OLD | NEW |
---|---|
1 // Copyright 2014 The Chromium Authors. All rights reserved. | 1 // Copyright 2014 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "chrome/browser/supervised_user/supervised_user_service.h" | 5 #include "chrome/browser/supervised_user/supervised_user_service.h" |
6 | 6 |
7 #include <utility> | 7 #include <utility> |
8 | 8 |
9 #include "base/command_line.h" | 9 #include "base/command_line.h" |
10 #include "base/feature_list.h" | |
10 #include "base/files/file_path.h" | 11 #include "base/files/file_path.h" |
11 #include "base/files/file_util.h" | 12 #include "base/files/file_util.h" |
12 #include "base/memory/ref_counted.h" | 13 #include "base/memory/ref_counted.h" |
13 #include "base/path_service.h" | 14 #include "base/path_service.h" |
14 #include "base/strings/stringprintf.h" | 15 #include "base/strings/stringprintf.h" |
15 #include "base/strings/utf_string_conversions.h" | 16 #include "base/strings/utf_string_conversions.h" |
16 #include "base/task_runner_util.h" | 17 #include "base/task_runner_util.h" |
17 #include "base/version.h" | 18 #include "base/version.h" |
18 #include "build/build_config.h" | 19 #include "build/build_config.h" |
19 #include "chrome/browser/browser_process.h" | 20 #include "chrome/browser/browser_process.h" |
20 #include "chrome/browser/component_updater/supervised_user_whitelist_installer.h " | 21 #include "chrome/browser/component_updater/supervised_user_whitelist_installer.h " |
21 #include "chrome/browser/profiles/profile.h" | 22 #include "chrome/browser/profiles/profile.h" |
22 #include "chrome/browser/profiles/profile_attributes_entry.h" | 23 #include "chrome/browser/profiles/profile_attributes_entry.h" |
23 #include "chrome/browser/profiles/profile_attributes_storage.h" | 24 #include "chrome/browser/profiles/profile_attributes_storage.h" |
24 #include "chrome/browser/profiles/profile_manager.h" | 25 #include "chrome/browser/profiles/profile_manager.h" |
25 #include "chrome/browser/signin/profile_oauth2_token_service_factory.h" | 26 #include "chrome/browser/signin/profile_oauth2_token_service_factory.h" |
26 #include "chrome/browser/signin/signin_manager_factory.h" | 27 #include "chrome/browser/signin/signin_manager_factory.h" |
27 #include "chrome/browser/supervised_user/experimental/supervised_user_filtering_ switches.h" | 28 #include "chrome/browser/supervised_user/experimental/supervised_user_filtering_ switches.h" |
28 #include "chrome/browser/supervised_user/permission_request_creator.h" | 29 #include "chrome/browser/supervised_user/permission_request_creator.h" |
29 #include "chrome/browser/supervised_user/supervised_user_constants.h" | 30 #include "chrome/browser/supervised_user/supervised_user_constants.h" |
31 #include "chrome/browser/supervised_user/supervised_user_features.h" | |
30 #include "chrome/browser/supervised_user/supervised_user_service_observer.h" | 32 #include "chrome/browser/supervised_user/supervised_user_service_observer.h" |
31 #include "chrome/browser/supervised_user/supervised_user_settings_service.h" | 33 #include "chrome/browser/supervised_user/supervised_user_settings_service.h" |
32 #include "chrome/browser/supervised_user/supervised_user_settings_service_factor y.h" | 34 #include "chrome/browser/supervised_user/supervised_user_settings_service_factor y.h" |
33 #include "chrome/browser/supervised_user/supervised_user_site_list.h" | 35 #include "chrome/browser/supervised_user/supervised_user_site_list.h" |
34 #include "chrome/browser/supervised_user/supervised_user_whitelist_service.h" | 36 #include "chrome/browser/supervised_user/supervised_user_whitelist_service.h" |
35 #include "chrome/browser/sync/profile_sync_service_factory.h" | 37 #include "chrome/browser/sync/profile_sync_service_factory.h" |
36 #include "chrome/browser/ui/browser.h" | 38 #include "chrome/browser/ui/browser.h" |
37 #include "chrome/browser/ui/browser_list.h" | 39 #include "chrome/browser/ui/browser_list.h" |
38 #include "chrome/common/chrome_paths.h" | 40 #include "chrome/common/chrome_paths.h" |
39 #include "chrome/common/chrome_switches.h" | 41 #include "chrome/common/chrome_switches.h" |
40 #include "chrome/common/pref_names.h" | 42 #include "chrome/common/pref_names.h" |
41 #include "chrome/grit/generated_resources.h" | 43 #include "chrome/grit/generated_resources.h" |
42 #include "components/browser_sync/browser/profile_sync_service.h" | 44 #include "components/browser_sync/browser/profile_sync_service.h" |
43 #include "components/pref_registry/pref_registry_syncable.h" | 45 #include "components/pref_registry/pref_registry_syncable.h" |
44 #include "components/prefs/pref_service.h" | 46 #include "components/prefs/pref_service.h" |
45 #include "components/signin/core/browser/profile_oauth2_token_service.h" | 47 #include "components/signin/core/browser/profile_oauth2_token_service.h" |
46 #include "components/signin/core/browser/signin_manager.h" | 48 #include "components/signin/core/browser/signin_manager.h" |
47 #include "components/signin/core/browser/signin_manager_base.h" | 49 #include "components/signin/core/browser/signin_manager_base.h" |
48 #include "components/signin/core/common/signin_switches.h" | 50 #include "components/signin/core/common/signin_switches.h" |
