Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(349)

Side by Side Diff: chrome/browser/ui/website_settings/website_settings.cc

Issue 2327433002: Stop using CertStore which is not compatible with PlzNavigate. (Closed)
Patch Set: remove certstore on non-ios and update plznavigate test filter Created 4 years, 3 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "chrome/browser/ui/website_settings/website_settings.h" 5 #include "chrome/browser/ui/website_settings/website_settings.h"
6 6
7 #include <stddef.h> 7 #include <stddef.h>
8 #include <stdint.h> 8 #include <stdint.h>
9 9
10 #include <string> 10 #include <string>
(...skipping 38 matching lines...) Expand 10 before | Expand all | Expand 10 after
49 #include "components/content_settings/core/browser/host_content_settings_map.h" 49 #include "components/content_settings/core/browser/host_content_settings_map.h"
50 #include "components/content_settings/core/browser/local_shared_objects_counter. h" 50 #include "components/content_settings/core/browser/local_shared_objects_counter. h"
51 #include "components/content_settings/core/common/content_settings.h" 51 #include "components/content_settings/core/common/content_settings.h"
52 #include "components/content_settings/core/common/content_settings_pattern.h" 52 #include "components/content_settings/core/common/content_settings_pattern.h"
53 #include "components/rappor/rappor_utils.h" 53 #include "components/rappor/rappor_utils.h"
54 #include "components/ssl_errors/error_info.h" 54 #include "components/ssl_errors/error_info.h"
55 #include "components/strings/grit/components_chromium_strings.h" 55 #include "components/strings/grit/components_chromium_strings.h"
56 #include "components/strings/grit/components_strings.h" 56 #include "components/strings/grit/components_strings.h"
57 #include "components/url_formatter/elide_url.h" 57 #include "components/url_formatter/elide_url.h"
58 #include "content/public/browser/browser_thread.h" 58 #include "content/public/browser/browser_thread.h"
59 #include "content/public/browser/cert_store.h"
60 #include "content/public/browser/permission_type.h" 59 #include "content/public/browser/permission_type.h"
61 #include "content/public/browser/user_metrics.h" 60 #include "content/public/browser/user_metrics.h"
62 #include "content/public/common/content_switches.h" 61 #include "content/public/common/content_switches.h"
63 #include "content/public/common/url_constants.h" 62 #include "content/public/common/url_constants.h"
64 #include "net/cert/cert_status_flags.h" 63 #include "net/cert/cert_status_flags.h"
65 #include "net/cert/x509_certificate.h" 64 #include "net/cert/x509_certificate.h"
66 #include "net/ssl/ssl_cipher_suite_names.h" 65 #include "net/ssl/ssl_cipher_suite_names.h"
67 #include "net/ssl/ssl_connection_status_flags.h" 66 #include "net/ssl/ssl_connection_status_flags.h"
68 #include "ui/base/l10n/l10n_util.h" 67 #include "ui/base/l10n/l10n_util.h"
69 68
(...skipping 176 matching lines...) Expand 10 before | Expand all | Expand 10 after
246 }; 245 };
247 246
248 } // namespace 247 } // namespace
249 248
250 WebsiteSettings::WebsiteSettings( 249 WebsiteSettings::WebsiteSettings(
251 WebsiteSettingsUI* ui, 250 WebsiteSettingsUI* ui,
252 Profile* profile, 251 Profile* profile,
