| OLD | NEW |
| 1 // Copyright 2017 The Chromium Authors. All rights reserved. | 1 // Copyright 2017 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "components/payments/content/utility/payment_manifest_parser.h" | 5 #include "components/payments/content/utility/payment_manifest_parser.h" |
| 6 | 6 |
| 7 #include <stddef.h> | 7 #include <stddef.h> |
| 8 | 8 |
| 9 #include <memory> | 9 #include <memory> |
| 10 #include <utility> | 10 #include <utility> |
| 11 | 11 |
| 12 #include "base/json/json_reader.h" | 12 #include "base/json/json_reader.h" |
| 13 #include "base/memory/ptr_util.h" | 13 #include "base/memory/ptr_util.h" |
| 14 #include "base/strings/string_number_conversions.h" |
| 14 #include "base/strings/string_util.h" | 15 #include "base/strings/string_util.h" |
| 15 #include "base/values.h" | 16 #include "base/values.h" |
| 16 #include "components/payments/content/utility/fingerprint_parser.h" | 17 #include "components/payments/content/utility/fingerprint_parser.h" |
| 17 #include "mojo/public/cpp/bindings/strong_binding.h" | 18 #include "mojo/public/cpp/bindings/strong_binding.h" |
| 19 #include "url/url_constants.h" |
| 18 | 20 |
| 19 namespace payments { | 21 namespace payments { |
| 20 | 22 |
| 21 // static | 23 // static |
| 22 void PaymentManifestParser::Create( | 24 void PaymentManifestParser::Create( |
| 23 mojom::PaymentManifestParserRequest request) { | 25 mojom::PaymentManifestParserRequest request) { |
| 24 mojo::MakeStrongBinding(base::MakeUnique<PaymentManifestParser>(), | 26 mojo::MakeStrongBinding(base::MakeUnique<PaymentManifestParser>(), |
| 25 std::move(request)); | 27 std::move(request)); |
| 26 } | 28 } |
| 27 | 29 |
| 28 // static | 30 // static |
| 29 std::vector<mojom::PaymentManifestSectionPtr> | 31 std::vector<GURL> PaymentManifestParser::ParsePaymentMethodManifestIntoVector( |
| 30 PaymentManifestParser::ParseIntoVector(const std::string& input) { | 32 const std::string& input) { |
| 31 std::vector<mojom::PaymentManifestSectionPtr> output; | 33 std::vector<GURL> output; |
| 32 std::unique_ptr<base::Value> value(base::JSONReader::Read(input)); | 34 std::unique_ptr<base::Value> value(base::JSONReader::Read(input)); |
| 33 if (!value) | 35 if (!value) |
| 34 return output; | 36 return output; |
| 35 | 37 |
| 36 std::unique_ptr<base::DictionaryValue> dict = | 38 std::unique_ptr<base::DictionaryValue> dict = |
| 37 base::DictionaryValue::From(std::move(value)); | 39 base::DictionaryValue::From(std::move(value)); |
| 38 if (!dict) | 40 if (!dict) |
| 39 return output; | 41 return output; |
| 40 | 42 |
| 41 base::ListValue* list = nullptr; | 43 base::ListValue* list = nullptr; |
| 42 if (!dict->GetList("android", &list) || !list) | 44 if (!dict->GetList("default_applications", &list)) |
| 43 return output; | 45 return output; |
| 44 | 46 |
| 45 size_t sections_size = list->GetSize(); | 47 size_t apps_number = list->GetSize(); |
| 46 const size_t kMaximumNumberOfSections = 100U; | 48 const size_t kMaximumNumberOfApps = 100U; |
| 47 if (sections_size > kMaximumNumberOfSections) | 49 if (apps_number > kMaximumNumberOfApps) |
| 48 return output; | 50 return output; |
| 49 | 51 |
| 50 const char* const kVersion = "version"; | 52 std::string item; |
| 51 const char* const kFingerprints = "sha256_cert_fingerprints"; | 53 for (size_t i = 0; i < apps_number; ++i) { |
| 52 for (size_t i = 0; i < sections_size; ++i) { | 54 if (!list->GetString(i, &item) && item.empty()) { |
| 53 base::DictionaryValue* item = nullptr; | |
| 54 if (!list->GetDictionary(i, &item) || !item) { | |
| 55 output.clear(); | 55 output.clear(); |
