Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(102)

Unified Diff: chrome/browser/android/webapk/webapk_icon_hasher.cc

Issue 2231843003: Take Murmur2 hash of untransformed icon when creating WebAPK part 1 (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Merge branch 'master' into webapk_builder_impl2_hash Created 4 years, 4 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: chrome/browser/android/webapk/webapk_icon_hasher.cc
diff --git a/chrome/browser/android/webapk/webapk_icon_hasher.cc b/chrome/browser/android/webapk/webapk_icon_hasher.cc
new file mode 100644
index 0000000000000000000000000000000000000000..070c2896f720c85da575c66e40f1ecefd8507209
--- /dev/null
+++ b/chrome/browser/android/webapk/webapk_icon_hasher.cc
@@ -0,0 +1,53 @@
+// Copyright 2016 The Chromium Authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+#include "chrome/browser/android/webapk/webapk_icon_hasher.h"
+
+#include "base/strings/string_number_conversions.h"
+#include "base/strings/utf_string_conversions.h"
+#include "net/http/http_status_code.h"
+#include "net/url_request/url_fetcher.h"
+#include "net/url_request/url_request_context_getter.h"
+#include "third_party/smhasher/src/MurmurHash2.h"
+#include "url/gurl.h"
+
+namespace {
+
+// The seed to use when taking the murmur2 hash of the icon.
+const uint64_t kMurmur2HashSeed = 0;
+
+} // anonymous namespace
+
+WebApkIconHasher::WebApkIconHasher() {}
+
+WebApkIconHasher::~WebApkIconHasher() {}
+
+void WebApkIconHasher::DownloadAndGetMurmur2Hash(
+ net::URLRequestContextGetter* request_context_getter,
+ const GURL& icon_url,
+ const Murmur2HashCallback& callback) {
+ callback_ = callback;
+
+ url_fetcher_ = net::URLFetcher::Create(icon_url, net::URLFetcher::GET, this);
+ url_fetcher_->SetRequestContext(request_context_getter);
+ url_fetcher_->Start();
+}
+
+void WebApkIconHasher::OnURLFetchComplete(const net::URLFetcher* source) {
+ if (!source->GetStatus().is_success() ||
+ source->GetResponseCode() != net::HTTP_OK) {
+ callback_.Run("");
+ return;
+ }
+
+ // WARNING: We are running in the browser process. |raw_image_data| is the
Robert Sesek 2016/08/16 19:55:57 Thanks for the security-conscious comment!
+ // image's raw, unsanitized bytes from the web. |raw_image_data| may contain
+ // malicious data. Decoding unsanitized bitmap data to an SkBitmap in the
+ // browser process is a security bug.
+ std::string raw_image_data;
+ source->GetResponseAsString(&raw_image_data);
+ uint64_t hash = MurmurHash64B(&raw_image_data.front(), raw_image_data.size(),
+ kMurmur2HashSeed);
+ callback_.Run(base::Uint64ToString(hash));
+}

Powered by Google App Engine
This is Rietveld 408576698