summaryrefslogtreecommitdiffstats
path: root/perl-install/standalone/draksec
diff options
context:
space:
mode:
Diffstat (limited to 'perl-install/standalone/draksec')
-rwxr-xr-xperl-install/standalone/draksec112
1 files changed, 67 insertions, 45 deletions
diff --git a/perl-install/standalone/draksec b/perl-install/standalone/draksec
index b5fd5d5ca..7a265194a 100755
--- a/perl-install/standalone/draksec
+++ b/perl-install/standalone/draksec
@@ -26,8 +26,8 @@ use common;
use standalone;
use vars qw($MODE %options);
use interactive;
-use mygtk2 qw(gtknew gtkset);
-use ugtk2 qw(:helpers :wrappers :ask :create);
+use mygtk3 qw(gtknew gtkset);
+use ugtk3 qw(:helpers :wrappers :ask :create);
use run_program;
use security::level;
use security::msec;
@@ -43,7 +43,7 @@ use security::l10n;
my $_in = 'interactive'->vnew('su'); # enforce being root
-$ugtk2::wm_icon = "/usr/share/mcc/themes/default/draksec-mdk.png";
+$ugtk3::wm_icon = "/usr/share/mcc/themes/default/draksec-mdk.png";
my ($w);
############################ I18N ###################################
@@ -64,15 +64,15 @@ sub to_i18n { map { $translations{$_} || $_ } @_ }
sub from_i18n { $inv_translations{$_[0]} || $_[0] }
sub resize { gtkset($_[0], width => 50) }
-# factorize this with rpmdrake and harddrake2
+# factorize this with drakrpm and harddrake2
sub wait_msg {
- my $mainw = ugtk2->new(N("Please wait"), (modal => 1, transient => $w->{real_window}));
+ my $mainw = ugtk3->new(N("Please wait"), (modal => 1, transient => $w->{real_window}));
$mainw->{window}->add(gtknew('WrappedLabel', text => $_[0]));
$mainw->{rwindow}->show_all;
- gtkset_mousecursor_wait($mainw->{rwindow}->window);
+ gtkset_mousecursor_wait($mainw->{rwindow}->get_window);
# ugly workaround for gtk+ not displaying subdialog contents:
- Glib::Timeout->add(300, sub { Gtk2->main_quit; 0 });
- Gtk2->main;
+ Glib::Timeout->add(300, sub { Gtk3->main_quit; 0 });
+ Gtk3->main;
$mainw;
}
@@ -84,12 +84,12 @@ sub new_nonedit_combo {
}
#my $msec = security::msec->new;
-$w = ugtk2->new(N("Security Level and Checks"));
+$w = ugtk3->new(N("Security Level and Checks"));
my $window = $w->{window};
############################ MAIN WINDOW ###################################
-# Set different options to Gtk2::Window
+# Set different options to Gtk3::Window
unless ($::isEmbedded) {
$w->{rwindow}->set_position('center');
$w->{rwindow}->set_title("DrakSec");
@@ -98,7 +98,7 @@ unless ($::isEmbedded) {
# Connect the signals
$window->signal_connect('delete_event', sub { $window->destroy });
-$window->signal_connect('destroy', sub { ugtk2->exit });
+$window->signal_connect('destroy', sub { ugtk3->exit });
$window->add(my $vbox = gtkshow(gtknew('VBox')));
@@ -110,43 +110,66 @@ my %progs;
my $auth_string = N("Configure authentication required to access %s tools", N("Mageia"));
my %auth = (
+ default => N("Default"),
no_passwd => N("No password"),
- root_passwd => N("Root password"),
+ root_passwd => N("Administrator password"),
user_passwd => N("User password"),
);
+my $polkit_rules_file = "/etc/polkit-1/rules.d/51-draksec.rules";
+my %overrides = map { if (/case '([^']+)': return polkit\.Result\.(YES|AUTH_ADMIN_KEEP|AUTH_SELF_KEEP)/) { ($1, $2) } } cat_($polkit_rules_file);
+
+
sub default_auth_value {
my ($prog) = @_;
- my $link = readlink("/etc/pam.d/$prog");
- if ($link =~ /mageia-console-auth/) {
- return $auth{no_passwd};
- } elsif ($link =~ /mageia-simple-auth/) {
- my ($user) = cat_("/etc/security/console.apps/$prog") =~ /USER=(.*)/;
- return $auth{root_passwd} if $user eq 'root';
- return $auth{user_passwd} if $user eq '<user>';
- }
+
+ return $auth{no_passwd} if $overrides{$prog} eq 'YES';
+ return $auth{root_passwd} if $overrides{$prog} eq 'AUTH_ADMIN_KEEP';
+ return $auth{user_passwd} if $overrides{$prog} eq 'AUTH_SELF_KEEP';
+ return $auth{default};
}
sub set_auth_value {
my ($prog, $auth) = @_;
if ($auth eq 'no_passwd') {
- symlinkf('../../etc/pam.d/mageia-console-auth', "/etc/pam.d/$prog");
+ $overrides{$prog} = 'YES';
+ } elsif ($auth eq 'root_passwd') {
+ $overrides{$prog} = 'AUTH_ADMIN_KEEP';
+ } elsif ($auth eq 'user_passwd') {
+ $overrides{$prog} = 'AUTH_SELF_KEEP';
} else {
- symlinkf('../../etc/pam.d/mageia-simple-auth', "/etc/pam.d/$prog");
- my $value = $auth eq 'user_passwd' ? '<user>' : 'root';
- substInFile {
- s/^USER=.*/USER=$value/;
- } "/etc/security/console.apps/$prog";
+ delete $overrides{$prog};
}
}
+sub write_rules() {
+ my $contents = '';
+ keys %overrides;
+ while (my ($k, $v) = each %overrides) {
+ $contents .= "case '$k': return polkit.Result.$v;\n" if $k && $v;
+ }
+
+ if ($contents) {
+ output($polkit_rules_file, <<EOF);
+// This file is written by draksec. Do not edit.
