OLD | NEW |
1 // Copyright 2016 The Chromium Authors. All rights reserved. | 1 // Copyright 2016 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "chrome/browser/plugins/plugin_utils.h" | 5 #include "chrome/browser/plugins/plugin_utils.h" |
6 | 6 |
7 #include "base/values.h" | 7 #include "base/values.h" |
| 8 #include "chrome/common/chrome_features.h" |
8 #include "chrome/common/plugin_utils.h" | 9 #include "chrome/common/plugin_utils.h" |
9 #include "components/content_settings/core/browser/host_content_settings_map.h" | 10 #include "components/content_settings/core/browser/host_content_settings_map.h" |
10 #include "content/public/common/webplugininfo.h" | 11 #include "content/public/common/webplugininfo.h" |
11 #include "url/gurl.h" | 12 #include "url/gurl.h" |
| 13 #include "url/origin.h" |
12 | 14 |
13 namespace { | 15 namespace { |
14 | 16 |
15 const char kFlashPluginID[] = "adobe-flash-player"; | 17 const char kFlashPluginID[] = "adobe-flash-player"; |
16 | 18 |
17 void GetPluginContentSettingInternal( | 19 void GetPluginContentSettingInternal( |
18 const HostContentSettingsMap* host_content_settings_map, | 20 const HostContentSettingsMap* host_content_settings_map, |
19 bool use_javascript_setting, | 21 bool use_javascript_setting, |
20 const GURL& policy_url, | 22 const url::Origin& main_frame_origin, |
21 const GURL& plugin_url, | 23 const GURL& plugin_url, |
22 const std::string& resource, | 24 const std::string& resource, |
23 ContentSetting* setting, | 25 ContentSetting* setting, |
24 bool* uses_default_content_setting, | 26 bool* uses_default_content_setting, |
25 bool* is_managed) { | 27 bool* is_managed) { |
| 28 GURL main_frame_url = main_frame_origin.GetURL(); |
26 std::unique_ptr<base::Value> value; | 29 std::unique_ptr<base::Value> value; |
27 content_settings::SettingInfo info; | 30 content_settings::SettingInfo info; |
28 bool uses_plugin_specific_setting = false; | 31 bool uses_plugin_specific_setting = false; |
29 if (use_javascript_setting) { | 32 if (use_javascript_setting) { |
30 value = host_content_settings_map->GetWebsiteSetting( | 33 value = host_content_settings_map->GetWebsiteSetting( |
31 policy_url, policy_url, CONTENT_SETTINGS_TYPE_JAVASCRIPT, std::string(), | 34 main_frame_url, main_frame_url, CONTENT_SETTINGS_TYPE_JAVASCRIPT, |
32 &info); | 35 std::string(), &info); |
33 } else { | 36 } else { |
34 content_settings::SettingInfo specific_info; | 37 content_settings::SettingInfo specific_info; |
35 std::unique_ptr<base::Value> specific_setting = | 38 std::unique_ptr<base::Value> specific_setting = |
36 host_content_settings_map->GetWebsiteSetting( | 39 host_content_settings_map->GetWebsiteSetting( |
37 policy_url, plugin_url, CONTENT_SETTINGS_TYPE_PLUGINS, resource, | 40 main_frame_url, plugin_url, CONTENT_SETTINGS_TYPE_PLUGINS, resource, |
38 &specific_info); | 41 &specific_info); |
39 content_settings::SettingInfo general_info; | 42 content_settings::SettingInfo general_info; |
40 std::unique_ptr<base::Value> general_setting = | 43 std::unique_ptr<base::Value> general_setting = |
41 host_content_settings_map->GetWebsiteSetting( | 44 host_content_settings_map->GetWebsiteSetting( |
42 policy_url, plugin_url, CONTENT_SETTINGS_TYPE_PLUGINS, | 45 main_frame_url, plugin_url, CONTENT_SETTINGS_TYPE_PLUGINS, |
43 std::string(), &general_info); | 46 std::string(), &general_info); |
44 // If there is a plugin-specific setting, we use it, unless the general | 47 // If there is a plugin-specific setting, we use it, unless the general |
45 // setting was set by policy, in which case it takes precedence. | 48 // setting was set by policy, in which case it takes precedence. |
46 uses_plugin_specific_setting = | 49 uses_plugin_specific_setting = |
47 specific_setting && | 50 specific_setting && |
48 general_info.source != content_settings::SETTING_SOURCE_POLICY; | 51 general_info.source != content_settings::SETTING_SOURCE_POLICY; |
49 if (uses_plugin_specific_setting) { | 52 if (uses_plugin_specific_setting) { |
