blob: bc6fe02652cd98591180d3e3e5d794941abfb615 [file] [log] [blame]
binjin5f405ef2014-09-03 21:23:161// Copyright 2014 The Chromium Authors. All rights reserved.
2// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4
5#include "chrome/browser/extensions/extension_management.h"
6
dcheng1fc00f12015-12-26 22:18:037#include <utility>
binjin81d7c552014-10-02 11:47:128
binjin1569c9b2014-09-05 13:33:189#include "base/bind.h"
10#include "base/bind_helpers.h"
binjin5f405ef2014-09-03 21:23:1611#include "base/logging.h"
rkaplowdd66a1342015-03-05 00:31:4912#include "base/metrics/histogram_macros.h"
tripta.g0ac673a2017-07-07 05:45:0913#include "base/stl_util.h"
binjine6b58b52014-10-31 01:55:5714#include "base/strings/string16.h"
binjinb2454382014-09-22 15:17:4315#include "base/strings/string_util.h"
rkaplowdd66a1342015-03-05 00:31:4916#include "base/trace_event/trace_event.h"
binjin8e3d0182014-12-04 16:44:2817#include "base/version.h"
binjinb2454382014-09-22 15:17:4318#include "chrome/browser/extensions/extension_management_constants.h"
binjin81d7c552014-10-02 11:47:1219#include "chrome/browser/extensions/extension_management_internal.h"
binjin30301062014-09-08 20:27:3420#include "chrome/browser/extensions/external_policy_loader.h"
binjin5f405ef2014-09-03 21:23:1621#include "chrome/browser/extensions/external_provider_impl.h"
binjine6b58b52014-10-31 01:55:5722#include "chrome/browser/extensions/permissions_based_management_policy_provider.h"
binjin1569c9b2014-09-05 13:33:1823#include "chrome/browser/extensions/standard_management_policy_provider.h"
binjin9733df12014-09-08 15:21:2124#include "chrome/browser/profiles/incognito_helpers.h"
binjin1569c9b2014-09-05 13:33:1825#include "chrome/browser/profiles/profile.h"
binjin5f405ef2014-09-03 21:23:1626#include "components/crx_file/id_util.h"
binjin1569c9b2014-09-05 13:33:1827#include "components/keyed_service/content/browser_context_dependency_manager.h"
binjinb2454382014-09-22 15:17:4328#include "components/pref_registry/pref_registry_syncable.h"
brettwb1fc1b82016-02-02 00:19:0829#include "components/prefs/pref_service.h"
binjin5f405ef2014-09-03 21:23:1630#include "extensions/browser/pref_names.h"
rdevlin.cronin0670b562016-07-02 02:05:4331#include "extensions/common/extension.h"
binjin685ade82014-11-06 09:53:5632#include "extensions/common/manifest_constants.h"
binjine6b58b52014-10-31 01:55:5733#include "extensions/common/permissions/api_permission_set.h"
34#include "extensions/common/permissions/permission_set.h"
binjin5f405ef2014-09-03 21:23:1635#include "extensions/common/url_pattern.h"
binjin311ecdf2014-09-12 22:56:5236#include "url/gurl.h"
binjin5f405ef2014-09-03 21:23:1637
achuith4607f072017-03-08 11:49:1338#if defined(OS_CHROMEOS)
39#include "chrome/browser/chromeos/profiles/profile_helper.h"
40#endif
41
binjin5f405ef2014-09-03 21:23:1642namespace extensions {
43
achuith4607f072017-03-08 11:49:1344ExtensionManagement::ExtensionManagement(PrefService* pref_service,
45 bool is_signin_profile)
46 : pref_service_(pref_service), is_signin_profile_(is_signin_profile) {
rkaplowdd66a1342015-03-05 00:31:4947 TRACE_EVENT0("browser,startup",
48 "ExtensionManagement::ExtensionManagement::ctor");
binjin1569c9b2014-09-05 13:33:1849 pref_change_registrar_.Init(pref_service_);
50 base::Closure pref_change_callback = base::Bind(
51 &ExtensionManagement::OnExtensionPrefChanged, base::Unretained(this));
52 pref_change_registrar_.Add(pref_names::kInstallAllowList,
53 pref_change_callback);
54 pref_change_registrar_.Add(pref_names::kInstallDenyList,
55 pref_change_callback);
56 pref_change_registrar_.Add(pref_names::kInstallForceList,
57 pref_change_callback);
achuith4607f072017-03-08 11:49:1358 pref_change_registrar_.Add(pref_names::kInstallLoginScreenAppList,
59 pref_change_callback);
binjin1569c9b2014-09-05 13:33:1860 pref_change_registrar_.Add(pref_names::kAllowedInstallSites,
61 pref_change_callback);
62 pref_change_registrar_.Add(pref_names::kAllowedTypes, pref_change_callback);
binjinb2454382014-09-22 15:17:4363 pref_change_registrar_.Add(pref_names::kExtensionManagement,
64 pref_change_callback);
binjin81d7c552014-10-02 11:47:1265 // Note that both |global_settings_| and |default_settings_| will be null
66 // before first call to Refresh(), so in order to resolve this, Refresh() must
67 // be called in the initialization of ExtensionManagement.
