gaia_auth_fetcher.cc revision 23730a6e56a168d1879203e4b3819bb36e3d8f1f
15821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// Copyright (c) 2012 The Chromium Authors. All rights reserved.
25821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// Use of this source code is governed by a BSD-style license that can be
35821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// found in the LICENSE file.
45821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
55821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "google_apis/gaia/gaia_auth_fetcher.h"
65821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
75821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include <string>
85821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include <utility>
95821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include <vector>
105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/json/json_reader.h"
125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/json/json_writer.h"
132a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)#include "base/strings/string_split.h"
14868fa2fe829687343ffae624259930155e16dbd8Torne (Richard Coles)#include "base/strings/string_util.h"
15868fa2fe829687343ffae624259930155e16dbd8Torne (Richard Coles)#include "base/strings/stringprintf.h"
165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/values.h"
175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "google_apis/gaia/gaia_auth_consumer.h"
185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "google_apis/gaia/gaia_constants.h"
195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "google_apis/gaia/gaia_urls.h"
205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "google_apis/gaia/google_service_auth_error.h"
215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "net/base/escape.h"
225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "net/base/load_flags.h"
232a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)#include "net/http/http_response_headers.h"
245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "net/http/http_status_code.h"
255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "net/url_request/url_fetcher.h"
265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "net/url_request/url_request_context_getter.h"
275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "net/url_request/url_request_status.h"
285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)namespace {
305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const int kLoadFlagsIgnoreCookies = net::LOAD_DO_NOT_SEND_COOKIES |
315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                    net::LOAD_DO_NOT_SAVE_COOKIES;
325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)static bool CookiePartsContains(const std::vector<std::string>& parts,
345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                const char* part) {
355d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)  for (std::vector<std::string>::const_iterator it = parts.begin();
365d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)       it != parts.end(); ++it) {
375d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)    if (LowerCaseEqualsASCII(*it, part))
385d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)      return true;
395d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)  }
405d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)  return false;
415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
43eb525c5499e34cc9c4b825d6d9e75bb07cc06aceBen Murdochbool ExtractOAuth2TokenPairResponse(base::DictionaryValue* dict,
445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                    std::string* refresh_token,
455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                    std::string* access_token,
465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                    int* expires_in_secs) {
475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(refresh_token);
485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(access_token);
495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(expires_in_secs);
505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!dict->GetStringWithoutPathExpansion("refresh_token", refresh_token) ||
525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      !dict->GetStringWithoutPathExpansion("access_token", access_token) ||
535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      !dict->GetIntegerWithoutPathExpansion("expires_in", expires_in_secs)) {
545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return false;
555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return true;
585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}  // namespace
615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// TODO(chron): Add sourceless version of this formatter.
635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kClientLoginFormat[] =
655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "Email=%s&"
665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "Passwd=%s&"
675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "PersistentCookie=%s&"
685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "accountType=%s&"
695821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "source=%s&"
705821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "service=%s";
715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kClientLoginCaptchaFormat[] =
735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "Email=%s&"
745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "Passwd=%s&"
755821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "PersistentCookie=%s&"
765821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "accountType=%s&"
775821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "source=%s&"
785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "service=%s&"
795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "logintoken=%s&"
805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "logincaptcha=%s";
815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kIssueAuthTokenFormat[] =
835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "SID=%s&"
845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "LSID=%s&"
855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "service=%s&"
865821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "Session=%s";
875821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kClientLoginToOAuth2BodyFormat[] =
895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "scope=%s&client_id=%s";
905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
915821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kOAuth2CodeToTokenPairBodyFormat[] =
925821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "scope=%s&"
935821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "grant_type=authorization_code&"
945821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "client_id=%s&"
955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "client_secret=%s&"
965821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "code=%s";
975821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
98c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)const char GaiaAuthFetcher::kOAuth2RevokeTokenBodyFormat[] =
99c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)    "token=%s";
100c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)// static
1015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kGetUserInfoFormat[] =
1025821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "LSID=%s";
1035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kMergeSessionFormat[] =
1055821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "uberauth=%s&"
1065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "continue=%s&"
1075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "source=%s";
1085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1095821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kUberAuthTokenURLFormat[] =
110d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)    "?source=%s&"
1115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "issueuberauth=1";
1125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kOAuthLoginFormat[] = "service=%s&source=%s";
1145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kAccountDeletedError[] = "AccountDeleted";
1175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kAccountDisabledError[] = "AccountDisabled";
1195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kBadAuthenticationError[] = "BadAuthentication";
