Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(88)

Issue 2794803003: PS - Remove Clipboard Read permission from extensions in Public Sessions (except for whitelisted on… (Closed)

Created:
3 years, 8 months ago by Ivan Šandrk
Modified:
3 years, 8 months ago
CC:
chromium-reviews, chromium-apps-reviews_chromium.org, oshima+watch_chromium.org, davemoore+watch_chromium.org, extensions-reviews_chromium.org
Target Ref:
refs/heads/master
Project:
chromium
Visibility:
Public.

Description

PS - Remove Clipboard Read permission from extensions in Public Sessions (except for whitelisted ones) In Public Sessions, apps and extensions are force-installed by admin policy so the user does not get a chance to review the permissions for these apps. This is not acceptable from a security standpoint, so we remove ClipboardRead permission from them (except for whitelisted ones - eg. remote desktop clients). This forceful removal of permission is safe since the clipboard pasting code checks for this permission before doing the paste. TEST= unit_tests --gtest_filter=DeviceLocalAccountManagementPolicyProviderTest.IsWhitelisted unit_tests --gtest_filter=PermissionsUpdaterDelegateChromeOSTest.* unit_tests --gtest_filter=PermissionsUpdaterTest.Delegate BUG=707864 Review-Url: https://codereview.chromium.org/2794803003 Cr-Commit-Position: refs/heads/master@{#464031} Committed: https://chromium.googlesource.com/chromium/src/+/80e3eb904ef28e2491b831099597fc05347845ae

Patch Set 1 #

Total comments: 2

Patch Set 2 : Using a platform delegate #

Total comments: 14

Patch Set 3 : Set delegate from Public Session specific code #

Patch Set 4 : Added tests #

Total comments: 6

Patch Set 5 : Updated comments #

Total comments: 13

Patch Set 6 : Drew's comments #

Patch Set 7 : Fixed test crash #

Total comments: 4

Patch Set 8 : Updated comment #

Unified diffs Side-by-side diffs Delta from patch set Stats (+298 lines, -2 lines) Patch
M chrome/browser/chromeos/BUILD.gn View 1 2 3 2 chunks +3 lines, -0 lines 0 comments Download
M chrome/browser/chromeos/extensions/device_local_account_management_policy_provider.h View 2 chunks +5 lines, -0 lines 0 comments Download
M chrome/browser/chromeos/extensions/device_local_account_management_policy_provider.cc View 2 chunks +7 lines, -1 line 0 comments Download
M chrome/browser/chromeos/extensions/device_local_account_management_policy_provider_unittest.cc View 1 2 3 2 chunks +13 lines, -0 lines 0 comments Download
A chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.h View 1 2 3 4 1 chunk +39 lines, -0 lines 0 comments Download
A chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc View 1 2 3 4 1 chunk +42 lines, -0 lines 0 comments Download
A chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos_unittest.cc View 1 2 3 1 chunk +98 lines, -0 lines 0 comments Download
M chrome/browser/chromeos/login/users/chrome_user_manager_impl.cc View 1 2 3 4 5 3 chunks +10 lines, -0 lines 0 comments Download
M chrome/browser/extensions/permissions_updater.h View 1 2 3 4 5 6 7 2 chunks +17 lines, -0 lines 0 comments Download
M chrome/browser/extensions/permissions_updater.cc View 1 2 3 4 5 6 4 chunks +14 lines, -1 line 0 comments Download
M chrome/browser/extensions/permissions_updater_unittest.cc View 1 2 3 2 chunks +50 lines, -0 lines 0 comments Download

