blob: a4baf08d270f20617056c64f257c9050ec72b922 [file] [log] [blame]
Avi Drissman4e1b7bc32022-09-15 14:03:501// Copyright 2013 The Chromium Authors
danakjc492bf82020-09-09 20:02:442// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4
5#ifndef CONTENT_BROWSER_RENDERER_HOST_FRAME_TREE_NODE_H_
6#define CONTENT_BROWSER_RENDERER_HOST_FRAME_TREE_NODE_H_
7
8#include <stddef.h>
9
10#include <memory>
Arthur Sonzognic686e8f2024-01-11 08:36:3711#include <optional>
danakjc492bf82020-09-09 20:02:4412#include <string>
David Sanders2c1194d92022-04-19 23:32:3213#include <utility>
danakjc492bf82020-09-09 20:02:4414
15#include "base/gtest_prod_util.h"
Keishi Hattori0e45c022021-11-27 09:25:5216#include "base/memory/raw_ptr.h"
Christian Biesingere1865c57c2023-10-20 15:19:2917#include "base/memory/safe_ref.h"
David Sanders2c1194d92022-04-19 23:32:3218#include "base/memory/scoped_refptr.h"
David Sandersd4bf5eb2022-03-17 07:12:0519#include "base/observer_list.h"
Mingyu Lei7956b8b2023-07-24 08:24:0820#include "base/task/cancelable_task_tracker.h"
Arthur Sonzognic686e8f2024-01-11 08:36:3721#include "base/time/time.h"
danakjc492bf82020-09-09 20:02:4422#include "content/browser/renderer_host/navigator.h"
23#include "content/browser/renderer_host/render_frame_host_impl.h"
24#include "content/browser/renderer_host/render_frame_host_manager.h"
Miyoung Shin7cf88b42022-11-07 13:22:3025#include "content/browser/renderer_host/render_frame_host_owner.h"
danakjc492bf82020-09-09 20:02:4426#include "content/common/content_export.h"
Julie Jeongeun Kimf38c1eca2021-12-14 07:46:5527#include "content/public/browser/frame_type.h"
Rakina Zata Amni58681c62024-06-25 06:32:1328#include "content/public/browser/navigation_discard_reason.h"
Anguluri Aravind Kumara8aa5952025-02-23 02:53:0729#include "services/network/public/cpp/is_potentially_trustworthy.h"
danakjc492bf82020-09-09 20:02:4430#include "services/network/public/mojom/content_security_policy.mojom-forward.h"
Julie Jeongeun Kim0e242242022-11-30 10:45:0931#include "services/network/public/mojom/referrer_policy.mojom-forward.h"
Kevin McNee43fe8292021-10-04 22:59:4132#include "third_party/blink/public/common/frame/frame_owner_element_type.h"
danakjc492bf82020-09-09 20:02:4433#include "third_party/blink/public/common/frame/frame_policy.h"
danakjc492bf82020-09-09 20:02:4434#include "third_party/blink/public/mojom/frame/frame_owner_properties.mojom.h"
Gyuyoung Kimc16e52e92021-03-19 02:45:3735#include "third_party/blink/public/mojom/frame/frame_replication_state.mojom-forward.h"
Daniel Cheng6ac128172021-05-25 18:49:0136#include "third_party/blink/public/mojom/frame/tree_scope_type.mojom.h"
David Sanders2c1194d92022-04-19 23:32:3237#include "third_party/blink/public/mojom/frame/user_activation_update_types.mojom-forward.h"
danakjc492bf82020-09-09 20:02:4438#include "url/gurl.h"
39#include "url/origin.h"
40
41namespace content {
42
43class NavigationRequest;
danakjc492bf82020-09-09 20:02:4444class NavigationEntryImpl;
Paul Semel3e241042022-10-11 12:57:3145class FrameTree;
danakjc492bf82020-09-09 20:02:4446
47// When a page contains iframes, its renderer process maintains a tree structure
48// of those frames. We are mirroring this tree in the browser process. This
49// class represents a node in this tree and is a wrapper for all objects that
50// are frame-specific (as opposed to page-specific).
51//
52// Each FrameTreeNode has a current RenderFrameHost, which can change over
53// time as the frame is navigated. Any immediate subframes of the current
54// document are tracked using FrameTreeNodes owned by the current
55// RenderFrameHost, rather than as children of FrameTreeNode itself. This
56// allows subframe FrameTreeNodes to stay alive while a RenderFrameHost is
57// still alive - for example while pending deletion, after a new current
58// RenderFrameHost has replaced it.
Miyoung Shin7cf88b42022-11-07 13:22:3059class CONTENT_EXPORT FrameTreeNode : public RenderFrameHostOwner {
danakjc492bf82020-09-09 20:02:4460 public:
61 class Observer {
62 public:
63 // Invoked when a FrameTreeNode is being destroyed.
64 virtual void OnFrameTreeNodeDestroyed(FrameTreeNode* node) {}
65
66 // Invoked when a FrameTreeNode becomes focused.
67 virtual void OnFrameTreeNodeFocused(FrameTreeNode* node) {}
68
Arthur Hemerye4659282022-03-28 08:36:1569 // Invoked when a FrameTreeNode moves to a different BrowsingInstance and
70 // the popups it opened should be disowned.
71 virtual void OnFrameTreeNodeDisownedOpenee(FrameTreeNode* node) {}
72
Fergal Dalya1d569972021-03-16 03:24:5373 virtual ~Observer() = default;
danakjc492bf82020-09-09 20:02:4474 };
75
danakjc492bf82020-09-09 20:02:4476 // Returns the FrameTreeNode with the given global |frame_tree_node_id|,
77 // regardless of which FrameTree it is in.
Avi Drissmanbd153642024-09-03 18:58:0578 static FrameTreeNode* GloballyFindByID(FrameTreeNodeId frame_tree_node_id);
danakjc492bf82020-09-09 20:02:4479
80 // Returns the FrameTreeNode for the given |rfh|. Same as
81 // rfh->frame_tree_node(), but also supports nullptrs.
82 static FrameTreeNode* From(RenderFrameHost* rfh);
83
84 // Callers are are expected to initialize sandbox flags separately after
85 // calling the constructor.
86 FrameTreeNode(
Arthur Sonzognif6785ec2022-12-05 10:11:5087 FrameTree& frame_tree,
danakjc492bf82020-09-09 20:02:4488 RenderFrameHostImpl* parent,
Daniel Cheng6ac128172021-05-25 18:49:0189 blink::mojom::TreeScopeType tree_scope_type,
danakjc492bf82020-09-09 20:02:4490 bool is_created_by_script,
danakjc492bf82020-09-09 20:02:4491 const blink::mojom::FrameOwnerProperties& frame_owner_properties,
Kevin McNee43fe8292021-10-04 22:59:4192 blink::FrameOwnerElementType owner_type,
Dominic Farolino08662c82021-06-11 07:36:3493 const blink::FramePolicy& frame_owner);
danakjc492bf82020-09-09 20:02:4494
Peter Boström828b9022021-09-21 02:28:4395 FrameTreeNode(const FrameTreeNode&) = delete;
96 FrameTreeNode& operator=(const FrameTreeNode&) = delete;
97
Miyoung Shin7cf88b42022-11-07 13:22:3098 ~FrameTreeNode() override;
danakjc492bf82020-09-09 20:02:4499
100 void AddObserver(Observer* observer);
101 void RemoveObserver(Observer* observer);
102
Ian Vollick25a9d032022-04-12 23:20:17103 // Frame trees may be nested so it can be the case that IsMainFrame() is true,
104 // but is not the outermost main frame. In particular, !IsMainFrame() cannot
105 // be used to check if the frame is an embedded frame -- use
106 // !IsOutermostMainFrame() instead. NB: this does not escape guest views;
107 // IsOutermostMainFrame will be true for the outermost main frame in an inner
108 // guest view.
danakjc492bf82020-09-09 20:02:44109 bool IsMainFrame() const;
Arthur Hemerya06697f2023-03-14 09:20:57110 bool IsOutermostMainFrame() const;
danakjc492bf82020-09-09 20:02:44111
Anguluri Aravind Kumara8aa5952025-02-23 02:53:07112 // Returns true if all the ancestors of the current frame have a potentially
113 // trustworthy origin.
114 bool AreAncestorsSecure();
115
Arthur Sonzognif6785ec2022-12-05 10:11:50116 FrameTree& frame_tree() const { return frame_tree_.get(); }
Paul Semel3e241042022-10-11 12:57:31117 Navigator& navigator();
danakjc492bf82020-09-09 20:02:44118
119 RenderFrameHostManager* render_manager() { return &render_manager_; }
Alexander Timin33e2e2c12022-03-03 04:21:33120 const RenderFrameHostManager* render_manager() const {
121 return &render_manager_;
122 }
Avi Drissmanbd153642024-09-03 18:58:05123 FrameTreeNodeId frame_tree_node_id() const { return frame_tree_node_id_; }
Yuzu Saijo03dbf9b2022-07-22 04:29:45124 // This reflects window.name, which is initially set to the the "name"
125 // attribute. But this won't reflect changes of 'name' attribute and instead
126 // reflect changes to the Window object's name property.
127 // This is different from IframeAttributes' name in that this will not get
128 // updated when 'name' attribute gets updated.
Harkiran Bolaria4eacb3a2021-12-13 20:03:47129 const std::string& frame_name() const {
130 return render_manager_.current_replication_state().name;
131 }
danakjc492bf82020-09-09 20:02:44132
133 const std::string& unique_name() const {
Harkiran Bolaria4eacb3a2021-12-13 20:03:47134 return render_manager_.current_replication_state().unique_name;
danakjc492bf82020-09-09 20:02:44135 }
136
danakjc492bf82020-09-09 20:02:44137 size_t child_count() const { return current_frame_host()->child_count(); }
138
danakjc492bf82020-09-09 20:02:44139 RenderFrameHostImpl* parent() const { return parent_; }
140
Dave Tapuskac8de3b02021-12-03 21:51:01141 // See `RenderFrameHost::GetParentOrOuterDocument()` for
142 // documentation.
Arthur Hemerya06697f2023-03-14 09:20:57143 RenderFrameHostImpl* GetParentOrOuterDocument() const;
Dave Tapuskac8de3b02021-12-03 21:51:01144
145 // See `RenderFrameHostImpl::GetParentOrOuterDocumentOrEmbedder()` for
146 // documentation.
147 RenderFrameHostImpl* GetParentOrOuterDocumentOrEmbedder();
148
danakjc492bf82020-09-09 20:02:44149 FrameTreeNode* opener() const { return opener_; }
150
Rakina Zata Amni3a48ae42022-05-05 03:39:56151 FrameTreeNode* first_live_main_frame_in_original_opener_chain() const {
152 return first_live_main_frame_in_original_opener_chain_;
153 }
danakjc492bf82020-09-09 20:02:44154
Arthur Sonzognic686e8f2024-01-11 08:36:37155 const std::optional<base::UnguessableToken>& opener_devtools_frame_token() {
Wolfgang Beyerd8809db2020-09-30 15:29:39156 return opener_devtools_frame_token_;
157 }
158
Julie Jeongeun Kimf38c1eca2021-12-14 07:46:55159 // Returns the type of the frame. Refer to frame_type.h for the details.
160 FrameType GetFrameType() const;
161
danakjc492bf82020-09-09 20:02:44162 // Assigns a new opener for this node and, if |opener| is non-null, registers
163 // an observer that will clear this node's opener if |opener| is ever
164 // destroyed.
165 void SetOpener(FrameTreeNode* opener);
166
167 // Assigns the initial opener for this node, and if |opener| is non-null,
168 // registers an observer that will clear this node's opener if |opener| is
169 // ever destroyed. The value set here is the root of the tree.
170 //
171 // It is not possible to change the opener once it was set.
172 void SetOriginalOpener(FrameTreeNode* opener);
173
Wolfgang Beyerd8809db2020-09-30 15:29:39174 // Assigns an opener frame id for this node. This string id is only set once
175 // and cannot be changed. It persists, even if the |opener| is destroyed. It
176 // is used for attribution in the DevTools frontend.
177 void SetOpenerDevtoolsFrameToken(
178 base::UnguessableToken opener_devtools_frame_token);
179
danakjc492bf82020-09-09 20:02:44180 FrameTreeNode* child_at(size_t index) const {
181 return current_frame_host()->child_at(index);
182 }
183
184 // Returns the URL of the last committed page in the current frame.
185 const GURL& current_url() const {
186 return current_frame_host()->GetLastCommittedURL();
187 }
188
Charlie Reis734db662024-01-11 18:20:03189 // Moves this frame out of the initial empty document state, which is a
190 // one-way change for FrameTreeNode (i.e., it cannot go back into the initial
191 // empty document state).
192 void set_not_on_initial_empty_document() {
193 is_on_initial_empty_document_ = false;
194 }
195
196 // Returns false if the frame has committed a document that is not the initial
197 // empty document, or if the current document's input stream has been opened
198 // with document.open(), causing the document to lose its "initial empty
199 // document" status. For more details, see the definition of
200 // `is_on_initial_empty_document_`.
Rakina Zata Amni86c88fa2021-11-01 01:27:30201 bool is_on_initial_empty_document() const {
Charlie Reis734db662024-01-11 18:20:03202 return is_on_initial_empty_document_;
Rakina Zata Amnifc4cc3d42021-06-10 09:03:56203 }
204
danakjc492bf82020-09-09 20:02:44205 // Returns whether the frame's owner element in the parent document is
206 // collapsed, that is, removed from the layout as if it did not exist, as per
207 // request by the embedder (of the content/ layer).
208 bool is_collapsed() const { return is_collapsed_; }
209
210 // Sets whether to collapse the frame's owner element in the parent document,
211 // that is, to remove it from the layout as if it did not exist, as per
212 // request by the embedder (of the content/ layer). Cannot be called for main
213 // frames.
214 //
215 // This only has an effect for <iframe> owner elements, and is a no-op when
216 // called on sub-frames hosted in <frame>, <object>, and <embed> elements.
217 void SetCollapsed(bool collapsed);
218
219 // Returns the origin of the last committed page in this frame.
220 // WARNING: To get the last committed origin for a particular
221 // RenderFrameHost, use RenderFrameHost::GetLastCommittedOrigin() instead,
222 // which will behave correctly even when the RenderFrameHost is not the
223 // current one for this frame (such as when it's pending deletion).
224 const url::Origin& current_origin() const {
Harkiran Bolaria4eacb3a2021-12-13 20:03:47225 return render_manager_.current_replication_state().origin;
danakjc492bf82020-09-09 20:02:44226 }
227
Andrew Verge7233e662025-05-13 13:09:23228 // Returns the origin of the last *successfully* committed page in this
229 // frame. This may be different from current_origin() if the current page is
230 // an error page.
231 // IMPORTANT: Use current_origin() instead, as all security-relevant decisions
232 // should be made using the current origin of the frame. The last successful
233 // origin is only relevant for specific abuse mitigations that require
234 // tracking the previous state of a frame before an error page navigation.
235 const url::Origin& last_successful_origin() const {
236 return last_successful_origin_;
237 }
238
239 void set_last_successful_origin(const url::Origin& origin) {
240 last_successful_origin_ = origin;
241 }
242
danakjc492bf82020-09-09 20:02:44243 // Returns the latest frame policy (sandbox flags and container policy) for
244 // this frame. This includes flags inherited from parent frames and the latest
245 // flags from the <iframe> element hosting this frame. The returned policies
246 // may not yet have taken effect, since "sandbox" and "allow" attribute
Liam Brady25a14162022-12-02 15:25:57247 // updates in an <iframe> element take effect on next navigation. For
248 // <fencedframe> elements, not everything in the frame policy might actually
249 // take effect after the navigation. To retrieve the currently active policy
250 // for this frame, use effective_frame_policy().
danakjc492bf82020-09-09 20:02:44251 const blink::FramePolicy& pending_frame_policy() const {
252 return pending_frame_policy_;
253 }
254
Ming-Ying Chung0430c592025-01-21 00:33:10255 // Update this frame's sandbox flags, container policy and deferred fetch
256 // policy.
257 // This is called when either
258 // - a parent frame updates the "sandbox" attribute in the <iframe> element
259 // for this frame
260 // - any of the attributes which affect the container policy
261 // ("allowfullscreen", "allowpaymentrequest", "allow", and "src".)
262 // - a frame begins navigation which leads to calculation of deferred fetch
263 // policy.
danakjc492bf82020-09-09 20:02:44264 // These policies won't take effect until next navigation. If this frame's
265 // parent is itself sandboxed, the parent's sandbox flags are combined with
266 // those in |frame_policy|.
267 // Attempting to change the container policy on the main frame will have no
268 // effect.
269 void SetPendingFramePolicy(blink::FramePolicy frame_policy);
270
271 // Returns the currently active frame policy for this frame, including the
272 // sandbox flags which were present at the time the document was loaded, and
Charlie Hu5130d25e2021-03-05 21:53:39273 // the permissions policy container policy, which is set by the iframe's
danakjc492bf82020-09-09 20:02:44274 // allowfullscreen, allowpaymentrequest, and allow attributes, along with the
275 // origin of the iframe's src attribute (which may be different from the URL
276 // of the document currently loaded into the frame). This does not include
277 // policy changes that have been made by updating the containing iframe
278 // element attributes since the frame was last navigated; use
279 // pending_frame_policy() for those.
280 const blink::FramePolicy& effective_frame_policy() const {
Harkiran Bolaria4eacb3a2021-12-13 20:03:47281 return render_manager_.current_replication_state().frame_policy;
danakjc492bf82020-09-09 20:02:44282 }
283
danakjc492bf82020-09-09 20:02:44284 const blink::mojom::FrameOwnerProperties& frame_owner_properties() {
285 return frame_owner_properties_;
286 }
287
288 void set_frame_owner_properties(
289 const blink::mojom::FrameOwnerProperties& frame_owner_properties) {
290 frame_owner_properties_ = frame_owner_properties;
291 }
292
Yuzu Saijo03dbf9b2022-07-22 04:29:45293 // Reflects the attributes of the corresponding iframe html element, such
Arthur Sonzogni64457592022-11-22 11:08:59294 // as 'credentialless', 'id', 'name' and 'src'. These values should not be
Yuzu Saijo03dbf9b2022-07-22 04:29:45295 // exposed to cross-origin renderers.
296 const network::mojom::ContentSecurityPolicy* csp_attribute() const {
297 return attributes_->parsed_csp_attribute.get();
danakjc492bf82020-09-09 20:02:44298 }
Yao Xiao9c54b3e2023-03-14 04:25:04299 // Tracks iframe's 'browsingtopics' attribute, indicating whether the
300 // navigation requests on this frame should calculate and send the
301 // `Sec-Browsing-Topics` header.
302 bool browsing_topics() const { return attributes_->browsing_topics; }
Camillia Smith Barnes6d2966c82023-08-23 21:16:18303
Orr Bernsteina0cc6792023-11-14 22:12:35304 // Tracks iframe's 'adauctionheaders' attribute, indicating whether the
305 // navigation request on this frame should calculate and send the
306 // 'Sec-Ad-Auction-Fetch` header.
307 bool ad_auction_headers() const { return attributes_->ad_auction_headers; }
308
Camillia Smith Barnes6d2966c82023-08-23 21:16:18309 // Tracks iframe's 'sharedstoragewritable' attribute, indicating what value
Camillia Smith Barnesc267be62023-11-01 20:01:02310 // the the corresponding
311 // `network::ResourceRequest::shared_storage_writable_eligible` should take
312 // for the navigation(s) on this frame, pending a permissions policy check. If
313 // true, and if the permissions policy check returns "enabled", the network
Camillia Smith Barnes6d2966c82023-08-23 21:16:18314 // service will send the `Shared-Storage-Write` request header.
Camillia Smith Barnesc267be62023-11-01 20:01:02315 bool shared_storage_writable_opted_in() const {
316 return attributes_->shared_storage_writable_opted_in;
Camillia Smith Barnes6d2966c82023-08-23 21:16:18317 }
Arthur Sonzognic686e8f2024-01-11 08:36:37318 const std::optional<std::string> html_id() const { return attributes_->id; }
Yuzu Saijo03dbf9b2022-07-22 04:29:45319 // This tracks iframe's 'name' attribute instead of window.name, which is
320 // tracked in FrameReplicationState. See the comment for frame_name() for
321 // more details.
Arthur Sonzognic686e8f2024-01-11 08:36:37322 const std::optional<std::string> html_name() const {
Yuzu Saijodc870f92023-01-20 03:39:11323 return attributes_->name;
324 }
Arthur Sonzognic686e8f2024-01-11 08:36:37325 const std::optional<std::string> html_src() const { return attributes_->src; }
danakjc492bf82020-09-09 20:02:44326
Yuzu Saijo03dbf9b2022-07-22 04:29:45327 void SetAttributes(blink::mojom::IframeAttributesPtr attributes);
Antonio Sartori5abc8de2021-07-13 08:42:47328
danakjc492bf82020-09-09 20:02:44329 bool HasSameOrigin(const FrameTreeNode& node) const {
Harkiran Bolaria4eacb3a2021-12-13 20:03:47330 return render_manager_.current_replication_state().origin.IsSameOriginWith(
331 node.current_replication_state().origin);
danakjc492bf82020-09-09 20:02:44332 }
333
Gyuyoung Kimc16e52e92021-03-19 02:45:37334 const blink::mojom::FrameReplicationState& current_replication_state() const {
Harkiran Bolaria4eacb3a2021-12-13 20:03:47335 return render_manager_.current_replication_state();
danakjc492bf82020-09-09 20:02:44336 }
337
338 RenderFrameHostImpl* current_frame_host() const {
339 return render_manager_.current_frame_host();
340 }
341
danakjc492bf82020-09-09 20:02:44342 // Returns true if this node is in a loading state.
343 bool IsLoading() const;
Nate Chapin470dbc62023-04-25 16:34:38344 LoadingState GetLoadingState() const;
danakjc492bf82020-09-09 20:02:44345
Alex Moshchuk9b0fd822020-10-26 23:08:15346 // Returns true if this node has a cross-document navigation in progress.
347 bool HasPendingCrossDocumentNavigation() const;
348
danakjc492bf82020-09-09 20:02:44349 NavigationRequest* navigation_request() { return navigation_request_.get(); }
350
351 // Transfers the ownership of the NavigationRequest to |render_frame_host|.
352 // From ReadyToCommit to DidCommit, the NavigationRequest is owned by the
353 // RenderFrameHost that is committing the navigation.
354 void TransferNavigationRequestOwnership(
355 RenderFrameHostImpl* render_frame_host);
356
357 // Takes ownership of |navigation_request| and makes it the current
358 // NavigationRequest of this frame. This corresponds to the start of a new
359 // navigation. If there was an ongoing navigation request before calling this
360 // function, it is canceled. |navigation_request| should not be null.
Charlie Reis09952ee2022-12-08 16:35:07361 void TakeNavigationRequest(
danakjc492bf82020-09-09 20:02:44362 std::unique_ptr<NavigationRequest> navigation_request);
363
Rakina Zata Amnif8f2bb62022-11-23 05:54:32364 // Resets the navigation request owned by `this` (which shouldn't have reached
365 // the "pending commit" stage yet) and any state created by it, including the
Rakina Zata Amni33175cb92022-11-24 02:46:03366 // speculative RenderFrameHost (if there are no other navigations associated
367 // with it). Note that this does not affect navigations that have reached the
368 // "pending commit" stage, which are owned by their corresponding
369 // RenderFrameHosts instead.
Daniel Cheng390e2a72022-09-28 06:07:53370 void ResetNavigationRequest(NavigationDiscardReason reason);
371
Rakina Zata Amnif8f2bb62022-11-23 05:54:32372 // Similar to `ResetNavigationRequest()`, but keeps the state created by the
Daniel Cheng390e2a72022-09-28 06:07:53373 // NavigationRequest (e.g. speculative RenderFrameHost, loading state).
Rakina Zata Amni58681c62024-06-25 06:32:13374 void ResetNavigationRequestButKeepState(NavigationDiscardReason reason);
danakjc492bf82020-09-09 20:02:44375
danakjc492bf82020-09-09 20:02:44376 // The load progress for a RenderFrameHost in this node was updated to
377 // |load_progress|. This will notify the FrameTree which will in turn notify
378 // the WebContents.
379 void DidChangeLoadProgress(double load_progress);
380
381 // Called when the user directed the page to stop loading. Stops all loads
382 // happening in the FrameTreeNode. This method should be used with
383 // FrameTree::ForEach to stop all loads in the entire FrameTree.
