blob: 8427cafde7c7614cde801244d2c6b2d47c3f4c69 [file] [log] [blame]
binjin5f405ef2014-09-03 21:23:161// Copyright 2014 The Chromium Authors. All rights reserved.
2// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4
5#include "chrome/browser/extensions/extension_management.h"
6
binjin81d7c552014-10-02 11:47:127#include <algorithm>
dcheng1fc00f12015-12-26 22:18:038#include <utility>
binjin81d7c552014-10-02 11:47:129
binjin1569c9b2014-09-05 13:33:1810#include "base/bind.h"
11#include "base/bind_helpers.h"
binjin5f405ef2014-09-03 21:23:1612#include "base/logging.h"
lazyboy4aeef202016-09-07 21:28:5913#include "base/memory/ptr_util.h"
rkaplowdd66a1342015-03-05 00:31:4914#include "base/metrics/histogram_macros.h"
binjine6b58b52014-10-31 01:55:5715#include "base/strings/string16.h"
binjinb2454382014-09-22 15:17:4316#include "base/strings/string_util.h"
rkaplowdd66a1342015-03-05 00:31:4917#include "base/trace_event/trace_event.h"
binjin8e3d0182014-12-04 16:44:2818#include "base/version.h"
binjinb2454382014-09-22 15:17:4319#include "chrome/browser/extensions/extension_management_constants.h"
binjin81d7c552014-10-02 11:47:1220#include "chrome/browser/extensions/extension_management_internal.h"
binjin30301062014-09-08 20:27:3421#include "chrome/browser/extensions/external_policy_loader.h"
binjin5f405ef2014-09-03 21:23:1622#include "chrome/browser/extensions/external_provider_impl.h"
binjine6b58b52014-10-31 01:55:5723#include "chrome/browser/extensions/permissions_based_management_policy_provider.h"
binjin1569c9b2014-09-05 13:33:1824#include "chrome/browser/extensions/standard_management_policy_provider.h"
binjin9733df12014-09-08 15:21:2125#include "chrome/browser/profiles/incognito_helpers.h"
binjin1569c9b2014-09-05 13:33:1826#include "chrome/browser/profiles/profile.h"
binjin5f405ef2014-09-03 21:23:1627#include "components/crx_file/id_util.h"
binjin1569c9b2014-09-05 13:33:1828#include "components/keyed_service/content/browser_context_dependency_manager.h"
binjinb2454382014-09-22 15:17:4329#include "components/pref_registry/pref_registry_syncable.h"
brettwb1fc1b82016-02-02 00:19:0830#include "components/prefs/pref_service.h"
binjin5f405ef2014-09-03 21:23:1631#include "extensions/browser/pref_names.h"
rdevlin.cronin0670b562016-07-02 02:05:4332#include "extensions/common/extension.h"
binjin685ade82014-11-06 09:53:5633#include "extensions/common/manifest_constants.h"
binjine6b58b52014-10-31 01:55:5734#include "extensions/common/permissions/api_permission_set.h"
35#include "extensions/common/permissions/permission_set.h"
binjin5f405ef2014-09-03 21:23:1636#include "extensions/common/url_pattern.h"
binjin311ecdf2014-09-12 22:56:5237#include "url/gurl.h"
binjin5f405ef2014-09-03 21:23:1638
achuith4607f072017-03-08 11:49:1339#if defined(OS_CHROMEOS)
40#include "chrome/browser/chromeos/profiles/profile_helper.h"
41#endif
42
binjin5f405ef2014-09-03 21:23:1643namespace extensions {
44
achuith4607f072017-03-08 11:49:1345ExtensionManagement::ExtensionManagement(PrefService* pref_service,
46 bool is_signin_profile)
47 : pref_service_(pref_service), is_signin_profile_(is_signin_profile) {
rkaplowdd66a1342015-03-05 00:31:4948 TRACE_EVENT0("browser,startup",
49 "ExtensionManagement::ExtensionManagement::ctor");
binjin1569c9b2014-09-05 13:33:1850 pref_change_registrar_.Init(pref_service_);
51 base::Closure pref_change_callback = base::Bind(
52 &ExtensionManagement::OnExtensionPrefChanged, base::Unretained(this));
53 pref_change_registrar_.Add(pref_names::kInstallAllowList,
54 pref_change_callback);
55 pref_change_registrar_.Add(pref_names::kInstallDenyList,
56 pref_change_callback);
57 pref_change_registrar_.Add(pref_names::kInstallForceList,
58 pref_change_callback);
achuith4607f072017-03-08 11:49:1359 pref_change_registrar_.Add(pref_names::kInstallLoginScreenAppList,
60 pref_change_callback);
binjin1569c9b2014-09-05 13:33:1861 pref_change_registrar_.Add(pref_names::kAllowedInstallSites,
62 pref_change_callback);
63 pref_change_registrar_.Add(pref_names::kAllowedTypes, pref_change_callback);
binjinb2454382014-09-22 15:17:4364 pref_change_registrar_.Add(pref_names::kExtensionManagement,
65 pref_change_callback);
binjin81d7c552014-10-02 11:47:1266 // Note that both |global_settings_| and |default_settings_| will be null
67 // before first call to Refresh(), so in order to resolve this, Refresh() must
68 // be called in the initialization of ExtensionManagement.
