blob: 2d5caa162512eb1549d7ce50a3e5f27355b196ad [file] [log] [blame]
[email protected]cce15bb2014-06-17 13:43:511// Copyright 2014 The Chromium Authors. All rights reserved.
[email protected]0850e842013-01-19 03:44:312// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4
[email protected]cce15bb2014-06-17 13:43:515#ifndef CHROME_BROWSER_SUPERVISED_USER_SUPERVISED_USER_SERVICE_H_
6#define CHROME_BROWSER_SUPERVISED_USER_SUPERVISED_USER_SERVICE_H_
[email protected]0850e842013-01-19 03:44:317
treib950c6e82014-09-23 13:07:298#include <map>
[email protected]0d9a1da82013-03-14 21:52:079#include <set>
treib950c6e82014-09-23 13:07:2910#include <string>
[email protected]0850e842013-01-19 03:44:3111#include <vector>
12
[email protected]438f7e12013-08-07 06:59:0013#include "base/callback.h"
[email protected]076ebeda2014-06-06 21:47:2614#include "base/gtest_prod_util.h"
[email protected]a581ea22013-05-06 12:34:1915#include "base/memory/scoped_ptr.h"
[email protected]1ab137b2013-03-21 03:33:1816#include "base/prefs/pref_change_registrar.h"
[email protected]f2253ac2014-05-28 08:37:2117#include "base/scoped_observer.h"
[email protected]f9b294362013-06-10 20:22:3118#include "base/strings/string16.h"
treib4edbded2014-09-05 08:43:5519#include "chrome/browser/supervised_user/experimental/supervised_user_blacklist.h"
[email protected]cce15bb2014-06-17 13:43:5120#include "chrome/browser/supervised_user/supervised_user_url_filter.h"
21#include "chrome/browser/supervised_user/supervised_users.h"
[email protected]a243d644c2013-06-20 18:37:5522#include "chrome/browser/sync/profile_sync_service_observer.h"
[email protected]3a276ff2014-08-12 14:22:0923#include "chrome/browser/sync/sync_type_preference_provider.h"
[email protected]514fcf22013-08-13 06:37:2424#include "chrome/browser/ui/browser_list_observer.h"
[email protected]12b7af32014-03-13 05:28:2025#include "components/keyed_service/core/keyed_service.h"
[email protected]bfd8cf982013-03-04 15:24:0026#include "content/public/browser/web_contents.h"
[email protected]c14a6802014-07-11 21:51:1227
28#if defined(ENABLE_EXTENSIONS)
[email protected]f2253ac2014-05-28 08:37:2129#include "extensions/browser/extension_registry_observer.h"
[email protected]301116c62013-11-26 10:37:4530#include "extensions/browser/management_policy.h"
[email protected]c14a6802014-07-11 21:51:1231#endif
[email protected]0850e842013-01-19 03:44:3132
[email protected]509ad1a92013-03-19 21:41:0633class Browser;
[email protected]acfcfbb2013-05-13 18:01:2734class GoogleServiceAuthError;
[email protected]4db65f952014-05-20 15:46:3035class PermissionRequestCreator;
[email protected]0850e842013-01-19 03:44:3136class Profile;
[email protected]cce15bb2014-06-17 13:43:5137class SupervisedUserRegistrationUtility;
38class SupervisedUserSettingsService;
39class SupervisedUserSiteList;
40class SupervisedUserURLFilter;
[email protected]0850e842013-01-19 03:44:3141
treibdaece84f2014-09-05 12:58:1542namespace base {
43class FilePath;
44}
45
[email protected]f2253ac2014-05-28 08:37:2146namespace extensions {
47class ExtensionRegistry;
48}
49
[email protected]443e9312013-05-06 06:17:3450namespace user_prefs {
51class PrefRegistrySyncable;
52}
53
[email protected]cce15bb2014-06-17 13:43:5154// This class handles all the information related to a given supervised profile
[email protected]0850e842013-01-19 03:44:3155// (e.g. the installed content packs, the default URL filtering behavior, or
56// manual whitelist/blacklist overrides).
