OLD | NEW |
1 // Copyright 2013 The Chromium Authors. All rights reserved. | 1 // Copyright 2013 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "chrome/browser/chromeos/settings/device_oauth2_token_service.h" | 5 #include "chrome/browser/chromeos/settings/device_oauth2_token_service.h" |
6 | 6 |
7 #include <string> | 7 #include <string> |
8 #include <vector> | 8 #include <vector> |
9 | 9 |
10 #include "base/prefs/pref_registry_simple.h" | 10 #include "base/prefs/pref_registry_simple.h" |
11 #include "base/prefs/pref_service.h" | 11 #include "base/prefs/pref_service.h" |
12 #include "base/values.h" | 12 #include "base/values.h" |
13 #include "chrome/browser/browser_process.h" | 13 #include "chrome/browser/browser_process.h" |
14 #include "chrome/browser/chromeos/policy/device_cloud_policy_manager_chromeos.h" | 14 #include "chrome/browser/chromeos/policy/device_cloud_policy_manager_chromeos.h" |
15 #include "chrome/browser/chromeos/settings/token_encryptor.h" | 15 #include "chrome/browser/chromeos/settings/token_encryptor.h" |
16 #include "chrome/browser/policy/browser_policy_connector.h" | 16 #include "chrome/browser/policy/browser_policy_connector.h" |
17 #include "chrome/browser/policy/proto/cloud/device_management_backend.pb.h" | 17 #include "chrome/browser/policy/proto/cloud/device_management_backend.pb.h" |
18 #include "chrome/common/pref_names.h" | 18 #include "chrome/common/pref_names.h" |
19 #include "chromeos/cryptohome/system_salt_getter.h" | |
20 #include "content/public/browser/browser_thread.h" | 19 #include "content/public/browser/browser_thread.h" |
21 #include "google_apis/gaia/gaia_urls.h" | 20 #include "google_apis/gaia/gaia_urls.h" |
22 #include "google_apis/gaia/google_service_auth_error.h" | 21 #include "google_apis/gaia/google_service_auth_error.h" |
23 | 22 |
24 namespace { | 23 namespace { |
25 const char kServiceScopeGetUserInfo[] = | 24 const char kServiceScopeGetUserInfo[] = |
26 "https://www.googleapis.com/auth/userinfo.email"; | 25 "https://www.googleapis.com/auth/userinfo.email"; |
27 } | 26 } |
28 | 27 |
29 namespace chromeos { | 28 namespace chromeos { |
(...skipping 200 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
230 // static | 229 // static |
231 void DeviceOAuth2TokenService::RegisterPrefs(PrefRegistrySimple* registry) { | 230 void DeviceOAuth2TokenService::RegisterPrefs(PrefRegistrySimple* registry) { |
232 registry->RegisterStringPref(prefs::kDeviceRobotAnyApiRefreshToken, | 231 registry->RegisterStringPref(prefs::kDeviceRobotAnyApiRefreshToken, |
233 std::string()); | 232 std::string()); |
234 } | 233 } |
235 | 234 |
236 void DeviceOAuth2TokenService::SetAndSaveRefreshToken( | 235 void DeviceOAuth2TokenService::SetAndSaveRefreshToken( |
237 const std::string& refresh_token) { | 236 const std::string& refresh_token) { |
238 DCHECK(content::BrowserThread::CurrentlyOn(content::BrowserThread::UI)); | 237 DCHECK(content::BrowserThread::CurrentlyOn(content::BrowserThread::UI)); |
239 | 238 |
240 // TODO(xiyuan): Use async GetSystemSalt after merging to M31. | |
241 const std::string system_salt = SystemSaltGetter::Get()->GetSystemSaltSync(); | |
242 if (system_salt.empty()) { | |
243 const int64 kRequestSystemSaltDelayMs = 500; | |
244 content::BrowserThread::PostDelayedTask( | |
245 content::BrowserThread::UI, | |
246 FROM_HERE, | |
247 base::Bind(&DeviceOAuth2TokenService::SetAndSaveRefreshToken, | |
248 weak_ptr_factory_.GetWeakPtr(), | |
249 refresh_token), | |
250 base::TimeDelta::FromMilliseconds(kRequestSystemSaltDelayMs)); | |
251 return; | |
252 } | |
253 | |
254 std::string encrypted_refresh_token = | 239 std::string encrypted_refresh_token = |
255 token_encryptor_->EncryptWithSystemSalt(refresh_token); | 240 token_encryptor_->EncryptWithSystemSalt(refresh_token); |
256 | 241 |
257 local_state_->SetString(prefs::kDeviceRobotAnyApiRefreshToken, | 242 local_state_->SetString(prefs::kDeviceRobotAnyApiRefreshToken, |
258 encrypted_refresh_token); | 243 encrypted_refresh_token); |
259 } | 244 } |
260 | 245 |
261 std::string DeviceOAuth2TokenService::GetRefreshToken( | 246 std::string DeviceOAuth2TokenService::GetRefreshToken( |
262 const std::string& account_id) { | 247 const std::string& account_id) { |
263 DCHECK_EQ(account_id, GetRobotAccountId()); | 248 DCHECK_EQ(account_id, GetRobotAccountId()); |
264 if (refresh_token_.empty()) { | 249 if (refresh_token_.empty()) { |
265 std::string encrypted_refresh_token = | 250 std::string encrypted_refresh_token = |
266 local_state_->GetString(prefs::kDeviceRobotAnyApiRefreshToken); | 251 local_state_->GetString(prefs::kDeviceRobotAnyApiRefreshToken); |
267 | 252 |
268 // TODO(xiyuan): This needs a proper fix after M31. | |
269 LOG_IF(ERROR, SystemSaltGetter::Get()->GetSystemSaltSync().empty()) | |
270 << "System salt is not available for decryption"; | |
271 | |
272 refresh_token_ = token_encryptor_->DecryptWithSystemSalt( | 253 refresh_token_ = token_encryptor_->DecryptWithSystemSalt( |
273 encrypted_refresh_token); | 254 encrypted_refresh_token); |
274 } | 255 } |
275 return refresh_token_; | 256 return refresh_token_; |
276 } | 257 } |
277 | 258 |
278 std::string DeviceOAuth2TokenService::GetRobotAccountId() { | 259 std::string DeviceOAuth2TokenService::GetRobotAccountId() { |
279 policy::BrowserPolicyConnector* connector = | 260 policy::BrowserPolicyConnector* connector = |
280 g_browser_process->browser_policy_connector(); | 261 g_browser_process->browser_policy_connector(); |
281 if (connector) | 262 if (connector) |
(...skipping 12 matching lines...) Expand all Loading... |
294 return OAuth2TokenService::CreateRequest(consumer); | 275 return OAuth2TokenService::CreateRequest(consumer); |
295 | 276 |
296 // Substitute our own consumer to wait for refresh token validation. | 277 // Substitute our own consumer to wait for refresh token validation. |
297 scoped_ptr<ValidatingConsumer> validating_consumer( | 278 scoped_ptr<ValidatingConsumer> validating_consumer( |
298 new ValidatingConsumer(this, consumer)); | 279 new ValidatingConsumer(this, consumer)); |
299 validating_consumer->StartValidation(); | 280 validating_consumer->StartValidation(); |
300 return validating_consumer.PassAs<RequestImpl>(); | 281 return validating_consumer.PassAs<RequestImpl>(); |
301 } | 282 } |
302 | 283 |
303 } // namespace chromeos | 284 } // namespace chromeos |
OLD | NEW |