Chromium Code Reviews| Index: base/unguessable_token.cc |
| diff --git a/base/unguessable_token.cc b/base/unguessable_token.cc |
| new file mode 100644 |
| index 0000000000000000000000000000000000000000..003bc99fc61b74acde44e6198f577f1d21603537 |
| --- /dev/null |
| +++ b/base/unguessable_token.cc |
| @@ -0,0 +1,49 @@ |
| +// Copyright 2016 The Chromium Authors. All rights reserved. |
| +// Use of this source code is governed by a BSD-style license that can be |
| +// found in the LICENSE file. |
| + |
| +#include "base/unguessable_token.h" |
| + |
| +#include "base/format_macros.h" |
| +#include "base/rand_util.h" |
| +#include "base/strings/stringprintf.h" |
| + |
| +namespace base { |
| + |
| +UnguessableToken::UnguessableToken(uint64_t high, uint64_t low) |
| + : high_(high), low_(low) {} |
| + |
| +std::string UnguessableToken::ToString() const { |
| + return base::StringPrintf("(%08" PRIX64 "%08" PRIX64 ")", high_, low_); |
| +} |
| + |
| +// static |
| +UnguessableToken UnguessableToken::Create() { |
| + UnguessableToken token; |
| + // Use base::RandBytes instead of crypto::RandBytes, because crypto calls the |
| + // base version directly, and to prevent the dependency from base/ to crypto/. |
| + base::RandBytes(&token, sizeof(token)); |
| + return token; |
| +} |
| + |
| +uint64_t UnguessableToken::GetHighForSerialization() const { |
| + // Serializing an empty UnguessableToken is a security issue. |
|
dcheng
2016/09/17 00:22:20
Just inline this. logging.h is already in our head
tguilbert
2016/09/17 00:49:49
Done.
|
| + DCHECK(!is_empty()); |
| + return high_; |
| +} |
| + |
| +uint64_t UnguessableToken::GetLowForSerialization() const { |
| + // Serializing an empty UnguessableToken is a security issue. |
| + DCHECK(!is_empty()); |
| + return low_; |
| +} |
| + |
| +// static |
| +UnguessableToken UnguessableToken::Deserialize(uint64_t high, uint64_t low) { |
| + // Receiving a zeroed out UnguessableToken from another process means that it |
| + // was never initialized via Create(). Treat this case as a security issue. |
| + DCHECK(!(high == 0 && low == 0)); |
| + return UnguessableToken(high, low); |
| +} |
| + |
| +} // namespace base |