binjin1569c9b2014-09-05 13:33:1869 Refresh();
lazyboy4aeef202016-09-07 21:28:5970 providers_.push_back(
71 base::MakeUnique<StandardManagementPolicyProvider>(this));
72 providers_.push_back(
73 base::MakeUnique<PermissionsBasedManagementPolicyProvider>(this));
binjin5f405ef2014-09-03 21:23:1674}
75
76ExtensionManagement::~ExtensionManagement() {
77}
78
binjine6b58b52014-10-31 01:55:5779void ExtensionManagement::Shutdown() {
80 pref_change_registrar_.RemoveAll();
81 pref_service_ = nullptr;
82}
83
binjin1569c9b2014-09-05 13:33:1884void ExtensionManagement::AddObserver(Observer* observer) {
85 observer_list_.AddObserver(observer);
86}
87
88void ExtensionManagement::RemoveObserver(Observer* observer) {
89 observer_list_.RemoveObserver(observer);
90}
91
lazyboy4aeef202016-09-07 21:28:5992const std::vector<std::unique_ptr<ManagementPolicy::Provider>>&
93ExtensionManagement::GetProviders() const {
94 return providers_;
binjin1569c9b2014-09-05 13:33:1895}
96
binjin81d7c552014-10-02 11:47:1297bool ExtensionManagement::BlacklistedByDefault() const {
98 return default_settings_->installation_mode == INSTALLATION_BLOCKED;
99}
100
101ExtensionManagement::InstallationMode ExtensionManagement::GetInstallationMode(
binjin685ade82014-11-06 09:53:56102 const Extension* extension) const {
103 // Check per-extension installation mode setting first.
104 auto iter_id = settings_by_id_.find(extension->id());
105 if (iter_id != settings_by_id_.end())
106 return iter_id->second->installation_mode;
107 std::string update_url;
108 // Check per-update-url installation mode setting.
109 if (extension->manifest()->GetString(manifest_keys::kUpdateURL,
110 &update_url)) {
111 auto iter_update_url = settings_by_update_url_.find(update_url);
112 if (iter_update_url != settings_by_update_url_.end())
113 return iter_update_url->second->installation_mode;
114 }
115 // Fall back to default installation mode setting.
116 return default_settings_->installation_mode;
binjin1569c9b2014-09-05 13:33:18117}
118
dchengc963c7142016-04-08 03:55:22119std::unique_ptr<base::DictionaryValue>
hashimoto146e05a2016-11-18 07:42:53120ExtensionManagement::GetForceInstallList() const {
achuith4607f072017-03-08 11:49:13121 return GetInstallListByMode(INSTALLATION_FORCED);
binjincccacef2014-10-13 19:00:20122}
123
dchengc963c7142016-04-08 03:55:22124std::unique_ptr<base::DictionaryValue>
binjincccacef2014-10-13 19:00:20125ExtensionManagement::GetRecommendedInstallList() const {
achuith4607f072017-03-08 11:49:13126 return GetInstallListByMode(INSTALLATION_RECOMMENDED);
binjin30301062014-09-08 20:27:34127}
128
binjinc641add2014-10-15 16:20:45129bool ExtensionManagement::IsInstallationExplicitlyAllowed(
130 const ExtensionId& id) const {
avi3ec9c0d2016-12-27 22:38:06131 auto it = settings_by_id_.find(id);
binjinc641add2014-10-15 16:20:45132 // No settings explicitly specified for |id|.