253 TabSpecificContentSettings* tab_specific_content_settings, 252 TabSpecificContentSettings* tab_specific_content_settings,
254 content::WebContents* web_contents, 253 content::WebContents* web_contents,
255 const GURL& url, 254 const GURL& url,
256 const SecurityStateModel::SecurityInfo& security_info, 255 const SecurityStateModel::SecurityInfo& security_info)
257 content::CertStore* cert_store)
258 : TabSpecificContentSettings::SiteDataObserver( 256 : TabSpecificContentSettings::SiteDataObserver(
259 tab_specific_content_settings), 257 tab_specific_content_settings),
260 ui_(ui), 258 ui_(ui),
261 #if !defined(OS_ANDROID) 259 #if !defined(OS_ANDROID)
262 web_contents_(web_contents), 260 web_contents_(web_contents),
263 #endif 261 #endif
264 show_info_bar_(false), 262 show_info_bar_(false),
265 site_url_(url), 263 site_url_(url),
266 site_identity_status_(SITE_IDENTITY_STATUS_UNKNOWN), 264 site_identity_status_(SITE_IDENTITY_STATUS_UNKNOWN),
267 cert_id_(0),
268 site_connection_status_(SITE_CONNECTION_STATUS_UNKNOWN), 265 site_connection_status_(SITE_CONNECTION_STATUS_UNKNOWN),
269 cert_store_(cert_store),
270 content_settings_(HostContentSettingsMapFactory::GetForProfile(profile)), 266 content_settings_(HostContentSettingsMapFactory::GetForProfile(profile)),
271 chrome_ssl_host_state_delegate_( 267 chrome_ssl_host_state_delegate_(
272 ChromeSSLHostStateDelegateFactory::GetForProfile(profile)), 268 ChromeSSLHostStateDelegateFactory::GetForProfile(profile)),
273 did_revoke_user_ssl_decisions_(false), 269 did_revoke_user_ssl_decisions_(false),
274 profile_(profile) { 270 profile_(profile) {
275 Init(url, security_info); 271 Init(url, security_info);
276 272
277 PresentSitePermissions(); 273 PresentSitePermissions();
278 PresentSiteData(); 274 PresentSiteData();
279 PresentSiteIdentity(); 275 PresentSiteIdentity();
(...skipping 135 matching lines...) Expand 10 before | Expand all | Expand 10 after
415 411
416 if (url.SchemeIs(content::kChromeUIScheme) || isChromeUINativeScheme) { 412 if (url.SchemeIs(content::kChromeUIScheme) || isChromeUINativeScheme) {
417 site_identity_status_ = SITE_IDENTITY_STATUS_INTERNAL_PAGE; 413 site_identity_status_ = SITE_IDENTITY_STATUS_INTERNAL_PAGE;
418 site_identity_details_ = 414 site_identity_details_ =
419 l10n_util::GetStringUTF16(IDS_PAGE_INFO_INTERNAL_PAGE); 415 l10n_util::GetStringUTF16(IDS_PAGE_INFO_INTERNAL_PAGE);
420 site_connection_status_ = SITE_CONNECTION_STATUS_INTERNAL_PAGE; 416 site_connection_status_ = SITE_CONNECTION_STATUS_INTERNAL_PAGE;
421 return; 417 return;
422 } 418 }
423 419
424 // Identity section. 420 // Identity section.
425 scoped_refptr<net::X509Certificate> cert; 421 certificate_ = security_info.certificate;
426 cert_id_ = security_info.cert_id;
427 422
428 // HTTPS with no or minor errors. 423 // HTTPS with no or minor errors.
429 if (security_info.cert_id && 424 if (certificate_.get() &&
430 cert_store_->RetrieveCert(security_info.cert_id, &cert) &&
431 (!net::IsCertStatusError(security_info.cert_status) || 425 (!net::IsCertStatusError(security_info.cert_status) ||
432 net::IsCertStatusMinorError(security_info.cert_status))) { 426 net::IsCertStatusMinorError(security_info.cert_status))) {
433 // There are no major errors. Check for minor errors. 427 // There are no major errors. Check for minor errors.