| 56 return output; | 56 return output; |
| 57 } | 57 } |
| 58 | 58 |
| 59 mojom::PaymentManifestSectionPtr section = | 59 GURL url(item); |
| 60 mojom::PaymentManifestSection::New(); | 60 if (!url.is_valid() || !url.SchemeIs(url::kHttpsScheme)) { |
| 61 section->version = 0; | |
| 62 | |
| 63 if (!item->GetString("package", §ion->package_name) || | |
| 64 section->package_name.empty() || | |
| 65 !base::IsStringASCII(section->package_name)) { | |
| 66 output.clear(); | 61 output.clear(); |
| 67 return output; | 62 return output; |
| 68 } | 63 } |
| 69 | 64 |
| 70 if (section->package_name == "*") { | 65 output.push_back(url); |
| 71 output.clear(); | 66 } |
| 72 // If there's a section with "package": "*", then it must be the only | |
| 73 // section and it should not have "version" or "sha256_cert_fingerprints". | |
| 74 // (Any deviations from a correct format cause the full file to be | |
| 75 // rejected.) | |
| 76 if (!item->HasKey(kVersion) && !item->HasKey(kFingerprints) && | |
| 77 sections_size == 1U) { | |
| 78 output.push_back(std::move(section)); | |
| 79 } | |
| 80 return output; | |
| 81 } | |
| 82 | 67 |
| 83 if (!item->HasKey(kVersion) || !item->HasKey(kFingerprints)) { | 68 return output; |
| 69 } |
| 70 |
| 71 // static |
| 72 std::vector<mojom::WebAppManifestSectionPtr> |
| 73 PaymentManifestParser::ParseWebAppManifestIntoVector(const std::string& input) { |
| 74 std::vector<mojom::WebAppManifestSectionPtr> output; |
| 75 std::unique_ptr<base::Value> value(base::JSONReader::Read(input)); |
| 76 if (!value) |
| 77 return output; |
| 78 |
| 79 std::unique_ptr<base::DictionaryValue> dict = |
| 80 base::DictionaryValue::From(std::move(value)); |
| 81 if (!dict) |
| 82 return output; |
| 83 |
| 84 base::ListValue* list = nullptr; |
| 85 if (!dict->GetList("related_applications", &list)) |
| 86 return output; |
| 87 |
| 88 size_t related_applications_size = list->GetSize(); |
| 89 for (size_t i = 0; i < related_applications_size; ++i) { |
| 90 base::DictionaryValue* related_application = nullptr; |
| 91 if (!list->GetDictionary(i, &related_application) || !related_application) { |
| 84 output.clear(); | 92 output.clear(); |
| 85 return output; | 93 return output; |
| 86 } | 94 } |
| 87 | 95 |
| 88 int version = 0; | 96 std::string platform; |
| 89 if (!item->GetInteger(kVersion, &version)) { | 97 if (!related_application->GetString("platform", &platform) || |
| 98 platform != "play") { |
| 99 continue; |
| 100 } |
| 101 |
| 102 const size_t kMaximumNumberOfRelatedApplications = 100U; |
| 103 if (output.size() >= kMaximumNumberOfRelatedApplications) { |
| 90 output.clear(); | 104 output.clear(); |
| 91 return output; | 105 return output; |
| 92 } | 106 } |
| 93 | 107 |
| 94 section->version = static_cast<int64_t>(version); | 108 const char* const kId = "id"; |
| 95 | 109 const char* const kMinVersion = "min_version"; |
| 96 base::ListValue* fingerprints = nullptr; | 110 const char* const kFingerprints = "fingerprints"; |
| 97 if (!item->GetList(kFingerprints, &fingerprints) || !fingerprints || | 111 if (!related_application->HasKey(kId) || |
| 98 fingerprints->empty()) { | 112 !related_application->HasKey(kMinVersion) || |
| 113 !related_application->HasKey(kFingerprints)) { |
| 99 output.clear(); | 114 output.clear(); |
| 100 return output; | 115 return output; |
| 101 } | 116 } |
| 102 | 117 |
| 103 size_t fingerprints_size = fingerprints->GetSize(); | 118 mojom::WebAppManifestSectionPtr section = |
| 104 const size_t kMaximumNumberOfFingerprints = 100U; | 119 mojom::WebAppManifestSection::New(); |
