electron_permission_manager.cc 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423
  1. // Copyright (c) 2016 GitHub, Inc.
  2. // Use of this source code is governed by the MIT license that can be
  3. // found in the LICENSE file.
  4. #include "shell/browser/electron_permission_manager.h"
  5. #include <memory>
  6. #include <utility>
  7. #include <vector>
  8. #include "base/values.h"
  9. #include "content/browser/permissions/permission_util.h" // nogncheck
  10. #include "content/public/browser/child_process_security_policy.h"
  11. #include "content/public/browser/global_routing_id.h"
  12. #include "content/public/browser/permission_controller.h"
  13. #include "content/public/browser/render_frame_host.h"
  14. #include "content/public/browser/render_process_host.h"
  15. #include "content/public/browser/render_view_host.h"
  16. #include "content/public/browser/web_contents.h"
  17. #include "gin/data_object_builder.h"
  18. #include "shell/browser/api/electron_api_web_contents.h"
  19. #include "shell/browser/electron_browser_context.h"
  20. #include "shell/browser/electron_browser_main_parts.h"
  21. #include "shell/browser/web_contents_permission_helper.h"
  22. #include "shell/browser/web_contents_preferences.h"
  23. #include "shell/common/gin_converters/content_converter.h"
  24. #include "shell/common/gin_converters/frame_converter.h"
  25. #include "shell/common/gin_converters/usb_protected_classes_converter.h"
  26. #include "shell/common/gin_converters/value_converter.h"
  27. #include "shell/common/gin_helper/dictionary.h"
  28. #include "shell/common/gin_helper/event_emitter_caller.h"
  29. #include "third_party/blink/public/common/permissions/permission_utils.h"
  30. namespace electron {
  31. namespace {
  32. bool WebContentsDestroyed(content::RenderFrameHost* rfh) {
  33. content::WebContents* web_contents =
  34. content::WebContents::FromRenderFrameHost(rfh);
  35. if (!web_contents)
  36. return true;
  37. return web_contents->IsBeingDestroyed();
  38. }
  39. void PermissionRequestResponseCallbackWrapper(
  40. ElectronPermissionManager::StatusCallback callback,
  41. const std::vector<blink::mojom::PermissionStatus>& vector) {
  42. std::move(callback).Run(vector[0]);
  43. }
  44. } // namespace
  45. class ElectronPermissionManager::PendingRequest {
  46. public:
  47. PendingRequest(content::RenderFrameHost* render_frame_host,
  48. const std::vector<blink::PermissionType>& permissions,
  49. StatusesCallback callback)
  50. : render_frame_host_id_(render_frame_host->GetGlobalId()),
  51. callback_(std::move(callback)),
  52. permissions_(permissions),
  53. results_(permissions.size(), blink::mojom::PermissionStatus::DENIED),
  54. remaining_results_(permissions.size()) {}
  55. void SetPermissionStatus(int permission_id,
  56. blink::mojom::PermissionStatus status) {
  57. DCHECK(!IsComplete());
  58. if (status == blink::mojom::PermissionStatus::GRANTED) {
  59. const auto permission = permissions_[permission_id];
  60. if (permission == blink::PermissionType::MIDI_SYSEX) {
  61. content::ChildProcessSecurityPolicy::GetInstance()
  62. ->GrantSendMidiSysExMessage(render_frame_host_id_.child_id);
  63. } else if (permission == blink::PermissionType::GEOLOCATION) {
  64. ElectronBrowserMainParts::Get()
  65. ->GetGeolocationControl()
  66. ->UserDidOptIntoLocationServices();
  67. }
  68. }
  69. results_[permission_id] = status;
  70. --remaining_results_;
  71. }
  72. content::RenderFrameHost* GetRenderFrameHost() {
  73. return content::RenderFrameHost::FromID(render_frame_host_id_);
  74. }
  75. [[nodiscard]] bool IsComplete() const { return remaining_results_ == 0; }
  76. void RunCallback() {
  77. if (!callback_.is_null()) {
  78. std::move(callback_).Run(results_);
  79. }
  80. }
  81. private:
  82. content::GlobalRenderFrameHostId render_frame_host_id_;
  83. StatusesCallback callback_;
  84. std::vector<blink::PermissionType> permissions_;
  85. std::vector<blink::mojom::PermissionStatus> results_;
  86. size_t remaining_results_;
  87. };
  88. ElectronPermissionManager::ElectronPermissionManager() = default;
  89. ElectronPermissionManager::~ElectronPermissionManager() = default;
  90. void ElectronPermissionManager::SetPermissionRequestHandler(
  91. const RequestHandler& handler) {
  92. if (handler.is_null() && !pending_requests_.IsEmpty()) {
  93. for (PendingRequestsMap::iterator iter(&pending_requests_); !iter.IsAtEnd();
  94. iter.Advance()) {
  95. auto* request = iter.GetCurrentValue();
  96. if (!WebContentsDestroyed(request->GetRenderFrameHost()))
  97. request->RunCallback();
  98. }
  99. pending_requests_.Clear();
  100. }
  101. request_handler_ = handler;
  102. }
  103. void ElectronPermissionManager::SetPermissionCheckHandler(
  104. const CheckHandler& handler) {
  105. check_handler_ = handler;
  106. }
  107. void ElectronPermissionManager::SetDevicePermissionHandler(
  108. const DeviceCheckHandler& handler) {
  109. device_permission_handler_ = handler;
  110. }
  111. void ElectronPermissionManager::SetProtectedUSBHandler(
  112. const ProtectedUSBHandler& handler) {
  113. protected_usb_handler_ = handler;
  114. }
  115. void ElectronPermissionManager::SetBluetoothPairingHandler(
  116. const BluetoothPairingHandler& handler) {
  117. bluetooth_pairing_handler_ = handler;
  118. }
  119. void ElectronPermissionManager::RequestPermissionWithDetails(
  120. blink::PermissionType permission,
  121. content::RenderFrameHost* render_frame_host,
  122. const GURL& requesting_origin,
  123. bool user_gesture,
  124. base::Value::Dict details,
  125. StatusCallback response_callback) {
  126. if (render_frame_host->IsNestedWithinFencedFrame()) {
  127. std::move(response_callback).Run(blink::mojom::PermissionStatus::DENIED);
  128. return;
  129. }
  130. RequestPermissionsWithDetails(
  131. render_frame_host,
  132. content::PermissionRequestDescription(permission, user_gesture,
  133. requesting_origin),
  134. std::move(details),
  135. base::BindOnce(PermissionRequestResponseCallbackWrapper,
  136. std::move(response_callback)));
  137. }
  138. void ElectronPermissionManager::RequestPermissions(
  139. content::RenderFrameHost* render_frame_host,
  140. const content::PermissionRequestDescription& request_description,
  141. StatusesCallback callback) {
  142. if (render_frame_host->IsNestedWithinFencedFrame()) {
  143. std::move(callback).Run(std::vector<blink::mojom::PermissionStatus>(
  144. request_description.permissions.size(),
  145. blink::mojom::PermissionStatus::DENIED));
  146. return;
  147. }
  148. RequestPermissionsWithDetails(render_frame_host, request_description, {},
  149. std::move(callback));
  150. }
  151. void ElectronPermissionManager::RequestPermissionsWithDetails(
  152. content::RenderFrameHost* render_frame_host,
  153. const content::PermissionRequestDescription& request_description,
  154. base::Value::Dict details,
  155. StatusesCallback response_callback) {
  156. auto& permissions = request_description.permissions;
  157. if (permissions.empty()) {
  158. std::move(response_callback).Run({});
  159. return;
  160. }
  161. if (request_handler_.is_null()) {
  162. std::vector<blink::mojom::PermissionStatus> statuses;
  163. for (auto& permission : permissions) {
  164. if (permission == blink::PermissionType::MIDI_SYSEX) {
  165. content::ChildProcessSecurityPolicy::GetInstance()
  166. ->GrantSendMidiSysExMessage(
  167. render_frame_host->GetProcess()->GetDeprecatedID());
  168. } else if (permission == blink::PermissionType::GEOLOCATION) {
  169. ElectronBrowserMainParts::Get()
  170. ->GetGeolocationControl()
  171. ->UserDidOptIntoLocationServices();
  172. }
  173. statuses.push_back(blink::mojom::PermissionStatus::GRANTED);
  174. }
  175. std::move(response_callback).Run(statuses);
  176. return;
  177. }
  178. auto* web_contents =
  179. content::WebContents::FromRenderFrameHost(render_frame_host);
  180. int request_id = pending_requests_.Add(std::make_unique<PendingRequest>(
  181. render_frame_host, permissions, std::move(response_callback)));
  182. details.Set("requestingUrl", render_frame_host->GetLastCommittedURL().spec());
