Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(49)

Side by Side Diff: chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc

Issue 2486843003: Allow navigations to non-web-accessible resources from chrome schemes. (Closed)
Patch Set: Created 4 years, 1 month ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright 2014 The Chromium Authors. All rights reserved. 1 // Copyright 2014 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "chrome/browser/extensions/chrome_content_browser_client_extensions_par t.h" 5 #include "chrome/browser/extensions/chrome_content_browser_client_extensions_par t.h"
6 6
7 #include <stddef.h> 7 #include <stddef.h>
8 8
9 #include <set> 9 #include <set>
10 10
11 #include "base/command_line.h" 11 #include "base/command_line.h"
12 #include "base/debug/alias.h" 12 #include "base/debug/alias.h"
13 #include "base/debug/dump_without_crashing.h" 13 #include "base/debug/dump_without_crashing.h"
14 #include "base/metrics/histogram_macros.h" 14 #include "base/metrics/histogram_macros.h"
15 #include "chrome/browser/browser_process.h" 15 #include "chrome/browser/browser_process.h"
16 #include "chrome/browser/extensions/extension_service.h" 16 #include "chrome/browser/extensions/extension_service.h"
17 #include "chrome/browser/extensions/extension_web_ui.h" 17 #include "chrome/browser/extensions/extension_web_ui.h"
18 #include "chrome/browser/extensions/extension_webkit_preferences.h" 18 #include "chrome/browser/extensions/extension_webkit_preferences.h"
19 #include "chrome/browser/media_galleries/fileapi/media_file_system_backend.h" 19 #include "chrome/browser/media_galleries/fileapi/media_file_system_backend.h"
20 #include "chrome/browser/profiles/profile.h" 20 #include "chrome/browser/profiles/profile.h"
21 #include "chrome/browser/profiles/profile_io_data.h" 21 #include "chrome/browser/profiles/profile_io_data.h"
22 #include "chrome/browser/profiles/profile_manager.h" 22 #include "chrome/browser/profiles/profile_manager.h"
23 #include "chrome/browser/renderer_host/chrome_extension_message_filter.h" 23 #include "chrome/browser/renderer_host/chrome_extension_message_filter.h"
24 #include "chrome/browser/sync_file_system/local/sync_file_system_backend.h" 24 #include "chrome/browser/sync_file_system/local/sync_file_system_backend.h"
25 #include "chrome/common/chrome_constants.h" 25 #include "chrome/common/chrome_constants.h"
26 #include "chrome/common/chrome_switches.h" 26 #include "chrome/common/chrome_switches.h"
27 #include "chrome/common/extensions/extension_process_policy.h" 27 #include "chrome/common/extensions/extension_process_policy.h"
28 #include "chrome/common/url_constants.h"
28 #include "components/guest_view/browser/guest_view_message_filter.h" 29 #include "components/guest_view/browser/guest_view_message_filter.h"
29 #include "content/public/browser/browser_thread.h" 30 #include "content/public/browser/browser_thread.h"
30 #include "content/public/browser/browser_url_handler.h" 31 #include "content/public/browser/browser_url_handler.h"
31 #include "content/public/browser/render_process_host.h" 32 #include "content/public/browser/render_process_host.h"
32 #include "content/public/browser/render_view_host.h" 33 #include "content/public/browser/render_view_host.h"
33 #include "content/public/browser/resource_dispatcher_host.h" 34 #include "content/public/browser/resource_dispatcher_host.h"
34 #include "content/public/browser/site_instance.h" 35 #include "content/public/browser/site_instance.h"
35 #include "content/public/browser/storage_partition.h" 36 #include "content/public/browser/storage_partition.h"
36 #include "content/public/browser/vpn_service_proxy.h" 37 #include "content/public/browser/vpn_service_proxy.h"
37 #include "content/public/browser/web_contents.h" 38 #include "content/public/browser/web_contents.h"
38 #include "content/public/common/content_switches.h" 39 #include "content/public/common/content_switches.h"
40 #include "content/public/common/url_constants.h"
39 #include "extensions/browser/api/web_request/web_request_api.h" 41 #include "extensions/browser/api/web_request/web_request_api.h"
40 #include "extensions/browser/api/web_request/web_request_api_helpers.h" 42 #include "extensions/browser/api/web_request/web_request_api_helpers.h"
41 #include "extensions/browser/bad_message.h" 43 #include "extensions/browser/bad_message.h"
42 #include "extensions/browser/extension_host.h" 44 #include "extensions/browser/extension_host.h"
43 #include "extensions/browser/extension_message_filter.h" 45 #include "extensions/browser/extension_message_filter.h"
44 #include "extensions/browser/extension_registry.h" 46 #include "extensions/browser/extension_registry.h"
45 #include "extensions/browser/extension_service_worker_message_filter.h" 47 #include "extensions/browser/extension_service_worker_message_filter.h"
