1/*
2 * Copyright (C) 2013 Google, Inc. All Rights Reserved.
3 * Copyright (C) 2017 Apple Inc. All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
13 *
14 * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
15 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
17 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR
18 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
19 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
20 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
21 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
22 * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
24 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25 */
26
27#pragma once
28
29#include <wtf/URL.h>
30#include <wtf/text/TextPosition.h>
31
32namespace WebCore {
33
34class Document;
35class FormData;
36
37// FIXME: Should change into a struct.
38// FIXME: Should return by value instead of using a unique_ptr.
39class XSSInfo {
40 WTF_MAKE_FAST_ALLOCATED;
41public:
42 XSSInfo(const String& originalURL, bool didBlockEntirePage, bool didSendXSSProtectionHeader)
43 : m_originalURL(originalURL.isolatedCopy())
44 , m_didBlockEntirePage(didBlockEntirePage)
45 , m_didSendXSSProtectionHeader(didSendXSSProtectionHeader)
46 {
47 }
48
49 String m_originalURL;
50 bool m_didBlockEntirePage;
51 bool m_didSendXSSProtectionHeader;
52 TextPosition m_textPosition;
53};
54
55class XSSAuditorDelegate {
56public:
57 explicit XSSAuditorDelegate(Document&);
58
59 void didBlockScript(const XSSInfo&);
60 void setReportURL(const URL& url) { m_reportURL = url; }
61
62private:
63 Ref<FormData> generateViolationReport(const XSSInfo&);
64
65 Document& m_document;
66 bool m_didSendNotifications { false };
67 URL m_reportURL;
68};
69
70} // namespace WebCore
71