| OLD | NEW |
| 1 // Copyright 2013 The Chromium Authors. All rights reserved. | 1 // Copyright 2013 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "components/signin/core/browser/signin_header_helper.h" | 5 #include "components/signin/core/browser/signin_header_helper.h" |
| 6 | 6 |
| 7 #include <stddef.h> | 7 #include <stddef.h> |
| 8 | 8 |
| 9 #include "base/macros.h" | 9 #include "base/macros.h" |
| 10 #include "base/strings/string_number_conversions.h" | 10 #include "base/strings/string_number_conversions.h" |
| 11 #include "base/strings/string_split.h" | 11 #include "base/strings/string_split.h" |
| 12 #include "base/strings/stringprintf.h" | 12 #include "base/strings/stringprintf.h" |
| 13 #include "build/build_config.h" | 13 #include "build/build_config.h" |
| 14 #include "components/content_settings/core/browser/cookie_settings.h" | 14 #include "components/content_settings/core/browser/cookie_settings.h" |
| 15 #include "components/google/core/browser/google_util.h" | 15 #include "components/google/core/browser/google_util.h" |
| 16 #include "components/signin/core/common/profile_management_switches.h" | 16 #include "components/signin/core/common/profile_management_switches.h" |
| 17 #include "google_apis/gaia/gaia_auth_util.h" | 17 #include "google_apis/gaia/gaia_auth_util.h" |
| 18 #include "google_apis/gaia/gaia_urls.h" | 18 #include "google_apis/gaia/gaia_urls.h" |
| 19 #include "net/base/escape.h" | 19 #include "net/base/escape.h" |
| 20 #include "net/http/http_response_headers.h" | 20 #include "net/http/http_response_headers.h" |
| 21 #include "net/url_request/url_request.h" | 21 #include "net/url_request/url_request.h" |
| 22 #include "url/gurl.h" | 22 #include "url/gurl.h" |
| 23 | 23 |
| 24 namespace { | 24 namespace { |
| 25 | 25 |
| 26 // Dictionary of fields in a mirror response header. | 26 // Dictionary of fields in a mirror response header. |
| 27 typedef std::map<std::string, std::string> MirrorResponseHeaderDictionary; | 27 typedef std::map<std::string, std::string> MirrorResponseHeaderDictionary; |
| 28 | 28 |
| 29 const char kChromeConnectedHeader[] = "X-Chrome-Connected"; | |
| 30 const char kChromeManageAccountsHeader[] = "X-Chrome-Manage-Accounts"; | 29 const char kChromeManageAccountsHeader[] = "X-Chrome-Manage-Accounts"; |
| 31 const char kContinueUrlAttrName[] = "continue_url"; | 30 const char kContinueUrlAttrName[] = "continue_url"; |
| 32 const char kEmailAttrName[] = "email"; | 31 const char kEmailAttrName[] = "email"; |
| 33 const char kEnableAccountConsistencyAttrName[] = "enable_account_consistency"; | 32 const char kEnableAccountConsistencyAttrName[] = "enable_account_consistency"; |
| 34 const char kGaiaIdAttrName[] = "id"; | 33 const char kGaiaIdAttrName[] = "id"; |
| 35 const char kProfileModeAttrName[] = "mode"; | 34 const char kProfileModeAttrName[] = "mode"; |
| 36 const char kIsSameTabAttrName[] = "is_same_tab"; | 35 const char kIsSameTabAttrName[] = "is_same_tab"; |
| 37 const char kIsSamlAttrName[] = "is_saml"; | 36 const char kIsSamlAttrName[] = "is_saml"; |
| 38 const char kServiceTypeAttrName[] = "action"; | 37 const char kServiceTypeAttrName[] = "action"; |
| 39 | 38 |
| (...skipping 53 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 93 const content_settings::CookieSettings* cookie_settings, | 92 const content_settings::CookieSettings* cookie_settings, |
| 94 int profile_mode_mask) { | 93 int profile_mode_mask) { |
| 95 if (account_id.empty()) | 94 if (account_id.empty()) |
| 96 return std::string(); | 95 return std::string(); |
| 97 | 96 |
| 98 // If signin cookies are not allowed, don't add the header. | 97 // If signin cookies are not allowed, don't add the header. |
| 99 if (!signin::SettingsAllowSigninCookies(cookie_settings)) { | 98 if (!signin::SettingsAllowSigninCookies(cookie_settings)) { |
| 100 return std::string(); | 99 return std::string(); |
| 101 } | 100 } |
| 102 | 101 |
| 103 // Only set the header for Drive and Gaia always, and other Google properties | 102 // Check if url is elligible for the header. |
