OLD | NEW |
---|---|
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #ifndef CONTENT_BROWSER_SSL_SSL_CLIENT_AUTH_HANDLER_H_ | 5 #ifndef CONTENT_BROWSER_SSL_SSL_CLIENT_AUTH_HANDLER_H_ |
6 #define CONTENT_BROWSER_SSL_SSL_CLIENT_AUTH_HANDLER_H_ | 6 #define CONTENT_BROWSER_SSL_SSL_CLIENT_AUTH_HANDLER_H_ |
7 | 7 |
8 #include "base/basictypes.h" | 8 #include "base/basictypes.h" |
9 #include "base/callback.h" | |
9 #include "base/memory/ref_counted.h" | 10 #include "base/memory/ref_counted.h" |
10 #include "base/sequenced_task_runner_helpers.h" | 11 #include "base/memory/weak_ptr.h" |
11 #include "content/common/content_export.h" | |
12 #include "content/public/browser/browser_thread.h" | 12 #include "content/public/browser/browser_thread.h" |
13 #include "net/ssl/ssl_cert_request_info.h" | 13 #include "net/ssl/ssl_cert_request_info.h" |
14 | 14 |
15 namespace net { | 15 namespace net { |
16 class ClientCertStore; | 16 class ClientCertStore; |
17 class HttpNetworkSession; | |
18 class URLRequest; | 17 class URLRequest; |
19 class X509Certificate; | 18 class X509Certificate; |
20 } // namespace net | 19 } // namespace net |
21 | 20 |
22 namespace content { | 21 namespace content { |
23 | 22 |
24 class ResourceContext; | |
25 | |
26 // This class handles the approval and selection of a certificate for SSL client | 23 // This class handles the approval and selection of a certificate for SSL client |
27 // authentication by the user. | 24 // authentication by the user. Should only be used on the IO thread. If the |
28 // It is self-owned and deletes itself when the UI reports the user selection or | 25 // SSLClientAuthHandler is destroyed before the certificate is selected, the |
29 // when the net::URLRequest is cancelled. | 26 // selection is canceled and the callback never called. |
30 class CONTENT_EXPORT SSLClientAuthHandler | 27 class SSLClientAuthHandler { |
31 : public base::RefCountedThreadSafe< | |
32 SSLClientAuthHandler, BrowserThread::DeleteOnIOThread> { | |
33 public: | 28 public: |
34 using CertificateCallback = base::Callback<void(net::X509Certificate*)>; | 29 using CertificateCallback = base::Callback<void(net::X509Certificate*)>; |
35 | 30 |
36 SSLClientAuthHandler(scoped_ptr<net::ClientCertStore> client_cert_store, | 31 SSLClientAuthHandler(scoped_ptr<net::ClientCertStore> client_cert_store, |
37 net::URLRequest* request, | 32 net::URLRequest* request, |
38 net::SSLCertRequestInfo* cert_request_info, | 33 net::SSLCertRequestInfo* cert_request_info, |
39 const CertificateCallback& callback); | 34 const CertificateCallback& callback); |
35 ~SSLClientAuthHandler(); | |
40 | 36 |
41 // Selects a certificate and resumes the URL request with that certificate. | 37 // Selects a certificate and resumes the URL request with that certificate. |
42 // Should only be called on the IO thread. | |
43 void SelectCertificate(); | 38 void SelectCertificate(); |
44 | 39 |
45 // Invoked when the request associated with this handler is cancelled. | 40 private: |
46 // Should only be called on the IO thread. | 41 class Core; |
47 void OnRequestCancelled(); | |
48 | 42 |
49 // Calls DoCertificateSelected on the I/O thread. | 43 // Called when |core_| is done retrieving the cert list. |
50 // Called on the UI thread after the user has made a selection (which may | 44 void DidGetClientCerts(); |
51 // be long after DoSelectCertificate returns, if the UI is modeless/async.) | 45 |
46 // Called when the user has selected a cert. | |
pneubeck (no reviews)
2014/12/14 16:45:13
wouldn't |cert| be null if the selection was abort
davidben
2015/01/23 21:05:35
We actually don't ever plumb through aborting a se
| |
52 void CertificateSelected(net::X509Certificate* cert); | 47 void CertificateSelected(net::X509Certificate* cert); |
53 | 48 |
54 protected: | 49 // A reference-counted core so the ClientCertStore may outlive |
55 virtual ~SSLClientAuthHandler(); | 50 // SSLClientAuthHandler if the handler is destroyed while an operation on the |
56 | 51 // ClientCertStore is in progress. |
57 private: | 52 scoped_refptr<Core> core_; |
58 friend class base::RefCountedThreadSafe< | |
59 SSLClientAuthHandler, BrowserThread::DeleteOnIOThread>; | |
60 friend class BrowserThread; | |
61 friend class base::DeleteHelper<SSLClientAuthHandler>; | |
62 | |
63 // Called when ClientCertStore is done retrieving the cert list. | |
64 void DidGetClientCerts(); | |
65 | |
66 // Notifies that the user has selected a cert. | |
67 // Called on the IO thread. | |
68 void DoCertificateSelected(net::X509Certificate* cert); | |
69 | |
70 // Selects a client certificate on the UI thread. | |
71 void DoSelectCertificate(int render_process_host_id, | |
72 int render_frame_host_id); | |
73 | 53 |
74 // The net::URLRequest that triggered this client auth. | 54 // The net::URLRequest that triggered this client auth. |
75 net::URLRequest* request_; | 55 net::URLRequest* request_; |
76 | 56 |
77 // The certs to choose from. | 57 // The certs to choose from. |
78 scoped_refptr<net::SSLCertRequestInfo> cert_request_info_; | 58 scoped_refptr<net::SSLCertRequestInfo> cert_request_info_; |
79 | 59 |
80 scoped_ptr<net::ClientCertStore> client_cert_store_; | |
81 | |
82 // The callback to call when the certificate is selected. | 60 // The callback to call when the certificate is selected. |
83 CertificateCallback callback_; | 61 CertificateCallback callback_; |
84 | 62 |
63 base::WeakPtrFactory<SSLClientAuthHandler> weak_factory_; | |
64 | |
85 DISALLOW_COPY_AND_ASSIGN(SSLClientAuthHandler); | 65 DISALLOW_COPY_AND_ASSIGN(SSLClientAuthHandler); |
86 }; | 66 }; |
87 | 67 |
88 } // namespace content | 68 } // namespace content |
89 | 69 |
90 #endif // CONTENT_BROWSER_SSL_SSL_CLIENT_AUTH_HANDLER_H_ | 70 #endif // CONTENT_BROWSER_SSL_SSL_CLIENT_AUTH_HANDLER_H_ |
OLD | NEW |