OLD | NEW |
1 // Copyright 2013 The Chromium Authors. All rights reserved. | 1 // Copyright 2013 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #ifndef NET_SSL_CLIENT_CERT_STORE_CHROMEOS_H_ | 5 #ifndef NET_SSL_CLIENT_CERT_STORE_CHROMEOS_H_ |
6 #define NET_SSL_CLIENT_CERT_STORE_CHROMEOS_H_ | 6 #define NET_SSL_CLIENT_CERT_STORE_CHROMEOS_H_ |
7 | 7 |
8 #include <string> | 8 #include <string> |
9 | 9 |
10 #include "crypto/scoped_nss_types.h" | 10 #include "base/memory/scoped_ptr.h" |
11 #include "net/cert/nss_profile_filter_chromeos.h" | |
12 #include "net/ssl/client_cert_store_nss.h" | 11 #include "net/ssl/client_cert_store_nss.h" |
13 | 12 |
14 namespace net { | 13 namespace net { |
15 | 14 |
| 15 class X509Certificate; |
| 16 |
16 class NET_EXPORT ClientCertStoreChromeOS : public ClientCertStoreNSS { | 17 class NET_EXPORT ClientCertStoreChromeOS : public ClientCertStoreNSS { |
17 public: | 18 public: |
18 // Constructs a ClientCertStore that will return client certs available on | 19 class CertFilter { |
19 // the user's private and public slots. If |use_system_slot| is true, certs on | 20 public: |
20 // the system slot will also be returned. | 21 virtual ~CertFilter() {} |
| 22 |
| 23 // Initializes this filter. Returns true if it finished initialization, |
| 24 // otherwise returns false and calls |callback| once the initialization is |
| 25 // completed. |
| 26 // Must be called at most once. |
| 27 virtual bool Init(const base::Closure& callback) = 0; |
| 28 |
| 29 // Returns true if |cert| is allowed to be used as a client certificate |
| 30 // (e.g. for a certain browser context or user). |
| 31 // This is only called once initialization is finished, see Init(). |
| 32 virtual bool IsCertAllowed( |
| 33 const scoped_refptr<X509Certificate>& cert) const = 0; |
| 34 }; |
| 35 |
| 36 // This ClientCertStore will return only client certs that pass the filter |
| 37 // |cert_filter|. |
21 ClientCertStoreChromeOS( | 38 ClientCertStoreChromeOS( |
22 bool use_system_slot, | 39 scoped_ptr<CertFilter> cert_filter, |
23 const std::string& username_hash, | |
24 const PasswordDelegateFactory& password_delegate_factory); | 40 const PasswordDelegateFactory& password_delegate_factory); |
25 virtual ~ClientCertStoreChromeOS(); | 41 virtual ~ClientCertStoreChromeOS(); |
26 | 42 |
27 // ClientCertStoreNSS: | 43 // ClientCertStoreNSS: |
28 virtual void GetClientCerts(const SSLCertRequestInfo& cert_request_info, | 44 virtual void GetClientCerts(const SSLCertRequestInfo& cert_request_info, |
29 CertificateList* selected_certs, | 45 CertificateList* selected_certs, |
30 const base::Closure& callback) override; | 46 const base::Closure& callback) override; |
31 | 47 |
32 protected: | 48 protected: |
33 // ClientCertStoreNSS: | 49 // ClientCertStoreNSS: |
34 virtual void GetClientCertsImpl(CERTCertList* cert_list, | 50 virtual void GetClientCertsImpl(CERTCertList* cert_list, |
35 const SSLCertRequestInfo& request, | 51 const SSLCertRequestInfo& request, |
36 bool query_nssdb, | 52 bool query_nssdb, |
37 CertificateList* selected_certs) override; | 53 CertificateList* selected_certs) override; |
38 | 54 |
39 private: | 55 private: |
40 void DidGetSystemAndPrivateSlot(const SSLCertRequestInfo* request, | 56 void CertFilterInitialized(const SSLCertRequestInfo* request, |
41 CertificateList* selected_certs, | 57 CertificateList* selected_certs, |
42 const base::Closure& callback, | 58 const base::Closure& callback); |
43 crypto::ScopedPK11Slot system_slot, | |
44 crypto::ScopedPK11Slot private_slot); | |
45 | 59 |
46 bool use_system_slot_; | 60 scoped_ptr<CertFilter> cert_filter_; |
47 std::string username_hash_; | |
48 NSSProfileFilterChromeOS profile_filter_; | |
49 | 61 |
50 DISALLOW_COPY_AND_ASSIGN(ClientCertStoreChromeOS); | 62 DISALLOW_COPY_AND_ASSIGN(ClientCertStoreChromeOS); |
51 }; | 63 }; |
52 | 64 |
53 } // namespace net | 65 } // namespace net |
54 | 66 |
55 #endif // NET_SSL_CLIENT_CERT_STORE_CHROMEOS_H_ | 67 #endif // NET_SSL_CLIENT_CERT_STORE_CHROMEOS_H_ |
OLD | NEW |