Code:
/ FXUpdate3074 / FXUpdate3074 / 1.1 / untmp / whidbey / QFE / ndp / clr / src / BCL / System / Security / PermissionSetTriple.cs / 4 / PermissionSetTriple.cs
// ==++==
//
// Copyright (c) Microsoft Corporation. All rights reserved.
//
// ==--==
/*==============================================================================
**
** Class: PermissionSetTriple
**
** Purpose: Container class for holding an AppDomain's Grantset and Refused sets.
** Also used for CompressedStacks which brings in the third PermissionSet.
** Hence, the name PermissionSetTriple.
**
=============================================================================*/
namespace System.Security
{
using IEnumerator = System.Collections.IEnumerator;
using System.Security;
using System.Security.Permissions;
using System.Runtime.InteropServices;
[Serializable()]
sealed internal class PermissionSetTriple
{
unsafe static private RuntimeMethodHandle s_emptyRMH = new RuntimeMethodHandle(null);
static private PermissionToken s_zoneToken;
static private PermissionToken s_urlToken;
internal PermissionSet AssertSet;
internal PermissionSet GrantSet;
internal PermissionSet RefusedSet;
internal PermissionSetTriple()
{
Reset();
}
internal PermissionSetTriple(PermissionSetTriple triple)
{
this.AssertSet = triple.AssertSet;
this.GrantSet = triple.GrantSet;
this.RefusedSet = triple.RefusedSet;
}
internal void Reset()
{
AssertSet = null;
GrantSet = null;
RefusedSet = null;
}
internal bool IsEmpty()
{
return (AssertSet == null && GrantSet == null && RefusedSet == null);
}
private PermissionToken ZoneToken
{
get
{
if (s_zoneToken == null)
s_zoneToken = PermissionToken.GetToken(typeof(ZoneIdentityPermission));
return s_zoneToken;
}
}
private PermissionToken UrlToken
{
get
{
if (s_urlToken == null)
s_urlToken = PermissionToken.GetToken(typeof(UrlIdentityPermission));
return s_urlToken;
}
}
internal bool Update(PermissionSetTriple psTriple, out PermissionSetTriple retTriple)
{
retTriple = null;
// Special case: unrestricted assertt. Note: dcs.Assert.IsUnrestricted => dcs.Grant.IsUnrestricted
if (psTriple.AssertSet != null && psTriple.AssertSet.IsUnrestricted())
{
return true; // stop construction
}
retTriple = UpdateAssert(psTriple.AssertSet);
UpdateGrant(psTriple.GrantSet);
UpdateRefused(psTriple.RefusedSet);
return false;
}
internal PermissionSetTriple UpdateAssert(PermissionSet in_a)
{
PermissionSetTriple retTriple = null;
if (in_a != null)
{
BCLDebug.Assert((!in_a.IsUnrestricted()), "Cannot be unrestricted here");
// if we're already assertting in_a, nothing to do
if (in_a.IsSubsetOf(AssertSet))
return null;
PermissionSet retPs;
if (GrantSet != null)
retPs = in_a.Intersect(GrantSet); // Restrict the assertt to what we've already been granted
else
{
GrantSet = new PermissionSet(true);
retPs = in_a.Copy(); // Currently unrestricted Grant: assertt the whole assertt set
}
bool bFailedToCompress;
// removes anything that is already in the refused set from the assertt set
retPs = PermissionSet.RemoveRefusedPermissionSet(retPs, RefusedSet, out bFailedToCompress);
if (!bFailedToCompress)
bFailedToCompress = PermissionSet.IsIntersectingAssertedPermissions(retPs, AssertSet);
if (bFailedToCompress)
{
retTriple = new PermissionSetTriple(this);
this.Reset();
this.GrantSet = retTriple.GrantSet.Copy();
}
if (AssertSet == null)
