| OLD | NEW |
| 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #ifndef NET_CERT_NSS_CERT_DATABASE_H_ | 5 #ifndef NET_CERT_NSS_CERT_DATABASE_H_ |
| 6 #define NET_CERT_NSS_CERT_DATABASE_H_ | 6 #define NET_CERT_NSS_CERT_DATABASE_H_ |
| 7 | 7 |
| 8 #include <string> | 8 #include <string> |
| 9 #include <vector> | 9 #include <vector> |
| 10 | 10 |
| 11 #include "base/basictypes.h" | 11 #include "base/basictypes.h" |
| 12 #include "base/callback_forward.h" | 12 #include "base/callback_forward.h" |
| 13 #include "base/memory/ref_counted.h" | 13 #include "base/memory/ref_counted.h" |
| 14 #include "base/memory/weak_ptr.h" |
| 14 #include "base/strings/string16.h" | 15 #include "base/strings/string16.h" |
| 15 #include "crypto/scoped_nss_types.h" | 16 #include "crypto/scoped_nss_types.h" |
| 17 #include "net/base/net_errors.h" |
| 16 #include "net/base/net_export.h" | 18 #include "net/base/net_export.h" |
| 17 #include "net/cert/cert_type.h" | 19 #include "net/cert/cert_type.h" |
| 18 #include "net/cert/x509_certificate.h" | 20 #include "net/cert/x509_certificate.h" |
| 19 | 21 |
| 20 namespace base { | 22 namespace base { |
| 21 template <typename T> struct DefaultLazyInstanceTraits; | 23 template <typename T> struct DefaultLazyInstanceTraits; |
| 22 class TaskRunner; | 24 class TaskRunner; |
| 23 } | 25 } |
| 24 template <class ObserverType> class ObserverListThreadSafe; | 26 template <class ObserverType> class ObserverListThreadSafe; |
| 25 | 27 |
| (...skipping 63 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 89 TRUSTED_EMAIL = 1 << 1, | 91 TRUSTED_EMAIL = 1 << 1, |
| 90 TRUSTED_OBJ_SIGN = 1 << 2, | 92 TRUSTED_OBJ_SIGN = 1 << 2, |
| 91 DISTRUSTED_SSL = 1 << 3, | 93 DISTRUSTED_SSL = 1 << 3, |
| 92 DISTRUSTED_EMAIL = 1 << 4, | 94 DISTRUSTED_EMAIL = 1 << 4, |
| 93 DISTRUSTED_OBJ_SIGN = 1 << 5, | 95 DISTRUSTED_OBJ_SIGN = 1 << 5, |
| 94 }; | 96 }; |
| 95 | 97 |
| 96 typedef base::Callback<void(scoped_ptr<CertificateList> certs)> | 98 typedef base::Callback<void(scoped_ptr<CertificateList> certs)> |
| 97 ListCertsCallback; | 99 ListCertsCallback; |
| 98 | 100 |
| 101 typedef base::Callback<void(bool)> DeleteCertCallback; |
| 102 |
| 99 // DEPRECATED: See http://crbug.com/329735. | 103 // DEPRECATED: See http://crbug.com/329735. |
| 100 static NSSCertDatabase* GetInstance(); | 104 static NSSCertDatabase* GetInstance(); |
| 101 | 105 |
| 102 // Get a list of unique certificates in the certificate database (one | 106 // Get a list of unique certificates in the certificate database (one |
| 103 // instance of all certificates). | 107 // instance of all certificates). |
| 104 // DEPRECATED by |ListCerts|. See http://crbug.com/340460. | 108 // DEPRECATED by |ListCerts|. See http://crbug.com/340460. |
| 105 virtual void ListCertsSync(CertificateList* certs); | 109 virtual void ListCertsSync(CertificateList* certs); |
| 106 | 110 |
| 107 // Asynchronously get a list of unique certificates in the certificate | 111 // Asynchronously get a list of unique certificates in the certificate |
| 108 // database (one instance of all certificates). Note that the callback may be | 112 // database (one instance of all certificates). Note that the callback may be |
| 109 // run even after the database is deleted. | 113 // run even after the database is deleted. |
| 110 virtual void ListCerts(const ListCertsCallback& callback); | 114 virtual void ListCerts(const ListCertsCallback& callback); |
| 111 | 115 |
| 116 // Get a list of certificates in the certificate database of the given slot. |
| 117 // Note that the callback may be run even after the database is deleted. |
| 118 // Must be called on the IO thread and it calls |callback| on the IO thread. |
| 119 // This does not block by retrieving the certs asynchronously on a worker |
| 120 // thread. Never calls |callback| synchronously. |
| 121 virtual void ListCertsInSlot(const ListCertsCallback& callback, |
| 122 PK11SlotInfo* slot); |
| 123 |
| 112 // Get the default slot for public key data. | 124 // Get the default slot for public key data. |