[email protected]cce15bb2014-06-17 13:43:5157class SupervisedUserService : public KeyedService,
[email protected]c14a6802014-07-11 21:51:1258#if defined(ENABLE_EXTENSIONS)
[email protected]cce15bb2014-06-17 13:43:5159 public extensions::ManagementPolicy::Provider,
[email protected]cce15bb2014-06-17 13:43:5160 public extensions::ExtensionRegistryObserver,
[email protected]c14a6802014-07-11 21:51:1261#endif
[email protected]3a276ff2014-08-12 14:22:0962 public SyncTypePreferenceProvider,
[email protected]c14a6802014-07-11 21:51:1263 public ProfileSyncServiceObserver,
[email protected]cce15bb2014-06-17 13:43:5164 public chrome::BrowserListObserver {
[email protected]0850e842013-01-19 03:44:3165 public:
[email protected]d2065e062013-12-12 23:49:5266 typedef std::vector<base::string16> CategoryList;
[email protected]438f7e12013-08-07 06:59:0067 typedef base::Callback<void(content::WebContents*)> NavigationBlockedCallback;
[email protected]514fcf22013-08-13 06:37:2468 typedef base::Callback<void(const GoogleServiceAuthError&)> AuthErrorCallback;
[email protected]0850e842013-01-19 03:44:3169
[email protected]5e022292013-02-06 16:42:1770 enum ManualBehavior {
71 MANUAL_NONE = 0,
72 MANUAL_ALLOW,
73 MANUAL_BLOCK
74 };
75
[email protected]f085fdd52014-06-11 18:09:2076 class Delegate {
77 public:
78 virtual ~Delegate() {}
79 // Returns true to indicate that the delegate handled the (de)activation, or
[email protected]cce15bb2014-06-17 13:43:5180 // false to indicate that the SupervisedUserService itself should handle it.
[email protected]f085fdd52014-06-11 18:09:2081 virtual bool SetActive(bool active) = 0;
treibdaece84f2014-09-05 12:58:1582 // Returns the path to a blacklist file to load, or an empty path to
83 // indicate "none".
84 virtual base::FilePath GetBlacklistPath() const = 0;
[email protected]f085fdd52014-06-11 18:09:2085 };
86
[email protected]cce15bb2014-06-17 13:43:5187 virtual ~SupervisedUserService();
[email protected]0850e842013-01-19 03:44:3188
[email protected]a243d644c2013-06-20 18:37:5589 // ProfileKeyedService override:
90 virtual void Shutdown() OVERRIDE;
91
[email protected]37ca3fe02013-07-05 15:32:4492 static void RegisterProfilePrefs(user_prefs::PrefRegistrySyncable* registry);
[email protected]0850e842013-01-19 03:44:3193
[email protected]f085fdd52014-06-11 18:09:2094 void SetDelegate(Delegate* delegate);
95
[email protected]0850e842013-01-19 03:44:3196 // Returns the URL filter for the IO thread, for filtering network requests
[email protected]cce15bb2014-06-17 13:43:5197 // (in SupervisedUserResourceThrottle).
98 scoped_refptr<const SupervisedUserURLFilter> GetURLFilterForIOThread();
[email protected]0850e842013-01-19 03:44:3199
100 // Returns the URL filter for the UI thread, for filtering navigations and
101 // classifying sites in the history view.
[email protected]cce15bb2014-06-17 13:43:51102 SupervisedUserURLFilter* GetURLFilterForUIThread();
[email protected]0850e842013-01-19 03:44:31103
104 // Returns the URL's category, obtained from the installed content packs.
105 int GetCategory(const GURL& url);
106
107 // Returns the list of all known human-readable category names, sorted by ID
108 // number. Called in the critical path of drawing the history UI, so needs to
109 // be fast.
110 void GetCategoryNames(CategoryList* list);
111
[email protected]0369d6ab2013-08-09 01:52:59112 // Whether the user can request access to blocked URLs.
113 bool AccessRequestsEnabled();
114
[email protected]4db65f952014-05-20 15:46:30115 void OnPermissionRequestIssued();
116
[email protected]e861bba2013-06-17 15:20:54117 // Adds an access request for the given URL. The requests are stored using
118 // a prefix followed by a URIEncoded version of the URL. Each entry contains
119 // a dictionary which currently has the timestamp of the request in it.
120 void AddAccessRequest(const GURL& url);
121
[email protected]a9c2d642013-05-31 14:37:14122 // Returns the email address of the custodian.
123 std::string GetCustodianEmailAddress() const;
124
[email protected]fae057a2013-06-21 22:46:08125 // Returns the name of the custodian, or the email address if the name is
126 // empty.
127 std::string GetCustodianName() const;
128
[email protected]5e022292013-02-06 16:42:17129 // These methods allow querying and modifying the manual filtering behavior.
130 // The manual behavior is set by the user and overrides all other settings
131 // (whitelists or the default behavior).