133 if (it == settings_by_id_.end())
134 return false;
135 // Checks if the extension is on the automatically installed list or
136 // install white-list.
137 InstallationMode mode = it->second->installation_mode;
138 return mode == INSTALLATION_FORCED || mode == INSTALLATION_RECOMMENDED ||
139 mode == INSTALLATION_ALLOWED;
binjin30301062014-09-08 20:27:34140}
141
binjin81d7c552014-10-02 11:47:12142bool ExtensionManagement::IsOffstoreInstallAllowed(
143 const GURL& url,
144 const GURL& referrer_url) const {
binjin311ecdf2014-09-12 22:56:52145 // No allowed install sites specified, disallow by default.
binjin81d7c552014-10-02 11:47:12146 if (!global_settings_->has_restricted_install_sources)
binjin311ecdf2014-09-12 22:56:52147 return false;
148
binjin81d7c552014-10-02 11:47:12149 const URLPatternSet& url_patterns = global_settings_->install_sources;
binjin311ecdf2014-09-12 22:56:52150
151 if (!url_patterns.MatchesURL(url))
152 return false;
153
154 // The referrer URL must also be whitelisted, unless the URL has the file
155 // scheme (there's no referrer for those URLs).
156 return url.SchemeIsFile() || url_patterns.MatchesURL(referrer_url);
157}
158
binjin81d7c552014-10-02 11:47:12159bool ExtensionManagement::IsAllowedManifestType(
160 Manifest::Type manifest_type) const {
161 if (!global_settings_->has_restricted_allowed_types)
162 return true;
163 const std::vector<Manifest::Type>& allowed_types =
164 global_settings_->allowed_types;
165 return std::find(allowed_types.begin(), allowed_types.end(), manifest_type) !=
166 allowed_types.end();
binjin1569c9b2014-09-05 13:33:18167}
168
binjin685ade82014-11-06 09:53:56169APIPermissionSet ExtensionManagement::GetBlockedAPIPermissions(
170 const Extension* extension) const {
171 // Fetch per-extension blocked permissions setting.
172 auto iter_id = settings_by_id_.find(extension->id());
173
174 // Fetch per-update-url blocked permissions setting.
175 std::string update_url;
176 auto iter_update_url = settings_by_update_url_.end();
177 if (extension->manifest()->GetString(manifest_keys::kUpdateURL,
178 &update_url)) {
179 iter_update_url = settings_by_update_url_.find(update_url);
180 }
181
182 if (iter_id != settings_by_id_.end() &&
183 iter_update_url != settings_by_update_url_.end()) {
184 // Blocked permissions setting are specified in both per-extension and
185 // per-update-url settings, try to merge them.
186 APIPermissionSet merged;
187 APIPermissionSet::Union(iter_id->second->blocked_permissions,
188 iter_update_url->second->blocked_permissions,
189 &merged);
190 return merged;
191 }
192 // Check whether if in one of them, setting is specified.
193 if (iter_id != settings_by_id_.end())
194 return iter_id->second->blocked_permissions;
195 if (iter_update_url != settings_by_update_url_.end())
196 return iter_update_url->second->blocked_permissions;
197 // Fall back to the default blocked permissions setting.