| 105 if (fingerprints_size > kMaximumNumberOfFingerprints) { | 120 section->min_version = 0; |
| 121 |
| 122 if (!related_application->GetString(kId, §ion->id) || |
| 123 section->id.empty() || !base::IsStringASCII(section->id)) { |
| 106 output.clear(); | 124 output.clear(); |
| 107 return output; | 125 return output; |
| 108 } | 126 } |
| 109 | 127 |
| 128 std::string min_version; |
| 129 if (!related_application->GetString(kMinVersion, &min_version) || |
| 130 min_version.empty() || !base::IsStringASCII(min_version) || |
| 131 !base::StringToInt64(min_version, §ion->min_version)) { |
| 132 output.clear(); |
| 133 return output; |
| 134 } |
| 135 |
| 136 const size_t kMaximumNumberOfFingerprints = 100U; |
| 137 base::ListValue* fingerprints_list = nullptr; |
| 138 if (!related_application->GetList(kFingerprints, &fingerprints_list) || |
| 139 fingerprints_list->empty() || |
| 140 fingerprints_list->GetSize() > kMaximumNumberOfFingerprints) { |
| 141 output.clear(); |
| 142 return output; |
| 143 } |
| 144 |
| 145 size_t fingerprints_size = fingerprints_list->GetSize(); |
| 110 for (size_t j = 0; j < fingerprints_size; ++j) { | 146 for (size_t j = 0; j < fingerprints_size; ++j) { |
| 111 std::string fingerprint; | 147 base::DictionaryValue* fingerprint_dict = nullptr; |
| 112 if (!fingerprints->GetString(j, &fingerprint) || fingerprint.empty()) { | 148 std::string fingerprint_type; |
| 149 std::string fingerprint_value; |
| 150 if (!fingerprints_list->GetDictionary(i, &fingerprint_dict) || |
| 151 !fingerprint_dict || |
| 152 !fingerprint_dict->GetString("type", &fingerprint_type) || |
| 153 fingerprint_type != "sha256_cert" || |
| 154 !fingerprint_dict->GetString("value", &fingerprint_value) || |
| 155 fingerprint_value.empty()) { |
| 113 output.clear(); | 156 output.clear(); |
| 114 return output; | 157 return output; |
| 115 } | 158 } |
| 116 | 159 |
| 117 std::vector<uint8_t> fingerprint_bytes = | 160 std::vector<uint8_t> hash = |
| 118 FingerprintStringToByteArray(fingerprint); | 161 FingerprintStringToByteArray(fingerprint_value); |
| 119 if (32U != fingerprint_bytes.size()) { | 162 if (hash.empty()) { |
| 120 output.clear(); | 163 output.clear(); |
| 121 return output; | 164 return output; |
| 122 } | 165 } |
| 123 | 166 |
| 124 section->sha256_cert_fingerprints.push_back(fingerprint_bytes); | 167 section->fingerprints.push_back(hash); |
| 125 } | 168 } |
| 126 | 169 |
| 127 output.push_back(std::move(section)); | 170 output.push_back(std::move(section)); |
| 128 } | 171 } |
| 129 | 172 |
| 130 return output; | 173 return output; |
| 131 } | 174 } |
| 132 | 175 |
| 133 PaymentManifestParser::PaymentManifestParser() {} | 176 PaymentManifestParser::PaymentManifestParser() {} |
| 134 | 177 |
| 135 PaymentManifestParser::~PaymentManifestParser() {} | 178 PaymentManifestParser::~PaymentManifestParser() {} |
| 136 | 179 |
| 137 void PaymentManifestParser::Parse(const std::string& content, | 180 void PaymentManifestParser::ParsePaymentMethodManifest( |
| 138 const ParseCallback& callback) { | 181 const std::string& content, |
| 139 callback.Run(ParseIntoVector(content)); | 182 const ParsePaymentMethodManifestCallback& callback) { |
| 183 callback.Run(ParsePaymentMethodManifestIntoVector(content)); |
| 184 } |
| 185 |
| 186 void PaymentManifestParser::ParseWebAppManifest( |
| 187 const std::string& content, |
| 188 const ParseWebAppManifestCallback& callback) { |
| 189 callback.Run(ParseWebAppManifestIntoVector(content)); |
| 140 } | 190 } |
| 141 | 191 |
| 142 } // namespace payments | 192 } // namespace payments |
| OLD | NEW |