Qt
Internal/Contributor docs for the Qt SDK. Note: These are NOT official API docs; those are found at https://doc.qt.io/
Loading...
Searching...
No Matches
qtdbus-security.qdoc
Go to the documentation of this file.
1// Copyright (C) 2026 The Qt Company Ltd.
2// SPDX-License-Identifier: LicenseRef-Qt-Commercial OR GFDL-1.3-no-invariants-only
3
4/*!
5 \page qtdbus-security.html
6 \title Qt D-Bus Security Considerations
7 \ingroup security-considerations
8 \brief Security considerations for applications using Qt D-Bus.
9
10 This page covers security considerations for applications using
11 \l{Qt D-Bus}.
12
13 \section1 Exporting QObjects directly
14
15 \l{QDBusConnection::registerObject()} can export a \l QObject's own
16 slots directly, by passing \l{QDBusConnection::RegisterOption}
17 {ExportNonScriptableSlots} or \l{QDBusConnection::RegisterOption}
18 {ExportAllSlots}. Doing so makes all of that object's invocables
19 accessible remotely, including those inherited from any superclass,
20 not only the ones declared on the object's own class. Only
21 \l QObject's own built-in slots (such as \l{QObject::deleteLater()}
22 {deleteLater()}) are excluded.
23
24 If you need precise, explicit control over which methods are
25 bus-callable, use the adaptor pattern instead. See
26 \l{Using Qt D-Bus Adaptors} for details.
27
28 \section1 Message validation relies on libdbus-1
29
30 Qt D-Bus does not itself validate incoming message size, nesting depth,
31 or type validity. This is delegated to libdbus-1, which rejects
32 malformed messages before Qt D-Bus reads them. Qt D-Bus links against
33 whichever libdbus-1 is installed on the system, not a version it ships
34 or controls, so this validation depends on that system library's
35 version and behavior.
36*/