binjin1569c9b2014-09-05 13:33:1868 Refresh();
lazyboy4aeef202016-09-07 21:28:5969 providers_.push_back(
Jinho Bangb5216cec2018-01-17 19:43:1170 std::make_unique<StandardManagementPolicyProvider>(this));
lazyboy4aeef202016-09-07 21:28:5971 providers_.push_back(
Jinho Bangb5216cec2018-01-17 19:43:1172 std::make_unique<PermissionsBasedManagementPolicyProvider>(this));
binjin5f405ef2014-09-03 21:23:1673}
74
75ExtensionManagement::~ExtensionManagement() {
76}
77
binjine6b58b52014-10-31 01:55:5778void ExtensionManagement::Shutdown() {
79 pref_change_registrar_.RemoveAll();
80 pref_service_ = nullptr;
81}
82
binjin1569c9b2014-09-05 13:33:1883void ExtensionManagement::AddObserver(Observer* observer) {
84 observer_list_.AddObserver(observer);
85}
86
87void ExtensionManagement::RemoveObserver(Observer* observer) {
88 observer_list_.RemoveObserver(observer);
89}
90
lazyboy4aeef202016-09-07 21:28:5991const std::vector<std::unique_ptr<ManagementPolicy::Provider>>&
92ExtensionManagement::GetProviders() const {
93 return providers_;
binjin1569c9b2014-09-05 13:33:1894}
95
binjin81d7c552014-10-02 11:47:1296bool ExtensionManagement::BlacklistedByDefault() const {
97 return default_settings_->installation_mode == INSTALLATION_BLOCKED;
98}
99
100ExtensionManagement::InstallationMode ExtensionManagement::GetInstallationMode(
binjin685ade82014-11-06 09:53:56101 const Extension* extension) const {
102 // Check per-extension installation mode setting first.
103 auto iter_id = settings_by_id_.find(extension->id());
104 if (iter_id != settings_by_id_.end())
105 return iter_id->second->installation_mode;
106 std::string update_url;
107 // Check per-update-url installation mode setting.
108 if (extension->manifest()->GetString(manifest_keys::kUpdateURL,
109 &update_url)) {
110 auto iter_update_url = settings_by_update_url_.find(update_url);
111 if (iter_update_url != settings_by_update_url_.end())
112 return iter_update_url->second->installation_mode;
113 }
114 // Fall back to default installation mode setting.
115 return default_settings_->installation_mode;
binjin1569c9b2014-09-05 13:33:18116}
117
dchengc963c7142016-04-08 03:55:22118std::unique_ptr<base::DictionaryValue>
hashimoto146e05a2016-11-18 07:42:53119ExtensionManagement::GetForceInstallList() const {
achuith4607f072017-03-08 11:49:13120 return GetInstallListByMode(INSTALLATION_FORCED);
binjincccacef2014-10-13 19:00:20121}
122
dchengc963c7142016-04-08 03:55:22123std::unique_ptr<base::DictionaryValue>
binjincccacef2014-10-13 19:00:20124ExtensionManagement::GetRecommendedInstallList() const {
achuith4607f072017-03-08 11:49:13125 return GetInstallListByMode(INSTALLATION_RECOMMENDED);
binjin30301062014-09-08 20:27:34126}
127
binjinc641add2014-10-15 16:20:45128bool ExtensionManagement::IsInstallationExplicitlyAllowed(
129 const ExtensionId& id) const {
avi3ec9c0d2016-12-27 22:38:06130 auto it = settings_by_id_.find(id);
binjinc641add2014-10-15 16:20:45131 // No settings explicitly specified for |id|.
