| OLD | NEW |
| 1 // Copyright (c) 2013 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2013 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #ifndef CHROME_BROWSER_POLICY_PROFILE_POLICY_CONNECTOR_H_ | 5 #ifndef CHROME_BROWSER_POLICY_PROFILE_POLICY_CONNECTOR_H_ |
| 6 #define CHROME_BROWSER_POLICY_PROFILE_POLICY_CONNECTOR_H_ | 6 #define CHROME_BROWSER_POLICY_PROFILE_POLICY_CONNECTOR_H_ |
| 7 | 7 |
| 8 #include <string> | 8 #include <string> |
| 9 #include <vector> | |
| 10 | 9 |
| 11 #include "base/basictypes.h" | 10 #include "base/basictypes.h" |
| 12 #include "base/callback.h" | 11 #include "base/callback.h" |
| 13 #include "base/memory/ref_counted.h" | 12 #include "base/memory/ref_counted.h" |
| 14 #include "base/memory/scoped_ptr.h" | 13 #include "base/memory/scoped_ptr.h" |
| 15 #include "base/memory/weak_ptr.h" | 14 #include "base/memory/weak_ptr.h" |
| 16 #include "components/browser_context_keyed_service/browser_context_keyed_service
.h" | 15 #include "components/browser_context_keyed_service/browser_context_keyed_service
.h" |
| 17 | 16 |
| 18 class Profile; | 17 class Profile; |
| 19 | 18 |
| 20 namespace net { | 19 namespace net { |
| 21 class CertTrustAnchorProvider; | 20 class CertTrustAnchorProvider; |
| 22 } | 21 } |
| 23 | 22 |
| 24 namespace net { | |
| 25 class X509Certificate; | |
| 26 typedef std::vector<scoped_refptr<X509Certificate> > CertificateList; | |
| 27 } | |
| 28 | |
| 29 namespace chromeos { | 23 namespace chromeos { |
| 30 class User; | 24 class User; |
| 31 } | 25 } |
| 32 | 26 |
| 33 namespace policy { | 27 namespace policy { |
| 34 | 28 |
| 35 class CloudPolicyManager; | 29 class CloudPolicyManager; |
| 36 class ConfigurationPolicyProvider; | 30 class ConfigurationPolicyProvider; |
| 37 class UserNetworkConfigurationUpdater; | |
| 38 class PolicyService; | 31 class PolicyService; |
| 39 class PolicyCertVerifier; | |
| 40 | 32 |
| 41 // A BrowserContextKeyedService that creates and manages the per-Profile policy | 33 // A BrowserContextKeyedService that creates and manages the per-Profile policy |
| 42 // components. | 34 // components. |
| 43 class ProfilePolicyConnector : public BrowserContextKeyedService { | 35 class ProfilePolicyConnector : public BrowserContextKeyedService { |
| 44 public: | 36 public: |
| 45 explicit ProfilePolicyConnector(Profile* profile); | 37 explicit ProfilePolicyConnector(Profile* profile); |
| 46 virtual ~ProfilePolicyConnector(); | 38 virtual ~ProfilePolicyConnector(); |
| 47 | 39 |
| 48 // If |force_immediate_load| then disk caches will be loaded synchronously. | 40 // If |force_immediate_load| then disk caches will be loaded synchronously. |
| 49 void Init(bool force_immediate_load, | 41 void Init(bool force_immediate_load, |
| 50 #if defined(OS_CHROMEOS) | 42 #if defined(OS_CHROMEOS) |
| 51 const chromeos::User* user, | 43 const chromeos::User* user, |
| 52 #endif | 44 #endif |
| 53 CloudPolicyManager* user_cloud_policy_manager); | 45 CloudPolicyManager* user_cloud_policy_manager); |
| 54 | 46 |
| 55 void InitForTesting(scoped_ptr<PolicyService> service); | 47 void InitForTesting(scoped_ptr<PolicyService> service); |
| 56 | 48 |
| 57 // BrowserContextKeyedService: | 49 // BrowserContextKeyedService: |
| 58 virtual void Shutdown() OVERRIDE; | 50 virtual void Shutdown() OVERRIDE; |
| 59 | 51 |
| 60 // This is never NULL. | 52 // This is never NULL. |
| 61 PolicyService* policy_service() const { return policy_service_.get(); } | 53 PolicyService* policy_service() const { return policy_service_.get(); } |
| 62 | 54 |
| 63 #if defined(OS_CHROMEOS) | 55 #if defined(OS_CHROMEOS) |
| 64 // Sets the CertVerifier on which the current list of Web trusted server and | |
| 65 // CA certificates will be set. Policy updates will trigger further calls to | |
| 66 // |cert_verifier| later. |cert_verifier| must be valid until | |
| 67 // SetPolicyCertVerifier is called again (with another CertVerifier or NULL) | |