198 return default_settings_->blocked_permissions;
binjine6b58b52014-10-31 01:55:57199}
200
nrpetere33d2a5b2017-04-25 00:12:31201const URLPatternSet& ExtensionManagement::GetDefaultRuntimeBlockedHosts()
202 const {
203 return default_settings_->runtime_blocked_hosts;
204}
205
206const URLPatternSet& ExtensionManagement::GetDefaultRuntimeAllowedHosts()
207 const {
208 return default_settings_->runtime_allowed_hosts;
209}
210
nrpeter40e16382017-04-13 17:34:58211const URLPatternSet& ExtensionManagement::GetRuntimeBlockedHosts(
212 const Extension* extension) const {
213 auto iter_id = settings_by_id_.find(extension->id());
214 if (iter_id != settings_by_id_.end())
215 return iter_id->second->runtime_blocked_hosts;
216 return default_settings_->runtime_blocked_hosts;
217}
218
219const URLPatternSet& ExtensionManagement::GetRuntimeAllowedHosts(
220 const Extension* extension) const {
221 auto iter_id = settings_by_id_.find(extension->id());
222 if (iter_id != settings_by_id_.end())
223 return iter_id->second->runtime_allowed_hosts;
224 return default_settings_->runtime_allowed_hosts;
225}
226
nrpetere33d2a5b2017-04-25 00:12:31227bool ExtensionManagement::UsesDefaultRuntimeHostRestrictions(
228 const Extension* extension) const {
229 return settings_by_id_.find(extension->id()) == settings_by_id_.end();
230}
231
232bool ExtensionManagement::IsRuntimeBlockedHost(const Extension* extension,
233 const GURL& url) const {
nrpeter40e16382017-04-13 17:34:58234 auto iter_id = settings_by_id_.find(extension->id());
235 if (iter_id != settings_by_id_.end())
236 return iter_id->second->runtime_blocked_hosts.MatchesURL(url);
237 return default_settings_->runtime_blocked_hosts.MatchesURL(url);
238}
239
dchengc963c7142016-04-08 03:55:22240std::unique_ptr<const PermissionSet> ExtensionManagement::GetBlockedPermissions(
binjin685ade82014-11-06 09:53:56241 const Extension* extension) const {
binjine6b58b52014-10-31 01:55:57242 // Only api permissions are supported currently.
dchengc963c7142016-04-08 03:55:22243 return std::unique_ptr<const PermissionSet>(new PermissionSet(
binjin685ade82014-11-06 09:53:56244 GetBlockedAPIPermissions(extension), ManifestPermissionSet(),
245 URLPatternSet(), URLPatternSet()));
binjine6b58b52014-10-31 01:55:57246}
247
248bool ExtensionManagement::IsPermissionSetAllowed(
binjin685ade82014-11-06 09:53:56249 const Extension* extension,
rdevlin.cronine2d0fd02015-09-24 22:35:49250 const PermissionSet& perms) const {
vmpstrae72b082016-07-25 21:55:47251 for (auto* blocked_api : GetBlockedAPIPermissions(extension)) {
rdevlin.cronine2d0fd02015-09-24 22:35:49252 if (perms.HasAPIPermission(blocked_api->id()))
binjine6b58b52014-10-31 01:55:57253 return false;
254 }
255 return true;
256}
257
nrpeter2362e7e2017-05-10 17:21:26258const std::string ExtensionManagement::BlockedInstallMessage(
259 const ExtensionId& id) const {
260 auto iter_id = settings_by_id_.find(id);
261 if (iter_id != settings_by_id_.end())
262 return iter_id->second->blocked_install_message;
263 return default_settings_->blocked_install_message;
264}
265
binjin8e3d0182014-12-04 16:44:28266bool ExtensionManagement::CheckMinimumVersion(
267 const Extension* extension,
268 std::string* required_version) const {
269 auto iter = settings_by_id_.find(extension->id());
270 // If there are no minimum version required for |extension|, return true.
271 if (iter == settings_by_id_.end() || !iter->second->minimum_version_required)
272 return true;
273 bool meets_requirement = extension->version()->CompareTo(
274 *iter->second->minimum_version_required) >= 0;
275 // Output a human readable version string for prompting if necessary.
276 if (!meets_requirement && required_version)
277 *required_version = iter->second->minimum_version_required->GetString();
278 return meets_requirement;
279}
280
binjin5f405ef2014-09-03 21:23:16281void ExtensionManagement::Refresh() {
rkaplowdd66a1342015-03-05 00:31:49282 TRACE_EVENT0("browser,startup", "ExtensionManagement::Refresh");
283 SCOPED_UMA_HISTOGRAM_TIMER("Extensions.ExtensionManagement_RefreshTime");
binjin5f405ef2014-09-03 21:23:16284 // Load all extension management settings preferences.