49 #include "content/public/browser/browser_thread.h" | 51 #include "content/public/browser/browser_thread.h" |
50 #include "content/public/browser/user_metrics.h" | 52 #include "content/public/browser/user_metrics.h" |
53 #include "extensions/browser/extension_registry.h" | |
51 #include "ui/base/l10n/l10n_util.h" | 54 #include "ui/base/l10n/l10n_util.h" |
52 | 55 |
53 #if !defined(OS_ANDROID) | 56 #if !defined(OS_ANDROID) |
54 #include "chrome/browser/supervised_user/legacy/custodian_profile_downloader_ser vice.h" | 57 #include "chrome/browser/supervised_user/legacy/custodian_profile_downloader_ser vice.h" |
55 #include "chrome/browser/supervised_user/legacy/custodian_profile_downloader_ser vice_factory.h" | 58 #include "chrome/browser/supervised_user/legacy/custodian_profile_downloader_ser vice_factory.h" |
56 #include "chrome/browser/supervised_user/legacy/permission_request_creator_sync. h" | 59 #include "chrome/browser/supervised_user/legacy/permission_request_creator_sync. h" |
57 #include "chrome/browser/supervised_user/legacy/supervised_user_pref_mapping_ser vice.h" | 60 #include "chrome/browser/supervised_user/legacy/supervised_user_pref_mapping_ser vice.h" |
58 #include "chrome/browser/supervised_user/legacy/supervised_user_pref_mapping_ser vice_factory.h" | 61 #include "chrome/browser/supervised_user/legacy/supervised_user_pref_mapping_ser vice_factory.h" |
59 #include "chrome/browser/supervised_user/legacy/supervised_user_registration_uti lity.h" | 62 #include "chrome/browser/supervised_user/legacy/supervised_user_registration_uti lity.h" |
60 #include "chrome/browser/supervised_user/legacy/supervised_user_shared_settings_ service_factory.h" | 63 #include "chrome/browser/supervised_user/legacy/supervised_user_shared_settings_ service_factory.h" |
61 #endif | 64 #endif |
62 | 65 |
63 #if defined(OS_CHROMEOS) | 66 #if defined(OS_CHROMEOS) |
64 #include "chrome/browser/chromeos/login/users/chrome_user_manager.h" | 67 #include "chrome/browser/chromeos/login/users/chrome_user_manager.h" |
65 #include "chrome/browser/chromeos/login/users/supervised_user_manager.h" | 68 #include "chrome/browser/chromeos/login/users/supervised_user_manager.h" |
66 #include "components/user_manager/user_manager.h" | 69 #include "components/user_manager/user_manager.h" |
67 #endif | 70 #endif |
68 | 71 |
69 #if defined(ENABLE_EXTENSIONS) | 72 #if defined(ENABLE_EXTENSIONS) |
70 #include "chrome/browser/extensions/extension_service.h" | 73 #include "chrome/browser/extensions/extension_service.h" |
74 #include "chrome/browser/extensions/extension_sync_service.h" | |
Marc Treib
2016/06/07 10:27:03
Not needed?
mamir
2016/06/07 17:00:07
Done.
| |
75 #include "chrome/browser/extensions/extension_util.h" | |
76 #include "chrome/browser/supervised_user/supervised_user_service_factory.h" | |
77 #include "extensions/browser/extension_prefs.h" | |
71 #include "extensions/browser/extension_system.h" | 78 #include "extensions/browser/extension_system.h" |
72 #endif | 79 #endif |
73 | 80 |
74 #if defined(ENABLE_THEMES) | 81 #if defined(ENABLE_THEMES) |
75 #include "chrome/browser/themes/theme_service.h" | 82 #include "chrome/browser/themes/theme_service.h" |
76 #include "chrome/browser/themes/theme_service_factory.h" | 83 #include "chrome/browser/themes/theme_service_factory.h" |
77 #endif | 84 #endif |
78 | 85 |
79 using base::DictionaryValue; | 86 using base::DictionaryValue; |
80 using base::UserMetricsAction; | 87 using base::UserMetricsAction; |
81 using content::BrowserThread; | 88 using content::BrowserThread; |
89 using extensions::Extension; | |
90 using extensions::ExtensionPrefs; | |
91 using extensions::ExtensionSystem; | |
82 | 92 |
83 namespace { | 93 namespace { |
84 | 94 |
85 // The URL from which to download a host blacklist if no local one exists yet. | 95 // The URL from which to download a host blacklist if no local one exists yet. |
86 const char kBlacklistURL[] = | 96 const char kBlacklistURL[] = |
87 "https://www.gstatic.com/chrome/supervised_user/blacklist-20141001-1k.bin"; | 97 "https://www.gstatic.com/chrome/supervised_user/blacklist-20141001-1k.bin"; |
88 // The filename under which we'll store the blacklist (in the user data dir). | 98 // The filename under which we'll store the blacklist (in the user data dir). |
89 const char kBlacklistFilename[] = "su-blacklist.bin"; | 99 const char kBlacklistFilename[] = "su-blacklist.bin"; |
90 | 100 |
91 const char* const kCustodianInfoPrefs[] = { | 101 const char* const kCustodianInfoPrefs[] = { |
92 prefs::kSupervisedUserCustodianName, | 102 prefs::kSupervisedUserCustodianName, |
93 prefs::kSupervisedUserCustodianEmail, | 103 prefs::kSupervisedUserCustodianEmail, |
94 prefs::kSupervisedUserCustodianProfileImageURL, | 104 prefs::kSupervisedUserCustodianProfileImageURL, |
95 prefs::kSupervisedUserCustodianProfileURL, | 105 prefs::kSupervisedUserCustodianProfileURL, |
96 prefs::kSupervisedUserSecondCustodianName, | 106 prefs::kSupervisedUserSecondCustodianName, |
97 prefs::kSupervisedUserSecondCustodianEmail, | 107 prefs::kSupervisedUserSecondCustodianEmail, |
98 prefs::kSupervisedUserSecondCustodianProfileImageURL, | 108 prefs::kSupervisedUserSecondCustodianProfileImageURL, |