384 bool StopLoading();
385
386 // Returns the time this frame was last focused.
387 base::TimeTicks last_focus_time() const { return last_focus_time_; }
388
389 // Called when this node becomes focused. Updates the node's last focused
390 // time and notifies observers.
391 void DidFocus();
392
393 // Called when the user closed the modal dialogue for BeforeUnload and
394 // cancelled the navigation. This should stop any load happening in the
395 // FrameTreeNode.
396 void BeforeUnloadCanceled();
397
danakjc492bf82020-09-09 20:02:44398 // Returns the sandbox flags currently in effect for this frame. This includes
399 // flags inherited from parent frames, the currently active flags from the
400 // <iframe> element hosting this frame, as well as any flags set from a
401 // Content-Security-Policy HTTP header. This does not include flags that have
402 // have been updated in an <iframe> element but have not taken effect yet; use
403 // pending_frame_policy() for those. To see the flags which will take effect
404 // on navigation (which does not include the CSP-set flags), use
405 // effective_frame_policy().
406 network::mojom::WebSandboxFlags active_sandbox_flags() const {
Harkiran Bolaria4eacb3a2021-12-13 20:03:47407 return render_manager_.current_replication_state().active_sandbox_flags;
danakjc492bf82020-09-09 20:02:44408 }
409
danakjc492bf82020-09-09 20:02:44410 // Returns whether the frame received a user gesture on a previous navigation
411 // on the same eTLD+1.
412 bool has_received_user_gesture_before_nav() const {
Harkiran Bolaria4eacb3a2021-12-13 20:03:47413 return render_manager_.current_replication_state()
414 .has_received_user_gesture_before_nav;
danakjc492bf82020-09-09 20:02:44415 }
416
417 // When a tab is discarded, WebContents sets was_discarded on its
418 // root FrameTreeNode.
419 // In addition, when a child frame is created, this bit is passed on from
420 // parent to child.
421 // When a navigation request is created, was_discarded is passed on to the
422 // request and reset to false in FrameTreeNode.
423 void set_was_discarded() { was_discarded_ = true; }
424 bool was_discarded() const { return was_discarded_; }
425
Miyoung Shin8a66ec022022-11-28 23:50:09426 // Deprecated. Use directly HasStickyUserActivation in RFHI.
danakjc492bf82020-09-09 20:02:44427 // Returns the sticky bit of the User Activation v2 state of the
428 // |FrameTreeNode|.
429 bool HasStickyUserActivation() const {
Miyoung Shin8a66ec022022-11-28 23:50:09430 return current_frame_host()->HasStickyUserActivation();
danakjc492bf82020-09-09 20:02:44431 }
432
Miyoung Shin8a66ec022022-11-28 23:50:09433 // Deprecated. Use directly HasStickyUserActivation in RFHI.
danakjc492bf82020-09-09 20:02:44434 // Returns the transient bit of the User Activation v2 state of the
435 // |FrameTreeNode|.
436 bool HasTransientUserActivation() {
Miyoung Shin8a66ec022022-11-28 23:50:09437 return current_frame_host()->HasTransientUserActivation();
danakjc492bf82020-09-09 20:02:44438 }
439
440 // Remove history entries for all frames created by script in this frame's
441 // subtree. If a frame created by a script is removed, then its history entry
442 // will never be reused - this saves memory.
443 void PruneChildFrameNavigationEntries(NavigationEntryImpl* entry);
444
Abhijeet Kandalkarb43affa72022-09-27 16:48:01445 using FencedFrameStatus = RenderFrameHostImpl::FencedFrameStatus;
Abhijeet Kandalkar3f29bc42022-09-23 12:39:58446 FencedFrameStatus fenced_frame_status() const { return fenced_frame_status_; }
447
Kevin McNee43fe8292021-10-04 22:59:41448 blink::FrameOwnerElementType frame_owner_element_type() const {
Daniel Cheng9bd90f92021-04-23 20:49:45449 return frame_owner_element_type_;
danakjc492bf82020-09-09 20:02:44450 }
danakjc492bf82020-09-09 20:02:44451
Daniel Cheng6ac128172021-05-25 18:49:01452 blink::mojom::TreeScopeType tree_scope_type() const {
453 return tree_scope_type_;
454 }
455
arthursonzogni034bb9c2020-10-01 08:29:56456 // The initial popup URL for new window opened using:
457 // `window.open(initial_popup_url)`.
458 // An empty GURL otherwise.
459 //
460 // [WARNING] There is no guarantee the FrameTreeNode will ever host a
461 // document served from this URL. The FrameTreeNode always starts hosting the
462 // initial empty document and attempts a navigation toward this URL. However
463 // the navigation might be delayed, redirected and even cancelled.
464 void SetInitialPopupURL(const GURL& initial_popup_url);
465 const GURL& initial_popup_url() const { return initial_popup_url_; }
466
467 // The origin of the document that used window.open() to create this frame.
468 // Otherwise, an opaque Origin with a nonce different from all previously
469 // existing Origins.
470 void SetPopupCreatorOrigin(const url::Origin& popup_creator_origin);
471 const url::Origin& popup_creator_origin() const {
472 return popup_creator_origin_;
473 }
474
Harkiran Bolaria59290d62021-03-17 01:53:01475 // Sets the associated FrameTree for this node. The node can change FrameTrees
Domenic Denicola7767a9c2023-07-13 15:36:39476 // as part of prerendering, which allows a page loaded in the prerendered
477 // FrameTree to be used for a navigation in the primary frame tree.
Harkiran Bolaria59290d62021-03-17 01:53:01478 void SetFrameTree(FrameTree& frame_tree);
479
Alexander Timin074cd182022-03-23 18:11:22480 using TraceProto = perfetto::protos::pbzero::FrameTreeNodeInfo;
Alexander Timinf785f342021-03-18 00:00:56481 // Write a representation of this object into a trace.
Alexander Timin074cd182022-03-23 18:11:22482 void WriteIntoTrace(perfetto::TracedProto<TraceProto> proto) const;
Alexander Timinf785f342021-03-18 00:00:56483
Carlos Caballero76711352021-03-24 17:38:21484 // Returns true the node is navigating, i.e. it has an associated
485 // NavigationRequest.
486 bool HasNavigation();
487
murakinonoka97a8f042024-01-10 09:17:07488 // Returns true if there are any navigations happening in FrameTreeNode that
489 // is pending commit (i.e. between ReadyToCommit and DidCommit). Note that
490 // those navigations won't live in the FrameTreeNode itself, as they will
491 // already be owned by the committing RenderFrameHost (either the current
492 // RenderFrameHost or the speculative RenderFrameHost).
493 bool HasPendingCommitNavigation();
494
shivanigithubf3ddff52021-07-03 22:06:30495 // Fenced frames (meta-bug crbug.com/1111084):
shivanigithub4cd016a2021-09-20 21:10:30496 // Note that these two functions cannot be invoked from a FrameTree's or
497 // its root node's constructor since they require the frame tree and the
498 // root node to be completely constructed.
499 //
shivanigithubf3ddff52021-07-03 22:06:30500 // Returns false if fenced frames are disabled. Returns true if the feature is
501 // enabled and if |this| is a fenced frame. Returns false for
502 // iframes embedded in a fenced frame. To clarify: for the MPArch
503 // implementation this only returns true if |this| is the actual
504 // root node of the inner FrameTree and not the proxy FrameTreeNode in the
505 // outer FrameTree.
Dominic Farolino4bc10ee2021-08-31 00:37:36506 bool IsFencedFrameRoot() const;
shivanigithubf3ddff52021-07-03 22:06:30507
508 // Returns false if fenced frames are disabled. Returns true if the
509 // feature is enabled and if |this| or any of its ancestor nodes is a
510 // fenced frame.
511 bool IsInFencedFrameTree() const;
512
shivanigithub4cd016a2021-09-20 21:10:30513 // Returns a valid nonce if `IsInFencedFrameTree()` returns true for `this`.
Garrett Tanzer34cb92fe2022-09-28 17:50:54514 // Returns nullopt otherwise.