434 if (security_info.security_level == 428 if (security_info.security_level ==
435 SecurityStateModel::SECURITY_POLICY_WARNING) { 429 SecurityStateModel::SECURITY_POLICY_WARNING) {
436 site_identity_status_ = SITE_IDENTITY_STATUS_ADMIN_PROVIDED_CERT; 430 site_identity_status_ = SITE_IDENTITY_STATUS_ADMIN_PROVIDED_CERT;
437 site_identity_details_ = l10n_util::GetStringFUTF16( 431 site_identity_details_ = l10n_util::GetStringFUTF16(
438 IDS_CERT_POLICY_PROVIDED_CERT_MESSAGE, UTF8ToUTF16(url.host())); 432 IDS_CERT_POLICY_PROVIDED_CERT_MESSAGE, UTF8ToUTF16(url.host()));
439 } else if (net::IsCertStatusMinorError(security_info.cert_status)) { 433 } else if (net::IsCertStatusMinorError(security_info.cert_status)) {
440 site_identity_status_ = SITE_IDENTITY_STATUS_CERT_REVOCATION_UNKNOWN; 434 site_identity_status_ = SITE_IDENTITY_STATUS_CERT_REVOCATION_UNKNOWN;
441 base::string16 issuer_name(UTF8ToUTF16(cert->issuer().GetDisplayName())); 435 base::string16 issuer_name(
436 UTF8ToUTF16(certificate_->issuer().GetDisplayName()));
442 if (issuer_name.empty()) { 437 if (issuer_name.empty()) {
443 issuer_name.assign(l10n_util::GetStringUTF16( 438 issuer_name.assign(l10n_util::GetStringUTF16(
444 IDS_PAGE_INFO_SECURITY_TAB_UNKNOWN_PARTY)); 439 IDS_PAGE_INFO_SECURITY_TAB_UNKNOWN_PARTY));
445 } 440 }
446 441
447 site_identity_details_.assign(l10n_util::GetStringFUTF16( 442 site_identity_details_.assign(l10n_util::GetStringFUTF16(
448 GetSiteIdentityDetailsMessageByCTInfo( 443 GetSiteIdentityDetailsMessageByCTInfo(
449 security_info.sct_verify_statuses, false /* not EV */), 444 security_info.sct_verify_statuses, false /* not EV */),
450 issuer_name)); 445 issuer_name));
451 446
452 site_identity_details_ += ASCIIToUTF16("\n\n"); 447 site_identity_details_ += ASCIIToUTF16("\n\n");
453 if (security_info.cert_status & 448 if (security_info.cert_status &
454 net::CERT_STATUS_UNABLE_TO_CHECK_REVOCATION) { 449 net::CERT_STATUS_UNABLE_TO_CHECK_REVOCATION) {
455 site_identity_details_ += l10n_util::GetStringUTF16( 450 site_identity_details_ += l10n_util::GetStringUTF16(
456 IDS_PAGE_INFO_SECURITY_TAB_UNABLE_TO_CHECK_REVOCATION); 451 IDS_PAGE_INFO_SECURITY_TAB_UNABLE_TO_CHECK_REVOCATION);
457 } else if (security_info.cert_status & 452 } else if (security_info.cert_status &
458 net::CERT_STATUS_NO_REVOCATION_MECHANISM) { 453 net::CERT_STATUS_NO_REVOCATION_MECHANISM) {
459 site_identity_details_ += l10n_util::GetStringUTF16( 454 site_identity_details_ += l10n_util::GetStringUTF16(
460 IDS_PAGE_INFO_SECURITY_TAB_NO_REVOCATION_MECHANISM); 455 IDS_PAGE_INFO_SECURITY_TAB_NO_REVOCATION_MECHANISM);
461 } else { 456 } else {
462 NOTREACHED() << "Need to specify string for this warning"; 457 NOTREACHED() << "Need to specify string for this warning";
463 } 458 }
464 } else { 459 } else {
465 if (security_info.cert_status & net::CERT_STATUS_IS_EV) { 460 if (security_info.cert_status & net::CERT_STATUS_IS_EV) {
466 // EV HTTPS page. 461 // EV HTTPS page.
