1 /*
2 * Copyright (c) 2024 Huawei Device Co., Ltd.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at
6 *
7 * http://www.apache.org/licenses/LICENSE-2.0
8 *
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
14 */
15
16 #include "set_permission_managed_state_plugin.h"
17
18 #include "permission_managed_state_serializer.h"
19 #include "permission_managed_state_info.h"
20
21 #include "accesstoken_kit.h"
22 #include "access_token_error.h"
23
24 #include "edm_access_token_manager_impl.h"
25 #include "edm_ipc_interface_code.h"
26 #include "iplugin_manager.h"
27 #include "ipolicy_manager.h"
28
29 namespace OHOS {
30 namespace EDM {
31 const bool REGISTER_RESULT = IPluginManager::GetInstance()->AddPlugin(SetPermissionManagedStatePlugin::GetPlugin());
32
InitPlugin(std::shared_ptr<IPluginTemplate<SetPermissionManagedStatePlugin,std::map<std::string,PermissionManagedStateInfo>>> ptr)33 void SetPermissionManagedStatePlugin::InitPlugin(
34 std::shared_ptr<IPluginTemplate<SetPermissionManagedStatePlugin,
35 std::map<std::string, PermissionManagedStateInfo>>> ptr)
36 {
37 EDMLOGI("SetPermissionManagedStatePlugin InitPlugin...");
38 ptr->InitAttribute(
39 EdmInterfaceCode::PERMISSION_MANAGED_STATE,
40 PolicyName::POLICY_PERMISSION_MANAGED_STATE_POLICY,
41 EdmPermission::PERMISSION_ENTERPRISE_MANAGE_USER_GRANT_PERMISSION,
42 IPlugin::PermissionType::SUPER_DEVICE_ADMIN, true);
43 ptr->SetSerializer(PermissionManagedStateSerializer::GetInstance());
44 ptr->SetOnHandlePolicyListener(&SetPermissionManagedStatePlugin::OnSetPolicy, FuncOperateType::SET);
45 ptr->SetOnAdminRemoveListener(&SetPermissionManagedStatePlugin::OnAdminRemove);
46 }
47
OnSetPolicy(std::map<std::string,PermissionManagedStateInfo> & data,std::map<std::string,PermissionManagedStateInfo> & currentData,std::map<std::string,PermissionManagedStateInfo> & mergeData,int32_t userId)48 ErrCode SetPermissionManagedStatePlugin::OnSetPolicy(
49 std::map<std::string, PermissionManagedStateInfo> &data,
50 std::map<std::string, PermissionManagedStateInfo> ¤tData,
51 std::map<std::string, PermissionManagedStateInfo> &mergeData,
52 int32_t userId)
53 {
54 if (data.empty()) {
55 EDMLOGE("SetPermissionManagedStatePlugin data is empty.");
56 return EdmReturnErrCode::PARAMETER_VERIFICATION_FAILED;
57 }
58 std::map<std::string, PermissionManagedStateInfo> newDataHandle = data;
59 std::map<std::string, PermissionManagedStateInfo> currentDataHandle = currentData;
60 std::map<std::string, PermissionManagedStateInfo> mergeDataHandle = mergeData;
61 for (const auto& pair : newDataHandle) {
62 if (mergeDataHandle.find(pair.first) != mergeDataHandle.end()) {
63 return EdmReturnErrCode::CONFIGURATION_CONFLICT_FAILED;
64 }
65 if (pair.second.managedState != static_cast<int32_t>(ManagedState::DEFAULT)) {
66 mergeDataHandle.insert({pair.first, pair.second});
67 }
68 }
69 PermissionManagedStateInfo info;
70 int32_t permissionFlagParam = 0;
71 for (const auto& pair : newDataHandle) {
72 info = pair.second;
73 if (currentDataHandle.find(pair.first) != currentDataHandle.end()) {
74 if (pair.second.managedState == static_cast<int32_t>(ManagedState::DEFAULT)) {
75 currentDataHandle.erase(pair.first);
76 } else {
77 currentDataHandle[pair.first] = pair.second;
78 }
79 } else if (pair.second.managedState != static_cast<int32_t>(ManagedState::DEFAULT)) {
80 currentDataHandle.insert({pair.first, pair.second});
81 }
82 }
83 if (info.managedState == static_cast<int32_t>(ManagedState::DEFAULT)) {
84 permissionFlagParam = static_cast<int32_t>(PermissionFlag::PERMISSION_ADMIN_POLICYS_CANCEL);
85 info.managedState = static_cast<int32_t>(ManagedState::DENIED);
86 } else {
87 permissionFlagParam = static_cast<int32_t>(PermissionFlag::PERMISSION_FIXED_BY_ADMIN_POLICY);
88 }
89 ErrCode rel = Security::AccessToken::AccessTokenKit::SetPermissionStatusWithPolicy(info.tokenId,
90 info.permissionNames, info.managedState, permissionFlagParam);
91 if (rel != ERR_OK) {
92 EDMLOGE("SetPermissionManagedStatePlugin OnSetPolicy SetPermissionStatusWithPolicy failed.");
93 if (rel == Security::AccessToken::AccessTokenError::ERR_PARAM_INVALID) {
94 return EdmReturnErrCode::PARAMETER_VERIFICATION_FAILED;
95 }
96 return EdmReturnErrCode::SYSTEM_ABNORMALLY;
97 }
98 currentData = currentDataHandle;
99 mergeData = mergeDataHandle;
100 return ERR_OK;
101 }
102
OnAdminRemove(const std::string & adminName,std::map<std::string,PermissionManagedStateInfo> & data,std::map<std::string,PermissionManagedStateInfo> & mergeData,int32_t userId)103 ErrCode SetPermissionManagedStatePlugin::OnAdminRemove(
104 const std::string &adminName,
105 std::map<std::string, PermissionManagedStateInfo> &data,
106 std::map<std::string, PermissionManagedStateInfo> &mergeData,
107 int32_t userId)
108 {
109 std::map<std::string, PermissionManagedStateInfo> currentDataHandle = data;
110 std::map<std::string, PermissionManagedStateInfo> mergeDataHandle = mergeData;
111
112 for (const auto &pair : data) {
113 PermissionManagedStateInfo info = pair.second;
114 info.managedState = static_cast<int32_t>(ManagedState::DENIED);
115 std::vector<std::string> permissionNamesParams;
116 permissionNamesParams.push_back(pair.second.permissionName);
117 ErrCode rel = Security::AccessToken::AccessTokenKit::SetPermissionStatusWithPolicy(info.tokenId,
118 permissionNamesParams, info.managedState,
119 static_cast<int32_t>(PermissionFlag::PERMISSION_ADMIN_POLICYS_CANCEL));
120 if (rel != ERR_OK) {
121 EDMLOGE("SetPermissionManagedStatePlugin OnAdminRemove SetPermissionStatusWithPolicy failed.");
122 return EdmReturnErrCode::SYSTEM_ABNORMALLY;
123 }
124 if (mergeDataHandle.find(pair.first) != mergeDataHandle.end()) {
125 mergeDataHandle.erase(pair.first);
126 }
127 currentDataHandle.erase(pair.first);
128 }
129
130 data = currentDataHandle;
131 mergeData = mergeDataHandle;
132 return ERR_OK;
133 }
134 } // namespace EDM
135 } // namespace OHOS