1*6777b538SAndroid Build Coastguard Worker // Copyright 2011 The Chromium Authors
2*6777b538SAndroid Build Coastguard Worker // Use of this source code is governed by a BSD-style license that can be
3*6777b538SAndroid Build Coastguard Worker // found in the LICENSE file.
4*6777b538SAndroid Build Coastguard Worker
5*6777b538SAndroid Build Coastguard Worker #include "net/http/http_auth.h"
6*6777b538SAndroid Build Coastguard Worker
7*6777b538SAndroid Build Coastguard Worker #include <algorithm>
8*6777b538SAndroid Build Coastguard Worker
9*6777b538SAndroid Build Coastguard Worker #include "base/strings/string_tokenizer.h"
10*6777b538SAndroid Build Coastguard Worker #include "base/strings/string_util.h"
11*6777b538SAndroid Build Coastguard Worker #include "base/values.h"
12*6777b538SAndroid Build Coastguard Worker #include "net/base/net_errors.h"
13*6777b538SAndroid Build Coastguard Worker #include "net/dns/host_resolver.h"
14*6777b538SAndroid Build Coastguard Worker #include "net/http/http_auth_challenge_tokenizer.h"
15*6777b538SAndroid Build Coastguard Worker #include "net/http/http_auth_handler.h"
16*6777b538SAndroid Build Coastguard Worker #include "net/http/http_auth_handler_factory.h"
17*6777b538SAndroid Build Coastguard Worker #include "net/http/http_auth_scheme.h"
18*6777b538SAndroid Build Coastguard Worker #include "net/http/http_request_headers.h"
19*6777b538SAndroid Build Coastguard Worker #include "net/http/http_response_headers.h"
20*6777b538SAndroid Build Coastguard Worker #include "net/http/http_util.h"
21*6777b538SAndroid Build Coastguard Worker #include "net/log/net_log.h"
22*6777b538SAndroid Build Coastguard Worker #include "net/log/net_log_values.h"
23*6777b538SAndroid Build Coastguard Worker
24*6777b538SAndroid Build Coastguard Worker namespace net {
25*6777b538SAndroid Build Coastguard Worker
26*6777b538SAndroid Build Coastguard Worker namespace {
27*6777b538SAndroid Build Coastguard Worker const char* const kSchemeNames[] = {kBasicAuthScheme, kDigestAuthScheme,
28*6777b538SAndroid Build Coastguard Worker kNtlmAuthScheme, kNegotiateAuthScheme,
29*6777b538SAndroid Build Coastguard Worker kSpdyProxyAuthScheme, kMockAuthScheme};
30*6777b538SAndroid Build Coastguard Worker } // namespace
31*6777b538SAndroid Build Coastguard Worker
32*6777b538SAndroid Build Coastguard Worker HttpAuth::Identity::Identity() = default;
33*6777b538SAndroid Build Coastguard Worker
34*6777b538SAndroid Build Coastguard Worker // static
ChooseBestChallenge(HttpAuthHandlerFactory * http_auth_handler_factory,const HttpResponseHeaders & response_headers,const SSLInfo & ssl_info,const NetworkAnonymizationKey & network_anonymization_key,Target target,const url::SchemeHostPort & scheme_host_port,const std::set<Scheme> & disabled_schemes,const NetLogWithSource & net_log,HostResolver * host_resolver,std::unique_ptr<HttpAuthHandler> * handler)35*6777b538SAndroid Build Coastguard Worker void HttpAuth::ChooseBestChallenge(
36*6777b538SAndroid Build Coastguard Worker HttpAuthHandlerFactory* http_auth_handler_factory,
37*6777b538SAndroid Build Coastguard Worker const HttpResponseHeaders& response_headers,
38*6777b538SAndroid Build Coastguard Worker const SSLInfo& ssl_info,
39*6777b538SAndroid Build Coastguard Worker const NetworkAnonymizationKey& network_anonymization_key,
40*6777b538SAndroid Build Coastguard Worker Target target,
41*6777b538SAndroid Build Coastguard Worker const url::SchemeHostPort& scheme_host_port,
42*6777b538SAndroid Build Coastguard Worker const std::set<Scheme>& disabled_schemes,
43*6777b538SAndroid Build Coastguard Worker const NetLogWithSource& net_log,
44*6777b538SAndroid Build Coastguard Worker HostResolver* host_resolver,
45*6777b538SAndroid Build Coastguard Worker std::unique_ptr<HttpAuthHandler>* handler) {
46*6777b538SAndroid Build Coastguard Worker DCHECK(http_auth_handler_factory);
47*6777b538SAndroid Build Coastguard Worker DCHECK(handler->get() == nullptr);
48*6777b538SAndroid Build Coastguard Worker
49*6777b538SAndroid Build Coastguard Worker // Choose the challenge whose authentication handler gives the maximum score.
