ContentSignatureVerifier.cpp out 15718
CredentialManagerSecret.cpp out 3861
CredentialManagerSecret.h out 984
CryptoTask.h Frequently we need to run a task on a background thread without blocking the main thread, and then call a callback on the main thread with the result. This class provides the framework for that. Subclasses must: (1) Override CalculateResult for the off-the-main-thread computation. (2) Override CallCallback() for the on-the-main-thread call of the callback. 1481
DER.jsm Class representing a decoded BIT STRING. 10185
DataStorage.h DataStorage is a threadsafe, generic, narrow string-based hash map that persists data on disk and additionally handles temporary and private data. However, if used in a context where there is no profile directory, data will not be persisted. Its lifecycle is as follows: - Allocate with a filename (this is or will eventually be a file in the profile directory, if the profile exists). - Call Init() from the main thread. This spins off an asynchronous read of the backing file. - Eventually observers of the topic "data-storage-ready" will be notified with the backing filename as the data in the notification when this has completed. - Should the profile directory not be available, (e.g. in xpcshell), DataStorage will not initially read any persistent data. The "data-storage-ready" event will still be emitted. This follows semantics similar to the permission manager and allows tests that test unrelated components to proceed without a profile. - A timer periodically fires on a background thread that checks if any persistent data has changed, and if so writes all persistent data to the backing file. When this happens, observers will be notified with the topic "data-storage-written" and the backing filename as the data. It is possible to receive a "data-storage-written" event while there exist pending persistent data changes. However, those changes will eventually be written when the timer fires again, and eventually another "data-storage-written" event will be sent. - When a DataStorage instance observes the topic "profile-before-change" in anticipation of shutdown, all persistent data for that DataStorage is written to the backing file (this blocks the main thread). In the process of doing this, the background serial event target responsible for these writes is then shut down to prevent further writes to that file (the background timer is also cancelled when this happens). If "profile-before-change" is not observed, this happens upon observing "xpcom-shutdown-threads". - For testing purposes, the preference "test.datastorage.write_timer_ms" can be set to cause the asynchronous writing of data to happen more quickly. - To prevent unbounded memory and disk use, the number of entries in each table is limited to 1024. Evictions are handled in by a modified LRU scheme (see implementation comments). - NB: Instances of DataStorage have long lifetimes because they are strong observers of events and won't go away until the observer service does. For each key/value: - The key must be a non-empty string containing no instances of '\t' or '\n' (this is a limitation of how the data is stored and will be addressed in the future). - The key must have a length no more than 256. - The value must not contain '\n' and must have a length no more than 1024. (the length limits are to prevent unbounded disk and memory usage) 10227
KeychainSecret.h out 1276
LibSecret.cpp <private> 13053
LibSecret.h out 933
LocalCertService.cpp out 13879
NSSErrorsService.cpp Please ensure the NSS error codes are mapped into the positive range 0x1000 to 0xf000 Search for NS_ERROR_MODULE_SECURITY to ensure there are no conflicts. The current code also assumes that NSS library error codes are negative. 6625
NSSKeyStore.cpp Implementing OSKeyStore when there is no platform specific one. This key store instead puts the keys into the NSS DB. 7174
NSSKeyStore.h out 1315
OSKeyStore.cpp out 22735
OSKeyStore.h out 3985
OSReauthenticator.cpp 20127
OSReauthenticator.h out 1194 out 2720
PSMIPCCommon.cpp encrypt this private key 5055
PublicKeyPinningService.cpp Computes in the location specified by base64Out the SHA256 digest of the DER Encoded subject Public Key Info for the given cert 13451
PublicKeyPinningService.h Sets chainHasValidPins to true if the given (host, certList) passes pinning checks, or to false otherwise. If the host is pinned, returns true via chainHasValidPins if one of the keys in the given certificate chain matches the pin set specified by the hostname. The certList's head is the EE cert and the tail is the trust anchor. Note: if an alt name is a wildcard, it won't necessarily find a pinset that would otherwise be valid for it 1809
RemoteSecuritySettings.jsm Helper function that returns a promise that will resolve with whether or not the nsICertStorage implementation has prior data of the given type. @param {Integer} dataType a Ci.nsICertStorage.DATA_TYPE_* constant indicating the type of data @return {Promise} a promise that will resolve with true if the data type is present 23485
