agama/service/share/dbus.conf
Martin Vidner 4da19c7689 [service] D-Bus policy: don't let non-root even Introspect us
It might seem courteous to allow non-root at least introspect our API
via d-feet, since the documentation is public anyway and this would be
a guaranteed up-to-date version, right?

But our services do a lot of probing at startup, so we might have a bug
where we would modify something as root when triggered by a curious
introspector. Better not allow it.

Let them `sudo -E d-feet`.
2022-11-16 11:18:15 +01:00

25 lines
1 KiB
Text

<!DOCTYPE busconfig PUBLIC
"-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN"
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
<busconfig>
<!-- only root can own the services -->
<policy user="root">
<allow own="org.opensuse.DInstaller" />
<allow own="org.opensuse.DInstaller.Language" />
<allow own="org.opensuse.DInstaller.Questions" />
<allow own="org.opensuse.DInstaller.Software" />
<allow own="org.opensuse.DInstaller.Storage" />
<allow own="org.opensuse.DInstaller.Users" />
</policy>
<!-- only root can send anything to the services -->
<policy user="root">
<allow send_destination="org.opensuse.DInstaller" />
<allow send_destination="org.opensuse.DInstaller.Language" />
<allow send_destination="org.opensuse.DInstaller.Questions" />
<allow send_destination="org.opensuse.DInstaller.Software" />
<allow send_destination="org.opensuse.DInstaller.Storage" />
<allow send_destination="org.opensuse.DInstaller.Users" />
</policy>
</busconfig>