Read user certificates only from the session of the active profile's owner

This commit is contained in:
Viktor Liu
2026-10-02 12:32:27 +02:00
parent e0b6a38aa2
commit a91fe94ada
10 changed files with 196 additions and 40 deletions
@@ -5,6 +5,7 @@ package certproof
import (
"bytes"
"fmt"
"strconv"
"sync"
"github.com/ebitengine/purego"
@@ -69,6 +70,13 @@ func (u ConsoleUser) hasDesktop() bool {
return u.UID != 0
}
// isOwner reports whether the console user is owner, the account of the active profile,
// which is recorded as a short user name or, for an account without one, a numeric uid.
// With no owner the console user counts, as macOS has a single console user.
func (u ConsoleUser) isOwner(owner string) bool {
return owner == "" || owner == u.Name || owner == strconv.FormatUint(uint64(u.UID), 10)
}
func cfString(str uintptr) string {
buf := make([]byte, consoleNameBufSize)
if !cfStringGetCString(str, &buf[0], len(buf), encodingUTF8) {