// Copyright (c) 2011 The Chromium Authors. All rights reserved. // Use of this source code is governed by a BSD-style license that can be // found in the LICENSE file. #include "chrome/browser/extensions/extension_function_dispatcher.h" #include #include "base/memory/ref_counted.h" #include "base/memory/singleton.h" #include "base/process_util.h" #include "base/values.h" #include "build/build_config.h" #include "chrome/browser/extensions/execute_code_in_tab_function.h" #include "chrome/browser/extensions/extension_accessibility_api.h" #include "chrome/browser/extensions/extension_app_api.h" #include "chrome/browser/extensions/extension_bookmark_manager_api.h" #include "chrome/browser/extensions/extension_bookmarks_module.h" #include "chrome/browser/extensions/extension_browser_actions_api.h" #include "chrome/browser/extensions/extension_clear_api.h" #include "chrome/browser/extensions/extension_chrome_auth_private_api.h" #include "chrome/browser/extensions/extension_content_settings_api.h" #include "chrome/browser/extensions/extension_context_menu_api.h" #include "chrome/browser/extensions/extension_cookies_api.h" #include "chrome/browser/extensions/extension_debugger_api.h" #include "chrome/browser/extensions/extension_downloads_api.h" #include "chrome/browser/extensions/extension_function.h" #include "chrome/browser/extensions/extension_history_api.h" #include "chrome/browser/extensions/extension_i18n_api.h" #include "chrome/browser/extensions/extension_idle_api.h" #include "chrome/browser/extensions/extension_infobar_module.h" #include "chrome/browser/extensions/extension_management_api.h" #include "chrome/browser/extensions/extension_metrics_module.h" #include "chrome/browser/extensions/extension_module.h" #include "chrome/browser/extensions/extension_omnibox_api.h" #include "chrome/browser/extensions/extension_page_actions_module.h" #include "chrome/browser/extensions/extension_permissions_api.h" #include "chrome/browser/extensions/extension_preference_api.h" #include "chrome/browser/extensions/extension_processes_api.h" #include "chrome/browser/extensions/extension_proxy_api.h" #include "chrome/browser/extensions/extension_rlz_module.h" #include "chrome/browser/extensions/extension_service.h" #include "chrome/browser/extensions/extension_settings_api.h" #include "chrome/browser/extensions/extension_sidebar_api.h" #include "chrome/browser/extensions/extension_tabs_module.h" #include "chrome/browser/extensions/extension_test_api.h" #include "chrome/browser/extensions/extension_tts_api.h" #include "chrome/browser/extensions/extension_tts_engine_api.h" #include "chrome/browser/extensions/extension_web_socket_proxy_private_api.h" #include "chrome/browser/extensions/extension_web_ui.h" #include "chrome/browser/extensions/extension_webnavigation_api.h" #include "chrome/browser/extensions/extension_webrequest_api.h" #include "chrome/browser/extensions/extension_webstore_private_api.h" #include "chrome/browser/extensions/extensions_quota_service.h" #include "chrome/browser/external_protocol/external_protocol_handler.h" #include "chrome/browser/profiles/profile.h" #include "chrome/browser/renderer_host/chrome_render_message_filter.h" #include "chrome/browser/ui/browser_list.h" #include "chrome/browser/ui/browser_window.h" #include "chrome/common/extensions/extension_messages.h" #include "chrome/common/url_constants.h" #include "content/browser/child_process_security_policy.h" #include "content/browser/renderer_host/render_process_host.h" #include "content/browser/renderer_host/render_view_host.h" #include "ipc/ipc_message.h" #include "ipc/ipc_message_macros.h" #include "third_party/skia/include/core/SkBitmap.h" #if defined(TOOLKIT_VIEWS) #include "chrome/browser/extensions/extension_input_api.h" #endif #if defined(OS_CHROMEOS) && defined(TOUCH_UI) #include "chrome/browser/extensions/extension_input_ui_api.h" #endif #if defined(OS_CHROMEOS) #include "chrome/browser/extensions/extension_file_browser_private_api.h" #include "chrome/browser/extensions/extension_info_private_api_chromeos.h" #include "chrome/browser/extensions/extension_input_ime_api.h" #include "chrome/browser/extensions/extension_input_method_api.h" #include "chrome/browser/extensions/extension_mediaplayer_private_api.h" #endif // FactoryRegistry ------------------------------------------------------------- namespace { // Template for defining ExtensionFunctionFactory. template ExtensionFunction* NewExtensionFunction() { return new T(); } // Contains a list of all known extension functions and allows clients to // create instances of them. class FactoryRegistry { public: static FactoryRegistry* GetInstance(); FactoryRegistry() { ResetFunctions(); } // Resets all functions to their default values. void ResetFunctions(); // Adds all function names to 'names'. void GetAllNames(std::vector* names); // Allows overriding of specific functions (e.g. for testing). Functions // must be previously registered. Returns true if successful. bool OverrideFunction(const std::string& name, ExtensionFunctionFactory factory); // Factory method for the ExtensionFunction registered as 'name'. ExtensionFunction* NewFunction(const std::string& name); private: template void RegisterFunction() { factories_[T::function_name()] = &NewExtensionFunction; } typedef std::map FactoryMap; FactoryMap factories_; }; FactoryRegistry* FactoryRegistry::GetInstance() { return Singleton::get(); } void FactoryRegistry::ResetFunctions() { // Register all functions here. // Windows RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Tabs RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Page Actions. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Browser Actions. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Browsing Data. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Bookmarks. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Infobars. RegisterFunction(); // BookmarkManager RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // History RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Idle RegisterFunction(); // I18N. RegisterFunction(); // Processes. RegisterFunction(); // Metrics. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // RLZ. #if defined(OS_WIN) RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); #endif // Cookies. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Test. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Accessibility. RegisterFunction(); RegisterFunction(); // Text-to-speech. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Context Menus. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Omnibox. RegisterFunction(); RegisterFunction(); // Sidebar. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); #if defined(TOOLKIT_VIEWS) // Input. RegisterFunction(); #endif #if defined(TOUCH_UI) RegisterFunction(); RegisterFunction(); #endif #if defined(OS_CHROMEOS) // IME RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); #if defined(TOUCH_UI) RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); #endif #endif // Management. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Extension module. RegisterFunction(); RegisterFunction(); RegisterFunction(); // WebstorePrivate. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // WebNavigation. RegisterFunction(); // WebRequest. RegisterFunction(); RegisterFunction(); // Preferences. RegisterFunction(); RegisterFunction(); RegisterFunction(); // ChromeOS-specific part of the API. #if defined(OS_CHROMEOS) // Device Customization. RegisterFunction(); // FileBrowserPrivate functions. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Mediaplayer RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // InputMethod RegisterFunction(); #if defined(TOUCH_UI) // Input RegisterFunction(); RegisterFunction(); #endif #endif // Websocket to TCP proxy. Currently noop on anything other than ChromeOS. RegisterFunction(); // Debugger RegisterFunction(); RegisterFunction(); RegisterFunction(); // Settings RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Content settings. RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // ChromeAuth settings. RegisterFunction(); // Experimental App API. RegisterFunction(); RegisterFunction(); // Permissions RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); // Downloads RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); RegisterFunction(); } void FactoryRegistry::GetAllNames(std::vector* names) { for (FactoryMap::iterator iter = factories_.begin(); iter != factories_.end(); ++iter) { names->push_back(iter->first); } } bool FactoryRegistry::OverrideFunction(const std::string& name, ExtensionFunctionFactory factory) { FactoryMap::iterator iter = factories_.find(name); if (iter == factories_.end()) { return false; } else { iter->second = factory; return true; } } ExtensionFunction* FactoryRegistry::NewFunction(const std::string& name) { FactoryMap::iterator iter = factories_.find(name); DCHECK(iter != factories_.end()); ExtensionFunction* function = iter->second(); function->set_name(name); return function; } }; // namespace // ExtensionFunctionDispatcher ------------------------------------------------- void ExtensionFunctionDispatcher::GetAllFunctionNames( std::vector* names) { FactoryRegistry::GetInstance()->GetAllNames(names); } bool ExtensionFunctionDispatcher::OverrideFunction( const std::string& name, ExtensionFunctionFactory factory) { return FactoryRegistry::GetInstance()->OverrideFunction(name, factory); } void ExtensionFunctionDispatcher::ResetFunctions() { FactoryRegistry::GetInstance()->ResetFunctions(); } // static void ExtensionFunctionDispatcher::DispatchOnIOThread( const ExtensionInfoMap* extension_info_map, void* profile, int render_process_id, base::WeakPtr ipc_sender, int routing_id, const ExtensionHostMsg_Request_Params& params) { const Extension* extension = extension_info_map->extensions().GetByURL(params.source_url); scoped_refptr function( CreateExtensionFunction(params, extension, profile, render_process_id, ipc_sender, routing_id)); if (!function) return; IOThreadExtensionFunction* function_io = function->AsIOThreadExtensionFunction(); if (!function_io) { NOTREACHED(); return; } function_io->set_ipc_sender(ipc_sender, routing_id); function_io->set_extension_info_map(extension_info_map); function->set_include_incognito( extension_info_map->IsIncognitoEnabled(extension->id())); function->Run(); } ExtensionFunctionDispatcher::ExtensionFunctionDispatcher(Profile* profile, Delegate* delegate) : profile_(profile), delegate_(delegate) { } ExtensionFunctionDispatcher::~ExtensionFunctionDispatcher() { } Browser* ExtensionFunctionDispatcher::GetCurrentBrowser( RenderViewHost* render_view_host, bool include_incognito) { Browser* browser = delegate_->GetBrowser(); // If the delegate has an associated browser, that is always the right answer. if (browser) return browser; // Otherwise, try to default to a reasonable browser. If |include_incognito| // is true, we will also search browsers in the incognito version of this // profile. Note that the profile may already be incognito, in which case // we will search the incognito version only, regardless of the value of // |include_incognito|. Profile* profile = Profile::FromBrowserContext( render_view_host->process()->browser_context()); browser = BrowserList::FindTabbedBrowser(profile, include_incognito); // NOTE(rafaelw): This can return NULL in some circumstances. In particular, // a background_page onload chrome.tabs api call can make it into here // before the browser is sufficiently initialized to return here. // A similar situation may arise during shutdown. // TODO(rafaelw): Delay creation of background_page until the browser // is available. http://code.google.com/p/chromium/issues/detail?id=13284 return browser; } void ExtensionFunctionDispatcher::Dispatch( const ExtensionHostMsg_Request_Params& params, RenderViewHost* render_view_host) { ExtensionService* service = profile()->GetExtensionService(); if (!service) return; if (!service->ExtensionBindingsAllowed(params.source_url)) { LOG(ERROR) << "Extension bindings not allowed for URL: " << params.source_url.spec(); SendAccessDenied(render_view_host, render_view_host->routing_id(), params.request_id); return; } // TODO(aa): When we allow content scripts to call extension APIs, we will // have to pass the extension ID explicitly here, not use the source URL. const Extension* extension = service->GetExtensionByURL(params.source_url); if (!extension) extension = service->GetExtensionByWebExtent(params.source_url); scoped_refptr function(CreateExtensionFunction( params, extension, profile_, render_view_host->process()->id(), render_view_host, render_view_host->routing_id())); if (!function) return; UIThreadExtensionFunction* function_ui = function->AsUIThreadExtensionFunction(); if (!function_ui) { NOTREACHED(); return; } function_ui->SetRenderViewHost(render_view_host); function_ui->set_dispatcher(AsWeakPtr()); function_ui->set_profile(profile_); function->set_include_incognito(service->CanCrossIncognito(extension)); ExtensionsQuotaService* quota = service->quota_service(); if (quota->Assess(extension->id(), function, ¶ms.arguments, base::TimeTicks::Now())) { // See crbug.com/39178. ExternalProtocolHandler::PermitLaunchUrl(); function->Run(); } else { render_view_host->Send(new ExtensionMsg_Response( render_view_host->routing_id(), function->request_id(), false, std::string(), QuotaLimitHeuristic::kGenericOverQuotaError)); } } // static ExtensionFunction* ExtensionFunctionDispatcher::CreateExtensionFunction( const ExtensionHostMsg_Request_Params& params, const Extension* extension, void* profile, int render_process_id, IPC::Message::Sender* ipc_sender, int routing_id) { // TODO(aa): It would be cool to use ExtensionProcessManager to track which // processes are extension processes rather than ChildProcessSecurityPolicy. // EPM has richer information: it not only knows which processes contain // at least one extension, but it knows which extensions are inside and what // permissions the have. So we would be able to enforce permissions more // granularly. if (!ChildProcessSecurityPolicy::GetInstance()->HasExtensionBindings( render_process_id)) { // TODO(aa): Allow content scripts access to low-threat extension APIs. // See: crbug.com/80308. LOG(ERROR) << "Extension API called from non-extension process."; SendAccessDenied(ipc_sender, routing_id, params.request_id); return NULL; } if (!extension) { LOG(ERROR) << "Extension does not exist for URL: " << params.source_url.spec(); SendAccessDenied(ipc_sender, routing_id, params.request_id); return NULL; } if (!extension->HasAPIPermission(params.name)) { LOG(ERROR) << "Extension " << extension->id() << " does not have " << "permission to function: " << params.name; SendAccessDenied(ipc_sender, routing_id, params.request_id); return NULL; } ExtensionFunction* function = FactoryRegistry::GetInstance()->NewFunction(params.name); function->SetArgs(¶ms.arguments); function->set_source_url(params.source_url); function->set_request_id(params.request_id); function->set_has_callback(params.has_callback); function->set_user_gesture(params.user_gesture); function->set_extension(extension); function->set_profile(profile); return function; } // static void ExtensionFunctionDispatcher::SendAccessDenied( IPC::Message::Sender* ipc_sender, int routing_id, int request_id) { ipc_sender->Send(new ExtensionMsg_Response( routing_id, request_id, false, std::string(), "Access to extension API denied.")); }