1 // Copyright (c) 2013 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
5 #include "chrome/browser/policy/profile_policy_connector.h"
9 #include "base/logging.h"
10 #include "chrome/browser/browser_process.h"
11 #include "chrome/browser/policy/browser_policy_connector.h"
12 #include "chrome/browser/policy/configuration_policy_provider.h"
13 #include "chrome/browser/policy/policy_service_impl.h"
15 #if defined(ENABLE_MANAGED_USERS)
16 #include "chrome/browser/policy/managed_mode_policy_provider.h"
19 #if defined(OS_CHROMEOS)
20 #include "base/bind.h"
21 #include "base/prefs/pref_service.h"
22 #include "chrome/browser/chromeos/login/user.h"
23 #include "chrome/browser/chromeos/login/user_manager.h"
24 #include "chrome/browser/chromeos/policy/device_local_account_policy_provider.h"
25 #include "chrome/browser/chromeos/policy/login_profile_policy_provider.h"
26 #include "chrome/browser/chromeos/policy/user_cloud_policy_manager_chromeos.h"
27 #include "chrome/browser/chromeos/policy/user_cloud_policy_manager_factory_chromeos.h"
28 #include "chrome/browser/chromeos/policy/user_network_configuration_updater.h"
29 #include "chrome/browser/chromeos/profiles/profile_helper.h"
30 #include "chrome/browser/policy/policy_service.h"
31 #include "chrome/common/pref_names.h"
32 #include "chromeos/network/network_handler.h"
33 #include "chromeos/network/onc/onc_certificate_importer_impl.h"
35 #include "chrome/browser/policy/cloud/user_cloud_policy_manager.h"
36 #include "chrome/browser/policy/cloud/user_cloud_policy_manager_factory.h"
41 ProfilePolicyConnector::ProfilePolicyConnector(Profile
* profile
)
43 #if defined(OS_CHROMEOS)
44 is_primary_user_(false),
45 weak_ptr_factory_(this),
49 ProfilePolicyConnector::~ProfilePolicyConnector() {}
51 void ProfilePolicyConnector::Init(
52 bool force_immediate_load
,
53 base::SequencedTaskRunner
* sequenced_task_runner
) {
54 BrowserPolicyConnector
* connector
=
55 g_browser_process
->browser_policy_connector();
56 // |providers| contains a list of the policy providers available for the
57 // PolicyService of this connector.
58 std::vector
<ConfigurationPolicyProvider
*> providers
;
60 #if defined(OS_CHROMEOS)
61 UserCloudPolicyManagerChromeOS
* cloud_policy_manager
=
62 UserCloudPolicyManagerFactoryChromeOS::GetForProfile(profile_
);
63 if (cloud_policy_manager
)
64 providers
.push_back(cloud_policy_manager
);
66 bool allow_trusted_certs_from_policy
= false;
67 chromeos::User
* user
= NULL
;
68 if (chromeos::ProfileHelper::IsSigninProfile(profile_
)) {
69 special_user_policy_provider_
.reset(new LoginProfilePolicyProvider(
70 connector
->GetPolicyService()));
71 special_user_policy_provider_
->Init();
73 // |user| should never be NULL except for the signin profile.
74 // TODO(joaodasilva): get the |user| that corresponds to the |profile_|
75 // from the ProfileHelper, once that's ready.
76 chromeos::UserManager
* user_manager
= chromeos::UserManager::Get();
77 user
= user_manager
->GetActiveUser();
79 std::string username
= user
->email();
81 chromeos::UserManager::Get()->GetLoggedInUsers().size() == 1;
82 if (user
->GetType() == chromeos::User::USER_TYPE_PUBLIC_ACCOUNT
)
83 InitializeDeviceLocalAccountPolicyProvider(username
);
84 // Allow trusted certs from policy only for managed regular accounts.