132 if (it == settings_by_id_.end())
133 return false;
134 // Checks if the extension is on the automatically installed list or
135 // install white-list.
136 InstallationMode mode = it->second->installation_mode;
137 return mode == INSTALLATION_FORCED || mode == INSTALLATION_RECOMMENDED ||
138 mode == INSTALLATION_ALLOWED;
binjin30301062014-09-08 20:27:34139}
140
binjin81d7c552014-10-02 11:47:12141bool ExtensionManagement::IsOffstoreInstallAllowed(
142 const GURL& url,
143 const GURL& referrer_url) const {
binjin311ecdf2014-09-12 22:56:52144 // No allowed install sites specified, disallow by default.
binjin81d7c552014-10-02 11:47:12145 if (!global_settings_->has_restricted_install_sources)
binjin311ecdf2014-09-12 22:56:52146 return false;
147
binjin81d7c552014-10-02 11:47:12148 const URLPatternSet& url_patterns = global_settings_->install_sources;
binjin311ecdf2014-09-12 22:56:52149
150 if (!url_patterns.MatchesURL(url))
151 return false;
152
153 // The referrer URL must also be whitelisted, unless the URL has the file
154 // scheme (there's no referrer for those URLs).
155 return url.SchemeIsFile() || url_patterns.MatchesURL(referrer_url);
156}
157
binjin81d7c552014-10-02 11:47:12158bool ExtensionManagement::IsAllowedManifestType(
159 Manifest::Type manifest_type) const {
160 if (!global_settings_->has_restricted_allowed_types)
161 return true;
162 const std::vector<Manifest::Type>& allowed_types =
163 global_settings_->allowed_types;
tripta.g0ac673a2017-07-07 05:45:09164 return base::ContainsValue(allowed_types, manifest_type);
binjin1569c9b2014-09-05 13:33:18165}
166
binjin685ade82014-11-06 09:53:56167APIPermissionSet ExtensionManagement::GetBlockedAPIPermissions(
168 const Extension* extension) const {
169 // Fetch per-extension blocked permissions setting.
170 auto iter_id = settings_by_id_.find(extension->id());
171
172 // Fetch per-update-url blocked permissions setting.
173 std::string update_url;
174 auto iter_update_url = settings_by_update_url_.end();
175 if (extension->manifest()->GetString(manifest_keys::kUpdateURL,
176 &update_url)) {
177 iter_update_url = settings_by_update_url_.find(update_url);
178 }
179
180 if (iter_id != settings_by_id_.end() &&
181 iter_update_url != settings_by_update_url_.end()) {
182 // Blocked permissions setting are specified in both per-extension and
183 // per-update-url settings, try to merge them.
184 APIPermissionSet merged;
185 APIPermissionSet::Union(iter_id->second->blocked_permissions,
186 iter_update_url->second->blocked_permissions,
187 &merged);
188 return merged;
189 }
190 // Check whether if in one of them, setting is specified.
191 if (iter_id != settings_by_id_.end())
192 return iter_id->second->blocked_permissions;
193 if (iter_update_url != settings_by_update_url_.end())
194 return iter_update_url->second->blocked_permissions;
195 // Fall back to the default blocked permissions setting.
