mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-10-05 14:57:30 +09:00
[Pale-Moon] Issue #1717 - Total Level Rewrite
SSLStatus is now used for basically everything.
This commit is contained in:
parent
66a5df11c1
commit
6d0384a86f
1 changed files with 64 additions and 65 deletions
|
|
@ -16,81 +16,80 @@ var padlock_PadLock =
|
||||||
onLocationChange: function() {},
|
onLocationChange: function() {},
|
||||||
onStatusChange: function() {},
|
onStatusChange: function() {},
|
||||||
onSecurityChange: function(aCallerWebProgress, aRequestWithState, aState) {
|
onSecurityChange: function(aCallerWebProgress, aRequestWithState, aState) {
|
||||||
// aState is defined as a bitmask that may be extended in the future.
|
|
||||||
// We filter out any unknown bits before testing for known values.
|
|
||||||
const wpl = Ci.nsIWebProgressListener;
|
const wpl = Ci.nsIWebProgressListener;
|
||||||
const wpl_security_bits = wpl.STATE_IS_SECURE |
|
|
||||||
wpl.STATE_IS_BROKEN |
|
|
||||||
wpl.STATE_IS_INSECURE;
|
|
||||||
var level;
|
var level;
|
||||||
var highlight_urlbar = false;
|
var highlight_urlbar = false;
|
||||||
|
var secUI = gBrowser.securityUI;
|
||||||
switch (aState & wpl_security_bits) {
|
var secState = secUI.QueryInterface(Ci.nsISSLStatusProvider).SSLStatus;
|
||||||
case wpl.STATE_IS_SECURE:
|
if (secState == null) {
|
||||||
level = "high";
|
level = null;
|
||||||
highlight_urlbar = true;
|
} else {
|
||||||
break;
|
highlight_urlbar = true;
|
||||||
case wpl.STATE_IS_BROKEN:
|
secState.QueryInterface(Ci.nsISSLStatus);
|
||||||
level = "broken";
|
// Step 1: Check EV
|
||||||
highlight_urlbar = true;
|
if (secState.isExtendedValidation) {
|
||||||
break;
|
// Step 1 TRUE: Extended Validation
|
||||||
default: // should not be reached
|
// Normal "ev"
|
||||||
level = null;
|
// Mixed Content "broken"
|
||||||
}
|
if ((aState & wpl.STATE_LOADED_MIXED_ACTIVE_CONTENT) ||
|
||||||
|
(aState & wpl.STATE_LOADED_MIXED_DISPLAY_CONTENT))
|
||||||
if (level != null) {
|
level = "broken";
|
||||||
var secUI = gBrowser.securityUI;
|
else
|
||||||
//if we wanted, we could use secUI.state instead of aState above?
|
level = "ev";
|
||||||
var secState = secUI.QueryInterface(Ci.nsISSLStatusProvider).SSLStatus;
|
} else {
|
||||||
if (secState) {
|
// Step 1 FALSE: Domain Validation
|
||||||
secState.QueryInterface(Ci.nsISSLStatus);
|
// Normal "high"
|
||||||
if (secState.isExtendedValidation) {
|
// Mixed Active Content "low"
|
||||||
if ((aState & wpl.STATE_LOADED_MIXED_ACTIVE_CONTENT) ||
|
if (aState & wpl.STATE_LOADED_MIXED_ACTIVE_CONTENT)
|
||||||
(aState & wpl.STATE_LOADED_MIXED_DISPLAY_CONTENT))
|
level = "low";
|
||||||
level = "broken";
|
else
|
||||||
else if (level == "high")
|
level = "high";
|
||||||
level = "ev";
|
}
|
||||||
} else {
|
// Step 2: Check Protocol
|
||||||
if (aState & wpl.STATE_LOADED_MIXED_ACTIVE_CONTENT)
|