85 const bool is_managed
=
86 connector
->GetUserAffiliation(username
) == USER_AFFILIATION_MANAGED
;
87 if (is_managed
&& user
->GetType() == chromeos::User::USER_TYPE_REGULAR
)
88 allow_trusted_certs_from_policy
= true;
90 if (special_user_policy_provider_
)
91 providers
.push_back(special_user_policy_provider_
.get());
94 UserCloudPolicyManager
* cloud_policy_manager
=
95 UserCloudPolicyManagerFactory::GetForProfile(profile_
);
96 if (cloud_policy_manager
)
97 providers
.push_back(cloud_policy_manager
);
100 #if defined(ENABLE_MANAGED_USERS)
101 managed_mode_policy_provider_
= ManagedModePolicyProvider::Create(
102 profile_
, sequenced_task_runner
, force_immediate_load
);
103 managed_mode_policy_provider_
->Init();
104 providers
.push_back(managed_mode_policy_provider_
.get());
107 policy_service_
= connector
->CreatePolicyService(providers
);
109 #if defined(OS_CHROMEOS)
110 if (is_primary_user_
) {
111 if (cloud_policy_manager
)
112 connector
->SetUserPolicyDelegate(cloud_policy_manager
);
113 else if (special_user_policy_provider_
)
114 connector
->SetUserPolicyDelegate(special_user_policy_provider_
.get());
116 // A reference to |user| is stored by the NetworkConfigurationUpdater until
117 // the Updater is destructed during Shutdown.
118 network_configuration_updater_
=
119 UserNetworkConfigurationUpdater::CreateForUserPolicy(
120 allow_trusted_certs_from_policy
,
122 scoped_ptr
<chromeos::onc::CertificateImporter
>(
123 new chromeos::onc::CertificateImporterImpl
),
125 chromeos::NetworkHandler::Get()
126 ->managed_network_configuration_handler());
131 void ProfilePolicyConnector::InitForTesting(scoped_ptr
<PolicyService
> service
) {
132 policy_service_
= service
.Pass();
135 void ProfilePolicyConnector::Shutdown() {
136 #if defined(OS_CHROMEOS)
137 if (is_primary_user_
)
138 g_browser_process
->browser_policy_connector()->SetUserPolicyDelegate(NULL
);
139 network_configuration_updater_
.reset();
140 if (special_user_policy_provider_
)
141 special_user_policy_provider_
->Shutdown();
144 #if defined(ENABLE_MANAGED_USERS)
145 if (managed_mode_policy_provider_
)
146 managed_mode_policy_provider_
->Shutdown();
150 #if defined(OS_CHROMEOS)
151 void ProfilePolicyConnector::SetPolicyCertVerifier(
152 PolicyCertVerifier
* cert_verifier
) {
153 if (network_configuration_updater_
)
154 network_configuration_updater_
->SetPolicyCertVerifier(cert_verifier
);
157 base::Closure
ProfilePolicyConnector::GetPolicyCertTrustedCallback() {
158 return base::Bind(&ProfilePolicyConnector::SetUsedPolicyCertificatesOnce
,
159 weak_ptr_factory_
.GetWeakPtr());
162 void ProfilePolicyConnector::GetWebTrustedCertificates(
163 net::CertificateList
* certs
) const {
165 if (network_configuration_updater_
)
166 network_configuration_updater_
->GetWebTrustedCertificates(certs
);
170 bool ProfilePolicyConnector::UsedPolicyCertificates() {
171 #if defined(OS_CHROMEOS)
172 return profile_
->GetPrefs()->GetBoolean(prefs::kUsedPolicyCertificatesOnce
);
178 #if defined(OS_CHROMEOS)
179 void ProfilePolicyConnector::SetUsedPolicyCertificatesOnce() {
180 profile_
->GetPrefs()->SetBoolean(prefs::kUsedPolicyCertificatesOnce
, true);
183 void ProfilePolicyConnector::InitializeDeviceLocalAccountPolicyProvider(
184 const std::string
& username
) {
185 BrowserPolicyConnector
* connector
=
186 g_browser_process
->browser_policy_connector();
187 DeviceLocalAccountPolicyService
* device_local_account_policy_service
=
188 connector
->GetDeviceLocalAccountPolicyService();
189 if (!device_local_account_policy_service
)
191 special_user_policy_provider_
.reset(new DeviceLocalAccountPolicyProvider(
192 username
, device_local_account_policy_service
));
193 special_user_policy_provider_
->Init();
197 } // namespace policy