Home | History | Annotate | Download | only in policy
      1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
      2 // Use of this source code is governed by a BSD-style license that can be
      3 // found in the LICENSE file.
      4 
      5 #ifndef CHROME_BROWSER_CHROMEOS_POLICY_USER_CLOUD_POLICY_MANAGER_CHROMEOS_H_
      6 #define CHROME_BROWSER_CHROMEOS_POLICY_USER_CLOUD_POLICY_MANAGER_CHROMEOS_H_
      7 
      8 #include <string>
      9 
     10 #include "base/basictypes.h"
     11 #include "base/compiler_specific.h"
     12 #include "base/files/file_path.h"
     13 #include "base/memory/ref_counted.h"
     14 #include "base/memory/scoped_ptr.h"
     15 #include "base/time/time.h"
     16 #include "base/timer/timer.h"
     17 #include "components/browser_context_keyed_service/browser_context_keyed_service.h"
     18 #include "components/policy/core/common/cloud/cloud_policy_client.h"
     19 #include "components/policy/core/common/cloud/cloud_policy_constants.h"
     20 #include "components/policy/core/common/cloud/cloud_policy_manager.h"
     21 #include "components/policy/core/common/cloud/cloud_policy_service.h"
     22 
     23 class GoogleServiceAuthError;
     24 class PrefService;
     25 
     26 namespace base {
     27 class SequencedTaskRunner;
     28 }
     29 
     30 namespace net {
     31 class URLRequestContextGetter;
     32 }
     33 
     34 namespace policy {
     35 
     36 class CloudExternalDataManager;
     37 class DeviceManagementService;
     38 class PolicyOAuth2TokenFetcher;
     39 class WildcardLoginChecker;
     40 
     41 // UserCloudPolicyManagerChromeOS implements logic for initializing user policy
     42 // on Chrome OS.
     43 class UserCloudPolicyManagerChromeOS
     44     : public CloudPolicyManager,
     45       public CloudPolicyClient::Observer,
     46       public CloudPolicyService::Observer,
     47       public BrowserContextKeyedService {
     48  public:
     49   // If |wait_for_policy_fetch| is true, IsInitializationComplete() will return
     50   // false as long as there hasn't been a successful policy fetch.
     51   // |task_runner| is the runner for policy refresh tasks.
     52   // |file_task_runner| is used for file operations. Currently this must be the
     53   // FILE BrowserThread.
     54   // |io_task_runner| is used for network IO. Currently this must be the IO
     55   // BrowserThread.
     56   UserCloudPolicyManagerChromeOS(
     57       scoped_ptr<CloudPolicyStore> store,
     58       scoped_ptr<CloudExternalDataManager> external_data_manager,
     59       const base::FilePath& component_policy_cache_path,
     60       bool wait_for_policy_fetch,
     61       base::TimeDelta initial_policy_fetch_timeout,
     62       const scoped_refptr<base::SequencedTaskRunner>& task_runner,
     63       const scoped_refptr<base::SequencedTaskRunner>& file_task_runner,
     64       const scoped_refptr<base::SequencedTaskRunner>& io_task_runner);
     65   virtual ~UserCloudPolicyManagerChromeOS();
     66 
     67   // Initializes the cloud connection. |local_state| and
     68   // |device_management_service| must stay valid until this object is deleted.
     69   void Connect(
     70       PrefService* local_state,
     71       DeviceManagementService* device_management_service,
     72       scoped_refptr<net::URLRequestContextGetter> system_request_context,
     73       UserAffiliation user_affiliation);
     74 
     75   // This class is one of the policy providers, and must be ready for the
     76   // creation of the Profile's PrefService; all the other
     77   // BrowserContextKeyedServices depend on the PrefService, so this class can't
     78   // depend on other BCKS to avoid a circular dependency. So instead of using
     79   // the ProfileOAuth2TokenService directly to get the access token, a 3rd
     80   // service (UserCloudPolicyTokenForwarder) will fetch it later and pass it
     81   // to this method once available.
     82   // The |access_token| can then be used to authenticate the registration
     83   // request to the DMServer.
     84   void OnAccessTokenAvailable(const std::string& access_token);
     85 
     86   // Returns true if the underlying CloudPolicyClient is already registered.
     87   bool IsClientRegistered() const;
     88 
     89   // Indicates a wildcard login check should be performed once an access token
     90   // is available.
     91   void EnableWildcardLoginCheck(const std::string& username);
     92 
     93   // ConfigurationPolicyProvider:
     94   virtual void Shutdown() OVERRIDE;
     95   virtual bool IsInitializationComplete(PolicyDomain domain) const OVERRIDE;
     96 
     97   // CloudPolicyService::Observer:
     98   virtual void OnInitializationCompleted(CloudPolicyService* service) OVERRIDE;
     99 
    100   // CloudPolicyClient::Observer:
    101   virtual void OnPolicyFetched(CloudPolicyClient* client) OVERRIDE;
    102   virtual void OnRegistrationStateChanged(CloudPolicyClient* client) OVERRIDE;
    103   virtual void OnClientError(CloudPolicyClient* client) OVERRIDE;
    104 
    105   // ComponentCloudPolicyService::Delegate:
    106   virtual void OnComponentCloudPolicyUpdated() OVERRIDE;
    107 
    108  private:
    109   // Fetches a policy token using the authentication context of the signin
    110   // Profile, and calls back to OnOAuth2PolicyTokenFetched when done.
    111   void FetchPolicyOAuthTokenUsingSigninProfile();
    112 
    113   // Called once the policy access token is available, and starts the
    114   // registration with the policy server if the token was successfully fetched.
    115   void OnOAuth2PolicyTokenFetched(const std::string& policy_token,
    116                                   const GoogleServiceAuthError& error);
    117 
    118   // Completion handler for the explicit policy fetch triggered on startup in
    119   // case |wait_for_policy_fetch_| is true. |success| is true if the fetch was
    120   // successful.
    121   void OnInitialPolicyFetchComplete(bool success);
    122 
    123   // Cancels waiting for the policy fetch and flags the
    124   // ConfigurationPolicyProvider ready (assuming all other initialization tasks
    125   // have completed).
    126   void CancelWaitForPolicyFetch();
    127 
    128   void StartRefreshSchedulerIfReady();
    129 
    130   // Owns the store, note that CloudPolicyManager just keeps a plain pointer.
    131   scoped_ptr<CloudPolicyStore> store_;
    132 
    133   // Manages external data referenced by policies.
    134   scoped_ptr<CloudExternalDataManager> external_data_manager_;
    135 
    136   // Username for the wildcard login check if applicable, empty otherwise.
    137   std::string wildcard_username_;
    138 
    139   // Path where policy for components will be cached.
    140   base::FilePath component_policy_cache_path_;
    141 
    142   // Whether to wait for a policy fetch to complete before reporting
    143   // IsInitializationComplete().
    144   bool wait_for_policy_fetch_;
    145 
    146   // A timer that puts a hard limit on the maximum time to wait for the intial
    147   // policy fetch.
    148   base::Timer policy_fetch_timeout_;
    149 
    150   // The pref service to pass to the refresh scheduler on initialization.
    151   PrefService* local_state_;
    152 
    153   // Used to fetch the policy OAuth token, when necessary. This object holds
    154   // a callback with an unretained reference to the manager, when it exists.
    155   scoped_ptr<PolicyOAuth2TokenFetcher> token_fetcher_;
    156 
    157   // Keeps alive the wildcard checker while its running.
    158   scoped_ptr<WildcardLoginChecker> wildcard_login_checker_;
    159 
    160   // The access token passed to OnAccessTokenAvailable. It is stored here so
    161   // that it can be used if OnInitializationCompleted is called later.
    162   std::string access_token_;
    163 
    164   // Timestamps for collecting timing UMA stats.
    165   base::Time time_init_started_;
    166   base::Time time_init_completed_;
    167   base::Time time_token_available_;
    168   base::Time time_client_registered_;
    169 
    170   DISALLOW_COPY_AND_ASSIGN(UserCloudPolicyManagerChromeOS);
    171 };
    172 
    173 }  // namespace policy
    174 
    175 #endif  // CHROME_BROWSER_CHROMEOS_POLICY_USER_CLOUD_POLICY_MANAGER_CHROMEOS_H_
    176