mirror of
https://gitlab.com/mishakmak/pam-fprint-grosshack.git
synced 2026-04-08 20:03:34 +02:00
In the way the rule is currently set it would allow clients to send messages with the fprintd interface to any other service, while we only allow them to be redirected to fprintd itself. This was causing a debian linter failure [1]. [1] https://lintian.debian.org/tags/dbus-policy-without-send-destination.html
20 lines
542 B
XML
20 lines
542 B
XML
<?xml version="1.0" encoding="UTF-8"?> <!-- -*- XML -*- -->
|
|
|
|
<!DOCTYPE busconfig PUBLIC
|
|
"-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN"
|
|
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
|
|
<busconfig>
|
|
|
|
<!-- Only root can own the service -->
|
|
<policy user="root">
|
|
<allow own="net.reactivated.Fprint"/>
|
|
</policy>
|
|
|
|
<!-- Anyone can talk to the service -->
|
|
<policy context="default">
|
|
<allow send_destination="net.reactivated.Fprint"
|
|
send_interface="net.reactivated.Fprint"/>
|
|
</policy>
|
|
|
|
</busconfig>
|