OLD | NEW |
---|---|
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "content/browser/loader/resource_loader.h" | 5 #include "content/browser/loader/resource_loader.h" |
6 | 6 |
7 #include <utility> | 7 #include <utility> |
8 | 8 |
9 #include "base/command_line.h" | 9 #include "base/command_line.h" |
10 #include "base/location.h" | 10 #include "base/location.h" |
11 #include "base/metrics/histogram.h" | 11 #include "base/metrics/histogram.h" |
12 #include "base/profiler/scoped_tracker.h" | 12 #include "base/profiler/scoped_tracker.h" |
13 #include "base/single_thread_task_runner.h" | 13 #include "base/single_thread_task_runner.h" |
14 #include "base/thread_task_runner_handle.h" | 14 #include "base/thread_task_runner_handle.h" |
15 #include "base/time/time.h" | 15 #include "base/time/time.h" |
16 #include "content/browser/appcache/appcache_interceptor.h" | 16 #include "content/browser/appcache/appcache_interceptor.h" |
17 #include "content/browser/child_process_security_policy_impl.h" | 17 #include "content/browser/child_process_security_policy_impl.h" |
18 #include "content/browser/loader/cross_site_resource_handler.h" | 18 #include "content/browser/loader/cross_site_resource_handler.h" |
19 #include "content/browser/loader/detachable_resource_handler.h" | 19 #include "content/browser/loader/detachable_resource_handler.h" |
20 #include "content/browser/loader/resource_loader_delegate.h" | 20 #include "content/browser/loader/resource_loader_delegate.h" |
21 #include "content/browser/loader/resource_request_info_impl.h" | 21 #include "content/browser/loader/resource_request_info_impl.h" |
22 #include "content/browser/service_worker/service_worker_request_handler.h" | 22 #include "content/browser/service_worker/service_worker_request_handler.h" |
23 #include "content/browser/ssl/ssl_client_auth_handler.h" | 23 #include "content/browser/ssl/ssl_client_auth_handler.h" |
24 #include "content/browser/ssl/ssl_manager.h" | 24 #include "content/browser/ssl/ssl_manager.h" |
25 #include "content/browser/ssl/ssl_policy.h" | 25 #include "content/browser/ssl/ssl_policy.h" |
26 #include "content/common/ssl_status_serialization.h" | 26 #include "content/common/ssl_status_serialization.h" |
27 #include "content/public/browser/cert_store.h" | 27 #include "content/public/browser/cert_store.h" |
28 #include "content/public/browser/resource_context.h" | 28 #include "content/public/browser/resource_context.h" |
29 #include "content/public/browser/resource_dispatcher_host_login_delegate.h" | 29 #include "content/public/browser/resource_dispatcher_host_login_delegate.h" |
30 #include "content/public/browser/signed_certificate_timestamp_store.h" | |
31 #include "content/public/common/content_client.h" | 30 #include "content/public/common/content_client.h" |
32 #include "content/public/common/content_switches.h" | 31 #include "content/public/common/content_switches.h" |
33 #include "content/public/common/process_type.h" | 32 #include "content/public/common/process_type.h" |
34 #include "content/public/common/resource_response.h" | 33 #include "content/public/common/resource_response.h" |
35 #include "content/public/common/security_style.h" | 34 #include "content/public/common/security_style.h" |
36 #include "net/base/io_buffer.h" | 35 #include "net/base/io_buffer.h" |
37 #include "net/base/load_flags.h" | 36 #include "net/base/load_flags.h" |
38 #include "net/http/http_response_headers.h" | 37 #include "net/http/http_response_headers.h" |
39 #include "net/ssl/client_cert_store.h" | 38 #include "net/ssl/client_cert_store.h" |
39 #include "net/ssl/signed_certificate_timestamp_and_status.h" | |
40 #include "net/ssl/ssl_platform_key.h" | 40 #include "net/ssl/ssl_platform_key.h" |
41 #include "net/ssl/ssl_private_key.h" | 41 #include "net/ssl/ssl_private_key.h" |
42 #include "net/url_request/redirect_info.h" | 42 #include "net/url_request/redirect_info.h" |
43 #include "net/url_request/url_request_status.h" | 43 #include "net/url_request/url_request_status.h" |
44 | 44 |
45 using base::TimeDelta; | 45 using base::TimeDelta; |
46 using base::TimeTicks; | 46 using base::TimeTicks; |
47 | 47 |
48 namespace content { | 48 namespace content { |
49 namespace { | 49 namespace { |
50 | 50 |
51 void StoreSignedCertificateTimestamps( | |
52 const net::SignedCertificateTimestampAndStatusList& sct_list, | |
53 int process_id, | |
54 SignedCertificateTimestampIDStatusList* sct_ids) { | |
55 SignedCertificateTimestampStore* sct_store( | |
56 SignedCertificateTimestampStore::GetInstance()); | |
57 | |
58 for (auto iter = sct_list.begin(); iter != sct_list.end(); ++iter) { | |
59 const int sct_id(sct_store->Store(iter->sct.get(), process_id)); | |
60 sct_ids->push_back( | |
61 SignedCertificateTimestampIDAndStatus(sct_id, iter->status)); | |
62 } | |
63 } | |
64 | |
65 void GetSSLStatusForRequest(const GURL& url, | 51 void GetSSLStatusForRequest(const GURL& url, |
