1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66
|
// Copyright 2024 The Chromium Authors
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
#ifndef CHROME_BROWSER_ENTERPRISE_PROFILE_MANAGEMENT_OIDC_AUTH_RESPONSE_CAPTURE_NAVIGATION_THROTTLE_H_
#define CHROME_BROWSER_ENTERPRISE_PROFILE_MANAGEMENT_OIDC_AUTH_RESPONSE_CAPTURE_NAVIGATION_THROTTLE_H_
#include <memory>
#include "base/memory/weak_ptr.h"
#include "chrome/browser/profiles/profile_attributes_entry.h"
#include "components/url_matcher/url_matcher.h"
#include "content/public/browser/navigation_throttle.h"
#include "services/data_decoder/public/cpp/data_decoder.h"
namespace profile_management {
// This throttle looks for redirection from Oidc authentications to the hard
// coded host `chromeprofiletoken`. It will capture the redirection and try to
// create or switch to a managed profile using the tokens from the auth
// response. The workflow is currently experimental and not productionized.
class OidcAuthResponseCaptureNavigationThrottle
: public content::NavigationThrottle {
public:
// Create a navigation throttle for the given navigation if Oidc
// authentication based enrollment is enabled. Returns nullptr if no
// throttling should be done.
static void MaybeCreateAndAdd(content::NavigationThrottleRegistry& registry);
explicit OidcAuthResponseCaptureNavigationThrottle(
content::NavigationThrottleRegistry& registry);
OidcAuthResponseCaptureNavigationThrottle(
const OidcAuthResponseCaptureNavigationThrottle&) = delete;
OidcAuthResponseCaptureNavigationThrottle& operator=(
const OidcAuthResponseCaptureNavigationThrottle&) = delete;
~OidcAuthResponseCaptureNavigationThrottle() override;
// content::NavigationThrottle implementation:
ThrottleCheckResult WillRedirectRequest() override;
ThrottleCheckResult WillProcessResponse() override;
const char* GetNameForLogging() override;
// Method to get a new URL matcher instead of the usual static one for
// testing, due the feature flag value may have changed in different cases.
static std::unique_ptr<url_matcher::URLMatcher>
GetOidcEnrollmentUrlMatcherForTesting();
private:
ThrottleCheckResult AttemptToTriggerUrlInterception();
ThrottleCheckResult AttemptToTriggerHeaderInterception();
// Starts OIDC registration and profile creation process if the response is
// valid.
void RegisterWithOidcTokens(ProfileManagementOidcTokens tokens,
data_decoder::DataDecoder::ValueOrError result);
bool interception_triggered_ = false;
base::WeakPtrFactory<OidcAuthResponseCaptureNavigationThrottle>
weak_ptr_factory_{this};
};
} // namespace profile_management
#endif // CHROME_BROWSER_ENTERPRISE_PROFILE_MANAGEMENT_OIDC_AUTH_RESPONSE_CAPTURE_NAVIGATION_THROTTLE_H_
|