Chromium Code Reviews| Index: chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc |
| diff --git a/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc b/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc |
| index 299d9d57a909f4d77587ec79874e6456671bd262..e2793e94f58251abdd0aecbd4dcd47c046201eee 100644 |
| --- a/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc |
| +++ b/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc |
| @@ -20,8 +20,11 @@ |
| #include "chrome/browser/renderer_host/chrome_extension_message_filter.h" |
| #include "chrome/browser/sync_file_system/local/sync_file_system_backend.h" |
| #include "chrome/common/chrome_constants.h" |
| +#include "chrome/common/chrome_switches.h" |
| +#include "chrome/common/chrome_version_info.h" |
| #include "chrome/common/extensions/extension_process_policy.h" |
| #include "chrome/common/extensions/manifest_handlers/app_isolation_info.h" |
| +#include "chrome/common/pepper_permission_util.h" |
| #include "content/public/browser/browser_thread.h" |
| #include "content/public/browser/browser_url_handler.h" |
| #include "content/public/browser/render_process_host.h" |
| @@ -38,6 +41,7 @@ |
| #include "extensions/common/constants.h" |
| #include "extensions/common/manifest_handlers/background_info.h" |
| #include "extensions/common/manifest_handlers/web_accessible_resources_info.h" |
| +#include "extensions/common/permissions/socket_permission.h" |
| #include "extensions/common/switches.h" |
| using content::BrowserThread; |
| @@ -391,6 +395,105 @@ void ChromeContentBrowserClientExtensionsPart::SetSigninProcess( |
| site_instance->GetProcess()->GetID())); |
| } |
| +// static |
| +bool ChromeContentBrowserClientExtensionsPart:: |
| + IsPluginAllowedToCallRequestOSFileHandle( |
| + content::BrowserContext* browser_context, |
| + const GURL& url, |
| + const std::set<std::string>& allowed_file_handle_origins) { |
| + Profile* profile = Profile::FromBrowserContext(browser_context); |
|
Lei Zhang
2014/09/23 01:15:11
I know you are just cutting+pasting code here, but
|
| + const extensions::ExtensionSet* extension_set = NULL; |
| + if (profile) { |
| + const ExtensionService* ext_service = |
| + extensions::ExtensionSystem::Get(profile)->extension_service(); |
| + if (ext_service) { |
| + extension_set = ext_service->extensions(); |
| + } |
| + } |
| + return chrome::IsExtensionOrSharedModuleWhitelisted( |
| + url, extension_set, allowed_file_handle_origins) || |
| + chrome::IsHostAllowedByCommandLine( |
| + url, extension_set, ::switches::kAllowNaClFileHandleAPI); |
| +} |
| + |
| +bool ChromeContentBrowserClientExtensionsPart::AllowPepperSocketAPI( |
| + content::BrowserContext* browser_context, |
| + const GURL& url, |
| + bool private_api, |
| + const content::SocketPermissionRequest* params, |
| + const std::set<std::string>& whitelist) { |
| + Profile* profile = Profile::FromBrowserContext(browser_context); |
| + const extensions::ExtensionSet* extension_set = NULL; |
| + if (profile) { |
| + const ExtensionService* ext_service = |
| + extensions::ExtensionSystem::Get(profile)->extension_service(); |
| + if (ext_service) { |
| + extension_set = ext_service->extensions(); |
| + } |
| + } |
| + |
| + if (private_api) { |
| + // Access to private socket APIs is controlled by the whitelist. |
| + if (chrome::IsExtensionOrSharedModuleWhitelisted( |
| + url, extension_set, whitelist)) { |
| + return true; |
| + } |
| + } else { |
| + // Access to public socket APIs is controlled by extension permissions. |
| + if (url.is_valid() && url.SchemeIs(extensions::kExtensionScheme) && |
| + extension_set) { |
| + const Extension* extension = extension_set->GetByID(url.host()); |
| + if (extension) { |
| + const extensions::PermissionsData* permissions_data = |
| + extension->permissions_data(); |
| + if (params) { |
| + extensions::SocketPermission::CheckParam check_params( |
| + params->type, params->host, params->port); |
| + if (permissions_data->CheckAPIPermissionWithParam( |
| + extensions::APIPermission::kSocket, &check_params)) { |
| + return true; |
| + } |
| + } else if (permissions_data->HasAPIPermission( |
| + extensions::APIPermission::kSocket)) { |
| + return true; |
| + } |
| + } |
| + } |
| + } |
| + |
| + // Allow both public and private APIs if the command line says so. |
| + return chrome::IsHostAllowedByCommandLine( |
| + url, extension_set, ::switches::kAllowNaClSocketAPI); |
| +} |
| + |
| +bool |
| +ChromeContentBrowserClientExtensionsPart::IsPluginAllowedToUseDevChannelAPIs( |
| + content::BrowserContext* browser_context, |
| + const GURL& url, |
| + const std::set<std::string>& allowed_dev_channel_origins) { |
| + Profile* profile = Profile::FromBrowserContext(browser_context); |
| + const extensions::ExtensionSet* extension_set = NULL; |
| + if (profile) { |
| + const ExtensionService* ext_service = |
| + extensions::ExtensionSystem::Get(profile)->extension_service(); |
| + if (ext_service) { |
| + extension_set = ext_service->extensions(); |
| + } |
| + } |
| + |
| + // Allow access for whitelisted applications. |
| + if (chrome::IsExtensionOrSharedModuleWhitelisted( |
| + url, extension_set, allowed_dev_channel_origins)) { |
| + return true; |
| + } |
| + |
| + chrome::VersionInfo::Channel channel = chrome::VersionInfo::GetChannel(); |
| + // Allow dev channel APIs to be used on "Canary", "Dev", and "Unknown" |
| + // releases of Chrome. Permitting "Unknown" allows these APIs to be used on |
| + // Chromium builds as well. |
| + return channel <= chrome::VersionInfo::CHANNEL_DEV; |
| +} |
| + |
| void ChromeContentBrowserClientExtensionsPart::RenderProcessWillLaunch( |
| content::RenderProcessHost* host) { |
| int id = host->GetID(); |