1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. 2 // Use of this source code is governed by a BSD-style license that can be 3 // found in the LICENSE file. 4 5 #ifndef CHROME_BROWSER_CHROMEOS_POLICY_USER_CLOUD_POLICY_MANAGER_CHROMEOS_H_ 6 #define CHROME_BROWSER_CHROMEOS_POLICY_USER_CLOUD_POLICY_MANAGER_CHROMEOS_H_ 7 8 #include <string> 9 10 #include "base/basictypes.h" 11 #include "base/compiler_specific.h" 12 #include "base/files/file_path.h" 13 #include "base/memory/ref_counted.h" 14 #include "base/memory/scoped_ptr.h" 15 #include "base/time/time.h" 16 #include "base/timer/timer.h" 17 #include "components/browser_context_keyed_service/browser_context_keyed_service.h" 18 #include "components/policy/core/common/cloud/cloud_policy_client.h" 19 #include "components/policy/core/common/cloud/cloud_policy_constants.h" 20 #include "components/policy/core/common/cloud/cloud_policy_manager.h" 21 #include "components/policy/core/common/cloud/cloud_policy_service.h" 22 23 class GoogleServiceAuthError; 24 class PrefService; 25 26 namespace base { 27 class SequencedTaskRunner; 28 } 29 30 namespace net { 31 class URLRequestContextGetter; 32 } 33 34 namespace policy { 35 36 class CloudExternalDataManager; 37 class DeviceManagementService; 38 class PolicyOAuth2TokenFetcher; 39 class WildcardLoginChecker; 40 41 // UserCloudPolicyManagerChromeOS implements logic for initializing user policy 42 // on Chrome OS. 43 class UserCloudPolicyManagerChromeOS 44 : public CloudPolicyManager, 45 public CloudPolicyClient::Observer, 46 public CloudPolicyService::Observer, 47 public BrowserContextKeyedService { 48 public: 49 // If |wait_for_policy_fetch| is true, IsInitializationComplete() will return 50 // false as long as there hasn't been a successful policy fetch. 51 // |task_runner| is the runner for policy refresh tasks. 52 // |file_task_runner| is used for file operations. Currently this must be the 53 // FILE BrowserThread. 54 // |io_task_runner| is used for network IO. Currently this must be the IO 55 // BrowserThread. 56 UserCloudPolicyManagerChromeOS( 57 scoped_ptr<CloudPolicyStore> store, 58 scoped_ptr<CloudExternalDataManager> external_data_manager, 59 const base::FilePath& component_policy_cache_path, 60 bool wait_for_policy_fetch, 61 base::TimeDelta initial_policy_fetch_timeout, 62 const scoped_refptr<base::SequencedTaskRunner>& task_runner, 63 const scoped_refptr<base::SequencedTaskRunner>& file_task_runner, 64 const scoped_refptr<base::SequencedTaskRunner>& io_task_runner); 65 virtual ~UserCloudPolicyManagerChromeOS(); 66 67 // Initializes the cloud connection. |local_state| and 68 // |device_management_service| must stay valid until this object is deleted. 69 void Connect( 70 PrefService* local_state, 71 DeviceManagementService* device_management_service, 72 scoped_refptr<net::URLRequestContextGetter> system_request_context, 73 UserAffiliation user_affiliation); 74 75 // This class is one of the policy providers, and must be ready for the 76 // creation of the Profile's PrefService; all the other 77 // BrowserContextKeyedServices depend on the PrefService, so this class can't 78 // depend on other BCKS to avoid a circular dependency. So instead of using 79 // the ProfileOAuth2TokenService directly to get the access token, a 3rd 80 // service (UserCloudPolicyTokenForwarder) will fetch it later and pass it 81 // to this method once available. 82 // The |access_token| can then be used to authenticate the registration 83 // request to the DMServer. 84 void OnAccessTokenAvailable(const std::string& access_token); 85 86 // Returns true if the underlying CloudPolicyClient is already registered. 