50 value = std::move(specific_setting); | 53 value = std::move(specific_setting); |
51 info = specific_info; | 54 info = specific_info; |
52 } else { | 55 } else { |
53 value = std::move(general_setting); | 56 value = std::move(general_setting); |
54 info = general_info; | 57 info = general_info; |
55 } | 58 } |
56 } | 59 } |
57 *setting = content_settings::ValueToContentSetting(value.get()); | 60 *setting = content_settings::ValueToContentSetting(value.get()); |
58 if (uses_default_content_setting) { | 61 if (uses_default_content_setting) { |
59 *uses_default_content_setting = | 62 *uses_default_content_setting = |
60 !uses_plugin_specific_setting && | 63 !uses_plugin_specific_setting && |
61 info.primary_pattern == ContentSettingsPattern::Wildcard() && | 64 info.primary_pattern == ContentSettingsPattern::Wildcard() && |
62 info.secondary_pattern == ContentSettingsPattern::Wildcard(); | 65 info.secondary_pattern == ContentSettingsPattern::Wildcard(); |
63 } | 66 } |
64 if (is_managed) | 67 if (is_managed) |
65 *is_managed = info.source == content_settings::SETTING_SOURCE_POLICY; | 68 *is_managed = info.source == content_settings::SETTING_SOURCE_POLICY; |
| 69 |
| 70 // For non-JavaScript treated plugins (Flash): unless the user has explicitly |
| 71 // ALLOWed plugins, return BLOCK for any non-HTTP and non-FILE origin. |
| 72 if (!use_javascript_setting && *setting != CONTENT_SETTING_ALLOW && |
| 73 base::FeatureList::IsEnabled(features::kPreferHtmlOverPlugins) && |
| 74 !main_frame_url.SchemeIsHTTPOrHTTPS() && !main_frame_url.SchemeIsFile()) { |
| 75 *setting = CONTENT_SETTING_BLOCK; |
| 76 } |
66 } | 77 } |
67 | 78 |
68 } // namespace | 79 } // namespace |
69 | 80 |
70 // static | 81 // static |
71 void PluginUtils::GetPluginContentSetting( | 82 void PluginUtils::GetPluginContentSetting( |
72 const HostContentSettingsMap* host_content_settings_map, | 83 const HostContentSettingsMap* host_content_settings_map, |
73 const content::WebPluginInfo& plugin, | 84 const content::WebPluginInfo& plugin, |
74 const GURL& policy_url, | 85 const url::Origin& main_frame_origin, |
75 const GURL& plugin_url, | 86 const GURL& plugin_url, |
76 const std::string& resource, | 87 const std::string& resource, |
77 ContentSetting* setting, | 88 ContentSetting* setting, |
78 bool* uses_default_content_setting, | 89 bool* uses_default_content_setting, |
79 bool* is_managed) { | 90 bool* is_managed) { |
80 GetPluginContentSettingInternal(host_content_settings_map, | 91 GetPluginContentSettingInternal( |
81 ShouldUseJavaScriptSettingForPlugin(plugin), | 92 host_content_settings_map, ShouldUseJavaScriptSettingForPlugin(plugin), |
82 policy_url, plugin_url, resource, setting, | 93 main_frame_origin, plugin_url, resource, setting, |
83 uses_default_content_setting, is_managed); | 94 uses_default_content_setting, is_managed); |
84 } | 95 } |
85 | 96 |
86 // static | 97 // static |
87 ContentSetting PluginUtils::GetFlashPluginContentSetting( | 98 ContentSetting PluginUtils::GetFlashPluginContentSetting( |
88 const HostContentSettingsMap* host_content_settings_map, | 99 const HostContentSettingsMap* host_content_settings_map, |
89 const GURL& policy_url, | 100 const url::Origin& main_frame_origin, |
90 const GURL& plugin_url, | 101 const GURL& plugin_url, |
91 bool* is_managed) { | 102 bool* is_managed) { |
92 ContentSetting plugin_setting = CONTENT_SETTING_DEFAULT; | 103 ContentSetting plugin_setting = CONTENT_SETTING_DEFAULT; |
93 GetPluginContentSettingInternal( | 104 GetPluginContentSettingInternal(host_content_settings_map, |
94 host_content_settings_map, false /* use_javascript_setting */, policy_url, | 105 false /* use_javascript_setting */, |
95 plugin_url, kFlashPluginID, &plugin_setting, nullptr, is_managed); | 106 main_frame_origin, plugin_url, kFlashPluginID, |
| 107 &plugin_setting, nullptr, is_managed); |
96 return plugin_setting; | 108 return plugin_setting; |
97 } | 109 } |
OLD | NEW |