From b3896f5f175eeb57afde6191a8bc291c65859bb0 Mon Sep 17 00:00:00 2001 From: Yan Zhu Date: Sun, 21 Sep 2014 23:57:22 -0700 Subject: [PATCH 1/4] Add HTTP Nowhere mode to Chromium Adds mode for blocking HTTP requests entirely after HTTPS Everywhere rewrites. Switches UI button from PageAction to BrowserAction, because why was it a PageAction in the first place? --- chromium/background.js | 73 +++++++++++++++++++++++++--------------- chromium/icon38-red.png | Bin 0 -> 2792 bytes chromium/icon38.png | Bin 0 -> 2763 bytes chromium/manifest.json | 7 ++-- chromium/popup.html | 4 +++ chromium/popup.js | 28 +++++++++++++++ 6 files changed, 82 insertions(+), 30 deletions(-) create mode 100644 chromium/icon38-red.png create mode 100644 chromium/icon38.png diff --git a/chromium/background.js b/chromium/background.js index e399304d31b4..6a2a5cef5952 100644 --- a/chromium/background.js +++ b/chromium/background.js @@ -29,6 +29,26 @@ var switchPlannerEnabledFor = {}; // rw / nrw stand for "rewritten" versus "not rewritten" var switchPlannerInfo = {}; +// Load prefs about whether http nowhere is on. Structure is: +// { httpNowhere: true/false } +var httpNowhereOn = false; +chrome.storage.sync.get({httpNowhere: false}, function(item) { + httpNowhereOn = item.httpNowhere; + setIconColor(); +}); +chrome.storage.onChanged.addListener(function(changes, areaName) { + if (areaName === 'sync') { + for (key in changes) { + if (key !== 'httpNowhere') { + return; + } else { + httpNowhereOn = changes[key].newValue; + setIconColor(); + } + } + } +}); + var getStoredUserRules = function() { var oldUserRuleString = localStorage.getItem(USER_RULE_KEY); var oldUserRules = []; @@ -48,6 +68,15 @@ var loadStoredUserRules = function() { }; loadStoredUserRules(); + +// Set the icon color correctly +var setIconColor = function() { + var newIconPath = httpNowhereOn ? './icon38-red.png' : './icon38.png'; + chrome.browserAction.setIcon({ + path: newIconPath + }); +} + /* for (var v in localStorage) { log(DBUG, "localStorage["+v+"]: "+localStorage[v]); @@ -124,6 +153,9 @@ function onBeforeRequest(details) { // todo: check that this is enough var uri = new URI(details.url); + // Should the request be canceled? + var shouldCancel = (httpNowhereOn && uri.protocol() === 'http'); + // Normalise hosts such as "www.example.com." var canonical_host = uri.hostname(); if (canonical_host.charAt(canonical_host.length - 1) == ".") { @@ -145,7 +177,7 @@ function onBeforeRequest(details) { " changed before processing to " + canonical_url); } if (canonical_url in urlBlacklist) { - return null; + return {cancel: shouldCancel}; } if (details.type == "main_frame") { @@ -162,7 +194,7 @@ function onBeforeRequest(details) { var hostname = uri.hostname(); domainBlacklist[hostname] = true; log(WARN, "Domain blacklisted " + hostname); - return null; + return {cancel: shouldCancel}; } var newuristr = null; @@ -174,10 +206,11 @@ function onBeforeRequest(details) { } } + var finaluri = newuristr ? new URI(newuristr) : null; + if (newuristr && tmpuserinfo !