aboutsummaryrefslogtreecommitdiff
path: root/data/org.ayatana.AccountsService.Sound.policy
diff options
context:
space:
mode:
authorMike Gabriel <mike.gabriel@das-netzwerkteam.de>2017-10-27 01:13:52 +0000
committerMike Gabriel <mike.gabriel@das-netzwerkteam.de>2017-10-27 01:17:08 +0000
commit01876018ef6af29a28a82c802fcc5de959e8109b (patch)
tree5e7d418d40038025b9bb16ef8be3908b811674bb /data/org.ayatana.AccountsService.Sound.policy
parentbc4bedc29d859040bc6ba052a5212a14a15c3578 (diff)
downloadayatana-indicator-sound-01876018ef6af29a28a82c802fcc5de959e8109b.tar.gz
ayatana-indicator-sound-01876018ef6af29a28a82c802fcc5de959e8109b.tar.bz2
ayatana-indicator-sound-01876018ef6af29a28a82c802fcc5de959e8109b.zip
data/org.ayatana.AccountsService.Sound: Use Ayatana namespace.
* Namespace switch from com.ubuntu to org.ayatana. * Add AccountsServer interface for the greeter. Obtained from accountsservice-ubuntu-schemas and adapted.
Diffstat (limited to 'data/org.ayatana.AccountsService.Sound.policy')
-rw-r--r--data/org.ayatana.AccountsService.Sound.policy24
1 files changed, 24 insertions, 0 deletions
diff --git a/data/org.ayatana.AccountsService.Sound.policy b/data/org.ayatana.AccountsService.Sound.policy
new file mode 100644
index 0000000..7140498
--- /dev/null
+++ b/data/org.ayatana.AccountsService.Sound.policy
@@ -0,0 +1,24 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<policyconfig>
+ <!-- Same as org.freedesktop.accounts.user-administration, but we override
+ settings for the lightdm user in a pkla file. -->
+ <action id="org.ayatana.AccountsService.GreeterChangeAny">
+ <defaults>
+ <allow_any>no</allow_any>
+ <allow_inactive>no</allow_inactive>
+ <allow_active>auth_admin_keep</allow_active>
+ </defaults>
+ </action>
+
+ <!-- Normally anyone can read these, but for a little bit extra lock down,
+ disallow all access, but we'll let the lightdm user read them via the
+ pkla override. -->
+ <action id="org.ayatana.AccountsService.GreeterReadAny">
+ <defaults>
+ <allow_any>no</allow_any>
+ <allow_inactive>no</allow_inactive>
+ <allow_active>no</allow_active>
+ </defaults>
+ </action>
+</policyconfig>