xref: /aosp_15_r20/external/cronet/url/origin.h (revision 6777b5387eb2ff775bb5750e3f5d96f37fb7352b)
1*6777b538SAndroid Build Coastguard Worker // Copyright 2015 The Chromium Authors
2*6777b538SAndroid Build Coastguard Worker // Use of this source code is governed by a BSD-style license that can be
3*6777b538SAndroid Build Coastguard Worker // found in the LICENSE file.
4*6777b538SAndroid Build Coastguard Worker 
5*6777b538SAndroid Build Coastguard Worker #ifndef URL_ORIGIN_H_
6*6777b538SAndroid Build Coastguard Worker #define URL_ORIGIN_H_
7*6777b538SAndroid Build Coastguard Worker 
8*6777b538SAndroid Build Coastguard Worker #include <stdint.h>
9*6777b538SAndroid Build Coastguard Worker 
10*6777b538SAndroid Build Coastguard Worker #include <memory>
11*6777b538SAndroid Build Coastguard Worker #include <optional>
12*6777b538SAndroid Build Coastguard Worker #include <string>
13*6777b538SAndroid Build Coastguard Worker #include <string_view>
14*6777b538SAndroid Build Coastguard Worker 
15*6777b538SAndroid Build Coastguard Worker #include "base/component_export.h"
16*6777b538SAndroid Build Coastguard Worker #include "base/debug/alias.h"
17*6777b538SAndroid Build Coastguard Worker #include "base/debug/crash_logging.h"
18*6777b538SAndroid Build Coastguard Worker #include "base/gtest_prod_util.h"
19*6777b538SAndroid Build Coastguard Worker #include "base/strings/string_util.h"
20*6777b538SAndroid Build Coastguard Worker #include "base/trace_event/base_tracing_forward.h"
21*6777b538SAndroid Build Coastguard Worker #include "base/unguessable_token.h"
22*6777b538SAndroid Build Coastguard Worker #include "build/build_config.h"
23*6777b538SAndroid Build Coastguard Worker #include "build/buildflag.h"
24*6777b538SAndroid Build Coastguard Worker #include "build/robolectric_buildflags.h"
25*6777b538SAndroid Build Coastguard Worker #include "url/scheme_host_port.h"
26*6777b538SAndroid Build Coastguard Worker 
27*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_ANDROID) || BUILDFLAG(IS_ROBOLECTRIC)
28*6777b538SAndroid Build Coastguard Worker #include "base/android/jni_android.h"
29*6777b538SAndroid Build Coastguard Worker #endif
30*6777b538SAndroid Build Coastguard Worker 
31*6777b538SAndroid Build Coastguard Worker class GURL;
32*6777b538SAndroid Build Coastguard Worker 
33*6777b538SAndroid Build Coastguard Worker namespace blink {
34*6777b538SAndroid Build Coastguard Worker class SecurityOrigin;
35*6777b538SAndroid Build Coastguard Worker class SecurityOriginTest;
36*6777b538SAndroid Build Coastguard Worker class StorageKey;
37*6777b538SAndroid Build Coastguard Worker class StorageKeyTest;
38*6777b538SAndroid Build Coastguard Worker }  // namespace blink
39*6777b538SAndroid Build Coastguard Worker 
40*6777b538SAndroid Build Coastguard Worker namespace content {
41*6777b538SAndroid Build Coastguard Worker class SiteInfo;
42*6777b538SAndroid Build Coastguard Worker }  // namespace content
43*6777b538SAndroid Build Coastguard Worker 
44*6777b538SAndroid Build Coastguard Worker namespace IPC {
45*6777b538SAndroid Build Coastguard Worker template <class P>
46*6777b538SAndroid Build Coastguard Worker struct ParamTraits;
47*6777b538SAndroid Build Coastguard Worker }  // namespace IPC
48*6777b538SAndroid Build Coastguard Worker 
49*6777b538SAndroid Build Coastguard Worker namespace ipc_fuzzer {
50*6777b538SAndroid Build Coastguard Worker template <class T>
51*6777b538SAndroid Build Coastguard Worker struct FuzzTraits;
52*6777b538SAndroid Build Coastguard Worker }  // namespace ipc_fuzzer
53*6777b538SAndroid Build Coastguard Worker 
54*6777b538SAndroid Build Coastguard Worker namespace mojo {
55*6777b538SAndroid Build Coastguard Worker template <typename DataViewType, typename T>
56*6777b538SAndroid Build Coastguard Worker struct StructTraits;
57*6777b538SAndroid Build Coastguard Worker struct UrlOriginAdapter;
58*6777b538SAndroid Build Coastguard Worker }  // namespace mojo
59*6777b538SAndroid Build Coastguard Worker 
60*6777b538SAndroid Build Coastguard Worker namespace net {
61*6777b538SAndroid Build Coastguard Worker class SchemefulSite;
62*6777b538SAndroid Build Coastguard Worker }  // namespace net
63*6777b538SAndroid Build Coastguard Worker 
64*6777b538SAndroid Build Coastguard Worker namespace url {
65*6777b538SAndroid Build Coastguard Worker 
66*6777b538SAndroid Build Coastguard Worker namespace mojom {
67*6777b538SAndroid Build Coastguard Worker class OriginDataView;
68*6777b538SAndroid Build Coastguard Worker }  // namespace mojom
69*6777b538SAndroid Build Coastguard Worker 
70*6777b538SAndroid Build Coastguard Worker // Per https://html.spec.whatwg.org/multipage/origin.html#origin, an origin is
71*6777b538SAndroid Build Coastguard Worker // either:
72*6777b538SAndroid Build Coastguard Worker // - a tuple origin of (scheme, host, port) as described in RFC 6454.
73*6777b538SAndroid Build Coastguard Worker // - an opaque origin with an internal value, and a memory of the tuple origin
74*6777b538SAndroid Build Coastguard Worker //   from which it was derived.
75*6777b538SAndroid Build Coastguard Worker //
76*6777b538SAndroid Build Coastguard Worker // TL;DR: If you need to make a security-relevant decision, use 'url::Origin'.
