OLD | NEW |
1 // Copyright (c) 2013 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2013 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "chrome/browser/ui/android/ssl_client_certificate_request.h" | 5 #include "chrome/browser/ui/android/ssl_client_certificate_request.h" |
6 | 6 |
7 #include "base/android/jni_array.h" | 7 #include "base/android/jni_array.h" |
8 #include "base/android/jni_string.h" | 8 #include "base/android/jni_string.h" |
9 #include "base/android/scoped_java_ref.h" | 9 #include "base/android/scoped_java_ref.h" |
10 #include "base/basictypes.h" | 10 #include "base/basictypes.h" |
11 #include "base/bind.h" | 11 #include "base/bind.h" |
12 #include "base/callback_helpers.h" | |
13 #include "base/compiler_specific.h" | 12 #include "base/compiler_specific.h" |
14 #include "base/logging.h" | 13 #include "base/logging.h" |
15 #include "chrome/browser/ssl/ssl_client_certificate_selector.h" | 14 #include "chrome/browser/ssl/ssl_client_certificate_selector.h" |
16 #include "chrome/browser/ui/android/window_android_helper.h" | 15 #include "chrome/browser/ui/android/window_android_helper.h" |
17 #include "content/public/browser/browser_thread.h" | 16 #include "content/public/browser/browser_thread.h" |
| 17 #include "content/public/browser/client_certificate_delegate.h" |
18 #include "crypto/scoped_openssl_types.h" | 18 #include "crypto/scoped_openssl_types.h" |
19 #include "jni/SSLClientCertificateRequest_jni.h" | 19 #include "jni/SSLClientCertificateRequest_jni.h" |
20 #include "net/android/keystore_openssl.h" | 20 #include "net/android/keystore_openssl.h" |
21 #include "net/base/host_port_pair.h" | 21 #include "net/base/host_port_pair.h" |
22 #include "net/cert/cert_database.h" | 22 #include "net/cert/cert_database.h" |
23 #include "net/cert/x509_certificate.h" | 23 #include "net/cert/x509_certificate.h" |
24 #include "net/ssl/openssl_client_key_store.h" | 24 #include "net/ssl/openssl_client_key_store.h" |
25 #include "net/ssl/ssl_cert_request_info.h" | 25 #include "net/ssl/ssl_cert_request_info.h" |
26 #include "net/ssl/ssl_client_cert_type.h" | 26 #include "net/ssl/ssl_client_cert_type.h" |
27 #include "ui/base/android/window_android.h" | 27 #include "ui/base/android/window_android.h" |
28 | 28 |
29 | 29 |
30 namespace chrome { | 30 namespace chrome { |
31 | 31 |
32 namespace { | 32 namespace { |
33 | 33 |
34 // Must be called on the I/O thread to record a client certificate | 34 // Must be called on the I/O thread to record a client certificate |
35 // and its private key in the OpenSSLClientKeyStore. | 35 // and its private key in the OpenSSLClientKeyStore. |
36 void RecordClientCertificateKey( | 36 void RecordClientCertificateKey( |
37 const scoped_refptr<net::X509Certificate>& client_cert, | 37 const scoped_refptr<net::X509Certificate>& client_cert, |
38 crypto::ScopedEVP_PKEY private_key) { | 38 crypto::ScopedEVP_PKEY private_key) { |
39 DCHECK_CURRENTLY_ON(content::BrowserThread::IO); | 39 DCHECK_CURRENTLY_ON(content::BrowserThread::IO); |
40 net::OpenSSLClientKeyStore::GetInstance()->RecordClientCertPrivateKey( | 40 net::OpenSSLClientKeyStore::GetInstance()->RecordClientCertPrivateKey( |
41 client_cert.get(), private_key.get()); | 41 client_cert.get(), private_key.get()); |
42 } | 42 } |
43 | 43 |
44 void StartClientCertificateRequest( | 44 void StartClientCertificateRequest( |
45 const net::SSLCertRequestInfo* cert_request_info, | 45 const net::SSLCertRequestInfo* cert_request_info, |
46 ui::WindowAndroid* window, | 46 ui::WindowAndroid* window, |
47 const chrome::SelectCertificateCallback& callback) { | 47 scoped_ptr<content::ClientCertificateDelegate> delegate) { |