50*6777b538SAndroid Build Coastguard Worker std::unique_ptr<HttpAuthHandler> best;
51*6777b538SAndroid Build Coastguard Worker const std::string header_name = GetChallengeHeaderName(target);
52*6777b538SAndroid Build Coastguard Worker std::string cur_challenge;
53*6777b538SAndroid Build Coastguard Worker size_t iter = 0;
54*6777b538SAndroid Build Coastguard Worker while (response_headers.EnumerateHeader(&iter, header_name, &cur_challenge)) {
55*6777b538SAndroid Build Coastguard Worker std::unique_ptr<HttpAuthHandler> cur;
56*6777b538SAndroid Build Coastguard Worker int rv = http_auth_handler_factory->CreateAuthHandlerFromString(
57*6777b538SAndroid Build Coastguard Worker cur_challenge, target, ssl_info, network_anonymization_key,
58*6777b538SAndroid Build Coastguard Worker scheme_host_port, net_log, host_resolver, &cur);
59*6777b538SAndroid Build Coastguard Worker if (rv != OK) {
60*6777b538SAndroid Build Coastguard Worker VLOG(1) << "Unable to create AuthHandler. Status: "
61*6777b538SAndroid Build Coastguard Worker << ErrorToString(rv) << " Challenge: " << cur_challenge;
62*6777b538SAndroid Build Coastguard Worker continue;
63*6777b538SAndroid Build Coastguard Worker }
64*6777b538SAndroid Build Coastguard Worker if (cur.get() && (!best.get() || best->score() < cur->score()) &&
65*6777b538SAndroid Build Coastguard Worker (disabled_schemes.find(cur->auth_scheme()) == disabled_schemes.end()))
66*6777b538SAndroid Build Coastguard Worker best.swap(cur);
67*6777b538SAndroid Build Coastguard Worker }
68*6777b538SAndroid Build Coastguard Worker handler->swap(best);
69*6777b538SAndroid Build Coastguard Worker }
70*6777b538SAndroid Build Coastguard Worker
71*6777b538SAndroid Build Coastguard Worker // static
HandleChallengeResponse(HttpAuthHandler * handler,const HttpResponseHeaders & response_headers,Target target,const std::set<Scheme> & disabled_schemes,std::string * challenge_used)72*6777b538SAndroid Build Coastguard Worker HttpAuth::AuthorizationResult HttpAuth::HandleChallengeResponse(
73*6777b538SAndroid Build Coastguard Worker HttpAuthHandler* handler,
74*6777b538SAndroid Build Coastguard Worker const HttpResponseHeaders& response_headers,
75*6777b538SAndroid Build Coastguard Worker Target target,
76*6777b538SAndroid Build Coastguard Worker const std::set<Scheme>& disabled_schemes,
77*6777b538SAndroid Build Coastguard Worker std::string* challenge_used) {
78*6777b538SAndroid Build Coastguard Worker DCHECK(handler);
79*6777b538SAndroid Build Coastguard Worker DCHECK(challenge_used);
80*6777b538SAndroid Build Coastguard Worker
81*6777b538SAndroid Build Coastguard Worker challenge_used->clear();
82*6777b538SAndroid Build Coastguard Worker HttpAuth::Scheme current_scheme = handler->auth_scheme();
83*6777b538SAndroid Build Coastguard Worker if (disabled_schemes.find(current_scheme) != disabled_schemes.end())
84*6777b538SAndroid Build Coastguard Worker return HttpAuth::AUTHORIZATION_RESULT_REJECT;
85*6777b538SAndroid Build Coastguard Worker const char* current_scheme_name = SchemeToString(current_scheme);
86*6777b538SAndroid Build Coastguard Worker const std::string header_name = GetChallengeHeaderName(target);
87*6777b538SAndroid Build Coastguard Worker size_t iter = 0;
88*6777b538SAndroid Build Coastguard Worker std::string challenge;
89*6777b538SAndroid Build Coastguard Worker HttpAuth::AuthorizationResult authorization_result =
90*6777b538SAndroid Build Coastguard Worker HttpAuth::AUTHORIZATION_RESULT_INVALID;
91*6777b538SAndroid Build Coastguard Worker while (response_headers.EnumerateHeader(&iter, header_name, &challenge)) {
92*6777b538SAndroid Build Coastguard Worker HttpAuthChallengeTokenizer challenge_tokens(challenge.begin(),
93*6777b538SAndroid Build Coastguard Worker challenge.end());
94*6777b538SAndroid Build Coastguard Worker if (challenge_tokens.auth_scheme() != current_scheme_name)
95*6777b538SAndroid Build Coastguard Worker continue;
96*6777b538SAndroid Build Coastguard Worker authorization_result = handler->HandleAnotherChallenge(&challenge_tokens);
97*6777b538SAndroid Build Coastguard Worker if (authorization_result != HttpAuth::AUTHORIZATION_RESULT_INVALID) {
98*6777b538SAndroid Build Coastguard Worker *challenge_used = challenge;
99*6777b538SAndroid Build Coastguard Worker return authorization_result;
100*6777b538SAndroid Build Coastguard Worker }
101*6777b538SAndroid Build Coastguard Worker }
102*6777b538SAndroid Build Coastguard Worker // Finding no matches is equivalent to rejection.