515 //
516 // Nonce used in the net::IsolationInfo and blink::StorageKey for a fenced
517 // frame and any iframes nested within it. Not set if this frame is not in a
518 // fenced frame's FrameTree. Note that this could be a field in FrameTree for
519 // the MPArch version but for the shadow DOM version we need to keep it here
520 // since the fenced frame root is not a main frame for the latter. The value
521 // of the nonce will be the same for all of the the iframes inside a fenced
522 // frame tree. If there is a nested fenced frame it will have a different
523 // nonce than its parent fenced frame. The nonce will stay the same across
524 // navigations initiated from the fenced frame tree because it is always used
525 // in conjunction with other fields of the keys and would be good to access
526 // the same storage across same-origin navigations. If the navigation is
527 // same-origin/site then the same network stack partition/storage will be
528 // reused and if it's cross-origin/site then other parts of the key will
529 // change and so, even with the same nonce, another partition will be used.
530 // But if the navigation is initiated from the embedder, the nonce will be
531 // reinitialized irrespective of same or cross origin such that there is no
532 // privacy leak via storage shared between two embedder initiated navigations.
533 // Note that this reinitialization is implemented for all embedder-initiated
534 // navigations in MPArch, but only urn:uuid navigations in ShadowDOM.
Arthur Sonzognic686e8f2024-01-11 08:36:37535 std::optional<base::UnguessableToken> GetFencedFrameNonce();
shivanigithub4cd016a2021-09-20 21:10:30536
Garrett Tanzer34cb92fe2022-09-28 17:50:54537 // If applicable, initialize the default fenced frame properties. Right now,
538 // this means setting a new fenced frame nonce. See comment on
shivanigithub4cd016a2021-09-20 21:10:30539 // fenced_frame_nonce() for when it is set to a non-null value. Invoked
540 // by FrameTree::Init() or FrameTree::AddFrame().
Garrett Tanzer34cb92fe2022-09-28 17:50:54541 void SetFencedFramePropertiesIfNeeded();
shivanigithub4cd016a2021-09-20 21:10:30542
Garrett Tanzer291a2d52023-03-20 22:41:57543 // Set the current FencedFrameProperties to have "opaque ads mode".
544 // This should only be used during tests, when the proper embedder-initiated
545 // fenced frame root urn/config navigation flow isn't available.
Alison Gale770f3fc2024-04-27 00:39:58546 // TODO(crbug.com/40233168): Refactor and expand use of test utils so there is
Garrett Tanzer291a2d52023-03-20 22:41:57547 // a consistent way to do this properly everywhere. Consider removing
548 // arbitrary restrictions in "default mode" so that using opaque ads mode is
549 // less necessary.
550 void SetFencedFramePropertiesOpaqueAdsModeForTesting() {
551 if (fenced_frame_properties_.has_value()) {
Garrett Tanzer06980702023-12-12 19:48:20552 fenced_frame_properties_
553 ->SetFencedFramePropertiesOpaqueAdsModeForTesting();
Garrett Tanzer291a2d52023-03-20 22:41:57554 }
555 }
556
557 // Returns the mode attribute from the `FencedFrameProperties` if this frame
558 // is in a fenced frame tree, otherwise returns `kDefault`.
559 blink::FencedFrame::DeprecatedFencedFrameMode GetDeprecatedFencedFrameMode();
Nan Lin171fe9a2022-02-17 16:42:16560
Dave Tapuskac8de3b02021-12-03 21:51:01561 // Helper for GetParentOrOuterDocument/GetParentOrOuterDocumentOrEmbedder.
562 // Do not use directly.
Kevin McNee86e64ee2023-02-17 16:35:50563 // `escape_guest_view` determines whether to iterate out of guest views and is
564 // the behaviour distinction between GetParentOrOuterDocument and
565 // GetParentOrOuterDocumentOrEmbedder. See the comment on
566 // GetParentOrOuterDocumentOrEmbedder for details.
567 // `include_prospective` includes embedders which own our frame tree, but have
568 // not yet attached it to the outer frame tree.
Arthur Hemerya06697f2023-03-14 09:20:57569 RenderFrameHostImpl* GetParentOrOuterDocumentHelper(
570 bool escape_guest_view,
571 bool include_prospective) const;
Dave Tapuskac8de3b02021-12-03 21:51:01572
Harkiran Bolariab4437fd2021-08-11 17:51:22573 // Sets the unique_name and name fields on replication_state_. To be used in
574 // prerender activation to make sure the FrameTreeNode replication state is
575 // correct after the RenderFrameHost is moved between FrameTreeNodes. The
576 // renderers should already have the correct value, so unlike
577 // FrameTreeNode::SetFrameName, we do not notify them here.
Alison Gale770f3fc2024-04-27 00:39:58578 // TODO(crbug.com/40192974): Remove this once the BrowsingContextState
Harkiran Bolaria4eacb3a2021-12-13 20:03:47579 // is implemented to utilize the new path.
Harkiran Bolariab4437fd2021-08-11 17:51:22580 void set_frame_name_for_activation(const std::string& unique_name,
581 const std::string& name) {
Harkiran Bolaria0b3bdef02022-03-10 13:04:40582 current_frame_host()->browsing_context_state()->set_frame_name(unique_name,
583 name);
Harkiran Bolariab4437fd2021-08-11 17:51:22584 }
585
Nan Linaaf84f72021-12-02 22:31:56586 // Returns true if error page isolation is enabled.
587 bool IsErrorPageIsolationEnabled() const;
588
W. James MacLean81b8d01f2022-01-25 20:50:59589 // Functions to store and retrieve a frame's srcdoc value on this
590 // FrameTreeNode.
591 void SetSrcdocValue(const std::string& srcdoc_value);
592 const std::string& srcdoc_value() const { return srcdoc_value_; }
593
Garrett Tanzerc69f4642022-08-15 22:15:14594 void set_fenced_frame_properties(
Arthur Sonzognic686e8f2024-01-11 08:36:37595 const std::optional<FencedFrameProperties>& fenced_frame_properties) {
Alison Gale770f3fc2024-04-27 00:39:58596 // TODO(crbug.com/40202462): Reenable this DCHECK once ShadowDOM and
Garrett Tanzer2975eeac2022-08-22 16:34:01597 // loading urns in iframes (for FLEDGE OT) are gone.
598 // DCHECK_EQ(fenced_frame_status_,
599 // RenderFrameHostImpl::FencedFrameStatus::kFencedFrameRoot);
Garrett Tanzerc69f4642022-08-15 22:15:14600 fenced_frame_properties_ = fenced_frame_properties;
601 }
602
Xiaochen Zhou86f2e712023-09-13 19:55:04603 // This function returns the fenced frame properties associated with the given
604 // source.
605 // - If `source_node` is set to `kClosestAncestor`, the fenced frame
606 // properties are obtained by a bottom-up traversal from this node.
607 // - If `source_node` is set tp `kFrameTreeRoot`, the fenced frame properties
608 // from the fenced frame tree root are returned.
609 // For example, for an urn iframe that is nested inside a fenced frame.
610 // Calling this function from the nested urn iframe with `source_node` set to:
611 // - `kClosestAncestor`: returns the fenced frame properties from the urn
612 // iframe.
613 // - `kFrameTreeRoot`: returns the fenced frame properties from the fenced
614 // frame.
615 // Clients should decide which one to use depending on how the application of
616 // the fenced frame properties interact with urn iframes.
Alison Gale770f3fc2024-04-27 00:39:58617 // TODO(crbug.com/40060657): Once navigation support for urn::uuid in iframes
Xiaochen Zhou86f2e712023-09-13 19:55:04618 // is deprecated, remove the parameter `node_source`.
Arthur Sonzognic686e8f2024-01-11 08:36:37619 std::optional<FencedFrameProperties>& GetFencedFrameProperties(
Xiaochen Zhou86f2e712023-09-13 19:55:04620 FencedFramePropertiesNodeSource node_source =
621 FencedFramePropertiesNodeSource::kClosestAncestor);
Garrett Tanzerc69f4642022-08-15 22:15:14622
Liam Brady27da6a22024-06-05 16:35:34623 // Helper function for getting the FrameTreeNode that houses the relevant
624 // FencedFrameProperties when GetFencedFrameProperties() is called with
625 // kClosestAncestor.
626 FrameTreeNode* GetClosestAncestorWithFencedFrameProperties();
627
Liam Brady86ca0482023-12-06 19:49:25628 bool HasFencedFrameProperties() const {
629 return fenced_frame_properties_.has_value();
630 }
631
Yao Xiaof9ae90a2023-03-01 20:52:44632 // Returns the number of fenced frame boundaries above this frame. The
Yao Xiaoa2337ad2022-10-12 20:59:29633 // outermost main frame's frame tree has fenced frame depth 0, a topmost
634 // fenced frame tree embedded in the outermost main frame has fenced frame
635 // depth 1, etc.
Yao Xiaof9ae90a2023-03-01 20:52:44636 //
637 // Also, sets `shared_storage_fenced_frame_root_count` to the
638 // number of fenced frame boundaries (roots) above this frame that originate
639 // from shared storage. This is used to check whether a fenced frame
640 // originates from shared storage only (i.e. not from FLEDGE).
Alison Gale770f3fc2024-04-27 00:39:58641 // TODO(crbug.com/40233168): Remove this check once we put permissions inside
Yao Xiaof9ae90a2023-03-01 20:52:44642 // FencedFrameConfig.
643 size_t GetFencedFrameDepth(size_t& shared_storage_fenced_frame_root_count);
Yao Xiaoa2337ad2022-10-12 20:59:29644
645 // Traverse up from this node. Return all valid
646 // `node->fenced_frame_properties_->shared_storage_budget_metadata` (i.e. this
647 // node is subjected to the shared storage budgeting associated with those
648 // metadata). Every node that originates from sharedStorage.selectURL() will
649 // have an associated metadata. This indicates that the metadata can only
650 // possibly be associated with a fenced frame root, unless when
651 // `kAllowURNsInIframes` is enabled in which case they could be be associated
652 // with any node.
Garrett Tanzer29de7112022-12-06 21:26:32653 std::vector<const SharedStorageBudgetMetadata*>
Yao Xiao1ac702d2022-06-08 17:20:49654 FindSharedStorageBudgetMetadata();
655
Camillia Smith Barnes7218518c2023-03-06 19:02:17656 // Returns any shared storage context string that was written to a
657 // `blink::FencedFrameConfig` before navigation via
658 // `setSharedStorageContext()`, as long as the request is for a same-origin
659 // frame within the config's fenced frame tree (or a same-origin descendant of
660 // a URN iframe).
Arthur Sonzognic686e8f2024-01-11 08:36:37661 std::optional<std::u16string> GetEmbedderSharedStorageContextIfAllowed();
Camillia Smith Barnes7218518c2023-03-06 19:02:17662
Harkiran Bolariaebbe7702022-02-22 19:19:03663 // Accessor to BrowsingContextState for subframes only. Only main frame
664 // navigations can change BrowsingInstances and BrowsingContextStates,
665 // therefore for subframes associated BrowsingContextState never changes. This
666 // helper method makes this more explicit and guards against calling this on
667 // main frames (there an appropriate BrowsingContextState should be obtained
668 // from RenderFrameHost or from RenderFrameProxyHost as e.g. during
669 // cross-BrowsingInstance navigations multiple BrowsingContextStates exist in
670 // the same frame).
671 const scoped_refptr<BrowsingContextState>&
672 GetBrowsingContextStateForSubframe() const;
673
Arthur Hemerye4659282022-03-28 08:36:15674 // Clears the opener property of popups referencing this FrameTreeNode as
675 // their opener.
676 void ClearOpenerReferences();
677
Liam Brady95d36d12023-03-13 21:13:06678 // Calculates whether one of the ancestor frames or this frame has a CSPEE in
679 // place. This is eventually sent over to LocalFrame in the renderer where it
680 // will be used by NavigatorAuction::canLoadAdAuctionFencedFrame for
681 // information it can't get on its own.
Liam Bradyd2a41e152022-07-19 13:58:48682 bool AncestorOrSelfHasCSPEE() const;
683
Arthur Sonzogni8e8eb1f2023-01-10 14:51:01684 // Reset every navigation in this frame, and its descendants. This is called
685 // after the <iframe> element has been removed, or after the document owning
686 // this frame has been navigated away.
687 //
688 // This takes into account:
689 // - Non-pending commit NavigationRequest owned by the FrameTreeNode
690 // - Pending commit NavigationRequest owned by the current RenderFrameHost
691 // - Speculative RenderFrameHost and its pending commit NavigationRequests.
692 void ResetAllNavigationsForFrameDetach();
693
Miyoung Shin7cf88b42022-11-07 13:22:30694 // RenderFrameHostOwner implementation:
Nate Chapin470dbc62023-04-25 16:34:38695 void DidStartLoading(LoadingState previous_frame_tree_loading_state) override;
Julie Jeongeun Kim07c077bd2022-12-05 08:40:31696 void DidStopLoading() override;
Miyoung Shin7cf88b42022-11-07 13:22:30697 void RestartNavigationAsCrossDocument(
698 std::unique_ptr<NavigationRequest> navigation_request) override;
Miyoung Shin1504eb712022-12-07 10:32:18699 bool Reload() override;
Julie Jeongeun Kimc1b07c32022-11-11 10:26:32700 Navigator& GetCurrentNavigator() override;
Miyoung Shine16cd2262022-11-30 05:52:16701 RenderFrameHostManager& GetRenderFrameHostManager() override;
Miyoung Shin64fd1bea2023-01-04 04:22:08702 FrameTreeNode* GetOpener() const override;
Julie Jeongeun Kim2132b37f82022-11-23 08:30:46703 void SetFocusedFrame(SiteInstanceGroup* source) override;
Julie Jeongeun Kim0e242242022-11-30 10:45:09704 void DidChangeReferrerPolicy(
705 network::mojom::ReferrerPolicy referrer_policy) override;
Miyoung Shin8a66ec022022-11-28 23:50:09706 // Updates the user activation state in the browser frame tree and in the
707 // frame trees in all renderer processes except the renderer for this node
708 // (which initiated the update). Returns |false| if the update tries to
709 // consume an already consumed/expired transient state, |true| otherwise. See
710 // the comment on `user_activation_state_` in RenderFrameHostImpl.
711 //
712 // The |notification_type| parameter is used for histograms, only for the case
713 // |update_state == kNotifyActivation|.
714 bool UpdateUserActivationState(
715 blink::mojom::UserActivationUpdateType update_type,
716 blink::mojom::UserActivationNotificationType notification_type) override;
Nate Chapin47276a62023-02-16 16:53:44717 void DidConsumeHistoryUserActivation() override;
Charlie Reis734db662024-01-11 18:20:03718 void DidOpenDocumentInputStream() override;
Miyoung Shinff13ed22022-11-30 09:21:47719 std::unique_ptr<NavigationRequest>
720 CreateNavigationRequestForSynchronousRendererCommit(
721 RenderFrameHostImpl* render_frame_host,
722 bool is_same_document,
723 const GURL& url,
724 const url::Origin& origin,
Arthur Sonzognic686e8f2024-01-11 08:36:37725 const std::optional<GURL>& initiator_base_url,
Miyoung Shinff13ed22022-11-30 09:21:47726 const net::IsolationInfo& isolation_info_for_subresources,
727 blink::mojom::ReferrerPtr referrer,
728 const ui::PageTransition& transition,
729 bool should_replace_current_entry,
730 const std::string& method,
731 bool has_transient_activation,
732 bool is_overriding_user_agent,
733 const std::vector<GURL>& redirects,
734 const GURL& original_url,
735 std::unique_ptr<CrossOriginEmbedderPolicyReporter> coep_reporter,
Camille Lamy36afacd2025-01-16 14:25:18736 std::unique_ptr<DocumentIsolationPolicyReporter> dip_reporter,
Charlie Reise1d9b8182025-04-02 04:32:12737 int http_response_code,
738 base::TimeTicks actual_navigation_start) override;
Rakina Zata Amni58681c62024-06-25 06:32:13739 void CancelNavigation(NavigationDiscardReason reason) override;
Thomas Lukaszewicz1b672fe2024-09-17 08:35:03740 void ResetNavigationsForDiscard() override;
Miyoung Shinc9ff4812023-01-05 08:58:05741 bool Credentialless() const override;
Kevin McNeef1b0f0b2024-09-17 21:49:41742 FrameType GetCurrentFrameType() const override;
Miyoung Shinff13ed22022-11-30 09:21:47743
Mingyu Lei7956b8b2023-07-24 08:24:08744 // Restart the navigation restoring the page from the back-forward cache
745 // as a regular non-BFCached history navigation.
746 //
747 // The restart itself is asynchronous as it's dangerous to restart navigation
748 // with arbitrary state on the stack (another navigation might be starting),
749 // so this function only posts the actual task to do all the work (See
750 // `RestartBackForwardCachedNavigationImpl()`).
751 void RestartBackForwardCachedNavigationAsync(int nav_entry_id);
752
753 // Cancel the asynchronous task that would restart the BFCache navigation.
754 // This should be called whenever a FrameTreeNode's NavigationRequest would
755 // normally get cancelled, including when another NavigationRequest starts.
756 // This preserves the previous behavior where a restarting BFCache
757 // NavigationRequest is kept around until the task to create the new
758 // navigation is run, or until that NavigationRequest gets deleted (which
759 // cancels the task).
760 void CancelRestartingBackForwardCacheNavigation();
761
Christian Biesingere1865c57c2023-10-20 15:19:29762 base::SafeRef<FrameTreeNode> GetSafeRef() {
763 return weak_factory_.GetSafeRef();
764 }
765
danakjc492bf82020-09-09 20:02:44766 private:
Yuzu Saijo03dbf9b2022-07-22 04:29:45767 friend class CSPEmbeddedEnforcementUnitTest;
Charlie Hubb5943d2021-03-09 19:46:12768 FRIEND_TEST_ALL_PREFIXES(SitePerProcessPermissionsPolicyBrowserTest,
danakjc492bf82020-09-09 20:02:44769 ContainerPolicyDynamic);
Charlie Hubb5943d2021-03-09 19:46:12770 FRIEND_TEST_ALL_PREFIXES(SitePerProcessPermissionsPolicyBrowserTest,
danakjc492bf82020-09-09 20:02:44771 ContainerPolicySandboxDynamic);
Yuzu Saijo03dbf9b2022-07-22 04:29:45772 FRIEND_TEST_ALL_PREFIXES(NavigationRequestTest, StorageKeyToCommit);
Arthur Sonzogni64457592022-11-22 11:08:59773 FRIEND_TEST_ALL_PREFIXES(
774 NavigationRequestTest,
775 NavigationToCredentiallessDocumentNetworkIsolationInfo);
Yuzu Saijo03dbf9b2022-07-22 04:29:45776 FRIEND_TEST_ALL_PREFIXES(RenderFrameHostImplTest,
Arthur Sonzogni64457592022-11-22 11:08:59777 ChildOfCredentiallessIsCredentialless);
Yifan Luo86a79f42022-08-16 18:38:27778 FRIEND_TEST_ALL_PREFIXES(ContentPasswordManagerDriverTest,
Arthur Sonzogni64457592022-11-22 11:08:59779 PasswordAutofillDisabledOnCredentiallessIframe);
danakjc492bf82020-09-09 20:02:44780
Dominic Farolino8a2187b2021-12-24 20:44:21781 // Called by the destructor. When `this` is an outer dummy FrameTreeNode
782 // representing an inner FrameTree, this method destroys said inner FrameTree.
783 void DestroyInnerFrameTreeIfExists();
784
danakjc492bf82020-09-09 20:02:44785 class OpenerDestroyedObserver;
786
danakjc492bf82020-09-09 20:02:44787 // The |notification_type| parameter is used for histograms only.
Liam Brady38b84562024-03-07 22:11:26788 // |sticky_only| is set to true when propagating sticky user activation during
789 // cross-document navigations. The transient state remains unchanged.
danakjc492bf82020-09-09 20:02:44790 bool NotifyUserActivation(
Liam Brady38b84562024-03-07 22:11:26791 blink::mojom::UserActivationNotificationType notification_type,
792 bool sticky_only = false);
793
794 bool NotifyUserActivationStickyOnly();
danakjc492bf82020-09-09 20:02:44795
796 bool ConsumeTransientUserActivation();
797
798 bool ClearUserActivation();
799
800 // Verify that the renderer process is allowed to set user activation on this
801 // frame by checking whether this frame's RenderWidgetHost had previously seen
802 // an input event that might lead to user activation. If user activation
803 // should be allowed, this returns true and also clears corresponding pending
804 // user activation state in the widget. Otherwise, this returns false.
805 bool VerifyUserActivation();
806
Mingyu Lei7956b8b2023-07-24 08:24:08807 // See `RestartBackForwardCachedNavigationAsync()`.
808 void RestartBackForwardCachedNavigationImpl(int nav_entry_id);
809
Avi Drissmanbd153642024-09-03 18:58:05810 // The browser-global FrameTreeNodeId generator.
811 static FrameTreeNodeId::Generator frame_tree_node_id_generator_;
danakjc492bf82020-09-09 20:02:44812
Arthur Sonzognif6785ec2022-12-05 10:11:50813 // The FrameTree owning |this|. It can change with Prerender2 during
814 // activation.
815 raw_ref<FrameTree> frame_tree_;
danakjc492bf82020-09-09 20:02:44816
danakjc492bf82020-09-09 20:02:44817 // A browser-global identifier for the frame in the page, which stays stable
818 // even if the frame does a cross-process navigation.
Avi Drissmanbd153642024-09-03 18:58:05819 const FrameTreeNodeId frame_tree_node_id_;
danakjc492bf82020-09-09 20:02:44820
821 // The RenderFrameHost owning this FrameTreeNode, which cannot change for the
822 // life of this FrameTreeNode. |nullptr| if this node is the root.
Keishi Hattori0e45c022021-11-27 09:25:52823 const raw_ptr<RenderFrameHostImpl> parent_;
danakjc492bf82020-09-09 20:02:44824
danakjc492bf82020-09-09 20:02:44825 // The frame that opened this frame, if any. Will be set to null if the
826 // opener is closed, or if this frame disowns its opener by setting its
827 // window.opener to null.
Keishi Hattori0e45c022021-11-27 09:25:52828 raw_ptr<FrameTreeNode> opener_ = nullptr;
danakjc492bf82020-09-09 20:02:44829
830 // An observer that clears this node's |opener_| if the opener is destroyed.
831 // This observer is added to the |opener_|'s observer list when the |opener_|
832 // is set to a non-null node, and it is removed from that list when |opener_|
833 // changes or when this node is destroyed. It is also cleared if |opener_|
834 // is disowned.
835 std::unique_ptr<OpenerDestroyedObserver> opener_observer_;
836
Rakina Zata Amni3a48ae42022-05-05 03:39:56837 // Unlike `opener_`, the "original opener chain" doesn't reflect
838 // window.opener, which can be suppressed or updated. The "original opener"
839 // is the main frame of the actual opener of this frame. This traces the all
840 // the way back, so if the original opener was closed (deleted or severed due
841 // to COOP), but _it_ had an original opener, this will return the original
842 // opener's original opener, etc. So this value will always be set as long as
843 // there is at least one live frame in the chain whose connection is not
844 // severed due to COOP.
845 raw_ptr<FrameTreeNode> first_live_main_frame_in_original_opener_chain_ =
846 nullptr;
danakjc492bf82020-09-09 20:02:44847
Wolfgang Beyerd8809db2020-09-30 15:29:39848 // The devtools frame token of the frame which opened this frame. This is
849 // not cleared even if the opener is destroyed or disowns the frame.
Arthur Sonzognic686e8f2024-01-11 08:36:37850 std::optional<base::UnguessableToken> opener_devtools_frame_token_;
Wolfgang Beyerd8809db2020-09-30 15:29:39851
Rakina Zata Amni3a48ae42022-05-05 03:39:56852 // An observer that updates this node's
853 // |first_live_main_frame_in_original_opener_chain_| to the next original
854 // opener in the chain if the original opener is destroyed.
danakjc492bf82020-09-09 20:02:44855 std::unique_ptr<OpenerDestroyedObserver> original_opener_observer_;
856
arthursonzogni034bb9c2020-10-01 08:29:56857 // When created by an opener, the URL specified in window.open(url)
858 // Please refer to {Get,Set}InitialPopupURL() documentation.
859 GURL initial_popup_url_;
860
861 // When created using window.open, the origin of the creator.
862 // Please refer to {Get,Set}PopupCreatorOrigin() documentation.
863 url::Origin popup_creator_origin_;
864
W. James MacLean81b8d01f2022-01-25 20:50:59865 // If the url from the the last BeginNavigation is about:srcdoc, this value
866 // stores the srcdoc_attribute's value for re-use in history navigations.
867 std::string srcdoc_value_;
868
Charlie Reis734db662024-01-11 18:20:03869 // Whether this frame is still on the initial about:blank document or the
870 // synchronously committed about:blank document committed at frame creation,
871 // and its "initial empty document"-ness is still true.
872 // This will be false if either of these has happened:
873 // - The current RenderFrameHost commits a cross-document navigation that is
874 // not the synchronously committed about:blank document per:
875 // https://html.spec.whatwg.org/multipage/browsers.html#creating-browsing-contexts:is-initial-about:blank
876 // - The document's input stream has been opened with document.open(), per
877 // https://html.spec.whatwg.org/multipage/dynamic-markup-insertion.html#opening-the-input-stream:is-initial-about:blank
878 // NOTE: we treat both the "initial about:blank document" and the
879 // "synchronously committed about:blank document" as the initial empty
880 // document. In the future, we plan to remove the synchronous about:blank
881 // commit so that this state will only be true if the frame is on the
882 // "initial about:blank document". See also:
883 // - https://github.com/whatwg/html/issues/6863
884 // - https://crbug.com/1215096
885 //
886 // Note that cross-document navigations update this state at
887 // DidCommitNavigation() time. Thus, this is still true when a cross-document
888 // navigation from an initial empty document is in the pending-commit window,
889 // after sending the CommitNavigation IPC but before receiving
890 // DidCommitNavigation(). This is in contrast to
891 // has_committed_any_navigation(), which is updated in CommitNavigation().
892 // TODO(alexmos): Consider updating this at CommitNavigation() time as well to
893 // match the has_committed_any_navigation() behavior.
894 bool is_on_initial_empty_document_ = true;
895
danakjc492bf82020-09-09 20:02:44896 // Whether the frame's owner element in the parent document is collapsed.
arthursonzogni9816b9192021-03-29 16:09:19897 bool is_collapsed_ = false;
danakjc492bf82020-09-09 20:02:44898
Daniel Cheng6ac128172021-05-25 18:49:01899 // The type of frame owner for this frame. This is only relevant for non-main
900 // frames.
Kevin McNee43fe8292021-10-04 22:59:41901 const blink::FrameOwnerElementType frame_owner_element_type_ =
902 blink::FrameOwnerElementType::kNone;
Daniel Cheng9bd90f92021-04-23 20:49:45903
Daniel Cheng6ac128172021-05-25 18:49:01904 // The tree scope type of frame owner element, i.e. whether the element is in
905 // the document tree (https://dom.spec.whatwg.org/#document-trees) or the
906 // shadow tree (https://dom.spec.whatwg.org/#shadow-trees). This is only
907 // relevant for non-main frames.
908 const blink::mojom::TreeScopeType tree_scope_type_ =
909 blink::mojom::TreeScopeType::kDocument;
910
Ming-Ying Chung0430c592025-01-21 00:33:10911 // Track the pending sandbox flags, container policy, and deferred fetch
912 // policy for this frame.
913 // When a parent frame dynamically updates 'sandbox', 'allow',
914 // 'allowfullscreen', 'allowpaymentrequest' or 'src' attributes, the updated
915 // policy for the frame is stored here, and transferred into
Harkiran Bolaria4eacb3a2021-12-13 20:03:47916 // render_manager_.current_replication_state().frame_policy when they take
917 // effect on the next frame navigation.
Ming-Ying Chung0430c592025-01-21 00:33:10918 //
919 // Note that updates to FramePolicy from the renderer side must be explicitly
920 // set in this field via `SetPendingFramePolicy()`; Otherwise, the browser
921 // side won't have it saved and can't pass it to new RenderFrameHost.
danakjc492bf82020-09-09 20:02:44922 blink::FramePolicy pending_frame_policy_;
923
924 // Whether the frame was created by javascript. This is useful to prune
925 // history entries when the frame is removed (because frames created by
926 // scripts are never recreated with the same unique name - see
927 // https://crbug.com/500260).
arthursonzogni9816b9192021-03-29 16:09:19928 const bool is_created_by_script_;
danakjc492bf82020-09-09 20:02:44929
danakjc492bf82020-09-09 20:02:44930 // Tracks the scrolling and margin properties for this frame. These
931 // properties affect the child renderer but are stored on its parent's
932 // frame element. When this frame's parent dynamically updates these
933 // properties, we update them here too.
934 //
935 // Note that dynamic updates only take effect on the next frame navigation.
936 blink::mojom::FrameOwnerProperties frame_owner_properties_;
937
Yuzu Saijo03dbf9b2022-07-22 04:29:45938 // Contains the tracked HTML attributes of the corresponding iframe element,
939 // such as 'id' and 'src'.
940 blink::mojom::IframeAttributesPtr attributes_;
Antonio Sartori5abc8de2021-07-13 08:42:47941
danakjc492bf82020-09-09 20:02:44942 // Owns an ongoing NavigationRequest until it is ready to commit. It will then
943 // be reset and a RenderFrameHost will be responsible for the navigation.
944 std::unique_ptr<NavigationRequest> navigation_request_;
945
946 // List of objects observing this FrameTreeNode.
947 base::ObserverList<Observer>::Unchecked observers_;
948
949 base::TimeTicks last_focus_time_;
950
arthursonzogni9816b9192021-03-29 16:09:19951 bool was_discarded_ = false;
danakjc492bf82020-09-09 20:02:44952
Abhijeet Kandalkar3f29bc42022-09-23 12:39:58953 const FencedFrameStatus fenced_frame_status_ =
954 FencedFrameStatus::kNotNestedInFencedFrame;
Harkiran Bolaria16f2c48d2022-04-22 12:39:57955
Garrett Tanzerc69f4642022-08-15 22:15:14956 // If this is a fenced frame resulting from a urn:uuid navigation, this
957 // contains all the metadata specifying the resulting context.
Alison Gale770f3fc2024-04-27 00:39:58958 // TODO(crbug.com/40202462): Move this into the FrameTree once ShadowDOM
Garrett Tanzer34cb92fe2022-09-28 17:50:54959 // and urn iframes are gone.
Arthur Sonzognic686e8f2024-01-11 08:36:37960 std::optional<FencedFrameProperties> fenced_frame_properties_;
Garrett Tanzerc69f4642022-08-15 22:15:14961
Mingyu Lei7956b8b2023-07-24 08:24:08962 // The tracker of the task that restarts the BFCache navigation. It might be
963 // used to cancel the task.
964 // See `CancelRestartingBackForwardCacheNavigation()`.
965 base::CancelableTaskTracker restart_back_forward_cached_navigation_tracker_;
966
Andrew Verge7233e662025-05-13 13:09:23967 // The last successfully committed origin in this frame. Set in two scenarios:
968 // 1. By RenderFrameHostImpl::DidNavigate() when a navigation in this frame
969 // succeeds.
970 // 2. By RenderFrameHostImpl::SetOriginDependentStateOfNewFrame() when a new
971 // frame is first created, which will reflect the origin of the initial
972 // about::blank document before any navigation has committed.
973 url::Origin last_successful_origin_;
974
Lukasz Anforowicz147141962020-12-16 18:03:24975 // Manages creation and swapping of RenderFrameHosts for this frame.
976 //
977 // This field needs to be declared last, because destruction of
978 // RenderFrameHostManager may call arbitrary callbacks (e.g. via
979 // WebContentsObserver::DidFinishNavigation fired after RenderFrameHostManager
980 // destructs a RenderFrameHostImpl and its NavigationRequest). Such callbacks
981 // may try to use FrameTreeNode's fields above - this would be an undefined
982 // behavior if the fields (even trivially-destructible ones) were destructed
983 // before the RenderFrameHostManager's destructor runs. See also
984 // https://crbug.com/1157988.
985 RenderFrameHostManager render_manager_;
Mingyu Lei7956b8b2023-07-24 08:24:08986
987 base::WeakPtrFactory<FrameTreeNode> weak_factory_{this};
danakjc492bf82020-09-09 20:02:44988};
989
990} // namespace content
991
992#endif // CONTENT_BROWSER_RENDERER_HOST_FRAME_TREE_NODE_H_