1215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kCaptchaError[] = "CaptchaRequired";
1235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kServiceUnavailableError[] =
1255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "ServiceUnavailable";
1265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kErrorParam[] = "Error";
1285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kErrorUrlParam[] = "Url";
1305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kCaptchaUrlParam[] = "CaptchaUrl";
1325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kCaptchaTokenParam[] = "CaptchaToken";
1345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kCookiePersistence[] = "true";
1375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// TODO(johnnyg): When hosted accounts are supported by sync,
1395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// we can always use "HOSTED_OR_GOOGLE"
1405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kAccountTypeHostedOrGoogle[] =
1415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "HOSTED_OR_GOOGLE";
1425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kAccountTypeGoogle[] =
1435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "GOOGLE";
1445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kSecondFactor[] = "Info=InvalidSecondFactor";
1475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kAuthHeaderFormat[] =
1505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "Authorization: GoogleLogin auth=%s";
1515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kOAuthHeaderFormat[] = "Authorization: OAuth %s";
1535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1542a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)const char GaiaAuthFetcher::kOAuth2BearerHeaderFormat[] =
1552a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)    "Authorization: Bearer %s";
1562a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)// static
1575d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)const char GaiaAuthFetcher::kClientLoginToOAuth2CookiePartSecure[] = "secure";
1585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kClientLoginToOAuth2CookiePartHttpOnly[] =
1605d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)    "httponly";
1615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const char GaiaAuthFetcher::kClientLoginToOAuth2CookiePartCodePrefix[] =
1635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    "oauth_code=";
1645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
1655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)const int GaiaAuthFetcher::kClientLoginToOAuth2CookiePartCodePrefixLength =
1665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    arraysize(GaiaAuthFetcher::kClientLoginToOAuth2CookiePartCodePrefix) - 1;
1675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)GaiaAuthFetcher::GaiaAuthFetcher(GaiaAuthConsumer* consumer,
1695821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                 const std::string& source,
1705821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                 net::URLRequestContextGetter* getter)
1715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    : consumer_(consumer),
1725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      getter_(getter),
1735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      source_(source),
1745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      client_login_gurl_(GaiaUrls::GetInstance()->client_login_url()),
1755821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      issue_auth_token_gurl_(GaiaUrls::GetInstance()->issue_auth_token_url()),
1765821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      oauth2_token_gurl_(GaiaUrls::GetInstance()->oauth2_token_url()),
177c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)      oauth2_revoke_gurl_(GaiaUrls::GetInstance()->oauth2_revoke_url()),
1785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      get_user_info_gurl_(GaiaUrls::GetInstance()->get_user_info_url()),
1795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      merge_session_gurl_(GaiaUrls::GetInstance()->merge_session_url()),
180d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)      uberauth_token_gurl_(GaiaUrls::GetInstance()->oauth1_login_url().Resolve(
181d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)          base::StringPrintf(kUberAuthTokenURLFormat, source.c_str()))),
1825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      oauth_login_gurl_(GaiaUrls::GetInstance()->oauth1_login_url()),
183f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)      list_accounts_gurl_(GaiaUrls::GetInstance()->list_accounts_url()),
1845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      client_login_to_oauth2_gurl_(
1855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)          GaiaUrls::GetInstance()->client_login_to_oauth2_url()),
1865d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)      fetch_pending_(false),
1875d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)      fetch_code_only_(false) {}
1885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)GaiaAuthFetcher::~GaiaAuthFetcher() {}
1905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1915821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)bool GaiaAuthFetcher::HasPendingFetch() {
1925821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return fetch_pending_;
1935821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
1945821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
1955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::CancelRequest() {
1965821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_.reset();
1975821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = false;
1985821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
1995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2005821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
2015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)net::URLFetcher* GaiaAuthFetcher::CreateGaiaFetcher(
2025821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    net::URLRequestContextGetter* getter,
2035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& body,
2045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& headers,
2055821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const GURL& gaia_gurl,
2065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    int load_flags,
2075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    net::URLFetcherDelegate* delegate) {
2085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  net::URLFetcher* to_return = net::URLFetcher::Create(
2095821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      0, gaia_gurl,
2105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      body == "" ? net::URLFetcher::GET : net::URLFetcher::POST,
2115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      delegate);
2125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  to_return->SetRequestContext(getter);
2135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  to_return->SetUploadData("application/x-www-form-urlencoded", body);
2145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(2) << "Gaia fetcher URL: " << gaia_gurl.spec();
2165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(2) << "Gaia fetcher headers: " << headers;
2175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(2) << "Gaia fetcher body: " << body;
2185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // The Gaia token exchange requests do not require any cookie-based
2205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // identification as part of requests.  We suppress sending any cookies to
2215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // maintain a separation between the user's browsing and Chrome's internal
222f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  // services.  Where such mixing is desired (MergeSession or OAuthLogin), it
223f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  // will be done explicitly.
2245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  to_return->SetLoadFlags(load_flags);
2255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2262a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  // Fetchers are sometimes cancelled because a network change was detected,
2272a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  // especially at startup and after sign-in on ChromeOS. Retrying once should
2282a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  // be enough in those cases; let the fetcher retry up to 3 times just in case.