196 return default_settings_->blocked_permissions;
binjine6b58b52014-10-31 01:55:57197}
198
nrpetere33d2a5b2017-04-25 00:12:31199const URLPatternSet& ExtensionManagement::GetDefaultRuntimeBlockedHosts()
200 const {
201 return default_settings_->runtime_blocked_hosts;
202}
203
204const URLPatternSet& ExtensionManagement::GetDefaultRuntimeAllowedHosts()
205 const {
206 return default_settings_->runtime_allowed_hosts;
207}
208
nrpeter40e16382017-04-13 17:34:58209const URLPatternSet& ExtensionManagement::GetRuntimeBlockedHosts(
210 const Extension* extension) const {
211 auto iter_id = settings_by_id_.find(extension->id());
212 if (iter_id != settings_by_id_.end())
213 return iter_id->second->runtime_blocked_hosts;
214 return default_settings_->runtime_blocked_hosts;
215}
216
217const URLPatternSet& ExtensionManagement::GetRuntimeAllowedHosts(
218 const Extension* extension) const {
219 auto iter_id = settings_by_id_.find(extension->id());
220 if (iter_id != settings_by_id_.end())
221 return iter_id->second->runtime_allowed_hosts;
222 return default_settings_->runtime_allowed_hosts;
223}
224
nrpetere33d2a5b2017-04-25 00:12:31225bool ExtensionManagement::UsesDefaultRuntimeHostRestrictions(
226 const Extension* extension) const {
227 return settings_by_id_.find(extension->id()) == settings_by_id_.end();
228}
229
230bool ExtensionManagement::IsRuntimeBlockedHost(const Extension* extension,
231 const GURL& url) const {
nrpeter40e16382017-04-13 17:34:58232 auto iter_id = settings_by_id_.find(extension->id());
233 if (iter_id != settings_by_id_.end())
234 return iter_id->second->runtime_blocked_hosts.MatchesURL(url);
235 return default_settings_->runtime_blocked_hosts.MatchesURL(url);
236}
237
dchengc963c7142016-04-08 03:55:22238std::unique_ptr<const PermissionSet> ExtensionManagement::GetBlockedPermissions(
binjin685ade82014-11-06 09:53:56239 const Extension* extension) const {
binjine6b58b52014-10-31 01:55:57240 // Only api permissions are supported currently.
dchengc963c7142016-04-08 03:55:22241 return std::unique_ptr<const PermissionSet>(new PermissionSet(
binjin685ade82014-11-06 09:53:56242 GetBlockedAPIPermissions(extension), ManifestPermissionSet(),
243 URLPatternSet(), URLPatternSet()));
binjine6b58b52014-10-31 01:55:57244}
245
246bool ExtensionManagement::IsPermissionSetAllowed(
binjin685ade82014-11-06 09:53:56247 const Extension* extension,
rdevlin.cronine2d0fd02015-09-24 22:35:49248 const PermissionSet& perms) const {
vmpstrae72b082016-07-25 21:55:47249 for (auto* blocked_api : GetBlockedAPIPermissions(extension)) {
rdevlin.cronine2d0fd02015-09-24 22:35:49250 if (perms.HasAPIPermission(blocked_api->id()))
binjine6b58b52014-10-31 01:55:57251 return false;
252 }
253 return true;
254}
255
nrpeter2362e7e2017-05-10 17:21:26256const std::string ExtensionManagement::BlockedInstallMessage(
257 const ExtensionId& id) const {
258 auto iter_id = settings_by_id_.find(id);
259 if (iter_id != settings_by_id_.end())
260 return iter_id->second->blocked_install_message;
261 return default_settings_->blocked_install_message;
262}
263
binjin8e3d0182014-12-04 16:44:28264bool ExtensionManagement::CheckMinimumVersion(
265 const Extension* extension,
266 std::string* required_version) const {
267 auto iter = settings_by_id_.find(extension->id());
268 // If there are no minimum version required for |extension|, return true.
269 if (iter == settings_by_id_.end() || !iter->second->minimum_version_required)
270 return true;
Devlin Cronin03bf2d22017-12-20 08:21:05271 bool meets_requirement = extension->version().CompareTo(
272 *iter->second->minimum_version_required) >= 0;
binjin8e3d0182014-12-04 16:44:28273 // Output a human readable version string for prompting if necessary.
274 if (!meets_requirement && required_version)
275 *required_version = iter->second->minimum_version_required->GetString();
276 return meets_requirement;
277}
278
binjin5f405ef2014-09-03 21:23:16279void ExtensionManagement::Refresh() {
rkaplowdd66a1342015-03-05 00:31:49280 TRACE_EVENT0("browser,startup", "ExtensionManagement::Refresh");
281 SCOPED_UMA_HISTOGRAM_TIMER("Extensions.ExtensionManagement_RefreshTime");
binjin5f405ef2014-09-03 21:23:16282 // Load all extension management settings preferences.
283 const base::ListValue* allowed_list_pref =
284 static_cast<const base::ListValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28285 pref_names::kInstallAllowList, true, base::Value::Type::LIST));
binjin5f405ef2014-09-03 21:23:16286 // Allow user to use preference to block certain extensions. Note that policy
287 // managed forcelist or whitelist will always override this.
288 const base::ListValue* denied_list_pref =
289 static_cast<const base::ListValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28290 pref_names::kInstallDenyList, false, base::Value::Type::LIST));
binjin5f405ef2014-09-03 21:23:16291 const base::DictionaryValue* forced_list_pref =
292 static_cast<const base::DictionaryValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28293 pref_names::kInstallForceList, true, base::Value::Type::DICTIONARY));
achuith4607f072017-03-08 11:49:13294 const base::DictionaryValue* login_screen_app_list_pref = nullptr;
295 if (is_signin_profile_) {
296 login_screen_app_list_pref = static_cast<const base::DictionaryValue*>(
297 LoadPreference(pref_names::kInstallLoginScreenAppList, true,
298 base::Value::Type::DICTIONARY));
299 }
binjin5f405ef2014-09-03 21:23:16300 const base::ListValue* install_sources_pref =
301 static_cast<const base::ListValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28302 pref_names::kAllowedInstallSites, true, base::Value::Type::LIST));
binjin5f405ef2014-09-03 21:23:16303 const base::ListValue* allowed_types_pref =
304 static_cast<const base::ListValue*>(LoadPreference(
jdoerriedc72ee942016-12-07 15:43:28305 pref_names::kAllowedTypes, true, base::Value::Type::LIST));
binjinb2454382014-09-22 15:17:43306 const base::DictionaryValue* dict_pref =
307 static_cast<const base::DictionaryValue*>(
308 LoadPreference(pref_names::kExtensionManagement,
309 true,
jdoerriedc72ee942016-12-07 15:43:28310 base::Value::Type::DICTIONARY));
binjin5f405ef2014-09-03 21:23:16311
312 // Reset all settings.
binjin81d7c552014-10-02 11:47:12313 global_settings_.reset(new internal::GlobalSettings());
binjin5f405ef2014-09-03 21:23:16314 settings_by_id_.clear();
binjin81d7c552014-10-02 11:47:12315 default_settings_.reset(new internal::IndividualSettings());
binjin5f405ef2014-09-03 21:23:16316
317 // Parse default settings.
jdoerrie122c4da2017-03-06 11:12:04318 const base::Value wildcard("*");
binjin5f405ef2014-09-03 21:23:16319 if (denied_list_pref &&
320 denied_list_pref->Find(wildcard) != denied_list_pref->end()) {
binjin81d7c552014-10-02 11:47:12321 default_settings_->installation_mode = INSTALLATION_BLOCKED;
binjin5f405ef2014-09-03 21:23:16322 }
323
binjinb2454382014-09-22 15:17:43324 const base::DictionaryValue* subdict = NULL;
325 if (dict_pref &&
326 dict_pref->GetDictionary(schema_constants::kWildcard, &subdict)) {
binjin81d7c552014-10-02 11:47:12327 if (!default_settings_->Parse(
328 subdict, internal::IndividualSettings::SCOPE_DEFAULT)) {
binjinb2454382014-09-22 15:17:43329 LOG(WARNING) << "Default extension management settings parsing error.";
binjin81d7c552014-10-02 11:47:12330 default_settings_->Reset();
binjinb2454382014-09-22 15:17:43331 }
332
333 // Settings from new preference have higher priority over legacy ones.
334 const base::ListValue* list_value = NULL;
335 if (subdict->GetList(schema_constants::kInstallSources, &list_value))
336 install_sources_pref = list_value;
337 if (subdict->GetList(schema_constants::kAllowedTypes, &list_value))
338 allowed_types_pref = list_value;
339 }
340
binjin5f405ef2014-09-03 21:23:16341 // Parse legacy preferences.
342 ExtensionId id;
343
344 if (allowed_list_pref) {
345 for (base::ListValue::const_iterator it = allowed_list_pref->begin();
346 it != allowed_list_pref->end(); ++it) {
jdoerriea5676c62017-04-11 18:09:14347 if (it->GetAsString(&id) && crx_file::id_util::IdIsValid(id))
binjin5f405ef2014-09-03 21:23:16348 AccessById(id)->installation_mode = INSTALLATION_ALLOWED;
349 }
350 }
351
352 if (denied_list_pref) {
353 for (base::ListValue::const_iterator it = denied_list_pref->begin();
354 it != denied_list_pref->end(); ++it) {
jdoerriea5676c62017-04-11 18:09:14355 if (it->GetAsString(&id) && crx_file::id_util::IdIsValid(id))
binjin5f405ef2014-09-03 21:23:16356 AccessById(id)->installation_mode = INSTALLATION_BLOCKED;
357 }
358 }
359
achuith4607f072017-03-08 11:49:13360 UpdateForcedExtensions(forced_list_pref);
361 UpdateForcedExtensions(login_screen_app_list_pref);
binjin5f405ef2014-09-03 21:23:16362
363 if (install_sources_pref) {
binjin81d7c552014-10-02 11:47:12364 global_settings_->has_restricted_install_sources = true;
binjin5f405ef2014-09-03 21:23:16365 for (base::ListValue::const_iterator it = install_sources_pref->begin();
366 it != install_sources_pref->end(); ++it) {
binjinb2454382014-09-22 15:17:43367 std::string url_pattern;
jdoerriea5676c62017-04-11 18:09:14368 if (it->GetAsString(&url_pattern)) {
binjinb2454382014-09-22 15:17:43369 URLPattern entry(URLPattern::SCHEME_ALL);
binjin5f405ef2014-09-03 21:23:16370 if (entry.Parse(url_pattern) == URLPattern::PARSE_SUCCESS) {
binjin81d7c552014-10-02 11:47:12371 global_settings_->install_sources.AddPattern(entry);
binjin5f405ef2014-09-03 21:23:16372 } else {
373 LOG(WARNING) << "Invalid URL pattern in for preference "
374 << pref_names::kAllowedInstallSites << ": "
375 << url_pattern << ".";
376 }
377 }
378 }
379 }
380
381 if (allowed_types_pref) {
binjin81d7c552014-10-02 11:47:12382 global_settings_->has_restricted_allowed_types = true;
binjin5f405ef2014-09-03 21:23:16383 for (base::ListValue::const_iterator it = allowed_types_pref->begin();
384 it != allowed_types_pref->end(); ++it) {
385 int int_value;
binjinb2454382014-09-22 15:17:43386 std::string string_value;
jdoerriea5676c62017-04-11 18:09:14387 if (it->GetAsInteger(&int_value) && int_value >= 0 &&
binjin5f405ef2014-09-03 21:23:16388 int_value < Manifest::Type::NUM_LOAD_TYPES) {
binjin81d7c552014-10-02 11:47:12389 global_settings_->allowed_types.push_back(
binjin5f405ef2014-09-03 21:23:16390 static_cast<Manifest::Type>(int_value));
jdoerriea5676c62017-04-11 18:09:14391 } else if (it->GetAsString(&string_value)) {
binjinb2454382014-09-22 15:17:43392 Manifest::Type manifest_type =
393 schema_constants::GetManifestType(string_value);
394 if (manifest_type != Manifest::TYPE_UNKNOWN)
binjin81d7c552014-10-02 11:47:12395 global_settings_->allowed_types.push_back(manifest_type);
binjin5f405ef2014-09-03 21:23:16396 }
397 }
398 }
399
binjinb2454382014-09-22 15:17:43400 if (dict_pref) {
401 // Parse new extension management preference.