77*6777b538SAndroid Build Coastguard Worker // If you only need to extract the bits of a URL which are relevant for a
78*6777b538SAndroid Build Coastguard Worker // network connection, use 'url::SchemeHostPort'.
79*6777b538SAndroid Build Coastguard Worker //
80*6777b538SAndroid Build Coastguard Worker // STL;SDR: If you aren't making actual network connections, use 'url::Origin'.
81*6777b538SAndroid Build Coastguard Worker //
82*6777b538SAndroid Build Coastguard Worker // This class ought to be used when code needs to determine if two resources
83*6777b538SAndroid Build Coastguard Worker // are "same-origin", and when a canonical serialization of an origin is
84*6777b538SAndroid Build Coastguard Worker // required. Note that the canonical serialization of an origin *must not* be
85*6777b538SAndroid Build Coastguard Worker // used to determine if two resources are same-origin.
86*6777b538SAndroid Build Coastguard Worker //
87*6777b538SAndroid Build Coastguard Worker // A tuple origin, like 'SchemeHostPort', is composed of a tuple of (scheme,
88*6777b538SAndroid Build Coastguard Worker // host, port), but contains a number of additional concepts which make it
89*6777b538SAndroid Build Coastguard Worker // appropriate for use as a security boundary and access control mechanism
90*6777b538SAndroid Build Coastguard Worker // between contexts. Two tuple origins are same-origin if the tuples are equal.
91*6777b538SAndroid Build Coastguard Worker // A tuple origin may also be re-created from its serialization.
92*6777b538SAndroid Build Coastguard Worker //
93*6777b538SAndroid Build Coastguard Worker // An opaque origin has an internal globally unique identifier. When creating a
94*6777b538SAndroid Build Coastguard Worker // new opaque origin from a URL, a fresh globally unique identifier is
95*6777b538SAndroid Build Coastguard Worker // generated. However, if an opaque origin is copied or moved, the internal
96*6777b538SAndroid Build Coastguard Worker // globally unique identifier is preserved. Two opaque origins are same-origin
97*6777b538SAndroid Build Coastguard Worker // iff the globally unique identifiers match. Unlike tuple origins, an opaque
98*6777b538SAndroid Build Coastguard Worker // origin cannot be re-created from its serialization, which is always the
99*6777b538SAndroid Build Coastguard Worker // string "null".
100*6777b538SAndroid Build Coastguard Worker //
101*6777b538SAndroid Build Coastguard Worker // IMPORTANT: Since opaque origins always serialize as the string "null", it is
102*6777b538SAndroid Build Coastguard Worker // *never* safe to use the serialization for security checks!
103*6777b538SAndroid Build Coastguard Worker //
104*6777b538SAndroid Build Coastguard Worker // A tuple origin and an opaque origin are never same-origin.
105*6777b538SAndroid Build Coastguard Worker //
106*6777b538SAndroid Build Coastguard Worker // There are a few subtleties to note:
107*6777b538SAndroid Build Coastguard Worker //
108*6777b538SAndroid Build Coastguard Worker // * A default constructed Origin is opaque, with no precursor origin.
109*6777b538SAndroid Build Coastguard Worker //
110*6777b538SAndroid Build Coastguard Worker // * Invalid and non-standard GURLs are parsed as opaque origins. This includes
111*6777b538SAndroid Build Coastguard Worker //   non-hierarchical URLs like 'data:text/html,...' and 'javascript:alert(1)'.
112*6777b538SAndroid Build Coastguard Worker //
113*6777b538SAndroid Build Coastguard Worker // * GURLs with schemes of 'filesystem' or 'blob' parse the origin out of the
114*6777b538SAndroid Build Coastguard Worker //   internals of the URL. That is, 'filesystem:https://example.com/temporary/f'
115*6777b538SAndroid Build Coastguard Worker //   is parsed as ('https', 'example.com', 443).
116*6777b538SAndroid Build Coastguard Worker //
117*6777b538SAndroid Build Coastguard Worker // * GURLs with a 'file' scheme are tricky. They are parsed as ('file', '', 0),
118*6777b538SAndroid Build Coastguard Worker //   but their behavior may differ from embedder to embedder.
119*6777b538SAndroid Build Coastguard Worker //   TODO(dcheng): This behavior is not consistent with Blink's notion of file
120*6777b538SAndroid Build Coastguard Worker //   URLs, which always creates an opaque origin.
121*6777b538SAndroid Build Coastguard Worker //
122*6777b538SAndroid Build Coastguard Worker // * The host component of an IPv6 address includes brackets, just like the URL
123*6777b538SAndroid Build Coastguard Worker //   representation.
124*6777b538SAndroid Build Coastguard Worker //
125*6777b538SAndroid Build Coastguard Worker // * Constructing origins from GURLs (or from SchemeHostPort) is typically a red
126*6777b538SAndroid Build Coastguard Worker //   flag (this is true for `url::Origin::Create` but also to some extent for
127*6777b538SAndroid Build Coastguard Worker //   `url::Origin::Resolve`). See docs/security/origin-vs-url.md for more.
128*6777b538SAndroid Build Coastguard Worker //
129*6777b538SAndroid Build Coastguard Worker // * To answer the question "Are |this| and |that| "same-origin" with each
130*6777b538SAndroid Build Coastguard Worker //   other?", use |Origin::IsSameOriginWith|:
131*6777b538SAndroid Build Coastguard Worker //
132*6777b538SAndroid Build Coastguard Worker //     if (this.IsSameOriginWith(that)) {
133*6777b538SAndroid Build Coastguard Worker //       // Amazingness goes here.
134*6777b538SAndroid Build Coastguard Worker //     }
COMPONENT_EXPORT(URL)135*6777b538SAndroid Build Coastguard Worker class COMPONENT_EXPORT(URL) Origin {
136*6777b538SAndroid Build Coastguard Worker  public:
137*6777b538SAndroid Build Coastguard Worker   // Creates an opaque Origin with a nonce that is different from all previously
138*6777b538SAndroid Build Coastguard Worker   // existing origins.