| 68 // or until this Connector is destructed. |cert_verifier|'s methods are only | |
| 69 // called on the IO thread. This function must be called on the UI thread. | |
| 70 void SetPolicyCertVerifier(PolicyCertVerifier* cert_verifier); | |
| 71 | |
| 72 // Returns a callback that should be called if a policy installed certificate | 56 // Returns a callback that should be called if a policy installed certificate |
| 73 // was trusted for the associated profile. The closure can be safely used (on | 57 // was trusted for the associated profile. The closure can be safely used (on |
| 74 // the UI thread) even after this Connector is destructed. | 58 // the UI thread) even after this Connector is destructed. |
| 75 base::Closure GetPolicyCertTrustedCallback(); | 59 base::Closure GetPolicyCertTrustedCallback(); |
| 76 | |
| 77 // Sets |certs| to the list of Web trusted server and CA certificates from the | |
| 78 // last received ONC user policy. | |
| 79 void GetWebTrustedCertificates(net::CertificateList* certs) const; | |
| 80 #endif | 60 #endif |
| 81 | 61 |
| 82 // Returns true if |profile()| has used certificates installed via policy | 62 // Returns true if |profile()| has used certificates installed via policy |
| 83 // to establish a secure connection before. This means that it may have | 63 // to establish a secure connection before. This means that it may have |
| 84 // cached content from an untrusted source. | 64 // cached content from an untrusted source. |
| 85 bool UsedPolicyCertificates(); | 65 bool UsedPolicyCertificates(); |
| 86 | 66 |
| 87 private: | 67 private: |
| 88 #if defined(ENABLE_CONFIGURATION_POLICY) | 68 #if defined(ENABLE_CONFIGURATION_POLICY) |
| 89 | 69 |
| 90 #if defined(OS_CHROMEOS) | 70 #if defined(OS_CHROMEOS) |
| 91 void SetUsedPolicyCertificatesOnce(); | 71 void SetUsedPolicyCertificatesOnce(); |
| 92 void InitializeDeviceLocalAccountPolicyProvider(const std::string& username); | 72 void InitializeDeviceLocalAccountPolicyProvider(const std::string& username); |
| 93 #endif | 73 #endif |
| 94 | 74 |
| 95 #if defined(OS_CHROMEOS) | 75 #if defined(OS_CHROMEOS) |
| 96 // Some of the user policy configuration affects browser global state, and | 76 // Some of the user policy configuration affects browser global state, and |
| 97 // can only come from one Profile. |is_primary_user_| is true if this | 77 // can only come from one Profile. |is_primary_user_| is true if this |
| 98 // connector belongs to the first signed-in Profile, and in that case that | 78 // connector belongs to the first signed-in Profile, and in that case that |
| 99 // Profile's policy is the one that affects global policy settings in | 79 // Profile's policy is the one that affects global policy settings in |
| 100 // local state. | 80 // local state. |
| 101 bool is_primary_user_; | 81 bool is_primary_user_; |
| 102 | 82 |
| 103 scoped_ptr<ConfigurationPolicyProvider> special_user_policy_provider_; | 83 scoped_ptr<ConfigurationPolicyProvider> special_user_policy_provider_; |
| 104 scoped_ptr<UserNetworkConfigurationUpdater> network_configuration_updater_; | |
| 105 | 84 |
| 106 base::WeakPtrFactory<ProfilePolicyConnector> weak_ptr_factory_; | 85 base::WeakPtrFactory<ProfilePolicyConnector> weak_ptr_factory_; |
| 107 #endif | 86 #endif |
| 108 | 87 |
| 109 Profile* profile_; | 88 Profile* profile_; |
| 110 | 89 |
| 111 #endif // ENABLE_CONFIGURATION_POLICY | 90 #endif // ENABLE_CONFIGURATION_POLICY |
| 112 | 91 |
| 113 scoped_ptr<PolicyService> policy_service_; | 92 scoped_ptr<PolicyService> policy_service_; |
| 114 | 93 |
| 115 DISALLOW_COPY_AND_ASSIGN(ProfilePolicyConnector); | 94 DISALLOW_COPY_AND_ASSIGN(ProfilePolicyConnector); |
| 116 }; | 95 }; |
| 117 | 96 |
| 118 } // namespace policy | 97 } // namespace policy |
| 119 | 98 |
| 120 #endif // CHROME_BROWSER_POLICY_PROFILE_POLICY_CONNECTOR_H_ | 99 #endif // CHROME_BROWSER_POLICY_PROFILE_POLICY_CONNECTOR_H_ |
| OLD | NEW |