[email protected]0850e842013-01-19 03:44:31132
[email protected]5e022292013-02-06 16:42:17133 // Returns the manual behavior for the given host.
134 ManualBehavior GetManualBehaviorForHost(const std::string& hostname);
[email protected]0850e842013-01-19 03:44:31135
[email protected]5e022292013-02-06 16:42:17136 // Returns the manual behavior for the given URL.
137 ManualBehavior GetManualBehaviorForURL(const GURL& url);
[email protected]0850e842013-01-19 03:44:31138
[email protected]43257902013-03-26 20:59:37139 // Returns all URLS on the given host that have exceptions.
140 void GetManualExceptionsForHost(const std::string& host,
141 std::vector<GURL>* urls);
142
[email protected]0850e842013-01-19 03:44:31143 // Initializes this object. This method does nothing if the profile is not
[email protected]cce15bb2014-06-17 13:43:51144 // supervised.
[email protected]0850e842013-01-19 03:44:31145 void Init();
146
[email protected]a243d644c2013-06-20 18:37:55147 // Initializes this profile for syncing, using the provided |refresh_token| to
148 // mint access tokens for Sync.
149 void InitSync(const std::string& refresh_token);
[email protected]acfcfbb2013-05-13 18:01:27150
[email protected]cce15bb2014-06-17 13:43:51151 // Convenience method that registers this supervised user using
[email protected]458d59442013-08-01 14:19:32152 // |registration_utility| and initializes sync with the returned token.
153 // The |callback| will be called when registration is complete,
[email protected]3a276ff2014-08-12 14:22:09154 // whether it succeeded or not -- unless registration was cancelled manually,
[email protected]458d59442013-08-01 14:19:32155 // in which case the callback will be ignored.
[email protected]cce15bb2014-06-17 13:43:51156 void RegisterAndInitSync(
157 SupervisedUserRegistrationUtility* registration_utility,
158 Profile* custodian_profile,
159 const std::string& supervised_user_id,
160 const AuthErrorCallback& callback);
[email protected]acfcfbb2013-05-13 18:01:27161
[email protected]4f02aac12013-05-20 05:19:06162 void set_elevated_for_testing(bool skip) {
163 elevated_for_testing_ = skip;
[email protected]849749d2013-05-06 17:30:45164 }
165
[email protected]438f7e12013-08-07 06:59:00166 void AddNavigationBlockedCallback(const NavigationBlockedCallback& callback);
167 void DidBlockNavigation(content::WebContents* web_contents);
168
[email protected]c14a6802014-07-11 21:51:12169#if defined(ENABLE_EXTENSIONS)
[email protected]ce019142013-02-12 18:08:10170 // extensions::ManagementPolicy::Provider implementation:
[email protected]0850e842013-01-19 03:44:31171 virtual std::string GetDebugPolicyProviderName() const OVERRIDE;
172 virtual bool UserMayLoad(const extensions::Extension* extension,
[email protected]0085863a2013-12-06 21:19:03173 base::string16* error) const OVERRIDE;
[email protected]0850e842013-01-19 03:44:31174 virtual bool UserMayModifySettings(const extensions::Extension* extension,
[email protected]0085863a2013-12-06 21:19:03175 base::string16* error) const OVERRIDE;
[email protected]0850e842013-01-19 03:44:31176
[email protected]f2253ac2014-05-28 08:37:21177 // extensions::ExtensionRegistryObserver implementation.
178 virtual void OnExtensionLoaded(
179 content::BrowserContext* browser_context,
180 const extensions::Extension* extension) OVERRIDE;
181 virtual void OnExtensionUnloaded(
182 content::BrowserContext* browser_context,
183 const extensions::Extension* extension,
184 extensions::UnloadedExtensionInfo::Reason reason) OVERRIDE;
[email protected]c14a6802014-07-11 21:51:12185#endif
186
[email protected]3a276ff2014-08-12 14:22:09187 // SyncTypePreferenceProvider implementation:
188 virtual syncer::ModelTypeSet GetPreferredDataTypes() const OVERRIDE;
189
[email protected]c14a6802014-07-11 21:51:12190 // ProfileSyncServiceObserver implementation:
191 virtual void OnStateChanged() OVERRIDE;
[email protected]0850e842013-01-19 03:44:31192
[email protected]dfddd022013-07-10 17:29:48193 // chrome::BrowserListObserver implementation:
194 virtual void OnBrowserSetLastActive(Browser* browser) OVERRIDE;
195
[email protected]0850e842013-01-19 03:44:31196 private:
[email protected]cce15bb2014-06-17 13:43:51197 friend class SupervisedUserServiceExtensionTestBase;
198 friend class SupervisedUserServiceFactory;
199 FRIEND_TEST_ALL_PREFIXES(SupervisedUserServiceTest, ClearOmitOnRegistration);
[email protected]0850e842013-01-19 03:44:31200
[email protected]cce15bb2014-06-17 13:43:51201 // A bridge from the UI thread to the SupervisedUserURLFilters, one of which
202 // lives on the IO thread. This class mediates access to them and makes sure
203 // they are kept in sync.
