2 * Copyright 2008, Google Inc.
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions are
9 * * Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
11 * * Redistributions in binary form must reproduce the above
12 * copyright notice, this list of conditions and the following disclaimer
13 * in the documentation and/or other materials provided with the
15 * * Neither the name of Google Inc. nor the names of its
16 * contributors may be used to endorse or promote products derived from
17 * this software without specific prior written permission.
19 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
20 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
21 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
22 * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
23 * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
24 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
25 * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
26 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
27 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
28 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
29 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
39 #include "native_client/npapi_plugin/origin.h"
42 # define dprintf(alist) printf alist
44 # define dprintf(alist)
49 std::string
UrlToOrigin(std::string url
) {
50 std::string::iterator it
= find(url
.begin(), url
.end(), ':');
51 if (url
.end() == it
) {
52 dprintf(("no protospec separator found\n"));
55 for (int num_slashes
= 0; num_slashes
< 3; ++num_slashes
) {
56 it
= find(it
+ 1, url
.end(), '/');
57 if (url
.end() == it
) {
58 dprintf(("no start of pathspec found\n"));
63 std::string
origin(url
.begin(), it
);
66 // Domain names are in ascii and case insensitive, so we can
67 // canonicalize to all lower case. NB: Internationalizing Domain
68 // Names in Applications (IDNA) encodes unicode in this reduced
71 for (it
= origin
.begin(); origin
.end() != it
; ++it
) {
75 // cannonicalize empty hostname as "localhost"
77 if ("file://" == origin
) {
78 origin
= "file://localhost";
83 // For now we are just checking that NaCl modules are local, or on
84 // code.google.com. Beware NaCl modules in the browser cache!
86 // Eventually, after sufficient security testing, we will always
88 bool OriginIsInWhitelist(std::string origin
) {
89 static char const *allowed_origin
[] = {
90 "file://localhost", // for testing
92 "http://code.google.com", // for demos hosted on project website
95 for (size_t i
= 0; i
< sizeof allowed_origin
/sizeof allowed_origin
[0]; ++i
) {
96 if (origin
== allowed_origin
[i
]) {