87 bool IsClientRegistered() const; 88 89 // Indicates a wildcard login check should be performed once an access token 90 // is available. 91 void EnableWildcardLoginCheck(const std::string& username); 92 93 // ConfigurationPolicyProvider: 94 virtual void Shutdown() OVERRIDE; 95 virtual bool IsInitializationComplete(PolicyDomain domain) const OVERRIDE; 96 97 // CloudPolicyService::Observer: 98 virtual void OnInitializationCompleted(CloudPolicyService* service) OVERRIDE; 99 100 // CloudPolicyClient::Observer: 101 virtual void OnPolicyFetched(CloudPolicyClient* client) OVERRIDE; 102 virtual void OnRegistrationStateChanged(CloudPolicyClient* client) OVERRIDE; 103 virtual void OnClientError(CloudPolicyClient* client) OVERRIDE; 104 105 // ComponentCloudPolicyService::Delegate: 106 virtual void OnComponentCloudPolicyUpdated() OVERRIDE; 107 108 private: 109 // Fetches a policy token using the authentication context of the signin 110 // Profile, and calls back to OnOAuth2PolicyTokenFetched when done. 111 void FetchPolicyOAuthTokenUsingSigninProfile(); 112 113 // Called once the policy access token is available, and starts the 114 // registration with the policy server if the token was successfully fetched. 115 void OnOAuth2PolicyTokenFetched(const std::string& policy_token, 116 const GoogleServiceAuthError& error); 117 118 // Completion handler for the explicit policy fetch triggered on startup in 119 // case |wait_for_policy_fetch_| is true. |success| is true if the fetch was 120 // successful. 121 void OnInitialPolicyFetchComplete(bool success); 122 123 // Cancels waiting for the policy fetch and flags the 124 // ConfigurationPolicyProvider ready (assuming all other initialization tasks 125 // have completed). 126 void CancelWaitForPolicyFetch(); 127 128 void StartRefreshSchedulerIfReady(); 129 130 // Owns the store, note that CloudPolicyManager just keeps a plain pointer. 131 scoped_ptr<CloudPolicyStore> store_; 132 133 // Manages external data referenced by policies. 134 scoped_ptr<CloudExternalDataManager> external_data_manager_; 135 136 // Username for the wildcard login check if applicable, empty otherwise. 137 std::string wildcard_username_; 138 139 // Path where policy for components will be cached. 140 base::FilePath component_policy_cache_path_; 141 142 // Whether to wait for a policy fetch to complete before reporting 143 // IsInitializationComplete(). 144 bool wait_for_policy_fetch_; 145 146 // A timer that puts a hard limit on the maximum time to wait for the intial 147 // policy fetch. 148 base::Timer policy_fetch_timeout_; 149 150 // The pref service to pass to the refresh scheduler on initialization. 151 PrefService* local_state_; 152 153 // Used to fetch the policy OAuth token, when necessary. This object holds 154 // a callback with an unretained reference to the manager, when it exists. 155 scoped_ptr<PolicyOAuth2TokenFetcher> token_fetcher_; 156 157 // Keeps alive the wildcard checker while its running. 158 scoped_ptr<WildcardLoginChecker> wildcard_login_checker_; 159 160 // The access token passed to OnAccessTokenAvailable. It is stored here so 161 // that it can be used if OnInitializationCompleted is called later. 162 std::string access_token_; 163 164 // Timestamps for collecting timing UMA stats. 165 base::Time time_init_started_; 166 base::Time time_init_completed_; 167 base::Time time_token_available_; 168 base::Time time_client_registered_; 169 170 DISALLOW_COPY_AND_ASSIGN(UserCloudPolicyManagerChromeOS); 171 }; 172 173 } // namespace policy 174 175 #endif // CHROME_BROWSER_CHROMEOS_POLICY_USER_CLOUD_POLICY_MANAGER_CHROMEOS_H_ 176