103*6777b538SAndroid Build Coastguard Worker return HttpAuth::AUTHORIZATION_RESULT_REJECT;
104*6777b538SAndroid Build Coastguard Worker }
105*6777b538SAndroid Build Coastguard Worker
106*6777b538SAndroid Build Coastguard Worker // static
GetChallengeHeaderName(Target target)107*6777b538SAndroid Build Coastguard Worker std::string HttpAuth::GetChallengeHeaderName(Target target) {
108*6777b538SAndroid Build Coastguard Worker switch (target) {
109*6777b538SAndroid Build Coastguard Worker case AUTH_PROXY:
110*6777b538SAndroid Build Coastguard Worker return "Proxy-Authenticate";
111*6777b538SAndroid Build Coastguard Worker case AUTH_SERVER:
112*6777b538SAndroid Build Coastguard Worker return "WWW-Authenticate";
113*6777b538SAndroid Build Coastguard Worker default:
114*6777b538SAndroid Build Coastguard Worker NOTREACHED();
115*6777b538SAndroid Build Coastguard Worker return std::string();
116*6777b538SAndroid Build Coastguard Worker }
117*6777b538SAndroid Build Coastguard Worker }
118*6777b538SAndroid Build Coastguard Worker
119*6777b538SAndroid Build Coastguard Worker // static
GetAuthorizationHeaderName(Target target)120*6777b538SAndroid Build Coastguard Worker std::string HttpAuth::GetAuthorizationHeaderName(Target target) {
121*6777b538SAndroid Build Coastguard Worker switch (target) {
122*6777b538SAndroid Build Coastguard Worker case AUTH_PROXY:
123*6777b538SAndroid Build Coastguard Worker return HttpRequestHeaders::kProxyAuthorization;
124*6777b538SAndroid Build Coastguard Worker case AUTH_SERVER:
125*6777b538SAndroid Build Coastguard Worker return HttpRequestHeaders::kAuthorization;
126*6777b538SAndroid Build Coastguard Worker default:
127*6777b538SAndroid Build Coastguard Worker NOTREACHED();
128*6777b538SAndroid Build Coastguard Worker return std::string();
129*6777b538SAndroid Build Coastguard Worker }
130*6777b538SAndroid Build Coastguard Worker }
131*6777b538SAndroid Build Coastguard Worker
132*6777b538SAndroid Build Coastguard Worker // static
GetAuthTargetString(Target target)133*6777b538SAndroid Build Coastguard Worker std::string HttpAuth::GetAuthTargetString(Target target) {
134*6777b538SAndroid Build Coastguard Worker switch (target) {
135*6777b538SAndroid Build Coastguard Worker case AUTH_PROXY:
136*6777b538SAndroid Build Coastguard Worker return "proxy";
137*6777b538SAndroid Build Coastguard Worker case AUTH_SERVER:
138*6777b538SAndroid Build Coastguard Worker return "server";
139*6777b538SAndroid Build Coastguard Worker default:
140*6777b538SAndroid Build Coastguard Worker NOTREACHED();
141*6777b538SAndroid Build Coastguard Worker return std::string();
142*6777b538SAndroid Build Coastguard Worker }
143*6777b538SAndroid Build Coastguard Worker }
144*6777b538SAndroid Build Coastguard Worker
145*6777b538SAndroid Build Coastguard Worker // static
SchemeToString(Scheme scheme)146*6777b538SAndroid Build Coastguard Worker const char* HttpAuth::SchemeToString(Scheme scheme) {
147*6777b538SAndroid Build Coastguard Worker static_assert(std::size(kSchemeNames) == AUTH_SCHEME_MAX,
148*6777b538SAndroid Build Coastguard Worker "http auth scheme names incorrect size");
149*6777b538SAndroid Build Coastguard Worker if (scheme < AUTH_SCHEME_BASIC || scheme >= AUTH_SCHEME_MAX) {