48 DCHECK_CURRENTLY_ON(content::BrowserThread::UI); | 48 DCHECK_CURRENTLY_ON(content::BrowserThread::UI); |
49 | 49 |
50 // Ensure that callback(NULL) is posted as a task on the UI thread | |
51 // in case of an error. | |
52 base::Closure post_task_closure = base::Bind( | |
53 base::IgnoreResult(&content::BrowserThread::PostTask), | |
54 content::BrowserThread::UI, | |
55 FROM_HERE, | |
56 base::Bind(callback, scoped_refptr<net::X509Certificate>())); | |
57 | |
58 base::ScopedClosureRunner guard(post_task_closure); | |
59 | |
60 // Build the |key_types| JNI parameter, as a String[] | 50 // Build the |key_types| JNI parameter, as a String[] |
61 std::vector<std::string> key_types; | 51 std::vector<std::string> key_types; |
62 for (size_t n = 0; n < cert_request_info->cert_key_types.size(); ++n) { | 52 for (size_t n = 0; n < cert_request_info->cert_key_types.size(); ++n) { |
63 switch (cert_request_info->cert_key_types[n]) { | 53 switch (cert_request_info->cert_key_types[n]) { |
64 case net::CLIENT_CERT_RSA_SIGN: | 54 case net::CLIENT_CERT_RSA_SIGN: |
65 key_types.push_back("RSA"); | 55 key_types.push_back("RSA"); |
66 break; | 56 break; |
67 case net::CLIENT_CERT_DSS_SIGN: | 57 case net::CLIENT_CERT_DSS_SIGN: |
68 key_types.push_back("DSA"); | 58 key_types.push_back("DSA"); |
69 break; | 59 break; |
(...skipping 22 matching lines...) Expand all Loading... |
92 LOG(ERROR) << "Could not create principals array (byte[][])"; | 82 LOG(ERROR) << "Could not create principals array (byte[][])"; |
93 return; | 83 return; |
94 } | 84 } |
95 | 85 |
96 // Build the |host_name| and |port| JNI parameters, as a String and | 86 // Build the |host_name| and |port| JNI parameters, as a String and |
97 // a jint. | 87 // a jint. |
98 ScopedJavaLocalRef<jstring> host_name_ref = | 88 ScopedJavaLocalRef<jstring> host_name_ref = |
99 base::android::ConvertUTF8ToJavaString( | 89 base::android::ConvertUTF8ToJavaString( |
100 env, cert_request_info->host_and_port.host()); | 90 env, cert_request_info->host_and_port.host()); |
101 | 91 |
102 // Create a copy of the callback on the heap so that its address | 92 // Pass the address of the delegate through to Java. |
103 // and ownership can be passed through and returned from Java via JNI. | 93 jlong request_id = reinterpret_cast<intptr_t>(delegate.get()); |
104 scoped_ptr<chrome::SelectCertificateCallback> request( | |
105 new chrome::SelectCertificateCallback(callback)); | |
106 | |
107 jlong request_id = reinterpret_cast<intptr_t>(request.get()); | |
108 | 94 |
109 if (!chrome::android:: | 95 if (!chrome::android:: |
110 Java_SSLClientCertificateRequest_selectClientCertificate( | 96 Java_SSLClientCertificateRequest_selectClientCertificate( |
111 env, | 97 env, |
112 request_id, | 98 request_id, |
113 window->GetJavaObject().obj(), | 99 window->GetJavaObject().obj(), |
114 key_types_ref.obj(), | 100 key_types_ref.obj(), |
115 principals_ref.obj(), | 101 principals_ref.obj(), |
116 host_name_ref.obj(), | 102 host_name_ref.obj(), |
117 cert_request_info->host_and_port.port())) { | 103 cert_request_info->host_and_port.port())) { |
118 return; | 104 return; |
119 } | 105 } |
120 | 106 |
121 ignore_result(guard.Release()); | |
122 | |
123 // Ownership was transferred to Java. | 107 // Ownership was transferred to Java. |
124 ignore_result(request.release()); | 108 ignore_result(delegate.release()); |
125 } | 109 } |
126 | 110 |
127 } // namespace | 111 } // namespace |
128 | 112 |
129 namespace android { | 113 namespace android { |
130 | 114 |
131 // Called from JNI on request completion/result. | 115 // Called from JNI on request completion/result. |