66 const net::SSLInfo& ssl_info, | 52 const net::SSLInfo& ssl_info, |
67 int child_id, | 53 int child_id, |
68 SSLStatus* ssl_status) { | 54 SSLStatus* ssl_status) { |
69 DCHECK(ssl_info.cert); | 55 DCHECK(ssl_info.cert); |
70 | 56 |
71 int cert_id = | 57 int cert_id = |
72 CertStore::GetInstance()->StoreCert(ssl_info.cert.get(), child_id); | 58 CertStore::GetInstance()->StoreCert(ssl_info.cert.get(), child_id); |
73 | 59 |
74 SignedCertificateTimestampIDStatusList signed_certificate_timestamp_ids; | |
75 StoreSignedCertificateTimestamps(ssl_info.signed_certificate_timestamps, | |
76 child_id, &signed_certificate_timestamp_ids); | |
77 | |
78 *ssl_status = SSLStatus(SSLPolicy::GetSecurityStyleForResource( | 60 *ssl_status = SSLStatus(SSLPolicy::GetSecurityStyleForResource( |
79 url, cert_id, ssl_info.cert_status), | 61 url, cert_id, ssl_info.cert_status), |
80 cert_id, signed_certificate_timestamp_ids, ssl_info); | 62 cert_id, ssl_info); |
81 } | 63 } |
82 | 64 |
83 void PopulateResourceResponse(ResourceRequestInfoImpl* info, | 65 void PopulateResourceResponse(ResourceRequestInfoImpl* info, |
84 net::URLRequest* request, | 66 net::URLRequest* request, |
85 ResourceResponse* response) { | 67 ResourceResponse* response) { |
86 response->head.request_time = request->request_time(); | 68 response->head.request_time = request->request_time(); |
87 response->head.response_time = request->response_time(); | 69 response->head.response_time = request->response_time(); |
88 response->head.headers = request->response_headers(); | 70 response->head.headers = request->response_headers(); |
89 request->GetCharset(&response->head.charset); | 71 request->GetCharset(&response->head.charset); |
90 response->head.content_length = request->GetExpectedContentSize(); | 72 response->head.content_length = request->GetExpectedContentSize(); |
(...skipping 19 matching lines...) Expand all Loading... | |
110 request, &response->head.appcache_id, | 92 request, &response->head.appcache_id, |
111 &response->head.appcache_manifest_url); | 93 &response->head.appcache_manifest_url); |
112 if (info->is_load_timing_enabled()) | 94 if (info->is_load_timing_enabled()) |
113 request->GetLoadTimingInfo(&response->head.load_timing); | 95 request->GetLoadTimingInfo(&response->head.load_timing); |
114 | 96 |
115 if (request->ssl_info().cert.get()) { | 97 if (request->ssl_info().cert.get()) { |
116 SSLStatus ssl_status; | 98 SSLStatus ssl_status; |
117 GetSSLStatusForRequest(request->url(), request->ssl_info(), | 99 GetSSLStatusForRequest(request->url(), request->ssl_info(), |
118 info->GetChildID(), &ssl_status); | 100 info->GetChildID(), &ssl_status); |
119 response->head.security_info = SerializeSecurityInfo(ssl_status); | 101 response->head.security_info = SerializeSecurityInfo(ssl_status); |
120 response->head.has_major_certificate_errors = | 102 response->head.has_major_certificate_errors = true; |
estark
2016/03/22 15:51:12
This change doesn't look right.
dwaxweiler
2016/03/22 20:47:43
Acknowledged.
| |
121 net::IsCertStatusError(ssl_status.cert_status) && | 103 net::IsCertStatusError(ssl_status.cert_status) && |
122 !net::IsCertStatusMinorError(ssl_status.cert_status); | 104 !net::IsCertStatusMinorError(ssl_status.cert_status); |
105 response->head.signed_certificate_timestamps = | |
106 request->ssl_info().signed_certificate_timestamps; | |
dwaxweiler
2016/03/21 23:03:44
I set the head.signed_certificate_timestamps here,
estark
2016/03/22 15:51:12
You probably need to add the field to content::Res
dwaxweiler
2016/03/22 20:47:43
Yes, you are right. Thanks! However, the compiler
estark
2016/03/23 01:08:52
The scoped_refptr<net::HttpResponseHeaders> in tha
dwaxweiler
2016/03/23 15:50:52
Done.
| |
123 } else { | 107 } else { |
124 // We should not have any SSL state. | 108 // We should not have any SSL state. |
125 DCHECK(!request->ssl_info().cert_status); | 109 DCHECK(!request->ssl_info().cert_status); |
126 DCHECK_EQ(request->ssl_info().security_bits, -1); | 110 DCHECK_EQ(request->ssl_info().security_bits, -1); |
127 DCHECK_EQ(request->ssl_info().key_exchange_info, 0); | 111 DCHECK_EQ(request->ssl_info().key_exchange_info, 0); |
128 DCHECK(!request->ssl_info().connection_status); | 112 DCHECK(!request->ssl_info().connection_status); |
129 } | 113 } |
130 } | 114 } |
131 | 115 |
132 } // namespace | 116 } // namespace |
(...skipping 577 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
710 case net::URLRequestStatus::FAILED: | 694 case net::URLRequestStatus::FAILED: |
711 status = STATUS_UNDEFINED; | 695 status = STATUS_UNDEFINED; |
712 break; | 696 break; |
713 } | 697 } |
714 | 698 |
715 UMA_HISTOGRAM_ENUMERATION("Net.Prefetch.Pattern", status, STATUS_MAX); | 699 UMA_HISTOGRAM_ENUMERATION("Net.Prefetch.Pattern", status, STATUS_MAX); |
716 } | 700 } |
717 } | 701 } |
718 | 702 |
719 } // namespace content | 703 } // namespace content |
OLD | NEW |