2292a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  // http://crbug.com/163710
2302a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  to_return->SetAutomaticallyRetryOnNetworkChanges(3);
2312a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)
2325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!headers.empty())
2335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    to_return->SetExtraRequestHeaders(headers);
2345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return to_return;
2365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
2375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
2395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)std::string GaiaAuthFetcher::MakeClientLoginBody(
2405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& username,
2415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& password,
2425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& source,
2435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const char* service,
2445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& login_token,
2455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& login_captcha,
2465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    HostedAccountsSetting allow_hosted_accounts) {
2475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_username = net::EscapeUrlEncodedData(username, true);
2485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_password = net::EscapeUrlEncodedData(password, true);
2495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_login_token = net::EscapeUrlEncodedData(login_token,
2505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                              true);
2515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_login_captcha = net::EscapeUrlEncodedData(login_captcha,
2525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                                true);
2535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  const char* account_type = allow_hosted_accounts == HostedAccountsAllowed ?
2555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      kAccountTypeHostedOrGoogle :
2565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      kAccountTypeGoogle;
2575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (login_token.empty() || login_captcha.empty()) {
2595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return base::StringPrintf(kClientLoginFormat,
2605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                              encoded_username.c_str(),
2615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                              encoded_password.c_str(),
2625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                              kCookiePersistence,
2635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                              account_type,
2645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                              source.c_str(),
2655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                              service);
2665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
2675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return base::StringPrintf(kClientLoginCaptchaFormat,
2695821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            encoded_username.c_str(),
2705821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            encoded_password.c_str(),
2715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            kCookiePersistence,
2725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            account_type,
2735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            source.c_str(),
2745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            service,
2755821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            encoded_login_token.c_str(),
2765821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            encoded_login_captcha.c_str());
2775821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
2785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
2805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)std::string GaiaAuthFetcher::MakeIssueAuthTokenBody(
2815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& sid,
2825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& lsid,
2835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const char* const service) {
2845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_sid = net::EscapeUrlEncodedData(sid, true);
2855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_lsid = net::EscapeUrlEncodedData(lsid, true);
2865821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2875821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // All tokens should be session tokens except the gaia auth token.
2885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  bool session = true;
2895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!strcmp(service, GaiaConstants::kGaiaService))
2905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    session = false;
2915821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2925821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return base::StringPrintf(kIssueAuthTokenFormat,
2935821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            encoded_sid.c_str(),
2945821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            encoded_lsid.c_str(),
2955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            service,
2965821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            session ? "true" : "false");
2975821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
2985821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
2995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
3005821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)std::string GaiaAuthFetcher::MakeGetAuthCodeBody() {
3015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_scope = net::EscapeUrlEncodedData(
302a1401311d1ab56c4ed0a474bd38c108f75cb0cd9Torne (Richard Coles)      GaiaConstants::kOAuth1LoginScope, true);
3035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_client_id = net::EscapeUrlEncodedData(
3045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      GaiaUrls::GetInstance()->oauth2_chrome_client_id(), true);
3052a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  return base::StringPrintf(kClientLoginToOAuth2BodyFormat,
3062a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                            encoded_scope.c_str(),
3072a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                            encoded_client_id.c_str());
3085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
3095821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
3105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
3115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)std::string GaiaAuthFetcher::MakeGetTokenPairBody(
3125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& auth_code) {
3135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_scope = net::EscapeUrlEncodedData(
314a1401311d1ab56c4ed0a474bd38c108f75cb0cd9Torne (Richard Coles)      GaiaConstants::kOAuth1LoginScope, true);
3155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_client_id = net::EscapeUrlEncodedData(
3165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      GaiaUrls::GetInstance()->oauth2_chrome_client_id(), true);
3175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_client_secret = net::EscapeUrlEncodedData(
3185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      GaiaUrls::GetInstance()->oauth2_chrome_client_secret(), true);
3195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_auth_code = net::EscapeUrlEncodedData(auth_code, true);
3202a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  return base::StringPrintf(kOAuth2CodeToTokenPairBodyFormat,
3212a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                            encoded_scope.c_str(),
3222a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                            encoded_client_id.c_str(),
3232a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                            encoded_client_secret.c_str(),
3242a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                            encoded_auth_code.c_str());
3255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
3265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
3275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
328c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)std::string GaiaAuthFetcher::MakeRevokeTokenBody(
329c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)    const std::string& auth_token) {
330c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)  return base::StringPrintf(kOAuth2RevokeTokenBodyFormat, auth_token.c_str());
331c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)}
332c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)
333c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)// static
3345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)std::string GaiaAuthFetcher::MakeGetUserInfoBody(const std::string& lsid) {
3355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_lsid = net::EscapeUrlEncodedData(lsid, true);
3365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return base::StringPrintf(kGetUserInfoFormat, encoded_lsid.c_str());
3375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
3385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
3395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
3405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)std::string GaiaAuthFetcher::MakeMergeSessionBody(
3415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& auth_token,
3425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& continue_url,
3435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& source) {
3445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_auth_token = net::EscapeUrlEncodedData(auth_token, true);
3455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_continue_url = net::EscapeUrlEncodedData(continue_url,
3465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                               true);
3475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_source = net::EscapeUrlEncodedData(source, true);
3485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return base::StringPrintf(kMergeSessionFormat,
3495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            encoded_auth_token.c_str(),
3505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            encoded_continue_url.c_str(),
3515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                            encoded_source.c_str());
3525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
3535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
3545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
3555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)std::string GaiaAuthFetcher::MakeGetAuthCodeHeader(
3565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& auth_token) {
3572a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  return base::StringPrintf(kAuthHeaderFormat, auth_token.c_str());
3585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
3595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
3605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// Helper method that extracts tokens from a successful reply.