467 site_identity_status_ = GetSiteIdentityStatusByCTInfo( 462 site_identity_status_ = GetSiteIdentityStatusByCTInfo(
468 security_info.sct_verify_statuses, true); 463 security_info.sct_verify_statuses, true);
469 DCHECK(!cert->subject().organization_names.empty()); 464 DCHECK(!certificate_->subject().organization_names.empty());
470 organization_name_ = UTF8ToUTF16(cert->subject().organization_names[0]); 465 organization_name_ =
466 UTF8ToUTF16(certificate_->subject().organization_names[0]);
471 // An EV Cert is required to have a city (localityName) and country but 467 // An EV Cert is required to have a city (localityName) and country but
472 // state is "if any". 468 // state is "if any".
473 DCHECK(!cert->subject().locality_name.empty()); 469 DCHECK(!certificate_->subject().locality_name.empty());
474 DCHECK(!cert->subject().country_name.empty()); 470 DCHECK(!certificate_->subject().country_name.empty());
475 base::string16 locality; 471 base::string16 locality;
476 if (!cert->subject().state_or_province_name.empty()) { 472 if (!certificate_->subject().state_or_province_name.empty()) {
477 locality = l10n_util::GetStringFUTF16( 473 locality = l10n_util::GetStringFUTF16(
478 IDS_PAGEINFO_ADDRESS, 474 IDS_PAGEINFO_ADDRESS,
479 UTF8ToUTF16(cert->subject().locality_name), 475 UTF8ToUTF16(certificate_->subject().locality_name),
480 UTF8ToUTF16(cert->subject().state_or_province_name), 476 UTF8ToUTF16(certificate_->subject().state_or_province_name),
481 UTF8ToUTF16(cert->subject().country_name)); 477 UTF8ToUTF16(certificate_->subject().country_name));
482 } else { 478 } else {
483 locality = l10n_util::GetStringFUTF16( 479 locality = l10n_util::GetStringFUTF16(
484 IDS_PAGEINFO_PARTIAL_ADDRESS, 480 IDS_PAGEINFO_PARTIAL_ADDRESS,
485 UTF8ToUTF16(cert->subject().locality_name), 481 UTF8ToUTF16(certificate_->subject().locality_name),
486 UTF8ToUTF16(cert->subject().country_name)); 482 UTF8ToUTF16(certificate_->subject().country_name));
487 } 483 }
488 DCHECK(!cert->subject().organization_names.empty()); 484 DCHECK(!certificate_->subject().organization_names.empty());
489 site_identity_details_.assign(l10n_util::GetStringFUTF16( 485 site_identity_details_.assign(l10n_util::GetStringFUTF16(
490 GetSiteIdentityDetailsMessageByCTInfo( 486 GetSiteIdentityDetailsMessageByCTInfo(
491 security_info.sct_verify_statuses, true /* is EV */), 487 security_info.sct_verify_statuses, true /* is EV */),
492 UTF8ToUTF16(cert->subject().organization_names[0]), locality, 488 UTF8ToUTF16(certificate_->subject().organization_names[0]),
493 UTF8ToUTF16(cert->issuer().GetDisplayName()))); 489 locality,
490 UTF8ToUTF16(certificate_->issuer().GetDisplayName())));
494 } else { 491 } else {
495 // Non-EV OK HTTPS page. 492 // Non-EV OK HTTPS page.
