FileHashPluginTrustPolicy Class
Definition
- Namespace
- Bodu.Globalization.Calendar.Plugins
- Assembly
- Bodu.Globalization.Calendar.Plugins.dll
- Package
- Bodu.Globalization.Calendar.Plugins 1.0.0
A trust policy that admits plugin assemblies whose SHA-256 file hash matches a digest pinned by the consumer under the candidate's assembly name.
public sealed class FileHashPluginTrustPolicy : IPluginTrustPolicy
- Inheritance
-
FileHashPluginTrustPolicy
- Implements
- Inherited Members
- Extension Methods
Remarks
The consumer pins, per assembly name (matched case-insensitively), the exact SHA-256 digest of the bytes on disk. The loader computes the candidate's hash before this policy runs; the policy asserts equality in constant time.
This gives byte-level tamper resistance without requiring a strong name. It does not roll with plugin versions - pinning a fresh digest when the plugin is updated is the consumer's responsibility. An assembly loaded in memory (no file, so no hash) is always rejected.
Constructors
FileHashPluginTrustPolicy(IReadOnlyDictionary<string, byte[]>)
Initializes a new instance of the FileHashPluginTrustPolicy class.
public FileHashPluginTrustPolicy(IReadOnlyDictionary<string, byte[]> allowedHashesByAssemblyName)
Parameters
allowedHashesByAssemblyNameIReadOnlyDictionary<string, byte[]>The trusted assembly names mapped to their SHA-256 digests.
Remarks
Assembly names are compared case-insensitively. Entries with a blank name or a null digest are ignored; an empty map rejects every assembly.
Exceptions
- ArgumentNullException
allowedHashesByAssemblyNameis null.
Methods
Evaluate(PluginTrustContext)
Evaluates the trust of a candidate plugin assembly.
public PluginTrustResult Evaluate(PluginTrustContext context)
Parameters
contextPluginTrustContextThe metadata describing the candidate assembly.
Returns
- PluginTrustResult
The trust result.
Exceptions
- ArgumentNullException
contextis null.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |