1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237
|
// Copyright 2013 The Chromium Authors
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
#include "components/autofill/core/browser/data_quality/validation.h"
#include <stddef.h>
#include <ostream>
#include <string_view>
#include "base/check.h"
#include "base/containers/adapters.h"
#include "base/containers/contains.h"
#include "base/containers/fixed_flat_map.h"
#include "base/containers/fixed_flat_set.h"
#include "base/notreached.h"
#include "base/strings/string_number_conversions.h"
#include "base/strings/string_util.h"
#include "base/strings/utf_string_conversions.h"
#include "base/time/time.h"
#include "components/autofill/core/browser/country_type.h"
#include "components/autofill/core/browser/geo/phone_number_i18n.h"
#include "components/autofill/core/browser/geo/state_names.h"
#include "components/autofill/core/common/autofill_regex_constants.h"
#include "components/autofill/core/common/autofill_regexes.h"
#include "components/autofill/core/common/credit_card_network_identifiers.h"
#include "components/strings/grit/components_strings.h"
namespace autofill {
bool IsValidCreditCardExpirationDate(int year, int month, base::Time now) {
if (month < 1 || month > 12) {
return false;
}
base::Time::Exploded now_exploded;
now.LocalExplode(&now_exploded);
// Convert 2-digit year to 4-digit year.
if (year < 100) {
year += (now_exploded.year / 100) * 100;
}
return year > now_exploded.year ||
(year == now_exploded.year && month >= now_exploded.month);
}
bool IsValidCreditCardExpirationYear(int year, base::Time now) {
base::Time::Exploded now_exploded;
now.LocalExplode(&now_exploded);
return year >= now_exploded.year;
}
bool IsValidCreditCardSecurityCode(std::u16string_view code,
std::string_view card_network,
CvcType cvc_type) {
return code.length() == GetCvcLengthForCardNetwork(card_network, cvc_type) &&
base::ContainsOnlyChars(code, u"0123456789");
}
bool IsValidEmailAddress(std::u16string_view text) {
// E-Mail pattern as defined by the WhatWG. (4.10.7.1.5 E-Mail state)
static constexpr char16_t kEmailPattern[] =
u"^[a-zA-Z0-9.!#$%&'*+/=?^_`{|}~-]+@[a-zA-Z0-9-]+(?:\\.[a-zA-Z0-9-]+)*$";
return MatchesRegex<kEmailPattern>(text);
}
bool IsValidState(std::u16string_view text) {
return !state_names::GetAbbreviationForName(text).empty() ||
!state_names::GetNameForAbbreviation(text).empty();
}
bool IsPossiblePhoneNumber(std::u16string_view text,
const std::string& country_code) {
return i18n::IsPossiblePhoneNumber(base::UTF16ToUTF8(text), country_code);
}
bool IsValidZip(std::u16string_view text,
const AddressCountryCode& country_code,
bool extended_validation) {
static constexpr char16_t kUsZipPattern[] = u"^\\d{5}(-\\d{4})?$";
if (extended_validation) {
// A valid zip code string can contain only digits, uppercase Latin letters,
// hyphens, and spaces.
// [Ref: https://en.wikipedia.org/wiki/List_of_postal_codes]
static constexpr char16_t kDefaultZipPattern[] = u"^[A-Z0-9- ]+$";
static constexpr char16_t kNumericZipPattern[] = u"^[0-9- ]+$";
static constexpr char16_t kJpZipCharacters[] = u"^[〒0-9- 0-9- ]+$";
// Defines the lower boundary of zip code lengths for countries with split
// zip format. This check prevents a ZIP prefix (e.g., the first 3 digits
// out of 8 in JP) from being imported as a full ZIP code from a form with
// split zip fields. For most countries, the min length constant is simply
// the prefix length + 1, because it's safer to use a smaller value than
// the exact minimal zip length in case the zip format changes.