== "") { // re-insert userpass info which was stripped temporarily // while rules were applied - var finaluri = new URI(newuristr); finaluri.userinfo(tmpuserinfo); newuristr = finaluri.toString(); } @@ -192,11 +225,17 @@ function onBeforeRequest(details) { newuristr); } + if (httpNowhereOn) { + if (finaluri && finaluri.protocol() === "http") { + // Abort early if we're about to redirect to HTTP in HTTP Nowhere mode + return {cancel: true}; + } + } + if (newuristr) { - log(DBUG, "Redirecting from "+details.url+" to "+newuristr); return {redirectUrl: newuristr}; } else { - return null; + return {cancel: shouldCancel}; } } @@ -204,8 +243,7 @@ function onBeforeRequest(details) { // Map of which values for the `type' enum denote active vs passive content. // https://developer.chrome.com/extensions/webRequest.html#event-onBeforeRequest var activeTypes = { stylesheet: 1, script: 1, object: 1, other: 1}; -// We consider sub_frame to be passive even though it can contain JS or Flash. -// This is because code running the sub_frame cannot access the main frame's + // content, by same-origin policy. This is true even if the sub_frame is on the // same domain but different protocol - i.e. HTTP while the parent is HTTPS - // because same-origin policy includes the protocol. This also mimics Chrome's @@ -402,27 +440,6 @@ wr.onBeforeRequest.addListener(onBeforeRequest, {urls: ["https://*/*", "http://* wr.onBeforeRedirect.addListener(onBeforeRedirect, {urls: ["https://*/*"]}); -// Add the small HTTPS Everywhere icon in the address bar. -// Note: We can't use any other hook (onCreated, onActivated, etc.) because Chrome resets the -// pageActions on URL change. We should strongly consider switching from pageAction to browserAction. -chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) { - if (changeInfo.status === "loading") { - chrome.pageAction.show(tabId); - } -}); - -// Pre-rendered tabs / instant experiments sometimes skip onUpdated. -// See http://crbug.com/109557 -chrome.tabs.onReplaced.addListener(function(addedTabId, removedTabId) { - chrome.tabs.get(addedTabId, function(tab) { - if(typeof(tab) === "undefined") { - log(DBUG, "Not a real tab. Skipping showing pageAction."); - } else { - chrome.pageAction.show(addedTabId); - } - }); -}); - // Listen for cookies set/updated and secure them if applicable. This function is async/nonblocking. chrome.cookies.onChanged.addListener(onCookieChanged); diff --git a/chromium/icon38-red.png b/chromium/icon38-red.png new file mode 100644 index 0000000000000000000000000000000000000000..3586baed05fd90d13a511a3f9c53436ada04339c GIT binary patch literal 2792 zcmVP)1-2yv;N|fOhaZH>GfXhp> zO9T53?4)q~E~KRo04BS#+LcTFF4;;KTal=#qP4O?F6h{0Ld17&i%g^o7=YDoNg@W+ zn0x)-;nHU-XZRjrPpDloys>+gn7Uv(k!aF?%{p)ZEUyREwnw0J_K=Zhuw{Sd5-xH1gFO z;8Cw+0T*KpMqM1zba<8F$Ws^C%<3b!M%-L6T>*eu_T1mkhlA&47C!o=N)v*vl=I3_ z^2KoL@=9%Sr>>rboqA+%d}<$6qU=kFR1oH%E4>O_Vs!4Ex2m@-n6F)Yo}KUQKVNY* z+@ZOf77ys>0)QDPQIxBk1)5#ZSvBc$q@IZP2BVir8l^^t>xtjho!Xo|sImBjs@Z<(azEyKhFJdQb)!fN=|z(n7pjsoFvFe9%y%9g^3<$^i?_a<|Le#2Iuz1xF$C*yto>8z0O+>7;@;HU zdVrnI^#byrsd!=?7-_Ovo=&9oH~NJ90ly=6M{X=NEssn_$NYRzJZ}~iF8l?