402 for (base::DictionaryValue::Iterator iter(*dict_pref); !iter.IsAtEnd();
403 iter.Advance()) {
404 if (iter.key() == schema_constants::kWildcard)
405 continue;
binjin81d7c552014-10-02 11:47:12406 if (!iter.value().GetAsDictionary(&subdict))
binjinb2454382014-09-22 15:17:43407 continue;
brettw66d1b81b2015-07-06 19:29:40408 if (base::StartsWith(iter.key(), schema_constants::kUpdateUrlPrefix,
409 base::CompareCase::SENSITIVE)) {
binjin685ade82014-11-06 09:53:56410 const std::string& update_url =
411 iter.key().substr(strlen(schema_constants::kUpdateUrlPrefix));
412 if (!GURL(update_url).is_valid()) {
413 LOG(WARNING) << "Invalid update URL: " << update_url << ".";
414 continue;
415 }
416 internal::IndividualSettings* by_update_url =
417 AccessByUpdateUrl(update_url);
418 if (!by_update_url->Parse(
419 subdict, internal::IndividualSettings::SCOPE_UPDATE_URL)) {
420 settings_by_update_url_.erase(update_url);
421 LOG(WARNING) << "Malformed Extension Management settings for "
422 "extensions with update url: " << update_url << ".";
423 }
424 } else {
425 const std::string& extension_id = iter.key();
426 if (!crx_file::id_util::IdIsValid(extension_id)) {
427 LOG(WARNING) << "Invalid extension ID : " << extension_id << ".";
428 continue;
429 }
430 internal::IndividualSettings* by_id = AccessById(extension_id);
431 if (!by_id->Parse(subdict,
432 internal::IndividualSettings::SCOPE_INDIVIDUAL)) {
433 settings_by_id_.erase(extension_id);
434 LOG(WARNING) << "Malformed Extension Management settings for "
435 << extension_id << ".";
436 }
binjinb2454382014-09-22 15:17:43437 }
438 }
439 }
binjin5f405ef2014-09-03 21:23:16440}
441
binjin5f405ef2014-09-03 21:23:16442const base::Value* ExtensionManagement::LoadPreference(
443 const char* pref_name,
444 bool force_managed,
445 base::Value::Type expected_type) {
binjine6b58b52014-10-31 01:55:57446 if (!pref_service_)
447 return nullptr;
binjin5f405ef2014-09-03 21:23:16448 const PrefService::Preference* pref =
449 pref_service_->FindPreference(pref_name);
450 if (pref && !pref->IsDefaultValue() &&
451 (!force_managed || pref->IsManaged())) {
452 const base::Value* value = pref->GetValue();
jdoerrie1f536b22017-10-23 17:15:11453 if (value && value->type() == expected_type)
binjin5f405ef2014-09-03 21:23:16454 return value;
455 }
binjine6b58b52014-10-31 01:55:57456 return nullptr;
binjin5f405ef2014-09-03 21:23:16457}
458
binjin1569c9b2014-09-05 13:33:18459void ExtensionManagement::OnExtensionPrefChanged() {
460 Refresh();
461 NotifyExtensionManagementPrefChanged();
462}
463
464void ExtensionManagement::NotifyExtensionManagementPrefChanged() {
ericwilligersb5f79de2016-10-19 04:15:10465 for (auto& observer : observer_list_)
466 observer.OnExtensionManagementSettingsChanged();
binjin1569c9b2014-09-05 13:33:18467}
468
achuith4607f072017-03-08 11:49:13469std::unique_ptr<base::DictionaryValue>
470ExtensionManagement::GetInstallListByMode(
471 InstallationMode installation_mode) const {
Jinho Bangb5216cec2018-01-17 19:43:11472 auto extension_dict = std::make_unique<base::DictionaryValue>();
achuith4607f072017-03-08 11:49:13473 for (const auto& entry : settings_by_id_) {
474 if (entry.second->installation_mode == installation_mode) {
475 ExternalPolicyLoader::AddExtension(extension_dict.get(), entry.first,
476 entry.second->update_url);
477 }
478 }
479 return extension_dict;
480}
481
482void ExtensionManagement::UpdateForcedExtensions(
483 const base::DictionaryValue* extension_dict) {
484 if (!extension_dict)
485 return;
486
487 std::string update_url;
488 for (base::DictionaryValue::Iterator it(*extension_dict); !it.IsAtEnd();
489 it.Advance()) {
