Merge "Prevend user spoofing in isRequestPinItemSupported" into sc-dev
This commit is contained in:
committed by
Android (Google) Code Review
commit
11f6a1013f
@@ -1664,6 +1664,19 @@ public class ShortcutService extends IShortcutService.Stub {
|
||||
mContext.enforceCallingPermission(permission, message);
|
||||
}
|
||||
|
||||
private void verifyCallerUserId(@UserIdInt int userId) {
|
||||
if (isCallerSystem()) {
|
||||
return; // no check
|
||||
}
|
||||
|
||||
final int callingUid = injectBinderCallingUid();
|
||||
|
||||
// Otherwise, make sure the arguments are valid.
|
||||
if (UserHandle.getUserId(callingUid) != userId) {
|
||||
throw new SecurityException("Invalid user-ID");
|
||||
}
|
||||
}
|
||||
|
||||
private void verifyCaller(@NonNull String packageName, @UserIdInt int userId) {
|
||||
Preconditions.checkStringNotEmpty(packageName, "packageName");
|
||||
|
||||
@@ -2847,6 +2860,8 @@ public class ShortcutService extends IShortcutService.Stub {
|
||||
|
||||
@Override
|
||||
public boolean isRequestPinItemSupported(int callingUserId, int requestType) {
|
||||
verifyCallerUserId(callingUserId);
|
||||
|
||||
final long token = injectClearCallingIdentity();
|
||||
try {
|
||||
return mShortcutRequestPinProcessor
|
||||
|
||||
Reference in New Issue
Block a user