Messages

Total messages: 67 (47 generated)
Ivan Šandrk
Hey Devlin, take a preliminary stab at this just to make sure I'm not doing ...
3 years, 8 months ago (2017-04-03 18:56:39 UTC) #4
Devlin
https://codereview.chromium.org/2794803003/diff/1/chrome/browser/extensions/permissions_updater.cc File chrome/browser/extensions/permissions_updater.cc (right): https://codereview.chromium.org/2794803003/diff/1/chrome/browser/extensions/permissions_updater.cc#newcode208 chrome/browser/extensions/permissions_updater.cc:208: #if defined(OS_CHROMEOS) I'd like to avoid adding so many ...
3 years, 8 months ago (2017-04-03 20:39:20 UTC) #7
Ivan Šandrk
Moved out platform specific code to a delegate. Ptal again! https://codereview.chromium.org/2794803003/diff/20001/chrome/browser/extensions/permissions_updater.cc File chrome/browser/extensions/permissions_updater.cc (right): https://codereview.chromium.org/2794803003/diff/20001/chrome/browser/extensions/permissions_updater.cc#newcode80 ...
3 years, 8 months ago (2017-04-04 15:41:57 UTC) #10
Ivan Šandrk
Hey Drew, ptal!
3 years, 8 months ago (2017-04-05 09:09:19 UTC) #14
Devlin
https://codereview.chromium.org/2794803003/diff/20001/chrome/browser/extensions/permissions_updater.cc File chrome/browser/extensions/permissions_updater.cc (right): https://codereview.chromium.org/2794803003/diff/20001/chrome/browser/extensions/permissions_updater.cc#newcode80 chrome/browser/extensions/permissions_updater.cc:80: if (!g_delegate) On 2017/04/04 15:41:56, Ivan Šandrk wrote: > ...
3 years, 8 months ago (2017-04-05 14:35:20 UTC) #15
Andrew T Wilson (Slow)
+1 to existing comments, also is it possible to add tests? At least testing the ...
3 years, 8 months ago (2017-04-06 13:19:57 UTC) #16
Ivan Šandrk
Hey guys, ptal again! Alexander, ptal at chrome/browser/chromeos/login/users/chrome_user_manager_impl.cc https://codereview.chromium.org/2794803003/diff/20001/chrome/browser/extensions/permissions_updater.cc File chrome/browser/extensions/permissions_updater.cc (right): https://codereview.chromium.org/2794803003/diff/20001/chrome/browser/extensions/permissions_updater.cc#newcode80 chrome/browser/extensions/permissions_updater.cc:80: if ...
3 years, 8 months ago (2017-04-07 14:39:40 UTC) #35
Alexander Alekseev
chrome_user_manager_impl.cc lgtm
3 years, 8 months ago (2017-04-07 22:49:38 UTC) #39
Devlin
extensions lgtm A few other drive-by nits, but in general, this looks great. :) https://codereview.chromium.org/2794803003/diff/120001/chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc ...
3 years, 8 months ago (2017-04-08 00:30:51 UTC) #40
Ivan Šandrk
Thanks for the explanations Devlin, learned something new :-) https://codereview.chromium.org/2794803003/diff/120001/chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc File chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc (right): https://codereview.chromium.org/2794803003/diff/120001/chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc#newcode26 chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc:26: ...
3 years, 8 months ago (2017-04-10 12:04:35 UTC) #43
Andrew T Wilson (Slow)
https://codereview.chromium.org/2794803003/diff/140001/chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc File chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc (right): https://codereview.chromium.org/2794803003/diff/140001/chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc#newcode27 chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc:27: !(*granted_permissions) Why check for this here? If kClipboardRead isn't ...
3 years, 8 months ago (2017-04-11 11:32:54 UTC) #46
Ivan Šandrk
Drew, I've adressed your comments. Ptal https://codereview.chromium.org/2794803003/diff/140001/chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc File chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc (right): https://codereview.chromium.org/2794803003/diff/140001/chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc#newcode27 chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc:27: !(*granted_permissions) On 2017/04/11 ...
3 years, 8 months ago (2017-04-11 13:37:27 UTC) #49
Devlin
(just responding to some questions) https://codereview.chromium.org/2794803003/diff/140001/chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc File chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc (right): https://codereview.chromium.org/2794803003/diff/140001/chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc#newcode27 chrome/browser/chromeos/extensions/permissions_updater_delegate_chromeos.cc:27: !(*granted_permissions) On 2017/04/11 13:37:27, ...
3 years, 8 months ago (2017-04-11 15:03:38 UTC) #54
Devlin
https://codereview.chromium.org/2794803003/diff/180001/chrome/browser/extensions/permissions_updater.h File chrome/browser/extensions/permissions_updater.h (right): https://codereview.chromium.org/2794803003/diff/180001/chrome/browser/extensions/permissions_updater.h#newcode56 chrome/browser/extensions/permissions_updater.h:56: // freed but this is fine since it will ...
3 years, 8 months ago (2017-04-11 15:06:22 UTC) #55
Ivan Šandrk
https://codereview.chromium.org/2794803003/diff/180001/chrome/browser/extensions/permissions_updater.h File chrome/browser/extensions/permissions_updater.h (right): https://codereview.chromium.org/2794803003/diff/180001/chrome/browser/extensions/permissions_updater.h#newcode56 chrome/browser/extensions/permissions_updater.h:56: // freed but this is fine since it will ...
3 years, 8 months ago (2017-04-11 15:11:16 UTC) #56
Devlin
https://codereview.chromium.org/2794803003/diff/180001/chrome/browser/extensions/permissions_updater.h File chrome/browser/extensions/permissions_updater.h (right): https://codereview.chromium.org/2794803003/diff/180001/chrome/browser/extensions/permissions_updater.h#newcode56 chrome/browser/extensions/permissions_updater.h:56: // freed but this is fine since it will ...
3 years, 8 months ago (2017-04-11 15:15:02 UTC) #57
Andrew T Wilson (Slow)
lgtm
3 years, 8 months ago (2017-04-12 13:11:57 UTC) #60
Ivan Šandrk
https://codereview.chromium.org/2794803003/diff/180001/chrome/browser/extensions/permissions_updater.h File chrome/browser/extensions/permissions_updater.h (right): https://codereview.chromium.org/2794803003/diff/180001/chrome/browser/extensions/permissions_updater.h#newcode56 chrome/browser/extensions/permissions_updater.h:56: // freed but this is fine since it will ...
3 years, 8 months ago (2017-04-12 13:57:47 UTC) #61
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2794803003/200001
3 years, 8 months ago (2017-04-12 13:58:34 UTC) #64
commit-bot: I haz the power
3 years, 8 months ago (2017-04-12 15:23:20 UTC) #67
Message was sent while issue was closed.
Committed patchset #8 (id:200001) as
https://chromium.googlesource.com/chromium/src/+/80e3eb904ef28e2491b831099597...

Powered by Google App Engine
This is Rietveld 408576698