external_protocol_handler.cc revision 2a99a7e74a7f215066514fe81d2bfa6639d9eddd
15821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// Copyright (c) 2012 The Chromium Authors. All rights reserved.
25821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// Use of this source code is governed by a BSD-style license that can be
35821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// found in the LICENSE file.
45821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
55821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "chrome/browser/external_protocol/external_protocol_handler.h"
65821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
75821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include <set>
85821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
95821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/bind.h"
105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/logging.h"
115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/message_loop.h"
122a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)#include "base/prefs/pref_registry_simple.h"
132a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)#include "base/prefs/pref_service.h"
145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/string_util.h"
155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/threading/thread.h"
165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "build/build_config.h"
175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "chrome/browser/browser_process.h"
185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "chrome/browser/platform_util.h"
195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "chrome/browser/prefs/scoped_user_pref_update.h"
205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "chrome/common/pref_names.h"
215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "content/public/browser/browser_thread.h"
225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "googleurl/src/gurl.h"
235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "net/base/escape.h"
245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)using content::BrowserThread;
265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// Whether we accept requests for launching external protocols. This is set to
285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// false every time an external protocol is requested, and set back to true on
295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// each user gesture. This variable should only be accessed from the UI thread.
305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)static bool g_accept_requests = true;
315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)namespace {
335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// Functions enabling unit testing. Using a NULL delegate will use the default
355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// behavior; if a delegate is provided it will be used instead.
365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)ShellIntegration::DefaultProtocolClientWorker* CreateShellWorker(
375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ShellIntegration::DefaultWebClientObserver* observer,
385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& protocol,
395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ExternalProtocolHandler::Delegate* delegate) {
405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!delegate)
415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return new ShellIntegration::DefaultProtocolClientWorker(observer,
425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                             protocol);
435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return delegate->CreateShellWorker(observer, protocol);
455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)ExternalProtocolHandler::BlockState GetBlockStateWithDelegate(
485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& scheme,
495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ExternalProtocolHandler::Delegate* delegate) {
505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!delegate)
515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return ExternalProtocolHandler::GetBlockState(scheme);
525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return delegate->GetBlockState(scheme);
545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void RunExternalProtocolDialogWithDelegate(
575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const GURL& url,
585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    int render_process_host_id,
595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    int routing_id,
605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ExternalProtocolHandler::Delegate* delegate) {
615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!delegate) {
625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ExternalProtocolHandler::RunExternalProtocolDialog(url,
635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                       render_process_host_id,
645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                       routing_id);
655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    delegate->RunExternalProtocolDialog(url, render_process_host_id,
675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                        routing_id);
685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
695821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
705821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void LaunchUrlWithoutSecurityCheckWithDelegate(
725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const GURL& url,
735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ExternalProtocolHandler::Delegate* delegate) {
745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!delegate)
755821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ExternalProtocolHandler::LaunchUrlWithoutSecurityCheck(url);
765821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  else
775821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    delegate->LaunchUrlWithoutSecurityCheck(url);
785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// When we are about to launch a URL with the default OS level application,
815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// we check if that external application will be us. If it is we just ignore
825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// the request.
835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)class ExternalDefaultProtocolObserver
845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    : public ShellIntegration::DefaultWebClientObserver {
855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) public:
865821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  ExternalDefaultProtocolObserver(const GURL& escaped_url,
875821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                  int render_process_host_id,
885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                  int tab_contents_id,
895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                  bool prompt_user,
905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                  ExternalProtocolHandler::Delegate* delegate)
915821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      : delegate_(delegate),
925821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        escaped_url_(escaped_url),
935821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        render_process_host_id_(render_process_host_id),
945821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        tab_contents_id_(tab_contents_id),
955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        prompt_user_(prompt_user) {}
965821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
975821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  virtual void SetDefaultWebClientUIState(
985821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      ShellIntegration::DefaultWebClientUIState state) OVERRIDE {
995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    DCHECK_EQ(MessageLoop::TYPE_UI, MessageLoop::current()->type());
1005821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // If we are still working out if we're the default, or we've found
1025821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // out we definately are the default, we end here.
