File: restricted_mgs_policy_provider.h

package info (click to toggle)
chromium 138.0.7204.157-1
  • links: PTS, VCS
  • area: main
  • in suites: trixie
  • size: 6,071,864 kB
  • sloc: cpp: 34,936,859; ansic: 7,176,967; javascript: 4,110,704; python: 1,419,953; asm: 946,768; xml: 739,967; pascal: 187,324; sh: 89,623; perl: 88,663; objc: 79,944; sql: 50,304; cs: 41,786; fortran: 24,137; makefile: 21,806; php: 13,980; tcl: 13,166; yacc: 8,925; ruby: 7,485; awk: 3,720; lisp: 3,096; lex: 1,327; ada: 727; jsp: 228; sed: 36
file content (52 lines) | stat: -rw-r--r-- 2,048 bytes parent folder | download | duplicates (5)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
// Copyright 2022 The Chromium Authors
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.

#ifndef CHROME_BROWSER_POLICY_RESTRICTED_MGS_POLICY_PROVIDER_H_
#define CHROME_BROWSER_POLICY_RESTRICTED_MGS_POLICY_PROVIDER_H_

#include <memory>

#include "base/memory/weak_ptr.h"
#include "components/policy/core/common/configuration_policy_provider.h"

namespace policy {

// Policy provider for a restricted Managed Guest Session (MGS). The provider
// applies restrictions on a list of policies if the
// DeviceRestrictedManagedGuestSessionEnabled policy is enabled when the session
// starts. The restricted MGS is only used in the context of shared sessions. If
// shared sessions are enabled, the session will not launch without the enabled
// DeviceRestrictedManagedGuestSessionEnabled policy. We do not check for
// updates of the policy in session because if it is disabled during a running
// shared session, it will deny the unlock of the shared session.
class RestrictedMGSPolicyProvider : public ConfigurationPolicyProvider {
 public:
  RestrictedMGSPolicyProvider();

  RestrictedMGSPolicyProvider(const RestrictedMGSPolicyProvider&) = delete;
  RestrictedMGSPolicyProvider& operator=(const RestrictedMGSPolicyProvider&) =
      delete;

  ~RestrictedMGSPolicyProvider() override;

  // ConfigurationPolicyProvider:
  void RefreshPolicies(PolicyFetchReason reason) override;

  // Factory function to create and initialize a provider. Returns nullptr if we
  // are not in a Managed Guest Session.
  static std::unique_ptr<RestrictedMGSPolicyProvider> Create();

 private:
  // Gets the current PolicyBundle and applies restrictions in case the
  // DeviceRestrictedManagedGuestSessionEnabled policy is enabled.
  void UpdatePolicyBundle();

  void ApplyRestrictedManagedGuestSessionOverride(PolicyMap* chrome_policy);

  base::WeakPtrFactory<RestrictedMGSPolicyProvider> weak_factory_{this};
};

}  // namespace policy

#endif  // CHROME_BROWSER_POLICY_RESTRICTED_MGS_POLICY_PROVIDER_H_