1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117
|
// Copyright 2020 The Chromium Authors
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
#ifndef COMPONENTS_TRUSTED_VAULT_TRUSTED_VAULT_CONNECTION_IMPL_H_
#define COMPONENTS_TRUSTED_VAULT_TRUSTED_VAULT_CONNECTION_IMPL_H_
#include <memory>
#include <vector>
#include "base/memory/scoped_refptr.h"
#include "base/time/time.h"
#include "components/trusted_vault/securebox.h"
#include "components/trusted_vault/trusted_vault_access_token_fetcher.h"
#include "components/trusted_vault/trusted_vault_connection.h"
#include "url/gurl.h"
namespace network {
class PendingSharedURLLoaderFactory;
class SharedURLLoaderFactory;
} // namespace network
namespace trusted_vault {
enum class SecurityDomainId;
// This class is created on UI thread and used/destroyed on trusted vault
// backend thread.
class TrustedVaultConnectionImpl : public TrustedVaultConnection {
public:
using JoinSecurityDomainsCallback =
base::OnceCallback<void(TrustedVaultRegistrationStatus,
int /*last_key_version=*/)>;
// Specifies how long JoinSecurityDomainRequest could be delayed due to
// retries in case of transient errors. Exposed for testing.
static constexpr base::TimeDelta kMaxJoinSecurityDomainRetryDuration =
base::Hours(1);
TrustedVaultConnectionImpl(
SecurityDomainId security_domain,
const GURL& trusted_vault_service_url,
std::unique_ptr<network::PendingSharedURLLoaderFactory>
pending_url_loader_factory,
std::unique_ptr<TrustedVaultAccessTokenFetcher> access_token_fetcher);
TrustedVaultConnectionImpl(const TrustedVaultConnectionImpl& other) = delete;
TrustedVaultConnectionImpl& operator=(
const TrustedVaultConnectionImpl& other) = delete;
~TrustedVaultConnectionImpl() override;
std::unique_ptr<Request> RegisterAuthenticationFactor(
const CoreAccountInfo& account_info,
const MemberKeysSource& member_keys_source,
const SecureBoxPublicKey& authentication_factor_public_key,
AuthenticationFactorTypeAndRegistrationParams
authentication_factor_type_and_registration_params,
RegisterAuthenticationFactorCallback callback) override;
std::unique_ptr<Request> RegisterLocalDeviceWithoutKeys(
const CoreAccountInfo& account_info,
const SecureBoxPublicKey& device_public_key,
RegisterAuthenticationFactorCallback callback) override;
std::unique_ptr<Request> DownloadNewKeys(
const CoreAccountInfo& account_info,
const TrustedVaultKeyAndVersion& last_trusted_vault_key_and_version,
std::unique_ptr<SecureBoxKeyPair> device_key_pair,
DownloadNewKeysCallback callback) override;
std::unique_ptr<Request> DownloadIsRecoverabilityDegraded(
const CoreAccountInfo& account_info,
IsRecoverabilityDegradedCallback callback) override;
std::unique_ptr<TrustedVaultConnection::Request>
DownloadAuthenticationFactorsRegistrationState(
const CoreAccountInfo& account_info,
DownloadAuthenticationFactorsRegistrationStateCallback callback,
base::RepeatingClosure keep_alive_callback) override;
std::unique_ptr<Request> DownloadAuthenticationFactorsRegistrationState(
const CoreAccountInfo& account_info,
std::set<trusted_vault_pb::SecurityDomainMember_MemberType>
recovery_factor_filter,
DownloadAuthenticationFactorsRegistrationStateCallback callback,
base::RepeatingClosure keep_alive_callback) override;
private:
std::unique_ptr<Request> SendJoinSecurityDomainsRequest(
const CoreAccountInfo& account_info,
const MemberKeysSource& member_keys_source,
const SecureBoxPublicKey& authentication_factor_public_key,
AuthenticationFactorTypeAndRegistrationParams
authentication_factor_type_and_registration_params,
JoinSecurityDomainsCallback callback);
const SecurityDomainId security_domain_;
// SharedURLLoaderFactory is created lazily, because it needs to be done on
// the backend sequence, while this class ctor is called on UI thread.
scoped_refptr<network::SharedURLLoaderFactory> GetOrCreateURLLoaderFactory();
std::unique_ptr<network::PendingSharedURLLoaderFactory>
pending_url_loader_factory_;
const std::unique_ptr<TrustedVaultAccessTokenFetcher> access_token_fetcher_;
// Instantiated upon first need using |pending_url_loader_factory_|.
scoped_refptr<network::SharedURLLoaderFactory> url_loader_factory_;
GURL trusted_vault_service_url_;
const bool enable_registration_state_security_domain_filtering_;
};
} // namespace trusted_vault
#endif // COMPONENTS_TRUSTED_VAULT_TRUSTED_VAULT_CONNECTION_IMPL_H_
|