|
Original Symbian headers
Selected EUSER, Window Server, networking, graphics and device declarations
|
Class representing a generic security policy. More...
#include <e32cmn.h>
Public Types | |
| enum | TSecPolicyType { EAlwaysFail =0 , EAlwaysPass =1 } |
| enum | TType { ETypeFail =0 , ETypePass =1 , ETypeC3 =2 , ETypeC7 =3 , ETypeS3 =4 , ETypeV3 =5 , ETypeLimit } |
| Constants to specify the type of TSecurityPolicy objects. More... | |
Public Member Functions | |
| TSecurityPolicy () | |
| Constructs a TSecurityPolicy that will always fail, irrespective of the checked object's attributes. | |
| IMPORT_C | TSecurityPolicy (TSecPolicyType aType) |
| IMPORT_C | TSecurityPolicy (TCapability aCap1, TCapability aCap2=ECapability_None, TCapability aCap3=ECapability_None) |
| IMPORT_C | TSecurityPolicy (TCapability aCap1, TCapability aCap2, TCapability aCap3, TCapability aCap4, TCapability aCap5=ECapability_None, TCapability aCap6=ECapability_None, TCapability aCap7=ECapability_None) |
| IMPORT_C | TSecurityPolicy (TSecureId aSecureId, TCapability aCap1=ECapability_None, TCapability aCap2=ECapability_None, TCapability aCap3=ECapability_None) |
| IMPORT_C | TSecurityPolicy (TVendorId aVendorId, TCapability aCap1=ECapability_None, TCapability aCap2=ECapability_None, TCapability aCap3=ECapability_None) |
| IMPORT_C TInt | Set (const TDesC8 &aDes) |
| Sets this TSecurityPolicy to a copy of the policy described by the supplied descriptor. | |
| IMPORT_C TPtrC8 | Package () const |
| Constructs a TPtrC8 wrapping the platform security attributes of this TSecurityPolicy. | |
| TBool | CheckPolicy (RProcess aProcess, const char *aDiagnostic=0) const |
| Checks this policy against the platform security attributes of aProcess. | |
| TBool | CheckPolicy (RThread aThread, const char *aDiagnostic=0) const |
| Checks this policy against the platform security attributes of the process owning aThread. | |
| TBool | CheckPolicy (RMessagePtr2 aMsgPtr, const char *aDiagnostic=0) const |
| Checks this policy against the platform security attributes of the process which sent the given message. | |
| TBool | CheckPolicy (RMessagePtr2 aMsgPtr, TSecurityInfo &aMissing, const char *aDiagnostic=0) const |
| Checks this policy against the platform security attributes of the process which sent the given message. | |
| TBool | CheckPolicyCreator (const char *aDiagnostic=0) const |
| Checks this policy against the platform security attributes of this process' creator. | |
| TInt | CheckPolicy (RSessionBase aSession) const |
| Internal component API. | |
| TBool | Validate () const |
| Checks that this object is in a valid state. | |
Protected Member Functions | |
| TBool | CheckPolicy (const SSecurityInfo &aSecInfo, SSecurityInfo &aMissing) const |
Friends | |
| class | TCompiledSecurityPolicy |
Class representing a generic security policy.
This class can specify a security policy consisting of either:
If multiple capabilities are specified, all of them must be present for the security check to succeed ('AND' relation).
The envisaged use case for this class is to specify access rights to an object managed either by the kernel or by a server but in principle owned by a client and usable in a limited way by other clients. For example
In these cases the owning client would pass one (or more) of these objects to the server to specify which security checks should be done on other clients before allowing access to the object.
To pass a TSecurityPolicy object via IPC, a client should obtain a descriptor for the object using Package() and send this. When a server receives this descriptor it should read the descriptor contents into a TSecurityPolicyBuf and then Set() should be used to create a policy object from this.
Because this class has non-default constructors, compilers will not initialise this object at compile time, instead code will be generated to construct the object at run-time. This is wasteful - and Symbian OS DLLs are not permitted to have such uninitialised data. To overcome these problems a set of macros are provided to construct a const object which behaves like a TSecurityPolicy. These are:
_LIT_SECURITY_POLICY_C1 through _LIT_SECURITY_POLICY_C7, _LIT_SECURITY_POLICY_S0 through _LIT_SECURITY_POLICY_S3 and _LIT_SECURITY_POLICY_V0 through _LIT_SECURITY_POLICY_V3.
Also, the macros _LIT_SECURITY_POLICY_PASS and _LIT_SECURITY_POLICY_FAIL are provided in order to allow easy construction of a const object which can be used as a TSecuityPolicy which always passes or always fails, respectively.
If a security policy object is needed to be embedded in another class then the TStaticSecurityPolicy structure can be used. This behaves in the same way as a TSecurityPolicy object but may be initialised at compile time.
Constants to specify the type of TSecurityPolicy objects.
| Enumerator | |
|---|---|
| ETypeFail | Always fail. |
| ETypePass | Always pass. |
| ETypeC3 | Up to 3 capabilities. |
| ETypeC7 | Up to 7 capabilities. |
| ETypeS3 | Secure ID and up to 3 capabilities. |
| ETypeV3 | Vendor ID and up to 3 capabilities. |
| ETypeLimit | The number of possible TSecurityPolicy types This is intended for internal Symbian use only.
|
|
inline |
Constructs a TSecurityPolicy that will always fail, irrespective of the checked object's attributes.
