From c8ff1c0453ba57432a743a333ec1723c5a1c3637 Mon Sep 17 00:00:00 2001 From: Zorg Date: Fri, 1 Apr 2016 15:06:47 -0400 Subject: [PATCH] Don't bring up an authorized dialog during cleanup If permissions are abnormal during cleanup or somewhere along the lines, it may be possible to bring up authorization dialog that is not really needed. Prevent this from happening. We would want to restrict authorization from being possible anyway when not needed. --- Sparkle/SUFileManager.h | 9 +++++++++ Sparkle/SUFileManager.m | 8 +++++++- Sparkle/SUPlainInstaller.m | 9 ++++++--- 3 files changed, 22 insertions(+), 4 deletions(-) diff --git a/Sparkle/SUFileManager.h b/Sparkle/SUFileManager.h index f6897ced..c3d2acd7 100644 --- a/Sparkle/SUFileManager.h +++ b/Sparkle/SUFileManager.h @@ -25,6 +25,15 @@ */ + (instancetype)fileManagerAllowingAuthorization:(BOOL)allowsAuthorization; +/** + * Returns a file manager that allows or disallows authorizing for file operations based on the current file manager + * @return A file manager instance that can perform authorized operations if the current file manager has already performed them. + * If the current file manager instance hasn't yet performed authorized operations, then neither can the instance returned by this method + * + * This may return a newly created file manager or re-use the existing file manager depending on the current authorization rights. + */ +- (instancetype)fileManagerByPreservingAuthorizationRights; + /** * Creates a temporary directory on the same volume as a provided URL * @param preferredName A name that may be used when creating the temporary directory. Note that in the uncommon case this name is used, the temporary directory will be created inside the directory pointed by appropriateURL diff --git a/Sparkle/SUFileManager.m b/Sparkle/SUFileManager.m index 68bceae0..f13e3ffd 100644 --- a/Sparkle/SUFileManager.m +++ b/Sparkle/SUFileManager.m @@ -88,12 +88,18 @@ static BOOL SUMakeRefFromURL(NSURL *url, FSRef *ref, NSError **error) { return self; } - + (instancetype)fileManagerAllowingAuthorization:(BOOL)allowsAuthorization { return [[self alloc] initAllowingAuthorization:allowsAuthorization]; } +- (instancetype)fileManagerByPreservingAuthorizationRights +{ + // Check if we don't allow authorization, or that we haven't needed to authorize yet, to create or re-use a + // file manager instance with these restrictions + return (_allowsAuthorization && _auth != NULL) ? self : [SUFileManager fileManagerAllowingAuthorization:NO]; +} + // Acquires an authorization reference which is intended to be used for future authorized file operations - (BOOL)_acquireAuthorizationWithError:(NSError *__autoreleasing *)error { diff --git a/Sparkle/SUPlainInstaller.m b/Sparkle/SUPlainInstaller.m index 70a7ded9..3e9f1b8f 100644 --- a/Sparkle/SUPlainInstaller.m +++ b/Sparkle/SUPlainInstaller.m @@ -139,15 +139,18 @@ return NO; } + // From here on out, we don't really need to bring up authorization if we haven't done so prior + SUFileManager *constrainedFileManager = [fileManager fileManagerByPreservingAuthorizationRights]; + // Cleanup: move the old app to the trash NSError *trashError = nil; - if (![fileManager moveItemAtURLToTrash:oldTempURL error:&trashError]) { + if (![constrainedFileManager moveItemAtURLToTrash:oldTempURL error:&trashError]) { SULog(@"Failed to move %@ to trash with error %@", oldTempURL, trashError); } - [fileManager removeItemAtURL:tempOldDirectoryURL error:NULL]; + [constrainedFileManager removeItemAtURL:tempOldDirectoryURL error:NULL]; - [fileManager removeItemAtURL:tempNewDirectoryURL error:NULL]; + [constrainedFileManager removeItemAtURL:tempNewDirectoryURL error:NULL]; return YES; }