/** * This file is part of Haketilo. * * Function: Miscellaneous operations refactored to a separate file. * * Copyright (C) 2021 Wojtek Kosior * Copyright (C) 2021 jahoti * * This program is free software: you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation, either version 3 of the License, or * (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * As additional permission under GNU GPL version 3 section 7, you * may distribute forms of that code without the copy of the GNU * GPL normally required by section 4, provided you include this * license notice and, in case of non-source distribution, a URL * through which recipients can access the Corresponding Source. * If you modify file(s) with this exception, you may extend this * exception to your version of the file(s), but you are not * obligated to do so. If you do not wish to do so, delete this * exception statement from your version. * * As a special exception to the GPL, any HTML file which merely * makes function calls to this code, and for that purpose * includes it by reference shall be deemed a separate work for * copyright law purposes. If you modify this code, you may extend * this exception to your version of the code, but you are not * obligated to do so. If you do not wish to do so, delete this * exception statement from your version. * * You should have received a copy of the GNU General Public License * along with this program. If not, see <https://www.gnu.org/licenses/>. * * I, Wojtek Kosior, thereby promise not to sue for violation of this file's * license. Although I request that you do not make use this code in a * proprietary program, I am not going to enforce this in court. */ /* * IMPORTS_START * IMPORT browser * IMPORT TYPE_NAME * IMPORT TYPE_PREFIX * IMPORTS_END */ /* Generate a random base64-encoded 128-bit sequence */ function gen_nonce() { let randomData = new Uint8Array(16); crypto.getRandomValues(randomData); return btoa(String.fromCharCode.apply(null, randomData)); } /* * generating unique, per-site value that can be computed synchronously * and is impossible to guess for a malicious website */ /* Uint8toHex is a separate function not exported as (a) it's useful and (b) it will be used in crypto.subtle-based digests */ function Uint8toHex(data) { let returnValue = ''; for (let byte of data) returnValue += ('00' + byte.toString(16)).slice(-2); return returnValue; } function gen_nonce(length=16) { let randomData = new Uint8Array(length); crypto.getRandomValues(randomData); return Uint8toHex(randomData); } /* CSP rule that blocks scripts according to policy's needs. */ function make_csp_rule(policy) { let rule = "prefetch-src 'none'; script-src-attr 'none';"; const script_src = policy.nonce !== undefined ? `'nonce-${policy.nonce}'` : "'none'"; rule += ` script-src ${script_src}; script-src-elem ${script_src};`; return rule; } /* Check if some HTTP header might define CSP rules. */ const csp_header_regex = /^\s*(content-security-policy|x-webkit-csp|x-content-security-policy)/i; /* * Print item together with type, e.g. * nice_name("s", "hello") → "hello (script)" */ function nice_name(prefix, name) { return `${name} (${TYPE_NAME[prefix]})`; } /* Open settings tab with given item's editing already on. */ function open_in_settings(prefix, name) { name = encodeURIComponent(name); const url = browser.runtime.getURL("html/options.html#" + prefix + name); window.open(url, "_blank"); } /* * Check if url corresponds to a browser's special page (or a directory index in * case of `file://' protocol). */ const privileged_reg = /^(chrome(-extension)?|moz-extension):\/\/|^about:|^file:\/\/.*\/$/; const is_privileged_url = url => privileged_reg.test(url); /* Parse a CSP header */ function parse_csp(csp) { let directive, directive_array; let directives = {}; for (directive of csp.split(';')) { directive = directive.trim(); if (directive === '') continue; directive_array = directive.split(/\s+/); directive = directive_array.shift(); /* The "true" case should never occur; nevertheless... */ directives[directive] = directive in directives ? directives[directive].concat(directive_array) : directive_array; } return directives; } /* Regexes and objects to use as/in schemas for parse_json_with_schema(). */ const nonempty_string_matcher = /.+/; const matchers = { sha256: /^[0-9a-f]{64}$/, nonempty_string: nonempty_string_matcher, component: [ new RegExp(`^[${TYPE_PREFIX.SCRIPT}${TYPE_PREFIX.BAG}]$`), nonempty_string_matcher ] }; /* * EXPORTS_START * EXPORT gen_nonce * EXPORT make_csp_rule * EXPORT csp_header_regex * EXPORT nice_name * EXPORT open_in_settings * EXPORT is_privileged_url * EXPORT matchers * EXPORTS_END */