490 if (!crx_file::id_util::IdIsValid(it.key()))
491 continue;
492 const base::DictionaryValue* dict_value = nullptr;
493 if (it.value().GetAsDictionary(&dict_value) &&
494 dict_value->GetStringWithoutPathExpansion(
495 ExternalProviderImpl::kExternalUpdateUrl, &update_url)) {
496 internal::IndividualSettings* by_id = AccessById(it.key());
497 by_id->installation_mode = INSTALLATION_FORCED;
498 by_id->update_url = update_url;
499 }
500 }
501}
502
binjin81d7c552014-10-02 11:47:12503internal::IndividualSettings* ExtensionManagement::AccessById(
binjin5f405ef2014-09-03 21:23:16504 const ExtensionId& id) {
505 DCHECK(crx_file::id_util::IdIsValid(id)) << "Invalid ID: " << id;
avi3ec9c0d2016-12-27 22:38:06506 std::unique_ptr<internal::IndividualSettings>& settings = settings_by_id_[id];
507 if (!settings) {
508 settings =
Jinho Bangb5216cec2018-01-17 19:43:11509 std::make_unique<internal::IndividualSettings>(default_settings_.get());
binjin81d7c552014-10-02 11:47:12510 }
avi3ec9c0d2016-12-27 22:38:06511 return settings.get();
binjin5f405ef2014-09-03 21:23:16512}
513
binjin685ade82014-11-06 09:53:56514internal::IndividualSettings* ExtensionManagement::AccessByUpdateUrl(
515 const std::string& update_url) {
516 DCHECK(GURL(update_url).is_valid()) << "Invalid update URL: " << update_url;
avi3ec9c0d2016-12-27 22:38:06517 std::unique_ptr<internal::IndividualSettings>& settings =
518 settings_by_update_url_[update_url];
519 if (!settings) {
520 settings =
Jinho Bangb5216cec2018-01-17 19:43:11521 std::make_unique<internal::IndividualSettings>(default_settings_.get());
binjin685ade82014-11-06 09:53:56522 }
avi3ec9c0d2016-12-27 22:38:06523 return settings.get();
binjin685ade82014-11-06 09:53:56524}
525
binjin1569c9b2014-09-05 13:33:18526ExtensionManagement* ExtensionManagementFactory::GetForBrowserContext(
527 content::BrowserContext* context) {
528 return static_cast<ExtensionManagement*>(
529 GetInstance()->GetServiceForBrowserContext(context, true));
530}
531
532ExtensionManagementFactory* ExtensionManagementFactory::GetInstance() {
olli.raula36aa8be2015-09-10 11:14:22533 return base::Singleton<ExtensionManagementFactory>::get();
binjin1569c9b2014-09-05 13:33:18534}
535
536ExtensionManagementFactory::ExtensionManagementFactory()
537 : BrowserContextKeyedServiceFactory(
538 "ExtensionManagement",
539 BrowserContextDependencyManager::GetInstance()) {
540}
541
542ExtensionManagementFactory::~ExtensionManagementFactory() {
543}
544
545KeyedService* ExtensionManagementFactory::BuildServiceInstanceFor(
546 content::BrowserContext* context) const {
rkaplowdd66a1342015-03-05 00:31:49547 TRACE_EVENT0("browser,startup",
548 "ExtensionManagementFactory::BuildServiceInstanceFor");
achuith4607f072017-03-08 11:49:13549 Profile* profile = Profile::FromBrowserContext(context);
550 bool is_signin_profile = false;
551#if defined(OS_CHROMEOS)
552 is_signin_profile = chromeos::ProfileHelper::IsSigninProfile(profile);
553#endif
554 return new ExtensionManagement(profile->GetPrefs(), is_signin_profile);
binjin1569c9b2014-09-05 13:33:18555}
556
binjin9733df12014-09-08 15:21:21557content::BrowserContext* ExtensionManagementFactory::GetBrowserContextToUse(
558 content::BrowserContext* context) const {
559 return chrome::GetBrowserContextRedirectedInIncognito(context);
560}
561
binjinb2454382014-09-22 15:17:43562void ExtensionManagementFactory::RegisterProfilePrefs(
563 user_prefs::PrefRegistrySyncable* user_prefs) {
raymesaa608722015-04-27 03:00:25564 user_prefs->RegisterDictionaryPref(pref_names::kExtensionManagement);
binjinb2454382014-09-22 15:17:43565}
566
binjin5f405ef2014-09-03 21:23:16567} // namespace extensions