3615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
3625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::ParseClientLoginResponse(const std::string& data,
3635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                               std::string* sid,
3645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                               std::string* lsid,
3655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                               std::string* token) {
3665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  using std::vector;
3675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  using std::pair;
3685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  using std::string;
3692a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  sid->clear();
3702a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  lsid->clear();
3712a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  token->clear();
3725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  vector<pair<string, string> > tokens;
3735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  base::SplitStringIntoKeyValuePairs(data, '=', '\n', &tokens);
3745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  for (vector<pair<string, string> >::iterator i = tokens.begin();
3755821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      i != tokens.end(); ++i) {
3765821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (i->first == "SID") {
3775821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      sid->assign(i->second);
3785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    } else if (i->first == "LSID") {
3795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      lsid->assign(i->second);
3805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    } else if (i->first == "Auth") {
3815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      token->assign(i->second);
3825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
3835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
3842a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  // If this was a request for uberauth token, then that's all we've got in
3852a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  // data.
3862a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  if (sid->empty() && lsid->empty() && token->empty())
3872a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)    token->assign(data);
3885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
3895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
3905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
3915821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)std::string GaiaAuthFetcher::MakeOAuthLoginBody(const std::string& service,
3925821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                const std::string& source) {
3935821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_service = net::EscapeUrlEncodedData(service, true);
3945821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string encoded_source = net::EscapeUrlEncodedData(source, true);
3952a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  return base::StringPrintf(kOAuthLoginFormat,
3962a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                            encoded_service.c_str(),
3972a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                            encoded_source.c_str());
3985821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
3995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4005821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
4015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::ParseClientLoginFailure(const std::string& data,
4025821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                              std::string* error,
4035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                              std::string* error_url,
4045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                              std::string* captcha_url,
4055821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                              std::string* captcha_token) {
4065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  using std::vector;
4075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  using std::pair;
4085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  using std::string;
4095821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  vector<pair<string, string> > tokens;
4115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  base::SplitStringIntoKeyValuePairs(data, '=', '\n', &tokens);
4125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  for (vector<pair<string, string> >::iterator i = tokens.begin();
4135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)       i != tokens.end(); ++i) {
4145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (i->first == kErrorParam) {
4155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      error->assign(i->second);
4165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    } else if (i->first == kErrorUrlParam) {
4175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      error_url->assign(i->second);
4185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    } else if (i->first == kCaptchaUrlParam) {
4195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      captcha_url->assign(i->second);
4205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    } else if (i->first == kCaptchaTokenParam) {
4215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      captcha_token->assign(i->second);
4225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
4235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
4245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
4255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
4275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)bool GaiaAuthFetcher::ParseClientLoginToOAuth2Response(
4285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const net::ResponseCookies& cookies,
4295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::string* auth_code) {
4305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(auth_code);
4315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  net::ResponseCookies::const_iterator iter;
4325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  for (iter = cookies.begin(); iter != cookies.end(); ++iter) {
4335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (ParseClientLoginToOAuth2Cookie(*iter, auth_code))
4345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      return true;
4355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
4365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return false;
4375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
4385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
4405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)bool GaiaAuthFetcher::ParseClientLoginToOAuth2Cookie(const std::string& cookie,
4415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                                     std::string* auth_code) {
4425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::vector<std::string> parts;
4435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  base::SplitString(cookie, ';', &parts);
4445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // Per documentation, the cookie should have Secure and HttpOnly.
4455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!CookiePartsContains(parts, kClientLoginToOAuth2CookiePartSecure) ||
4465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      !CookiePartsContains(parts, kClientLoginToOAuth2CookiePartHttpOnly)) {
4475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return false;
4485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
4495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::vector<std::string>::const_iterator iter;
4515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  for (iter = parts.begin(); iter != parts.end(); ++iter) {
4525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& part = *iter;
4535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (StartsWithASCII(
4545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        part, kClientLoginToOAuth2CookiePartCodePrefix, false)) {
4555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      auth_code->assign(part.substr(
4565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)          kClientLoginToOAuth2CookiePartCodePrefixLength));
4575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      return true;
4585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
4595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
4605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return false;
4615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
4625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::StartClientLogin(
4645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& username,
4655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& password,
4665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const char* const service,
4675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& login_token,
4685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& login_captcha,
4695821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    HostedAccountsSetting allow_hosted_accounts) {
4705821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
4725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // This class is thread agnostic, so be sure to call this only on the
4745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // same thread each time.