496 site_identity_status_ = GetSiteIdentityStatusByCTInfo( 493 site_identity_status_ = GetSiteIdentityStatusByCTInfo(
497 security_info.sct_verify_statuses, false); 494 security_info.sct_verify_statuses, false);
498 base::string16 issuer_name( 495 base::string16 issuer_name(
499 UTF8ToUTF16(cert->issuer().GetDisplayName())); 496 UTF8ToUTF16(certificate_->issuer().GetDisplayName()));
500 if (issuer_name.empty()) { 497 if (issuer_name.empty()) {
501 issuer_name.assign(l10n_util::GetStringUTF16( 498 issuer_name.assign(l10n_util::GetStringUTF16(
502 IDS_PAGE_INFO_SECURITY_TAB_UNKNOWN_PARTY)); 499 IDS_PAGE_INFO_SECURITY_TAB_UNKNOWN_PARTY));
503 } 500 }
504 501
505 site_identity_details_.assign(l10n_util::GetStringFUTF16( 502 site_identity_details_.assign(l10n_util::GetStringFUTF16(
506 GetSiteIdentityDetailsMessageByCTInfo( 503 GetSiteIdentityDetailsMessageByCTInfo(
507 security_info.sct_verify_statuses, false /* not EV */), 504 security_info.sct_verify_statuses, false /* not EV */),
508 issuer_name)); 505 issuer_name));
509 } 506 }
(...skipping 21 matching lines...) Expand all
531 // UNKNOWN_SHA1 should only appear when certificate info has not been 528 // UNKNOWN_SHA1 should only appear when certificate info has not been
532 // initialized, in which case this if-statement should not be running 529 // initialized, in which case this if-statement should not be running
533 // because there is no other cert info. 530 // because there is no other cert info.
534 NOTREACHED(); 531 NOTREACHED();
535 } 532 }
536 } 533 }
537 } else { 534 } else {
538 // HTTP or HTTPS with errors (not warnings). 535 // HTTP or HTTPS with errors (not warnings).
539 site_identity_details_.assign(l10n_util::GetStringUTF16( 536 site_identity_details_.assign(l10n_util::GetStringUTF16(
540 IDS_PAGE_INFO_SECURITY_TAB_INSECURE_IDENTITY)); 537 IDS_PAGE_INFO_SECURITY_TAB_INSECURE_IDENTITY));
541 if (!security_info.scheme_is_cryptographic || !security_info.cert_id) 538 if (!security_info.scheme_is_cryptographic ||
539 !security_info.certificate.get()) {
542 site_identity_status_ = SITE_IDENTITY_STATUS_NO_CERT; 540 site_identity_status_ = SITE_IDENTITY_STATUS_NO_CERT;
543 else 541 } else {
544 site_identity_status_ = SITE_IDENTITY_STATUS_ERROR; 542 site_identity_status_ = SITE_IDENTITY_STATUS_ERROR;
543 }
545 544
546 const base::string16 bullet = UTF8ToUTF16("\n • "); 545 const base::string16 bullet = UTF8ToUTF16("\n • ");
547 std::vector<ssl_errors::ErrorInfo> errors; 546 std::vector<ssl_errors::ErrorInfo> errors;
548 ssl_errors::ErrorInfo::GetErrorsForCertStatus( 547 ssl_errors::ErrorInfo::GetErrorsForCertStatus(
549 cert, security_info.cert_status, url, &errors); 548 certificate_, security_info.cert_status, url, &errors);
550 for (size_t i = 0; i < errors.size(); ++i) { 549 for (size_t i = 0; i < errors.size(); ++i) {
551 site_identity_details_ += bullet; 550 site_identity_details_ += bullet;
552 site_identity_details_ += errors[i].short_description(); 551 site_identity_details_ += errors[i].short_description();
553 } 552 }
554 553
555 if (security_info.cert_status & net::CERT_STATUS_NON_UNIQUE_NAME) { 554 if (security_info.cert_status & net::CERT_STATUS_NON_UNIQUE_NAME) {
556 site_identity_details_ += ASCIIToUTF16("\n\n"); 555 site_identity_details_ += ASCIIToUTF16("\n\n");
557 site_identity_details_ += l10n_util::GetStringUTF16( 556 site_identity_details_ += l10n_util::GetStringUTF16(
558 IDS_PAGE_INFO_SECURITY_TAB_NON_UNIQUE_NAME); 557 IDS_PAGE_INFO_SECURITY_TAB_NON_UNIQUE_NAME);
559 } 558 }
560 } 559 }
561 560
562 // Site Connection 561 // Site Connection
563 // We consider anything less than 80 bits encryption to be weak encryption. 562 // We consider anything less than 80 bits encryption to be weak encryption.
