OLD | NEW |
---|---|
(Empty) | |
1 // Copyright 2014 The Chromium Authors. All rights reserved. | |
2 // Use of this source code is governed by a BSD-style license that can be | |
3 // found in the LICENSE file. | |
4 | |
5 #include "chrome/browser/chromeos/login/saml_offline_signin_limiter.h" | |
6 | |
7 #include <string> | |
8 | |
9 #include "base/bind.h" | |
10 #include "base/bind_helpers.h" | |
11 #include "base/location.h" | |
12 #include "base/logging.h" | |
13 #include "base/prefs/pref_service.h" | |
14 #include "base/time/clock.h" | |
15 #include "base/time/time.h" | |
16 #include "chrome/browser/chromeos/login/user_manager.h" | |
17 #include "chrome/browser/profiles/profile.h" | |
18 #include "chrome/common/pref_names.h" | |
19 #include "components/user_prefs/pref_registry_syncable.h" | |
20 | |
21 namespace chromeos { | |
22 | |
23 // static | |
24 void SAMLOfflineSigninLimiter::RegisterProfilePrefs( | |
25 user_prefs::PrefRegistrySyncable* registry) { | |
26 registry->RegisterIntegerPref( | |
27 prefs::kSAMLOfflineSigninTimeLimit, | |
28 1209600, // 14 days, expressed in seconds. | |
Mattias Nissler (ping if slow)
2014/01/23 08:49:15
nit: might be simpler to read if you just write 60
bartfab (slow)
2014/01/23 09:47:23
Done.
| |
29 user_prefs::PrefRegistrySyncable::UNSYNCABLE_PREF); | |
30 registry->RegisterInt64Pref( | |
31 prefs::kSAMLLastGAIASignInTime, | |
32 0, | |
33 user_prefs::PrefRegistrySyncable::UNSYNCABLE_PREF); | |
34 } | |
35 | |
36 void SAMLOfflineSigninLimiter::SignedIn(UserContext::AuthFlow auth_flow) { | |
37 PrefService* prefs = profile_->GetPrefs(); | |
38 const User* user = UserManager::Get()->GetUserByProfile(profile_); | |
39 if (!user) { | |
40 NOTREACHED(); | |
41 return; | |
42 } | |
43 const std::string& user_id = user->email(); | |
44 | |
45 if (auth_flow == UserContext::AUTH_FLOW_GAIA_WITHOUT_SAML) { | |
46 // The user went through online authentication and GAIA did not redirect to | |
47 // a SAML IdP. No limit applies in this case. Clear the time of last login | |
48 // with SAML and the flag enforcing online login, then return. | |
49 prefs->ClearPref(prefs::kSAMLLastGAIASignInTime); | |
50 UserManager::Get()->SaveForceOnlineSignin(user_id, false); | |
51 return; | |
52 } | |
53 | |
54 if (auth_flow == UserContext::AUTH_FLOW_GAIA_WITH_SAML) { | |
55 // The user went through online authentication and GAIA did redirect to a | |
56 // SAML IdP. Update the time of last login with SAML and clear the flag | |
57 // enforcing online login. The flag will be set again when the limit | |
58 // expires. If the limit already expired (e.g. because it was set to zero), | |
59 // the flag will be set again immediately. | |
60 UserManager::Get()->SaveForceOnlineSignin(user_id, false); | |
61 prefs->SetInt64(prefs::kSAMLLastGAIASignInTime, | |
62 clock_->Now().ToInternalValue()); | |
63 } | |
64 | |
65 // Start listening for pref changes. | |
66 pref_change_registrar_.Init(prefs); | |
67 pref_change_registrar_.Add(prefs::kSAMLOfflineSigninTimeLimit, | |
68 base::Bind(&SAMLOfflineSigninLimiter::UpdateLimit, | |
69 base::Unretained(this))); | |
70 | |
71 // Arm the |offline_signin_limit_timer_| if a limit is in force. | |
72 UpdateLimit(); | |
73 } | |
74 | |
75 void SAMLOfflineSigninLimiter::Shutdown() { | |
76 pref_change_registrar_.RemoveAll(); | |
77 offline_signin_limit_timer_.reset(); | |
78 } | |
79 | |
80 SAMLOfflineSigninLimiter::SAMLOfflineSigninLimiter(Profile* profile, | |
81 base::Clock* clock) | |
82 : profile_(profile), | |
83 clock_(clock ? clock : &default_clock_) { | |
84 } | |
85 | |
86 SAMLOfflineSigninLimiter::~SAMLOfflineSigninLimiter() { | |
87 } | |
88 | |
89 void SAMLOfflineSigninLimiter::UpdateLimit() { | |
90 // Stop the |offline_signin_limit_timer_|. | |
91 offline_signin_limit_timer_.reset(); | |
92 | |
93 PrefService* prefs = pref_change_registrar_.prefs(); | |
94 const base::TimeDelta offline_signin_time_limit = | |
95 base::TimeDelta::FromSeconds( | |
96 prefs->GetInteger(prefs::kSAMLOfflineSigninTimeLimit)); | |
97 base::Time last_gaia_signin_time = base::Time::FromInternalValue( | |
98 prefs->GetInt64(prefs::kSAMLLastGAIASignInTime)); | |
99 if (offline_signin_time_limit < base::TimeDelta() || | |
100 last_gaia_signin_time.is_null()) { | |
101 // If no limit is in force, return. | |
102 return; | |
103 } | |
104 | |
105 const base::Time now = clock_->Now(); | |
106 if (last_gaia_signin_time > now) { | |
107 // If the time of last login with SAML lies in the future, set it to the | |
108 // current time. | |
109 NOTREACHED(); | |
110 last_gaia_signin_time = now; | |
111 prefs->SetInt64(prefs::kSAMLLastGAIASignInTime, now.ToInternalValue()); | |
112 } | |
113 | |
114 const base::TimeDelta time_since_last_gaia_signin = | |
115 now - last_gaia_signin_time; | |
116 if (time_since_last_gaia_signin >= offline_signin_time_limit) { | |
117 // If the limit already expired, set the flag enforcing online login | |
118 // immediately and return. | |
119 ForceOnlineLogin(); | |
120 return; | |
121 } | |
122 | |
123 // Arm |offline_signin_limit_timer_| so that it sets the flag enforcing online | |
124 // login when the limit expires. | |
125 offline_signin_limit_timer_.reset( | |
126 new base::OneShotTimer<SAMLOfflineSigninLimiter>); | |
127 offline_signin_limit_timer_->Start( | |
128 FROM_HERE, | |
129 offline_signin_time_limit - time_since_last_gaia_signin, | |
130 this, | |
131 &SAMLOfflineSigninLimiter::ForceOnlineLogin); | |
132 } | |
133 | |
134 void SAMLOfflineSigninLimiter::ForceOnlineLogin() { | |
135 User* user = UserManager::Get()->GetUserByProfile(profile_); | |
136 if (!user) { | |
137 NOTREACHED(); | |
138 return; | |
139 } | |
140 | |
141 UserManager::Get()->SaveForceOnlineSignin(user->email(), true); | |
142 offline_signin_limit_timer_.reset(); | |
143 } | |
144 | |
145 } // namespace chromeos | |
OLD | NEW |