#include "config.h"
#include "PolicyChecker.h"
#include "ContentFilter.h"
#include "ContentSecurityPolicy.h"
#include "DOMWindow.h"
#include "DocumentLoader.h"
#include "Event.h"
#include "EventNames.h"
#include "FormState.h"
#include "Frame.h"
#include "FrameLoader.h"
#include "FrameLoaderClient.h"
#include "HTMLFormElement.h"
#include "HTMLFrameOwnerElement.h"
#include "HTMLPlugInElement.h"
#include <wtf/CompletionHandler.h>
#if USE(QUICK_LOOK)
#include "QuickLook.h"
#endif
namespace WebCore {
static bool isAllowedByContentSecurityPolicy(const URL& url, const Element* ownerElement, bool didReceiveRedirectResponse)
{
if (!ownerElement)
return true;
if (ownerElement->isInUserAgentShadowTree())
return true;
auto redirectResponseReceived = didReceiveRedirectResponse ? ContentSecurityPolicy::RedirectResponseReceived::Yes : ContentSecurityPolicy::RedirectResponseReceived::No;
ASSERT(ownerElement->document().contentSecurityPolicy());
if (is<HTMLPlugInElement>(ownerElement))
return ownerElement->document().contentSecurityPolicy()->allowObjectFromSource(url, redirectResponseReceived);
return ownerElement->document().contentSecurityPolicy()->allowChildFrameFromSource(url, redirectResponseReceived);
}
PolicyChecker::PolicyChecker(Frame& frame)
: m_frame(frame)
, m_delegateIsDecidingNavigationPolicy(false)
, m_delegateIsHandlingUnimplementablePolicy(false)
, m_loadType(FrameLoadType::Standard)
{
}
void PolicyChecker::checkNavigationPolicy(ResourceRequest&& newRequest, bool didReceiveRedirectResponse, NavigationPolicyDecisionFunction&& function)
{
checkNavigationPolicy(WTFMove(newRequest), didReceiveRedirectResponse, m_frame.loader().activeDocumentLoader(), nullptr, WTFMove(function));
}
void PolicyChecker::checkNavigationPolicy(ResourceRequest&& request, bool didReceiveRedirectResponse, DocumentLoader* loader, FormState* formState, NavigationPolicyDecisionFunction&& function)
{
NavigationAction action = loader->triggeringAction();
if (action.isEmpty()) {
action = NavigationAction { *m_frame.document(), request, InitiatedByMainFrame::Unknown, NavigationType::Other, loader->shouldOpenExternalURLsPolicyToPropagate() };
loader->setTriggeringAction(action);
}
if (equalIgnoringHeaderFields(request, loader->lastCheckedRequest()) || (!request.isNull() && request.url().isEmpty())) {
function(ResourceRequest(request), nullptr, true);
loader->setLastCheckedRequest(WTFMove(request));
return;
}
auto& substituteData = loader->substituteData();
if (substituteData.isValid() && !substituteData.failingURL().isEmpty()) {
bool shouldContinue = true;
#if ENABLE(CONTENT_FILTERING)
shouldContinue = ContentFilter::continueAfterSubstituteDataRequest(*m_frame.loader().activeDocumentLoader(), substituteData);
#endif
if (isBackForwardLoadType(m_loadType))
m_loadType = FrameLoadType::Reload;
function(WTFMove(request), nullptr, shouldContinue);
return;
}
if (!isAllowedByContentSecurityPolicy(request.url(), m_frame.ownerElement(), didReceiveRedirectResponse)) {
if (m_frame.ownerElement()) {
m_frame.ownerElement()->dispatchEvent(Event::create(eventNames().loadEvent, false, false));
}
function(WTFMove(request), nullptr, false);
return;
}
loader->setLastCheckedRequest(ResourceRequest(request));
#if USE(QUICK_LOOK)
if (!request.isNull() && isQuickLookPreviewURL(request.url()))
return function(WTFMove(request), formState, true);
#endif
#if ENABLE(CONTENT_FILTERING)
if (m_contentFilterUnblockHandler.canHandleRequest(request)) {
RefPtr<Frame> frame { &m_frame };
m_contentFilterUnblockHandler.requestUnblockAsync([frame](bool unblocked) {
if (unblocked)
frame->loader().reload();
});
return function({ }, nullptr, false);
}
m_contentFilterUnblockHandler = { };
#endif
m_delegateIsDecidingNavigationPolicy = true;
String suggestedFilename = action.downloadAttribute().isEmpty() ? nullAtom() : action.downloadAttribute();
ResourceRequest requestCopy = request;
m_frame.loader().client().dispatchDecidePolicyForNavigationAction(action, request, didReceiveRedirectResponse, formState, [this, function = WTFMove(function), request = WTFMove(requestCopy), formState = makeRefPtr(formState), suggestedFilename = WTFMove(suggestedFilename)](PolicyAction policyAction) mutable {
switch (policyAction) {
case PolicyAction::Download:
m_frame.loader().setOriginalURLForDownloadRequest(request);
m_frame.loader().client().startDownload(request, suggestedFilename);
FALLTHROUGH;
case PolicyAction::Ignore:
return function({ }, nullptr, false);
case PolicyAction::Use:
if (!m_frame.loader().client().canHandleRequest(request)) {
handleUnimplementablePolicy(m_frame.loader().client().cannotShowURLError(request));
return function({ }, nullptr, false);
}
return function(WTFMove(request), formState.get(), true);
}
ASSERT_NOT_REACHED();
});
m_delegateIsDecidingNavigationPolicy = false;
}
void PolicyChecker::checkNewWindowPolicy(NavigationAction&& navigationAction, const ResourceRequest& request, FormState* formState, const String& frameName, NewWindowPolicyDecisionFunction&& function)
{
if (m_frame.document() && m_frame.document()->isSandboxed(SandboxPopups))
return function({ }, nullptr, { }, { }, false);
if (!DOMWindow::allowPopUp(m_frame))
return function({ }, nullptr, { }, { }, false);
m_frame.loader().client().dispatchDecidePolicyForNewWindowAction(navigationAction, request, formState, frameName, [frame = makeRef(m_frame), request, formState = makeRefPtr(formState), frameName, navigationAction, function = WTFMove(function)](PolicyAction policyAction) mutable {
switch (policyAction) {
case PolicyAction::Download:
frame->loader().client().startDownload(request);
FALLTHROUGH;
case PolicyAction::Ignore:
function({ }, nullptr, { }, { }, false);
return;
case PolicyAction::Use:
function(request, formState.get(), frameName, navigationAction, true);
return;
}
ASSERT_NOT_REACHED();
});
}
void PolicyChecker::stopCheck()
{
m_frame.loader().client().cancelPolicyCheck();
}
void PolicyChecker::cannotShowMIMEType(const ResourceResponse& response)
{
handleUnimplementablePolicy(m_frame.loader().client().cannotShowMIMETypeError(response));
}
void PolicyChecker::handleUnimplementablePolicy(const ResourceError& error)
{
m_delegateIsHandlingUnimplementablePolicy = true;
m_frame.loader().client().dispatchUnableToImplementPolicy(error);
m_delegateIsHandlingUnimplementablePolicy = false;
}
}