// [Ref: https://en.wikipedia.org/wiki/List_of_postal_codes]
static constexpr auto kZipCodeMinLengthMap =
base::MakeFixedFlatMap<std::string_view, std::size_t>({{"BR", 6},
{"CA", 4},
{"CZ", 4},
{"GB", 5},
{"GR", 4},
{"IE", 4},
{"IN", 4},
{"JP", 4},
{"NL", 5},
{"PL", 3},
{"PT", 5},
{"SE", 4}});
// A set of some of the biggest countries with a strictly numeric zip code
// format + countries with split numeric zip format (e.g., "GR", "PT").
static constexpr auto kNumericZipCodeCountriesSet =
base::MakeFixedFlatSet<std::string_view>({"BR", "CH", "CN", "DE", "ES",
"GR", "IN", "IT", "MX", "PL",
"PT", "RU", "SE"});
auto it = kZipCodeMinLengthMap.find(country_code.value());
if (it != kZipCodeMinLengthMap.end() && text.length() < it->second) {
return false;
}
if (country_code == AddressCountryCode("US")) {
return MatchesRegex<kUsZipPattern>(text);
}
if (country_code == AddressCountryCode("JP")) {
return MatchesRegex<kJpZipCharacters>(text);
}
if (base::Contains(kNumericZipCodeCountriesSet, country_code.value())) {
return MatchesRegex<kNumericZipPattern>(text);
}
return MatchesRegex<kDefaultZipPattern>(text);
} else {
if (country_code != AddressCountryCode("US")) {
return true;
}
return MatchesRegex<kUsZipPattern>(text);
}
}
bool IsSSN(std::u16string_view text) {
std::u16string number_string;
base::RemoveChars(text, u"- ", &number_string);
// A SSN is of the form AAA-GG-SSSS (A = area number, G = group number, S =
// serial number). The validation we do here is simply checking if the area,
// group, and serial numbers are valid.
//
// Historically, the area number was assigned per state, with the group number
// ascending in an alternating even/odd sequence. With that scheme it was
// possible to check for validity by referencing a table that had the highest
// group number assigned for a given area number. (This was something that
// Chromium never did though, because the "high group" values were constantly
// changing.)
//
// However, starting on 25 June 2011 the SSA began issuing SSNs randomly from
// all areas and groups. Group numbers and serial numbers of zero remain
// invalid, and areas 000, 666, and 900-999 remain invalid.
//
// References for current practices:
// http://www.socialsecurity.gov/employer/randomization.html
// http://www.socialsecurity.gov/employer/randomizationfaqs.html
//
// References for historic practices:
// http://www.socialsecurity.gov/history/ssn/geocard.html
// http://www.socialsecurity.gov/employer/stateweb.htm
// http://www.socialsecurity.gov/employer/ssnvhighgroup.htm
if (number_string.length() != 9 || !base::IsStringASCII(number_string)) {
return false;
}
int area;
if (!base::StringToInt(std::u16string_view(number_string).substr(0, 3),
&area)) {
return false;
}
if (area < 1 || area == 666 || area >= 900) {
return false;
}
int group;
if (!base::StringToInt(std::u16string_view(number_string).substr(3, 2),
&group) ||
group == 0) {
return false;
}
int serial;
if (!base::StringToInt(std::u16string_view(number_string).substr(5, 4),
&serial) ||
serial == 0) {
return false;
}
return true;
}
size_t GetCvcLengthForCardNetwork(std::string_view card_network,
CvcType cvc_type) {
if (card_network == kAmericanExpressCard &&
cvc_type == CvcType::kRegularCvc) {
return AMEX_CVC_LENGTH;
}
return GENERAL_CVC_LENGTH;
}
bool IsUPIVirtualPaymentAddress(std::u16string_view value) {
return MatchesRegex<kUPIVirtualPaymentAddressRe>(value);
}
bool IsInternationalBankAccountNumber(std::u16string_view value) {
std::u16string no_spaces;
base::RemoveChars(value, u" ", &no_spaces);
return MatchesRegex<kInternationalBankAccountNumberValueRe>(no_spaces);
}
bool IsPlausibleCreditCardCVCNumber(std::u16string_view value) {
return MatchesRegex<kCreditCardCVCPattern>(value);
}
bool IsPlausible4DigitExpirationYear(std::u16string_view value) {
return MatchesRegex<kCreditCard4DigitExpYearPattern>(value);
}
bool IsValidNameOnCard(std::u16string_view name) {
static constexpr size_t kMaxNameOnCardLength = 26;
static constexpr char16_t kInvalidNameCharacters[] =
u"[0-9@#$^*()\\[\\]<>{}=?\"“”|•]";
if (name.length() > kMaxNameOnCardLength) {
return false;
}
return !MatchesRegex<kInvalidNameCharacters>(name);
}
} // namespace autofill
|