RootCertificateTelemetryUtils.h 1396 63744
SSLServerCertVerification.cpp 55681
SSLServerCertVerification.h 6592
ScopedNSSTypes.h A more convenient way of dealing with digests calculated into stack-allocated buffers. NSS must be initialized on the main thread before use, and the caller must ensure NSS isn't shut down, typically by being within the lifetime of XPCOM. Typical usage, for digesting a buffer in memory: nsCOMPtr<nsISupports> nssDummy = do_GetService(";1", &rv); nsTArray<uint8_t> digestArray; nsresult rv = Digest::DigestBuf(SEC_OID_SHA256, mybuffer, myBufferLen, digestArray); NS_ENSURE_SUCCESS(rv, rv); Less typical usage, for digesting while doing streaming I/O and similar: Digest digest; nsresult rv = digest.Begin(SEC_OID_SHA256); NS_ENSURE_SUCCESS(rv, rv); for (...) { rv = digest.Update(buf, len); NS_ENSURE_SUCCESS(rv, rv); } nsTArray<uint8_t> digestArray; rv = digest.End(digestArray); NS_ENSURE_SUCCESS(rv, rv) 12858
SecretDecoderRing.cpp out 10733
SecretDecoderRing.h out 1157
SharedCertVerifier.h 1523
StaticHPKPins.h / /* This is an automatically generated file. If you're not 60229
TransportSecurityInfo.cpp 39941
TransportSecurityInfo.h mHaveCertErrrorBits is relied on to determine whether or not a SPDY connection is eligible for joining in nsNSSSocketInfo::JoinConnection() 7386
VerifySSLServerCertChild.cpp 4899
VerifySSLServerCertChild.h 2239
VerifySSLServerCertParent.cpp 6892
VerifySSLServerCertParent.h 2355
X509.jsm Helper function to read a NULL tag from the given DER. @param {DER} der a DER object to read a NULL from @return {NULL} an object representing an ASN.1 NULL 18349
md4.c "clean room" MD4 implementation (see RFC 1320) 4769
md4.h md4sum - computes the MD4 sum over the input buffer per RFC 1320 @param input buffer containing input data @param inputLen length of input buffer (number of bytes) @param result 16-byte buffer that will contain the MD4 sum upon return NOTE: MD4 is superceded by MD5. do not use MD4 unless required by the protocol you are implementing (e.g., NTLM requires MD4). NOTE: this interface is designed for relatively small buffers. A streaming interface would make more sense if that were a requirement. Currently, this is good enough for the applications we care about. 1099 6082
nsCertOverrideService.cpp out 26809
nsCertOverrideService.h 5330
nsCertTree.cpp heading for thread 23064
nsCertTree.h Disable the "base class XXX should be explicitly initialized in the copy constructor" warning. 3879
nsClientAuthRemember.cpp out 11004
nsClientAuthRemember.h out 2659
nsICertOverrideService.idl The hostname of the server the override is used for. 8419
nsICertStorage.idl Callback type used to notify callers that an operation performed by nsICertStorage has completed. Indicates the result of the requested operation, as well as any data returned by the operation. 11668
nsICertificateDialogs.idl Functions that implement user interface dialogs to manage certificates. 2414
nsIClientAuthDialogs.idl Provides UI for SSL client-auth dialogs. 1612
nsIClientAuthRememberService.idl 1813
nsIContentSignatureVerifier.idl An interface for verifying content-signatures, inspired by described here 1693
nsICryptoHMAC.idl nsICryptoHMAC This interface provides HMAC signature algorithms. 3735
nsICryptoHash.idl nsICryptoHash This interface provides crytographic hashing algorithms. 3756
nsILocalCertService.idl Get or create a new self-signed X.509 cert to represent this device over a secure transport, like TLS. The cert is stored permanently in the profile's key store after first use, and is valid for 1 year. If an expired or otherwise invalid cert is found with the nickname supplied here, it is removed and a new one is made. @param nickname Nickname that identifies the cert @param cb Callback to be notified with the result 2291
nsINSSComponent.idl When we log out of a PKCS#11 token, any TLS connections that may have involved a client certificate stored on that token must be closed. Since we don't have a fine-grained way to do this, we basically cancel everything. More speficially, this clears all temporary certificate exception overrides and any remembered client authentication certificate decisions, and then cancels all network connections (strictly speaking, this last part is overzealous - we only need to cancel all https connections (see bug 1446645)). 4448
nsINSSErrorsService.idl @param aNSPRCode An error code obtained using PR_GetError() @return True if it is error code defined by the NSS library 3011
nsINSSVersion.idl Minimal required versions as used at build time 1233
