2022-12-21 05:37:03 +01:00
|
|
|
|
/*
|
2024-03-05 18:13:14 +01:00
|
|
|
|
* Copyright (c) 2023 ETH Zürich, IT Services
|
2022-12-21 05:37:03 +01:00
|
|
|
|
*
|
|
|
|
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
|
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
|
|
|
*/
|
|
|
|
|
|
2023-09-01 12:28:03 +02:00
|
|
|
|
using System;
|
|
|
|
|
using System.Linq;
|
2022-12-21 05:37:03 +01:00
|
|
|
|
using SafeExamBrowser.Core.Contracts.OperationModel;
|
|
|
|
|
using SafeExamBrowser.Core.Contracts.OperationModel.Events;
|
|
|
|
|
using SafeExamBrowser.I18n.Contracts;
|
|
|
|
|
using SafeExamBrowser.Logging.Contracts;
|
|
|
|
|
using SafeExamBrowser.SystemComponents.Contracts.Registry;
|
|
|
|
|
|
|
|
|
|
namespace SafeExamBrowser.Runtime.Operations
|
|
|
|
|
{
|
|
|
|
|
internal class SessionIntegrityOperation : SessionOperation
|
|
|
|
|
{
|
2023-11-01 09:23:37 +01:00
|
|
|
|
private static readonly string USER_PATH = $@"{Environment.ExpandEnvironmentVariables("%LocalAppData%")}\Microsoft\Windows\Cursors\";
|
|
|
|
|
private static readonly string SYSTEM_PATH = $@"{Environment.ExpandEnvironmentVariables("%SystemRoot%")}\Cursors\";
|
|
|
|
|
|
2022-12-21 05:37:03 +01:00
|
|
|
|
private readonly ILogger logger;
|
|
|
|
|
private readonly IRegistry registry;
|
|
|
|
|
|
|
|
|
|
public override event ActionRequiredEventHandler ActionRequired { add { } remove { } }
|
|
|
|
|
public override event StatusChangedEventHandler StatusChanged;
|
|
|
|
|
|
|
|
|
|
public SessionIntegrityOperation(ILogger logger, IRegistry registry, SessionContext context) : base(context)
|
|
|
|
|
{
|
|
|
|
|
this.logger = logger;
|
|
|
|
|
this.registry = registry;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public override OperationResult Perform()
|
|
|
|
|
{
|
2024-03-05 16:39:21 +01:00
|
|
|
|
var success = true;
|
2022-12-21 05:37:03 +01:00
|
|
|
|
|
2024-03-05 16:39:21 +01:00
|
|
|
|
StatusChanged?.Invoke(TextKey.OperationStatus_VerifySessionIntegrity);
|
2023-09-01 12:28:03 +02:00
|
|
|
|
|
2024-03-05 16:39:21 +01:00
|
|
|
|
success &= VerifyCursorConfiguration();
|
|
|
|
|
success &= VerifyEaseOfAccessConfiguration();
|
2023-09-01 12:28:03 +02:00
|
|
|
|
|
|
|
|
|
return success ? OperationResult.Success : OperationResult.Failed;
|
2022-12-21 05:37:03 +01:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public override OperationResult Repeat()
|
|
|
|
|
{
|
2024-03-05 16:39:21 +01:00
|
|
|
|
var success = true;
|
2022-12-21 05:37:03 +01:00
|
|
|
|
|
2024-03-05 16:39:21 +01:00
|
|
|
|
StatusChanged?.Invoke(TextKey.OperationStatus_VerifySessionIntegrity);
|
2023-09-01 12:28:03 +02:00
|
|
|
|
|
2024-03-05 16:39:21 +01:00
|
|
|
|
success &= VerifyCursorConfiguration();
|
|
|
|
|
success &= VerifyEaseOfAccessConfiguration();
|
2023-09-01 12:28:03 +02:00
|
|
|
|
|
|
|
|
|
return success ? OperationResult.Success : OperationResult.Failed;
|
2022-12-21 05:37:03 +01:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public override OperationResult Revert()
|
|
|
|
|
{
|
|
|
|
|
return OperationResult.Success;
|
|
|
|
|
}
|
|
|
|
|
|
2023-09-01 12:28:03 +02:00
|
|
|
|
private bool VerifyCursorConfiguration()
|
|
|
|
|
{
|
|
|
|
|
var success = true;
|
|
|
|
|
|
2024-03-05 16:39:21 +01:00
|
|
|
|
if (Context.Next.Settings.Security.VerifyCursorConfiguration)
|
2023-09-01 12:28:03 +02:00
|
|
|
|
{
|
2024-03-05 16:39:21 +01:00
|
|
|
|
logger.Info($"Attempting to verify cursor configuration...");
|
2023-09-01 12:28:03 +02:00
|
|
|
|
|
2024-03-05 16:39:21 +01:00
|
|
|
|
success = registry.TryGetNames(RegistryValue.UserHive.Cursors_Key, out var cursors);
|
2023-09-01 12:28:03 +02:00
|
|
|
|
|
2024-03-05 16:39:21 +01:00
|
|
|
|
if (success)
|
|
|
|
|
{
|
|
|
|
|
foreach (var cursor in cursors.Where(c => !string.IsNullOrWhiteSpace(c)))