4755821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(1) << "Starting new ClientLogin fetch for:" << username;
4765821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4775821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // Must outlive fetcher_.
4785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  request_body_ = MakeClientLoginBody(username,
4795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                      password,
4805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                      source_,
4815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                      service,
4825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                      login_token,
4835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                      login_captcha,
4845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                      allow_hosted_accounts);
4855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
4865821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   request_body_,
487c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   std::string(),
4885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   client_login_gurl_,
4895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   kLoadFlagsIgnoreCookies,
4905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   this));
4915821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = true;
4925821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_->Start();
4935821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
4945821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
4955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::StartIssueAuthToken(const std::string& sid,
4965821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                          const std::string& lsid,
4975821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                          const char* const service) {
4985821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
4995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
5005821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(1) << "Starting IssueAuthToken for: " << service;
5015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  requested_service_ = service;
5025821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  request_body_ = MakeIssueAuthTokenBody(sid, lsid, service);
5035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
5045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   request_body_,
505c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   std::string(),
5065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   issue_auth_token_gurl_,
5075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   kLoadFlagsIgnoreCookies,
5085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   this));
5095821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = true;
5105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_->Start();
5115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
5125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
5135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::StartLsoForOAuthLoginTokenExchange(
5145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& auth_token) {
5155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
5165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
5175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(1) << "Starting OAuth login token exchange with auth_token";
5185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  request_body_ = MakeGetAuthCodeBody();
5195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  client_login_to_oauth2_gurl_ =
520d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)      GaiaUrls::GetInstance()->client_login_to_oauth2_url();
5215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
5225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
5235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   request_body_,
5245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   MakeGetAuthCodeHeader(auth_token),
5255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   client_login_to_oauth2_gurl_,
5265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   kLoadFlagsIgnoreCookies,
5275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   this));
5285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = true;
5295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_->Start();
5305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
5315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
532c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)void GaiaAuthFetcher::StartRevokeOAuth2Token(const std::string& auth_token) {
533c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
534c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)
535c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)  DVLOG(1) << "Starting OAuth2 token revocation";
536c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)  request_body_ = MakeRevokeTokenBody(auth_token);
537c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
538c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   request_body_,
539c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   std::string(),
540c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   oauth2_revoke_gurl_,
541c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   kLoadFlagsIgnoreCookies,
542c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   this));
543c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)  fetch_pending_ = true;
544c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)  fetcher_->Start();
545c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)}
546c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)
5475d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)void GaiaAuthFetcher::StartCookieForOAuthCodeExchange(
5485d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)    const std::string& session_index) {
5495d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)  // Same as the first step of StartCookieForOAuthLoginTokenExchange;
5505d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)  StartCookieForOAuthLoginTokenExchange(session_index);
5515d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)  fetch_code_only_ = true;
5525d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)}
5535d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)
5545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::StartCookieForOAuthLoginTokenExchange(
5555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& session_index) {
5565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
5575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
5585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(1) << "Starting OAuth login token fetch with cookie jar";
5595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  request_body_ = MakeGetAuthCodeBody();
5605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
561d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)  client_login_to_oauth2_gurl_ =
562d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)      GaiaUrls::GetInstance()->client_login_to_oauth2_url();
563d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)  if (!session_index.empty()) {
564d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)    client_login_to_oauth2_gurl_ =
565d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)        client_login_to_oauth2_gurl_.Resolve("?authuser=" + session_index);
566d0247b1b59f9c528cb6df88b4f2b9afaf80d181eTorne (Richard Coles)  }
5675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
5685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
5695821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   request_body_,
570c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   std::string(),
5715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   client_login_to_oauth2_gurl_,
5725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   net::LOAD_NORMAL,
5735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   this));
5745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = true;
5755d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)  fetch_code_only_ = false;
5765821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_->Start();
5775821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
5785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
5792a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)void GaiaAuthFetcher::StartAuthCodeForOAuth2TokenExchange(
5802a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)    const std::string& auth_code) {
5812a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
5822a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)
5832a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  DVLOG(1) << "Starting OAuth token pair fetch";
5842a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  request_body_ = MakeGetTokenPairBody(auth_code);
5852a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
5862a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                                   request_body_,
587c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   std::string(),
5882a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                                   oauth2_token_gurl_,
5892a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                                   kLoadFlagsIgnoreCookies,
5902a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)                                   this));
5912a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  fetch_pending_ = true;
5922a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  fetcher_->Start();
5932a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)}
5942a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)
5955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::StartGetUserInfo(const std::string& lsid) {
5965821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
5975821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
5985821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(1) << "Starting GetUserInfo for lsid=" << lsid;
5995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  request_body_ = MakeGetUserInfoBody(lsid);
6005821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
6015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   request_body_,
602c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   std::string(),
6035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   get_user_info_gurl_,
6045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   kLoadFlagsIgnoreCookies,
6055821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   this));
6065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = true;
6075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_->Start();
6085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
6095821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
6105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::StartMergeSession(const std::string& uber_token) {
6115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
6125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
6135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(1) << "Starting MergeSession with uber_token=" << uber_token;
6145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
6155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // The continue URL is a required parameter of the MergeSession API, but in
6165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // this case we don't actually need or want to navigate to it.  Setting it to
6175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // an arbitrary Google URL.
