Chromium Code Reviews| Index: extensions/browser/api/web_request/web_request_permissions.cc |
| diff --git a/extensions/browser/api/web_request/web_request_permissions.cc b/extensions/browser/api/web_request/web_request_permissions.cc |
| index c4ac79580cec811af010da24ee14d79d50018e26..1989484fc43fb33601cc7680761aed267bb430c6 100644 |
| --- a/extensions/browser/api/web_request/web_request_permissions.cc |
| +++ b/extensions/browser/api/web_request/web_request_permissions.cc |
| @@ -6,6 +6,7 @@ |
| #include "base/strings/string_util.h" |
| #include "base/strings/stringprintf.h" |
| +#include "chromeos/login/login_state.h" |
| #include "content/public/browser/resource_request_info.h" |
| #include "extensions/browser/extension_navigation_ui_data.h" |
| #include "extensions/browser/guest_view/web_view/web_view_renderer_state.h" |
| @@ -108,6 +109,18 @@ bool WebRequestPermissions::HideRequest( |
| return IsSensitiveURL(url) || !HasWebRequestScheme(url); |
| } |
| +namespace { |
| + |
| +bool g_allow_all_extension_locations_in_public_session = false; |
|
Devlin
2016/11/15 15:12:02
This should go in the existing anonymous namespace
Ivan Šandrk
2016/11/15 16:07:40
Done.
|
| + |
| +} // namespace |
| + |
| +// static |
| +void WebRequestPermissions:: |
| + AllowAllExtensionLocationsInPublicSessionForTesting(bool value) { |
| + g_allow_all_extension_locations_in_public_session = value; |
| +} |
| + |
| // static |
| PermissionsData::AccessType WebRequestPermissions::CanExtensionAccessURL( |
| const extensions::InfoMap* extension_info_map, |
| @@ -125,6 +138,20 @@ PermissionsData::AccessType WebRequestPermissions::CanExtensionAccessURL( |
| if (!extension) |
| return PermissionsData::ACCESS_DENIED; |
| + // When we are in a Public Session, allow all URLs for webRequests initiated |
| + // by a regular extension. |
| +#if defined(OS_CHROMEOS) |
| + if (chromeos::LoginState::IsInitialized() && |
| + chromeos::LoginState::Get()->IsPublicSessionUser() && |
| + extension->is_extension()) { |
| + // Make sure that the extension is truly installed by policy (the assumption |
| + // in Public Session is that all extensions are installed by policy). |
| + CHECK(g_allow_all_extension_locations_in_public_session || |
| + extensions::Manifest::IsPolicyLocation(extension->location())); |
| + return PermissionsData::ACCESS_ALLOWED; |
| + } |
| +#endif |
| + |
| // Check if this event crosses incognito boundaries when it shouldn't. |
| if (crosses_incognito && !extension_info_map->CanCrossIncognito(extension)) |
| return PermissionsData::ACCESS_DENIED; |