nsIOSKeyStore.idl This interface provides encryption and decryption operations for data at rest. The key used to encrypt and decrypt the data is stored in the OS key store. Usage: // obtain the singleton OSKeyStore instance const oskeystore = Cc[";1"].getService(Ci.nsIOSKeyStore); const PASSWORD_LABEL = "mylabel1"; const COOKIE_LABEL = "mylabel2"; // Unlock the key store. // Note that this is not necesssary. The key store will be unlocked // automatically when an operation is performed on it. await oskeystore.asyncUnlock(); // Check if there's a secret for your label already. if (!await oskeystore.asyncSecretAvailable(PASSWORD_LABEL)) { // Fail or generate a new secret for your label. // If you want to generate a new secret, do. // Hold onto `recoveryPhrase` to present to the user. let recoveryPhrase = await oskeystore.asyncGenerateSecret(PASSWORD_LABEL); } // Assuming there's a secret with your label. Encrypt/Decrypt as follows. let encryptedPasswordBytes = await oskeystore.asyncEncryptBytes(PASSWORD_LABEL, passwordBytes); let newPasswordBytes = await oskeystore.asyncDecryptBytes(PASSWORD_LABEL, encryptedPasswordBytes); // Delete the secret from the key store. await oskeystore.asyncDeleteSecret(PASSWORD_LABEL); // Recover a secret from a recovery code. await oskeystore.asyncRecoverSecret(PASSWORD_LABEL, recoveryPhrase); // Lock the key store to prompt the user to log into her OS key store again. await oskeystore.asyncLock(); 5190
nsIOSReauthenticator.idl This interface provides an abstract way to request that the user reauthenticate themselves to the operating system. It may be useful in conjunction with nsIOSKeyStore, whereby consumers of these APIs may consider some secrets too sensitive to access without first reauthenticating the user. Usage: // obtain the singleton nsIOSReauthenticator instance const reauthenticator = Cc[";1"] .getService(Ci.nsIOSReauthenticator); if (await reauthenticator.asyncReauthenticate()) { // do something only authenticated users are allowed to do... } else { // show a "sorry, this isn't allowed" error } 1958
nsIPK11Token.idl The name of the token 2135
nsIPK11TokenDB.idl The PK11 Token Database provides access to the PK11 modules that are installed, and the tokens that are available. Interfaces: nsIPK11TokenDB Threading: ?? 836
nsIPKCS11Slot.idl Manufacturer ID of the slot. 1553
nsIProtectedAuthThread.idl Used to communicate with the thread for logging on to a token with CKF_PROTECTED_AUTHENTICATION_PATH set. 1466
nsIPublicKeyPinningService.idl Returns true if the host of the given URI has pinning information, and false otherwise. 632
nsISecretDecoderRing.idl Encrypt to Base64 output. Note that the input must basically be a byte array (i.e. the code points must be within the range [0, 255]). Hence, using this method directly to encrypt passwords (or any text, really) won't work as expected. Instead, use something like nsIScriptableUnicodeConverter to first convert the desired password or text to UTF-8, then encrypt that. Remember to convert back when calling decryptString(). @param text The text to encrypt. @return The encrypted text, encoded as Base64. 2709
nsISecurityUITelemetry.idl Addon installation warnings 6102
nsISiteSecurityService.idl SECURITY_PROPERTY_SET and SECURITY_PROPERTY_UNSET correspond to indicating a site has or does not have the security property in question, respectively. SECURITY_PROPERTY_KNOCKOUT indicates a value on a preloaded list is being overridden, and the associated site does not have the security property in question. 9252
nsITokenDialogs.idl Displays notification dialog to the user that they are expected to authenticate to the token using its "protected authentication path" feature. 783
nsITokenPasswordDialogs.idl This is the interface for setting and changing password on a PKCS11 token. 902
nsIX509Cert.idl forward declaration 5385
nsIX509CertDB.idl Callback type for use with asyncVerifyCertAtTime. If aPRErrorCode is PRErrorCodeSuccess (i.e. 0), aVerifiedChain represents the verified certificate chain determined by asyncVerifyCertAtTime. aHasEVPolicy represents whether or not the end-entity certificate verified as EV. If aPRErrorCode is non-zero, it represents the error encountered during verification. aVerifiedChain is null in that case and aHasEVPolicy has no meaning. 13593
nsIX509CertValidity.idl Information on the validity period of a X.509 certificate. 1978
nsNSSCallbacks.cpp out 45370
nsNSSCallbacks.h out 1373
nsNSSCertificate.cpp static 22378
nsNSSCertificate.h int 2766
nsNSSCertificateDB.cpp out 42980
nsNSSCertificateDB.h fb0bbc5c-452e-4783-b32c-80124693d871 2600
nsNSSComponent.cpp out 99554
nsNSSComponent.h out 6092
nsNSSIOLayer.cpp out 100600
nsNSSIOLayer.h 13232
nsNTLMAuthModule.cpp We don't actually send a LM response, but we still have to send something in this spot 33130
nsPK11TokenDB.cpp out 8666
nsPK11TokenDB.h out 1870
nsPKCS11Slot.cpp out 8023
nsPKCS11Slot.h out 1507
nsSSLSocketProvider.h 217d014a-1dd2-11b2-999c-b0c4df79b324 977 2203643
nsSecureBrowserUI.cpp 5483
nsSiteSecurityService.cpp out 33081
nsSiteSecurityService.h SecurityPropertyState: A utility enum for representing the different states a security property can be in. SecurityPropertySet and SecurityPropertyUnset correspond to indicating a site has or does not have the security property in question, respectively. SecurityPropertyKnockout indicates a value on a preloaded list is being overridden, and the associated site does not have the security property in question. 6231
nsTLSSocketProvider.cpp 1930