6185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  //
6195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // In order for the new session to be merged correctly, the server needs to
6205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // know what sessions already exist in the browser.  The fetcher needs to be
6215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // created such that it sends the cookies with the request, which is
6225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // different from all other requests the fetcher can make.
6235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string continue_url("http://www.google.com");
6245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  request_body_ = MakeMergeSessionBody(uber_token, continue_url, source_);
6255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
6265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   request_body_,
627c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   std::string(),
6285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   merge_session_gurl_,
6295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   net::LOAD_NORMAL,
6305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   this));
6315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = true;
6325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_->Start();
6335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
6345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
6355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::StartTokenFetchForUberAuthExchange(
6365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& access_token) {
6375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
6385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
6395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DVLOG(1) << "Starting StartTokenFetchForUberAuthExchange with access_token="
6405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)           << access_token;
6415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string authentication_header =
6425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      base::StringPrintf(kOAuthHeaderFormat, access_token.c_str());
6435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
644c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)                                   std::string(),
6455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   authentication_header,
6465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   uberauth_token_gurl_,
647f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)                                   net::LOAD_NORMAL,
6485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   this));
6495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = true;
6505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_->Start();
6515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
6525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
6535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::StartOAuthLogin(const std::string& access_token,
6545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                      const std::string& service) {
6555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
6565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
6575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  request_body_ = MakeOAuthLoginBody(service, source_);
6585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string authentication_header =
6592a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)      base::StringPrintf(kOAuth2BearerHeaderFormat, access_token.c_str());
6605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
6615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   request_body_,
6625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   authentication_header,
6635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   oauth_login_gurl_,
664f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)                                   net::LOAD_NORMAL,
665f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)                                   this));
666f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  fetch_pending_ = true;
667f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  fetcher_->Start();
668f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)}
669f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)
670f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)void GaiaAuthFetcher::StartListAccounts() {
671f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  DCHECK(!fetch_pending_) << "Tried to fetch two things at once!";
672f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)
673f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  fetcher_.reset(CreateGaiaFetcher(getter_,
674f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)                                   " ",  // To force an HTTP POST.
675f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)                                   "Origin: https://www.google.com",
676f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)                                   list_accounts_gurl_,
677f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)                                   net::LOAD_NORMAL,
6785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                   this));
6795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = true;
6805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetcher_->Start();
6815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
6825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
6835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
6845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)GoogleServiceAuthError GaiaAuthFetcher::GenerateAuthError(
6855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& data,
6865821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const net::URLRequestStatus& status) {
6875821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (!status.is_success()) {
6885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (status.status() == net::URLRequestStatus::CANCELED) {
6895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      return GoogleServiceAuthError(GoogleServiceAuthError::REQUEST_CANCELED);
6905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
69123730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)    DLOG(WARNING) << "Could not reach Google Accounts servers: errno "
69223730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)                  << status.error();
69323730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)    return GoogleServiceAuthError::FromConnectionError(status.error());
69423730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  }
6955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
69623730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  if (IsSecondFactorSuccess(data))
69723730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)    return GoogleServiceAuthError(GoogleServiceAuthError::TWO_FACTOR);
69823730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)
69923730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  std::string error;
70023730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  std::string url;
70123730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  std::string captcha_url;
70223730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  std::string captcha_token;
70323730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  ParseClientLoginFailure(data, &error, &url, &captcha_url, &captcha_token);
70423730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  DLOG(WARNING) << "ClientLogin failed with " << error;
70523730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)
70623730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  if (error == kCaptchaError) {
70723730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)    return GoogleServiceAuthError::FromClientLoginCaptchaChallenge(
70823730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)        captcha_token,
70923730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)        GURL(GaiaUrls::GetInstance()->captcha_base_url().Resolve(captcha_url)),
71023730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)        GURL(url));
71123730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  }
71223730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  if (error == kAccountDeletedError)
71323730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)    return GoogleServiceAuthError(GoogleServiceAuthError::ACCOUNT_DELETED);
71423730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  if (error == kAccountDisabledError)
71523730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)    return GoogleServiceAuthError(GoogleServiceAuthError::ACCOUNT_DISABLED);
71623730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  if (error == kBadAuthenticationError) {
7175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return GoogleServiceAuthError(
71823730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)        GoogleServiceAuthError::INVALID_GAIA_CREDENTIALS);
7195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
72023730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  if (error == kServiceUnavailableError) {
7215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    return GoogleServiceAuthError(
7225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        GoogleServiceAuthError::SERVICE_UNAVAILABLE);
7235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
7245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
72523730a6e56a168d1879203e4b3819bb36e3d8f1fTorne (Richard Coles)  DLOG(WARNING) << "Incomprehensible response from Google Accounts servers.";
7265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return GoogleServiceAuthError(GoogleServiceAuthError::SERVICE_UNAVAILABLE);
7275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
7285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
7295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::OnClientLoginFetched(const std::string& data,
7305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                           const net::URLRequestStatus& status,
7315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                           int response_code) {
7325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (status.is_success() && response_code == net::HTTP_OK) {
7335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    DVLOG(1) << "ClientLogin successful!";
7345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::string sid;
7355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::string lsid;
7365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::string token;
7375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ParseClientLoginResponse(data, &sid, &lsid, &token);
7385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnClientLoginSuccess(
7395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        GaiaAuthConsumer::ClientLoginResult(sid, lsid, token, data));
7405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
7415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnClientLoginFailure(GenerateAuthError(data, status));
7425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
7435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
7445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
7455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::OnIssueAuthTokenFetched(
7465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& data,
7475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const net::URLRequestStatus& status,
7485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    int response_code) {
7495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (status.is_success() && response_code == net::HTTP_OK) {
7505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // Only the bare token is returned in the body of this Gaia call
7515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    // without any padding.