if (level != "broken") {
|
||||||
level = "low";
|
// SSL 3 "broken"
|
||||||
else if (aState & wpl.STATE_LOADED_MIXED_DISPLAY_CONTENT)
|
// TLS 1.0 "low"
|
||||||
level = "high";
|
// TLS 1.1 "low"
|
||||||
}
|
var proto = secState.protocolVersion;
|
||||||
if (level != "broken") {
|
if (proto == Ci.nsISSLStatus.SSL_VERSION_3)
|
||||||
var proto = secState.protocolVersion;
|
level = "broken";
|
||||||
if (proto == Ci.nsISSLStatus.SSL_VERSION_3) {
|
else if (proto == Ci.nsISSLStatus.TLS_VERSION_1 ||
|
||||||
level = "broken";
|
proto == Ci.nsISSLStatus.TLS_VERSION_1_1) {
|
||||||
} else if (proto == Ci.nsISSLStatus.TLS_VERSION_1 ||
|
level = "low";
|
||||||
proto == Ci.nsISSLStatus.TLS_VERSION_1_1) {
|
|
||||||
level = "low";
|
|
||||||
}
|
|
||||||
if (level != "broken") {
|
|
||||||
var aCipher = secState.cipherSuite;
|
|
||||||
if (aCipher.indexOf("_EXPORT") > -1) {
|
|
||||||
level = "broken";
|
|
||||||
} else if (aCipher.indexOf("_RC2_") > -1) {
|
|
||||||
level = "broken";
|
|
||||||
} else if (aCipher.indexOf("_RC4_") > -1) {
|
|
||||||
if (aCipher.indexOf("_MD5") > -1) {
|
|
||||||
level = "broken";
|
|
||||||
} else if (aCipher.indexOf("_SHA") > -1) {
|
|
||||||
level = "low";
|
|
||||||
}
|
|
||||||
} else if (aCipher.indexOf("_3DES_") > -1) {
|
|
||||||
level = "low";
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
// Step 3: Check Bad Ciphers
|
||||||
|
if (level != "broken") {
|
||||||
try {
|
// EXPORT "broken"
|
||||||
var proto = gBrowser.contentWindow.location.protocol;
|
// RC2 "broken"
|
||||||
if (proto == "about:" || proto == "chrome:" || proto == "file:" ) {
|
// RC4 + MD5 "broken"
|
||||||
// do not warn when using local protocols
|
// RC4 + SHA1 "low"
|
||||||
highlight_urlbar = false;
|
// 3DES "low"
|
||||||
|
var aCipher = secState.cipherSuite;
|
||||||
|
if (aCipher.indexOf("_EXPORT") > -1) {
|
||||||
|
level = "broken";
|
||||||
|
} else if (aCipher.indexOf("_RC2_") > -1) {
|
||||||
|
level = "broken";
|
||||||
|
} else if (aCipher.indexOf("_RC4_") > -1) {
|
||||||
|
if (aCipher.indexOf("_MD5") > -1) {
|
||||||
|
level = "broken";
|
||||||
|
} else if (aCipher.indexOf("_SHA") > -1) {
|
||||||
|
level = "low";
|
||||||
|
}
|
||||||
|
} else if (aCipher.indexOf("_3DES_") > -1) {
|
||||||
|
level = "low";
|
||||||
|
}
|
||||||
}
|
}
|
||||||
} catch(ex) {}
|
// Step 4: Check Boolean Problems
|
||||||
|
if (level != "broken") {
|
||||||
|
// Untrusted "broken"
|
||||||
|
// Domain Mismatch "broken"
|
||||||
|
// Expired (or too new) "broken"
|
||||||
|
if (secState.isUntrusted || secState.isDomainMismatch ||
|
||||||
|
secState.isNotValidAtThisTime)
|
||||||
|
level = "broken";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
let ub = document.getElementById("urlbar");
|
let ub = document.getElementById("urlbar");
|
||||||
if (ub) {
|
if (ub) {
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue