Table of Contents

FileHashPluginTrustPolicy Class

Definition

Namespace
Bodu.Globalization.Calendar.Plugins
Assembly
Bodu.Globalization.Calendar.Plugins.dll
Package
Bodu.Globalization.Calendar.Plugins 1.0.0
Source
FileHashPluginTrustPolicy.cs

A trust policy that admits plugin assemblies whose SHA-256 file hash matches a digest pinned by the consumer under the candidate's assembly name.

public sealed class FileHashPluginTrustPolicy : IPluginTrustPolicy
Inheritance
FileHashPluginTrustPolicy
Implements
Inherited Members
Extension Methods

Remarks

The consumer pins, per assembly name (matched case-insensitively), the exact SHA-256 digest of the bytes on disk. The loader computes the candidate's hash before this policy runs; the policy asserts equality in constant time.

This gives byte-level tamper resistance without requiring a strong name. It does not roll with plugin versions - pinning a fresh digest when the plugin is updated is the consumer's responsibility. An assembly loaded in memory (no file, so no hash) is always rejected.

Constructors

FileHashPluginTrustPolicy(IReadOnlyDictionary<string, byte[]>)

Initializes a new instance of the FileHashPluginTrustPolicy class.

public FileHashPluginTrustPolicy(IReadOnlyDictionary<string, byte[]> allowedHashesByAssemblyName)

Parameters

allowedHashesByAssemblyName IReadOnlyDictionary<string, byte[]>

The trusted assembly names mapped to their SHA-256 digests.

Remarks

Assembly names are compared case-insensitively. Entries with a blank name or a null digest are ignored; an empty map rejects every assembly.

Exceptions

ArgumentNullException

allowedHashesByAssemblyName is null.

Methods

Evaluate(PluginTrustContext)

Evaluates the trust of a candidate plugin assembly.

public PluginTrustResult Evaluate(PluginTrustContext context)

Parameters

context PluginTrustContext

The metadata describing the candidate assembly.

Returns

PluginTrustResult

The trust result.

Exceptions

ArgumentNullException

context is null.

Applies to

ProductVersions
.NET8, 10