Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(3179)

Unified Diff: chrome/android/java/src/org/chromium/chrome/browser/externalnav/ExternalNavigationDelegateImpl.java

Issue 2167573003: Verify intent signatures. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: fix error on presubmit Created 4 years, 5 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: chrome/android/java/src/org/chromium/chrome/browser/externalnav/ExternalNavigationDelegateImpl.java
diff --git a/chrome/android/java/src/org/chromium/chrome/browser/externalnav/ExternalNavigationDelegateImpl.java b/chrome/android/java/src/org/chromium/chrome/browser/externalnav/ExternalNavigationDelegateImpl.java
index 0269372a91fe45d29b372fdb1dc5b7bfda8af30a..7aa45e6dc9ebf6ddc83a36d24c77e9a0cdf3e4a7 100644
--- a/chrome/android/java/src/org/chromium/chrome/browser/externalnav/ExternalNavigationDelegateImpl.java
+++ b/chrome/android/java/src/org/chromium/chrome/browser/externalnav/ExternalNavigationDelegateImpl.java
@@ -14,6 +14,7 @@ import android.content.Intent;
import android.content.IntentFilter;
import android.content.pm.PackageManager;
import android.content.pm.ResolveInfo;
+import android.content.pm.Signature;
import android.net.Uri;
import android.os.Build;
import android.os.StrictMode;
@@ -49,8 +50,12 @@ import org.chromium.ui.base.WindowAndroid;
import org.chromium.ui.base.WindowAndroid.PermissionCallback;
import org.chromium.webapk.lib.client.WebApkValidator;
+import java.security.MessageDigest;
+import java.security.NoSuchAlgorithmException;
import java.util.ArrayList;
+import java.util.HashSet;
import java.util.List;
+import java.util.Set;
/**
* The main implementation of the {@link ExternalNavigationDelegate}.
@@ -542,4 +547,57 @@ public class ExternalNavigationDelegateImpl implements ExternalNavigationDelegat
intent.putExtra(IntentHandler.EXTRA_EXTERNAL_NAV_PACKAGES,
getSpecializedHandlersWithFilter(infos, null));
}
+
+
+ @Override
+ public Set<String> getPackageSHA256Fingerprints(String pkgName)
+ throws PackageManager.NameNotFoundException {
+ PackageManager pm = getAvailableContext().getPackageManager();
+ Signature[] signatures = pm.getPackageInfo(pkgName,
+ PackageManager.GET_SIGNATURES).signatures;
+ HashSet<String> fingerPrint256Set = new HashSet<String>();
+ if (signatures.length > 0) {
+ for (Signature each : signatures) {
+ String fingerPrint = getSha256(each.toByteArray());
+ fingerPrint256Set.add(fingerPrint);
+ }
+ }
+ return fingerPrint256Set;
+ }
+
+ /**
+ * Compute sha256 fingerprint from signature using MessageDigest.
+ *
+ * @param signature The signature to process.
+ * @return The hex string for the fingerprint.
+ */
+ private String getSha256(byte[] signature) {
+ MessageDigest digester;
+ try {
+ digester = MessageDigest.getInstance("SHA-256");
+ } catch (NoSuchAlgorithmException e) {
+ return "";
+ }
+ digester.update(signature);
+ return byteArrayToHexString(digester.digest());
+ }
+
+ /**
+ * Convert bytes to a hex string.
+ *
+ * @param bytes The bytes to convert into a string.
+ * @return The hex string for the bytes.
+ */
+ private String byteArrayToHexString(byte[] bytes) {
+ if (bytes.length == 0) {
+ return "";
+ }
+ StringBuilder data = new StringBuilder();
+ for (byte b : bytes) {
+ data.append(Integer.toHexString((b >> 4) & 0x0f));
+ data.append(Integer.toHexString(b & 0x0f));
+ }
+ return data.toString().toUpperCase();
+ }
+
}

Powered by Google App Engine
This is Rietveld 408576698