Merge "Fix admin policies in managed profiles" into lmp-dev
This commit is contained in:
committed by
Android (Google) Code Review
commit
2c3886cb34
@@ -1341,7 +1341,7 @@ public class DevicePolicyManager {
|
|||||||
* {@link DeviceAdminInfo#USES_POLICY_RESET_PASSWORD} to be able to call
|
* {@link DeviceAdminInfo#USES_POLICY_RESET_PASSWORD} to be able to call
|
||||||
* this method; if it has not, a security exception will be thrown.
|
* this method; if it has not, a security exception will be thrown.
|
||||||
*
|
*
|
||||||
* Can not be called from a managed profile.
|
* <p>Calling this from a managed profile will throw a security exception.
|
||||||
*
|
*
|
||||||
* @param password The new password for the user.
|
* @param password The new password for the user.
|
||||||
* @param flags May be 0 or {@link #RESET_PASSWORD_REQUIRE_ENTRY}.
|
* @param flags May be 0 or {@link #RESET_PASSWORD_REQUIRE_ENTRY}.
|
||||||
@@ -1887,8 +1887,8 @@ public class DevicePolicyManager {
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Called by an application that is administering the device to disable all cameras
|
* Called by an application that is administering the device to disable all cameras
|
||||||
* on the device. After setting this, no applications will be able to access any cameras
|
* on the device, for this user. After setting this, no applications running as this user
|
||||||
* on the device.
|
* will be able to access any cameras on the device.
|
||||||
*
|
*
|
||||||
* <p>The calling device admin must have requested
|
* <p>The calling device admin must have requested
|
||||||
* {@link DeviceAdminInfo#USES_POLICY_DISABLE_CAMERA} to be able to call
|
* {@link DeviceAdminInfo#USES_POLICY_DISABLE_CAMERA} to be able to call
|
||||||
@@ -1908,8 +1908,8 @@ public class DevicePolicyManager {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Determine whether or not the device's cameras have been disabled either by the current
|
* Determine whether or not the device's cameras have been disabled for this user,
|
||||||
* admin, if specified, or all admins.
|
* either by the current admin, if specified, or all admins.
|
||||||
* @param admin The name of the admin component to check, or null to check if any admins
|
* @param admin The name of the admin component to check, or null to check if any admins
|
||||||
* have disabled the camera
|
* have disabled the camera
|
||||||
*/
|
*/
|
||||||
@@ -2018,6 +2018,8 @@ public class DevicePolicyManager {
|
|||||||
* {@link DeviceAdminInfo#USES_POLICY_DISABLE_KEYGUARD_FEATURES} to be able to call
|
* {@link DeviceAdminInfo#USES_POLICY_DISABLE_KEYGUARD_FEATURES} to be able to call
|
||||||
* this method; if it has not, a security exception will be thrown.
|
* this method; if it has not, a security exception will be thrown.
|
||||||
*
|
*
|
||||||
|
* <p>Calling this from a managed profile will throw a security exception.
|
||||||
|
*
|
||||||
* @param admin Which {@link DeviceAdminReceiver} this request is associated with.
|
* @param admin Which {@link DeviceAdminReceiver} this request is associated with.
|
||||||
* @param which {@link #KEYGUARD_DISABLE_FEATURES_NONE} (default),
|
* @param which {@link #KEYGUARD_DISABLE_FEATURES_NONE} (default),
|
||||||
* {@link #KEYGUARD_DISABLE_WIDGETS_ALL}, {@link #KEYGUARD_DISABLE_SECURE_CAMERA},
|
* {@link #KEYGUARD_DISABLE_WIDGETS_ALL}, {@link #KEYGUARD_DISABLE_SECURE_CAMERA},
|
||||||
|
|||||||
@@ -2924,9 +2924,6 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
enforceCrossUserPermission(userHandle);
|
enforceCrossUserPermission(userHandle);
|
||||||
if ((flags & DevicePolicyManager.WIPE_EXTERNAL_STORAGE) != 0) {
|
|
||||||
enforceNotManagedProfile(userHandle, "wipe external storage");
|
|
||||||
}
|
|
||||||
synchronized (this) {
|
synchronized (this) {
|
||||||
// This API can only be called by an active device admin,
|
// This API can only be called by an active device admin,
|
||||||
// so try to retrieve it to check that the caller is one.
|
// so try to retrieve it to check that the caller is one.
|
||||||
@@ -3526,7 +3523,6 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
enforceCrossUserPermission(userHandle);
|
enforceCrossUserPermission(userHandle);
|
||||||
enforceNotManagedProfile(userHandle, "enable/disable cameras");
|
|
||||||
synchronized (this) {
|
synchronized (this) {
|
||||||
if (who == null) {
|
if (who == null) {
|
||||||
throw new NullPointerException("ComponentName is null");
|
throw new NullPointerException("ComponentName is null");
|
||||||
|
|||||||
Reference in New Issue
Block a user