564 // TODO(wtc): Bug 1198735: report mixed/unsafe content for unencrypted and 563 // TODO(wtc): Bug 1198735: report mixed/unsafe content for unencrypted and
565 // weakly encrypted connections. 564 // weakly encrypted connections.
566 site_connection_status_ = SITE_CONNECTION_STATUS_UNKNOWN; 565 site_connection_status_ = SITE_CONNECTION_STATUS_UNKNOWN;
567 566
568 base::string16 subject_name(GetSimpleSiteName(url)); 567 base::string16 subject_name(GetSimpleSiteName(url));
569 if (subject_name.empty()) { 568 if (subject_name.empty()) {
570 subject_name.assign( 569 subject_name.assign(
571 l10n_util::GetStringUTF16(IDS_PAGE_INFO_SECURITY_TAB_UNKNOWN_PARTY)); 570 l10n_util::GetStringUTF16(IDS_PAGE_INFO_SECURITY_TAB_UNKNOWN_PARTY));
572 } 571 }
573 572
574 if (!security_info.cert_id || !security_info.scheme_is_cryptographic) { 573 if (!security_info.certificate.get() ||
574 !security_info.scheme_is_cryptographic) {
575 // Page is still loading (so SSL status is not yet available) or 575 // Page is still loading (so SSL status is not yet available) or
576 // loaded over HTTP or loaded over HTTPS with no cert. 576 // loaded over HTTP or loaded over HTTPS with no cert.
577 site_connection_status_ = SITE_CONNECTION_STATUS_UNENCRYPTED; 577 site_connection_status_ = SITE_CONNECTION_STATUS_UNENCRYPTED;
578 578
579 site_connection_details_.assign(l10n_util::GetStringFUTF16( 579 site_connection_details_.assign(l10n_util::GetStringFUTF16(
580 IDS_PAGE_INFO_SECURITY_TAB_NOT_ENCRYPTED_CONNECTION_TEXT, 580 IDS_PAGE_INFO_SECURITY_TAB_NOT_ENCRYPTED_CONNECTION_TEXT,
581 subject_name)); 581 subject_name));
582 } else if (security_info.security_bits < 0) { 582 } else if (security_info.security_bits < 0) {
583 // Security strength is unknown. Say nothing. 583 // Security strength is unknown. Say nothing.
584 site_connection_status_ = SITE_CONNECTION_STATUS_ENCRYPTED_ERROR; 584 site_connection_status_ = SITE_CONNECTION_STATUS_ENCRYPTED_ERROR;
(...skipping 215 matching lines...) Expand 10 before | Expand all | Expand 10 after
800 info.site_identity = UTF16ToUTF8(organization_name()); 800 info.site_identity = UTF16ToUTF8(organization_name());
801 else 801 else
802 info.site_identity = UTF16ToUTF8(GetSimpleSiteName(site_url_)); 802 info.site_identity = UTF16ToUTF8(GetSimpleSiteName(site_url_));
803 803
804 info.connection_status = site_connection_status_; 804 info.connection_status = site_connection_status_;
805 info.connection_status_description = 805 info.connection_status_description =
806 UTF16ToUTF8(site_connection_details_); 806 UTF16ToUTF8(site_connection_details_);
807 info.identity_status = site_identity_status_; 807 info.identity_status = site_identity_status_;
808 info.identity_status_description = 808 info.identity_status_description =
809 UTF16ToUTF8(site_identity_details_); 809 UTF16ToUTF8(site_identity_details_);
810 info.cert_id = cert_id_; 810 info.certificate = certificate_;
811 info.show_ssl_decision_revoke_button = show_ssl_decision_revoke_button_; 811 info.show_ssl_decision_revoke_button = show_ssl_decision_revoke_button_;
812 ui_->SetIdentityInfo(info); 812 ui_->SetIdentityInfo(info);
813 } 813 }
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698