Home | History | Annotate | Download | only in loader
      1 /*
      2  * Copyright (C) 2012 Google Inc. All rights reserved.
      3  *
      4  * Redistribution and use in source and binary forms, with or without
      5  * modification, are permitted provided that the following conditions
      6  * are met:
      7  *
      8  * 1.  Redistributions of source code must retain the above copyright
      9  *     notice, this list of conditions and the following disclaimer.
     10  * 2.  Redistributions in binary form must reproduce the above copyright
     11  *     notice, this list of conditions and the following disclaimer in the
     12  *     documentation and/or other materials provided with the distribution.
     13  * 3.  Neither the name of Apple Computer, Inc. ("Apple") nor the names of
     14  *     its contributors may be used to endorse or promote products derived
     15  *     from this software without specific prior written permission.
     16  *
     17  * THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
     18  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
     19  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
     20  * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
     21  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
     22  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
     23  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
     24  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     25  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
     26  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     27  */
     28 
     29 #include "config.h"
     30 #include "core/loader/MixedContentChecker.h"
     31 
     32 #include "core/dom/Document.h"
     33 #include "core/loader/FrameLoader.h"
     34 #include "core/loader/FrameLoaderClient.h"
     35 #include "core/page/Frame.h"
     36 #include "core/page/Settings.h"
     37 #include "weborigin/SecurityOrigin.h"
     38 #include "wtf/text/WTFString.h"
     39 
     40 namespace WebCore {
     41 
     42 MixedContentChecker::MixedContentChecker(Frame* frame)
     43     : m_frame(frame)
     44 {
     45 }
     46 
     47 FrameLoaderClient* MixedContentChecker::client() const
     48 {
     49     return m_frame->loader()->client();
     50 }
     51 
     52 // static
     53 bool MixedContentChecker::isMixedContent(SecurityOrigin* securityOrigin, const KURL& url)
     54 {
     55     if (securityOrigin->protocol() != "https")
     56         return false; // We only care about HTTPS security origins.
     57 
     58     // We're in a secure context, so |url| is mixed content if it's insecure.
     59     return !SecurityOrigin::isSecure(url);
     60 }
     61 
     62 bool MixedContentChecker::canDisplayInsecureContent(SecurityOrigin* securityOrigin, const KURL& url) const
     63 {
     64     if (!isMixedContent(securityOrigin, url))
     65         return true;
     66 
     67     Settings* settings = m_frame->settings();
     68     bool allowed = client()->allowDisplayingInsecureContent(settings && settings->allowDisplayOfInsecureContent(), securityOrigin, url);
     69     logWarning(allowed, "displayed", url);
     70 
     71     if (allowed)
     72         client()->didDisplayInsecureContent();
     73 
     74     return allowed;
     75 }
     76 
     77 bool MixedContentChecker::canRunInsecureContent(SecurityOrigin* securityOrigin, const KURL& url) const
     78 {
     79     if (!isMixedContent(securityOrigin, url))
     80         return true;
     81 
     82     Settings* settings = m_frame->settings();
     83     bool allowed = client()->allowRunningInsecureContent(settings && settings->allowRunningOfInsecureContent(), securityOrigin, url);
     84     logWarning(allowed, "ran", url);
     85 
     86     if (allowed)
     87         client()->didRunInsecureContent(securityOrigin, url);
     88 
     89     return allowed;
     90 }
     91 
     92 void MixedContentChecker::logWarning(bool allowed, const String& action, const KURL& target) const
     93 {
     94     String message = String(allowed ? "" : "[blocked] ") + "The page at " + m_frame->document()->url().elidedString() + " " + action + " insecure content from " + target.elidedString() + ".\n";
     95     m_frame->document()->addConsoleMessage(SecurityMessageSource, WarningMessageLevel, message);
     96 }
     97 
     98 } // namespace WebCore
     99