summaryrefslogtreecommitdiffstats
path: root/security/manager/ssl/VerifySSLServerCertParent.h
diff options
context:
space:
mode:
authorDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-19 00:47:55 +0000
committerDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-19 00:47:55 +0000
commit26a029d407be480d791972afb5975cf62c9360a6 (patch)
treef435a8308119effd964b339f76abb83a57c29483 /security/manager/ssl/VerifySSLServerCertParent.h
parentInitial commit. (diff)
downloadfirefox-26a029d407be480d791972afb5975cf62c9360a6.tar.xz
firefox-26a029d407be480d791972afb5975cf62c9360a6.zip
Adding upstream version 124.0.1.upstream/124.0.1
Signed-off-by: Daniel Baumann <daniel.baumann@progress-linux.org>
Diffstat (limited to 'security/manager/ssl/VerifySSLServerCertParent.h')
-rw-r--r--security/manager/ssl/VerifySSLServerCertParent.h60
1 files changed, 60 insertions, 0 deletions
diff --git a/security/manager/ssl/VerifySSLServerCertParent.h b/security/manager/ssl/VerifySSLServerCertParent.h
new file mode 100644
index 0000000000..de2c062935
--- /dev/null
+++ b/security/manager/ssl/VerifySSLServerCertParent.h
@@ -0,0 +1,60 @@
+/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
+/* vim: set sw=2 ts=8 et tw=80 : */
+
+/* This Source Code Form is subject to the terms of the Mozilla Public
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
+ * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
+
+#ifndef mozilla_psm_VerifySSLServerCertParent_h__
+#define mozilla_psm_VerifySSLServerCertParent_h__
+
+#include "mozilla/psm/PVerifySSLServerCertParent.h"
+#include "mozpkix/Time.h"
+#include "ScopedNSSTypes.h"
+#include "SharedCertVerifier.h"
+
+namespace mozilla {
+namespace psm {
+
+// This class implements the main process side of the server certificate
+// verification for socket process.
+// SSLServerCertVerificationJob::Dispatch is called in
+// VerifySSLServerCertParent::Dispatch with IPCServerCertVerificationResult and
+// the result of the certificate verification will be sent to the socket process
+// via IPC.
+class VerifySSLServerCertParent : public PVerifySSLServerCertParent {
+ public:
+ NS_INLINE_DECL_THREADSAFE_REFCOUNTING(VerifySSLServerCertParent, override)
+
+ VerifySSLServerCertParent();
+
+ bool Dispatch(nsTArray<ByteArray>&& aPeerCertChain,
+ const nsACString& aHostName, const int32_t& aPort,
+ const OriginAttributes& aOriginAttributes,
+ const Maybe<ByteArray>& aStapledOCSPResponse,
+ const Maybe<ByteArray>& aSctsFromTLSExtension,
+ const Maybe<DelegatedCredentialInfoArg>& aDcInfo,
+ const uint32_t& aProviderFlags,
+ const uint32_t& aCertVerifierFlags);
+
+ void OnVerifiedSSLServerCert(const nsTArray<ByteArray>& aBuiltCertChain,
+ uint16_t aCertificateTransparencyStatus,
+ uint8_t aEVStatus, bool aSucceeded,
+ PRErrorCode aFinalError,
+ uint32_t aOverridableErrorCategory,
+ bool aIsBuiltCertChainRootBuiltInRoot,
+ bool aMadeOCSPRequests);
+
+ private:
+ virtual ~VerifySSLServerCertParent();
+
+ // PVerifySSLServerCertParent
+ void ActorDestroy(ActorDestroyReason aWhy) override;
+
+ nsCOMPtr<nsISerialEventTarget> mBackgroundThread;
+};
+
+} // namespace psm
+} // namespace mozilla
+
+#endif // mozilla_psm_VerifySSLServerCertParent_h__