285 const base::ListValue* allowed_list_pref =
286 static_cast<const base::ListValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28287 pref_names::kInstallAllowList, true, base::Value::Type::LIST));
binjin5f405ef2014-09-03 21:23:16288 // Allow user to use preference to block certain extensions. Note that policy
289 // managed forcelist or whitelist will always override this.
290 const base::ListValue* denied_list_pref =
291 static_cast<const base::ListValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28292 pref_names::kInstallDenyList, false, base::Value::Type::LIST));
binjin5f405ef2014-09-03 21:23:16293 const base::DictionaryValue* forced_list_pref =
294 static_cast<const base::DictionaryValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28295 pref_names::kInstallForceList, true, base::Value::Type::DICTIONARY));
achuith4607f072017-03-08 11:49:13296 const base::DictionaryValue* login_screen_app_list_pref = nullptr;
297 if (is_signin_profile_) {
298 login_screen_app_list_pref = static_cast<const base::DictionaryValue*>(
299 LoadPreference(pref_names::kInstallLoginScreenAppList, true,
300 base::Value::Type::DICTIONARY));
301 }
binjin5f405ef2014-09-03 21:23:16302 const base::ListValue* install_sources_pref =
303 static_cast<const base::ListValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28304 pref_names::kAllowedInstallSites, true, base::Value::Type::LIST));
binjin5f405ef2014-09-03 21:23:16305 const base::ListValue* allowed_types_pref =
306 static_cast<const base::ListValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28307 pref_names::kAllowedTypes, true, base::Value::Type::LIST));
binjinb2454382014-09-22 15:17:43308 const base::DictionaryValue* dict_pref =
309 static_cast<const base::DictionaryValue*>(
310 LoadPreference(pref_names::kExtensionManagement,
311 true,
jdoerriedc72ee942016-12-07 15:43:28312 base::Value::Type::DICTIONARY));
binjin5f405ef2014-09-03 21:23:16313
314 // Reset all settings.
binjin81d7c552014-10-02 11:47:12315 global_settings_.reset(new internal::GlobalSettings());
binjin5f405ef2014-09-03 21:23:16316 settings_by_id_.clear();
binjin81d7c552014-10-02 11:47:12317 default_settings_.reset(new internal::IndividualSettings());
binjin5f405ef2014-09-03 21:23:16318
319 // Parse default settings.
jdoerrie122c4da2017-03-06 11:12:04320 const base::Value wildcard("*");
binjin5f405ef2014-09-03 21:23:16321 if (denied_list_pref &&
322 denied_list_pref->Find(wildcard) != denied_list_pref->end()) {
binjin81d7c552014-10-02 11:47:12323 default_settings_->installation_mode = INSTALLATION_BLOCKED;
binjin5f405ef2014-09-03 21:23:16324 }
325
binjinb2454382014-09-22 15:17:43326 const base::DictionaryValue* subdict = NULL;
327 if (dict_pref &&
328 dict_pref->GetDictionary(schema_constants::kWildcard, &subdict)) {
binjin81d7c552014-10-02 11:47:12329 if (!default_settings_->Parse(
330 subdict, internal::IndividualSettings::SCOPE_DEFAULT)) {
binjinb2454382014-09-22 15:17:43331 LOG(WARNING) << "Default extension management settings parsing error.";
binjin81d7c552014-10-02 11:47:12332 default_settings_->Reset();
binjinb2454382014-09-22 15:17:43333 }
334
335 // Settings from new preference have higher priority over legacy ones.
336 const base::ListValue* list_value = NULL;
337 if (subdict->GetList(schema_constants::kInstallSources, &list_value))
338 install_sources_pref = list_value;
339 if (subdict->GetList(schema_constants::kAllowedTypes, &list_value))
340 allowed_types_pref = list_value;
341 }
342
binjin5f405ef2014-09-03 21:23:16343 // Parse legacy preferences.