46 #include "extensions/browser/extension_system.h" 48 #include "extensions/browser/extension_system.h"
47 #include "extensions/browser/guest_view/extensions_guest_view_message_filter.h" 49 #include "extensions/browser/guest_view/extensions_guest_view_message_filter.h"
48 #include "extensions/browser/guest_view/web_view/web_view_renderer_state.h" 50 #include "extensions/browser/guest_view/web_view/web_view_renderer_state.h"
(...skipping 465 matching lines...) Expand 10 before | Expand all | Expand 10 after
514 // could happen in the case of, e.g., an unloaded extension). 516 // could happen in the case of, e.g., an unloaded extension).
515 return extension != nullptr; 517 return extension != nullptr;
516 } 518 }
517 519
518 // static 520 // static
519 bool ChromeContentBrowserClientExtensionsPart::ShouldAllowOpenURL( 521 bool ChromeContentBrowserClientExtensionsPart::ShouldAllowOpenURL(
520 content::SiteInstance* site_instance, 522 content::SiteInstance* site_instance,
521 const GURL& to_url, 523 const GURL& to_url,
522 bool* result) { 524 bool* result) {
523 DCHECK(result); 525 DCHECK(result);
524
525 // Using url::Origin is important to properly handle blob: and filesystem: 526 // Using url::Origin is important to properly handle blob: and filesystem:
526 // URLs. 527 // URLs.
527 url::Origin to_origin(to_url); 528 url::Origin to_origin(to_url);
528 if (to_origin.scheme() != kExtensionScheme) { 529 if (to_origin.scheme() != kExtensionScheme) {
529 // We're not responsible for protecting this resource. Note that hosted 530 // We're not responsible for protecting this resource. Note that hosted
530 // apps fall into this category. 531 // apps fall into this category.
531 return false; 532 return false;
532 } 533 }
533 534
535 // Navigations from chrome:// or chrome-search:// pages need to be allowed,
536 // even if |to_url| is not web-accessible. See https://crbug.com/662602.
537 GURL site_url(site_instance->GetSiteURL());
538 if (site_url.SchemeIs(content::kChromeUIScheme) ||
539 site_url.SchemeIs(chrome::kChromeSearchScheme)) {
ncarter (slow) 2016/11/09 18:44:21 Are we sure we want to allow this for extension bl
alexmos 2016/11/09 22:20:31 Done, given the observation that Blink already blo
540 *result = true;
541 return true;
542 }
543
534 // Do not allow pages from the web or other extensions navigate to 544 // Do not allow pages from the web or other extensions navigate to
535 // non-web-accessible extension resources. 545 // non-web-accessible extension resources.
536 546
537 ExtensionRegistry* registry = 547 ExtensionRegistry* registry =
538 ExtensionRegistry::Get(site_instance->GetBrowserContext()); 548 ExtensionRegistry::Get(site_instance->GetBrowserContext());
539 const Extension* to_extension = 549 const Extension* to_extension =
540 registry->enabled_extensions().GetByID(to_origin.host()); 550 registry->enabled_extensions().GetByID(to_origin.host());
541 if (!to_extension) { 551 if (!to_extension) {
542 *result = true; 552 *result = true;
543 return true; 553 return true;
544 } 554 }
545 555
546 GURL site_url(site_instance->GetSiteURL());
547 const Extension* from_extension = 556 const Extension* from_extension =
548 registry->enabled_extensions().GetExtensionOrAppByURL(site_url); 557 registry->enabled_extensions().GetExtensionOrAppByURL(site_url);
549 if (from_extension && from_extension == to_extension) { 558 if (from_extension && from_extension == to_extension) {
550 *result = true; 559 *result = true;
551 return true; 560 return true;
552 } 561 }
553 562
554 // Blob and filesystem URLs are never considered web-accessible. See 563 // Blob and filesystem URLs are never considered web-accessible. See
555 // https://crbug.com/656752. 564 // https://crbug.com/656752.
556 if (to_url.SchemeIsFileSystem() || to_url.SchemeIsBlob()) { 565 if (to_url.SchemeIsFileSystem() || to_url.SchemeIsBlob()) {
(...skipping 200 matching lines...) Expand 10 before | Expand all | Expand 10 after
757 command_line->AppendSwitch(switches::kExtensionProcess); 766 command_line->AppendSwitch(switches::kExtensionProcess);
758 } 767 }
759 } 768 }
760 769
761 void ChromeContentBrowserClientExtensionsPart::ResourceDispatcherHostCreated() { 770 void ChromeContentBrowserClientExtensionsPart::ResourceDispatcherHostCreated() {
762 content::ResourceDispatcherHost::Get()->RegisterInterceptor( 771 content::ResourceDispatcherHost::Get()->RegisterInterceptor(
763 "Origin", kExtensionScheme, base::Bind(&OnHttpHeaderReceived)); 772 "Origin", kExtensionScheme, base::Bind(&OnHttpHeaderReceived));
764 } 773 }
765 774
766 } // namespace extensions 775 } // namespace extensions
OLDNEW
« no previous file with comments | « no previous file | chrome/browser/extensions/window_open_apitest.cc » ('j') | chrome/browser/extensions/window_open_apitest.cc » ('J')

Powered by Google App Engine
This is Rietveld 408576698