139*6777b538SAndroid Build Coastguard Worker   Origin();
140*6777b538SAndroid Build Coastguard Worker 
141*6777b538SAndroid Build Coastguard Worker   // WARNING: Converting an URL into an Origin is usually a red flag. See
142*6777b538SAndroid Build Coastguard Worker   // //docs/security/origin-vs-url.md for more details. Some discussion about
143*6777b538SAndroid Build Coastguard Worker   // deprecating the Create method can be found in https://crbug.com/1270878.
144*6777b538SAndroid Build Coastguard Worker   //
145*6777b538SAndroid Build Coastguard Worker   // Creates an Origin from `url`, as described at
146*6777b538SAndroid Build Coastguard Worker   // https://url.spec.whatwg.org/#origin, with the following additions:
147*6777b538SAndroid Build Coastguard Worker   // 1. If `url` is invalid or non-standard, an opaque Origin is constructed.
148*6777b538SAndroid Build Coastguard Worker   // 2. 'filesystem' URLs behave as 'blob' URLs (that is, the origin is parsed
149*6777b538SAndroid Build Coastguard Worker   //    out of everything in the URL which follows the scheme).
150*6777b538SAndroid Build Coastguard Worker   // 3. 'file' URLs all parse as ("file", "", 0).
151*6777b538SAndroid Build Coastguard Worker   //
152*6777b538SAndroid Build Coastguard Worker   // WARNING: `url::Origin::Create(url)` can give unexpected results if:
153*6777b538SAndroid Build Coastguard Worker   // 1) `url` is "about:blank", or "about:srcdoc" (returning unique, opaque
154*6777b538SAndroid Build Coastguard Worker   //    origin rather than the real origin of the frame)
155*6777b538SAndroid Build Coastguard Worker   // 2) `url` comes from a sandboxed frame (potentially returning a non-opaque
156*6777b538SAndroid Build Coastguard Worker   //    origin, when an opaque one is needed; see also
157*6777b538SAndroid Build Coastguard Worker   //    https://www.html5rocks.com/en/tutorials/security/sandboxed-iframes/)
158*6777b538SAndroid Build Coastguard Worker   // 3) Wrong `url` is used - e.g. in some navigations `base_url_for_data_url`
159*6777b538SAndroid Build Coastguard Worker   //    might need to be used instead of relying on
160*6777b538SAndroid Build Coastguard Worker   //    `content::NavigationHandle::GetURL`.
161*6777b538SAndroid Build Coastguard Worker   //
162*6777b538SAndroid Build Coastguard Worker   // WARNING: The returned Origin may have a different scheme and host from
163*6777b538SAndroid Build Coastguard Worker   // `url` (e.g. in case of blob URLs - see OriginTest.ConstructFromGURL).
164*6777b538SAndroid Build Coastguard Worker   //
165*6777b538SAndroid Build Coastguard Worker   // WARNING: data: URLs will be correctly be translated into opaque origins,
166*6777b538SAndroid Build Coastguard Worker   // but the precursor origin will be lost (unlike with `url::Origin::Resolve`).
167*6777b538SAndroid Build Coastguard Worker   static Origin Create(const GURL& url);
168*6777b538SAndroid Build Coastguard Worker 
169*6777b538SAndroid Build Coastguard Worker   // Creates an Origin for the resource `url` as if it were requested
170*6777b538SAndroid Build Coastguard Worker   // from the context of `base_origin`. If `url` is standard
171*6777b538SAndroid Build Coastguard Worker   // (in the sense that it embeds a complete origin, like http/https),
172*6777b538SAndroid Build Coastguard Worker   // this returns the same value as would Create().
173*6777b538SAndroid Build Coastguard Worker   //
174*6777b538SAndroid Build Coastguard Worker   // If `url` is "about:blank" or "about:srcdoc", this returns a copy of
175*6777b538SAndroid Build Coastguard Worker   // `base_origin`.
176*6777b538SAndroid Build Coastguard Worker   //
177*6777b538SAndroid Build Coastguard Worker   // Otherwise, returns a new opaque origin derived from `base_origin`.
178*6777b538SAndroid Build Coastguard Worker   // In this case, the resulting opaque origin will inherit the tuple
179*6777b538SAndroid Build Coastguard Worker   // (or precursor tuple) of `base_origin`, but will not be same origin
180*6777b538SAndroid Build Coastguard Worker   // with `base_origin`, even if `base_origin` is already opaque.
181*6777b538SAndroid Build Coastguard Worker   static Origin Resolve(const GURL& url, const Origin& base_origin);
182*6777b538SAndroid Build Coastguard Worker 
183*6777b538SAndroid Build Coastguard Worker   // Copyable and movable.
184*6777b538SAndroid Build Coastguard Worker   Origin(const Origin&);
185*6777b538SAndroid Build Coastguard Worker   Origin& operator=(const Origin&);
186*6777b538SAndroid Build Coastguard Worker   Origin(Origin&&) noexcept;
187*6777b538SAndroid Build Coastguard Worker   Origin& operator=(Origin&&) noexcept;
188*6777b538SAndroid Build Coastguard Worker 
189*6777b538SAndroid Build Coastguard Worker   // Creates an Origin from a |scheme|, |host|, and |port|. All the parameters
190*6777b538SAndroid Build Coastguard Worker   // must be valid and canonicalized. Returns nullopt if any parameter is not
191*6777b538SAndroid Build Coastguard Worker   // canonical, or if all the parameters are empty.
192*6777b538SAndroid Build Coastguard Worker   //
193*6777b538SAndroid Build Coastguard Worker   // This constructor should be used in order to pass 'Origin' objects back and
194*6777b538SAndroid Build Coastguard Worker   // forth over IPC (as transitioning through GURL would risk potentially
195*6777b538SAndroid Build Coastguard Worker   // dangerous recanonicalization); other potential callers should prefer the
196*6777b538SAndroid Build Coastguard Worker   // 'GURL'-based constructor.
197*6777b538SAndroid Build Coastguard Worker   static std::optional<Origin> UnsafelyCreateTupleOriginWithoutNormalization(
198*6777b538SAndroid Build Coastguard Worker       std::string_view scheme,
199*6777b538SAndroid Build Coastguard Worker       std::string_view host,
200*6777b538SAndroid Build Coastguard Worker       uint16_t port);
201*6777b538SAndroid Build Coastguard Worker 
202*6777b538SAndroid Build Coastguard Worker   // Creates an origin without sanity checking that the host is canonicalized.
203*6777b538SAndroid Build Coastguard Worker   // This should only be used when converting between already normalized types,
204*6777b538SAndroid Build Coastguard Worker   // and should NOT be used for IPC. Method takes std::strings for use with move
205*6777b538SAndroid Build Coastguard Worker   // operators to avoid copies.
206*6777b538SAndroid Build Coastguard Worker   static Origin CreateFromNormalizedTuple(std::string scheme,
207*6777b538SAndroid Build Coastguard Worker                                           std::string host,
208*6777b538SAndroid Build Coastguard Worker                                           uint16_t port);
209*6777b538SAndroid Build Coastguard Worker 
210*6777b538SAndroid Build Coastguard Worker   ~Origin();
211*6777b538SAndroid Build Coastguard Worker 
212*6777b538SAndroid Build Coastguard Worker   // For opaque origins, these return ("", "", 0).
213*6777b538SAndroid Build Coastguard Worker   const std::string& scheme() const {
214*6777b538SAndroid Build Coastguard Worker     return !opaque() ? tuple_.scheme() : base::EmptyString();
215*6777b538SAndroid Build Coastguard Worker   }
216*6777b538SAndroid Build Coastguard Worker   const std::string& host() const {
217*6777b538SAndroid Build Coastguard Worker     return !opaque() ? tuple_.host() : base::EmptyString();
218*6777b538SAndroid Build Coastguard Worker   }
219*6777b538SAndroid Build Coastguard Worker   uint16_t port() const { return !opaque() ? tuple_.port() : 0; }
220*6777b538SAndroid Build Coastguard Worker 
221*6777b538SAndroid Build Coastguard Worker   bool opaque() const { return nonce_.has_value(); }
222*6777b538SAndroid Build Coastguard Worker 
223*6777b538SAndroid Build Coastguard Worker   // An ASCII serialization of the Origin as per Section 6.2 of RFC 6454, with
224*6777b538SAndroid Build Coastguard Worker   // the addition that all Origins with a 'file' scheme serialize to "file://".
225*6777b538SAndroid Build Coastguard Worker   std::string Serialize() const;
226*6777b538SAndroid Build Coastguard Worker 
227*6777b538SAndroid Build Coastguard Worker   // Two non-opaque Origins are "same-origin" if their schemes, hosts, and ports
228*6777b538SAndroid Build Coastguard Worker   // are exact matches. Two opaque origins are same-origin only if their
229*6777b538SAndroid Build Coastguard Worker   // internal nonce values match. A non-opaque origin is never same-origin with
230*6777b538SAndroid Build Coastguard Worker   // an opaque origin.
231*6777b538SAndroid Build Coastguard Worker   bool IsSameOriginWith(const Origin& other) const;
232*6777b538SAndroid Build Coastguard Worker   bool operator==(const Origin& other) const { return IsSameOriginWith(other); }
233*6777b538SAndroid Build Coastguard Worker   bool operator!=(const Origin& other) const {
234*6777b538SAndroid Build Coastguard Worker     return !IsSameOriginWith(other);
235*6777b538SAndroid Build Coastguard Worker   }
236*6777b538SAndroid Build Coastguard Worker 
237*6777b538SAndroid Build Coastguard Worker   // Non-opaque origin is "same-origin" with `url` if their schemes, hosts, and
238*6777b538SAndroid Build Coastguard Worker   // ports are exact matches. Opaque origin is never "same-origin" with any
239*6777b538SAndroid Build Coastguard Worker   // `url`.  about:blank, about:srcdoc, and invalid GURLs are never
240*6777b538SAndroid Build Coastguard Worker   // "same-origin" with any origin. This method is a shorthand for
241*6777b538SAndroid Build Coastguard Worker   // `origin.IsSameOriginWith(url::Origin::Create(url))`.
242*6777b538SAndroid Build Coastguard Worker   //
243*6777b538SAndroid Build Coastguard Worker   // See also CanBeDerivedFrom.
244*6777b538SAndroid Build Coastguard Worker   bool IsSameOriginWith(const GURL& url) const;
245*6777b538SAndroid Build Coastguard Worker 
246*6777b538SAndroid Build Coastguard Worker   // This method returns true for any |url| which if navigated to could result
247*6777b538SAndroid Build Coastguard Worker   // in an origin compatible with |this|.
248*6777b538SAndroid Build Coastguard Worker   bool CanBeDerivedFrom(const GURL& url) const;
249*6777b538SAndroid Build Coastguard Worker 
250*6777b538SAndroid Build Coastguard Worker   // Get the scheme, host, and port from which this origin derives. For
251*6777b538SAndroid Build Coastguard Worker   // a tuple Origin, this gives the same values as calling scheme(), host()
252*6777b538SAndroid Build Coastguard Worker   // and port(). For an opaque Origin that was created by calling
253*6777b538SAndroid Build Coastguard Worker   // Origin::DeriveNewOpaqueOrigin() on a precursor or Origin::Resolve(),
254*6777b538SAndroid Build Coastguard Worker   // this returns the tuple inherited from the precursor.
255*6777b538SAndroid Build Coastguard Worker   //
256*6777b538SAndroid Build Coastguard Worker   // If this Origin is opaque and was created via the default constructor or
257*6777b538SAndroid Build Coastguard Worker   // Origin::Create(), the precursor origin is unknown.
