Merge "Stop managed profile owner granting READ_SMS" into sc-dev am: 28e4c5d57a

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15371691

Change-Id: I0d9242aa9682a7bfa8ff972ebd4356160e23fce3
This commit is contained in:
Rubin Xu
2021-07-28 18:29:27 +00:00
committed by Automerger Merge Worker

View File

@@ -10997,6 +10997,16 @@ public class DevicePolicyManager {
* {@link #EXTRA_PROVISIONING_SENSORS_PERMISSION_GRANT_OPT_OUT} in the provisioning parameters.
* In that case the device owner's control will be limited do denying these permissions.
* <p>
* NOTE: On devices running {@link android.os.Build.VERSION_CODES#S} and above, control over
* the following permissions are restricted for managed profile owners:
* <ul>
* <li>Manifest.permission.READ_SMS</li>
* </ul>
* <p>
* A managed profile owner may not grant these permissions (i.e. call this method with any of
* the permissions listed above and {@code grantState} of
* {@code #PERMISSION_GRANT_STATE_GRANTED}), but may deny them.
* <p>
* Attempts by the admin to grant these permissions, when the admin is restricted from doing
* so, will be silently ignored (no exception will be thrown).
*