Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(157)

Side by Side Diff: chrome/browser/extensions/api/identity/gaia_web_auth_flow.h

Issue 15148007: Identity API: web-based scope approval dialogs for getAuthToken (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: address reviewer comments Created 7 years, 7 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
« no previous file with comments | « no previous file | chrome/browser/extensions/api/identity/gaia_web_auth_flow.cc » ('j') | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
(Empty)
1 // Copyright (c) 2013 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
4
5 #ifndef CHROME_BROWSER_EXTENSIONS_API_IDENTITY_GAIA_WEB_AUTH_FLOW_H_
6 #define CHROME_BROWSER_EXTENSIONS_API_IDENTITY_GAIA_WEB_AUTH_FLOW_H_
7
8 #include "chrome/browser/extensions/api/identity/web_auth_flow.h"
9 #include "chrome/browser/signin/ubertoken_fetcher.h"
10 #include "chrome/browser/ui/host_desktop.h"
11 #include "chrome/common/extensions/api/identity/oauth2_manifest_handler.h"
12
13 namespace extensions {
14
15 // Implements a web-based OAuth2 scope approval dialog. This flow has
16 // four parts:
17 // 1. Fetch an ubertoken for the signed-in user.
18 // 2. Use the ubertoken to get session cookies using MergeSession.
19 // 3. Start the OAuth flow and wait for final redirect.
20 // 4. Parse results from the fragment component of the final redirect URI.
21 //
22 // The OAuth flow is a special version of the OAuth2 out-of-band flow
23 // where the final response page's title contains the
24 // redirect_uri. The redirect URI has an unusual format to prevent its
25 // use in other contexts. The scheme of the URI is a reversed version
26 // of the OAuth client ID, and the path starts with the Chrome
27 // extension ID. For example, an app with the OAuth client ID
28 // "32610281651.apps.googleusercontent.com" and a Chrome app ID
29 // "kbinjhdkhikmpjoejcfofghmjjpidcnj", would get redirected to:
30 //
31 // com.googleusercontent.apps.32610281651:/kbinjhdkhikmpjoejcfofghmjjpidcnj
32 //
33 // Arriving at this URI completes the flow. The last response from
34 // gaia does a JavaScript redirect to the special URI, but also
35 // includes the same URI in its title. The navigation to this URI gets
36 // filtered out because of its unusual protocol scheme, so
37 // GaiaWebAuthFlow pulls it out of the window title instead.
38
39 class GaiaWebAuthFlow : public UbertokenConsumer, public WebAuthFlow::Delegate {
40 public:
41 enum Failure {
42 WINDOW_CLOSED, // Window closed by user.
43 INVALID_REDIRECT, // Redirect parse error.
44 SERVICE_AUTH_ERROR, // Non-OAuth related authentication error
45 OAUTH_ERROR // Flow reached final redirect, which contained an error.
46 };
47
48 class Delegate {
49 public:
50 // Called when the flow fails prior to the final OAuth redirect,
51 virtual void OnGaiaFlowFailure(Failure failure,
52 GoogleServiceAuthError service_error,
53 const std::string& oauth_error) = 0;
54 // Called when the OAuth2 flow completes.
55 virtual void OnGaiaFlowCompleted(const std::string& access_token,
56 const std::string& expiration) = 0;
57 };
58
59 GaiaWebAuthFlow(Delegate* delegate,
60 Profile* profile,
61 chrome::HostDesktopType host_desktop_type,
62 const std::string& extension_id,
63 const OAuth2Info& oauth2_info);
64 virtual ~GaiaWebAuthFlow();
65
66 // Starts the flow by fetching an ubertoken. Can override for testing.
67 virtual void Start();
68
69 // UbertokenConsumer implementation:
70 virtual void OnUbertokenSuccess(const std::string& token) OVERRIDE;
71 virtual void OnUbertokenFailure(const GoogleServiceAuthError& error) OVERRIDE;
72
73 // WebAuthFlow::Delegate implementation.
74 virtual void OnAuthFlowFailure(WebAuthFlow::Failure failure) OVERRIDE;
75 virtual void OnAuthFlowURLChange(const GURL& redirect_url) OVERRIDE;
76 virtual void OnAuthFlowTitleChange(const std::string& title) OVERRIDE;
77
78 private:
79 // Creates a WebAuthFlow, which will navigate to |url|. Can override
80 // for testing. Used to kick off the MergeSession (step #2).
81 virtual scoped_ptr<WebAuthFlow> CreateWebAuthFlow(GURL url);
82
83 Delegate* delegate_;
84 Profile* profile_;
85 chrome::HostDesktopType host_desktop_type_;
86 std::string redirect_scheme_;
87 std::string redirect_path_prefix_;
88 GURL auth_url_;
89 scoped_ptr<UbertokenFetcher> ubertoken_fetcher_;
90 scoped_ptr<WebAuthFlow> web_flow_;
91
92 DISALLOW_COPY_AND_ASSIGN(GaiaWebAuthFlow);
93 };
94
95 } // extensions
96
97 #endif // CHROME_BROWSER_EXTENSIONS_API_IDENTITY_GAIA_WEB_AUTH_FLOW_H_
OLDNEW
« no previous file with comments | « no previous file | chrome/browser/extensions/api/identity/gaia_web_auth_flow.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698