[Pale-Moon] Issue #1717 - Total Level Rewrite

SSLStatus is now used for basically everything.
This commit is contained in:
Andy 2020-08-14 16:49:32 -07:00 • committed by Roy Tam
commit 6d0384a86f

View file

@ -16,81 +16,80 @@ var padlock_PadLock =
onLocationChange: function() {}, onLocationChange: function() {},
onStatusChange: function() {}, onStatusChange: function() {},
onSecurityChange: function(aCallerWebProgress, aRequestWithState, aState) { onSecurityChange: function(aCallerWebProgress, aRequestWithState, aState) {
// aState is defined as a bitmask that may be extended in the future.
// We filter out any unknown bits before testing for known values.
const wpl = Ci.nsIWebProgressListener; const wpl = Ci.nsIWebProgressListener;
const wpl_security_bits = wpl.STATE_IS_SECURE |
wpl.STATE_IS_BROKEN |
wpl.STATE_IS_INSECURE;
var level; var level;
var highlight_urlbar = false; var highlight_urlbar = false;
var secUI = gBrowser.securityUI;
switch (aState & wpl_security_bits) { var secState = secUI.QueryInterface(Ci.nsISSLStatusProvider).SSLStatus;
case wpl.STATE_IS_SECURE: if (secState == null) {
level = "high"; level = null;
highlight_urlbar = true; } else {
break; highlight_urlbar = true;
case wpl.STATE_IS_BROKEN: secState.QueryInterface(Ci.nsISSLStatus);
level = "broken"; // Step 1: Check EV
highlight_urlbar = true; if (secState.isExtendedValidation) {
break; // Step 1 TRUE: Extended Validation
default: // should not be reached // Normal "ev"
level = null; // Mixed Content "broken"
} if ((aState & wpl.STATE_LOADED_MIXED_ACTIVE_CONTENT) ||
(aState & wpl.STATE_LOADED_MIXED_DISPLAY_CONTENT))
if (level != null) { level = "broken";
var secUI = gBrowser.securityUI; else
//if we wanted, we could use secUI.state instead of aState above? level = "ev";
var secState = secUI.QueryInterface(Ci.nsISSLStatusProvider).SSLStatus; } else {
if (secState) { // Step 1 FALSE: Domain Validation
secState.QueryInterface(Ci.nsISSLStatus); // Normal "high"
if (secState.isExtendedValidation) { // Mixed Active Content "low"
if ((aState & wpl.STATE_LOADED_MIXED_ACTIVE_CONTENT) || if (aState & wpl.STATE_LOADED_MIXED_ACTIVE_CONTENT)
(aState & wpl.STATE_LOADED_MIXED_DISPLAY_CONTENT)) level = "low";
level = "broken"; else
else if (level == "high") level = "high";
level = "ev"; }
} else { // Step 2: Check Protocol
if (aState & wpl.STATE_LOADED_MIXED_ACTIVE_CONTENT) if (level != "broken") {
level = "low"; // SSL 3 "broken"
else if (aState & wpl.STATE_LOADED_MIXED_DISPLAY_CONTENT) // TLS 1.0 "low"
level = "high"; // TLS 1.1 "low"
} var proto = secState.protocolVersion;
if (level != "broken") { if (proto == Ci.nsISSLStatus.SSL_VERSION_3)
var proto = secState.protocolVersion; level = "broken";
if (proto == Ci.nsISSLStatus.SSL_VERSION_3) { else if (proto == Ci.nsISSLStatus.TLS_VERSION_1 ||
level = "broken"; proto == Ci.nsISSLStatus.TLS_VERSION_1_1) {
} else if (proto == Ci.nsISSLStatus.TLS_VERSION_1 || level = "low";
proto == Ci.nsISSLStatus.TLS_VERSION_1_1) {
level = "low";
}
if (level != "broken") {
var aCipher = secState.cipherSuite;
if (aCipher.indexOf("_EXPORT") > -1) {
level = "broken";
} else if (aCipher.indexOf("_RC2_") > -1) {
level = "broken";
} else if (aCipher.indexOf("_RC4_") > -1) {
if (aCipher.indexOf("_MD5") > -1) {
level = "broken";
} else if (aCipher.indexOf("_SHA") > -1) {
level = "low";
}
} else if (aCipher.indexOf("_3DES_") > -1) {
level = "low";
}
}
} }
} }
} // Step 3: Check Bad Ciphers
if (level != "broken") {
try { // EXPORT "broken"
var proto = gBrowser.contentWindow.location.protocol; // RC2 "broken"
if (proto == "about:" || proto == "chrome:" || proto == "file:" ) { // RC4 + MD5 "broken"
// do not warn when using local protocols // RC4 + SHA1 "low"
highlight_urlbar = false; // 3DES "low"
var aCipher = secState.cipherSuite;
if (aCipher.indexOf("_EXPORT") > -1) {
level = "broken";
} else if (aCipher.indexOf("_RC2_") > -1) {
level = "broken";
} else if (aCipher.indexOf("_RC4_") > -1) {
if (aCipher.indexOf("_MD5") > -1) {
level = "broken";
} else if (aCipher.indexOf("_SHA") > -1) {
level = "low";
}
} else if (aCipher.indexOf("_3DES_") > -1) {
level = "low";
}
} }
} catch(ex) {} // Step 4: Check Boolean Problems
if (level != "broken") {
// Untrusted "broken"
// Domain Mismatch "broken"
// Expired (or too new) "broken"
if (secState.isUntrusted || secState.isDomainMismatch ||
secState.isNotValidAtThisTime)
level = "broken";
}
}
let ub = document.getElementById("urlbar"); let ub = document.getElementById("urlbar");
if (ub) { if (ub) {