Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(241)

Side by Side Diff: content/browser/loader/resource_loader.cc

Issue 1772603002: Addition of Certificate Transparency details to Security panel of DevTools (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: removed SignedCertificateTimestampStore and SignedCertificateTimestampIDStatus(List) Created 4 years, 9 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "content/browser/loader/resource_loader.h" 5 #include "content/browser/loader/resource_loader.h"
6 6
7 #include <utility> 7 #include <utility>
8 8
9 #include "base/command_line.h" 9 #include "base/command_line.h"
10 #include "base/location.h" 10 #include "base/location.h"
11 #include "base/metrics/histogram.h" 11 #include "base/metrics/histogram.h"
12 #include "base/profiler/scoped_tracker.h" 12 #include "base/profiler/scoped_tracker.h"
13 #include "base/single_thread_task_runner.h" 13 #include "base/single_thread_task_runner.h"
14 #include "base/thread_task_runner_handle.h" 14 #include "base/thread_task_runner_handle.h"
15 #include "base/time/time.h" 15 #include "base/time/time.h"
16 #include "content/browser/appcache/appcache_interceptor.h" 16 #include "content/browser/appcache/appcache_interceptor.h"
17 #include "content/browser/child_process_security_policy_impl.h" 17 #include "content/browser/child_process_security_policy_impl.h"
18 #include "content/browser/loader/cross_site_resource_handler.h" 18 #include "content/browser/loader/cross_site_resource_handler.h"
19 #include "content/browser/loader/detachable_resource_handler.h" 19 #include "content/browser/loader/detachable_resource_handler.h"
20 #include "content/browser/loader/resource_loader_delegate.h" 20 #include "content/browser/loader/resource_loader_delegate.h"
21 #include "content/browser/loader/resource_request_info_impl.h" 21 #include "content/browser/loader/resource_request_info_impl.h"
22 #include "content/browser/service_worker/service_worker_request_handler.h" 22 #include "content/browser/service_worker/service_worker_request_handler.h"
23 #include "content/browser/ssl/ssl_client_auth_handler.h" 23 #include "content/browser/ssl/ssl_client_auth_handler.h"
24 #include "content/browser/ssl/ssl_manager.h" 24 #include "content/browser/ssl/ssl_manager.h"
25 #include "content/browser/ssl/ssl_policy.h" 25 #include "content/browser/ssl/ssl_policy.h"
26 #include "content/common/ssl_status_serialization.h" 26 #include "content/common/ssl_status_serialization.h"
27 #include "content/public/browser/cert_store.h" 27 #include "content/public/browser/cert_store.h"
28 #include "content/public/browser/resource_context.h" 28 #include "content/public/browser/resource_context.h"
29 #include "content/public/browser/resource_dispatcher_host_login_delegate.h" 29 #include "content/public/browser/resource_dispatcher_host_login_delegate.h"
30 #include "content/public/browser/signed_certificate_timestamp_store.h"
31 #include "content/public/common/content_client.h" 30 #include "content/public/common/content_client.h"
32 #include "content/public/common/content_switches.h" 31 #include "content/public/common/content_switches.h"
33 #include "content/public/common/process_type.h" 32 #include "content/public/common/process_type.h"
34 #include "content/public/common/resource_response.h" 33 #include "content/public/common/resource_response.h"
35 #include "content/public/common/security_style.h" 34 #include "content/public/common/security_style.h"
36 #include "net/base/io_buffer.h" 35 #include "net/base/io_buffer.h"
37 #include "net/base/load_flags.h" 36 #include "net/base/load_flags.h"
38 #include "net/http/http_response_headers.h" 37 #include "net/http/http_response_headers.h"
39 #include "net/ssl/client_cert_store.h" 38 #include "net/ssl/client_cert_store.h"
39 #include "net/ssl/signed_certificate_timestamp_and_status.h"
40 #include "net/ssl/ssl_platform_key.h" 40 #include "net/ssl/ssl_platform_key.h"
41 #include "net/ssl/ssl_private_key.h" 41 #include "net/ssl/ssl_private_key.h"
42 #include "net/url_request/redirect_info.h" 42 #include "net/url_request/redirect_info.h"
43 #include "net/url_request/url_request_status.h" 43 #include "net/url_request/url_request_status.h"
44 44
45 using base::TimeDelta; 45 using base::TimeDelta;
46 using base::TimeTicks; 46 using base::TimeTicks;
47 47
48 namespace content { 48 namespace content {
49 namespace { 49 namespace {
50 50
51 void StoreSignedCertificateTimestamps(
52 const net::SignedCertificateTimestampAndStatusList& sct_list,
53 int process_id,
54 SignedCertificateTimestampIDStatusList* sct_ids) {
55 SignedCertificateTimestampStore* sct_store(
56 SignedCertificateTimestampStore::GetInstance());
57
58 for (auto iter = sct_list.begin(); iter != sct_list.end(); ++iter) {
59 const int sct_id(sct_store->Store(iter->sct.get(), process_id));
60 sct_ids->push_back(
