::HttpAuthFilterWhitelist(auth_server_whitelist_); |
| + new net::HttpAuthFilterWhitelist(server_whitelist); |
| } |
| net::HttpAuthFilterWhitelist* auth_filter_delegate = NULL; |
| - if (!auth_delegate_whitelist_.empty()) { |
| - auth_filter_delegate = |
| - new net::HttpAuthFilterWhitelist(auth_delegate_whitelist_); |
| - } |
| + std::string delegate_whitelist = auth_delegate_whitelist_.GetValue(); |
| + if (!delegate_whitelist.empty()) |
| + auth_filter_delegate = new net::HttpAuthFilterWhitelist(delegate_whitelist); |
| globals_->url_security_manager.reset( |
|
asanka
2015/10/26 15:11:54
This isn't safe anymore since that UpdateSecurityM
aberent
2015/10/27 19:34:13
Fixed by keeping the security manager and updating
|
| net::URLSecurityManager::Create(auth_filter_default_credentials, |
| auth_filter_delegate)); |
| + globals_->http_auth_handler_factory->SetSecurityManager( |
| + globals_->url_security_manager.get()); |
| +} |
| + |
| +void IOThread::UpdateAndroidAuthNegotiateAccount() { |
| + globals_->http_auth_handler_factory->SetAndroidAuthNegotiateAccountType( |
| + make_scoped_ptr( |
| + new std::string(auth_android_negotiate_account_type_.GetValue()))); |
| +} |
| + |
| +void IOThread::UpdateNegotiateDisableCnameLookup() { |
| + globals_->http_auth_handler_factory->SetNegotiateDisableCnameLookup( |
| + negotiate_disable_cname_lookup_.GetValue()); |
| +} |
| + |
| +void IOThread::UpdateNegotiateEnablePort() { |
| + globals_->http_auth_handler_factory->SetNegotiateEnablePort( |
| + negotiate_enable_port_.GetValue()); |
| +} |
| + |
| +void IOThread::CreateDefaultAuthHandlerFactory() { |
| std::vector<std::string> supported_schemes = base::SplitString( |
| auth_schemes_, ",", base::TRIM_WHITESPACE, base::SPLIT_WANT_ALL); |
| - |
| - scoped_ptr<net::HttpAuthHandlerRegistryFactory> registry_factory( |
| - net::HttpAuthHandlerRegistryFactory::Create( |
| - supported_schemes, globals_->url_security_manager.get(), resolver, |
| - gssapi_library_name_, auth_android_negotiate_account_type_, |
| - negotiate_disable_cname_lookup_, negotiate_enable_port_)); |
| - return registry_factory.release(); |
| + globals_->http_auth_handler_factory.reset( |
| + net::HttpAuthHandlerRegistryFactory::Create(supported_schemes, |
| + globals_->host_resolver.get(), |
| + gssapi_library_name_)); |
| + UpdateSecurityManager(); |
| + UpdateAndroidAuthNegotiateAccount(); |
| + UpdateNegotiateDisableCnameLookup(); |
| + UpdateNegotiateEnablePort(); |
| } |
| void IOThread::ClearHostCache() { |