258*6777b538SAndroid Build Coastguard Worker   //
259*6777b538SAndroid Build Coastguard Worker   // Use with great caution: opaque origins should generally not inherit
260*6777b538SAndroid Build Coastguard Worker   // privileges from the origins they derive from. However, in some cases
261*6777b538SAndroid Build Coastguard Worker   // (such as restrictions on process placement, or determining the http lock
262*6777b538SAndroid Build Coastguard Worker   // icon) this information may be relevant to ensure that entering an
263*6777b538SAndroid Build Coastguard Worker   // opaque origin does not grant privileges initially denied to the original
264*6777b538SAndroid Build Coastguard Worker   // non-opaque origin.
265*6777b538SAndroid Build Coastguard Worker   //
266*6777b538SAndroid Build Coastguard Worker   // This method has a deliberately obnoxious name to prompt caution in its use.
267*6777b538SAndroid Build Coastguard Worker   const SchemeHostPort& GetTupleOrPrecursorTupleIfOpaque() const {
268*6777b538SAndroid Build Coastguard Worker     return tuple_;
269*6777b538SAndroid Build Coastguard Worker   }
270*6777b538SAndroid Build Coastguard Worker 
271*6777b538SAndroid Build Coastguard Worker   // Efficiently returns what GURL(Serialize()) would without re-parsing the
272*6777b538SAndroid Build Coastguard Worker   // URL. This can be used for the (rare) times a GURL representation is needed
273*6777b538SAndroid Build Coastguard Worker   // for an Origin.
274*6777b538SAndroid Build Coastguard Worker   // Note: The returned URL will not necessarily be serialized to the same value
275*6777b538SAndroid Build Coastguard Worker   // as the Origin would. The GURL will have an added "/" path for Origins with
276*6777b538SAndroid Build Coastguard Worker   // valid SchemeHostPorts and file Origins.
277*6777b538SAndroid Build Coastguard Worker   //
278*6777b538SAndroid Build Coastguard Worker   // Try not to use this method under normal circumstances, as it loses type
279*6777b538SAndroid Build Coastguard Worker   // information. Downstream consumers can mistake the returned GURL with a full
280*6777b538SAndroid Build Coastguard Worker   // URL (e.g. with a path component).
281*6777b538SAndroid Build Coastguard Worker   GURL GetURL() const;
282*6777b538SAndroid Build Coastguard Worker 
283*6777b538SAndroid Build Coastguard Worker   // Same as GURL::DomainIs. If |this| origin is opaque, then returns false.
284*6777b538SAndroid Build Coastguard Worker   bool DomainIs(std::string_view canonical_domain) const;
285*6777b538SAndroid Build Coastguard Worker 
286*6777b538SAndroid Build Coastguard Worker   // Allows Origin to be used as a key in STL (for example, a std::set or
287*6777b538SAndroid Build Coastguard Worker   // std::map).
288*6777b538SAndroid Build Coastguard Worker   bool operator<(const Origin& other) const;
289*6777b538SAndroid Build Coastguard Worker 
290*6777b538SAndroid Build Coastguard Worker   // Creates a new opaque origin that is guaranteed to be cross-origin to all
291*6777b538SAndroid Build Coastguard Worker   // currently existing origins. An origin created by this method retains its
292*6777b538SAndroid Build Coastguard Worker   // identity across copies. Copies are guaranteed to be same-origin to each
293*6777b538SAndroid Build Coastguard Worker   // other, e.g.
294*6777b538SAndroid Build Coastguard Worker   //
295*6777b538SAndroid Build Coastguard Worker   //   url::Origin page = Origin::Create(GURL("http://example.com"))
296*6777b538SAndroid Build Coastguard Worker   //   url::Origin a = page.DeriveNewOpaqueOrigin();
297*6777b538SAndroid Build Coastguard Worker   //   url::Origin b = page.DeriveNewOpaqueOrigin();
298*6777b538SAndroid Build Coastguard Worker   //   url::Origin c = a;
299*6777b538SAndroid Build Coastguard Worker   //   url::Origin d = b;
300*6777b538SAndroid Build Coastguard Worker   //
301*6777b538SAndroid Build Coastguard Worker   // |a| and |c| are same-origin, since |c| was copied from |a|. |b| and |d| are
302*6777b538SAndroid Build Coastguard Worker   // same-origin as well, since |d| was copied from |b|. All other combinations
303*6777b538SAndroid Build Coastguard Worker   // of origins are considered cross-origin, e.g. |a| is cross-origin to |b| and
304*6777b538SAndroid Build Coastguard Worker   // |d|, |b| is cross-origin to |a| and |c|, |c| is cross-origin to |b| and
305*6777b538SAndroid Build Coastguard Worker   // |d|, and |d| is cross-origin to |a| and |c|.
306*6777b538SAndroid Build Coastguard Worker   Origin DeriveNewOpaqueOrigin() const;
307*6777b538SAndroid Build Coastguard Worker 
308*6777b538SAndroid Build Coastguard Worker   // Returns the nonce associated with the origin, if it is opaque, or nullptr
309*6777b538SAndroid Build Coastguard Worker   // otherwise. This is only for use in tests.
310*6777b538SAndroid Build Coastguard Worker   const base::UnguessableToken* GetNonceForTesting() const;
311*6777b538SAndroid Build Coastguard Worker 
312*6777b538SAndroid Build Coastguard Worker   // Creates a string representation of the object that can be used for logging
313*6777b538SAndroid Build Coastguard Worker   // and debugging. It serializes the internal state, such as the nonce value
314*6777b538SAndroid Build Coastguard Worker   // and precursor information.
315*6777b538SAndroid Build Coastguard Worker   std::string GetDebugString(bool include_nonce = true) const;
316*6777b538SAndroid Build Coastguard Worker 
317*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_ANDROID) || BUILDFLAG(IS_ROBOLECTRIC)
318*6777b538SAndroid Build Coastguard Worker   base::android::ScopedJavaLocalRef<jobject> ToJavaObject() const;
319*6777b538SAndroid Build Coastguard Worker   static Origin FromJavaObject(
320*6777b538SAndroid Build Coastguard Worker       const base::android::JavaRef<jobject>& java_origin);
321*6777b538SAndroid Build Coastguard Worker   static jlong CreateNative(JNIEnv* env,
322*6777b538SAndroid Build Coastguard Worker                             const base::android::JavaRef<jstring>& java_scheme,
323*6777b538SAndroid Build Coastguard Worker                             const base::android::JavaRef<jstring>& java_host,
324*6777b538SAndroid Build Coastguard Worker                             uint16_t port,
325*6777b538SAndroid Build Coastguard Worker                             bool is_opaque,
326*6777b538SAndroid Build Coastguard Worker                             uint64_t tokenHighBits,
327*6777b538SAndroid Build Coastguard Worker                             uint64_t tokenLowBits);
328*6777b538SAndroid Build Coastguard Worker #endif  // BUILDFLAG(IS_ANDROID)
329*6777b538SAndroid Build Coastguard Worker 
330*6777b538SAndroid Build Coastguard Worker   void WriteIntoTrace(perfetto::TracedValue context) const;
331*6777b538SAndroid Build Coastguard Worker 
332*6777b538SAndroid Build Coastguard Worker   // Estimates dynamic memory usage.
333*6777b538SAndroid Build Coastguard Worker   // See base/trace_event/memory_usage_estimator.h for more info.
334*6777b538SAndroid Build Coastguard Worker   size_t EstimateMemoryUsage() const;
335*6777b538SAndroid Build Coastguard Worker 
336*6777b538SAndroid Build Coastguard Worker  private:
337*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_ANDROID) || BUILDFLAG(IS_ROBOLECTRIC)
338*6777b538SAndroid Build Coastguard Worker   friend Origin CreateOpaqueOriginForAndroid(
339*6777b538SAndroid Build Coastguard Worker       const std::string& scheme,
340*6777b538SAndroid Build Coastguard Worker       const std::string& host,
341*6777b538SAndroid Build Coastguard Worker       uint16_t port,
342*6777b538SAndroid Build Coastguard Worker       const base::UnguessableToken& nonce_token);
343*6777b538SAndroid Build Coastguard Worker #endif
344*6777b538SAndroid Build Coastguard Worker   friend class blink::SecurityOrigin;
345*6777b538SAndroid Build Coastguard Worker   friend class blink::SecurityOriginTest;
346*6777b538SAndroid Build Coastguard Worker   friend class blink::StorageKey;
347*6777b538SAndroid Build Coastguard Worker   // SiteInfo needs the nonce to compute the site URL for some opaque origins,
348*6777b538SAndroid Build Coastguard Worker   // like data: URLs.
349*6777b538SAndroid Build Coastguard Worker   friend class content::SiteInfo;
350*6777b538SAndroid Build Coastguard Worker   // SchemefulSite needs access to the serialization/deserialization logic which
351*6777b538SAndroid Build Coastguard Worker   // includes the nonce.
352*6777b538SAndroid Build Coastguard Worker   friend class net::SchemefulSite;
353*6777b538SAndroid Build Coastguard Worker   friend class OriginTest;
354*6777b538SAndroid Build Coastguard Worker   friend struct mojo::UrlOriginAdapter;
355*6777b538SAndroid Build Coastguard Worker   friend struct ipc_fuzzer::FuzzTraits<Origin>;
356*6777b538SAndroid Build Coastguard Worker   friend struct mojo::StructTraits<url::mojom::OriginDataView, url::Origin>;
357*6777b538SAndroid Build Coastguard Worker   friend IPC::ParamTraits<url::Origin>;
358*6777b538SAndroid Build Coastguard Worker   friend COMPONENT_EXPORT(URL) std::ostream& operator<<(std::ostream& out,
359*6777b538SAndroid Build Coastguard Worker                                                         const Origin& origin);
360*6777b538SAndroid Build Coastguard Worker   friend class blink::StorageKeyTest;
361*6777b538SAndroid Build Coastguard Worker 
362*6777b538SAndroid Build Coastguard Worker   // Origin::Nonce is a wrapper around base::UnguessableToken that generates
363*6777b538SAndroid Build Coastguard Worker   // the random value only when the value is first accessed. The lazy generation
364*6777b538SAndroid Build Coastguard Worker   // allows Origin to be default-constructed quickly, without spending time
365*6777b538SAndroid Build Coastguard Worker   // in random number generation.
366*6777b538SAndroid Build Coastguard Worker   //
367*6777b538SAndroid Build Coastguard Worker   // TODO(nick): Should this optimization move into UnguessableToken, once it no
368*6777b538SAndroid Build Coastguard Worker   // longer treats the Null case specially?
369*6777b538SAndroid Build Coastguard Worker   class COMPONENT_EXPORT(URL) Nonce {
370*6777b538SAndroid Build Coastguard Worker    public:
371*6777b538SAndroid Build Coastguard Worker     // Creates a nonce to hold a newly-generated UnguessableToken. The actual
372*6777b538SAndroid Build Coastguard Worker     // token value will be generated lazily.
373*6777b538SAndroid Build Coastguard Worker     Nonce();
374*6777b538SAndroid Build Coastguard Worker 
375*6777b538SAndroid Build Coastguard Worker     // Creates a nonce to hold an already-generated UnguessableToken value. This
376*6777b538SAndroid Build Coastguard Worker     // constructor should only be used for IPC serialization and testing --
377*6777b538SAndroid Build Coastguard Worker     // regular code should never need to touch the UnguessableTokens directly,
378*6777b538SAndroid Build Coastguard Worker     // and the default constructor is faster.
379*6777b538SAndroid Build Coastguard Worker     explicit Nonce(const base::UnguessableToken& token);
380*6777b538SAndroid Build Coastguard Worker 
381*6777b538SAndroid Build Coastguard Worker     // Accessor, which lazily initializes the underlying |token_| member.
382*6777b538SAndroid Build Coastguard Worker     const base::UnguessableToken& token() const;
383*6777b538SAndroid Build Coastguard Worker 
384*6777b538SAndroid Build Coastguard Worker     // Do not use in cases where lazy initialization is expected! This
385*6777b538SAndroid Build Coastguard Worker     // accessor does not initialize the |token_| member.
386*6777b538SAndroid Build Coastguard Worker     const base::UnguessableToken& raw_token() const;
387*6777b538SAndroid Build Coastguard Worker 
388*6777b538SAndroid Build Coastguard Worker     // Copyable and movable. Copying a Nonce triggers lazy-initialization,
389*6777b538SAndroid Build Coastguard Worker     // moving it does not.
390*6777b538SAndroid Build Coastguard Worker     Nonce(const Nonce&);
391*6777b538SAndroid Build Coastguard Worker     Nonce& operator=(const Nonce&);
392*6777b538SAndroid Build Coastguard Worker     Nonce(Nonce&&) noexcept;
393*6777b538SAndroid Build Coastguard Worker     Nonce& operator=(Nonce&&) noexcept;
394*6777b538SAndroid Build Coastguard Worker 
395*6777b538SAndroid Build Coastguard Worker     // Note that operator<, used by maps type containers, will trigger |token_|
396*6777b538SAndroid Build Coastguard Worker     // lazy-initialization. Equality comparisons do not.
397*6777b538SAndroid Build Coastguard Worker     bool operator<(const Nonce& other) const;
398*6777b538SAndroid Build Coastguard Worker     bool operator==(const Nonce& other) const;
399*6777b538SAndroid Build Coastguard Worker     bool operator!=(const Nonce& other) const;
400*6777b538SAndroid Build Coastguard Worker 
401*6777b538SAndroid Build Coastguard Worker    private:
402*6777b538SAndroid Build Coastguard Worker     friend class OriginTest;
403*6777b538SAndroid Build Coastguard Worker 
404*6777b538SAndroid Build Coastguard Worker     // mutable to support lazy generation.
405*6777b538SAndroid Build Coastguard Worker     mutable base::UnguessableToken token_;
406*6777b538SAndroid Build Coastguard Worker   };
407*6777b538SAndroid Build Coastguard Worker 
408*6777b538SAndroid Build Coastguard Worker   // This needs to be friended within Origin as well, since Nonce is a private
409*6777b538SAndroid Build Coastguard Worker   // nested class of Origin.
410*6777b538SAndroid Build Coastguard Worker   friend COMPONENT_EXPORT(URL) std::ostream& operator<<(std::ostream& out,
411*6777b538SAndroid Build Coastguard Worker                                                         const Nonce& nonce);
412*6777b538SAndroid Build Coastguard Worker 
413*6777b538SAndroid Build Coastguard Worker   // Creates an origin without sanity checking that the host is canonicalized.
414*6777b538SAndroid Build Coastguard Worker   // This should only be used when converting between already normalized types,
415*6777b538SAndroid Build Coastguard Worker   // and should NOT be used for IPC. Method takes std::strings for use with move
416*6777b538SAndroid Build Coastguard Worker   // operators to avoid copies.
417*6777b538SAndroid Build Coastguard Worker   static Origin CreateOpaqueFromNormalizedPrecursorTuple(
418*6777b538SAndroid Build Coastguard Worker       std::string precursor_scheme,
419*6777b538SAndroid Build Coastguard Worker       std::string precursor_host,
420*6777b538SAndroid Build Coastguard Worker       uint16_t precursor_port,
421*6777b538SAndroid Build Coastguard Worker       const Nonce& nonce);
422*6777b538SAndroid Build Coastguard Worker 
423*6777b538SAndroid Build Coastguard Worker   // Creates an opaque Origin with the identity given by |nonce|, and an
424*6777b538SAndroid Build Coastguard Worker   // optional precursor origin given by |precursor_scheme|, |precursor_host| and
425*6777b538SAndroid Build Coastguard Worker   // |precursor_port|. Returns nullopt if any parameter is not canonical. When
426*6777b538SAndroid Build Coastguard Worker   // the precursor is unknown, the precursor parameters should be ("", "", 0).
427*6777b538SAndroid Build Coastguard Worker   //
428*6777b538SAndroid Build Coastguard Worker   // This factory method should be used in order to pass opaque Origin objects
429*6777b538SAndroid Build Coastguard Worker   // back and forth over IPC (as transitioning through GURL would risk
430*6777b538SAndroid Build Coastguard Worker   // potentially dangerous recanonicalization).
431*6777b538SAndroid Build Coastguard Worker   static std::optional<Origin> UnsafelyCreateOpaqueOriginWithoutNormalization(
432*6777b538SAndroid Build Coastguard Worker       std::string_view precursor_scheme,
433*6777b538SAndroid Build Coastguard Worker       std::string_view precursor_host,
434*6777b538SAndroid Build Coastguard Worker       uint16_t precursor_port,
435*6777b538SAndroid Build Coastguard Worker       const Nonce& nonce);
436*6777b538SAndroid Build Coastguard Worker 
437*6777b538SAndroid Build Coastguard Worker   // Constructs a non-opaque tuple origin. |tuple| must be valid.
438*6777b538SAndroid Build Coastguard Worker   explicit Origin(SchemeHostPort tuple);
439*6777b538SAndroid Build Coastguard Worker 
440*6777b538SAndroid Build Coastguard Worker   // Constructs an opaque origin derived from the |precursor| tuple, with the
441*6777b538SAndroid Build Coastguard Worker   // given |nonce|.
442*6777b538SAndroid Build Coastguard Worker   Origin(const Nonce& nonce, SchemeHostPort precursor);
443*6777b538SAndroid Build Coastguard Worker 
444*6777b538SAndroid Build Coastguard Worker   // Get the nonce associated with this origin, if it is opaque, or nullptr
445*6777b538SAndroid Build Coastguard Worker   // otherwise. This should be used only when trying to send an Origin across an
446*6777b538SAndroid Build Coastguard Worker   // IPC pipe.