+var drakToolAuth = function(tool){switch (tool){
+$contents
+}return polkit.Result.NOT_HANDLED;};
+EOF
+ } else {
+ rm_rf($polkit_rules_file) if -f $polkit_rules_file;
+ }
+
+ system('systemctl', 'try-restart', 'polkit.service');
+}
+
my %descr = (
- rpmdrake => N("Software Management"),
- mageiaupdate => N("%s Update", N("Mageia")),
- 'drakrpm-edit-media' => N("Software Media Manager"),
+ drakrpm => N("Software Management"),
+ 'drakrpm-update' => N("%s Update", N("Mageia")),
+ 'drakrpm-editmedia' => N("Software Media Manager"),
drak3d => N("Configure 3D Desktop effects"),
- xfdrake => N("Graphical Server Configuration"),
+ drakx11 => N("Graphical Server Configuration"),
drakmouse => N("Mouse Configuration"),
drakkeyboard => N("Keyboard Configuration"),
drakups => N("UPS Configuration"),
@@ -162,7 +185,7 @@ my %descr = (
drakfont => N("Import fonts"),
draklog => N("Logs"),
drakxservices => N("Services"),
- userdrake => N("Users"),
+ drakuser => N("Users"),
drakclock => N("Date, Clock & Time Zone Settings"),
drakboot => N("Boot Configuration"),
);
@@ -174,41 +197,39 @@ my %descr = (
####################### OK CANCEL BUTTONS ##################################
gtkpack_($vbox,
0, gtkshow(gtknew('VBox', spacing => 5, children => [
- if_(!$::isEmbedded, 0, Gtk2::Banner->new('/usr/share/mcc/themes/default/drakperm-mdk.png', N("Permissions"))),
+ if_(!$::isEmbedded, 0, Gtk3::Banner->new('/usr/share/mcc/themes/default/drakperm-mdk.png', N("Permissions"))),
0, gtknew('Label', text => $auth_string, alignment => [ 0.5, 0 ])
])),
1, gtkshow(create_scrolled_window(
gtknew('VBox', children => [
- 1, create_packtable(
- $common_opts,
map {
my ($title, $progs) = @$_;
- ([ gtknew('Title2', label => $title), '' ],
+ (0, gtknew('Expander', use_markup => 1, text => mygtk3::title1_to_markup($title), child => create_packtable(
+ $common_opts,
map {
[
gtkshow(gtknew('Label_Left', line_wrap => 1, text => $descr{$_} || $_)),
$progs{$_} = new_nonedit_combo([
- @auth{qw(user_passwd root_passwd no_passwd)}
+ @auth{qw(default user_passwd root_passwd no_passwd)}
],
default_auth_value($_)
#$msec->get_check_value($opt)
)
];
} split(' ', $progs)
- );
+ )));
} (
- [ N("Software Management"), 'rpmdrake mageiaupdate drakrpm-edit-media' ],
- [ N("Hardware"), 'drak3d xfdrake drakmouse drakkeyboard drakups' ],
+ [ N("Software Management"), 'drakrpm drakrpm-update drakrpm-editmedia' ],
+ [ N("Hardware"), 'drak3d drakx11 drakmouse drakkeyboard drakups' ],
[ N("Network"), 'drakconnect drakhosts draknetcenter drakroam drakvpn drakproxy drakgw' ],
- [ N("System"), 'drakauth drakbackup drakfont draklog drakxservices userdrake drakclock' ],
+ [ N("System"), 'drakauth drakfont draklog drakxservices drakuser drakclock' ],
[ N("Boot"), 'drakboot' ],
)
- )
]))),
0, create_okcancel(my $oc =
{
- cancel_clicked => sub { ugtk2->exit(0) },
+ cancel_clicked => sub { ugtk3->exit(0) },
ok_clicked => sub {
log::explanations("Setting up right delegation");
my %rev_auth = reverse %auth;
@@ -217,16 +238,17 @@ gtkpack_($vbox,
set_auth_value($key, $rev_auth{$value});
}
+ write_rules();
remove_wait_msg($w);
- ugtk2->exit(0);
+ ugtk3->exit(0);
}
},
undef, undef, ''
),
);
-$oc->{cancel}->can_default(1);
+$oc->{cancel}->set_can_default(1);
$oc->{cancel}->grab_default;
$w->main;
-ugtk2->exit(0);
+ugtk3->exit(0);