344 ExtensionId id;
345
346 if (allowed_list_pref) {
347 for (base::ListValue::const_iterator it = allowed_list_pref->begin();
348 it != allowed_list_pref->end(); ++it) {
jdoerriea5676c62017-04-11 18:09:14349 if (it->GetAsString(&id) && crx_file::id_util::IdIsValid(id))
binjin5f405ef2014-09-03 21:23:16350 AccessById(id)->installation_mode = INSTALLATION_ALLOWED;
351 }
352 }
353
354 if (denied_list_pref) {
355 for (base::ListValue::const_iterator it = denied_list_pref->begin();
356 it != denied_list_pref->end(); ++it) {
jdoerriea5676c62017-04-11 18:09:14357 if (it->GetAsString(&id) && crx_file::id_util::IdIsValid(id))
binjin5f405ef2014-09-03 21:23:16358 AccessById(id)->installation_mode = INSTALLATION_BLOCKED;
359 }
360 }
361
achuith4607f072017-03-08 11:49:13362 UpdateForcedExtensions(forced_list_pref);
363 UpdateForcedExtensions(login_screen_app_list_pref);
binjin5f405ef2014-09-03 21:23:16364
365 if (install_sources_pref) {
binjin81d7c552014-10-02 11:47:12366 global_settings_->has_restricted_install_sources = true;
binjin5f405ef2014-09-03 21:23:16367 for (base::ListValue::const_iterator it = install_sources_pref->begin();
368 it != install_sources_pref->end(); ++it) {
binjinb2454382014-09-22 15:17:43369 std::string url_pattern;
jdoerriea5676c62017-04-11 18:09:14370 if (it->GetAsString(&url_pattern)) {
binjinb2454382014-09-22 15:17:43371 URLPattern entry(URLPattern::SCHEME_ALL);
binjin5f405ef2014-09-03 21:23:16372 if (entry.Parse(url_pattern) == URLPattern::PARSE_SUCCESS) {
binjin81d7c552014-10-02 11:47:12373 global_settings_->install_sources.AddPattern(entry);
binjin5f405ef2014-09-03 21:23:16374 } else {
375 LOG(WARNING) << "Invalid URL pattern in for preference "
376 << pref_names::kAllowedInstallSites << ": "
377 << url_pattern << ".";
378 }
379 }
380 }
381 }
382
383 if (allowed_types_pref) {
binjin81d7c552014-10-02 11:47:12384 global_settings_->has_restricted_allowed_types = true;
binjin5f405ef2014-09-03 21:23:16385 for (base::ListValue::const_iterator it = allowed_types_pref->begin();
386 it != allowed_types_pref->end(); ++it) {
387 int int_value;
binjinb2454382014-09-22 15:17:43388 std::string string_value;
jdoerriea5676c62017-04-11 18:09:14389 if (it->GetAsInteger(&int_value) && int_value >= 0 &&
binjin5f405ef2014-09-03 21:23:16390 int_value < Manifest::Type::NUM_LOAD_TYPES) {
binjin81d7c552014-10-02 11:47:12391 global_settings_->allowed_types.push_back(
binjin5f405ef2014-09-03 21:23:16392 static_cast<Manifest::Type>(int_value));
jdoerriea5676c62017-04-11 18:09:14393 } else if (it->GetAsString(&string_value)) {
binjinb2454382014-09-22 15:17:43394 Manifest::Type manifest_type =
395 schema_constants::GetManifestType(string_value);
396 if (manifest_type != Manifest::TYPE_UNKNOWN)
binjin81d7c552014-10-02 11:47:12397 global_settings_->allowed_types.push_back(manifest_type);
binjin5f405ef2014-09-03 21:23:16398 }
399 }
400 }
401
binjinb2454382014-09-22 15:17:43402 if (dict_pref) {
403 // Parse new extension management preference.