447*6777b538SAndroid Build Coastguard Worker   const base::UnguessableToken* GetNonceForSerialization() const;
448*6777b538SAndroid Build Coastguard Worker 
449*6777b538SAndroid Build Coastguard Worker   // Serializes this Origin, including its nonce if it is opaque. If an opaque
450*6777b538SAndroid Build Coastguard Worker   // origin's |tuple_| is invalid nullopt is returned. If the nonce is not
451*6777b538SAndroid Build Coastguard Worker   // initialized, a nonce of 0 is used. Use of this method should be limited as
452*6777b538SAndroid Build Coastguard Worker   // an opaque origin will never be matchable in future browser sessions.
453*6777b538SAndroid Build Coastguard Worker   std::optional<std::string> SerializeWithNonce() const;
454*6777b538SAndroid Build Coastguard Worker 
455*6777b538SAndroid Build Coastguard Worker   // Like SerializeWithNonce(), but forces |nonce_| to be initialized prior to
456*6777b538SAndroid Build Coastguard Worker   // serializing.
457*6777b538SAndroid Build Coastguard Worker   std::optional<std::string> SerializeWithNonceAndInitIfNeeded();
458*6777b538SAndroid Build Coastguard Worker 
459*6777b538SAndroid Build Coastguard Worker   std::optional<std::string> SerializeWithNonceImpl() const;
460*6777b538SAndroid Build Coastguard Worker 
461*6777b538SAndroid Build Coastguard Worker   // Deserializes an origin from |ToValueWithNonce|. Returns nullopt if the
462*6777b538SAndroid Build Coastguard Worker   // value was invalid in any way.
463*6777b538SAndroid Build Coastguard Worker   static std::optional<Origin> Deserialize(const std::string& value);
464*6777b538SAndroid Build Coastguard Worker 
465*6777b538SAndroid Build Coastguard Worker   // The tuple is used for both tuple origins (e.g. https://example.com:80), as
466*6777b538SAndroid Build Coastguard Worker   // well as for opaque origins, where it tracks the tuple origin from which
467*6777b538SAndroid Build Coastguard Worker   // the opaque origin was initially derived (we call this the "precursor"
468*6777b538SAndroid Build Coastguard Worker   // origin).
469*6777b538SAndroid Build Coastguard Worker   SchemeHostPort tuple_;
470*6777b538SAndroid Build Coastguard Worker 
471*6777b538SAndroid Build Coastguard Worker   // The nonce is used for maintaining identity of an opaque origin. This
472*6777b538SAndroid Build Coastguard Worker   // nonce is preserved when an opaque origin is copied or moved. An Origin
473*6777b538SAndroid Build Coastguard Worker   // is considered opaque if and only if |nonce_| holds a value.
474*6777b538SAndroid Build Coastguard Worker   std::optional<Nonce> nonce_;
475*6777b538SAndroid Build Coastguard Worker };
476*6777b538SAndroid Build Coastguard Worker 
477*6777b538SAndroid Build Coastguard Worker // Pretty-printers for logging. These expose the internal state of the nonce.
478*6777b538SAndroid Build Coastguard Worker COMPONENT_EXPORT(URL)
479*6777b538SAndroid Build Coastguard Worker std::ostream& operator<<(std::ostream& out, const Origin& origin);
480*6777b538SAndroid Build Coastguard Worker COMPONENT_EXPORT(URL)
481*6777b538SAndroid Build Coastguard Worker std::ostream& operator<<(std::ostream& out, const Origin::Nonce& origin);
482*6777b538SAndroid Build Coastguard Worker 
483*6777b538SAndroid Build Coastguard Worker COMPONENT_EXPORT(URL) bool IsSameOriginWith(const GURL& a, const GURL& b);
484*6777b538SAndroid Build Coastguard Worker 
485*6777b538SAndroid Build Coastguard Worker // DEBUG_ALIAS_FOR_ORIGIN(var_name, origin) copies `origin` into a new
486*6777b538SAndroid Build Coastguard Worker // stack-allocated variable named `<var_name>`. This helps ensure that the
487*6777b538SAndroid Build Coastguard Worker // value of `origin` gets preserved in crash dumps.
488*6777b538SAndroid Build Coastguard Worker #define DEBUG_ALIAS_FOR_ORIGIN(var_name, origin) \
489*6777b538SAndroid Build Coastguard Worker   DEBUG_ALIAS_FOR_CSTR(var_name, (origin).Serialize().c_str(), 128)
490*6777b538SAndroid Build Coastguard Worker 
491*6777b538SAndroid Build Coastguard Worker namespace debug {
492*6777b538SAndroid Build Coastguard Worker 
493*6777b538SAndroid Build Coastguard Worker class COMPONENT_EXPORT(URL) ScopedOriginCrashKey {
494*6777b538SAndroid Build Coastguard Worker  public:
495*6777b538SAndroid Build Coastguard Worker   ScopedOriginCrashKey(base::debug::CrashKeyString* crash_key,
496*6777b538SAndroid Build Coastguard Worker                        const url::Origin* value);
497*6777b538SAndroid Build Coastguard Worker   ~ScopedOriginCrashKey();
498*6777b538SAndroid Build Coastguard Worker 
499*6777b538SAndroid Build Coastguard Worker   ScopedOriginCrashKey(const ScopedOriginCrashKey&) = delete;
500*6777b538SAndroid Build Coastguard Worker   ScopedOriginCrashKey& operator=(const ScopedOriginCrashKey&) = delete;
501*6777b538SAndroid Build Coastguard Worker 
502*6777b538SAndroid Build Coastguard Worker  private:
503*6777b538SAndroid Build Coastguard Worker   base::debug::ScopedCrashKeyString scoped_string_value_;
504*6777b538SAndroid Build Coastguard Worker };
505*6777b538SAndroid Build Coastguard Worker 
506*6777b538SAndroid Build Coastguard Worker }  // namespace debug
507*6777b538SAndroid Build Coastguard Worker 
508*6777b538SAndroid Build Coastguard Worker }  // namespace url
509*6777b538SAndroid Build Coastguard Worker 
510*6777b538SAndroid Build Coastguard Worker #endif  // URL_ORIGIN_H_
511