|
|
|
|
|
{
|
|
|
|
|
success &= VerifyCursor(cursor);
|
2023-09-01 12:28:03 +02:00
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (success)
|
|
|
|
|
{
|
|
|
|
|
logger.Info("Cursor configuration successfully verified.");
|
|
|
|
|
}
|
2024-03-05 16:39:21 +01:00
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
logger.Warn("Failed to verify cursor configuration or configuration is compromised! Aborting session initialization...");
|
|
|
|
|
}
|
2023-09-01 12:28:03 +02:00
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
{
|
2024-03-05 16:39:21 +01:00
|
|
|
|
logger.Debug("Verification of cursor configuration is disabled.");
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return success;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
private bool VerifyCursor(string cursor)
|
|
|
|
|
{
|
|
|
|
|
var success = true;
|
|
|
|
|
|
|
|
|
|
success &= registry.TryRead(RegistryValue.UserHive.Cursors_Key, cursor, out var value);
|
|
|
|
|
success &= !(value is string) || (value is string path && (string.IsNullOrWhiteSpace(path) || IsValidCursorPath(path)));
|
|
|
|
|
|
|
|
|
|
if (!success)
|
|
|
|
|
{
|
|
|
|
|
if (value != default)
|
|
|
|
|
{
|
|
|
|
|
logger.Warn($"Configuration of cursor '{cursor}' is compromised: '{value}'!");
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
logger.Warn($"Failed to verify configuration of cursor '{cursor}'!");
|
|
|
|
|
}
|
2023-09-01 12:28:03 +02:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return success;
|
|
|
|
|
}
|
|
|
|
|
|
2023-11-01 09:23:37 +01:00
|
|
|
|
private bool IsValidCursorPath(string path)
|
|
|
|
|
{
|
|
|
|
|
return path.StartsWith(USER_PATH, StringComparison.OrdinalIgnoreCase) || path.StartsWith(SYSTEM_PATH, StringComparison.OrdinalIgnoreCase);
|
|
|
|
|
}
|
|
|
|
|
|
2023-09-01 12:28:03 +02:00
|
|
|
|
private bool VerifyEaseOfAccessConfiguration()
|
2022-12-21 05:37:03 +01:00
|
|
|
|
{
|
2023-09-01 12:28:03 +02:00
|
|
|
|
var success = false;
|
2022-12-21 05:37:03 +01:00
|
|
|
|
|
|
|
|
|
logger.Info($"Attempting to verify ease of access configuration...");
|
|
|
|
|
|
2022-12-21 05:50:26 +01:00
|
|
|
|
if (registry.TryRead(RegistryValue.MachineHive.EaseOfAccess_Key, RegistryValue.MachineHive.EaseOfAccess_Name, out var value))
|
2022-12-21 05:37:03 +01:00
|
|
|
|
{
|
2023-12-28 16:11:26 +01:00
|
|
|
|
if (value is string s && string.IsNullOrWhiteSpace(s))
|
2022-12-21 05:37:03 +01:00
|
|
|
|
{
|
2023-09-01 12:28:03 +02:00
|
|
|
|
success = true;
|
2022-12-21 05:37:03 +01:00
|
|
|
|
logger.Info("Ease of access configuration successfully verified.");
|
|
|
|
|
}
|
|
|
|
|
else if (!Context.Next.Settings.Service.IgnoreService)
|
|
|
|
|
{
|
2023-09-01 12:28:03 +02:00
|
|
|
|
success = true;
|
2022-12-21 05:37:03 +01:00
|
|
|
|
logger.Info($"Ease of access configuration is compromised ('{value}'), but service will be active in the next session.");
|
|
|
|
|
}
|
2023-11-23 18:00:35 +01:00
|
|
|
|
else if (Context.Current?.Settings.Service.IgnoreService == false)
|
|
|
|
|
{
|
|
|
|
|
success = true;
|
|
|
|
|
logger.Info($"Ease of access configuration is set ('{value}'), but service was active in the current session.");
|
|
|
|
|
}
|
2022-12-21 05:37:03 +01:00
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
logger.Warn($"Ease of access configuration is compromised: '{value}'! Aborting session initialization...");
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
{
|
2023-12-28 16:11:26 +01:00
|
|
|
|
success = true;
|
|
|
|
|
logger.Info("Ease of access configuration successfully verified (value does not exist).");
|
2022-12-21 05:37:03 +01:00
|
|
|
|
}
|
|
|
|
|
|
2023-09-01 12:28:03 +02:00
|
|
|
|
return success;
|
2022-12-21 05:37:03 +01:00
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|