99 prefs::kSupervisedUserSecondCustodianProfileURL, | 109 prefs::kSupervisedUserSecondCustodianProfileURL, |
100 }; | 110 }; |
101 | 111 |
102 void CreateURLAccessRequest( | 112 void CreateURLAccessRequest( |
103 const GURL& url, | 113 const GURL& url, |
104 PermissionRequestCreator* creator, | 114 PermissionRequestCreator* creator, |
105 const SupervisedUserService::SuccessCallback& callback) { | 115 const SupervisedUserService::SuccessCallback& callback) { |
106 creator->CreateURLAccessRequest(url, callback); | 116 creator->CreateURLAccessRequest(url, callback); |
107 } | 117 } |
108 | 118 |
119 void CreateExtensionInstallRequest( | |
120 const std::string& id, | |
121 PermissionRequestCreator* creator, | |
122 const SupervisedUserService::SuccessCallback& callback) { | |
123 creator->CreateExtensionInstallRequest(id, callback); | |
124 } | |
125 | |
109 void CreateExtensionUpdateRequest( | 126 void CreateExtensionUpdateRequest( |
110 const std::string& id, | 127 const std::string& id, |
111 PermissionRequestCreator* creator, | 128 PermissionRequestCreator* creator, |
112 const SupervisedUserService::SuccessCallback& callback) { | 129 const SupervisedUserService::SuccessCallback& callback) { |
113 creator->CreateExtensionUpdateRequest(id, callback); | 130 creator->CreateExtensionUpdateRequest(id, callback); |
114 } | 131 } |
115 | 132 |
133 // Default callback for AddExtensionInstallRequest. | |
134 void ExtensionInstallRequestSent(const std::string& id, bool success) { | |
135 VLOG_IF(1, !success) << "Failed sending install request for " << id; | |
136 } | |
137 | |
116 // Default callback for AddExtensionUpdateRequest. | 138 // Default callback for AddExtensionUpdateRequest. |
117 void ExtensionUpdateRequestSent(const std::string& id, bool success) { | 139 void ExtensionUpdateRequestSent(const std::string& id, bool success) { |
118 VLOG_IF(1, !success) << "Failed sending update request for " << id; | 140 VLOG_IF(1, !success) << "Failed sending update request for " << id; |
119 } | 141 } |
120 | 142 |
121 base::FilePath GetBlacklistPath() { | 143 base::FilePath GetBlacklistPath() { |
122 base::FilePath blacklist_dir; | 144 base::FilePath blacklist_dir; |
123 PathService::Get(chrome::DIR_USER_DATA, &blacklist_dir); | 145 PathService::Get(chrome::DIR_USER_DATA, &blacklist_dir); |
124 return blacklist_dir.AppendASCII(kBlacklistFilename); | 146 return blacklist_dir.AppendASCII(kBlacklistFilename); |
125 } | 147 } |
126 | |
127 #if defined(ENABLE_EXTENSIONS) | |
128 enum ExtensionState { | |
129 EXTENSION_FORCED, | |
130 EXTENSION_BLOCKED, | |
131 EXTENSION_ALLOWED | |
132 }; | |
133 | |
134 ExtensionState GetExtensionState(const extensions::Extension* extension) { | |
135 bool was_installed_by_default = extension->was_installed_by_default(); | |
136 #if defined(OS_CHROMEOS) | |
137 // On Chrome OS all external sources are controlled by us so it means that | |
138 // they are "default". Method was_installed_by_default returns false because | |
139 // extensions creation flags are ignored in case of default extensions with | |
140 // update URL(the flags aren't passed to OnExternalExtensionUpdateUrlFound). | |
141 // TODO(dpolukhin): remove this Chrome OS specific code as soon as creation | |
142 // flags are not ignored. | |
143 was_installed_by_default = | |
144 extensions::Manifest::IsExternalLocation(extension->location()); | |
145 #endif | |
146 // Note: Component extensions are protected from modification/uninstallation | |
147 // anyway, so there's no need to enforce them again for supervised users. | |
148 // Also, leave policy-installed extensions alone - they have their own | |
149 // management; in particular we don't want to override the force-install list. | |
150 if (extensions::Manifest::IsComponentLocation(extension->location()) || | |
151 extensions::Manifest::IsPolicyLocation(extension->location()) || | |
152 extension->is_theme() || | |
153 extension->from_bookmark() || | |
154 extension->is_shared_module() || | |
155 was_installed_by_default) { | |
156 return EXTENSION_ALLOWED; | |
157 } | |
158 | |
159 if (extension->was_installed_by_custodian()) | |
160 return EXTENSION_FORCED; | |
161 | |
162 return EXTENSION_BLOCKED; | |
163 } | |
164 #endif | |
165 | |
166 } // namespace | 148 } // namespace |
167 | 149 |
168 SupervisedUserService::~SupervisedUserService() { | 150 SupervisedUserService::~SupervisedUserService() { |
169 DCHECK(!did_init_ || did_shutdown_); | 151 DCHECK(!did_init_ || did_shutdown_); |
170 url_filter_context_.ui_url_filter()->RemoveObserver(this); | 152 url_filter_context_.ui_url_filter()->RemoveObserver(this); |
171 } | 153 } |
172 | 154 |
173 // static | 155 // static |
174 void SupervisedUserService::RegisterProfilePrefs( | 156 void SupervisedUserService::RegisterProfilePrefs( |
175 user_prefs::PrefRegistrySyncable* registry) { | 157 user_prefs::PrefRegistrySyncable* registry) { |
158 registry->RegisterDictionaryPref(prefs::kSupervisedUserApprovedExtensions); | |
176 registry->RegisterDictionaryPref(prefs::kSupervisedUserManualHosts); | 159 registry->RegisterDictionaryPref(prefs::kSupervisedUserManualHosts); |
177 registry->RegisterDictionaryPref(prefs::kSupervisedUserManualURLs); | 160 registry->RegisterDictionaryPref(prefs::kSupervisedUserManualURLs); |