1035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (state == ShellIntegration::STATE_PROCESSING) {
1045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      return;
1055821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
1065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (delegate_)
1085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      delegate_->FinishedProcessingCheck();
1095821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (state == ShellIntegration::STATE_IS_DEFAULT) {
1115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      if (delegate_)
1125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        delegate_->BlockRequest();
1135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      return;
1145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
1155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // If we get here, either we are not the default or we cannot work out
1175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // what the default is, so we proceed.
1185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (prompt_user_) {
1195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      // Ask the user if they want to allow the protocol. This will call
1205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      // LaunchUrlWithoutSecurityCheck if the user decides to accept the
1215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      // protocol.
1225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      RunExternalProtocolDialogWithDelegate(escaped_url_,
1235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)          render_process_host_id_, tab_contents_id_, delegate_);
1245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      return;
1255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
1265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    LaunchUrlWithoutSecurityCheckWithDelegate(escaped_url_, delegate_);
1285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
1295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  virtual bool IsOwnedByWorker() OVERRIDE { return true; }
1315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) private:
1335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  ExternalProtocolHandler::Delegate* delegate_;
1345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  GURL escaped_url_;
1355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  int render_process_host_id_;
1365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  int tab_contents_id_;
1375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  bool prompt_user_;
1385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)};
1395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}  // namespace
1415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void ExternalProtocolHandler::PrepopulateDictionary(DictionaryValue* win_pref) {
1445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  static bool is_warm = false;
1455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (is_warm)
1465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return;
1475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  is_warm = true;
1485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  static const char* const denied_schemes[] = {
1505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "afp",
1515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "data",
1525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "disk",
1535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "disks",
1545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // ShellExecuting file:///C:/WINDOWS/system32/notepad.exe will simply
1555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // execute the file specified!  Hopefully we won't see any "file" schemes
1565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // because we think of file:// URLs as handled URLs, but better to be safe
1575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // than to let an attacker format the user's hard drive.
1585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "file",
1595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "hcp",
1605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "javascript",
1615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "ms-help",
1625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "nntp",
1635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "shell",
1645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "vbscript",
1655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // view-source is a special case in chrome. When it comes through an
1665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // iframe or a redirect, it looks like an external protocol, but we don't
1675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // want to shellexecute it.
1685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "view-source",
1695821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "vnd.ms.radio",
1705821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  };
1715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  static const char* const allowed_schemes[] = {
1735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "mailto",
1745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "news",
1755821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "snews",
1762a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)#if defined(OS_WIN)
1772a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)    "ms-windows-store",
1782a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)#endif
1795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  };
1805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  bool should_block;
1825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  for (size_t i = 0; i < arraysize(denied_schemes); ++i) {
1835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (!win_pref->GetBoolean(denied_schemes[i], &should_block)) {
1845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      win_pref->SetBoolean(denied_schemes[i], true);
1855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
1865821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
1875821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  for (size_t i = 0; i < arraysize(allowed_schemes); ++i) {
1895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (!win_pref->GetBoolean(allowed_schemes[i], &should_block)) {
1905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      win_pref->SetBoolean(allowed_schemes[i], false);
1915821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
1925821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
1935821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
1945821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1965821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)ExternalProtocolHandler::BlockState ExternalProtocolHandler::GetBlockState(
1975821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& scheme) {
1985821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // If we are being carpet bombed, block the request.
1995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!g_accept_requests)
2005821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return BLOCK;
2015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2025821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (scheme.length() == 1) {
2035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // We have a URL that looks something like:
2045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    //   C:/WINDOWS/system32/notepad.exe
2055821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // ShellExecuting this URL will cause the specified program to be executed.
2065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return BLOCK;
2075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
2085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2095821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // Check the stored prefs.
2105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // TODO(pkasting): http://b/1119651 This kind of thing should go in the
2115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // preferences on the profile, not in the local state.
2125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  PrefService* pref = g_browser_process->local_state();
2135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (pref) {  // May be NULL during testing.
