| OLD | NEW |
| 1 // Copyright 2017 The Chromium Authors. All rights reserved. | 1 // Copyright 2017 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "chrome/browser/chromeos/extensions/permissions_updater_delegate_chrome
os.h" | 5 #include "chrome/browser/chromeos/extensions/permissions_updater_delegate_chrome
os.h" |
| 6 | 6 |
| 7 #include <string> | 7 #include <string> |
| 8 | 8 |
| 9 #include "base/files/file_path.h" | 9 #include "base/files/file_path.h" |
| 10 #include "base/memory/ptr_util.h" | 10 #include "base/memory/ptr_util.h" |
| 11 #include "base/values.h" | 11 #include "base/values.h" |
| 12 #include "chromeos/login/login_state.h" | 12 #include "chromeos/login/login_state.h" |
| 13 #include "extensions/common/extension.h" | 13 #include "extensions/common/extension.h" |
| 14 #include "extensions/common/manifest.h" | 14 #include "extensions/common/manifest.h" |
| 15 #include "extensions/common/manifest_constants.h" | 15 #include "extensions/common/manifest_constants.h" |
| 16 #include "extensions/common/permissions/api_permission.h" |
| 17 #include "extensions/common/permissions/api_permission_set.h" |
| 18 #include "extensions/common/permissions/manifest_permission.h" |
| 19 #include "extensions/common/permissions/manifest_permission_set.h" |
| 16 #include "extensions/common/permissions/permission_set.h" | 20 #include "extensions/common/permissions/permission_set.h" |
| 21 #include "extensions/common/url_pattern.h" |
| 22 #include "extensions/common/url_pattern_set.h" |
| 17 #include "testing/gtest/include/gtest/gtest.h" | 23 #include "testing/gtest/include/gtest/gtest.h" |
| 18 | 24 |
| 19 namespace extensions { | 25 namespace extensions { |
| 20 | 26 |
| 21 namespace { | 27 namespace { |
| 22 | 28 |
| 23 const char kWhitelistedId[] = "cbkkbcmdlboombapidmoeolnmdacpkch"; | 29 const char kWhitelistedId[] = "cbkkbcmdlboombapidmoeolnmdacpkch"; |
| 24 const char kBogusId[] = "bogus"; | 30 const char kBogusId[] = "bogus"; |
| 25 | 31 |
| 32 // TODO(isandrk, crbug.com/715638): Extract MockManifestPermission into its own |
| 33 // file (since it's duplicated in two places). |
| 34 class MockManifestPermission : public ManifestPermission { |
| 35 public: |
| 36 MockManifestPermission(const std::string& name) |
| 37 : name_(name) { |
| 38 } |
| 39 |
| 40 std::string name() const override { return name_; } |
| 41 |
| 42 std::string id() const override { return name(); } |
| 43 |
| 44 PermissionIDSet GetPermissions() const override { return PermissionIDSet(); } |
| 45 |
| 46 bool FromValue(const base::Value* value) override { return true; } |
| 47 |
| 48 std::unique_ptr<base::Value> ToValue() const override { |
| 49 return base::MakeUnique<base::Value>(); |
| 50 } |
| 51 |
| 52 ManifestPermission* Diff(const ManifestPermission* rhs) const override { |
| 53 const MockManifestPermission* other = |
| 54 static_cast<const MockManifestPermission*>(rhs); |
| 55 EXPECT_EQ(name_, other->name_); |
| 56 return NULL; |
| 57 } |
| 58 |
| 59 ManifestPermission* Union(const ManifestPermission* rhs) const override { |
| 60 const MockManifestPermission* other = |
| 61 static_cast<const MockManifestPermission*>(rhs); |
| 62 EXPECT_EQ(name_, other->name_); |
| 63 return new MockManifestPermission(name_); |
| 64 } |
| 65 |
| 66 ManifestPermission* Intersect(const ManifestPermission* rhs) const override { |
| 67 const MockManifestPermission* other = |
| 68 static_cast<const MockManifestPermission*>(rhs); |
| 69 EXPECT_EQ(name_, other->name_); |
| 70 return new MockManifestPermission(name_); |
| 71 } |
| 72 |
| 73 private: |
| 74 std::string name_; |
| 75 }; |
| 76 |
| 26 scoped_refptr<Extension> CreateExtension(const std::string& id) { | 77 scoped_refptr<Extension> CreateExtension(const std::string& id) { |
| 27 std::string error; | 78 std::string error; |
| 28 base::DictionaryValue manifest; | 79 base::DictionaryValue manifest; |
| 29 manifest.SetString(manifest_keys::kName, "test"); | 80 manifest.SetString(manifest_keys::kName, "test"); |
| 30 manifest.SetString(manifest_keys::kVersion, "0.1"); | 81 manifest.SetString(manifest_keys::kVersion, "0.1"); |
| 31 scoped_refptr<Extension> extension = Extension::Create( | 82 scoped_refptr<Extension> extension = Extension::Create( |
| 32 base::FilePath(), | 83 base::FilePath(), |