178 registry->RegisterIntegerPref(prefs::kDefaultSupervisedUserFilteringBehavior, | 161 registry->RegisterIntegerPref(prefs::kDefaultSupervisedUserFilteringBehavior, |
179 SupervisedUserURLFilter::ALLOW); | 162 SupervisedUserURLFilter::ALLOW); |
180 registry->RegisterBooleanPref(prefs::kSupervisedUserCreationAllowed, true); | 163 registry->RegisterBooleanPref(prefs::kSupervisedUserCreationAllowed, true); |
181 registry->RegisterBooleanPref(prefs::kSupervisedUserSafeSites, true); | 164 registry->RegisterBooleanPref(prefs::kSupervisedUserSafeSites, true); |
182 for (const char* pref : kCustodianInfoPrefs) { | 165 for (const char* pref : kCustodianInfoPrefs) { |
183 registry->RegisterStringPref(pref, std::string()); | 166 registry->RegisterStringPref(pref, std::string()); |
184 } | 167 } |
185 } | 168 } |
(...skipping 70 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
256 } | 239 } |
257 | 240 |
258 void SupervisedUserService::ReportURL(const GURL& url, | 241 void SupervisedUserService::ReportURL(const GURL& url, |
259 const SuccessCallback& callback) { | 242 const SuccessCallback& callback) { |
260 if (url_reporter_) | 243 if (url_reporter_) |
261 url_reporter_->ReportUrl(url, callback); | 244 url_reporter_->ReportUrl(url, callback); |
262 else | 245 else |
263 callback.Run(false); | 246 callback.Run(false); |
264 } | 247 } |
265 | 248 |
249 void SupervisedUserService::AddExtensionInstallRequest( | |
250 const std::string& extension_id, | |
251 const base::Version& version, | |
252 const SuccessCallback& callback) { | |
253 std::string id = GetExtensionRequestId(extension_id, version); | |
254 AddPermissionRequestInternal(base::Bind(CreateExtensionInstallRequest, id), | |
255 callback, 0); | |
256 } | |
257 | |
258 void SupervisedUserService::AddExtensionInstallRequest( | |
259 const std::string& extension_id, | |
260 const base::Version& version) { | |
261 std::string id = GetExtensionRequestId(extension_id, version); | |
262 AddPermissionRequestInternal(base::Bind(CreateExtensionInstallRequest, id), | |
263 base::Bind(ExtensionInstallRequestSent, id), 0); | |
264 } | |
265 | |
266 void SupervisedUserService::AddExtensionUpdateRequest( | 266 void SupervisedUserService::AddExtensionUpdateRequest( |
267 const std::string& extension_id, | 267 const std::string& extension_id, |
268 const base::Version& version, | 268 const base::Version& version, |
269 const SuccessCallback& callback) { | 269 const SuccessCallback& callback) { |
270 std::string id = GetExtensionUpdateRequestId(extension_id, version); | 270 std::string id = GetExtensionRequestId(extension_id, version); |
271 AddPermissionRequestInternal( | 271 AddPermissionRequestInternal( |
272 base::Bind(CreateExtensionUpdateRequest, id), callback, 0); | 272 base::Bind(CreateExtensionUpdateRequest, id), callback, 0); |
273 } | 273 } |
274 | 274 |
275 void SupervisedUserService::AddExtensionUpdateRequest( | 275 void SupervisedUserService::AddExtensionUpdateRequest( |
276 const std::string& extension_id, | 276 const std::string& extension_id, |
277 const base::Version& version) { | 277 const base::Version& version) { |
278 std::string id = GetExtensionUpdateRequestId(extension_id, version); | 278 std::string id = GetExtensionRequestId(extension_id, version); |
279 AddExtensionUpdateRequest(extension_id, version, | 279 AddExtensionUpdateRequest(extension_id, version, |
280 base::Bind(ExtensionUpdateRequestSent, id)); | 280 base::Bind(ExtensionUpdateRequestSent, id)); |
281 } | 281 } |
282 | 282 |
283 void SupervisedUserService::UpdateApprovedExtensionVersion( | |
284 const std::string& extension_id, | |
285 const base::Version& version) { | |
286 approved_extensions_map_[extension_id] = version; | |
Marc Treib
2016/06/07 10:27:03
wrong indent
Marc Treib
2016/06/07 10:27:04
You also need to update the corresponding SU setti
mamir
2016/06/07 17:00:06
Done.
mamir
2016/06/07 17:00:07
Done.
| |
287 EnableExtensionIfPossible(extension_id); | |
288 } | |
289 | |
290 void SupervisedUserService::EnableExtensionIfPossible( | |
291 const std::string& extension_id) { | |
292 ExtensionService* service = | |
293 ExtensionSystem::Get(profile_)->extension_service(); | |
294 ExtensionPrefs* extension_prefs = ExtensionPrefs::Get(profile_); | |
295 // Check if the extension was pending custodian approval. | |
296 if (extension_prefs->HasDisableReason( | |
297 extension_id, Extension::DISABLE_CUSTODIAN_APPROVAL_REQUIRED)) { | |
298 extension_prefs->RemoveDisableReason( | |
299 extension_id, Extension::DISABLE_CUSTODIAN_APPROVAL_REQUIRED); | |
300 // If no other disable reasons, enable it. | |
301 if (!extension_prefs->GetDisableReasons(extension_id)) { | |
302 // Try to enable the extension, this will call the ManagmentPolicy and | |
303 // properly enable the extension if possible. | |
304 service->EnableExtension(extension_id); | |
305 } | |
306 } | |
307 } | |
308 | |
283 // static | 309 // static |
284 std::string SupervisedUserService::GetExtensionUpdateRequestId( | 310 std::string SupervisedUserService::GetExtensionRequestId( |
285 const std::string& extension_id, | 311 const std::string& extension_id, |
286 const base::Version& version) { | 312 const base::Version& version) { |
