From 51e41ad887a2e30a1366f0a3b4750f0204912b8e Mon Sep 17 00:00:00 2001 From: Clara Bayarri Date: Thu, 11 Feb 2016 17:48:53 +0000 Subject: [PATCH] Add support for current failed lock attempts and max attempts This is needed from Settings to show a message informing the user of the number of attempts before their work profile gets wiped when using ConfirmDeviceCredentials. Bug: 26677759 Change-Id: I4b16f7dc2f415d0ce0215a3b7a646f98fabece33 --- .../android/app/admin/DevicePolicyManager.java | 16 +++++++++++++++- .../internal/widget/LockPatternUtils.java | 9 +++++++++ .../devicepolicy/DevicePolicyManagerService.java | 11 +++++++---- 3 files changed, 31 insertions(+), 5 deletions(-) diff --git a/core/java/android/app/admin/DevicePolicyManager.java b/core/java/android/app/admin/DevicePolicyManager.java index 02eb115175fd1..dd54c7b75388e 100644 --- a/core/java/android/app/admin/DevicePolicyManager.java +++ b/core/java/android/app/admin/DevicePolicyManager.java @@ -1826,9 +1826,23 @@ public class DevicePolicyManager { * this method; if it has not, a security exception will be thrown. */ public int getCurrentFailedPasswordAttempts() { + return getCurrentFailedPasswordAttempts(myUserId()); + } + + /** + * Retrieve the number of times the given user has failed at entering a + * password since that last successful password entry. + * + *

The calling device admin must have requested + * {@link DeviceAdminInfo#USES_POLICY_WATCH_LOGIN} to be able to call this method; if it has + * not and it is not the system uid, a security exception will be thrown. + * + * @hide + */ + public int getCurrentFailedPasswordAttempts(int userHandle) { if (mService != null) { try { - return mService.getCurrentFailedPasswordAttempts(myUserId(), mParentInstance); + return mService.getCurrentFailedPasswordAttempts(userHandle, mParentInstance); } catch (RemoteException e) { Log.w(TAG, REMOTE_EXCEPTION_MESSAGE, e); } diff --git a/core/java/com/android/internal/widget/LockPatternUtils.java b/core/java/com/android/internal/widget/LockPatternUtils.java index e239852673e88..cbc735fc065c2 100644 --- a/core/java/com/android/internal/widget/LockPatternUtils.java +++ b/core/java/com/android/internal/widget/LockPatternUtils.java @@ -283,6 +283,15 @@ public class LockPatternUtils { getTrustManager().reportUnlockAttempt(true /* authenticated */, userId); } + public int getCurrentFailedPasswordAttempts(int userId) { + return getDevicePolicyManager().getCurrentFailedPasswordAttempts(userId); + } + + public int getMaximumFailedPasswordsForWipe(int userId) { + return getDevicePolicyManager().getMaximumFailedPasswordsForWipe( + null /* componentName */, userId); + } + /** * Check to see if a pattern matches the saved pattern. * If pattern matches, return an opaque attestation that the challenge diff --git a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java index 3fb5a0d39b84c..155ff7b578d6a 100644 --- a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java +++ b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java @@ -3527,11 +3527,14 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub { @Override public int getCurrentFailedPasswordAttempts(int userHandle, boolean parent) { + enforceFullCrossUsersPermission(userHandle); synchronized (this) { - // This API can only be called by an active device admin, - // so try to retrieve it to check that the caller is one. - getActiveAdminForCallerLocked( - null, DeviceAdminInfo.USES_POLICY_WATCH_LOGIN, parent); + if (!isCallerWithSystemUid()) { + // This API can only be called by an active device admin, + // so try to retrieve it to check that the caller is one. + getActiveAdminForCallerLocked( + null, DeviceAdminInfo.USES_POLICY_WATCH_LOGIN, parent); + } DevicePolicyData policy = getUserDataUnchecked(getCredentialOwner(userHandle, parent));