| 104 // if account consistency is enabled. | 103 if (!signin::IsUrlEligibleForXChromeConnectedHeader(url)) |
| 105 // Vasquette, which is integrated with most Google properties, needs the | |
| 106 // header to redirect certain user actions to Chrome native UI. Drive and Gaia | |
| 107 // need the header to tell if the current user is connected. The drive path is | |
| 108 // a temporary workaround until the more generic chrome.principals API is | |
| 109 // available. | |
| 110 GURL origin(url.GetOrigin()); | |
| 111 bool is_enable_account_consistency = switches::IsEnableAccountConsistency(); | |
| 112 bool is_google_url = is_enable_account_consistency && | |
| 113 (google_util::IsGoogleDomainUrl( | |
| 114 url, google_util::ALLOW_SUBDOMAIN, | |
| 115 google_util::DISALLOW_NON_STANDARD_PORTS) || | |
| 116 google_util::IsYoutubeDomainUrl( | |
| 117 url, google_util::ALLOW_SUBDOMAIN, | |
| 118 google_util::DISALLOW_NON_STANDARD_PORTS)); | |
| 119 if (!is_google_url && !IsDriveOrigin(origin) && | |
| 120 !gaia::IsGaiaSignonRealm(origin)) { | |
| 121 return std::string(); | 104 return std::string(); |
| 122 } | |
| 123 | 105 |
| 124 return base::StringPrintf(pattern, kGaiaIdAttrName, account_id.c_str(), | 106 return base::StringPrintf( |
| 125 kProfileModeAttrName, | 107 pattern, kGaiaIdAttrName, account_id.c_str(), kProfileModeAttrName, |
| 126 base::IntToString(profile_mode_mask).c_str(), | 108 base::IntToString(profile_mode_mask).c_str(), |
| 127 kEnableAccountConsistencyAttrName, | 109 kEnableAccountConsistencyAttrName, |
| 128 is_enable_account_consistency ? "true" : "false"); | 110 switches::IsEnableAccountConsistency() ? "true" : "false"); |
| 129 } | 111 } |
| 130 | 112 |
| 131 } // namespace | 113 } // namespace |
| 132 | 114 |
| 133 namespace signin { | 115 namespace signin { |
| 134 | 116 |
| 117 extern const char kChromeConnectedHeader[] = "X-Chrome-Connected"; |
| 118 |
| 135 ManageAccountsParams::ManageAccountsParams() | 119 ManageAccountsParams::ManageAccountsParams() |
| 136 : service_type(GAIA_SERVICE_TYPE_NONE), | 120 : service_type(GAIA_SERVICE_TYPE_NONE), |
| 137 email(""), | 121 email(""), |
| 138 is_saml(false), | 122 is_saml(false), |
| 139 continue_url(""), | 123 continue_url(""), |
| 140 is_same_tab(false) { | 124 is_same_tab(false) { |
| 141 #if !defined(OS_IOS) | 125 #if !defined(OS_IOS) |
| 142 child_id = 0; | 126 child_id = 0; |
| 143 route_id = 0; | 127 route_id = 0; |
| 144 #endif // !defined(OS_IOS) | 128 #endif // !defined(OS_IOS) |
| (...skipping 13 matching lines...) Expand all Loading... |
| 158 | 142 |
| 159 std::string BuildMirrorRequestCookieIfPossible( | 143 std::string BuildMirrorRequestCookieIfPossible( |
| 160 const GURL& url, | 144 const GURL& url, |
| 161 const std::string& account_id, | 145 const std::string& account_id, |
| 162 const content_settings::CookieSettings* cookie_settings, | 146 const content_settings::CookieSettings* cookie_settings, |
| 163 int profile_mode_mask) { | 147 int profile_mode_mask) { |
| 164 return BuildMirrorRequestIfPossible("%s=%s:%s=%s:%s=%s", url, account_id, | 148 return BuildMirrorRequestIfPossible("%s=%s:%s=%s:%s=%s", url, account_id, |
| 165 cookie_settings, profile_mode_mask); | 149 cookie_settings, profile_mode_mask); |
| 166 } | 150 } |
| 167 | 151 |
| 168 bool AppendMirrorRequestHeaderIfPossible( | 152 bool AppendOrRemoveMirrorRequestHeaderIfPossible( |
| 169 net::URLRequest* request, | 153 net::URLRequest* request, |
| 170 const GURL& redirect_url, | 154 const GURL& redirect_url, |
| 171 const std::string& account_id, | 155 const std::string& account_id, |
| 172 const content_settings::CookieSettings* cookie_settings, | 156 const content_settings::CookieSettings* cookie_settings, |
| 173 int profile_mode_mask) { | 157 int profile_mode_mask) { |
| 174 const GURL& url = redirect_url.is_empty() ? request->url() : redirect_url; | 158 const GURL& url = redirect_url.is_empty() ? request->url() : redirect_url; |
| 175 std::string header_value = BuildMirrorRequestIfPossible( | 159 std::string header_value = |
| 176 "%s=%s,%s=%s,%s=%s", url, account_id, cookie_settings, profile_mode_mask); | 160 BuildMirrorRequestIfPossible("%s=%s,%s=%s,%s=%s", url, account_id, |