287 return base::StringPrintf("%s:%s", extension_id.c_str(), | 313 return base::StringPrintf("%s:%s", extension_id.c_str(), |
288 version.GetString().c_str()); | 314 version.GetString().c_str()); |
289 } | 315 } |
290 | 316 |
291 std::string SupervisedUserService::GetCustodianEmailAddress() const { | 317 std::string SupervisedUserService::GetCustodianEmailAddress() const { |
292 std::string email = profile_->GetPrefs()->GetString( | 318 std::string email = profile_->GetPrefs()->GetString( |
293 prefs::kSupervisedUserCustodianEmail); | 319 prefs::kSupervisedUserCustodianEmail); |
294 #if defined(OS_CHROMEOS) | 320 #if defined(OS_CHROMEOS) |
(...skipping 221 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
516 profile_(profile), | 542 profile_(profile), |
517 active_(false), | 543 active_(false), |
518 delegate_(NULL), | 544 delegate_(NULL), |
519 waiting_for_sync_initialization_(false), | 545 waiting_for_sync_initialization_(false), |
520 is_profile_active_(false), | 546 is_profile_active_(false), |
521 did_init_(false), | 547 did_init_(false), |
522 did_shutdown_(false), | 548 did_shutdown_(false), |
523 blacklist_state_(BlacklistLoadState::NOT_LOADED), | 549 blacklist_state_(BlacklistLoadState::NOT_LOADED), |
524 weak_ptr_factory_(this) { | 550 weak_ptr_factory_(this) { |
525 url_filter_context_.ui_url_filter()->AddObserver(this); | 551 url_filter_context_.ui_url_filter()->AddObserver(this); |
552 extensions::ExtensionRegistry::Get(profile)->AddObserver(this); | |
526 } | 553 } |
527 | 554 |
528 void SupervisedUserService::SetActive(bool active) { | 555 void SupervisedUserService::SetActive(bool active) { |
529 if (active_ == active) | 556 if (active_ == active) |
530 return; | 557 return; |
531 active_ = active; | 558 active_ = active; |
532 | 559 |
533 if (!delegate_ || !delegate_->SetActive(active_)) { | 560 if (!delegate_ || !delegate_->SetActive(active_)) { |
534 if (active_) { | 561 if (active_) { |
535 #if !defined(OS_ANDROID) | 562 #if !defined(OS_ANDROID) |
(...skipping 44 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
580 | 607 |
581 #if defined(ENABLE_EXTENSIONS) | 608 #if defined(ENABLE_EXTENSIONS) |
582 SetExtensionsActive(); | 609 SetExtensionsActive(); |
583 #endif | 610 #endif |
584 | 611 |
585 if (active_) { | 612 if (active_) { |
586 pref_change_registrar_.Add( | 613 pref_change_registrar_.Add( |
587 prefs::kDefaultSupervisedUserFilteringBehavior, | 614 prefs::kDefaultSupervisedUserFilteringBehavior, |
588 base::Bind(&SupervisedUserService::OnDefaultFilteringBehaviorChanged, | 615 base::Bind(&SupervisedUserService::OnDefaultFilteringBehaviorChanged, |
589 base::Unretained(this))); | 616 base::Unretained(this))); |
617 pref_change_registrar_.Add( | |
618 prefs::kSupervisedUserApprovedExtensions, | |
619 base::Bind(&SupervisedUserService::UpdateApprovedExtensions, | |
620 base::Unretained(this))); | |
590 pref_change_registrar_.Add(prefs::kSupervisedUserSafeSites, | 621 pref_change_registrar_.Add(prefs::kSupervisedUserSafeSites, |
591 base::Bind(&SupervisedUserService::OnSafeSitesSettingChanged, | 622 base::Bind(&SupervisedUserService::OnSafeSitesSettingChanged, |
592 base::Unretained(this))); | 623 base::Unretained(this))); |
593 pref_change_registrar_.Add(prefs::kSupervisedUserManualHosts, | 624 pref_change_registrar_.Add(prefs::kSupervisedUserManualHosts, |
594 base::Bind(&SupervisedUserService::UpdateManualHosts, | 625 base::Bind(&SupervisedUserService::UpdateManualHosts, |
595 base::Unretained(this))); | 626 base::Unretained(this))); |
596 pref_change_registrar_.Add(prefs::kSupervisedUserManualURLs, | 627 pref_change_registrar_.Add(prefs::kSupervisedUserManualURLs, |
597 base::Bind(&SupervisedUserService::UpdateManualURLs, | 628 base::Bind(&SupervisedUserService::UpdateManualURLs, |
598 base::Unretained(this))); | 629 base::Unretained(this))); |
599 for (const char* pref : kCustodianInfoPrefs) { | 630 for (const char* pref : kCustodianInfoPrefs) { |
600 pref_change_registrar_.Add(pref, | 631 pref_change_registrar_.Add(pref, |
601 base::Bind(&SupervisedUserService::OnCustodianInfoChanged, | 632 base::Bind(&SupervisedUserService::OnCustodianInfoChanged, |
602 base::Unretained(this))); | 633 base::Unretained(this))); |
603 } | 634 } |
604 | 635 |
605 // Initialize the filter. | 636 // Initialize the filter. |
606 OnDefaultFilteringBehaviorChanged(); | 637 OnDefaultFilteringBehaviorChanged(); |
607 OnSafeSitesSettingChanged(); | 638 OnSafeSitesSettingChanged(); |
608 whitelist_service_->Init(); | 639 whitelist_service_->Init(); |
609 UpdateManualHosts(); | 640 UpdateManualHosts(); |
610 UpdateManualURLs(); | 641 UpdateManualURLs(); |
642 UpdateApprovedExtensions(); | |
611 | 643 |
612 #if !defined(OS_ANDROID) | 644 #if !defined(OS_ANDROID) |
613 // TODO(bauerb): Get rid of the platform-specific #ifdef here. | 645 // TODO(bauerb): Get rid of the platform-specific #ifdef here. |
614 // http://crbug.com/313377 | 646 // http://crbug.com/313377 |
615 BrowserList::AddObserver(this); | 647 BrowserList::AddObserver(this); |
616 #endif | 648 #endif |
617 } else { | 649 } else { |
618 permissions_creators_.clear(); | 650 permissions_creators_.clear(); |
619 url_reporter_.reset(); | 651 url_reporter_.reset(); |
