blob: 2471e93467d7699f429e37322dd4ec8a1c15bf99 [file] [log] [blame]
[email protected]70c39bb2013-11-26 22:59:281// Copyright 2013 The Chromium Authors. All rights reserved.
[email protected]2702b79f2013-03-27 08:44:332// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4
[email protected]70c39bb2013-11-26 22:59:285#include "extensions/common/manifest_handlers/sandboxed_page_info.h"
[email protected]2702b79f2013-03-27 08:44:336
7#include "base/lazy_instance.h"
8#include "base/memory/scoped_ptr.h"
[email protected]d2e754f2013-06-11 01:41:479#include "base/strings/string_number_conversions.h"
[email protected]12bfb612013-06-07 19:54:0210#include "base/strings/utf_string_conversions.h"
[email protected]2702b79f2013-03-27 08:44:3311#include "base/values.h"
[email protected]70c39bb2013-11-26 22:59:2812#include "extensions/common/csp_validator.h"
[email protected]2702b79f2013-03-27 08:44:3313#include "extensions/common/error_utils.h"
[email protected]0c3c9732013-09-16 08:53:4114#include "extensions/common/manifest_constants.h"
[email protected]2702b79f2013-03-27 08:44:3315#include "extensions/common/url_pattern.h"
16
17namespace extensions {
18
19namespace {
20
[email protected]6bf90612013-08-15 00:36:2721namespace keys = extensions::manifest_keys;
[email protected]0c3c9732013-09-16 08:53:4122namespace errors = manifest_errors;
[email protected]2702b79f2013-03-27 08:44:3323
24const char kDefaultSandboxedPageContentSecurityPolicy[] =
25 "sandbox allow-scripts allow-forms allow-popups";
26
27static base::LazyInstance<SandboxedPageInfo> g_empty_sandboxed_info =
28 LAZY_INSTANCE_INITIALIZER;
29
30const SandboxedPageInfo& GetSandboxedPageInfo(const Extension* extension) {
31 SandboxedPageInfo* info = static_cast<SandboxedPageInfo*>(
32 extension->GetManifestData(keys::kSandboxedPages));
33 return info ? *info : g_empty_sandboxed_info.Get();
34}
35
36} // namespace
37
38SandboxedPageInfo::SandboxedPageInfo() {
39}
40
41SandboxedPageInfo::~SandboxedPageInfo() {
42}
43
44const std::string& SandboxedPageInfo::GetContentSecurityPolicy(
45 const Extension* extension) {
46 return GetSandboxedPageInfo(extension).content_security_policy;
47}
48
49const URLPatternSet& SandboxedPageInfo::GetPages(const Extension* extension) {
50 return GetSandboxedPageInfo(extension).pages;
51}
52
53bool SandboxedPageInfo::IsSandboxedPage(const Extension* extension,
54 const std::string& relative_path) {
55 return extension->ResourceMatches(GetPages(extension), relative_path);
56}
57
58SandboxedPageHandler::SandboxedPageHandler() {
59}
60
61SandboxedPageHandler::~SandboxedPageHandler() {
62}
63
[email protected]0d163dc2013-12-20 23:48:3664bool SandboxedPageHandler::Parse(Extension* extension, base::string16* error) {
[email protected]2702b79f2013-03-27 08:44:3365 scoped_ptr<SandboxedPageInfo> sandboxed_info(new SandboxedPageInfo);
66
67 const base::ListValue* list_value = NULL;
68 if (!extension->manifest()->GetList(keys::kSandboxedPages, &list_value)) {
[email protected]ad65a3e2013-12-25 18:18:0169 *error = base::ASCIIToUTF16(errors::kInvalidSandboxedPagesList);
[email protected]2702b79f2013-03-27 08:44:3370 return false;
71 }
72
73 for (size_t i = 0; i < list_value->GetSize(); ++i) {
74 std::string relative_path;
75 if (!list_value->GetString(i, &relative_path)) {
76 *error = ErrorUtils::FormatErrorMessageUTF16(
77 errors::kInvalidSandboxedPage, base::IntToString(i));
78 return false;
79 }
80 URLPattern pattern(URLPattern::SCHEME_EXTENSION);
81 if (pattern.Parse(extension->url().spec()) != URLPattern::PARSE_SUCCESS) {
82 *error = ErrorUtils::FormatErrorMessageUTF16(
83 errors::kInvalidURLPatternError, extension->url().spec());
84 return false;
85 }
86 while (relative_path[0] == '/')
87 relative_path = relative_path.substr(1, relative_path.length() - 1);
88 pattern.SetPath(pattern.path() + relative_path);
89 sandboxed_info->pages.AddPattern(pattern);
90 }
91
92 if (extension->manifest()->HasPath(keys::kSandboxedPagesCSP)) {
93 if (!extension->manifest()->GetString(
94 keys::kSandboxedPagesCSP,
95 &sandboxed_info->content_security_policy)) {
[email protected]ad65a3e2013-12-25 18:18:0196 *error = base::ASCIIToUTF16(errors::kInvalidSandboxedPagesCSP);
[email protected]2702b79f2013-03-27 08:44:3397 return false;
98 }
99
100 if (!csp_validator::ContentSecurityPolicyIsLegal(
101 sandboxed_info->content_security_policy) ||
102 !csp_validator::ContentSecurityPolicyIsSandboxed(
103 sandboxed_info->content_security_policy, extension->GetType())) {
[email protected]ad65a3e2013-12-25 18:18:01104 *error = base::ASCIIToUTF16(errors::kInvalidSandboxedPagesCSP);
[email protected]2702b79f2013-03-27 08:44:33105 return false;
106 }
107 } else {
108 sandboxed_info->content_security_policy =
109 kDefaultSandboxedPageContentSecurityPolicy;
110 CHECK(csp_validator::ContentSecurityPolicyIsSandboxed(
111 sandboxed_info->content_security_policy, extension->GetType()));
112 }
113
114 extension->SetManifestData(keys::kSandboxedPages, sandboxed_info.release());
115 return true;
116}
117
118const std::vector<std::string> SandboxedPageHandler::Keys() const {
119 return SingleKey(keys::kSandboxedPages);
120}
121
122} // namespace extensions