150*6777b538SAndroid Build Coastguard Worker NOTREACHED();
151*6777b538SAndroid Build Coastguard Worker return "invalid_scheme";
152*6777b538SAndroid Build Coastguard Worker }
153*6777b538SAndroid Build Coastguard Worker return kSchemeNames[scheme];
154*6777b538SAndroid Build Coastguard Worker }
155*6777b538SAndroid Build Coastguard Worker
156*6777b538SAndroid Build Coastguard Worker // static
StringToScheme(const std::string & str)157*6777b538SAndroid Build Coastguard Worker HttpAuth::Scheme HttpAuth::StringToScheme(const std::string& str) {
158*6777b538SAndroid Build Coastguard Worker for (uint8_t i = 0; i < std::size(kSchemeNames); i++) {
159*6777b538SAndroid Build Coastguard Worker if (str == kSchemeNames[i])
160*6777b538SAndroid Build Coastguard Worker return static_cast<Scheme>(i);
161*6777b538SAndroid Build Coastguard Worker }
162*6777b538SAndroid Build Coastguard Worker NOTREACHED();
163*6777b538SAndroid Build Coastguard Worker return AUTH_SCHEME_MAX;
164*6777b538SAndroid Build Coastguard Worker }
165*6777b538SAndroid Build Coastguard Worker
166*6777b538SAndroid Build Coastguard Worker // static
AuthorizationResultToString(AuthorizationResult authorization_result)167*6777b538SAndroid Build Coastguard Worker const char* HttpAuth::AuthorizationResultToString(
168*6777b538SAndroid Build Coastguard Worker AuthorizationResult authorization_result) {
169*6777b538SAndroid Build Coastguard Worker switch (authorization_result) {
170*6777b538SAndroid Build Coastguard Worker case AUTHORIZATION_RESULT_ACCEPT:
171*6777b538SAndroid Build Coastguard Worker return "accept";
172*6777b538SAndroid Build Coastguard Worker case AUTHORIZATION_RESULT_REJECT:
173*6777b538SAndroid Build Coastguard Worker return "reject";
174*6777b538SAndroid Build Coastguard Worker case AUTHORIZATION_RESULT_STALE:
175*6777b538SAndroid Build Coastguard Worker return "stale";
176*6777b538SAndroid Build Coastguard Worker case AUTHORIZATION_RESULT_INVALID:
177*6777b538SAndroid Build Coastguard Worker return "invalid";
178*6777b538SAndroid Build Coastguard Worker case AUTHORIZATION_RESULT_DIFFERENT_REALM:
179*6777b538SAndroid Build Coastguard Worker return "different_realm";
180*6777b538SAndroid Build Coastguard Worker }
181*6777b538SAndroid Build Coastguard Worker NOTREACHED();
182*6777b538SAndroid Build Coastguard Worker return "(invalid result)";
183*6777b538SAndroid Build Coastguard Worker }
184*6777b538SAndroid Build Coastguard Worker
185*6777b538SAndroid Build Coastguard Worker // static
NetLogAuthorizationResultParams(const char * name,AuthorizationResult authorization_result)186*6777b538SAndroid Build Coastguard Worker base::Value::Dict HttpAuth::NetLogAuthorizationResultParams(
187*6777b538SAndroid Build Coastguard Worker const char* name,
188*6777b538SAndroid Build Coastguard Worker AuthorizationResult authorization_result) {
189*6777b538SAndroid Build Coastguard Worker return NetLogParamsWithString(
190*6777b538SAndroid Build Coastguard Worker name, AuthorizationResultToString(authorization_result));
191*6777b538SAndroid Build Coastguard Worker }
192*6777b538SAndroid Build Coastguard Worker
193*6777b538SAndroid Build Coastguard Worker } // namespace net
194