(generated from Symbian Developer Library)
| IMPORT_C TSecurityPolicy::TSecurityPolicy | ( | TSecPolicyType | aType | ) |
| aType | Must be one of EAlwaysPass or EAlwaysFail |
Panic condition: USER 191 if aType is not a valid value
(generated from Symbian Developer Library)
| IMPORT_C TSecurityPolicy::TSecurityPolicy | ( | TCapability | aCap1, |
| TCapability | aCap2 = ECapability_None, |
||
| TCapability | aCap3 = ECapability_None |
||
| ) |
| aCap1 | The first capability to add to this policy |
| aCap2 | An optional second capability to add to this policy |
| aCap3 | An optional third capability to add to this policy |
Panic condition: USER 189 If any of the supplied capabilities are not valid.
(generated from Symbian Developer Library)
| IMPORT_C TSecurityPolicy::TSecurityPolicy | ( | TCapability | aCap1, |
| TCapability | aCap2, | ||
| TCapability | aCap3, | ||
| TCapability | aCap4, | ||
| TCapability | aCap5 = ECapability_None, |
||
| TCapability | aCap6 = ECapability_None, |
||
| TCapability | aCap7 = ECapability_None |
||
| ) |
| aCap1 | The first capability to add to this policy |
| aCap2 | The second capability to add to this policy |
| aCap3 | The third capability to add to this policy |
| aCap4 | The fourth capability to add to this policy |
| aCap5 | An optional fifth capability to add to this policy |
| aCap6 | An optional sixth capability to add to this policy |
| aCap7 | An optional seventh capability to add to this policy |
Panic condition: USER 189 If any of the supplied capabilities are not valid.
(generated from Symbian Developer Library)
| IMPORT_C TSecurityPolicy::TSecurityPolicy | ( | TSecureId | aSecureId, |
| TCapability | aCap1 = ECapability_None, |
||
| TCapability | aCap2 = ECapability_None, |
||
| TCapability | aCap3 = ECapability_None |
||
| ) |
| aSecureId | The secure id to add to this policy |
| aCap1 | The first capability to add to this policy |
| aCap2 | The second capability to add to this policy |
| aCap3 | The third capability to add to this policy |
Panic condition: USER 189 If any of the supplied capabilities are not valid.
(generated from Symbian Developer Library)
| IMPORT_C TSecurityPolicy::TSecurityPolicy | ( | TVendorId | aVendorId, |
| TCapability | aCap1 = ECapability_None, |
||
| TCapability | aCap2 = ECapability_None, |
||
| TCapability | aCap3 = ECapability_None |
||
| ) |
| aVendorId | The vendor id to add to this policy |
| aCap1 | The first capability to add to this policy |
| aCap2 | The second capability to add to this policy |
| aCap3 | The third capability to add to this policy |
Panic condition: USER 189 If any of the supplied capabilities are not valid.
(generated from Symbian Developer Library)
|
protected |
| aSecInfo | The SSecurityInfo object to check against this TSecurityPolicy. |
| aMissing | A SSecurityInfo object which this method fills with any capabilities or IDs it finds to be missing. This is designed to help generating diagnostic messages. |
Panic condition: USER 190 if aSecInfo is an invalid SSecurityInfo object otherwise.
(generated from Symbian Developer Library)
|
inline |
Checks this policy against the platform security attributes of the process which sent the given message.
When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.
| aMsgPtr | The RMessagePtr2 object to check against this TSecurityPolicy. |
| aDiagnostic | A string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system. |
Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object
(generated from Symbian Developer Library)
|
inline |
Checks this policy against the platform security attributes of the process which sent the given message.
When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.
| aMsgPtr | The RMessagePtr2 object to check against this TSecurityPolicy. |
| aMissing | A TSecurityInfo object which this method fills with any capabilities or IDs it finds to be missing. |
| aDiagnostic | A string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system. |
Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object
(generated from Symbian Developer Library)
|
inline |
Checks this policy against the platform security attributes of aProcess.
When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.
| aProcess | The RProcess object to check against this TSecurityPolicy. |
| aDiagnostic | A string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system. |
Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object
(generated from Symbian Developer Library)
| TInt TSecurityPolicy::CheckPolicy | ( | RSessionBase | aSession | ) | const |
Internal component API.
|
inline |
Checks this policy against the platform security attributes of the process owning aThread.
When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.
| aThread | The thread whose owning process' platform security attributes are to be checked against this TSecurityPolicy. |
| aDiagnostic | A string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system. |
Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object
(generated from Symbian Developer Library)
|
inline |
Checks this policy against the platform security attributes of this process' creator.
When a check fails the action taken is determined by the system wide Platform Security configuration. If PlatSecDiagnostics is ON, then a diagnostic message is emitted. If PlatSecEnforcement is OFF, then this function will return ETrue even though the check failed.
| aDiagnostic | A string that will be emitted along with any diagnostic message that may be issued if the policy check fails. This string must be enclosed in the __PLATSEC_DIAGNOSTIC_STRING macro which enables it to be easily removed from the system. |
Panic condition: USER 190 if 'this' is an invalid SSecurityInfo object
(generated from Symbian Developer Library)
| IMPORT_C TPtrC8 TSecurityPolicy::Package | ( | ) | const |
Constructs a TPtrC8 wrapping the platform security attributes of this TSecurityPolicy.
Such a descriptor is suitable for passing across the client server boundary.
The format of the descriptor is determined by the first byte which specifies the type of this TSecurityPolicy. The first byte is one of the constants specified in the enum TSecurityPolicy::TType.
(generated from Symbian Developer Library)
| IMPORT_C TInt TSecurityPolicy::Set | ( | const TDesC8 & | aDes | ) |
Sets this TSecurityPolicy to a copy of the policy described by the supplied descriptor.
Such a descriptor can be obtained from TSecurityPolicy::Package(). TSecurityPolicy::Package()
| aDes | A descriptor representing the state of another TSecurityPolicy. |
(generated from Symbian Developer Library)
| TBool TSecurityPolicy::Validate | ( | ) | const |
Checks that this object is in a valid state.
(generated from Symbian Developer Library)