| 177 if (header_value.empty()) | 161 cookie_settings, profile_mode_mask); |
| 178 return false; | 162 if (header_value.empty()) { |
| 179 request->SetExtraRequestHeaderByName(kChromeConnectedHeader, header_value, | 163 // If the request is being redirected, and it has the x-chrome-connected |
| 180 false); | 164 // header, and current url is a Google URL, and the redirected one is not, |
| 181 return true; | 165 // remove the header. |
| 166 if (!redirect_url.is_empty() && |
| 167 request->extra_request_headers().HasHeader( |
| 168 signin::kChromeConnectedHeader) && |
| 169 signin::IsUrlEligibleForXChromeConnectedHeader(request->url()) && |
| 170 !signin::IsUrlEligibleForXChromeConnectedHeader(redirect_url)) { |
| 171 request->RemoveRequestHeaderByName(signin::kChromeConnectedHeader); |
| 172 } |
| 173 return false; |
| 174 } |
| 175 request->SetExtraRequestHeaderByName(kChromeConnectedHeader, header_value, |
| 176 false); |
| 177 return true; |
| 182 } | 178 } |
| 183 | 179 |
| 184 ManageAccountsParams BuildManageAccountsParams( | 180 ManageAccountsParams BuildManageAccountsParams( |
| 185 const std::string& header_value) { | 181 const std::string& header_value) { |
| 186 signin::ManageAccountsParams params; | 182 signin::ManageAccountsParams params; |
| 187 MirrorResponseHeaderDictionary header_dictionary = | 183 MirrorResponseHeaderDictionary header_dictionary = |
| 188 ParseMirrorResponseHeader(header_value); | 184 ParseMirrorResponseHeader(header_value); |
| 189 MirrorResponseHeaderDictionary::const_iterator it = header_dictionary.begin(); | 185 MirrorResponseHeaderDictionary::const_iterator it = header_dictionary.begin(); |
| 190 for (; it != header_dictionary.end(); ++it) { | 186 for (; it != header_dictionary.end(); ++it) { |
| 191 const std::string key_name(it->first); | 187 const std::string key_name(it->first); |
| (...skipping 25 matching lines...) Expand all Loading... |
| 217 std::string header_value; | 213 std::string header_value; |
| 218 if (!request->response_headers()->GetNormalizedHeader( | 214 if (!request->response_headers()->GetNormalizedHeader( |
| 219 kChromeManageAccountsHeader, &header_value)) { | 215 kChromeManageAccountsHeader, &header_value)) { |
| 220 return empty_params; | 216 return empty_params; |
| 221 } | 217 } |
| 222 | 218 |
| 223 DCHECK(switches::IsEnableAccountConsistency() && !is_off_the_record); | 219 DCHECK(switches::IsEnableAccountConsistency() && !is_off_the_record); |
| 224 return BuildManageAccountsParams(header_value); | 220 return BuildManageAccountsParams(header_value); |
| 225 } | 221 } |
| 226 | 222 |
| 223 // Checks if the url has the required properties to have an |
| 224 // X-CHROME-CONNECTED header. |
| 225 bool IsUrlEligibleForXChromeConnectedHeader(const GURL& url) { |
| 226 // Only set the header for Drive and Gaia always, and other Google properties |
| 227 // if account consistency is enabled. |
| 228 // Vasquette, which is integrated with most Google properties, needs the |
| 229 // header to redirect certain user actions to Chrome native UI. Drive and Gaia |
| 230 // need the header to tell if the current user is connected. The drive path is |
| 231 // a temporary workaround until the more generic chrome.principals API is |
| 232 // available. |
| 233 |
| 234 // Consider the account id sensitive and limit it to secure domains. |
| 235 if (!url.SchemeIsCryptographic()) |
| 236 return false; |
| 237 |
| 238 GURL origin(url.GetOrigin()); |
| 239 bool is_enable_account_consistency = switches::IsEnableAccountConsistency(); |
| 240 bool is_google_url = is_enable_account_consistency && |
| 241 (google_util::IsGoogleDomainUrl( |
| 242 url, google_util::ALLOW_SUBDOMAIN, |
| 243 google_util::DISALLOW_NON_STANDARD_PORTS) || |
| 244 google_util::IsYoutubeDomainUrl( |
| 245 url, google_util::ALLOW_SUBDOMAIN, |
| 246 google_util::DISALLOW_NON_STANDARD_PORTS)); |
| 247 return is_google_url || IsDriveOrigin(origin) || |
| 248 gaia::IsGaiaSignonRealm(origin); |
| 249 } |
| 250 |
| 227 } // namespace signin | 251 } // namespace signin |
| OLD | NEW |