Original Symbian headers
Selected EUSER, Window Server, networking, graphics and device declarations
Loading...
Searching...
No Matches
TSecurityPolicy Class Reference

Class representing a generic security policy. More...

#include <e32cmn.h>

Public Types

enum  TSecPolicyType { EAlwaysFail =0 , EAlwaysPass =1 }
 
enum  TType {
  ETypeFail =0 , ETypePass =1 , ETypeC3 =2 , ETypeC7 =3 ,
  ETypeS3 =4 , ETypeV3 =5 , ETypeLimit
}
 Constants to specify the type of TSecurityPolicy objects. More...
 

Public Member Functions

 TSecurityPolicy ()
 Constructs a TSecurityPolicy that will always fail, irrespective of the checked object's attributes.
 
IMPORT_C TSecurityPolicy (TSecPolicyType aType)
 
IMPORT_C TSecurityPolicy (TCapability aCap1, TCapability aCap2=ECapability_None, TCapability aCap3=ECapability_None)
 
IMPORT_C TSecurityPolicy (TCapability aCap1, TCapability aCap2, TCapability aCap3, TCapability aCap4, TCapability aCap5=ECapability_None, TCapability aCap6=ECapability_None, TCapability aCap7=ECapability_None)
 
IMPORT_C TSecurityPolicy (TSecureId aSecureId, TCapability aCap1=ECapability_None, TCapability aCap2=ECapability_None, TCapability aCap3=ECapability_None)
 
IMPORT_C TSecurityPolicy (TVendorId aVendorId, TCapability aCap1=ECapability_None, TCapability aCap2=ECapability_None, TCapability aCap3=ECapability_None)
 
IMPORT_C TInt Set (const TDesC8 &aDes)
 Sets this TSecurityPolicy to a copy of the policy described by the supplied descriptor.
 
IMPORT_C TPtrC8 Package () const
 Constructs a TPtrC8 wrapping the platform security attributes of this TSecurityPolicy.
 
TBool CheckPolicy (RProcess aProcess, const char *aDiagnostic=0) const
 Checks this policy against the platform security attributes of aProcess.
 
TBool CheckPolicy (RThread aThread, const char *aDiagnostic=0) const
 Checks this policy against the platform security attributes of the process owning aThread.
 
TBool CheckPolicy (RMessagePtr2 aMsgPtr, const char *aDiagnostic=0) const
 Checks this policy against the platform security attributes of the process which sent the given message.
 
TBool CheckPolicy (RMessagePtr2 aMsgPtr, TSecurityInfo &aMissing, const char *aDiagnostic=0) const
 Checks this policy against the platform security attributes of the process which sent the given message.
 
TBool CheckPolicyCreator (const char *aDiagnostic=0) const
 Checks this policy against the platform security attributes of this process' creator.
 
TInt CheckPolicy (RSessionBase aSession) const
 Internal component API.
 
TBool Validate () const
 Checks that this object is in a valid state.
 

Protected Member Functions

TBool CheckPolicy (const SSecurityInfo &aSecInfo, SSecurityInfo &aMissing) const
 

Friends

class TCompiledSecurityPolicy
 

Detailed Description

Class representing a generic security policy.

This class can specify a security policy consisting of either:

  1. A check for between 0 and 7 capabilities
  2. A check for a given Secure ID along with 0-3 capabilities
  3. A check for a given Vendor ID along with 0-3 capabilities

If multiple capabilities are specified, all of them must be present for the security check to succeed ('AND' relation).

The envisaged use case for this class is to specify access rights to an object managed either by the kernel or by a server but in principle owned by a client and usable in a limited way by other clients. For example

  • Publish and Subscribe properties
  • DBMS databases

In these cases the owning client would pass one (or more) of these objects to the server to specify which security checks should be done on other clients before allowing access to the object.

To pass a TSecurityPolicy object via IPC, a client should obtain a descriptor for the object using Package() and send this. When a server receives this descriptor it should read the descriptor contents into a TSecurityPolicyBuf and then Set() should be used to create a policy object from this.

Because this class has non-default constructors, compilers will not initialise this object at compile time, instead code will be generated to construct the object at run-time. This is wasteful - and Symbian OS DLLs are not permitted to have such uninitialised data. To overcome these problems a set of macros are provided to construct a const object which behaves like a TSecurityPolicy. These are:

_LIT_SECURITY_POLICY_C1 through _LIT_SECURITY_POLICY_C7, _LIT_SECURITY_POLICY_S0 through _LIT_SECURITY_POLICY_S3 and _LIT_SECURITY_POLICY_V0 through _LIT_SECURITY_POLICY_V3.

Also, the macros _LIT_SECURITY_POLICY_PASS and _LIT_SECURITY_POLICY_FAIL are provided in order to allow easy construction of a const object which can be used as a TSecuityPolicy which always passes or always fails, respectively.

If a security policy object is needed to be embedded in another class then the TStaticSecurityPolicy structure can be used. This behaves in the same way as a TSecurityPolicy object but may be initialised at compile time.

See also
TStaticSecurityPolicy
TSecurityPolicyBuf
_LIT_SECURITY_POLICY_PASS
_LIT_SECURITY_POLICY_FAIL
_LIT_SECURITY_POLICY_C1
_LIT_SECURITY_POLICY_C2
_LIT_SECURITY_POLICY_C3
_LIT_SECURITY_POLICY_C4
_LIT_SECURITY_POLICY_C5
_LIT_SECURITY_POLICY_C6
_LIT_SECURITY_POLICY_C7
_LIT_SECURITY_POLICY_S0
_LIT_SECURITY_POLICY_S1
_LIT_SECURITY_POLICY_S2
_LIT_SECURITY_POLICY_S3
_LIT_SECURITY_POLICY_V0
_LIT_SECURITY_POLICY_V1
_LIT_SECURITY_POLICY_V2
_LIT_SECURITY_POLICY_V3
API status
Published to all clients. Released API.

Definition at line 3829 of file e32cmn.h.

Member Enumeration Documentation

◆ TSecPolicyType

Enumerator
EAlwaysFail 
EAlwaysPass 

Definition at line 3832 of file e32cmn.h.

◆ TType

Constants to specify the type of TSecurityPolicy objects.

Enumerator
ETypeFail 

Always fail.

ETypePass 

Always pass.

ETypeC3 

Up to 3 capabilities.

ETypeC7 

Up to 7 capabilities.

ETypeS3 

Secure ID and up to 3 capabilities.

ETypeV3 

Vendor ID and up to 3 capabilities.

ETypeLimit 

The number of possible TSecurityPolicy types This is intended for internal Symbian use only.

API status
Internal technology API.

Definition at line 3913 of file e32cmn.h.

Constructor & Destructor Documentation

◆ TSecurityPolicy() [1/6]

TSecurityPolicy::TSecurityPolicy ( )
inline

Constructs a TSecurityPolicy that will always fail, irrespective of the checked object's attributes.

(generated from Symbian Developer Library)

◆ TSecurityPolicy() [2/6]

IMPORT_C TSecurityPolicy::TSecurityPolicy ( TSecPolicyType  aType)
Parameters
aTypeMust be one of EAlwaysPass or EAlwaysFail

Panic condition: USER 191 if aType is not a valid value

(generated from Symbian Developer Library)

◆ TSecurityPolicy() [3/6]

IMPORT_C TSecurityPolicy::TSecurityPolicy ( TCapability  aCap1,
TCapability  aCap2 = ECapability_None,
TCapability  aCap3 = ECapability_None 
)
Parameters
aCap1The first capability to add to this policy
aCap2An optional second capability to add to this policy
aCap3An optional third capability to add to this policy

Panic condition: USER 189 If any of the supplied capabilities are not valid.

(generated from Symbian Developer Library)

◆ TSecurityPolicy() [4/6]

IMPORT_C TSecurityPolicy::TSecurityPolicy ( TCapability  aCap1,
TCapability  aCap2,
TCapability  aCap3,
TCapability  aCap4,
TCapability  aCap5 = ECapability_None,
TCapability  aCap6 = ECapability_None,
TCapability  aCap7 = ECapability_None 
)
Parameters
aCap1The first capability to add to this policy
aCap2The second capability to add to this policy
aCap3The third capability to add to this policy
aCap4The fourth capability to add to this policy
aCap5An optional fifth capability to add to this policy
aCap6An optional sixth capability to add to this policy
aCap7An optional seventh capability to add to this policy

Panic condition: USER 189 If any of the supplied capabilities are not valid.

(generated from Symbian Developer Library)

◆ TSecurityPolicy() [5/6]

IMPORT_C TSecurityPolicy::TSecurityPolicy ( TSecureId  aSecureId,
TCapability  aCap1 = ECapability_None,
TCapability  aCap2 = ECapability_None,
TCapability  aCap3 = ECapability_None 
)
Parameters
aSecureIdThe secure id to add to this policy
aCap1The first capability to add to this policy
aCap2The second capability to add to this policy
aCap3The third capability to add to this policy

Panic condition: USER 189 If any of the supplied capabilities are not valid.

(generated from Symbian Developer Library)

◆ TSecurityPolicy() [6/6]

IMPORT_C TSecurityPolicy::TSecurityPolicy ( TVendorId  aVendorId,
TCapability  aCap1 = ECapability_None,
TCapability  aCap2 = ECapability_None,
TCapability  aCap3 = ECapability_None 
)
Parameters
aVendorIdThe vendor id to add to this policy
aCap1The first capability to add to this policy
aCap2The second capability to add to this policy
aCap3The third capability to add to this policy

Panic condition: USER 189 If any of the supplied capabilities are not valid.

(generated from Symbian Developer Library)

Member Function Documentation

◆ CheckPolicy() [1/6]

TBool TSecurityPolicy::CheckPolicy ( const SSecurityInfo &  aSecInfo,
SSecurityInfo &  aMissing 
) const
protected
Parameters
aSecInfoThe SSecurityInfo object to check against this TSecurityPolicy.
aMissingA SSecurityInfo object which this method fills with any capabilities or IDs it finds to be missing. This is designed to help generating diagnostic messages.