| 113 virtual crypto::ScopedPK11Slot GetPublicSlot() const; | 125 virtual crypto::ScopedPK11Slot GetPublicSlot() const; |
| 114 | 126 |
| 115 // Get the default slot for private key or mixed private/public key data. | 127 // Get the default slot for private key or mixed private/public key data. |
| 116 virtual crypto::ScopedPK11Slot GetPrivateSlot() const; | 128 virtual crypto::ScopedPK11Slot GetPrivateSlot() const; |
| 117 | 129 |
| 118 // Get the default module for public key data. | 130 // Get the default module for public key data. |
| 119 // The returned pointer must be stored in a scoped_refptr<CryptoModule>. | 131 // The returned pointer must be stored in a scoped_refptr<CryptoModule>. |
| 120 // DEPRECATED: use GetPublicSlot instead. | 132 // DEPRECATED: use GetPublicSlot instead. |
| 121 // TODO(mattm): remove usage of this method and remove it. | 133 // TODO(mattm): remove usage of this method and remove it. |
| (...skipping 70 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 192 | 204 |
| 193 // Set trust values for certificate. | 205 // Set trust values for certificate. |
| 194 // Returns true on success or false on failure. | 206 // Returns true on success or false on failure. |
| 195 bool SetCertTrust(const X509Certificate* cert, | 207 bool SetCertTrust(const X509Certificate* cert, |
| 196 CertType type, | 208 CertType type, |
| 197 TrustBits trust_bits); | 209 TrustBits trust_bits); |
| 198 | 210 |
| 199 // Delete certificate and associated private key (if one exists). | 211 // Delete certificate and associated private key (if one exists). |
| 200 // |cert| is still valid when this function returns. Returns true on | 212 // |cert| is still valid when this function returns. Returns true on |
| 201 // success. | 213 // success. |
| 202 bool DeleteCertAndKey(const X509Certificate* cert); | 214 bool DeleteCertAndKey(X509Certificate* cert); |
| 215 |
| 216 // Like DeleteCertAndKey but does not block by running the removal on a worker |
| 217 // thread. This must be called on IO thread and it will run |callback| on IO |
| 218 // thread. Never calls |callback| synchronously. |
| 219 void DeleteCertAndKeyAsync(const scoped_refptr<X509Certificate>& cert, |
| 220 const DeleteCertCallback& callback); |
| 203 | 221 |
| 204 // Check whether cert is stored in a readonly slot. | 222 // Check whether cert is stored in a readonly slot. |
| 205 bool IsReadOnly(const X509Certificate* cert) const; | 223 bool IsReadOnly(const X509Certificate* cert) const; |
| 206 | 224 |
| 207 // Check whether cert is stored in a hardware slot. | 225 // Check whether cert is stored in a hardware slot. |
| 208 bool IsHardwareBacked(const X509Certificate* cert) const; | 226 bool IsHardwareBacked(const X509Certificate* cert) const; |
| 209 | 227 |
| 210 // Registers |observer| to receive notifications of certificate changes. The | 228 // Registers |observer| to receive notifications of certificate changes. The |
| 211 // thread on which this is called is the thread on which |observer| will be | 229 // thread on which this is called is the thread on which |observer| will be |
| 212 // called back with notifications. | 230 // called back with notifications. |
| 213 // NOTE: CertDatabase::AddObserver should be preferred. Observers registered | 231 // NOTE: CertDatabase::AddObserver should be preferred. Observers registered |
| 214 // here will only receive notifications generated directly through the | 232 // here will only receive notifications generated directly through the |
| 215 // NSSCertDatabase, but not those from the CertDatabase. The CertDatabase | 233 // NSSCertDatabase, but not those from the CertDatabase. The CertDatabase |
| 216 // observers will receive both. | 234 // observers will receive both. |
| 217 void AddObserver(Observer* observer); | 235 void AddObserver(Observer* observer); |
| 218 | 236 |
| 219 // Unregisters |observer| from receiving notifications. This must be called | 237 // Unregisters |observer| from receiving notifications. This must be called |