AssertSet = retPs;
else
AssertSet.InplaceUnion(retPs);
}
return retTriple;
}
internal void UpdateGrant(PermissionSet in_g, out ZoneIdentityPermission z,out UrlIdentityPermission u)
{
z = null;
u = null;
if (in_g != null)
{
if (GrantSet == null)
GrantSet = in_g.Copy();
else
GrantSet.InplaceIntersect(in_g);
z = (ZoneIdentityPermission)in_g.GetPermission(ZoneToken);
u = (UrlIdentityPermission)in_g.GetPermission(UrlToken);
}
}
internal void UpdateGrant(PermissionSet in_g)
{
if (in_g != null)
{
if (GrantSet == null)
GrantSet = in_g.Copy();
else
GrantSet.InplaceIntersect(in_g);
}
}
internal void UpdateRefused(PermissionSet in_r)
{
if (in_r != null)
{
if (RefusedSet == null)
RefusedSet = in_r.Copy();
else
RefusedSet.InplaceUnion(in_r);
}
}
static bool CheckAssert(PermissionSet pSet, CodeAccessPermission demand, PermissionToken permToken)
{
if (pSet != null)
{
pSet.CheckDecoded(demand, permToken);
CodeAccessPermission perm = (CodeAccessPermission)pSet.GetPermission(demand);
// If the assertt set does contain the demanded permission, halt the stackwalk
try
{
if ((pSet.IsUnrestricted() && demand.CanUnrestrictedOverride()) || demand.CheckAssert(perm))
{
return SecurityRuntime.StackHalt;
}
}
catch (ArgumentException)
{
}
}
return SecurityRuntime.StackContinue;
}
static bool CheckAssert(PermissionSet asserttPset, PermissionSet demandSet, out PermissionSet newDemandSet)
{
newDemandSet = null;
if (asserttPset!= null)
{
asserttPset.CheckDecoded(demandSet);
// If this frame assertts a superset of the demand set we're done
if (demandSet.CheckAssertion(asserttPset))
return SecurityRuntime.StackHalt;
PermissionSet.RemoveAssertedPermissionSet(demandSet, asserttPset, out newDemandSet);
}
return SecurityRuntime.StackContinue;
}
internal bool CheckDemand(CodeAccessPermission demand, PermissionToken permToken, RuntimeMethodHandle rmh)
{
if (CheckAssert(AssertSet, demand, permToken) == SecurityRuntime.StackHalt)
return SecurityRuntime.StackHalt;
CodeAccessSecurityEngine.CheckHelper(GrantSet, RefusedSet, demand, permToken, rmh, null, SecurityAction.Demand, true);
return SecurityRuntime.StackContinue;
}
internal bool CheckSetDemand(PermissionSet demandSet , out PermissionSet alteredDemandset, RuntimeMethodHandle rmh)
{
alteredDemandset = null;
if (CheckAssert(AssertSet, demandSet, out alteredDemandset) == SecurityRuntime.StackHalt)
return SecurityRuntime.StackHalt;
if (alteredDemandset != null)
demandSet = alteredDemandset; //
CodeAccessSecurityEngine.CheckSetHelper(GrantSet, RefusedSet, demandSet, rmh, null, SecurityAction.Demand, true);
return SecurityRuntime.StackContinue;
}
internal bool CheckDemandNoThrow(CodeAccessPermission demand, PermissionToken permToken)
{
BCLDebug.Assert(AssertSet == null, "AssertSet not null");
return CodeAccessSecurityEngine.CheckHelper(GrantSet, RefusedSet, demand, permToken, s_emptyRMH, null, SecurityAction.Demand, false);
}
internal bool CheckSetDemandNoThrow(PermissionSet demandSet)
{
BCLDebug.Assert(AssertSet == null, "AssertSet not null");
return CodeAccessSecurityEngine.CheckSetHelper(GrantSet, RefusedSet, demandSet, s_emptyRMH, null, SecurityAction.Demand, false);
}
///
/// Check to see if the triple satisfies a demand for the permission represented by the flag.
///
///
/// If the triple assertts for one of the bits in the flags, it is zeroed out.
