Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(124)

Side by Side Diff: chrome/browser/extensions/permissions_updater.h

Issue 2499493004: Communicate ExtensionSettings policy to renderers (Closed)
Patch Set: Add URLPattern effective TLD whitelisting, Switched IPC to UpdatePermissions, Removed shared memor… Created 3 years, 11 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #ifndef CHROME_BROWSER_EXTENSIONS_PERMISSIONS_UPDATER_H__ 5 #ifndef CHROME_BROWSER_EXTENSIONS_PERMISSIONS_UPDATER_H__
6 #define CHROME_BROWSER_EXTENSIONS_PERMISSIONS_UPDATER_H__ 6 #define CHROME_BROWSER_EXTENSIONS_PERMISSIONS_UPDATER_H__
7 7
8 #include <memory> 8 #include <memory>
9 #include <string> 9 #include <string>
10 10
11 #include "base/macros.h" 11 #include "base/macros.h"
12 #include "base/memory/shared_memory.h"
Devlin 2017/01/26 22:47:39 needed?
nrpeter 2017/02/03 19:32:24 Done.
12 #include "extensions/browser/extension_event_histogram_value.h" 13 #include "extensions/browser/extension_event_histogram_value.h"
13 14
14 namespace base { 15 namespace base {
15 class DictionaryValue; 16 class DictionaryValue;
16 } 17 }
17 18
18 namespace content { 19 namespace content {
19 class BrowserContext; 20 class BrowserContext;
20 } 21 }
21 22
22 namespace extensions { 23 namespace extensions {
23 24
24 class Extension; 25 class Extension;
25 class ExtensionPrefs; 26 class ExtensionPrefs;
26 class PermissionSet; 27 class PermissionSet;
28 class URLPatternSet;
27 29
28 // Updates an Extension's active and granted permissions in persistent storage 30 // Updates an Extension's active and granted permissions in persistent storage
29 // and notifies interested parties of the changes. 31 // and notifies interested parties of the changes.
30 class PermissionsUpdater { 32 class PermissionsUpdater {
31 public: 33 public:
32 enum InitFlag { 34 enum InitFlag {
33 INIT_FLAG_NONE = 0, 35 INIT_FLAG_NONE = 0,
34 INIT_FLAG_TRANSIENT = 1 << 0, 36 INIT_FLAG_TRANSIENT = 1 << 0,
35 }; 37 };
36 38
(...skipping 25 matching lines...) Expand all
62 void RemovePermissions(const Extension* extension, 64 void RemovePermissions(const Extension* extension,
63 const PermissionSet& permissions, 65 const PermissionSet& permissions,
64 RemoveType remove_type); 66 RemoveType remove_type);
65 67
66 // Removes the |permissions| from |extension| and makes no effort to determine 68 // Removes the |permissions| from |extension| and makes no effort to determine
67 // if doing so is safe in the slightlest. This method shouldn't be used, 69 // if doing so is safe in the slightlest. This method shouldn't be used,
68 // except for removing permissions totally blacklisted by management. 70 // except for removing permissions totally blacklisted by management.
69 void RemovePermissionsUnsafe(const Extension* extension, 71 void RemovePermissionsUnsafe(const Extension* extension,
70 const PermissionSet& permissions); 72 const PermissionSet& permissions);
71 73
74 // Sets list of hosts |extension| may not interact with (overrides default).
75 // This is the individual scope of ExtensionSettings.
76 void SetPolicyHostRestrictions(const Extension* extension,
Devlin 2017/01/26 22:47:39 See comment in extension_service.cc
nrpeter 2017/02/03 19:32:24 Done.
77 const URLPatternSet& runtime_blocked_hosts,
Devlin 2017/01/26 22:47:39 don't forget to use git cl format - it's a life-sa
nrpeter 2017/02/03 19:32:24 Done.
78 const URLPatternSet& runtime_allowed_hosts,
79 bool is_default);
80
81 // Sets list of hosts extensions may not interact with. Extension specific
82 // exceptions to this default policy are defined with
83 // SetPolicyHostRestrictions. This is the Deault scope "*" of
84 // ExtensionSettings.
85 void SetDefaultPolicyHostRestrictions(
86 const URLPatternSet& default_runtime_blocked_hosts,
87 const URLPatternSet& default_runtime_allowed_hosts);
88
72 // Returns the set of revokable permissions. 89 // Returns the set of revokable permissions.
73 std::unique_ptr<const PermissionSet> GetRevokablePermissions( 90 std::unique_ptr<const PermissionSet> GetRevokablePermissions(
74 const Extension* extension) const; 91 const Extension* extension) const;
75 92
76 // Adds all permissions in the |extension|'s active permissions to its 93 // Adds all permissions in the |extension|'s active permissions to its
77 // granted permission set. 94 // granted permission set.
