1
|
/**
|
2
|
* This file is part of Haketilo.
|
3
|
*
|
4
|
* Function: Miscellaneous operations refactored to a separate file.
|
5
|
*
|
6
|
* Copyright (C) 2021 Wojtek Kosior
|
7
|
* Copyright (C) 2021 jahoti
|
8
|
*
|
9
|
* This program is free software: you can redistribute it and/or modify
|
10
|
* it under the terms of the GNU General Public License as published by
|
11
|
* the Free Software Foundation, either version 3 of the License, or
|
12
|
* (at your option) any later version.
|
13
|
*
|
14
|
* This program is distributed in the hope that it will be useful,
|
15
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
16
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
17
|
* GNU General Public License for more details.
|
18
|
*
|
19
|
* As additional permission under GNU GPL version 3 section 7, you
|
20
|
* may distribute forms of that code without the copy of the GNU
|
21
|
* GPL normally required by section 4, provided you include this
|
22
|
* license notice and, in case of non-source distribution, a URL
|
23
|
* through which recipients can access the Corresponding Source.
|
24
|
* If you modify file(s) with this exception, you may extend this
|
25
|
* exception to your version of the file(s), but you are not
|
26
|
* obligated to do so. If you do not wish to do so, delete this
|
27
|
* exception statement from your version.
|
28
|
*
|
29
|
* As a special exception to the GPL, any HTML file which merely
|
30
|
* makes function calls to this code, and for that purpose
|
31
|
* includes it by reference shall be deemed a separate work for
|
32
|
* copyright law purposes. If you modify this code, you may extend
|
33
|
* this exception to your version of the code, but you are not
|
34
|
* obligated to do so. If you do not wish to do so, delete this
|
35
|
* exception statement from your version.
|
36
|
*
|
37
|
* You should have received a copy of the GNU General Public License
|
38
|
* along with this program. If not, see <https://www.gnu.org/licenses/>.
|
39
|
*
|
40
|
* I, Wojtek Kosior, thereby promise not to sue for violation of this file's
|
41
|
* license. Although I request that you do not make use of this code in a
|
42
|
* proprietary program, I am not going to enforce this in court.
|
43
|
*/
|
44
|
|
45
|
#FROM common/browser.js IMPORT browser
|
46
|
#FROM common/stored_types.js IMPORT TYPE_NAME, TYPE_PREFIX
|
47
|
|
48
|
/* uint8_to_hex is a separate function used in cryptographic functions. */
|
49
|
const uint8_to_hex =
|
50
|
array => [...array].map(b => ("0" + b.toString(16)).slice(-2)).join("");
|
51
|
|
52
|
/*
|
53
|
* Asynchronously compute hex string representation of a sha256 digest of a
|
54
|
* UTF-8 string.
|
55
|
*/
|
56
|
async function sha256_async(string) {
|
57
|
const input_ab = new TextEncoder("utf-8").encode(string);
|
58
|
const digest_ab = await crypto.subtle.digest("SHA-256", input_ab);
|
59
|
return uint8_to_hex(new Uint8Array(digest_ab));
|
60
|
}
|
61
|
#EXPORT sha256_async
|
62
|
|
63
|
/*
|
64
|
* Generate a unique value that can be computed synchronously and is impossible
|
65
|
* to guess for a malicious website.
|
66
|
*/
|
67
|
function gen_nonce(length=16)
|
68
|
{
|
69
|
const random_data = new Uint8Array(length);
|
70
|
crypto.getRandomValues(random_data);
|
71
|
return uint8_to_hex(random_data);
|
72
|
}
|
73
|
#EXPORT gen_nonce
|
74
|
|
75
|
/* Check if some HTTP header might define CSP rules. */
|
76
|
const csp_header_regex =
|
77
|
/^\s*(content-security-policy|x-webkit-csp|x-content-security-policy)/i;
|
78
|
#EXPORT csp_header_regex
|
79
|
|
80
|
/*
|
81
|
* Print item together with type, e.g.
|
82
|
* nice_name("s", "hello") → "hello (script)"
|
83
|
*/
|
84
|
#EXPORT (prefix, name) => `${name} (${TYPE_NAME[prefix]})` AS nice_name
|
85
|
|
86
|
/* Open settings tab with given item's editing already on. */
|
87
|
function open_in_settings(prefix, name)
|
88
|
{
|
89
|
name = encodeURIComponent(name);
|
90
|
const url = browser.runtime.getURL("html/options.html#" + prefix + name);
|
91
|
window.open(url, "_blank");
|
92
|
}
|
93
|
#EXPORT open_in_settings
|
94
|
|
95
|
/*
|
96
|
* Check if url corresponds to a browser's special page (or a directory index in
|
97
|
* case of `file://' protocol).
|
98
|
*/
|
99
|
#IF MOZILLA
|
100
|
const priv_reg = /^moz-extension:\/\/|^about:|^file:\/\/[^?#]*\/([?#]|$)/;
|
101
|
#ELIF CHROMIUM
|
102
|
const priv_reg = /^chrome(-extension)?:\/\/|^about:|^file:\/\/[^?#]*\/([?#]|$)/;
|
103
|
#ENDIF
|
104
|
#EXPORT url => priv_reg.test(url) AS is_privileged_url
|
105
|
|
106
|
/* Parse a CSP header */
|
107
|
function parse_csp(csp) {
|
108
|
let directive, directive_array;
|
109
|
let directives = {};
|
110
|
for (directive of csp.split(';')) {
|
111
|
directive = directive.trim();
|
112
|
if (directive === '')
|
113
|
continue;
|
114
|
|
115
|
directive_array = directive.split(/\s+/);
|
116
|
directive = directive_array.shift();
|
117
|
/* The "true" case should never occur; nevertheless... */
|
118
|
directives[directive] = directive in directives ?
|
119
|
directives[directive].concat(directive_array) :
|
120
|
directive_array;
|
121
|
}
|
122
|
return directives;
|
123
|
}
|
124
|
|
125
|
/* Regexes and objects to use as/in schemas for parse_json_with_schema(). */
|
126
|
const nonempty_string_matcher = /.+/;
|
127
|
|
128
|
const matchers = {
|
129
|
sha256: /^[0-9a-f]{64}$/,
|
130
|
nonempty_string: nonempty_string_matcher,
|
131
|
component: [
|
132
|
new RegExp(`^[${TYPE_PREFIX.SCRIPT}${TYPE_PREFIX.BAG}]$`),
|
133
|
nonempty_string_matcher
|
134
|
]
|
135
|
};
|
136
|
#EXPORT matchers
|
137
|
|
138
|
/*
|
139
|
* Facilitates checking if there aren't any keys in object. This does *NOT*
|
140
|
* account for pathological cases like redefined properties of Object prototype.
|
141
|
*/
|
142
|
function is_object_empty(object)
|
143
|
{
|
144
|
for (const key in object)
|
145
|
return false;
|
146
|
return true;
|
147
|
}
|
148
|
#EXPORT is_object_empty
|