Merge "Add permission checking on service calls in LockSettingsService" into nyc-dev
This commit is contained in:
@@ -617,6 +617,7 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
|
|
||||||
@Override
|
@Override
|
||||||
public boolean getSeparateProfileChallengeEnabled(int userId) throws RemoteException {
|
public boolean getSeparateProfileChallengeEnabled(int userId) throws RemoteException {
|
||||||
|
checkReadPermission(SEPARATE_PROFILE_CHALLENGE_KEY, userId);
|
||||||
synchronized (mSeparateChallengeLock) {
|
synchronized (mSeparateChallengeLock) {
|
||||||
return getBoolean(SEPARATE_PROFILE_CHALLENGE_KEY, false, userId);
|
return getBoolean(SEPARATE_PROFILE_CHALLENGE_KEY, false, userId);
|
||||||
}
|
}
|
||||||
@@ -625,6 +626,7 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
@Override
|
@Override
|
||||||
public void setSeparateProfileChallengeEnabled(int userId, boolean enabled,
|
public void setSeparateProfileChallengeEnabled(int userId, boolean enabled,
|
||||||
String managedUserPassword) throws RemoteException {
|
String managedUserPassword) throws RemoteException {
|
||||||
|
checkWritePermission(userId);
|
||||||
synchronized (mSeparateChallengeLock) {
|
synchronized (mSeparateChallengeLock) {
|
||||||
setBoolean(SEPARATE_PROFILE_CHALLENGE_KEY, enabled, userId);
|
setBoolean(SEPARATE_PROFILE_CHALLENGE_KEY, enabled, userId);
|
||||||
if (enabled) {
|
if (enabled) {
|
||||||
@@ -672,7 +674,6 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
@Override
|
@Override
|
||||||
public long getLong(String key, long defaultValue, int userId) throws RemoteException {
|
public long getLong(String key, long defaultValue, int userId) throws RemoteException {
|
||||||
checkReadPermission(key, userId);
|
checkReadPermission(key, userId);
|
||||||
|
|
||||||
String value = getStringUnchecked(key, null, userId);
|
String value = getStringUnchecked(key, null, userId);
|
||||||
return TextUtils.isEmpty(value) ? defaultValue : Long.parseLong(value);
|
return TextUtils.isEmpty(value) ? defaultValue : Long.parseLong(value);
|
||||||
}
|
}
|
||||||
@@ -680,7 +681,6 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
@Override
|
@Override
|
||||||
public String getString(String key, String defaultValue, int userId) throws RemoteException {
|
public String getString(String key, String defaultValue, int userId) throws RemoteException {
|
||||||
checkReadPermission(key, userId);
|
checkReadPermission(key, userId);
|
||||||
|
|
||||||
return getStringUnchecked(key, defaultValue, userId);
|
return getStringUnchecked(key, defaultValue, userId);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -899,7 +899,7 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLockPatternInternal(String pattern, String savedCredential, int userId)
|
private void setLockPatternInternal(String pattern, String savedCredential, int userId)
|
||||||
throws RemoteException {
|
throws RemoteException {
|
||||||
byte[] currentHandle = getCurrentHandle(userId);
|
byte[] currentHandle = getCurrentHandle(userId);
|
||||||
|
|
||||||
@@ -962,7 +962,7 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLockPasswordInternal(String password, String savedCredential, int userId)
|
private void setLockPasswordInternal(String password, String savedCredential, int userId)
|
||||||
throws RemoteException {
|
throws RemoteException {
|
||||||
byte[] currentHandle = getCurrentHandle(userId);
|
byte[] currentHandle = getCurrentHandle(userId);
|
||||||
if (password == null) {
|
if (password == null) {
|
||||||
@@ -1156,6 +1156,7 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
|
|
||||||
@Override
|
@Override
|
||||||
public void resetKeyStore(int userId) throws RemoteException {
|
public void resetKeyStore(int userId) throws RemoteException {
|
||||||
|
checkWritePermission(userId);
|
||||||
if (DEBUG) Slog.v(TAG, "Reset keystore for user: " + userId);
|
if (DEBUG) Slog.v(TAG, "Reset keystore for user: " + userId);
|
||||||
int managedUserId = -1;
|
int managedUserId = -1;
|
||||||
String managedUserDecryptedPassword = null;
|
String managedUserDecryptedPassword = null;
|
||||||
@@ -1558,6 +1559,7 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
LockPatternUtils.LOCK_PASSWORD_SALT_KEY,
|
LockPatternUtils.LOCK_PASSWORD_SALT_KEY,
|
||||||
LockPatternUtils.PASSWORD_HISTORY_KEY,
|
LockPatternUtils.PASSWORD_HISTORY_KEY,
|
||||||
LockPatternUtils.PASSWORD_TYPE_KEY,
|
LockPatternUtils.PASSWORD_TYPE_KEY,
|
||||||
|
SEPARATE_PROFILE_CHALLENGE_KEY
|
||||||
};
|
};
|
||||||
|
|
||||||
private static final String[] SETTINGS_TO_BACKUP = new String[] {
|
private static final String[] SETTINGS_TO_BACKUP = new String[] {
|
||||||
|
|||||||
Reference in New Issue
Block a user