78 void GrantActivePermissions(const Extension* extension); 95 void GrantActivePermissions(const Extension* extension);
79 96
80 // Initializes the |extension|'s active permission set to include only 97 // Initializes the |extension|'s active permission set to include only
81 // permissions currently requested by the extension and all the permissions 98 // permissions currently requested by the extension and all the permissions
82 // required by the extension. 99 // required by the extension.
83 void InitializePermissions(const Extension* extension); 100 void InitializePermissions(const Extension* extension);
84 101
85 private: 102 private:
86 enum EventType { 103 enum EventType {
87 ADDED, 104 ADDED,
88 REMOVED, 105 REMOVED,
106 POLICY
Devlin 2017/01/26 22:47:39 nit: trailing comma
nrpeter 2017/02/03 19:32:24 Done.
89 }; 107 };
90 108
91 // Sets the |extension|'s active permissions to |active| and records the 109 // Sets the |extension|'s active permissions to |active| and records the
92 // change in the prefs. If |withheld| is non-null, also sets the extension's 110 // change in the prefs. If |withheld| is non-null, also sets the extension's
93 // withheld permissions to |withheld|. Otherwise, |withheld| permissions are 111 // withheld permissions to |withheld|. Otherwise, |withheld| permissions are
94 // not changed. 112 // not changed.
95 void SetPermissions(const Extension* extension, 113 void SetPermissions(const Extension* extension,
96 std::unique_ptr<const PermissionSet> active, 114 std::unique_ptr<const PermissionSet> active,
97 std::unique_ptr<const PermissionSet> withheld); 115 std::unique_ptr<const PermissionSet> withheld);
98 116
99 // Dispatches specified event to the extension. 117 // Dispatches specified event to the extension.
100 void DispatchEvent(const std::string& extension_id, 118 void DispatchEvent(const std::string& extension_id,
101 events::HistogramValue histogram_value, 119 events::HistogramValue histogram_value,
102 const char* event_name, 120 const char* event_name,
103 const PermissionSet& changed_permissions); 121 const PermissionSet& changed_permissions);
104 122
105 // Issues the relevant events, messages and notifications when the 123 // Issues the relevant events, messages and notifications when the
106 // |extension|'s permissions have |changed| (|changed| is the delta). 124 // |extension|'s permissions have |changed| (|changed| is the delta).
107 // Specifically, this sends the EXTENSION_PERMISSIONS_UPDATED notification, 125 // Specifically, this sends the EXTENSION_PERMISSIONS_UPDATED notification,
108 // the ExtensionMsg_UpdatePermissions IPC message, and fires the 126 // the ExtensionMsg_UpdatePermissions IPC message, and fires the
109 // onAdded/onRemoved events in the extension. 127 // onAdded/onRemoved events in the extension.
110 void NotifyPermissionsUpdated(EventType event_type, 128 void NotifyPermissionsUpdated(EventType event_type,
111 const Extension* extension, 129 const Extension* extension,
112 const PermissionSet& changed); 130 const PermissionSet& changed);
113 131
132 // Issues the relevant events, messages and notifications when the
133 // default scope management policy have changed.
134 // Specifically, this sends the ExtensionMsg_UpdateDefaultHostRestrictions
135 // IPC message.
136 void NotifyDefaultPolicyHostRestrictionsUpdated(
137 const URLPatternSet& default_runtime_blocked_hosts,
138 const URLPatternSet& default_runtime_allowed_hosts);
139
114 // The associated BrowserContext. 140 // The associated BrowserContext.
115 content::BrowserContext* browser_context_; 141 content::BrowserContext* browser_context_;
116 142
117 // Initialization flag that determines whether prefs is consulted about the 143 // Initialization flag that determines whether prefs is consulted about the
118 // extension. Transient extensions should not have entries in prefs. 144 // extension. Transient extensions should not have entries in prefs.
119 InitFlag init_flag_; 145 InitFlag init_flag_;
120 146
121 DISALLOW_COPY_AND_ASSIGN(PermissionsUpdater); 147 DISALLOW_COPY_AND_ASSIGN(PermissionsUpdater);
122 }; 148 };
123 149
124 } // namespace extensions 150 } // namespace extensions
125 151
126 #endif // CHROME_BROWSER_EXTENSIONS_PERMISSIONS_UPDATER_H__ 152 #endif // CHROME_BROWSER_EXTENSIONS_PERMISSIONS_UPDATER_H__
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698