404 for (base::DictionaryValue::Iterator iter(*dict_pref); !iter.IsAtEnd();
405 iter.Advance()) {
406 if (iter.key() == schema_constants::kWildcard)
407 continue;
binjin81d7c552014-10-02 11:47:12408 if (!iter.value().GetAsDictionary(&subdict))
binjinb2454382014-09-22 15:17:43409 continue;
brettw66d1b81b2015-07-06 19:29:40410 if (base::StartsWith(iter.key(), schema_constants::kUpdateUrlPrefix,
411 base::CompareCase::SENSITIVE)) {
binjin685ade82014-11-06 09:53:56412 const std::string& update_url =
413 iter.key().substr(strlen(schema_constants::kUpdateUrlPrefix));
414 if (!GURL(update_url).is_valid()) {
415 LOG(WARNING) << "Invalid update URL: " << update_url << ".";
416 continue;
417 }
418 internal::IndividualSettings* by_update_url =
419 AccessByUpdateUrl(update_url);
420 if (!by_update_url->Parse(
421 subdict, internal::IndividualSettings::SCOPE_UPDATE_URL)) {
422 settings_by_update_url_.erase(update_url);
423 LOG(WARNING) << "Malformed Extension Management settings for "
424 "extensions with update url: " << update_url << ".";
425 }
426 } else {
427 const std::string& extension_id = iter.key();
428 if (!crx_file::id_util::IdIsValid(extension_id)) {
429 LOG(WARNING) << "Invalid extension ID : " << extension_id << ".";
430 continue;
431 }
432 internal::IndividualSettings* by_id = AccessById(extension_id);
433 if (!by_id->Parse(subdict,
434 internal::IndividualSettings::SCOPE_INDIVIDUAL)) {
435 settings_by_id_.erase(extension_id);
436 LOG(WARNING) << "Malformed Extension Management settings for "
437 << extension_id << ".";
438 }
binjinb2454382014-09-22 15:17:43439 }
440 }
441 }
binjin5f405ef2014-09-03 21:23:16442}
443
binjin5f405ef2014-09-03 21:23:16444const base::Value* ExtensionManagement::LoadPreference(
445 const char* pref_name,
446 bool force_managed,
447 base::Value::Type expected_type) {
binjine6b58b52014-10-31 01:55:57448 if (!pref_service_)
449 return nullptr;
binjin5f405ef2014-09-03 21:23:16450 const PrefService::Preference* pref =
451 pref_service_->FindPreference(pref_name);
452 if (pref && !pref->IsDefaultValue() &&
453 (!force_managed || pref->IsManaged())) {
454 const base::Value* value = pref->GetValue();
455 if (value && value->IsType(expected_type))
456 return value;
457 }
binjine6b58b52014-10-31 01:55:57458 return nullptr;
binjin5f405ef2014-09-03 21:23:16459}
460
binjin1569c9b2014-09-05 13:33:18461void ExtensionManagement::OnExtensionPrefChanged() {
462 Refresh();
463 NotifyExtensionManagementPrefChanged();
464}
465
466void ExtensionManagement::NotifyExtensionManagementPrefChanged() {
ericwilligersb5f79de2016-10-19 04:15:10467 for (auto& observer : observer_list_)
468 observer.OnExtensionManagementSettingsChanged();
binjin1569c9b2014-09-05 13:33:18469}
470
achuith4607f072017-03-08 11:49:13471std::unique_ptr<base::DictionaryValue>
472ExtensionManagement::GetInstallListByMode(
473 InstallationMode installation_mode) const {
474 auto extension_dict = base::MakeUnique<base::DictionaryValue>();
475 for (const auto& entry : settings_by_id_) {
476 if (entry.second->installation_mode == installation_mode) {
477 ExternalPolicyLoader::AddExtension(extension_dict.get(), entry.first,
478 entry.second->update_url);
479 }
480 }
481 return extension_dict;
482}
483
484void ExtensionManagement::UpdateForcedExtensions(
485 const base::DictionaryValue* extension_dict) {
486 if (!extension_dict)
487 return;
488
489 std::string update_url;
490 for (base::DictionaryValue::Iterator it(*extension_dict); !it.IsAtEnd();
491 it.Advance()) {
492 if (!crx_file::id_util::IdIsValid(it.key()))
