feat: complete Windows client control and recovery paths
This commit is contained in:
@@ -5,12 +5,25 @@ package windowstray
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"encoding/binary"
|
||||
"errors"
|
||||
"fmt"
|
||||
"unicode/utf8"
|
||||
)
|
||||
|
||||
// PipeName is the machine-local service endpoint used by every tray session.
|
||||
// The native implementation creates it with PIPE_REJECT_REMOTE_CLIENTS and
|
||||
// an explicit SYSTEM/Administrators/interactive-user ACL. Keeping the name
|
||||
// here (rather than deriving it from user input) prevents cross-session and
|
||||
// path-confusion bugs.
|
||||
const PipeName = `\\.\pipe\RVBoxClientTrayV1`
|
||||
|
||||
// Handler is invoked by the service after the native adapter has verified the
|
||||
// connecting process token, SID, and session. A response is always encoded
|
||||
// as ActionStatus; requests other than status deliberately carry no payload.
|
||||
type Handler func(context.Context, Peer, Frame) (Frame, error)
|
||||
|
||||
const (
|
||||
protocolVersion uint16 = 1
|
||||
maxFrameBytes = 64 << 10
|
||||
@@ -33,6 +46,8 @@ const (
|
||||
ActionStartService
|
||||
ActionStopService
|
||||
ActionRestartService
|
||||
ActionSetAutomatic
|
||||
ActionSetManual
|
||||
ActionExitTray
|
||||
)
|
||||
|
||||
@@ -115,7 +130,7 @@ func Authorize(peer Peer, action Action) error {
|
||||
switch action {
|
||||
case ActionStatus, ActionOpenConfig, ActionOpenLog, ActionExitTray:
|
||||
return nil
|
||||
case ActionStartService, ActionStopService, ActionRestartService:
|
||||
case ActionStartService, ActionStopService, ActionRestartService, ActionSetAutomatic, ActionSetManual:
|
||||
if peer.Administrator || peer.System {
|
||||
return nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user