New API: DevicePolicyManager.listForegroundAffiliatedUsers()

Bug: 173541467
Bug: 179163496

Test: m update-api

Test: atest CtsDevicePolicyManagerTestCases:com.android.cts.devicepolicy.DeviceOwnerTest#testListForegroundAffiliatedUsers_onlyForegroundUser,testListForegroundAffiliatedUsers_extraUser,testListForegroundAffiliatedUsers_notDeviceOwner,testListForegroundAffiliatedUsers_notAffiliated,testListForegroundAffiliatedUsers_affiliated

Change-Id: I520dc35da627d7cb89f6ff2d7010fc04af1b01f7
This commit is contained in:
Felipe Leme
2021-02-02 10:56:19 -08:00
parent 0845888808
commit 002e214afd
4 changed files with 51 additions and 5 deletions

View File

@@ -7104,6 +7104,7 @@ package android.app.admin {
method public boolean isUniqueDeviceAttestationSupported();
method public boolean isUsbDataSignalingEnabled();
method public boolean isUsingUnifiedPassword(@NonNull android.content.ComponentName);
method @NonNull public java.util.List<android.os.UserHandle> listForegroundAffiliatedUsers();
method public void lockNow();
method public void lockNow(int);
method public int logoutUser(@NonNull android.content.ComponentName);

View File

@@ -13357,6 +13357,7 @@ public class DevicePolicyManager {
}
}
}
/**
* Returns true if the caller is running on a device where the admin can grant
* permissions related to device sensors.
@@ -13459,4 +13460,22 @@ public class DevicePolicyManager {
}
return false;
}
/**
* Gets the list of {@link #isAffiliatedUser() affiliated} users running on foreground.
*
* @return list of {@link #isAffiliatedUser() affiliated} users running on foreground.
*
* @throws SecurityException if the calling application is not a device owner
*/
@NonNull
public List<UserHandle> listForegroundAffiliatedUsers() {
if (mService == null) return Collections.emptyList();
try {
return mService.listForegroundAffiliatedUsers();
} catch (RemoteException re) {
throw re.rethrowFromSystemServer();
}
}
}

View File

@@ -507,4 +507,6 @@ interface IDevicePolicyManager {
boolean isUsbDataSignalingEnabled(String callerPackage);
boolean isUsbDataSignalingEnabledForUser(int userId);
boolean canUsbDataSignalingBeDisabled();
List<UserHandle> listForegroundAffiliatedUsers();
}

View File

@@ -6450,7 +6450,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
private void forceWipeUser(int userId, String wipeReasonForUser, boolean wipeSilently) {
boolean success = false;
try {
if (getCurrentForegroundUser() == userId) {
if (getCurrentForegroundUserId() == userId) {
mInjector.getIActivityManager().switchUser(UserHandle.USER_SYSTEM);
}
@@ -7910,7 +7910,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
Slog.i(LOG_TAG, "Device owner set: " + admin + " on user " + userId);
if (mInjector.userManagerIsHeadlessSystemUserMode()) {
int currentForegroundUser = getCurrentForegroundUser();
int currentForegroundUser = getCurrentForegroundUserId();
Slog.i(LOG_TAG, "setDeviceOwner(): setting " + admin
+ " as profile owner on user " + currentForegroundUser);
// Sets profile owner on current foreground user since
@@ -9041,7 +9041,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
return UserHandle.isSameApp(caller.getUid(), Process.SHELL_UID);
}
private @UserIdInt int getCurrentForegroundUser() {
private @UserIdInt int getCurrentForegroundUserId() {
try {
return mInjector.getIActivityManager().getCurrentUser().id;
} catch (RemoteException e) {
@@ -9050,6 +9050,25 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
return UserHandle.USER_NULL;
}
@Override
public List<UserHandle> listForegroundAffiliatedUsers() {
checkIsDeviceOwner(getCallerIdentity());
int userId = mInjector.binderWithCleanCallingIdentity(() -> getCurrentForegroundUserId());
boolean isAffiliated;
synchronized (getLockObject()) {
isAffiliated = isUserAffiliatedWithDeviceLocked(userId);
}
if (!isAffiliated) return Collections.emptyList();
List<UserHandle> users = new ArrayList<>(1);
users.add(UserHandle.of(userId));
return users;
}
protected int getProfileParentId(int userHandle) {
return mInjector.binderWithCleanCallingIdentity(() -> {
UserInfo parentUser = mUserManager.getProfileParent(userHandle);
@@ -12861,7 +12880,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
return CODE_NONSYSTEM_USER_EXISTS;
}
int currentForegroundUser = getCurrentForegroundUser();
int currentForegroundUser = getCurrentForegroundUserId();
if (callingUserId != currentForegroundUser
&& mInjector.userManagerIsHeadlessSystemUserMode()
&& currentForegroundUser == UserHandle.USER_SYSTEM) {
@@ -12957,6 +12976,11 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
return CODE_OK;
}
private void checkIsDeviceOwner(CallerIdentity caller) {
Preconditions.checkCallAuthorization(isDeviceOwner(caller), caller.getUid()
+ " is not device owner");
}
private ComponentName getOwnerComponent(String packageName, int userId) {
if (isDeviceOwnerPackage(packageName, userId)) {
return mOwners.getDeviceOwnerComponent();
@@ -15447,7 +15471,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
private boolean isLockTaskFeatureEnabled(int lockTaskFeature) throws RemoteException {
//TODO(b/175285301): Explicitly get the user's identity to check.
int lockTaskFeatures =
getUserData(getCurrentForegroundUser()).mLockTaskFeatures;
getUserData(getCurrentForegroundUserId()).mLockTaskFeatures;
return (lockTaskFeatures & lockTaskFeature) == lockTaskFeature;
}