132 // |env| is the current thread's JNIEnv. | 116 // |env| is the current thread's JNIEnv. |
133 // |clazz| is the SSLClientCertificateRequest JNI class reference. | 117 // |clazz| is the SSLClientCertificateRequest JNI class reference. |
134 // |request_id| is the id passed to | 118 // |request_id| is the id passed to |
135 // Java_SSLClientCertificateRequest_selectClientCertificate() in Start(). | 119 // Java_SSLClientCertificateRequest_selectClientCertificate() in Start(). |
136 // |encoded_chain_ref| is a JNI reference to a Java array of byte arrays, | 120 // |encoded_chain_ref| is a JNI reference to a Java array of byte arrays, |
137 // each item holding a DER-encoded X.509 certificate. | 121 // each item holding a DER-encoded X.509 certificate. |
138 // |private_key_ref| is the platform PrivateKey object JNI reference for | 122 // |private_key_ref| is the platform PrivateKey object JNI reference for |
139 // the client certificate. | 123 // the client certificate. |
140 // Note: both |encoded_chain_ref| and |private_key_ref| will be NULL if | 124 // Note: both |encoded_chain_ref| and |private_key_ref| will be NULL if |
141 // the user didn't select a certificate. | 125 // the user didn't select a certificate. |
142 static void OnSystemRequestCompletion( | 126 static void OnSystemRequestCompletion( |
143 JNIEnv* env, | 127 JNIEnv* env, |
144 jclass clazz, | 128 jclass clazz, |
145 jlong request_id, | 129 jlong request_id, |
146 jobjectArray encoded_chain_ref, | 130 jobjectArray encoded_chain_ref, |
147 jobject private_key_ref) { | 131 jobject private_key_ref) { |
148 DCHECK_CURRENTLY_ON(content::BrowserThread::UI); | 132 DCHECK_CURRENTLY_ON(content::BrowserThread::UI); |
149 | 133 |
150 // Take back ownership of the request object. | 134 // Take back ownership of the delegate object. |
151 scoped_ptr<chrome::SelectCertificateCallback> callback( | 135 scoped_ptr<content::ClientCertificateDelegate> delegate( |
152 reinterpret_cast<chrome::SelectCertificateCallback*>(request_id)); | 136 reinterpret_cast<content::ClientCertificateDelegate*>(request_id)); |
153 | |
154 // Ensure that callback(NULL) is called in case of an error. | |
155 base::Closure null_closure = | |
156 base::Bind(*callback, scoped_refptr<net::X509Certificate>()); | |
157 | |
158 base::ScopedClosureRunner guard(null_closure); | |
159 | 137 |
160 if (encoded_chain_ref == NULL || private_key_ref == NULL) { | 138 if (encoded_chain_ref == NULL || private_key_ref == NULL) { |
161 LOG(ERROR) << "Client certificate request cancelled"; | 139 LOG(ERROR) << "No client certificate selected"; |
| 140 delegate->ContinueWithCertificate(nullptr); |
162 return; | 141 return; |
163 } | 142 } |
164 | 143 |
165 // Convert the encoded chain to a vector of strings. | 144 // Convert the encoded chain to a vector of strings. |
166 std::vector<std::string> encoded_chain_strings; | 145 std::vector<std::string> encoded_chain_strings; |
167 if (encoded_chain_ref) { | 146 if (encoded_chain_ref) { |
168 base::android::JavaArrayOfByteArrayToStringVector( | 147 base::android::JavaArrayOfByteArrayToStringVector( |
169 env, encoded_chain_ref, &encoded_chain_strings); | 148 env, encoded_chain_ref, &encoded_chain_strings); |
170 } | 149 } |
171 | 150 |
(...skipping 10 matching lines...) Expand all Loading... |
182 } | 161 } |
183 | 162 |
184 // Create an EVP_PKEY wrapper for the private key JNI reference. | 163 // Create an EVP_PKEY wrapper for the private key JNI reference. |
185 crypto::ScopedEVP_PKEY private_key( | 164 crypto::ScopedEVP_PKEY private_key( |
186 net::android::GetOpenSSLPrivateKeyWrapper(private_key_ref)); | 165 net::android::GetOpenSSLPrivateKeyWrapper(private_key_ref)); |