///
/// set of flags to
internal bool CheckFlags(ref int flags)
{
if (AssertSet != null)
{
// remove any permissions which were assertted for
int asserttFlags = SecurityManager.GetSpecialFlags(AssertSet, null);
if ((flags & asserttFlags) != 0)
flags = flags & ~asserttFlags;
}
return (SecurityManager.GetSpecialFlags(GrantSet, RefusedSet) & flags) == flags;
}
}
}
// File provided for Reference Use Only by Microsoft Corporation (c) 2007.
// Copyright (c) Microsoft Corporation. All rights reserved.
Link Menu

This book is available now!
Buy at Amazon US or
Buy at Amazon UK
- DesignerProperties.cs
- DataGridTextBox.cs
- SQLGuid.cs
- WorkflowQueuingService.cs
- IconBitmapDecoder.cs
- ExpressionTextBox.xaml.cs
- MetadataItem.cs
- PointLightBase.cs
- TableItemPatternIdentifiers.cs
- SecurityKeyIdentifier.cs
- AssemblyInfo.cs
- HelpEvent.cs
- UnmanagedMemoryStreamWrapper.cs
- DocumentXmlWriter.cs
- NeutralResourcesLanguageAttribute.cs
- ColorInterpolationModeValidation.cs
- SiteMapHierarchicalDataSourceView.cs
- IfAction.cs
- MembershipSection.cs
- GroupBoxRenderer.cs
- PeerApplicationLaunchInfo.cs
- CodeTypeDelegate.cs
- MergeLocalizationDirectives.cs
- RoleManagerModule.cs
- DispatcherExceptionFilterEventArgs.cs
- PointCollection.cs
- DataColumnMappingCollection.cs
- CodeParameterDeclarationExpressionCollection.cs
- ErrorItem.cs
- MDIControlStrip.cs
- HashCodeCombiner.cs
- GridView.cs
- Vector.cs
- ToolStripSeparatorRenderEventArgs.cs
- TransactedBatchingElement.cs
- Image.cs
- FileAuthorizationModule.cs
- UidManager.cs
- KnownAssemblyEntry.cs
- WebServiceClientProxyGenerator.cs
- ThaiBuddhistCalendar.cs
- Site.cs
- TreeViewImageIndexConverter.cs
- BooleanSwitch.cs
- ProfileEventArgs.cs
- Expressions.cs
- SqlStatistics.cs
- XsdBuilder.cs
- WebPartVerbCollection.cs
- DesignerLoader.cs
- wgx_exports.cs
- HScrollProperties.cs
- AuthenticateEventArgs.cs
- StructuredTypeEmitter.cs
- QuaternionAnimation.cs
- ObjectReaderCompiler.cs
- X500Name.cs
- DataGridView.cs
- SqlUserDefinedAggregateAttribute.cs
- SessionSwitchEventArgs.cs
- ListSortDescriptionCollection.cs
- XmlResolver.cs
- DotExpr.cs
- QilTernary.cs
- InfoCardRSACryptoProvider.cs
- CodeBlockBuilder.cs
- DrawingServices.cs
- CompatibleIComparer.cs
- DataViewManager.cs
- UserPreferenceChangedEventArgs.cs
- ActiveXHelper.cs
- VisualStyleInformation.cs
- NoClickablePointException.cs
- COM2AboutBoxPropertyDescriptor.cs
- SqlClientMetaDataCollectionNames.cs
- StandardToolWindows.cs
- DataGridViewSelectedRowCollection.cs
- OleAutBinder.cs
- WebPartChrome.cs
- XmlMapping.cs
- InvalidPipelineStoreException.cs
- FamilyTypeface.cs
- PrefixQName.cs
- SmiContextFactory.cs
- PenThread.cs
- AttributeCollection.cs
- BindingElementExtensionElement.cs
- _ProxyRegBlob.cs
- SelectionRange.cs
- coordinator.cs
- OrderedDictionary.cs
- CrossSiteScriptingValidation.cs
- UTF8Encoding.cs
- ProgressChangedEventArgs.cs
- TableRowGroup.cs
- ReadOnlyDictionary.cs
- MutexSecurity.cs
- SystemEvents.cs
- EncoderNLS.cs
- WebPartTransformerCollection.cs