1/*
2 * Copyright (C) 2009 Apple Inc. All Rights Reserved.
3 *
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that the following conditions
6 * are met:
7 * 1. Redistributions of source code must retain the above copyright
8 * notice, this list of conditions and the following disclaimer.
9 * 2. Redistributions in binary form must reproduce the above copyright
10 * notice, this list of conditions and the following disclaimer in the
11 * documentation and/or other materials provided with the distribution.
12 *
13 * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
14 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
16 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR
17 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
18 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
19 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
20 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
21 * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
22 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
23 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
24 */
25
26#pragma once
27
28#include "Credential.h"
29#include "ProtectionSpaceHash.h"
30#include "SecurityOriginData.h"
31#include <wtf/HashMap.h>
32#include <wtf/HashSet.h>
33#include <wtf/text/StringHash.h>
34#include <wtf/text/WTFString.h>
35
36namespace WebCore {
37
38class ProtectionSpace;
39
40class CredentialStorage {
41public:
42 // WebCore session credential storage.
43 WEBCORE_EXPORT void set(const String&, const Credential&, const ProtectionSpace&, const URL&);
44 WEBCORE_EXPORT Credential get(const String&, const ProtectionSpace&);
45 WEBCORE_EXPORT void remove(const String&, const ProtectionSpace&);
46 WEBCORE_EXPORT void removeCredentialsWithOrigin(const SecurityOriginData&);
47
48 // OS persistent storage.
49 WEBCORE_EXPORT static Credential getFromPersistentStorage(const ProtectionSpace&);
50 WEBCORE_EXPORT static Vector<SecurityOriginData> originsWithPersistentCredentials();
51
52 WEBCORE_EXPORT void clearCredentials();
53
54 // These methods work for authentication schemes that support sending credentials without waiting for a request. E.g., for HTTP Basic authentication scheme
55 // a client should assume that all paths at or deeper than the depth of a known protected resource share are within the same protection space.
56 WEBCORE_EXPORT bool set(const String&, const Credential&, const URL&); // Returns true if the URL corresponds to a known protection space, so credentials could be updated.
57 WEBCORE_EXPORT Credential get(const String&, const URL&);
58
59 WEBCORE_EXPORT Vector<SecurityOriginData> originsWithCredentials() const;
60
61private:
62 HashMap<std::pair<String /* partitionName */, ProtectionSpace>, Credential> m_protectionSpaceToCredentialMap;
63 HashSet<String> m_originsWithCredentials;
64
65 typedef HashMap<String, ProtectionSpace> PathToDefaultProtectionSpaceMap;
66 PathToDefaultProtectionSpaceMap m_pathToDefaultProtectionSpaceMap;
67
68 PathToDefaultProtectionSpaceMap::iterator findDefaultProtectionSpaceForURL(const URL&);
69};
70
71} // namespace WebCore
72