620 | 652 |
621 pref_change_registrar_.Remove( | 653 pref_change_registrar_.Remove( |
622 prefs::kDefaultSupervisedUserFilteringBehavior); | 654 prefs::kDefaultSupervisedUserFilteringBehavior); |
655 pref_change_registrar_.Remove(prefs::kSupervisedUserApprovedExtensions); | |
623 pref_change_registrar_.Remove(prefs::kSupervisedUserManualHosts); | 656 pref_change_registrar_.Remove(prefs::kSupervisedUserManualHosts); |
624 pref_change_registrar_.Remove(prefs::kSupervisedUserManualURLs); | 657 pref_change_registrar_.Remove(prefs::kSupervisedUserManualURLs); |
625 for (const char* pref : kCustodianInfoPrefs) { | 658 for (const char* pref : kCustodianInfoPrefs) { |
626 pref_change_registrar_.Remove(pref); | 659 pref_change_registrar_.Remove(pref); |
627 } | 660 } |
628 | 661 |
629 url_filter_context_.Clear(); | 662 url_filter_context_.Clear(); |
630 FOR_EACH_OBSERVER( | 663 FOR_EACH_OBSERVER( |
631 SupervisedUserServiceObserver, observer_list_, OnURLFilterChanged()); | 664 SupervisedUserServiceObserver, observer_list_, OnURLFilterChanged()); |
632 | 665 |
(...skipping 275 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
908 bool result = it.value().GetAsBoolean(&allow); | 941 bool result = it.value().GetAsBoolean(&allow); |
909 DCHECK(result); | 942 DCHECK(result); |
910 (*url_map)[GURL(it.key())] = allow; | 943 (*url_map)[GURL(it.key())] = allow; |
911 } | 944 } |
912 url_filter_context_.SetManualURLs(std::move(url_map)); | 945 url_filter_context_.SetManualURLs(std::move(url_map)); |
913 | 946 |
914 FOR_EACH_OBSERVER( | 947 FOR_EACH_OBSERVER( |
915 SupervisedUserServiceObserver, observer_list_, OnURLFilterChanged()); | 948 SupervisedUserServiceObserver, observer_list_, OnURLFilterChanged()); |
916 } | 949 } |
917 | 950 |
951 void SupervisedUserService::UpdateApprovedExtensions() { | |
952 const base::DictionaryValue* dict = profile_->GetPrefs()->GetDictionary( | |
953 prefs::kSupervisedUserApprovedExtensions); | |
954 approved_extensions_map_.clear(); | |
955 for (base::DictionaryValue::Iterator it(*dict); !it.IsAtEnd(); it.Advance()) { | |
956 std::string version_str; | |
957 bool result = it.value().GetAsString(&version_str); | |
958 DCHECK(result); | |
959 base::Version version = base::Version(version_str); | |
Marc Treib
2016/06/07 10:27:03
Just
base::Version version(version_str);
mamir
2016/06/07 17:00:07
Done.
| |
960 if (version.IsValid()) | |
961 approved_extensions_map_[it.key()] = version; | |
962 else | |
963 LOG(ERROR) << "Invalid version number " << version_str; | |
Marc Treib
2016/06/07 10:27:04
DLOG(WARNING) should be enough
mamir
2016/06/07 17:00:07
Done.
| |
964 } | |
965 | |
966 for (const auto& extensions_entry : approved_extensions_map_) { | |
967 EnableExtensionIfPossible(extensions_entry.first); | |
968 } | |
969 } | |
970 | |
918 std::string SupervisedUserService::GetSupervisedUserName() const { | 971 std::string SupervisedUserService::GetSupervisedUserName() const { |
919 #if defined(OS_CHROMEOS) | 972 #if defined(OS_CHROMEOS) |
920 // The active user can be NULL in unit tests. | 973 // The active user can be NULL in unit tests. |
921 if (user_manager::UserManager::Get()->GetActiveUser()) { | 974 if (user_manager::UserManager::Get()->GetActiveUser()) { |
922 return UTF16ToUTF8(user_manager::UserManager::Get()->GetUserDisplayName( | 975 return UTF16ToUTF8(user_manager::UserManager::Get()->GetUserDisplayName( |
923 user_manager::UserManager::Get()->GetActiveUser()->GetAccountId())); | 976 user_manager::UserManager::Get()->GetActiveUser()->GetAccountId())); |
924 } | 977 } |
925 return std::string(); | 978 return std::string(); |
926 #else | 979 #else |
927 return profile_->GetPrefs()->GetString(prefs::kProfileName); | 980 return profile_->GetPrefs()->GetString(prefs::kProfileName); |
928 #endif | 981 #endif |
929 } | 982 } |
930 | 983 |
931 void SupervisedUserService::OnForceSessionSyncChanged() { | 984 void SupervisedUserService::OnForceSessionSyncChanged() { |
932 includes_sync_sessions_type_ = | 985 includes_sync_sessions_type_ = |
933 profile_->GetPrefs()->GetBoolean(prefs::kForceSessionSync); | 986 profile_->GetPrefs()->GetBoolean(prefs::kForceSessionSync); |
934 ProfileSyncServiceFactory::GetForProfile(profile_) | 987 ProfileSyncServiceFactory::GetForProfile(profile_) |
935 ->ReconfigureDatatypeManager(); | 988 ->ReconfigureDatatypeManager(); |
936 } | 989 } |
937 | 990 |
991 void SupervisedUserService::OnExtensionInstalled( | |
992 content::BrowserContext* browser_context, | |
993 const extensions::Extension* extension, | |
994 bool is_update) { | |
995 // This calls is responsible only for updating the approved version | |
Marc Treib
2016/06/07 10:27:04
"This call"
mamir
2016/06/07 17:00:07
Done.
| |
996 // upon extension update if it doesn't require extra permission, | |
997 // and sending an approval request when it requires extra permissions | |
998 if (!is_update) | |
999 return; | |
1000 | |
1001 ExtensionPrefs* extension_prefs = ExtensionPrefs::Get(profile_); | |
1002 const std::string& id = extension->id(); | |
1003 | |
1004 // If the extensions is disabled because it requires parent approval, | |
Marc Treib
2016/06/07 10:27:04
"the extension"
mamir
2016/06/07 17:00:07
Done.
