OLD | NEW |
---|---|
1 /* | 1 /* |
2 * Copyright (C) 2011 Google Inc. All rights reserved. | 2 * Copyright (C) 2014 Google Inc. All rights reserved. |
3 * | 3 * |
4 * Redistribution and use in source and binary forms, with or without | 4 * Redistribution and use in source and binary forms, with or without |
5 * modification, are permitted provided that the following conditions | 5 * modification, are permitted provided that the following conditions |
6 * are met: | 6 * are met: |
7 * | 7 * |
8 * 1. Redistributions of source code must retain the above copyright | 8 * 1. Redistributions of source code must retain the above copyright |
9 * notice, this list of conditions and the following disclaimer. | 9 * notice, this list of conditions and the following disclaimer. |
10 * 2. Redistributions in binary form must reproduce the above copyright | 10 * 2. Redistributions in binary form must reproduce the above copyright |
11 * notice, this list of conditions and the following disclaimer in the | 11 * notice, this list of conditions and the following disclaimer in the |
12 * documentation and/or other materials provided with the distribution. | 12 * documentation and/or other materials provided with the distribution. |
13 * 3. Neither the name of Google, Inc. ("Google") nor the names of | 13 * 3. Neither the name of Google, Inc. ("Google") nor the names of |
14 * its contributors may be used to endorse or promote products derived | 14 * its contributors may be used to endorse or promote products derived |
15 * from this software without specific prior written permission. | 15 * from this software without specific prior written permission. |
16 * | 16 * |
17 * THIS SOFTWARE IS PROVIDED BY GOOGLE AND ITS CONTRIBUTORS "AS IS" AND ANY | 17 * THIS SOFTWARE IS PROVIDED BY GOOGLE AND ITS CONTRIBUTORS "AS IS" AND ANY |
18 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED | 18 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED |
19 * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE | 19 * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE |
20 * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY | 20 * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY |
21 * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES | 21 * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES |
22 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; | 22 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; |
23 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND | 23 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND |
24 * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT | 24 * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
25 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF | 25 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF |
26 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. | 26 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
27 */ | 27 */ |
28 | 28 |
29 #ifndef SecurityPolicy_h | 29 #ifndef CryptoUtilities_h |
30 #define SecurityPolicy_h | 30 #define CryptoUtilities_h |
31 | 31 |
32 #include "platform/PlatformExport.h" | 32 #include "platform/PlatformExport.h" |
33 #include "platform/weborigin/ReferrerPolicy.h" | 33 #include "wtf/HashSet.h" |
34 #include "wtf/text/WTFString.h" | 34 #include "wtf/StringHasher.h" |
35 #include "wtf/Vector.h" | |
36 #include "wtf/text/CString.h" | |
35 | 37 |
36 namespace WebCore { | 38 namespace WebCore { |
39 namespace CryptoUtil { | |
abarth-chromium
2014/03/12 18:59:02
I'd just drop this namespace entirely. WebCore is
jww
2014/04/01 23:29:09
Done.
| |
37 | 40 |
38 class KURL; | 41 static const size_t kMaxDigestSize = 64; |
39 class SecurityOrigin; | 42 typedef Vector<uint8_t, kMaxDigestSize> DigestValue; |
eseidel
2014/03/12 06:51:23
I see, you're just typdefing to a vector directly,
jww
2014/04/01 23:29:09
Correct.
| |
40 | 43 |
41 class PLATFORM_EXPORT SecurityPolicy { | 44 const size_t sha1HashSize = 20; |
42 public: | 45 enum HashAlgorithm { |
43 // True if the referrer should be omitted according to the | 46 HashAlgorithmSha1, |
44 // ReferrerPolicyDefault. If you intend to send a referrer header, you | 47 HashAlgorithmSha256, |
45 // should use generateReferrerHeader instead. | 48 HashAlgorithmSha384, |
46 static bool shouldHideReferrer(const KURL&, const String& referrer); | 49 HashAlgorithmSha512 |
47 | |
48 // Returns the referrer modified according to the referrer policy for a | |
49 // navigation to a given URL. If the referrer returned is empty, the | |
50 // referrer header should be omitted. | |
51 static String generateReferrerHeader(ReferrerPolicy, const KURL&, const Stri ng& referrer); | |
52 | |
53 static void addOriginAccessWhitelistEntry(const SecurityOrigin& sourceOrigin , const String& destinationProtocol, const String& destinationDomain, bool allow DestinationSubdomains); | |
54 static void removeOriginAccessWhitelistEntry(const SecurityOrigin& sourceOri gin, const String& destinationProtocol, const String& destinationDomain, bool al lowDestinationSubdomains); | |
55 static void resetOriginAccessWhitelists(); | |
56 | |
57 static bool isAccessWhiteListed(const SecurityOrigin* activeOrigin, const Se curityOrigin* targetOrigin); | |
58 static bool isAccessToURLWhiteListed(const SecurityOrigin* activeOrigin, con st KURL&); | |
59 }; | 50 }; |
60 | 51 |
52 PLATFORM_EXPORT void computeDigest(HashAlgorithm, const char* digestable, size_t length, DigestValue& digestResult); | |
53 | |
54 } // namespace CryptoUtil | |
61 } // namespace WebCore | 55 } // namespace WebCore |
62 | 56 |
63 #endif // SecurityPolicy_h | 57 namespace WTF { |
58 | |
59 struct DigestValueHash { | |
60 static unsigned hash(const WebCore::CryptoUtil::DigestValue& v) | |
61 { | |
62 return StringHasher::computeHash(v.data(), v.size()); | |
63 } | |
64 static bool equal(const WebCore::CryptoUtil::DigestValue& a, const WebCore:: CryptoUtil::DigestValue& b) | |
65 { | |
66 return a == b; | |
67 }; | |
68 static const bool safeToCompareToEmptyOrDeleted = true; | |
69 }; | |
70 template <> | |
71 struct DefaultHash<WebCore::CryptoUtil::DigestValue> { | |
72 typedef DigestValueHash Hash; | |
73 }; | |
74 | |
75 template <> | |
76 struct DefaultHash<WebCore::CryptoUtil::HashAlgorithm> { | |
77 typedef IntHash<WebCore::CryptoUtil::HashAlgorithm> Hash; | |
78 }; | |
79 template <> | |
80 struct HashTraits<WebCore::CryptoUtil::HashAlgorithm> : UnsignedWithZeroKeyHashT raits<WebCore::CryptoUtil::HashAlgorithm> { | |
81 }; | |
82 | |
83 } // namespace WTF | |
84 #endif // CryptoUtilities_h | |
OLD | NEW |