  183. details.Set("isMainFrame", render_frame_host->GetParent() == nullptr);
  184. base::Value dict_value(std::move(details));
  185. for (size_t i = 0; i < permissions.size(); ++i) {
  186. auto permission = permissions[i];
  187. const auto callback =
  188. base::BindRepeating(&ElectronPermissionManager::OnPermissionResponse,
  189. base::Unretained(this), request_id, i);
  190. request_handler_.Run(web_contents, permission, callback, dict_value);
  191. }
  192. }
  193. void ElectronPermissionManager::OnPermissionResponse(
  194. int request_id,
  195. int permission_id,
  196. blink::mojom::PermissionStatus status) {
  197. auto* pending_request = pending_requests_.Lookup(request_id);
  198. if (!pending_request)
  199. return;
  200. pending_request->SetPermissionStatus(permission_id, status);
  201. if (pending_request->IsComplete()) {
  202. pending_request->RunCallback();
  203. pending_requests_.Remove(request_id);
  204. }
  205. }
  206. void ElectronPermissionManager::ResetPermission(
  207. blink::PermissionType permission,
  208. const GURL& requesting_origin,
  209. const GURL& embedding_origin) {}
  210. void ElectronPermissionManager::RequestPermissionsFromCurrentDocument(
  211. content::RenderFrameHost* render_frame_host,
  212. const content::PermissionRequestDescription& request_description,
  213. base::OnceCallback<void(const std::vector<blink::mojom::PermissionStatus>&)>
  214. callback) {
  215. if (render_frame_host->IsNestedWithinFencedFrame()) {
  216. std::move(callback).Run(std::vector<blink::mojom::PermissionStatus>(
  217. request_description.permissions.size(),
  218. blink::mojom::PermissionStatus::DENIED));
  219. return;
  220. }
  221. RequestPermissionsWithDetails(render_frame_host, request_description, {},
  222. std::move(callback));
  223. }
  224. blink::mojom::PermissionStatus ElectronPermissionManager::GetPermissionStatus(
  225. blink::PermissionType permission,
  226. const GURL& requesting_origin,
  227. const GURL& embedding_origin) {
  228. base::Value::Dict details;
  229. details.Set("embeddingOrigin", embedding_origin.spec());
  230. bool granted = CheckPermissionWithDetails(permission, {}, requesting_origin,
  231. std::move(details));
  232. return granted ? blink::mojom::PermissionStatus::GRANTED
  233. : blink::mojom::PermissionStatus::DENIED;
  234. }
  235. content::PermissionResult
  236. ElectronPermissionManager::GetPermissionResultForOriginWithoutContext(
  237. blink::PermissionType permission,
  238. const url::Origin& requesting_origin,
  239. const url::Origin& embedding_origin) {
  240. blink::mojom::PermissionStatus status = GetPermissionStatus(
  241. permission, requesting_origin.GetURL(), embedding_origin.GetURL());
  242. return {status, content::PermissionStatusSource::UNSPECIFIED};
  243. }
  244. void ElectronPermissionManager::CheckBluetoothDevicePair(
  245. gin_helper::Dictionary details,
  246. PairCallback pair_callback) const {
  247. if (bluetooth_pairing_handler_.is_null()) {
  248. base::Value::Dict response;
  249. response.Set("confirmed", false);
  250. std::move(pair_callback).Run(std::move(response));
  251. } else {
  252. bluetooth_pairing_handler_.Run(details, std::move(pair_callback));
  253. }
  254. }
  255. bool ElectronPermissionManager::CheckPermissionWithDetails(
  256. blink::PermissionType permission,
  257. content::RenderFrameHost* render_frame_host,
  258. const GURL& requesting_origin,
  259. base::Value::Dict details) const {
  260. if (check_handler_.is_null()) {
  261. if (permission == blink::PermissionType::DEPRECATED_SYNC_CLIPBOARD_READ) {
  262. return false;
  263. } else {
  264. return true;
  265. }
  266. }
  267. auto* web_contents =
  268. render_frame_host
  269. ? content::WebContents::FromRenderFrameHost(render_frame_host)
  270. : nullptr;
  271. if (render_frame_host) {
  272. details.Set("requestingUrl",
  273. render_frame_host->GetLastCommittedURL().spec());
  274. }
  275. details.Set("isMainFrame",
  276. render_frame_host && render_frame_host->GetParent() == nullptr);
