Defines | |
#define | DBUS_AUTH_IN_END_STATE(auth) ((auth)->state->handler == NULL) |
Functions | |
DBusAuth * | _dbus_auth_server_new (void) |
Creates a new auth conversation object for the server side. | |
DBusAuth * | _dbus_auth_client_new (void) |
Creates a new auth conversation object for the client side. | |
DBusAuth * | _dbus_auth_ref (DBusAuth *auth) |
Increments the refcount of an auth object. | |
void | _dbus_auth_unref (DBusAuth *auth) |
Decrements the refcount of an auth object. | |
dbus_bool_t | _dbus_auth_set_mechanisms (DBusAuth *auth, const char **mechanisms) |
Sets an array of authentication mechanism names that we are willing to use. | |
DBusAuthState | _dbus_auth_do_work (DBusAuth *auth) |
Analyzes buffered input and moves the auth conversation forward, returning the new state of the auth conversation. | |
dbus_bool_t | _dbus_auth_get_bytes_to_send (DBusAuth *auth, const DBusString **str) |
Gets bytes that need to be sent to the peer we're conversing with. | |
void | _dbus_auth_bytes_sent (DBusAuth *auth, int bytes_sent) |
Notifies the auth conversation object that the given number of bytes of the outgoing buffer have been written out. | |
void | _dbus_auth_get_buffer (DBusAuth *auth, DBusString **buffer) |
Get a buffer to be used for reading bytes from the peer we're conversing with. | |
void | _dbus_auth_return_buffer (DBusAuth *auth, DBusString *buffer, int bytes_read) |
Returns a buffer with new data read into it. | |
void | _dbus_auth_get_unused_bytes (DBusAuth *auth, const DBusString **str) |
Returns leftover bytes that were not used as part of the auth conversation. | |
void | _dbus_auth_delete_unused_bytes (DBusAuth *auth) |
Gets rid of unused bytes returned by _dbus_auth_get_unused_bytes() after we've gotten them and successfully moved them elsewhere. | |
dbus_bool_t | _dbus_auth_needs_encoding (DBusAuth *auth) |
Called post-authentication, indicates whether we need to encode the message stream with _dbus_auth_encode_data() prior to sending it to the peer. | |
dbus_bool_t | _dbus_auth_encode_data (DBusAuth *auth, const DBusString *plaintext, DBusString *encoded) |
Called post-authentication, encodes a block of bytes for sending to the peer. | |
dbus_bool_t | _dbus_auth_needs_decoding (DBusAuth *auth) |
Called post-authentication, indicates whether we need to decode the message stream with _dbus_auth_decode_data() after receiving it from the peer. | |
dbus_bool_t | _dbus_auth_decode_data (DBusAuth *auth, const DBusString *encoded, DBusString *plaintext) |
Called post-authentication, decodes a block of bytes received from the peer. | |
void | _dbus_auth_set_credentials (DBusAuth *auth, const DBusCredentials *credentials) |
Sets credentials received via reliable means from the operating system. | |
void | _dbus_auth_get_identity (DBusAuth *auth, DBusCredentials *credentials) |
Gets the identity we authorized the client as. | |
dbus_bool_t | _dbus_auth_set_context (DBusAuth *auth, const DBusString *context) |
Sets the "authentication context" which scopes cookies with the DBUS_COOKIE_SHA1 auth mechanism for example. |
DBusAuth manages the authentication negotiation when a connection is first established, and also manage any encryption used over a connection.
DBusAuth really needs to be rewritten as an explicit state machine.
right now sometimes both ends will block waiting for input from the other end, e.g.
the cookie keyring needs to be cached globally not just per-auth (which raises threadsafety issues too)
grep FIXME in dbus-auth.c
Right now it's too hard to prove to yourself by inspection that it works.
if there's an error during DBUS_COOKIE_SHA1.
|
Definition at line 2061 of file dbus-auth.c. Referenced by _dbus_auth_delete_unused_bytes(), _dbus_auth_do_work(), and _dbus_auth_get_unused_bytes(). |
|
Notifies the auth conversation object that the given number of bytes of the outgoing buffer have been written out.
Definition at line 2140 of file dbus-auth.c. References _dbus_string_delete(), and DBUS_AUTH_NAME. |
|
Creates a new auth conversation object for the client side. See doc/dbus-sasl-profile.txt for full details on what this object does.
Definition at line 1953 of file dbus-auth.c. References _dbus_auth_unref(), side, and state. Referenced by _dbus_transport_init_base(). |
|
Called post-authentication, decodes a block of bytes received from the peer. If no encoding was negotiated, just copies the bytes (you can avoid this by checking _dbus_auth_needs_decoding()).
Definition at line 2323 of file dbus-auth.c. References _dbus_assert, _dbus_auth_needs_decoding(), _dbus_string_copy(), DBUS_AUTH_IS_CLIENT, and FALSE. |
|
Gets rid of unused bytes returned by _dbus_auth_get_unused_bytes() after we've gotten them and successfully moved them elsewhere.
Definition at line 2216 of file dbus-auth.c. References _dbus_string_set_length(), and DBUS_AUTH_IN_END_STATE. |
|
Analyzes buffered input and moves the auth conversation forward, returning the new state of the auth conversation.
Definition at line 2071 of file dbus-auth.c. References DBUS_AUTH_IN_END_STATE, DBUS_AUTH_NAME, FALSE, and needed_memory. Referenced by _dbus_transport_get_dispatch_status(), and _dbus_transport_get_is_authenticated(). |
|
Called post-authentication, encodes a block of bytes for sending to the peer. If no encoding was negotiated, just copies the bytes (you can avoid this by checking _dbus_auth_needs_encoding()).
Definition at line 2260 of file dbus-auth.c. References _dbus_assert, _dbus_auth_needs_encoding(), _dbus_string_copy(), DBUS_AUTH_IS_CLIENT, and FALSE. |
|
Get a buffer to be used for reading bytes from the peer we're conversing with. Bytes should be appended to this buffer.
Definition at line 2160 of file dbus-auth.c. References _dbus_assert, buffer_outstanding, incoming, and TRUE. |
|
Gets bytes that need to be sent to the peer we're conversing with. After writing some bytes, _dbus_auth_bytes_sent() must be called to notify the auth object that they were written.
Definition at line 2115 of file dbus-auth.c. References _dbus_assert, FALSE, and TRUE. |
|
Gets the identity we authorized the client as. Apps may have different policies as to what identities they allow.
Definition at line 2368 of file dbus-auth.c. References _dbus_credentials_clear(), authorized_identity, and state. Referenced by _dbus_transport_get_is_authenticated(), _dbus_transport_get_unix_process_id(), and _dbus_transport_get_unix_user(). |
|
Returns leftover bytes that were not used as part of the auth conversation. These bytes will be part of the message stream instead. This function may not be called until authentication has succeeded.
Definition at line 2199 of file dbus-auth.c. References DBUS_AUTH_IN_END_STATE. |
|
Called post-authentication, indicates whether we need to decode the message stream with _dbus_auth_decode_data() after receiving it from the peer.
Definition at line 2292 of file dbus-auth.c. References DBUS_AUTH_IS_CLIENT, FALSE, mech, and state. Referenced by _dbus_auth_decode_data(). |
|
Called post-authentication, indicates whether we need to encode the message stream with _dbus_auth_encode_data() prior to sending it to the peer.
Definition at line 2233 of file dbus-auth.c. References DBUS_AUTH_IS_CLIENT, FALSE, mech, and state. Referenced by _dbus_auth_encode_data(). |
|
Increments the refcount of an auth object.
Definition at line 1982 of file dbus-auth.c. References _dbus_assert, and refcount. |
|
Returns a buffer with new data read into it.
Definition at line 2179 of file dbus-auth.c. References _dbus_assert, buffer_outstanding, FALSE, and incoming. |
|
Creates a new auth conversation object for the server side. See doc/dbus-sasl-profile.txt for full details on what this object does.
Definition at line 1922 of file dbus-auth.c. References DBUS_AUTH_SERVER, DBusAuthServer::failures, DBusAuthServer::max_failures, side, and state. Referenced by _dbus_transport_init_base(). |
|
Sets the "authentication context" which scopes cookies with the DBUS_COOKIE_SHA1 auth mechanism for example.
Definition at line 2386 of file dbus-auth.c. References _dbus_string_replace_len(), and context. |
|
Sets credentials received via reliable means from the operating system.
Definition at line 2354 of file dbus-auth.c. References credentials. |
|
Sets an array of authentication mechanism names that we are willing to use.
Definition at line 2036 of file dbus-auth.c. References _dbus_dup_string_array(), allowed_mechs, dbus_free_string_array(), FALSE, and TRUE. Referenced by _dbus_transport_set_auth_mechanisms(). |
|
Decrements the refcount of an auth object.
Definition at line 1997 of file dbus-auth.c. References _dbus_assert, _dbus_keyring_unref(), _dbus_list_clear(), _dbus_string_free(), DBUS_AUTH_CLIENT, DBUS_AUTH_IS_CLIENT, dbus_free(), dbus_free_string_array(), and refcount. Referenced by _dbus_auth_client_new(), _dbus_transport_finalize_base(), and _dbus_transport_init_base(). |