187 if (!private_key.get()) { | 166 if (!private_key.get()) { |
188 LOG(ERROR) << "Could not create OpenSSL wrapper for private key"; | 167 LOG(ERROR) << "Could not create OpenSSL wrapper for private key"; |
189 return; | 168 return; |
190 } | 169 } |
191 | 170 |
192 ignore_result(guard.Release()); | |
193 | |
194 // RecordClientCertificateKey() must be called on the I/O thread, | 171 // RecordClientCertificateKey() must be called on the I/O thread, |
195 // before the callback is called with the selected certificate on | 172 // before the callback is called with the selected certificate on |
196 // the UI thread. | 173 // the UI thread. |
197 content::BrowserThread::PostTaskAndReply( | 174 content::BrowserThread::PostTaskAndReply( |
198 content::BrowserThread::IO, | 175 content::BrowserThread::IO, FROM_HERE, |
199 FROM_HERE, | 176 base::Bind(&RecordClientCertificateKey, client_cert, |
200 base::Bind(&RecordClientCertificateKey, | |
201 client_cert, | |
202 base::Passed(&private_key)), | 177 base::Passed(&private_key)), |
203 base::Bind(*callback, client_cert)); | 178 base::Bind(&content::ClientCertificateDelegate::ContinueWithCertificate, |
| 179 base::Owned(delegate.release()), client_cert)); |
204 } | 180 } |
205 | 181 |
206 static void NotifyClientCertificatesChanged() { | 182 static void NotifyClientCertificatesChanged() { |
207 net::CertDatabase::GetInstance()->OnAndroidKeyStoreChanged(); | 183 net::CertDatabase::GetInstance()->OnAndroidKeyStoreChanged(); |
208 } | 184 } |
209 | 185 |
210 static void NotifyClientCertificatesChangedOnIOThread(JNIEnv* env, jclass) { | 186 static void NotifyClientCertificatesChangedOnIOThread(JNIEnv* env, jclass) { |
211 if (content::BrowserThread::CurrentlyOn(content::BrowserThread::IO)) { | 187 if (content::BrowserThread::CurrentlyOn(content::BrowserThread::IO)) { |
212 NotifyClientCertificatesChanged(); | 188 NotifyClientCertificatesChanged(); |
213 } else { | 189 } else { |
214 content::BrowserThread::PostTask( | 190 content::BrowserThread::PostTask( |
215 content::BrowserThread::IO, | 191 content::BrowserThread::IO, |
216 FROM_HERE, | 192 FROM_HERE, |
217 base::Bind(&NotifyClientCertificatesChanged)); | 193 base::Bind(&NotifyClientCertificatesChanged)); |
218 } | 194 } |
219 } | 195 } |
220 | 196 |
221 bool RegisterSSLClientCertificateRequestAndroid(JNIEnv* env) { | 197 bool RegisterSSLClientCertificateRequestAndroid(JNIEnv* env) { |
222 return RegisterNativesImpl(env); | 198 return RegisterNativesImpl(env); |
223 } | 199 } |
224 | 200 |
225 } // namespace android | 201 } // namespace android |
226 | 202 |
227 void ShowSSLClientCertificateSelector( | 203 void ShowSSLClientCertificateSelector( |
228 content::WebContents* contents, | 204 content::WebContents* contents, |
229 net::SSLCertRequestInfo* cert_request_info, | 205 net::SSLCertRequestInfo* cert_request_info, |
230 const chrome::SelectCertificateCallback& callback) { | 206 scoped_ptr<content::ClientCertificateDelegate> delegate) { |
231 ui::WindowAndroid* window = | 207 ui::WindowAndroid* window = |
232 WindowAndroidHelper::FromWebContents(contents)->GetWindowAndroid(); | 208 WindowAndroidHelper::FromWebContents(contents)->GetWindowAndroid(); |
233 DCHECK(window); | 209 DCHECK(window); |
234 DCHECK_CURRENTLY_ON(content::BrowserThread::UI); | 210 DCHECK_CURRENTLY_ON(content::BrowserThread::UI); |
235 StartClientCertificateRequest(cert_request_info, window, callback); | 211 StartClientCertificateRequest(cert_request_info, window, delegate.Pass()); |
236 } | 212 } |
237 | 213 |
238 } // namespace chrome | 214 } // namespace chrome |
OLD | NEW |