  277. switch (permission) {
  278. case blink::PermissionType::AUDIO_CAPTURE:
  279. details.Set("mediaType", "audio");
  280. break;
  281. case blink::PermissionType::VIDEO_CAPTURE:
  282. details.Set("mediaType", "video");
  283. break;
  284. default:
  285. break;
  286. }
  287. return check_handler_.Run(web_contents, permission, requesting_origin,
  288. base::Value(std::move(details)));
  289. }
  290. bool ElectronPermissionManager::CheckDevicePermission(
  291. blink::PermissionType permission,
  292. const url::Origin& origin,
  293. const base::Value& device,
  294. ElectronBrowserContext* browser_context) const {
  295. if (device_permission_handler_.is_null())
  296. return browser_context->CheckDevicePermission(origin, device, permission);
  297. v8::Isolate* isolate = JavascriptEnvironment::GetIsolate();
  298. v8::HandleScope scope(isolate);
  299. v8::Local<v8::Object> details = gin::DataObjectBuilder(isolate)
  300. .Set("deviceType", permission)
  301. .Set("origin", origin.Serialize())
  302. .Set("device", device.Clone())
  303. .Build();
  304. return device_permission_handler_.Run(details);
  305. }
  306. void ElectronPermissionManager::GrantDevicePermission(
  307. blink::PermissionType permission,
  308. const url::Origin& origin,
  309. const base::Value& device,
  310. ElectronBrowserContext* browser_context) const {
  311. if (device_permission_handler_.is_null()) {
  312. browser_context->GrantDevicePermission(origin, device, permission);
  313. }
  314. }
  315. void ElectronPermissionManager::RevokeDevicePermission(
  316. blink::PermissionType permission,
  317. const url::Origin& origin,
  318. const base::Value& device,
  319. ElectronBrowserContext* browser_context) const {
  320. browser_context->RevokeDevicePermission(origin, device, permission);
  321. }
  322. ElectronPermissionManager::USBProtectedClasses
  323. ElectronPermissionManager::CheckProtectedUSBClasses(
  324. const USBProtectedClasses& classes) const {
  325. if (protected_usb_handler_.is_null())
  326. return classes;
  327. v8::Isolate* isolate = JavascriptEnvironment::GetIsolate();
  328. v8::HandleScope scope(isolate);
  329. v8::Local<v8::Object> details =
  330. gin::DataObjectBuilder(isolate).Set("protectedClasses", classes).Build();
  331. return protected_usb_handler_.Run(details);
  332. }
  333. blink::mojom::PermissionStatus
  334. ElectronPermissionManager::GetPermissionStatusForCurrentDocument(
  335. blink::PermissionType permission,
  336. content::RenderFrameHost* render_frame_host,
  337. bool /*should_include_device_status*/) {
  338. if (render_frame_host->IsNestedWithinFencedFrame())
  339. return blink::mojom::PermissionStatus::DENIED;
  340. base::Value::Dict details;
  341. details.Set("embeddingOrigin",
  342. content::PermissionUtil::GetLastCommittedOriginAsURL(
  343. render_frame_host->GetMainFrame())
  344. .spec());
  345. bool granted = CheckPermissionWithDetails(
  346. permission, render_frame_host,
  347. render_frame_host->GetLastCommittedOrigin().GetURL(), std::move(details));
  348. return granted ? blink::mojom::PermissionStatus::GRANTED
  349. : blink::mojom::PermissionStatus::DENIED;
  350. }
  351. blink::mojom::PermissionStatus
  352. ElectronPermissionManager::GetPermissionStatusForWorker(
  353. blink::PermissionType permission,
  354. content::RenderProcessHost* render_process_host,
  355. const GURL& worker_origin) {
  356. return GetPermissionStatus(permission, worker_origin, worker_origin);
  357. }
  358. blink::mojom::PermissionStatus
  359. ElectronPermissionManager::GetPermissionStatusForEmbeddedRequester(
  360. blink::PermissionType permission,
  361. content::RenderFrameHost* render_frame_host,
  362. const url::Origin& overridden_origin) {
  363. if (render_frame_host->IsNestedWithinFencedFrame())
  364. return blink::mojom::PermissionStatus::DENIED;
  365. return GetPermissionStatus(
  366. permission, overridden_origin.GetURL(),
  367. render_frame_host->GetLastCommittedOrigin().GetURL());
  368. }
  369. } // namespace electron