Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(326)

Unified Diff: ui/file_manager/file_manager/foreground/js/quick_view_controller.js

Issue 2181953003: Improved security of Quick View by rendering videos and audios inside webview. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Nit Created 4 years, 4 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: ui/file_manager/file_manager/foreground/js/quick_view_controller.js
diff --git a/ui/file_manager/file_manager/foreground/js/quick_view_controller.js b/ui/file_manager/file_manager/foreground/js/quick_view_controller.js
index d859d5fe8edfa5131c4f4c5098e1e45b8055623c..d3d655a602afd45a3251d323d707ddb67dd30d27 100644
--- a/ui/file_manager/file_manager/foreground/js/quick_view_controller.js
+++ b/ui/file_manager/file_manager/foreground/js/quick_view_controller.js
@@ -233,6 +233,15 @@ QuickViewController.prototype.getQuickViewParameters_ = function(entry, items) {
filePath: entry.name,
};
+ /**
+ * @type function(!FileEntry): !Promise<!File>
+ */
+ var getFile = function(entry) {
+ return new Promise(function(resolve, reject) {
+ entry.file(resolve, reject);
+ });
+ };
+
if (type === 'image') {
if (item.externalFileUrl) {
if (item.thumbnailUrl) {
@@ -244,11 +253,9 @@ QuickViewController.prototype.getQuickViewParameters_ = function(entry, items) {
}.bind(this));
}
} else {
- return new Promise(function(resolve, reject) {
- entry.file(function(file) {
- params.contentUrl = URL.createObjectURL(file);
- resolve(params);
- });
+ return getFile(entry).then(function(file) {
+ params.contentUrl = URL.createObjectURL(file);
+ return params;
});
}
} else if (type === 'video') {
@@ -263,26 +270,37 @@ QuickViewController.prototype.getQuickViewParameters_ = function(entry, items) {
});
}
} else {
- params.contentUrl = entry.toURL();
params.autoplay = true;
if (item.thumbnailUrl) {
params.videoPoster = item.thumbnailUrl;
}
+ return getFile(entry).then(function(file) {
+ params.contentUrl = URL.createObjectURL(file);
+ return params;
+ });
}
} else if (type === 'audio') {
if (item.externalFileUrl) {
// If the file is in Drive, we ask user to open it with external app.
} else {
- params.contentUrl = entry.toURL();
params.autoplay = true;
- return this.metadataModel_.get([entry], ['contentThumbnailUrl'])
- .then(function(entry, items) {
+ return Promise
+ .all([
+ this.metadataModel_.get([entry], ['contentThumbnailUrl']),
+ getFile(entry)
+ ])
+ .then(function(values) {
+ /** @type {!Array<!MetadataItem>} */
+ var items = values[0];
+ /** @type {!File} */
+ var file = values[1];
var item = items[0];
if (item.contentThumbnailUrl) {
params.audioArtwork = item.contentThumbnailUrl;
}
+ params.contentUrl = URL.createObjectURL(file);
return params;
- }.bind(this, entry));
+ });
}
}
return Promise.resolve(params);

Powered by Google App Engine
This is Rietveld 408576698