Loading...
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 | /* * Copyright (c) 2000 Apple Computer, Inc. All rights reserved. * * @APPLE_LICENSE_HEADER_START@ * * Copyright (c) 1999-2003 Apple Computer, Inc. All Rights Reserved. * * This file contains Original Code and/or Modifications of Original Code * as defined in and that are subject to the Apple Public Source License * Version 2.0 (the 'License'). You may not use this file except in * compliance with the License. Please obtain a copy of the License at * http://www.opensource.apple.com/apsl/ and read it before using this * file. * * The Original Code and all software distributed under the License are * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. * Please see the License for the specific language governing rights and * limitations under the License. * * @APPLE_LICENSE_HEADER_END@ */ #include <sys/param.h> #include <sys/time.h> #include <sys/resource.h> #include <err.h> #include <errno.h> #include <grp.h> #include <paths.h> #include <stdio.h> #include <stdlib.h> #include <string.h> #include <syslog.h> #include <unistd.h> #include "authentication.h" int isAuthenticatedAsAdministrator(void) { if (isAuthenticatedAsRoot()) { return 1; } // otherwise ... return isAuthenticatedAsAdministratorForTask(0); } int isAuthenticatedAsAdministratorForTask(int taskNum) { int admin = 0; uid_t ruid; if (isAuthenticatedAsRoot()) { return 1; } ruid = getuid(); if (ruid) { gid_t groups[NGROUPS_MAX]; int numgroups; /* * Only allow those in group taskNum group (By default admin) to authenticate. */ if ((numgroups = getgroups(NGROUPS_MAX, groups)) > 0) { int i; gid_t admingid = 0; struct group *admingroup; if ((admingroup = getgrnam(groupNameForTask(taskNum))) != NULL) { admingid = admingroup->gr_gid; for (i = 0; i < numgroups; i++) { if (groups[i] == admingid) { admin = 1; break; } } } } } // otherwise return admin; } int isAuthenticatedAsRoot(void) { if (getuid() == 0) { return 1; } return 0; } char *groupNameForTask(int taskNum) { if (taskNum == 0) return "admin"; return "admin"; } |