61 SignedCertificateTimestampIDAndStatus(sct_id, iter->status));
62 }
63 }
64
65 void GetSSLStatusForRequest(const GURL& url, 51 void GetSSLStatusForRequest(const GURL& url,
66 const net::SSLInfo& ssl_info, 52 const net::SSLInfo& ssl_info,
67 int child_id, 53 int child_id,
68 SSLStatus* ssl_status) { 54 SSLStatus* ssl_status) {
69 DCHECK(ssl_info.cert); 55 DCHECK(ssl_info.cert);
70 56
71 int cert_id = 57 int cert_id =
72 CertStore::GetInstance()->StoreCert(ssl_info.cert.get(), child_id); 58 CertStore::GetInstance()->StoreCert(ssl_info.cert.get(), child_id);
73 59
74 SignedCertificateTimestampIDStatusList signed_certificate_timestamp_ids;
75 StoreSignedCertificateTimestamps(ssl_info.signed_certificate_timestamps,
76 child_id, &signed_certificate_timestamp_ids);
77
78 *ssl_status = SSLStatus(SSLPolicy::GetSecurityStyleForResource( 60 *ssl_status = SSLStatus(SSLPolicy::GetSecurityStyleForResource(
79 url, cert_id, ssl_info.cert_status), 61 url, cert_id, ssl_info.cert_status),
80 cert_id, signed_certificate_timestamp_ids, ssl_info); 62 cert_id, ssl_info);
81 } 63 }
82 64
83 void PopulateResourceResponse(ResourceRequestInfoImpl* info, 65 void PopulateResourceResponse(ResourceRequestInfoImpl* info,
84 net::URLRequest* request, 66 net::URLRequest* request,
85 ResourceResponse* response) { 67 ResourceResponse* response) {
86 response->head.request_time = request->request_time(); 68 response->head.request_time = request->request_time();
87 response->head.response_time = request->response_time(); 69 response->head.response_time = request->response_time();
88 response->head.headers = request->response_headers(); 70 response->head.headers = request->response_headers();
89 request->GetCharset(&response->head.charset); 71 request->GetCharset(&response->head.charset);
90 response->head.content_length = request->GetExpectedContentSize(); 72 response->head.content_length = request->GetExpectedContentSize();
(...skipping 19 matching lines...) Expand all
110 request, &response->head.appcache_id, 92 request, &response->head.appcache_id,
111 &response->head.appcache_manifest_url); 93 &response->head.appcache_manifest_url);
112 if (info->is_load_timing_enabled()) 94 if (info->is_load_timing_enabled())
113 request->GetLoadTimingInfo(&response->head.load_timing); 95 request->GetLoadTimingInfo(&response->head.load_timing);
114 96
115 if (request->ssl_info().cert.get()) { 97 if (request->ssl_info().cert.get()) {
116 SSLStatus ssl_status; 98 SSLStatus ssl_status;
117 GetSSLStatusForRequest(request->url(), request->ssl_info(), 99 GetSSLStatusForRequest(request->url(), request->ssl_info(),
118 info->GetChildID(), &ssl_status); 100 info->GetChildID(), &ssl_status);
119 response->head.security_info = SerializeSecurityInfo(ssl_status); 101 response->head.security_info = SerializeSecurityInfo(ssl_status);
120 response->head.has_major_certificate_errors = 102 response->head.has_major_certificate_errors = true;
estark 2016/03/22 15:51:12 This change doesn't look right.
dwaxweiler 2016/03/22 20:47:43 Acknowledged.
121 net::IsCertStatusError(ssl_status.cert_status) && 103 net::IsCertStatusError(ssl_status.cert_status) &&
122 !net::IsCertStatusMinorError(ssl_status.cert_status); 104 !net::IsCertStatusMinorError(ssl_status.cert_status);
105 response->head.signed_certificate_timestamps =
106 request->ssl_info().signed_certificate_timestamps;
dwaxweiler 2016/03/21 23:03:44 I set the head.signed_certificate_timestamps here,
estark 2016/03/22 15:51:12 You probably need to add the field to content::Res
dwaxweiler 2016/03/22 20:47:43 Yes, you are right. Thanks! However, the compiler
estark 2016/03/23 01:08:52 The scoped_refptr<net::HttpResponseHeaders> in tha
dwaxweiler 2016/03/23 15:50:52 Done.
123 } else { 107 } else {
124 // We should not have any SSL state. 108 // We should not have any SSL state.
125 DCHECK(!request->ssl_info().cert_status); 109 DCHECK(!request->ssl_info().cert_status);
126 DCHECK_EQ(request->ssl_info().security_bits, -1); 110 DCHECK_EQ(request->ssl_info().security_bits, -1);
127 DCHECK_EQ(request->ssl_info().key_exchange_info, 0); 111 DCHECK_EQ(request->ssl_info().key_exchange_info, 0);
128 DCHECK(!request->ssl_info().connection_status); 112 DCHECK(!request->ssl_info().connection_status);
129 } 113 }
130 } 114 }
131 115
132 } // namespace 116 } // namespace
(...skipping 577 matching lines...) Expand 10 before | Expand all | Expand 10 after
710 case net::URLRequestStatus::FAILED: 694 case net::URLRequestStatus::FAILED:
711 status = STATUS_UNDEFINED; 695 status = STATUS_UNDEFINED;
712 break; 696 break;
713 } 697 }
714 698
715 UMA_HISTOGRAM_ENUMERATION("Net.Prefetch.Pattern", status, STATUS_MAX); 699 UMA_HISTOGRAM_ENUMERATION("Net.Prefetch.Pattern", status, STATUS_MAX);
716 } 700 }
717 } 701 }
718 702
719 } // namespace content 703 } // namespace content
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698