1 // Copyright (c) 2013 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
5 #include "chrome/browser/policy/profile_policy_connector.h"
10 #include "base/logging.h"
11 #include "base/values.h"
12 #include "chrome/browser/browser_process.h"
13 #include "components/policy/core/browser/browser_policy_connector.h"
14 #include "components/policy/core/common/cloud/cloud_policy_core.h"
15 #include "components/policy/core/common/cloud/cloud_policy_manager.h"
16 #include "components/policy/core/common/cloud/cloud_policy_store.h"
17 #include "components/policy/core/common/configuration_policy_provider.h"
18 #include "components/policy/core/common/policy_service_impl.h"
19 #include "components/policy/core/common/schema_registry_tracking_policy_provider.h"
20 #include "google_apis/gaia/gaia_auth_util.h"
22 #if defined(OS_CHROMEOS)
23 #include "chrome/browser/chromeos/policy/browser_policy_connector_chromeos.h"
24 #include "chrome/browser/chromeos/policy/device_cloud_policy_manager_chromeos.h"
25 #include "chrome/browser/chromeos/policy/device_local_account_policy_provider.h"
26 #include "chrome/browser/chromeos/policy/login_profile_policy_provider.h"
27 #include "components/user_manager/user.h"
28 #include "components/user_manager/user_manager.h"
35 bool HasChromePolicy(ConfigurationPolicyProvider
* provider
,
39 PolicyNamespace
chrome_ns(POLICY_DOMAIN_CHROME
, "");
40 return provider
->policies().Get(chrome_ns
).Get(name
) != NULL
;
45 ProfilePolicyConnector::ProfilePolicyConnector()
46 #if defined(OS_CHROMEOS)
47 : is_primary_user_(false),
48 user_cloud_policy_manager_(NULL
)
50 : user_cloud_policy_manager_(NULL
)
54 ProfilePolicyConnector::~ProfilePolicyConnector() {}
56 void ProfilePolicyConnector::Init(
57 bool force_immediate_load
,
58 #if defined(OS_CHROMEOS)
59 const user_manager::User
* user
,
61 SchemaRegistry
* schema_registry
,
62 CloudPolicyManager
* user_cloud_policy_manager
) {
63 user_cloud_policy_manager_
= user_cloud_policy_manager
;
65 // |providers| contains a list of the policy providers available for the
66 // PolicyService of this connector, in decreasing order of priority.
68 // Note: all the providers appended to this vector must eventually become
69 // initialized for every policy domain, otherwise some subsystems will never
70 // use the policies exposed by the PolicyService!
71 // The default ConfigurationPolicyProvider::IsInitializationComplete()
72 // result is true, so take care if a provider overrides that.
74 // Note: if you append a new provider then make sure IsPolicyFromCloudPolicy()
75 // is also updated below.
76 std::vector
<ConfigurationPolicyProvider
*> providers
;
78 #if defined(OS_CHROMEOS)
79 BrowserPolicyConnectorChromeOS
* connector
=
80 g_browser_process
->platform_part()->browser_policy_connector_chromeos();
82 BrowserPolicyConnector
* connector
=
83 g_browser_process
->browser_policy_connector();
86 if (connector
->GetPlatformProvider()) {
87 wrapped_platform_policy_provider_
.reset(
88 new SchemaRegistryTrackingPolicyProvider(
89 connector
->GetPlatformProvider()));
90 wrapped_platform_policy_provider_
->Init(schema_registry
);
91 providers
.push_back(wrapped_platform_policy_provider_
.get());
94 #if defined(OS_CHROMEOS)
95 if (connector
->GetDeviceCloudPolicyManager())
96 providers
.push_back(connector
->GetDeviceCloudPolicyManager());
99 if (user_cloud_policy_manager
)
100 providers
.push_back(user_cloud_policy_manager
);
102 #if defined(OS_CHROMEOS)
104 DCHECK(schema_registry
);
105 // This case occurs for the signin profile.
106 special_user_policy_provider_
.reset(
107 new LoginProfilePolicyProvider(connector
->GetPolicyService()));
109 // |user| should never be NULL except for the signin profile.
111 user
== user_manager::UserManager::Get()->GetPrimaryUser();
112 special_user_policy_provider_
= DeviceLocalAccountPolicyProvider::Create(
114 connector
->GetDeviceLocalAccountPolicyService());
116 if (special_user_policy_provider_
) {
117 special_user_policy_provider_
->Init(schema_registry
);
118 providers
.push_back(special_user_policy_provider_
.get());
122 policy_service_
.reset(new PolicyServiceImpl(providers
));
124 #if defined(OS_CHROMEOS)
125 if (is_primary_user_
) {
126 if (user_cloud_policy_manager
)
127 connector
->SetUserPolicyDelegate(user_cloud_policy_manager
);
128 else if (special_user_policy_provider_
)
129 connector
->SetUserPolicyDelegate(special_user_policy_provider_
.get());
134 void ProfilePolicyConnector::InitForTesting(scoped_ptr
<PolicyService
> service
) {
135 policy_service_
= service
.Pass();
138 void ProfilePolicyConnector::Shutdown() {
139 #if defined(OS_CHROMEOS)
140 BrowserPolicyConnectorChromeOS
* connector
=
141 g_browser_process
->platform_part()->browser_policy_connector_chromeos();
142 if (is_primary_user_
)
143 connector
->SetUserPolicyDelegate(NULL
);
144 if (special_user_policy_provider_
)
145 special_user_policy_provider_
->Shutdown();
147 if (wrapped_platform_policy_provider_
)
148 wrapped_platform_policy_provider_
->Shutdown();
151 bool ProfilePolicyConnector::IsManaged() const {
152 return !GetManagementDomain().empty();
155 std::string
ProfilePolicyConnector::GetManagementDomain() const {
156 if (!user_cloud_policy_manager_
)
158 CloudPolicyStore
* store
= user_cloud_policy_manager_
->core()->store();
159 if (store
&& store
->is_managed() && store
->policy()->has_username())
160 return gaia::ExtractDomainName(store
->policy()->username());
164 bool ProfilePolicyConnector::IsPolicyFromCloudPolicy(const char* name
) const {
165 if (!HasChromePolicy(user_cloud_policy_manager_
, name
))
168 // Check all the providers that have higher priority than the
169 // |user_cloud_policy_manager_|. These checks must be kept in sync with the
170 // order of the providers in Init().
172 if (HasChromePolicy(wrapped_platform_policy_provider_
.get(), name
))
175 #if defined(OS_CHROMEOS)
176 BrowserPolicyConnectorChromeOS
* connector
=
177 g_browser_process
->platform_part()->browser_policy_connector_chromeos();
178 if (HasChromePolicy(connector
->GetDeviceCloudPolicyManager(), name
))
185 } // namespace policy