Qt
Internal/Contributor docs for the Qt SDK. Note: These are NOT official API docs; those are found at https://doc.qt.io/
Loading...
Searching...
No Matches
qtpositioning-security.qdoc
Go to the documentation of this file.
1
// Copyright (C) 2026 The Qt Company Ltd.
2
// SPDX-License-Identifier: LicenseRef-Qt-Commercial OR GFDL-1.3-no-invariants-only
3
4
/*!
5
\page qtpositioning-security.html
6
\title Qt Positioning Security Considerations
7
\ingroup security-considerations
8
\brief How to prevent security problems when using Qt Positioning.
9
10
This page highlights potential security issues that can arise when using
11
the module and suggests how to avoid them.
12
13
\section1 Plugins
14
15
The module uses a \l {Qt Positioning Plugins}{plugin system} to select a
16
backend at runtime. This selection can be based either on the platform or on
17
an explicit request from the application.
18
19
\section2 Prevent loading malicious plugins
20
21
The plugin system gives an attacker an opportunity to get a malicious plugin
22
loaded into the application. Because a plugin is a shared library running in
23
the application's process, it can execute arbitrary code with the
24
application's privileges.
25
26
The \l {Deploying Plugins#The Plugin Directory}{Qt plugins documentation}
27
gives an overview of how plugins are located and loaded, and of what
28
affects the lookup paths. Making sure that no untrusted plugin is
29
reachable through those paths is the responsibility of the application
30
developer. When deploying an application, verify that:
31
32
\list
33
\li The Qt installation and application directories cannot be modified
34
by untrusted users.
35
\li If the application uses a \c {qt.conf} file, its contents are
36
correct, and untrusted users cannot modify the file.
37
\li Untrusted parties cannot control the process environment, because
38
variables such as \c {QT_PLUGIN_PATH} extend the plugin lookup
39
paths.
40
\endlist
41
42
An application can also call \l {QCoreApplication::setLibraryPaths()} at
43
startup to set the lookup paths explicitly. The paths set this way still
44
need to be protected from modification by untrusted users.
45
46
\section2 Avoid test mode in production
47
48
To keep automated tests deterministic, the module ignores all production
49
plugins when the \c {QT_QTESTLIB_RUNNING} environment variable is set. As a
50
result, no position or satellite source is available to the application.
51
Make sure that this variable is not set in a production environment.
52
*/
qtpositioning
src
positioning
doc
src
qtpositioning-security.qdoc
Generated on
for Qt by
1.16.1