| 220 // on the same thread on which AddObserver() was called. | 238 // on the same thread on which AddObserver() was called. |
| 221 void RemoveObserver(Observer* observer); | 239 void RemoveObserver(Observer* observer); |
| 222 | 240 |
| 223 // Overrides task runner that's used for running slow tasks. | 241 // Overrides task runner that's used for running slow tasks. |
| 224 void SetSlowTaskRunnerForTest( | 242 void SetSlowTaskRunnerForTest( |
| 225 const scoped_refptr<base::TaskRunner>& task_runner); | 243 const scoped_refptr<base::TaskRunner>& task_runner); |
| 226 | 244 |
| 227 protected: | 245 protected: |
| 228 NSSCertDatabase(); | 246 NSSCertDatabase(); |
| 229 virtual ~NSSCertDatabase(); | 247 virtual ~NSSCertDatabase(); |
| 230 | 248 |
| 231 // Certificate listing implementation used by |ListCerts| and |ListCertsSync|. | 249 // Certificate listing implementation used by |ListCerts*| and |
| 232 // Static so it may safely be used on the worker thread. | 250 // |ListCertsSync|. Static so it may safely be used on the worker thread. |
| 233 static void ListCertsImpl(CertificateList* certs); | 251 // If |slot| is NULL, obtains the certs of all slots, otherwise only of |
| 252 // |slot|. |
| 253 static void ListCertsImpl(crypto::ScopedPK11Slot slot, |
| 254 CertificateList* certs); |
| 234 | 255 |
| 235 // Gets task runner that should be used for slow tasks like certificate | 256 // Gets task runner that should be used for slow tasks like certificate |
| 236 // listing. Defaults to a base::WorkerPool runner, but may be overriden | 257 // listing. Defaults to a base::WorkerPool runner, but may be overriden |
| 237 // in tests (see SetSlowTaskRunnerForTest). | 258 // in tests (see SetSlowTaskRunnerForTest). |
| 238 scoped_refptr<base::TaskRunner> GetSlowTaskRunner() const; | 259 scoped_refptr<base::TaskRunner> GetSlowTaskRunner() const; |
| 239 | 260 |
| 240 private: | 261 private: |
| 241 friend struct base::DefaultLazyInstanceTraits<NSSCertDatabase>; | 262 friend struct base::DefaultLazyInstanceTraits<NSSCertDatabase>; |
| 242 | 263 |
| 264 // Notifies observers of the removal of |cert| and calls |callback| with |
| 265 // |success| as argument. |
| 266 void NotifyCertRemovalAndCallBack(scoped_refptr<X509Certificate> cert, |
| 267 const DeleteCertCallback& callback, |
| 268 bool success); |
| 269 |
| 243 // Broadcasts notifications to all registered observers. | 270 // Broadcasts notifications to all registered observers. |
| 244 void NotifyObserversOfCertAdded(const X509Certificate* cert); | 271 void NotifyObserversOfCertAdded(const X509Certificate* cert); |
| 245 void NotifyObserversOfCertRemoved(const X509Certificate* cert); | 272 void NotifyObserversOfCertRemoved(const X509Certificate* cert); |
| 246 void NotifyObserversOfCACertChanged(const X509Certificate* cert); | 273 void NotifyObserversOfCACertChanged(const X509Certificate* cert); |
| 247 | 274 |
| 275 // Certificate removal implementation used by |DeleteCertAndKey*|. Static so |
| 276 // it may safely be used on the worker thread. |
| 277 static bool DeleteCertAndKeyImpl(scoped_refptr<X509Certificate> cert); |
| 278 |
| 248 // Task runner that should be used in tests if set. | 279 // Task runner that should be used in tests if set. |
| 249 scoped_refptr<base::TaskRunner> slow_task_runner_for_test_; | 280 scoped_refptr<base::TaskRunner> slow_task_runner_for_test_; |
| 250 | 281 |
| 251 const scoped_refptr<ObserverListThreadSafe<Observer> > observer_list_; | 282 const scoped_refptr<ObserverListThreadSafe<Observer> > observer_list_; |
| 252 | 283 |
| 284 base::WeakPtrFactory<NSSCertDatabase> weak_factory_; |
| 285 |
| 253 DISALLOW_COPY_AND_ASSIGN(NSSCertDatabase); | 286 DISALLOW_COPY_AND_ASSIGN(NSSCertDatabase); |
| 254 }; | 287 }; |
| 255 | 288 |
| 256 } // namespace net | 289 } // namespace net |
| 257 | 290 |
| 258 #endif // NET_CERT_NSS_CERT_DATABASE_H_ | 291 #endif // NET_CERT_NSS_CERT_DATABASE_H_ |
| OLD | NEW |