1 /*
2  * Copyright (c) 2021-2023 Huawei Device Co., Ltd.
3  * Licensed under the Apache License, Version 2.0 (the "License");
4  * you may not use this file except in compliance with the License.
5  * You may obtain a copy of the License at
6  *
7  *     http://www.apache.org/licenses/LICENSE-2.0
8  *
9  * Unless required by applicable law or agreed to in writing, software
10  * distributed under the License is distributed on an "AS IS" BASIS,
11  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12  * See the License for the specific language governing permissions and
13  * limitations under the License.
14  */
15 
16 #ifndef PERMISSION_POLICY_SET_H
17 #define PERMISSION_POLICY_SET_H
18 
19 #include <memory>
20 #include <string>
21 #include <vector>
22 
23 #include "access_token.h"
24 #include "callback_manager.h"
25 #include "generic_values.h"
26 #include "permission_def.h"
27 #include "permission_state_full.h"
28 #include "rwlock.h"
29 
30 namespace OHOS {
31 namespace Security {
32 namespace AccessToken {
33 struct PermissionPolicySet final {
34 public:
PermissionPolicySetfinal35     PermissionPolicySet() : tokenId_(0) {}
36     virtual ~PermissionPolicySet();
37 
38     static std::shared_ptr<PermissionPolicySet> BuildPermissionPolicySet(AccessTokenID tokenId,
39         const std::vector<PermissionStateFull>& permStateList);
40     static std::shared_ptr<PermissionPolicySet> BuildPolicySetWithoutDefCheck(AccessTokenID tokenId,
41         const std::vector<PermissionStateFull>& permStateList);
42     static std::shared_ptr<PermissionPolicySet> RestorePermissionPolicy(AccessTokenID tokenId,
43         const std::vector<GenericValues>& permStateRes);
44     void StorePermissionPolicySet(std::vector<GenericValues>& permStateValueList);
45     void Update(const std::vector<PermissionStateFull>& permStateList);
46 
47     PermUsedTypeEnum GetUserGrantedPermissionUsedType(const std::string& permissionName);
48     int VerifyPermissionStatus(const std::string& permissionName);
49     void GetDefPermissions(std::vector<PermissionDef>& permList);
50     void GetPermissionStateFulls(std::vector<PermissionStateFull>& permList);
51     bool IsPermissionGrantedWithSecComp(const std::string& permissionName);
52     int QueryPermissionFlag(const std::string& permissionName, int& flag);
53     int32_t UpdatePermissionStatus(const std::string& permissionName, bool isGranted, uint32_t flag);
54     void ToString(std::string& info);
55     bool IsPermissionReqValid(int32_t tokenApl, const std::string& permissionName,
56         const std::vector<std::string>& nativeAcls);
57     void PermStateToString(int32_t tokenApl, const std::vector<std::string>& nativeAcls, std::string& info);
58     void GetPermissionStateList(std::vector<PermissionStateFull>& stateList);
59     void ResetUserGrantPermissionStatus(void);
60     void ClearSecCompGrantedPerm(void);
61     static uint32_t GetFlagWithoutSpecifiedElement(uint32_t fullFlag, uint32_t removedFlag);
62     static uint32_t GetFlagWroteToDb(uint32_t grantFlag);
63     void GetDeletedPermissionListToNotify(std::vector<std::string>& permissionList);
64     void GetGrantedPermissionList(std::vector<std::string>& permissionList);
65 
66     void GetPermissionStateList(std::vector<uint32_t>& opCodeList, std::vector<bool>& statusList);
67     uint32_t GetReqPermissionSize();
68 private:
69     static void MergePermissionStateFull(std::vector<PermissionStateFull>& permStateList,
70         PermissionStateFull& state);
71     void UpdatePermStateFull(const PermissionStateFull& permOld, PermissionStateFull& permNew);
72     void StorePermissionDef(std::vector<GenericValues>& valueList) const;
73     void StorePermissionState(std::vector<GenericValues>& valueList) const;
74     void PermDefToString(const PermissionDef& def, std::string& info) const;
75     void PermStateFullToString(const PermissionStateFull& state, std::string& info) const;
76     int32_t UpdateSecCompGrantedPermList(const std::string& permissionName, bool isGranted);
77     int32_t UpdatePermStateList(const std::string& permissionName, bool isGranted, uint32_t flag);
78     void SetPermissionFlag(const std::string& permissionName, uint32_t flag, bool needToAdd);
79     void SecCompGrantedPermListUpdated(const std::string& permissionName, bool isToGrant);
80     OHOS::Utils::RWLock permPolicySetLock_;
81     std::vector<PermissionStateFull> permStateList_;
82     std::vector<std::string> secCompGrantedPermList_;
83     AccessTokenID tokenId_;
84 };
85 }  // namespace AccessToken
86 }  // namespace Security
87 }  // namespace OHOS
88 #endif  // PERMISSION_POLICY_SET_H
89 
90