| 86 | } |
| 87 | |
| 88 | PipeSecurityAttributes::PipeSecurityAttributes(): |
| 89 | securittyDescriptor_(nullptr) { |
| 90 | |
| 91 | securityAttributes_.nLength = sizeof(SECURITY_ATTRIBUTES); |
| 92 | securityAttributes_.lpSecurityDescriptor = nullptr; |
| 93 | securityAttributes_.bInheritHandle = TRUE; |
| 94 | |
| 95 | // References: |
| 96 | // google-input-tools: |
| 97 | // https://chromium.googlesource.com/external/google-input-tools/+/master/client/common/security_util_win.cc |
| 98 | // Windows ACL examples: |
| 99 | // https://www.installsetupconfig.com/win32programming/accesscontrollistaclexample3_4.html |
| 100 | |
| 101 | auto logonSid = getLogonSid(); |
| 102 | if (logonSid.empty()) { |
| 103 | return; |
| 104 | } |
| 105 | |
| 106 | std::wstring ownerSid, groupSid; |
| 107 | if (!getProcessOwnerSids(ownerSid, groupSid)) { |
| 108 | return; |
| 109 | } |
| 110 | |
| 111 | // Use Windows SDDL syntax to describe the security settings. |
| 112 | |
| 113 | std::wstring securityDescriptorStr; |
| 114 | // owner and group. |
| 115 | securityDescriptorStr += SDDL_OWNER L":" + ownerSid; |
| 116 | securityDescriptorStr += SDDL_GROUP L":" + groupSid; |
| 117 | |
| 118 | // DACL |
| 119 | securityDescriptorStr += SDDL_DACL L":"; |
| 120 | |
| 121 | // ACE strings in this DACL. |
| 122 | // Syntax: ace_type;ace_flags;rights;object_guid;inherit_object_guid;account_sid;(resource_attribute) |
| 123 | if (::IsWindows8OrGreater()) { |
| 124 | // Deny Remote Acccess. |
| 125 | securityDescriptorStr += L"(" SDDL_ACCESS_DENIED L";;" SDDL_GENERIC_ALL L";;;" SDDL_NETWORK L")"; |
| 126 | |
| 127 | // Allow general access to LocalSystem. |
| 128 | securityDescriptorStr += L"(" SDDL_ACCESS_ALLOWED L";;" SDDL_GENERIC_ALL L";;;" SDDL_LOCAL_SYSTEM L")"; |
| 129 | |
| 130 | // Allow general access to Built-in Administorators. |
| 131 | securityDescriptorStr += L"(" SDDL_ACCESS_ALLOWED L";;" SDDL_GENERIC_ALL L";;;" SDDL_BUILTIN_ADMINISTRATORS L")"; |
| 132 | |
| 133 | // Allow general access to ALL APPLICATION PACKAGES. |
| 134 | securityDescriptorStr += L"(" SDDL_ACCESS_ALLOWED L";;" SDDL_GENERIC_ALL L";;;" SDDL_ALL_APP_PACKAGES L")"; |
| 135 | } |
| 136 | |
| 137 | // Add generic & standand and all other possible object specific access right to logon user. |
| 138 | |
| 139 | // Hex of PROCESS_ALL_ACCESS = 0x1ffff |
| 140 | securityDescriptorStr += L"(" SDDL_ACCESS_ALLOWED L";;" PROCESS_ALL_ACCESS_HEX L";;;" + logonSid + L")"; |
| 141 | |
| 142 | // Add low integrity label to support application environment like IE |
| 143 | // protective mode if system supports(vista or latter). |
| 144 | if (::IsWindowsVistaOrGreater()) { |
| 145 | // Reference: https://flylib.com/books/en/1.286.1.27/1/ |
nothing calls this directly
no test coverage detected