1 /* GDBus - GLib D-Bus Library
3 * Copyright (C) 2008-2010 Red Hat, Inc.
5 * This library is free software; you can redistribute it and/or
6 * modify it under the terms of the GNU Lesser General Public
7 * License as published by the Free Software Foundation; either
8 * version 2 of the License, or (at your option) any later version.
10 * This library is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 * Lesser General Public License for more details.
15 * You should have received a copy of the GNU Lesser General
16 * Public License along with this library; if not, write to the
17 * Free Software Foundation, Inc., 59 Temple Place, Suite 330,
18 * Boston, MA 02111-1307, USA.
20 * Author: David Zeuthen <davidz@redhat.com>
26 #include <sys/types.h>
31 #include "gdbusauthmechanismexternal.h"
32 #include "gcredentials.h"
33 #include "gdbuserror.h"
34 #include "gioenumtypes.h"
38 struct _GDBusAuthMechanismExternalPrivate
42 GDBusAuthMechanismState state;
45 static gint mechanism_get_priority (void);
46 static const gchar *mechanism_get_name (void);
48 static gboolean mechanism_is_supported (GDBusAuthMechanism *mechanism);
49 static gchar *mechanism_encode_data (GDBusAuthMechanism *mechanism,
53 static gchar *mechanism_decode_data (GDBusAuthMechanism *mechanism,
57 static GDBusAuthMechanismState mechanism_server_get_state (GDBusAuthMechanism *mechanism);
58 static void mechanism_server_initiate (GDBusAuthMechanism *mechanism,
59 const gchar *initial_response,
60 gsize initial_response_len);
61 static void mechanism_server_data_receive (GDBusAuthMechanism *mechanism,
64 static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism,
66 static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism);
67 static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism);
68 static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism);
69 static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism,
70 gsize *out_initial_response_len);
71 static void mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
74 static gchar *mechanism_client_data_send (GDBusAuthMechanism *mechanism,
76 static void mechanism_client_shutdown (GDBusAuthMechanism *mechanism);
78 /* ---------------------------------------------------------------------------------------------------- */
80 G_DEFINE_TYPE_WITH_PRIVATE (GDBusAuthMechanismExternal, _g_dbus_auth_mechanism_external, G_TYPE_DBUS_AUTH_MECHANISM)
82 /* ---------------------------------------------------------------------------------------------------- */
85 _g_dbus_auth_mechanism_external_finalize (GObject *object)
87 //GDBusAuthMechanismExternal *mechanism = G_DBUS_AUTH_MECHANISM_EXTERNAL (object);
89 if (G_OBJECT_CLASS (_g_dbus_auth_mechanism_external_parent_class)->finalize != NULL)
90 G_OBJECT_CLASS (_g_dbus_auth_mechanism_external_parent_class)->finalize (object);
94 _g_dbus_auth_mechanism_external_class_init (GDBusAuthMechanismExternalClass *klass)
96 GObjectClass *gobject_class;
97 GDBusAuthMechanismClass *mechanism_class;
99 gobject_class = G_OBJECT_CLASS (klass);
100 gobject_class->finalize = _g_dbus_auth_mechanism_external_finalize;
102 mechanism_class = G_DBUS_AUTH_MECHANISM_CLASS (klass);
103 mechanism_class->get_name = mechanism_get_name;
104 mechanism_class->get_priority = mechanism_get_priority;
105 mechanism_class->is_supported = mechanism_is_supported;
106 mechanism_class->encode_data = mechanism_encode_data;
107 mechanism_class->decode_data = mechanism_decode_data;
108 mechanism_class->server_get_state = mechanism_server_get_state;
109 mechanism_class->server_initiate = mechanism_server_initiate;
110 mechanism_class->server_data_receive = mechanism_server_data_receive;
111 mechanism_class->server_data_send = mechanism_server_data_send;
112 mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason;
113 mechanism_class->server_shutdown = mechanism_server_shutdown;
114 mechanism_class->client_get_state = mechanism_client_get_state;
115 mechanism_class->client_initiate = mechanism_client_initiate;
116 mechanism_class->client_data_receive = mechanism_client_data_receive;
117 mechanism_class->client_data_send = mechanism_client_data_send;
118 mechanism_class->client_shutdown = mechanism_client_shutdown;
122 _g_dbus_auth_mechanism_external_init (GDBusAuthMechanismExternal *mechanism)
124 mechanism->priv = _g_dbus_auth_mechanism_external_get_instance_private (mechanism);
127 /* ---------------------------------------------------------------------------------------------------- */
130 mechanism_is_supported (GDBusAuthMechanism *mechanism)
132 g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), FALSE);
133 /* This mechanism is only available if credentials has been exchanged */
134 if (_g_dbus_auth_mechanism_get_credentials (mechanism) != NULL)
141 mechanism_get_priority (void)
143 /* We prefer EXTERNAL to most other mechanism (DBUS_COOKIE_SHA1 and ANONYMOUS) */
148 mechanism_get_name (void)
154 mechanism_encode_data (GDBusAuthMechanism *mechanism,
164 mechanism_decode_data (GDBusAuthMechanism *mechanism,
172 /* ---------------------------------------------------------------------------------------------------- */
174 static GDBusAuthMechanismState
175 mechanism_server_get_state (GDBusAuthMechanism *mechanism)
177 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
179 g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), G_DBUS_AUTH_MECHANISM_STATE_INVALID);
180 g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, G_DBUS_AUTH_MECHANISM_STATE_INVALID);
182 return m->priv->state;
186 data_matches_credentials (const gchar *data,
187 GCredentials *credentials)
193 if (credentials == NULL)
196 if (data == NULL || strlen (data) == 0)
199 #if defined(G_OS_UNIX)
204 /* on UNIX, this is the uid as a string in base 10 */
205 alleged_uid = g_ascii_strtoll (data, &endp, 10);
208 if (g_credentials_get_unix_user (credentials, NULL) == alleged_uid)
215 /* TODO: Dont know how to compare credentials on this OS. Please implement. */
223 mechanism_server_initiate (GDBusAuthMechanism *mechanism,
224 const gchar *initial_response,
225 gsize initial_response_len)
227 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
229 g_return_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism));
230 g_return_if_fail (!m->priv->is_server && !m->priv->is_client);
232 m->priv->is_server = TRUE;
234 if (initial_response != NULL)
236 if (data_matches_credentials (initial_response, _g_dbus_auth_mechanism_get_credentials (mechanism)))
238 m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_ACCEPTED;
242 m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED;
247 m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_WAITING_FOR_DATA;
252 mechanism_server_data_receive (GDBusAuthMechanism *mechanism,
256 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
258 g_return_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism));
259 g_return_if_fail (m->priv->is_server && !m->priv->is_client);
260 g_return_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_WAITING_FOR_DATA);
262 if (data_matches_credentials (data, _g_dbus_auth_mechanism_get_credentials (mechanism)))
264 m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_ACCEPTED;
268 m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED;
273 mechanism_server_data_send (GDBusAuthMechanism *mechanism,
276 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
278 g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), NULL);
279 g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
280 g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_HAVE_DATA_TO_SEND, NULL);
282 /* can never end up here because we are never in the HAVE_DATA_TO_SEND state */
283 g_assert_not_reached ();
289 mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism)
291 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
293 g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), NULL);
294 g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
295 g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
297 /* can never end up here because we are never in the REJECTED state */
298 g_assert_not_reached ();
304 mechanism_server_shutdown (GDBusAuthMechanism *mechanism)
306 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
308 g_return_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism));
309 g_return_if_fail (m->priv->is_server && !m->priv->is_client);
311 m->priv->is_server = FALSE;
314 /* ---------------------------------------------------------------------------------------------------- */
316 static GDBusAuthMechanismState
317 mechanism_client_get_state (GDBusAuthMechanism *mechanism)
319 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
321 g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), G_DBUS_AUTH_MECHANISM_STATE_INVALID);
322 g_return_val_if_fail (m->priv->is_client && !m->priv->is_server, G_DBUS_AUTH_MECHANISM_STATE_INVALID);
324 return m->priv->state;
328 mechanism_client_initiate (GDBusAuthMechanism *mechanism,
329 gsize *out_initial_response_len)
331 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
332 gchar *initial_response;
333 GCredentials *credentials;
335 g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), NULL);
336 g_return_val_if_fail (!m->priv->is_server && !m->priv->is_client, NULL);
338 m->priv->is_client = TRUE;
339 m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_ACCEPTED;
341 *out_initial_response_len = -1;
343 credentials = _g_dbus_auth_mechanism_get_credentials (mechanism);
344 g_assert (credentials != NULL);
347 #if defined(G_OS_UNIX)
348 initial_response = g_strdup_printf ("%" G_GINT64_FORMAT, (gint64) g_credentials_get_unix_user (credentials, NULL));
349 #elif defined(G_OS_WIN32)
351 #warning Dont know how to send credentials on this OS. The EXTERNAL D-Bus authentication mechanism will not work.
353 m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED;
355 return initial_response;
359 mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
363 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
365 g_return_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism));
366 g_return_if_fail (m->priv->is_client && !m->priv->is_server);
367 g_return_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_WAITING_FOR_DATA);
369 /* can never end up here because we are never in the WAITING_FOR_DATA state */
370 g_assert_not_reached ();
374 mechanism_client_data_send (GDBusAuthMechanism *mechanism,
377 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
379 g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), NULL);
380 g_return_val_if_fail (m->priv->is_client && !m->priv->is_server, NULL);
381 g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_HAVE_DATA_TO_SEND, NULL);
383 /* can never end up here because we are never in the HAVE_DATA_TO_SEND state */
384 g_assert_not_reached ();
390 mechanism_client_shutdown (GDBusAuthMechanism *mechanism)
392 GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
394 g_return_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism));
395 g_return_if_fail (m->priv->is_client && !m->priv->is_server);
397 m->priv->is_client = FALSE;
400 /* ---------------------------------------------------------------------------------------------------- */