7525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnIssueAuthTokenSuccess(requested_service_, data);
7535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
7545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnIssueAuthTokenFailure(requested_service_,
7555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        GenerateAuthError(data, status));
7565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
7575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
7585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
7595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::OnClientLoginToOAuth2Fetched(
7605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& data,
7615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const net::ResponseCookies& cookies,
7625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const net::URLRequestStatus& status,
7635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    int response_code) {
7645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (status.is_success() && response_code == net::HTTP_OK) {
7655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::string auth_code;
7665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ParseClientLoginToOAuth2Response(cookies, &auth_code);
7675d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)    if (fetch_code_only_)
7685d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)      consumer_->OnClientOAuthCodeSuccess(auth_code);
7695d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)    else
7705d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)      StartAuthCodeForOAuth2TokenExchange(auth_code);
7715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
7725d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)    GoogleServiceAuthError auth_error(GenerateAuthError(data, status));
7735d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)    if (fetch_code_only_)
7745d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)      consumer_->OnClientOAuthCodeFailure(auth_error);
7755d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)    else
7765d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)      consumer_->OnClientOAuthFailure(auth_error);
7775821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
7785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
7795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
7805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::OnOAuth2TokenPairFetched(
7815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& data,
7825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const net::URLRequestStatus& status,
7835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    int response_code) {
7845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string refresh_token;
7855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string access_token;
7865821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  int expires_in_secs = 0;
7875821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
7885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  bool success = false;
7895821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (status.is_success() && response_code == net::HTTP_OK) {
7905821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    scoped_ptr<base::Value> value(base::JSONReader::Read(data));
7915821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    if (value.get() && value->GetType() == base::Value::TYPE_DICTIONARY) {
792eb525c5499e34cc9c4b825d6d9e75bb07cc06aceBen Murdoch      base::DictionaryValue* dict =
793eb525c5499e34cc9c4b825d6d9e75bb07cc06aceBen Murdoch          static_cast<base::DictionaryValue*>(value.get());
7945821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      success = ExtractOAuth2TokenPairResponse(dict, &refresh_token,
7955821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                               &access_token, &expires_in_secs);
7965821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
7975821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
7985821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
7995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (success) {
8005821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnClientOAuthSuccess(
8015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        GaiaAuthConsumer::ClientOAuthResult(refresh_token, access_token,
8025821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                            expires_in_secs));
8035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
8045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnClientOAuthFailure(GenerateAuthError(data, status));
8055821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
8065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
8075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
808c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)void GaiaAuthFetcher::OnOAuth2RevokeTokenFetched(
809c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)    const std::string& data,
810c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)    const net::URLRequestStatus& status,
811c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)    int response_code) {
812c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)  consumer_->OnOAuth2RevokeTokenCompleted();
813c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)}
814c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)
815f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)void GaiaAuthFetcher::OnListAccountsFetched(const std::string& data,
816f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)                                            const net::URLRequestStatus& status,
817f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)                                            int response_code) {
818f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  if (status.is_success() && response_code == net::HTTP_OK) {
819f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)    consumer_->OnListAccountsSuccess(data);
820f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  } else {
821f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)    consumer_->OnListAccountsFailure(GenerateAuthError(data, status));
822f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  }
823f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)}
824f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)
8255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::OnGetUserInfoFetched(
8265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& data,
8275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const net::URLRequestStatus& status,
8285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    int response_code) {
8295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (status.is_success() && response_code == net::HTTP_OK) {
8305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::vector<std::pair<std::string, std::string> > tokens;
8315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    UserInfoMap matches;
8325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    base::SplitStringIntoKeyValuePairs(data, '=', '\n', &tokens);
8335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::vector<std::pair<std::string, std::string> >::iterator i;
8345821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    for (i = tokens.begin(); i != tokens.end(); ++i) {
8355821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      matches[i->first] = i->second;
8365821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    }
8375821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnGetUserInfoSuccess(matches);
8385821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
8395821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnGetUserInfoFailure(GenerateAuthError(data, status));
8405821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
8415821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
8425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
8435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::OnMergeSessionFetched(const std::string& data,
8445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                            const net::URLRequestStatus& status,
8455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                            int response_code) {
8465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (status.is_success() && response_code == net::HTTP_OK) {
8475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnMergeSessionSuccess(data);
8485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
8495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnMergeSessionFailure(GenerateAuthError(data, status));
8505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
8515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
8525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
8535821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::OnUberAuthTokenFetch(const std::string& data,
8545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                           const net::URLRequestStatus& status,
8555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                           int response_code) {
8565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (status.is_success() && response_code == net::HTTP_OK) {
8575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnUberAuthTokenSuccess(data);
8585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
8595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnUberAuthTokenFailure(GenerateAuthError(data, status));
8605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
8615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
8625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
8635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::OnOAuthLoginFetched(const std::string& data,
8645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                          const net::URLRequestStatus& status,
8655821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)                                          int response_code) {
8665821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (status.is_success() && response_code == net::HTTP_OK) {
8675821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    DVLOG(1) << "ClientLogin successful!";
8685821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::string sid;
8695821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::string lsid;
8705821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    std::string token;
8715821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    ParseClientLoginResponse(data, &sid, &lsid, &token);
8725821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnClientLoginSuccess(
8735821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        GaiaAuthConsumer::ClientLoginResult(sid, lsid, token, data));
8745821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
8755821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    consumer_->OnClientLoginFailure(GenerateAuthError(data, status));
8765821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
8775821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
8785821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
8795821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)void GaiaAuthFetcher::OnURLFetchComplete(const net::URLFetcher* source) {
8805821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  fetch_pending_ = false;
8815821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // Some of the GAIA requests perform redirects, which results in the final
8825821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // URL of the fetcher not being the original URL requested.  Therefore use
8835821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  // the original URL when determining which OnXXX function to call.
8845821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  const GURL& url = source->GetOriginalURL();
8855821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  const net::URLRequestStatus& status = source->GetStatus();
8865821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  int response_code = source->GetResponseCode();
8875821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  std::string data;
8885821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  source->GetResponseAsString(&data);
8892a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)#ifndef NDEBUG
8902a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  std::string headers;
8912a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  if (source->GetResponseHeaders())
8922a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)    source->GetResponseHeaders()->GetNormalizedHeaders(&headers);
8932a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  DVLOG(2) << "Response " << url.spec() << ", code = " << response_code << "\n"
8942a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)           << headers << "\n";
8952a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  DVLOG(2) << "data: " << data << "\n";
8962a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)#endif
8972a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  // Retrieve the response headers from the request.  Must only be called after
8982a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)  // the OnURLFetchComplete callback has run.
8995821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  if (url == client_login_gurl_) {
9005821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    OnClientLoginFetched(data, status, response_code);
9015821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else if (url == issue_auth_token_gurl_) {
9025821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    OnIssueAuthTokenFetched(data, status, response_code);
9035821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else if (url == client_login_to_oauth2_gurl_) {
9045821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    OnClientLoginToOAuth2Fetched(
9055821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)        data, source->GetCookies(), status, response_code);
9065821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else if (url == oauth2_token_gurl_) {
9075821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    OnOAuth2TokenPairFetched(data, status, response_code);
9085821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else if (url == get_user_info_gurl_) {
9095821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    OnGetUserInfoFetched(data, status, response_code);
9105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else if (url == merge_session_gurl_) {
9115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    OnMergeSessionFetched(data, status, response_code);
9125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else if (url == uberauth_token_gurl_) {
9135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    OnUberAuthTokenFetch(data, status, response_code);
9145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else if (url == oauth_login_gurl_) {
9155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    OnOAuthLoginFetched(data, status, response_code);
916c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)  } else if (url == oauth2_revoke_gurl_) {
917c2e0dbddbe15c98d52c4786dac06cb8952a8ae6dTorne (Richard Coles)    OnOAuth2RevokeTokenFetched(data, status, response_code);
918f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)  } else if (url == list_accounts_gurl_) {
919f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)    OnListAccountsFetched(data, status, response_code);
9205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  } else {
9215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    NOTREACHED();
9225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  }
9235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
9245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)
9255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// static
9265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)bool GaiaAuthFetcher::IsSecondFactorSuccess(
9275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)    const std::string& alleged_error) {
9285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)  return alleged_error.find(kSecondFactor) !=
9295821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)      std::string::npos;
9305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}
931