|9oztb z$cG=nzj8gA-+Leac#Nx|(;0{Mmj2T*(>A`eEd~H1k%#^8w~w(!idzvyMR5btWY5oC z_jL8iqoaBccrh7l2?)kwq!KgJk8c=N7}KW~v&x-JR;6g%7%F~b2`H98bmyBe>Y895 zJrtIrLKyr04r&cinxMyZy<4E#hheLh@3-wcD)z(A{48PR?soXtDI?1`7-SuW@;DMs#SnbHVejr4K6R~Z(ps(GC^y3?m zK3)aufZoU`?E*Kc=m15{m1JZlQWep)>%C2o2JZ*aoc7g$x*MkfANU`>sx$!JjL!go z?-M4|Q=E=0%PVQjKvFoF$gOH{dOR@YdoK7AfxLyFOgE5-1F8zGix>7oN08alf=n`m zRo6>wCT(>2VDFh*M%o2%#<*JNX8_=5+w5kr%ccWBG7_6)l2X_}uxKV&$B%}&d^o@i z%WYF&d+teCpLhsrX$i=r!9K47)?THs2>}-raxp`efMAg<%rXsq$90!J zeF%L}i84`%Bkc!9cQEEG(*yvdA#`EGb3K@vGwiP_EAFlM@cw1I zxtk&ToxI4HBL`@Tfd*w2>_1-<9(MhBacv|%4#0c?VNYgcJZ8(ydY@V&BU7!dnMR#o zCVl5P>hmE~Q-ff2HJWOwQD0NTXB++OOGZVbS=6;=T4zwdo)0&NTAGBUJPUJvrWBkl zfov$SLm?A{5lg484IcV9wmTO5KnvK#Y~0B7ycc-C8g$cri){O!dF8NTwLc0Y-4i6z zg0R&ydT4cc=T7+qz$;uGy>5eFb4B9)><}O@bhH&l0*nY4%?c2+n)X6d@7mB(d+K>W z%mm~Tcd^G~HBHZH3O}5cHZmL}NHQY;i5lpJPvKZJ%Q|IiqyJqHNYR3wl$X#db52&T z(L<35%(C2+zx2lmn)IejX$%jt?BnwTpjYfPXNz!3ts z5_3T67O8XDaBs;jrCG$)Kf-6s&n_4zLXjD|qBU6zw4_tI0swDQIgJVJHIDb_MLn?v z-QO{mhm*;YW{35GKZMV(o3rvBt8MSmTv8zT=OgMjFI*8rxB+7yeo`z)AMr3gHpZhj zO#MIA=SQwL;cV5WxSn)IAdmqCAf_aknutY;h!w-=lW1&ya9B6bFKOxEVIt;l8juRM z<_fbG063zUtc@Gbo$|Li)mW?;7|v=qUtf`GXjrR){;d?`Pfqww`k()=9rb6+K)+hu znKZE6focH2g07jg`STWD*tyq@srveth2&F$5VfhM7z06_jbK_8F(?!yNdaLt1(GIZ zA6Zp1#r5Q+AB;i|0z&v3&NBdvK}Q-iytCVX==g_7B)h?B-#vEEo|`{;XppqNcZ2je zkCIOZWIT^o?KuIO^u>ADPE@02Gf=z$SlV}}Jy?Cl4ni7>F!k;98TkO3600003Rp=* zK~z}7x3(F209k4My=HDbqm z-47-eu5bu#0KlVX9F;2LlQe2*!a-{`OS!dc^)a&+O>c{*Hf5EnfnWpz{+tZ}yE_R0 ze|jE^M$uYgiCF!aqO4)TjR&&ok*rcRB&7lY%p3y%oZR(4z!-rSztUn|I>orZ0;_Gc72AK@EOL+ zu*ceb{iu=2%U)`cc*)D?*`h-;n(j>nO6Q338ZN7<)F;iH^=FbTKc#;B|u0P`S3RWmOh)$3AA$mH7q@#jp=S;t_}qb5wgr!SR_u@H;% zF6Q3yYI>4gRx^t$hO$*vE2oaErPX7HBEy8Odu?=NT}-YD;FuyWo{DMoyC71o>t^i} zcK7sQ<;?NTPnlkU=4LKrqZLQNW5zC(dShpzW>9#=>s!|+uy7H*YPY5m=ihy=$1=tR zyxyB_Z}@yJsRqibq_374}W&n`H$FUFq1S~^hSja$;DF6m)yaGf0 z62trwA%g%AhWI6_{U(HIfh`}iH;5cWbxJAVxw?N{Tpo2jwq-5@^T4b<&N1Fb@eBCgAZx8(yJY1$^HDR=?l*h8qAO1fo$rfa-#P(EP$TbpCt@#0vGi?5adxaU1{*z29WD=+)WJrZ?u#37#hSi|?_}CoD(c}y0xr|X!C&AgYH?R4$eioONjyX#Vt)JrUaOFCs z0j>3^f#E0rQV$=T)-z`imM{MhAOH*ju$LJiB1~FNcy@)ZKL4uXyv~hfrp8pba;mDX zt0=D>t_N3@i=f{Rk_MOv#0+Q`%E=?vpTz#IUQWbfBr}O#!_Btm)2S1+)(pdx!W$%M znsB59Wpj*p2Nl`9+m@eTHeU1O3v7lqXs2a#!DD3spu+*iba2i7S6Y(e&L1mM)uX0? zu@Hg+MR0De2>PGvcQLU)lP~G8UESK3FPsUM>pE`cX0RqeVl7=6`uaC z_F_9R=d>bTm5BHCXrd}Mywy5X!n$Y>5Gnh(8=<_7t5NPw4hSu!)^^^S?Z`{h^Z!90Cg2fM|JVm47 z2>?O>$|(eflLIm-$Ycz@d}fCUz9Rnc9lLPV7J(nn)x~qJt@MQ}FX#!BuW~}AMdS?< zYYil0KxeCxJ#BVr)}Gn@yUouKK$0g*iP!JdZ}}_MB=XL5W_+d8Z>?>A=+2+oZ|;o0 z?VBi?j{hsaa^f*KH?Q(;XUpn4WDV*;v95X!n z`ya3DK_nuvWsM#giJE(_yfG1Kc{G(~EYL!l1SY6FQ#Qq9Cs_B#yslPX7&f~8(cUtd zG4QL0R9QpQw1gIOq!c~Mu;Tf=QwWORJxQ24MU_ACCgGeD@pQxdWjQBR7fi*kP2TtO zbt^7e;M-w&E2Kw=h@m^L{Mkl331C%fiomjE0;^Uj`Q52_?FT;hbN(i4Z<_9OZ99Za z8t@l^1PHktQKCnXa#)c#r8}Ejdcv?Xze8i@eNS|y?9=0!e1%7f7=V;z8QuFHT;EZk zB*y6rZzw&`-QC!g&aH)EyjkNl8rqt(9f)oD2;aU*sRA|cX-*KY&d$BxryDA$&(`?L@-ONyA~JEEGiL%w@?nZ+ zP8WFeaUGaG|M8sToLb`Zt@(Ua;1?}-txFDkS3H6+`YeItx(cP)VVR78Q%_>-sAoJg z>EknB" ], "update_url": "https://www.eff.org/files/https-everywhere-chrome-updates.xml", diff --git a/chromium/popup.html b/chromium/popup.html index 58ff2308caa7..a95e22f23304 100755 --- a/chromium/popup.html +++ b/chromium/popup.html @@ -14,6 +14,10 @@

+
+ + +
Add a rule for this site