| 33 Manifest::INTERNAL, | 84 Manifest::INTERNAL, |
| 34 manifest, | 85 manifest, |
| 35 Extension::NO_FLAGS, | 86 Extension::NO_FLAGS, |
| 36 id, | 87 id, |
| 37 &error); | 88 &error); |
| 38 return extension; | 89 return extension; |
| 39 } | 90 } |
| 40 | 91 |
| 41 std::unique_ptr<const PermissionSet> CreatePermissions() { | 92 std::unique_ptr<const PermissionSet> CreatePermissions( |
| 93 bool include_clipboard = true) { |
| 42 APIPermissionSet apis; | 94 APIPermissionSet apis; |
| 43 apis.insert(APIPermission::kAudio); | 95 apis.insert(APIPermission::kAudio); |
| 44 apis.insert(APIPermission::kClipboardRead); | |
| 45 apis.insert(APIPermission::kFullscreen); | 96 apis.insert(APIPermission::kFullscreen); |
| 97 if (include_clipboard) |
| 98 apis.insert(APIPermission::kClipboardRead); |
| 99 ManifestPermissionSet manifest; |
| 100 manifest.insert(new MockManifestPermission("author")); |
| 101 manifest.insert(new MockManifestPermission("background")); |
| 102 URLPatternSet explicit_hosts({ |
| 103 URLPattern(URLPattern::SCHEME_ALL, "http://www.google.com/*"), |
| 104 URLPattern(URLPattern::SCHEME_ALL, "<all_urls>")}); |
| 105 URLPatternSet scriptable_hosts({ |
| 106 URLPattern(URLPattern::SCHEME_ALL, "http://www.wikipedia.com/*")}); |
| 46 auto permissions = base::MakeUnique<const PermissionSet>( | 107 auto permissions = base::MakeUnique<const PermissionSet>( |
| 47 apis, ManifestPermissionSet(), | 108 apis, manifest, explicit_hosts, scriptable_hosts); |
| 48 URLPatternSet(), URLPatternSet()); | |
| 49 return permissions; | 109 return permissions; |
| 50 } | 110 } |
| 51 | 111 |
| 52 } // namespace | 112 } // namespace |
| 53 | 113 |
| 54 TEST(PermissionsUpdaterDelegateChromeOSTest, NoFilteringOutsidePublicSession) { | 114 TEST(PermissionsUpdaterDelegateChromeOSTest, NoFilteringOutsidePublicSession) { |
| 55 PermissionsUpdaterDelegateChromeOS delegate; | 115 PermissionsUpdaterDelegateChromeOS delegate; |
| 56 ASSERT_FALSE(chromeos::LoginState::IsInitialized()); | 116 ASSERT_FALSE(chromeos::LoginState::IsInitialized()); |
| 57 | 117 |
| 58 // Whitelisted extension outside PS, nothing filtered. | 118 // Whitelisted extension outside PS, nothing filtered. |
| (...skipping 17 matching lines...) Expand all Loading... |
| 76 chromeos::LoginState::Get()->SetLoggedInState( | 136 chromeos::LoginState::Get()->SetLoggedInState( |
| 77 chromeos::LoginState::LOGGED_IN_ACTIVE, | 137 chromeos::LoginState::LOGGED_IN_ACTIVE, |
| 78 chromeos::LoginState::LOGGED_IN_USER_PUBLIC_ACCOUNT); | 138 chromeos::LoginState::LOGGED_IN_USER_PUBLIC_ACCOUNT); |
| 79 | 139 |
| 80 // Whitelisted extension, nothing gets filtered. | 140 // Whitelisted extension, nothing gets filtered. |
| 81 auto extension = CreateExtension(kWhitelistedId); | 141 auto extension = CreateExtension(kWhitelistedId); |
| 82 auto granted_permissions = CreatePermissions(); | 142 auto granted_permissions = CreatePermissions(); |
| 83 delegate.InitializePermissions(extension.get(), &granted_permissions); | 143 delegate.InitializePermissions(extension.get(), &granted_permissions); |
| 84 EXPECT_EQ(*CreatePermissions(), *granted_permissions); | 144 EXPECT_EQ(*CreatePermissions(), *granted_permissions); |
| 85 | 145 |
| 86 // Bogus extension ID (never whitelisted), ClipboardRead filtered out. | 146 // Bogus extension ID (never whitelisted), ClipboardRead filtered out, |
| 147 // everything else stays. |
| 87 extension = CreateExtension(kBogusId); | 148 extension = CreateExtension(kBogusId); |
| 88 granted_permissions = CreatePermissions(); | 149 granted_permissions = CreatePermissions(); |
| 89 delegate.InitializePermissions(extension.get(), &granted_permissions); | 150 delegate.InitializePermissions(extension.get(), &granted_permissions); |
| 90 EXPECT_FALSE(granted_permissions->HasAPIPermission( | 151 EXPECT_EQ(*CreatePermissions(false), *granted_permissions); |
| 91 APIPermission::kClipboardRead)); | |
| 92 EXPECT_EQ(2u, granted_permissions->apis().size()); | |
| 93 | 152 |
| 94 // Reset state at the end of test. | 153 // Reset state at the end of test. |
| 95 chromeos::LoginState::Shutdown(); | 154 chromeos::LoginState::Shutdown(); |
| 96 } | 155 } |
| 97 | 156 |
| 98 } // namespace extensions | 157 } // namespace extensions |
| OLD | NEW |