| |
1005 // but it doesn't require new permissions, then it should be enabled if | |
1006 // it has been approved before. | |
1007 if (extension_prefs->HasDisableReason( | |
1008 id, Extension::DISABLE_CUSTODIAN_APPROVAL_REQUIRED) && | |
1009 !extension_prefs->HasDisableReason( | |
1010 id, Extension::DISABLE_PERMISSIONS_INCREASE) && | |
1011 approved_extensions_map_.count(id) > 0) { | |
1012 UpdateApprovedExtensionVersion(id, *extension->version()); | |
Marc Treib
2016/06/07 10:27:04
When exactly do we get here? When do we have CUSTO
mamir
2016/06/07 17:00:07
We get here when SupervisedUserService.MustRemainD
| |
1013 } | |
1014 } | |
1015 | |
938 void SupervisedUserService::Shutdown() { | 1016 void SupervisedUserService::Shutdown() { |
939 if (!did_init_) | 1017 if (!did_init_) |
940 return; | 1018 return; |
941 DCHECK(!did_shutdown_); | 1019 DCHECK(!did_shutdown_); |
942 did_shutdown_ = true; | 1020 did_shutdown_ = true; |
943 if (ProfileIsSupervised()) { | 1021 if (ProfileIsSupervised()) { |
944 content::RecordAction(UserMetricsAction("ManagedUsers_QuitBrowser")); | 1022 content::RecordAction(UserMetricsAction("ManagedUsers_QuitBrowser")); |
945 } | 1023 } |
946 SetActive(false); | 1024 SetActive(false); |
947 | 1025 |
948 ProfileSyncService* sync_service = | 1026 ProfileSyncService* sync_service = |
949 ProfileSyncServiceFactory::GetForProfile(profile_); | 1027 ProfileSyncServiceFactory::GetForProfile(profile_); |
950 | 1028 |
951 // Can be null in tests. | 1029 // Can be null in tests. |
952 if (sync_service) | 1030 if (sync_service) |
953 sync_service->RemovePreferenceProvider(this); | 1031 sync_service->RemovePreferenceProvider(this); |
954 } | 1032 } |
955 | 1033 |
956 #if defined(ENABLE_EXTENSIONS) | 1034 #if defined(ENABLE_EXTENSIONS) |
1035 SupervisedUserService::ExtensionState SupervisedUserService::GetExtensionState( | |
1036 const Extension& extension) const { | |
1037 bool was_installed_by_default = extension.was_installed_by_default(); | |
1038 #if defined(OS_CHROMEOS) | |
1039 // On Chrome OS all external sources are controlled by us so it means that | |
1040 // they are "default". Method was_installed_by_default returns false because | |
1041 // extensions creation flags are ignored in case of default extensions with | |
1042 // update URL(the flags aren't passed to OnExternalExtensionUpdateUrlFound). | |
1043 // TODO(dpolukhin): remove this Chrome OS specific code as soon as creation | |
1044 // flags are not ignored. | |
1045 was_installed_by_default = | |
1046 extensions::Manifest::IsExternalLocation(extension->location()); | |
1047 #endif | |
1048 // Note: Component extensions are protected from modification/uninstallation | |
1049 // anyway, so there's no need to enforce them again for supervised users. | |
1050 // Also, leave policy-installed extensions alone - they have their own | |
1051 // management; in particular we don't want to override the force-install list. | |
1052 if (extensions::Manifest::IsComponentLocation(extension.location()) || | |
1053 extensions::Manifest::IsPolicyLocation(extension.location()) || | |
1054 extension.is_theme() || extension.from_bookmark() || | |
1055 extension.is_shared_module() || was_installed_by_default) { | |
1056 return ExtensionState::ALLOWED; | |
1057 } | |
1058 | |
1059 if (extension.was_installed_by_custodian()) | |
1060 return ExtensionState::FORCED; | |
1061 | |
1062 // TODO(mamir): if(on blacklist) return BLOCKED; | |
1063 if (!base::FeatureList::IsEnabled( | |
1064 supervised_users::kSupervisedUserInitiatedExtensionInstall)) | |
1065 return ExtensionState::BLOCKED; | |
Marc Treib
2016/06/07 10:27:03
Braces please (the condition isn't on one line)
mamir
2016/06/07 17:00:07
Done.
| |
1066 | |
1067 const std::string& id = extension.id(); | |
1068 auto extension_it = approved_extensions_map_.find(extension.id()); | |
Marc Treib
2016/06/07 10:27:04
Either use the |id| var here, or just remove it an
mamir
2016/06/07 17:00:07
Done.
| |
1069 if (extension_it == approved_extensions_map_.end() || | |
1070 extension_it->second != *(extension.version())) { | |
1071 return ExtensionState::REQUIRE_APPROVAL; | |
1072 } | |
1073 ExtensionPrefs* extension_prefs = ExtensionPrefs::Get(profile_); | |
Marc Treib
2016/06/07 10:27:03
nit: empty line before, not after. Or just inline
mamir
2016/06/07 17:00:07
Done.
| |
1074 | |
1075 if (extension_prefs->HasDisableReason( | |
1076 id, Extension::DISABLE_PERMISSIONS_INCREASE)) | |
1077 return ExtensionState::REQUIRE_APPROVAL; | |
Marc Treib
2016/06/07 10:27:04
Also here, braces please
mamir
2016/06/07 17:00:07
Done.
