Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(496)

Side by Side Diff: extensions/browser/url_request_util.cc

Issue 2432153003: Make sure the default CSP is used for <webview> with PlzNavigate. (Closed)
Patch Set: add comment Created 4 years, 2 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright 2014 The Chromium Authors. All rights reserved. 1 // Copyright 2014 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "extensions/browser/url_request_util.h" 5 #include "extensions/browser/url_request_util.h"
6 6
7 #include <string> 7 #include <string>
8 8
9 #include "content/public/browser/resource_request_info.h" 9 #include "content/public/browser/resource_request_info.h"
10 #include "content/public/common/browser_side_navigation_policy.h" 10 #include "content/public/common/browser_side_navigation_policy.h"
11 #include "extensions/browser/extension_navigation_ui_data.h"
12 #include "extensions/browser/extensions_browser_client.h"
11 #include "extensions/browser/guest_view/web_view/web_view_renderer_state.h" 13 #include "extensions/browser/guest_view/web_view/web_view_renderer_state.h"
12 #include "extensions/browser/info_map.h" 14 #include "extensions/browser/info_map.h"
13 #include "extensions/common/extension.h" 15 #include "extensions/common/extension.h"
14 #include "extensions/common/manifest_handlers/icons_handler.h" 16 #include "extensions/common/manifest_handlers/icons_handler.h"
15 #include "extensions/common/manifest_handlers/web_accessible_resources_info.h" 17 #include "extensions/common/manifest_handlers/web_accessible_resources_info.h"
16 #include "extensions/common/manifest_handlers/webview_info.h" 18 #include "extensions/common/manifest_handlers/webview_info.h"
17 #include "net/url_request/url_request.h" 19 #include "net/url_request/url_request.h"
18 20
19 namespace extensions { 21 namespace extensions {
20 namespace url_request_util { 22 namespace url_request_util {
(...skipping 98 matching lines...) Expand 10 before | Expand all | Expand 10 after
119 121
120 if (!ui::PageTransitionIsWebTriggerable(info->GetPageTransition())) { 122 if (!ui::PageTransitionIsWebTriggerable(info->GetPageTransition())) {
121 *allowed = false; 123 *allowed = false;
122 return true; 124 return true;
123 } 125 }
124 126
125 // Couldn't determine if the resource is allowed or not. 127 // Couldn't determine if the resource is allowed or not.
126 return false; 128 return false;
127 } 129 }
128 130
129 bool IsWebViewRequest(const net::URLRequest* request) { 131 bool IsWebViewRequest(net::URLRequest* request) {
130 const content::ResourceRequestInfo* info = 132 const content::ResourceRequestInfo* info =
131 content::ResourceRequestInfo::ForRequest(request); 133 content::ResourceRequestInfo::ForRequest(request);
132 // |info| can be NULL sometimes: http://crbug.com/370070. 134 // |info| can be NULL sometimes: http://crbug.com/370070.
133 if (!info) 135 if (!info)
134 return false; 136 return false;
135 return WebViewRendererState::GetInstance()->IsGuest(info->GetChildID()); 137 if (WebViewRendererState::GetInstance()->IsGuest(info->GetChildID()))
138 return true;
139
140 // GetChildId() is -1 with PlzNavigate for navigation requests, so also try
141 // the ExtensionNavigationUIData data.
142 ExtensionNavigationUIData* data =
143 ExtensionsBrowserClient::Get()->GetExtensionNavigationUIData(request);
144 return data && data->is_web_view();
136 } 145 }
137 146
138 bool AllowCrossRendererResourceLoadHelper(bool is_guest, 147 bool AllowCrossRendererResourceLoadHelper(bool is_guest,
139 const Extension* extension, 148 const Extension* extension,
140 const Extension* owner_extension, 149 const Extension* owner_extension,
141 const std::string& partition_id, 150 const std::string& partition_id,
142 const std::string& resource_path, 151 const std::string& resource_path,
143 ui::PageTransition page_transition, 152 ui::PageTransition page_transition,
144 bool* allowed) { 153 bool* allowed) {
145 // |owner_extension == extension| needs to be checked because extension 154 // |owner_extension == extension| needs to be checked because extension
146 // resources should only be accessible to WebViews owned by that extension. 155 // resources should only be accessible to WebViews owned by that extension.
147 if (is_guest && owner_extension == extension && 156 if (is_guest && owner_extension == extension &&
148 WebviewInfo::IsResourceWebviewAccessible(extension, partition_id, 157 WebviewInfo::IsResourceWebviewAccessible(extension, partition_id,
149 resource_path)) { 158 resource_path)) {
150 *allowed = true; 159 *allowed = true;
151 return true; 160 return true;
152 } 161 }
153 162
154 if (is_guest && !ui::PageTransitionIsWebTriggerable(page_transition)) { 163 if (is_guest && !ui::PageTransitionIsWebTriggerable(page_transition)) {
155 *allowed = false; 164 *allowed = false;
156 return true; 165 return true;
157 } 166 }
158 167
159 return false; 168 return false;
160 } 169 }
161 170
162 } // namespace url_request_util 171 } // namespace url_request_util
163 } // namespace extensions 172 } // namespace extensions
OLDNEW
« no previous file with comments | « extensions/browser/url_request_util.h ('k') | extensions/shell/browser/shell_network_delegate.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698