493 continue;
494 const base::DictionaryValue* dict_value = nullptr;
495 if (it.value().GetAsDictionary(&dict_value) &&
496 dict_value->GetStringWithoutPathExpansion(
497 ExternalProviderImpl::kExternalUpdateUrl, &update_url)) {
498 internal::IndividualSettings* by_id = AccessById(it.key());
499 by_id->installation_mode = INSTALLATION_FORCED;
500 by_id->update_url = update_url;
501 }
502 }
503}
504
binjin81d7c552014-10-02 11:47:12505internal::IndividualSettings* ExtensionManagement::AccessById(
binjin5f405ef2014-09-03 21:23:16506 const ExtensionId& id) {
507 DCHECK(crx_file::id_util::IdIsValid(id)) << "Invalid ID: " << id;
avi3ec9c0d2016-12-27 22:38:06508 std::unique_ptr<internal::IndividualSettings>& settings = settings_by_id_[id];
509 if (!settings) {
510 settings =
511 base::MakeUnique<internal::IndividualSettings>(default_settings_.get());
binjin81d7c552014-10-02 11:47:12512 }
avi3ec9c0d2016-12-27 22:38:06513 return settings.get();
binjin5f405ef2014-09-03 21:23:16514}
515
binjin685ade82014-11-06 09:53:56516internal::IndividualSettings* ExtensionManagement::AccessByUpdateUrl(
517 const std::string& update_url) {
518 DCHECK(GURL(update_url).is_valid()) << "Invalid update URL: " << update_url;
avi3ec9c0d2016-12-27 22:38:06519 std::unique_ptr<internal::IndividualSettings>& settings =
520 settings_by_update_url_[update_url];
521 if (!settings) {
522 settings =
523 base::MakeUnique<internal::IndividualSettings>(default_settings_.get());
binjin685ade82014-11-06 09:53:56524 }
avi3ec9c0d2016-12-27 22:38:06525 return settings.get();
binjin685ade82014-11-06 09:53:56526}
527
binjin1569c9b2014-09-05 13:33:18528ExtensionManagement* ExtensionManagementFactory::GetForBrowserContext(
529 content::BrowserContext* context) {
530 return static_cast<ExtensionManagement*>(
531 GetInstance()->GetServiceForBrowserContext(context, true));
532}
533
534ExtensionManagementFactory* ExtensionManagementFactory::GetInstance() {
olli.raula36aa8be2015-09-10 11:14:22535 return base::Singleton<ExtensionManagementFactory>::get();
binjin1569c9b2014-09-05 13:33:18536}
537
538ExtensionManagementFactory::ExtensionManagementFactory()
539 : BrowserContextKeyedServiceFactory(
540 "ExtensionManagement",
541 BrowserContextDependencyManager::GetInstance()) {
542}
543
544ExtensionManagementFactory::~ExtensionManagementFactory() {
545}
546
547KeyedService* ExtensionManagementFactory::BuildServiceInstanceFor(
548 content::BrowserContext* context) const {
rkaplowdd66a1342015-03-05 00:31:49549 TRACE_EVENT0("browser,startup",
550 "ExtensionManagementFactory::BuildServiceInstanceFor");
achuith4607f072017-03-08 11:49:13551 Profile* profile = Profile::FromBrowserContext(context);
552 bool is_signin_profile = false;
553#if defined(OS_CHROMEOS)
554 is_signin_profile = chromeos::ProfileHelper::IsSigninProfile(profile);
555#endif
556 return new ExtensionManagement(profile->GetPrefs(), is_signin_profile);
binjin1569c9b2014-09-05 13:33:18557}
558
binjin9733df12014-09-08 15:21:21559content::BrowserContext* ExtensionManagementFactory::GetBrowserContextToUse(
560 content::BrowserContext* context) const {
561 return chrome::GetBrowserContextRedirectedInIncognito(context);
562}
563
binjinb2454382014-09-22 15:17:43564void ExtensionManagementFactory::RegisterProfilePrefs(
565 user_prefs::PrefRegistrySyncable* user_prefs) {
raymesaa608722015-04-27 03:00:25566 user_prefs->RegisterDictionaryPref(pref_names::kExtensionManagement);
binjinb2454382014-09-22 15:17:43567}
568
binjin5f405ef2014-09-03 21:23:16569} // namespace extensions