2145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    DictionaryPrefUpdate update_excluded_schemas(pref, prefs::kExcludedSchemes);
2155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // Warm up the dictionary if needed.
2175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    PrepopulateDictionary(update_excluded_schemas.Get());
2185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    bool should_block;
2205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (update_excluded_schemas->GetBoolean(scheme, &should_block))
2215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      return should_block ? BLOCK : DONT_BLOCK;
2225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
2235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return UNKNOWN;
2255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
2265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
2285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void ExternalProtocolHandler::SetBlockState(const std::string& scheme,
2295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                            BlockState state) {
2305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // Set in the stored prefs.
2315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // TODO(pkasting): http://b/1119651 This kind of thing should go in the
2325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // preferences on the profile, not in the local state.
2335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  PrefService* pref = g_browser_process->local_state();
2345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (pref) {  // May be NULL during testing.
2355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    DictionaryPrefUpdate update_excluded_schemas(pref, prefs::kExcludedSchemes);
2365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (state == UNKNOWN) {
2385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      update_excluded_schemas->Remove(scheme, NULL);
2395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    } else {
2405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      update_excluded_schemas->SetBoolean(scheme, (state == BLOCK));
2415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
2425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
2435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
2445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
2465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void ExternalProtocolHandler::LaunchUrlWithDelegate(const GURL& url,
2475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                    int render_process_host_id,
2485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                    int tab_contents_id,
2495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                    Delegate* delegate) {
2505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK_EQ(MessageLoop::TYPE_UI, MessageLoop::current()->type());
2515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // Escape the input scheme to be sure that the command does not
2535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // have parameters unexpected by the external program.
2545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string escaped_url_string = net::EscapeExternalHandlerValue(url.spec());
2555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  GURL escaped_url(escaped_url_string);
2565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  BlockState block_state = GetBlockStateWithDelegate(escaped_url.scheme(),
2575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                     delegate);
2585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (block_state == BLOCK) {
2595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (delegate)
2605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      delegate->BlockRequest();
2615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return;
2625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
2635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  g_accept_requests = false;
2655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // The worker creates tasks with references to itself and puts them into
2675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // message loops. When no tasks are left it will delete the observer and
2685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // eventually be deleted itself.
2695821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  ShellIntegration::DefaultWebClientObserver* observer =
2705821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      new ExternalDefaultProtocolObserver(url,
2715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                          render_process_host_id,
2725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                          tab_contents_id,
2735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                          block_state == UNKNOWN,
2745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                          delegate);
2755821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  scoped_refptr<ShellIntegration::DefaultProtocolClientWorker> worker =
2765821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      CreateShellWorker(observer, escaped_url.scheme(), delegate);
2775821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // Start the check process running. This will send tasks to the FILE thread
2795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // and when the answer is known will send the result back to the observer on
2805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // the UI thread.
2815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  worker->StartCheckIsDefault();
2825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
2835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
2855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void ExternalProtocolHandler::LaunchUrlWithoutSecurityCheck(const GURL& url) {
2865821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#if defined(OS_MACOSX)
2875821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // This must run on the UI thread on OS X.
2885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  platform_util::OpenExternal(url);
2895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#else
2905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // Otherwise put this work on the file thread. On Windows ShellExecute may
2915821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // block for a significant amount of time, and it shouldn't hurt on Linux.
2925821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  BrowserThread::PostTask(
2935821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      BrowserThread::FILE,
2945821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      FROM_HERE,
2955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      base::Bind(&platform_util::OpenExternal, url));
2965821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#endif
2975821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
2985821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
3002a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)void ExternalProtocolHandler::RegisterPrefs(PrefRegistrySimple* registry) {
3012a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  registry->RegisterDictionaryPref(prefs::kExcludedSchemes);
3025821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
3035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
3045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
3055821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void ExternalProtocolHandler::PermitLaunchUrl() {
3065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK_EQ(MessageLoop::TYPE_UI, MessageLoop::current()->type());
3075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  g_accept_requests = true;
3085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
309