| |
1078 | |
1079 return ExtensionState::ALLOWED; | |
1080 } | |
1081 | |
957 std::string SupervisedUserService::GetDebugPolicyProviderName() const { | 1082 std::string SupervisedUserService::GetDebugPolicyProviderName() const { |
958 // Save the string space in official builds. | 1083 // Save the string space in official builds. |
959 #ifdef NDEBUG | 1084 #ifdef NDEBUG |
960 NOTREACHED(); | 1085 NOTREACHED(); |
961 return std::string(); | 1086 return std::string(); |
962 #else | 1087 #else |
963 return "Supervised User Service"; | 1088 return "Supervised User Service"; |
964 #endif | 1089 #endif |
965 } | 1090 } |
966 | 1091 |
967 bool SupervisedUserService::UserMayLoad(const extensions::Extension* extension, | 1092 bool SupervisedUserService::UserMayLoad(const Extension* extension, |
968 base::string16* error) const { | 1093 base::string16* error) const { |
969 DCHECK(ProfileIsSupervised()); | 1094 DCHECK(ProfileIsSupervised()); |
970 ExtensionState result = GetExtensionState(extension); | 1095 ExtensionState result = GetExtensionState(*extension); |
971 bool may_load = (result != EXTENSION_BLOCKED); | 1096 bool may_load = (result != ExtensionState::BLOCKED); |
972 if (!may_load && error) | 1097 if (!may_load && error) |
973 *error = GetExtensionsLockedMessage(); | 1098 *error = GetExtensionsLockedMessage(); |
974 return may_load; | 1099 return may_load; |
975 } | 1100 } |
976 | 1101 |
977 bool SupervisedUserService::UserMayModifySettings( | 1102 bool SupervisedUserService::UserMayModifySettings(const Extension* extension, |
978 const extensions::Extension* extension, | 1103 base::string16* error) const { |
979 base::string16* error) const { | |
980 DCHECK(ProfileIsSupervised()); | 1104 DCHECK(ProfileIsSupervised()); |
981 ExtensionState result = GetExtensionState(extension); | 1105 ExtensionState result = GetExtensionState(*extension); |
982 bool may_modify = (result == EXTENSION_ALLOWED); | 1106 // While the following check allows the SU to modify the settings and enable |
1107 // or disable the extension, MustRemainDisabled properly takes care of | |
1108 // keeping an extension disabled when required. | |
1109 // For custodian-installed extensions, the state is always FORCED, even if | |
1110 // it's waiting for an update approval. | |
1111 bool may_modify = (result != ExtensionState::FORCED); | |
983 if (!may_modify && error) | 1112 if (!may_modify && error) |
984 *error = GetExtensionsLockedMessage(); | 1113 *error = GetExtensionsLockedMessage(); |
985 return may_modify; | 1114 return may_modify; |
986 } | 1115 } |
987 | 1116 |
988 // Note: Having MustRemainInstalled always say "true" for custodian-installed | 1117 // Note: Having MustRemainInstalled always say "true" for custodian-installed |
989 // extensions does NOT prevent remote uninstalls (which is a bit unexpected, but | 1118 // extensions does NOT prevent remote uninstalls (which is a bit unexpected, but |
990 // exactly what we want). | 1119 // exactly what we want). |
991 bool SupervisedUserService::MustRemainInstalled( | 1120 bool SupervisedUserService::MustRemainInstalled(const Extension* extension, |
992 const extensions::Extension* extension, | 1121 base::string16* error) const { |
993 base::string16* error) const { | |
994 DCHECK(ProfileIsSupervised()); | 1122 DCHECK(ProfileIsSupervised()); |
995 ExtensionState result = GetExtensionState(extension); | 1123 ExtensionState result = GetExtensionState(*extension); |
996 bool may_not_uninstall = (result == EXTENSION_FORCED); | 1124 bool may_not_uninstall = (result == ExtensionState::FORCED); |
997 if (may_not_uninstall && error) | 1125 if (may_not_uninstall && error) |
998 *error = GetExtensionsLockedMessage(); | 1126 *error = GetExtensionsLockedMessage(); |
999 return may_not_uninstall; | 1127 return may_not_uninstall; |
1000 } | 1128 } |
1001 | 1129 |
1130 bool SupervisedUserService::MustRemainDisabled(const Extension* extension, | |
1131 Extension::DisableReason* reason, | |
1132 base::string16* error) const { | |
1133 DCHECK(ProfileIsSupervised()); | |
1134 ExtensionState state = GetExtensionState(*extension); | |
1135 bool must_remain_disabled = (state == ExtensionState::BLOCKED) || | |
1136 (state == ExtensionState::REQUIRE_APPROVAL); | |
1137 | |
1138 if (must_remain_disabled) { | |
1139 if (reason) | |
1140 *reason = Extension::DISABLE_CUSTODIAN_APPROVAL_REQUIRED; | |
1141 if (error) | |
1142 *error = l10n_util::GetStringUTF16(IDS_EXTENSIONS_LOCKED_SUPERVISED_USER); | |
1143 if (base::FeatureList::IsEnabled( | |
1144 supervised_users::kSupervisedUserInitiatedExtensionInstall)) { | |
1145 // If the Extension isn't pending a custodian approval already, send | |
1146 // an approval request. | |
1147 ExtensionPrefs* extension_prefs = ExtensionPrefs::Get(profile_); | |
1148 if (!extension_prefs->HasDisableReason( | |
1149 extension->id(), | |
1150 Extension::DISABLE_CUSTODIAN_APPROVAL_REQUIRED)) { | |
1151 // MustRemainDisabled is a const method and hence cannot call | |
1152 // AddExtensionInstallRequest directly. | |
1153 SupervisedUserService* supervised_user_service = | |
1154 SupervisedUserServiceFactory::GetForProfile(profile_); | |
1155 supervised_user_service->AddExtensionInstallRequest( | |
1156 extension->id(), *extension->version()); | |
1157 } | |
1158 } | |
1159 } | |
1160 return must_remain_disabled; | |
1161 } | |
1162 | |
1002 void SupervisedUserService::SetExtensionsActive() { | 1163 void SupervisedUserService::SetExtensionsActive() { |
1003 extensions::ExtensionSystem* extension_system = | 1164 extensions::ExtensionSystem* extension_system = |
1004 extensions::ExtensionSystem::Get(profile_); | 1165 extensions::ExtensionSystem::Get(profile_); |
1005 extensions::ManagementPolicy* management_policy = | 1166 extensions::ManagementPolicy* management_policy = |
1006 extension_system->management_policy(); | 1167 extension_system->management_policy(); |
1007 | 1168 |
1008 if (management_policy) { | 1169 if (management_policy) { |
1009 if (active_) | 1170 if (active_) |
1010 management_policy->RegisterProvider(this); | 1171 management_policy->RegisterProvider(this); |
1011 else | 1172 else |
(...skipping 45 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
1057 content::RecordAction(UserMetricsAction("ManagedUsers_SwitchProfile")); | 1218 content::RecordAction(UserMetricsAction("ManagedUsers_SwitchProfile")); |
1058 | 1219 |
1059 is_profile_active_ = profile_became_active; | 1220 is_profile_active_ = profile_became_active; |
1060 } | 1221 } |
1061 #endif // !defined(OS_ANDROID) | 1222 #endif // !defined(OS_ANDROID) |
1062 | 1223 |
1063 void SupervisedUserService::OnSiteListUpdated() { | 1224 void SupervisedUserService::OnSiteListUpdated() { |
1064 FOR_EACH_OBSERVER( | 1225 FOR_EACH_OBSERVER( |
1065 SupervisedUserServiceObserver, observer_list_, OnURLFilterChanged()); | 1226 SupervisedUserServiceObserver, observer_list_, OnURLFilterChanged()); |
1066 } | 1227 } |
OLD | NEW |