Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(392)

Unified Diff: chrome/browser/chromeos/policy/user_cloud_policy_store_chromeos.cc

Issue 2801993002: Abandon user sign in when policy is retrieved before session started (Closed)
Patch Set: Nit Created 3 years, 8 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: chrome/browser/chromeos/policy/user_cloud_policy_store_chromeos.cc
diff --git a/chrome/browser/chromeos/policy/user_cloud_policy_store_chromeos.cc b/chrome/browser/chromeos/policy/user_cloud_policy_store_chromeos.cc
index f73ec0ceb7924b4cee34ba619a98db1525294b92..60ef856fd159927798e72f3c5844deb0279fa8d3 100644
--- a/chrome/browser/chromeos/policy/user_cloud_policy_store_chromeos.cc
+++ b/chrome/browser/chromeos/policy/user_cloud_policy_store_chromeos.cc
@@ -19,9 +19,9 @@
#include "base/stl_util.h"
#include "base/strings/stringprintf.h"
#include "chrome/browser/chromeos/policy/user_policy_token_loader.h"
+#include "chrome/browser/lifetime/application_lifetime.h"
#include "chromeos/cryptohome/cryptohome_parameters.h"
#include "chromeos/dbus/cryptohome_client.h"
-#include "chromeos/dbus/session_manager_client.h"
#include "components/policy/core/common/cloud/cloud_policy_constants.h"
#include "components/policy/proto/cloud_policy.pb.h"
#include "components/policy/proto/device_management_local.pb.h"
@@ -109,15 +109,34 @@ void UserCloudPolicyStoreChromeOS::LoadImmediately() {
// However, on those paths we must load policy synchronously so that the
// Profile initialization never sees unmanaged prefs, which would lead to
// data loss. http://crbug.com/263061
- std::string policy_blob =
+ std::string policy_blob;
+ chromeos::SessionManagerClient::RetrievePolicyResponseType response_type =
session_manager_client_->BlockingRetrievePolicyForUser(
- cryptohome::Identification(account_id_));
- if (policy_blob.empty()) {
- // The session manager doesn't have policy, or the call failed.
+ cryptohome::Identification(account_id_), &policy_blob);
+
+ if (response_type == chromeos::SessionManagerClient::
+ RetrievePolicyResponseType::SESSION_DOES_NOT_EXIST) {
+ LOG(ERROR)
+ << "Session manager claims that session doesn't exist; signing out";
+ chrome::AttemptUserExit();
+ return;
+ }
+
+ if (response_type ==
+ chromeos::SessionManagerClient::RetrievePolicyResponseType::SUCCESS &&
+ policy_blob.empty()) {
+ // The session manager doesn't have policy.
NotifyStoreLoaded();
return;
}
+ if (response_type !=
+ chromeos::SessionManagerClient::RetrievePolicyResponseType::SUCCESS) {
Daniel Erat 2017/04/21 14:22:45 in this file and others, feel free to pull Retriev
igorcov 2017/04/24 15:06:47 Done.
+ status_ = STATUS_LOAD_ERROR;
+ NotifyStoreError();
+ return;
+ }
+
std::unique_ptr<em::PolicyFetchResponse> policy(
new em::PolicyFetchResponse());
if (!policy->ParseFromString(policy_blob)) {
@@ -214,8 +233,23 @@ void UserCloudPolicyStoreChromeOS::OnPolicyStored(bool success) {
}
void UserCloudPolicyStoreChromeOS::OnPolicyRetrieved(
- const std::string& policy_blob) {
- if (policy_blob.empty()) {
+ const std::string& policy_blob,
+ chromeos::SessionManagerClient::RetrievePolicyResponseType response_type) {
+ // Disallow the sign in when the Chrome OS user session has not started, which
+ // should always happen before the profile construction. An attempt to read
+ // the policy outside the session will always fail and return an empty policy
+ // blob.
+ if (response_type == chromeos::SessionManagerClient::
+ RetrievePolicyResponseType::SESSION_DOES_NOT_EXIST) {
+ LOG(ERROR)
+ << "Session manager claims that session doesn't exist; signing out";
+ chrome::AttemptUserExit();
+ return;
+ }
+
+ if (policy_blob.empty() &&
+ response_type ==
+ chromeos::SessionManagerClient::RetrievePolicyResponseType::SUCCESS) {
// session_manager doesn't have policy. Adjust internal state and notify
// the world about the policy update.
policy_map_.Clear();
@@ -225,6 +259,13 @@ void UserCloudPolicyStoreChromeOS::OnPolicyRetrieved(
return;
}
+ if (response_type !=
+ chromeos::SessionManagerClient::RetrievePolicyResponseType::SUCCESS) {
+ status_ = STATUS_LOAD_ERROR;
+ NotifyStoreError();
+ return;
+ }
+
std::unique_ptr<em::PolicyFetchResponse> policy(
new em::PolicyFetchResponse());
if (!policy->ParseFromString(policy_blob)) {

Powered by Google App Engine
This is Rietveld 408576698