[email protected]0850e842013-01-19 03:44:31204 class URLFilterContext {
205 public:
206 URLFilterContext();
207 ~URLFilterContext();
208
[email protected]cce15bb2014-06-17 13:43:51209 SupervisedUserURLFilter* ui_url_filter() const;
210 SupervisedUserURLFilter* io_url_filter() const;
[email protected]0850e842013-01-19 03:44:31211
212 void SetDefaultFilteringBehavior(
[email protected]cce15bb2014-06-17 13:43:51213 SupervisedUserURLFilter::FilteringBehavior behavior);
214 void LoadWhitelists(ScopedVector<SupervisedUserSiteList> site_lists);
treib4edbded2014-09-05 08:43:55215 void LoadBlacklist(const base::FilePath& path);
[email protected]5e022292013-02-06 16:42:17216 void SetManualHosts(scoped_ptr<std::map<std::string, bool> > host_map);
217 void SetManualURLs(scoped_ptr<std::map<GURL, bool> > url_map);
[email protected]0850e842013-01-19 03:44:31218
219 private:
treib4edbded2014-09-05 08:43:55220 void OnBlacklistLoaded();
221
[email protected]cce15bb2014-06-17 13:43:51222 // SupervisedUserURLFilter is refcounted because the IO thread filter is
223 // used both by ProfileImplIOData and OffTheRecordProfileIOData (to filter
[email protected]0850e842013-01-19 03:44:31224 // network requests), so they both keep a reference to it.
225 // Clients should not keep references to the UI thread filter, however
226 // (the filter will live as long as the profile lives, and afterwards it
227 // should not be used anymore either).
[email protected]cce15bb2014-06-17 13:43:51228 scoped_refptr<SupervisedUserURLFilter> ui_url_filter_;
229 scoped_refptr<SupervisedUserURLFilter> io_url_filter_;
[email protected]0850e842013-01-19 03:44:31230
treib4edbded2014-09-05 08:43:55231 SupervisedUserBlacklist blacklist_;
232
[email protected]0850e842013-01-19 03:44:31233 DISALLOW_COPY_AND_ASSIGN(URLFilterContext);
234 };
235
[email protected]cce15bb2014-06-17 13:43:51236 // Use |SupervisedUserServiceFactory::GetForProfile(..)| to get
[email protected]3bf45d02013-07-10 00:03:41237 // an instance of this service.
[email protected]cce15bb2014-06-17 13:43:51238 explicit SupervisedUserService(Profile* profile);
[email protected]3bf45d02013-07-10 00:03:41239
[email protected]f085fdd52014-06-11 18:09:20240 void SetActive(bool active);
241
[email protected]0085863a2013-12-06 21:19:03242 void OnCustodianProfileDownloaded(const base::string16& full_name);
[email protected]200729f82013-06-22 07:05:55243
[email protected]cce15bb2014-06-17 13:43:51244 void OnSupervisedUserRegistered(const AuthErrorCallback& callback,
245 Profile* custodian_profile,
246 const GoogleServiceAuthError& auth_error,
247 const std::string& token);
[email protected]acfcfbb2013-05-13 18:01:27248
[email protected]a243d644c2013-06-20 18:37:55249 void SetupSync();
[email protected]6e08b9a62014-07-08 00:32:48250 void StartSetupSync();
251 void FinishSetupSyncWhenReady();
252 void FinishSetupSync();
[email protected]a243d644c2013-06-20 18:37:55253
[email protected]cce15bb2014-06-17 13:43:51254 bool ProfileIsSupervised() const;
[email protected]e000daf2013-07-31 16:50:58255
[email protected]c14a6802014-07-11 21:51:12256#if defined(ENABLE_EXTENSIONS)
[email protected]0850e842013-01-19 03:44:31257 // Internal implementation for ExtensionManagementPolicy::Delegate methods.
258 // If |error| is not NULL, it will be filled with an error message if the
259 // requested extension action (install, modify status, etc.) is not permitted.
[email protected]38b7fb92013-07-26 16:32:26260 bool ExtensionManagementPolicyImpl(const extensions::Extension* extension,
[email protected]0085863a2013-12-06 21:19:03261 base::string16* error) const;
[email protected]0850e842013-01-19 03:44:31262
263 // Returns a list of all installed and enabled site lists in the current
[email protected]cce15bb2014-06-17 13:43:51264 // supervised profile.
265 ScopedVector<SupervisedUserSiteList> GetActiveSiteLists();
[email protected]0850e842013-01-19 03:44:31266
[email protected]c14a6802014-07-11 21:51:12267 // Extensions helper to SetActive().
268 void SetExtensionsActive();
269#endif
270
[email protected]cce15bb2014-06-17 13:43:51271 SupervisedUserSettingsService* GetSettingsService();
[email protected]e861bba2013-06-17 15:20:54272
[email protected]cce15bb2014-06-17 13:43:51273 void OnSupervisedUserIdChanged();
[email protected]f085fdd52014-06-11 18:09:20274
[email protected]0850e842013-01-19 03:44:31275 void OnDefaultFilteringBehaviorChanged();
276
277 void UpdateSiteLists();
278
treib4edbded2014-09-05 08:43:55279 // Asynchronously loads a static blacklist from a binary file at |path| and
280 // applies it to the URL filters.
281 void LoadBlacklist(const base::FilePath& path);
282
[email protected]5e022292013-02-06 16:42:17283 // Updates the manual overrides for hosts in the URL filters when the
284 // corresponding preference is changed.
285 void UpdateManualHosts();
[email protected]0850e842013-01-19 03:44:31286
[email protected]5e022292013-02-06 16:42:17287 // Updates the manual overrides for URLs in the URL filters when the
288 // corresponding preference is changed.
289 void UpdateManualURLs();
[email protected]0850e842013-01-19 03:44:31290
[email protected]0b4c6b22014-08-04 09:46:31291 // Returns the human readable name of the supervised user.
292 std::string GetSupervisedUserName() const;
293
[email protected]12b7af32014-03-13 05:28:20294 // Owns us via the KeyedService mechanism.
[email protected]0850e842013-01-19 03:44:31295 Profile* profile_;
296
[email protected]f085fdd52014-06-11 18:09:20297 bool active_;
298
299 Delegate* delegate_;
300
[email protected]c14a6802014-07-11 21:51:12301#if defined(ENABLE_EXTENSIONS)
[email protected]f2253ac2014-05-28 08:37:21302 ScopedObserver<extensions::ExtensionRegistry,
303 extensions::ExtensionRegistryObserver>
304 extension_registry_observer_;
[email protected]c14a6802014-07-11 21:51:12305#endif
[email protected]f2253ac2014-05-28 08:37:21306
[email protected]0850e842013-01-19 03:44:31307 PrefChangeRegistrar pref_change_registrar_;
308
[email protected]a243d644c2013-06-20 18:37:55309 // True iff we're waiting for the Sync service to be initialized.
310 bool waiting_for_sync_initialization_;
[email protected]dfddd022013-07-10 17:29:48311 bool is_profile_active_;
[email protected]a243d644c2013-06-20 18:37:55312
[email protected]438f7e12013-08-07 06:59:00313 std::vector<NavigationBlockedCallback> navigation_blocked_callbacks_;
314
[email protected]4f02aac12013-05-20 05:19:06315 // Sets a profile in elevated state for testing if set to true.
316 bool elevated_for_testing_;
[email protected]849749d2013-05-06 17:30:45317
[email protected]3a276ff2014-08-12 14:22:09318 // True only when |Init()| method has been called.
319 bool did_init_;
320
[email protected]3bf45d02013-07-10 00:03:41321 // True only when |Shutdown()| method has been called.
322 bool did_shutdown_;
323
[email protected]0850e842013-01-19 03:44:31324 URLFilterContext url_filter_context_;
[email protected]8052b242013-11-15 16:40:55325
[email protected]4db65f952014-05-20 15:46:30326 // Used to create permission requests.
327 scoped_ptr<PermissionRequestCreator> permissions_creator_;
328
[email protected]cce15bb2014-06-17 13:43:51329 base::WeakPtrFactory<SupervisedUserService> weak_ptr_factory_;
[email protected]0850e842013-01-19 03:44:31330};
331
[email protected]cce15bb2014-06-17 13:43:51332#endif // CHROME_BROWSER_SUPERVISED_USER_SUPERVISED_USER_SERVICE_H_