MegaBites-AI/Windows-powershell
0308
1// Copyright (c) Microsoft Corporation.2// Licensed under the MIT License.3 4using System.Management.Automation.Host;5 6using Dbg = System.Management.Automation;7 8namespace System.Management.Automation9{10 /// <summary>11 /// This enum defines the dispatch origin of a command.12 /// </summary>13 public enum CommandOrigin14 {15 /// <summary>16 /// The command was submitted via a runspace.17 /// </summary>18 Runspace,19 20 /// <summary>21 /// The command was dispatched by the engine as a result of22 /// a dispatch request from an already running command.23 /// </summary>24 Internal25 }26 27 /// <summary>28 /// Defines the base class for an authorization manager of a Runspace.29 ///30 /// An authorization manager helps a host control and restrict the31 /// execution of commands. For each of the command types listed in32 /// the <see cref="System.Management.Automation.CommandTypes"/>33 /// enumeration, the engine requests permission from the AuthorizationManager34 /// to run the command.35 ///36 /// Extending this class requires that you override the ShouldRun method with37 /// the logic specific to your needs. The base class gives permission to run38 /// every command. The default39 /// Microsoft.PowerShell.PSAuthorizationManager40 /// provides a customized and much more complete authorization policy.41 /// </summary>42 public class AuthorizationManager43 {44 #region constructor45 46 /// <summary>47 /// Creates an instance of authorization manager using specified shellID.48 /// </summary>49 /// <param name="shellId">50 /// </param>51 public AuthorizationManager(string shellId)52 {53 ShellId = shellId;54 }55 56 #endregion constructor57 58 private readonly object _policyCheckLock = new object();59 60 #region methods to use internally61 62 /// <summary>63 /// Determine if we should run the specified file.64 /// </summary>65 /// <param name="commandInfo">Info on entity to be run.</param>66 /// <param name="origin">The dispatch origin of a command.</param>67 /// <param name="host">Allows access to the host.</param>68 /// <remarks>69 /// This method throws SecurityException in case running is not allowed.70 /// </remarks>71 /// <exception cref="System.Management.Automation.PSSecurityException">72 /// If the derived security manager threw an exception or returned73 /// false with a reason.74 /// </exception>75 internal void ShouldRunInternal(CommandInfo commandInfo,76 CommandOrigin origin,77 PSHost host)78 {79#if UNIX80 // TODO:PSL this is a workaround since the exception below81 // hides the internal issue of what's going on in terms of82 // execution policy.83 // On non-Windows platform Set/Get-ExecutionPolicy throw84 // PlatformNotSupportedException85 return;86#else87 88#if DEBUG89 // If we are debugging, let the unit tests swap the file from beneath us90 if (commandInfo.CommandType == CommandTypes.ExternalScript)91 {92 while (Environment.GetEnvironmentVariable("PSCommandDiscoveryPreDelay") != null) { System.Threading.Thread.Sleep(100); }93 }94#endif95 96 bool result = false;97 bool defaultCatch = false;98 Exception authorizationManagerException = null;99 100 try101 {102 lock (_policyCheckLock)103 {104 result = this.ShouldRun(commandInfo, origin, host, out authorizationManagerException);105 }106 107#if DEBUG108 // If we are debugging, let the unit tests swap the file from beneath us109 if (commandInfo.CommandType == CommandTypes.ExternalScript)110 {111 while (Environment.GetEnvironmentVariable("PSCommandDiscoveryPostDelay") != null) { System.Threading.Thread.Sleep(100); }112 }113#endif114 }115 catch (Exception e) // Catch-all OK. 3rd party callout116 {117 authorizationManagerException = e;118 119 defaultCatch = true;120 result = false;121 }122 123 if (!result)124 {125 if (authorizationManagerException != null)126 {127 if (authorizationManagerException is PSSecurityException)128 {129 throw authorizationManagerException;130 }131 else132 {133 string message = authorizationManagerException.Message;134 if (defaultCatch)135 {136 message = AuthorizationManagerBase.AuthorizationManagerDefaultFailureReason;137 }138 139 PSSecurityException securityException = new PSSecurityException(message, authorizationManagerException);140 throw securityException;141 }142 }143 else144 {145 throw new PSSecurityException(AuthorizationManagerBase.AuthorizationManagerDefaultFailureReason);146 }147 }148#endif149 }150 151 /// <summary>152 /// Get the shell ID from the authorization manager...153 /// </summary>154 internal string ShellId { get; }155 156 #endregion methods to use internally157 158 #region methods for derived class to override159 160 /// <summary>161 /// Determines if the host should run the command a specified by the CommandInfo parameter.162 /// The default implementation gives permission to run every command.163 /// </summary>164 /// <param name="commandInfo">Information about the command to be run.</param>165 /// <param name="origin">The origin of the command.</param>166 /// <param name="host">The host running the command.</param>167 /// <param name="reason">The reason for preventing execution, if applicable.</param>168 /// <returns>True if the host should run the command. False otherwise.</returns>169 protected internal virtual bool ShouldRun(CommandInfo commandInfo,170 CommandOrigin origin,171 PSHost host,172 out Exception reason)173 {174 Dbg.Diagnostics.Assert(commandInfo != null, "caller should validate the parameter");175 176 reason = null;177 178 return true;179 }180 181 #endregion methods for derived class to override182 }183}184 