Team Ai
Datasetpublic

MegaBites-AI/Windows-powershell

sourceHugging Facemitupdated 6mo agoView on Hugging Face
0likes308downloads
SecurityManagerBase.cs184 linesDownload Raw Back to engine
1// Copyright (c) Microsoft Corporation.2// Licensed under the MIT License.3 4using System.Management.Automation.Host;5 6using Dbg = System.Management.Automation;7 8namespace System.Management.Automation9{10    /// <summary>11    /// This enum defines the dispatch origin of a command.12    /// </summary>13    public enum CommandOrigin14    {15        /// <summary>16        /// The command was submitted via a runspace.17        /// </summary>18        Runspace,19 20        /// <summary>21        /// The command was dispatched by the engine as a result of22        /// a dispatch request from an already running command.23        /// </summary>24        Internal25    }26 27    /// <summary>28    /// Defines the base class for an authorization manager of a Runspace.29    ///30    /// An authorization manager helps a host control and restrict the31    /// execution of commands.  For each of the command types listed in32    /// the <see cref="System.Management.Automation.CommandTypes"/>33    /// enumeration, the engine requests permission from the AuthorizationManager34    /// to run the command.35    ///36    /// Extending this class requires that you override the ShouldRun method with37    /// the logic specific to your needs.  The base class gives permission to run38    /// every command.  The default39    /// Microsoft.PowerShell.PSAuthorizationManager40    /// provides a customized and much more complete authorization policy.41    /// </summary>42    public class AuthorizationManager43    {44        #region constructor45 46        /// <summary>47        /// Creates an instance of authorization manager using specified shellID.48        /// </summary>49        /// <param name="shellId">50        /// </param>51        public AuthorizationManager(string shellId)52        {53            ShellId = shellId;54        }55 56        #endregion constructor57 58        private readonly object _policyCheckLock = new object();59 60        #region methods to use internally61 62        /// <summary>63        /// Determine if we should run the specified file.64        /// </summary>65        /// <param name="commandInfo">Info on entity to be run.</param>66        /// <param name="origin">The dispatch origin of a command.</param>67        /// <param name="host">Allows access to the host.</param>68        /// <remarks>69        /// This method throws SecurityException in case running is not allowed.70        /// </remarks>71        /// <exception cref="System.Management.Automation.PSSecurityException">72        /// If the derived security manager threw an exception or returned73        /// false with a reason.74        /// </exception>75        internal void ShouldRunInternal(CommandInfo commandInfo,76                                        CommandOrigin origin,77                                        PSHost host)78        {79#if UNIX80            // TODO:PSL this is a workaround since the exception below81            // hides the internal issue of what's going on in terms of82            // execution policy.83            // On non-Windows platform Set/Get-ExecutionPolicy throw84            // PlatformNotSupportedException85            return;86#else87 88#if DEBUG89            // If we are debugging, let the unit tests swap the file from beneath us90            if (commandInfo.CommandType == CommandTypes.ExternalScript)91            {92                while (Environment.GetEnvironmentVariable("PSCommandDiscoveryPreDelay") != null) { System.Threading.Thread.Sleep(100); }93            }94#endif95 96            bool result = false;97            bool defaultCatch = false;98            Exception authorizationManagerException = null;99 100            try101            {102                lock (_policyCheckLock)103                {104                    result = this.ShouldRun(commandInfo, origin, host, out authorizationManagerException);105                }106 107#if DEBUG108                // If we are debugging, let the unit tests swap the file from beneath us109                if (commandInfo.CommandType == CommandTypes.ExternalScript)110                {111                    while (Environment.GetEnvironmentVariable("PSCommandDiscoveryPostDelay") != null) { System.Threading.Thread.Sleep(100); }112                }113#endif114            }115            catch (Exception e) // Catch-all OK. 3rd party callout116            {117                authorizationManagerException = e;118 119                defaultCatch = true;120                result = false;121            }122 123            if (!result)124            {125                if (authorizationManagerException != null)126                {127                    if (authorizationManagerException is PSSecurityException)128                    {129                        throw authorizationManagerException;130                    }131                    else132                    {133                        string message = authorizationManagerException.Message;134                        if (defaultCatch)135                        {136                            message = AuthorizationManagerBase.AuthorizationManagerDefaultFailureReason;137                        }138 139                        PSSecurityException securityException = new PSSecurityException(message, authorizationManagerException);140                        throw securityException;141                    }142                }143                else144                {145                    throw new PSSecurityException(AuthorizationManagerBase.AuthorizationManagerDefaultFailureReason);146                }147            }148#endif149        }150 151        /// <summary>152        /// Get the shell ID from the authorization manager...153        /// </summary>154        internal string ShellId { get; }155 156        #endregion methods to use internally157 158        #region methods for derived class to override159 160        /// <summary>161        /// Determines if the host should run the command a specified by the CommandInfo parameter.162        /// The default implementation gives permission to run every command.163        /// </summary>164        /// <param name="commandInfo">Information about the command to be run.</param>165        /// <param name="origin">The origin of the command.</param>166        /// <param name="host">The host running the command.</param>167        /// <param name="reason">The reason for preventing execution, if applicable.</param>168        /// <returns>True if the host should run the command.  False otherwise.</returns>169        protected internal virtual bool ShouldRun(CommandInfo commandInfo,170                                                  CommandOrigin origin,171                                                  PSHost host,172                                                  out Exception reason)173        {174            Dbg.Diagnostics.Assert(commandInfo != null, "caller should validate the parameter");175 176            reason = null;177 178            return true;179        }180 181        #endregion methods for derived class to override182    }183}184