Panic condition: USER 190 if aSecInfo is an invalid SSecurityInfo object otherwise.

(generated from Symbian Developer Library)

◆ CheckPolicy() [2/6]

TBool TSecurityPolicy::CheckPolicy ( RMessagePtr2  aMsgPtr,
const char *  aDiagnostic = 0 
) const
inline

Checks this policy against the platform security attributes of the process which sent the given message.

When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.

Parameters
aMsgPtrThe RMessagePtr2 object to check against this TSecurityPolicy.
aDiagnosticA string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system.

Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object

(generated from Symbian Developer Library)

◆ CheckPolicy() [3/6]

TBool TSecurityPolicy::CheckPolicy ( RMessagePtr2  aMsgPtr,
TSecurityInfo &  aMissing,
const char *  aDiagnostic = 0 
) const
inline

Checks this policy against the platform security attributes of the process which sent the given message.

When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.

Parameters
aMsgPtrThe RMessagePtr2 object to check against this TSecurityPolicy.
aMissingA TSecurityInfo object which this method fills with any capabilities or IDs it finds to be missing.
aDiagnosticA string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system.

Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object

(generated from Symbian Developer Library)

◆ CheckPolicy() [4/6]

TBool TSecurityPolicy::CheckPolicy ( RProcess  aProcess,
const char *  aDiagnostic = 0 
) const
inline

Checks this policy against the platform security attributes of aProcess.

When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.

Parameters
aProcessThe RProcess object to check against this TSecurityPolicy.
aDiagnosticA string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system.

Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object

(generated from Symbian Developer Library)

◆ CheckPolicy() [5/6]

TInt TSecurityPolicy::CheckPolicy ( RSessionBase  aSession) const

Internal component API.

◆ CheckPolicy() [6/6]

TBool TSecurityPolicy::CheckPolicy ( RThread  aThread,
const char *  aDiagnostic = 0 
) const
inline

Checks this policy against the platform security attributes of the process owning aThread.

When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.

Parameters
aThreadThe thread whose owning process' platform security attributes are to be checked against this TSecurityPolicy.
aDiagnosticA string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system.

Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object

(generated from Symbian Developer Library)

◆ CheckPolicyCreator()

TBool TSecurityPolicy::CheckPolicyCreator ( const char *  aDiagnostic = 0) const
inline

Checks this policy against the platform security attributes of this process' creator.

When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.

Parameters
aDiagnosticA string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system.

Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object

(generated from Symbian Developer Library)

◆ Package()

IMPORT_C TPtrC8 TSecurityPolicy::Package ( ) const

Constructs a TPtrC8 wrapping the platform security attributes of this TSecurityPolicy.

Such a descriptor is suitable for passing across the client server boundary.

The format of the descriptor is determined by the first byte which specifies the type of this TSecurityPolicy. The first byte is one of the constants specified in the enum TSecurityPolicy::TType.

TUint8 iType; // set to ETypeC3, ETypeS3, ETypePass or ETypeFail
TUint8 iCaps[3];
TUint32 iSecureId;
TUint32 iSecureId
Definition e32cmn.h:3941
TUint8 iType; // set to ETypeV3
TUint8 iCaps[3]; // set to the values of 3 capabilities
TUint32 iVendorId; // set to the value of the vendor ID of the TSecurityPolicy
TUint32 iVendorId
Definition e32cmn.h:3942
TUint8 iType; // set to ETypeC7
TUint8 iCaps[3]; // set to the values of 3 of the objects capabilities
TUint8 iExtraCaps[4]; // set to the values of 4 of the objects capabilities
TUint8 iExtraCaps[4]
Definition e32cmn.h:3943

(generated from Symbian Developer Library)

◆ Set()

IMPORT_C TInt TSecurityPolicy::Set ( const TDesC8 &  aDes)

Sets this TSecurityPolicy to a copy of the policy described by the supplied descriptor.

Such a descriptor can be obtained from TSecurityPolicy::Package(). TSecurityPolicy::Package()

Parameters
aDesA descriptor representing the state of another TSecurityPolicy.

(generated from Symbian Developer Library)

◆ Validate()

TBool TSecurityPolicy::Validate ( ) const

Checks that this object is in a valid state.

(generated from Symbian Developer Library)

Friends And Related Symbol Documentation

◆ TCompiledSecurityPolicy

friend class TCompiledSecurityPolicy
friend

Definition at line 3945 of file e32cmn.h.

Member Data Documentation

◆ iExtraCaps

TUint8 TSecurityPolicy::iExtraCaps[4]

Definition at line 3943 of file e32cmn.h.

◆ iSecureId

TUint32 TSecurityPolicy::iSecureId

Definition at line 3941 of file e32cmn.h.

◆ iVendorId

TUint32 TSecurityPolicy::iVendorId

Definition at line 3942 of file e32cmn.h.


The documentation for this class was generated from the following files: