Merge "Add permission checking on service calls in LockSettingsService" into nyc-dev

This commit is contained in:
Ricky Wai
2016-06-16 10:33:22 +00:00
committed by Android (Google) Code Review

View File

@@ -617,6 +617,7 @@ public class LockSettingsService extends ILockSettings.Stub {
@Override @Override
public boolean getSeparateProfileChallengeEnabled(int userId) throws RemoteException { public boolean getSeparateProfileChallengeEnabled(int userId) throws RemoteException {
checkReadPermission(SEPARATE_PROFILE_CHALLENGE_KEY, userId);
synchronized (mSeparateChallengeLock) { synchronized (mSeparateChallengeLock) {
return getBoolean(SEPARATE_PROFILE_CHALLENGE_KEY, false, userId); return getBoolean(SEPARATE_PROFILE_CHALLENGE_KEY, false, userId);
} }
@@ -625,6 +626,7 @@ public class LockSettingsService extends ILockSettings.Stub {
@Override @Override
public void setSeparateProfileChallengeEnabled(int userId, boolean enabled, public void setSeparateProfileChallengeEnabled(int userId, boolean enabled,
String managedUserPassword) throws RemoteException { String managedUserPassword) throws RemoteException {
checkWritePermission(userId);
synchronized (mSeparateChallengeLock) { synchronized (mSeparateChallengeLock) {
setBoolean(SEPARATE_PROFILE_CHALLENGE_KEY, enabled, userId); setBoolean(SEPARATE_PROFILE_CHALLENGE_KEY, enabled, userId);
if (enabled) { if (enabled) {
@@ -672,7 +674,6 @@ public class LockSettingsService extends ILockSettings.Stub {
@Override @Override
public long getLong(String key, long defaultValue, int userId) throws RemoteException { public long getLong(String key, long defaultValue, int userId) throws RemoteException {
checkReadPermission(key, userId); checkReadPermission(key, userId);
String value = getStringUnchecked(key, null, userId); String value = getStringUnchecked(key, null, userId);
return TextUtils.isEmpty(value) ? defaultValue : Long.parseLong(value); return TextUtils.isEmpty(value) ? defaultValue : Long.parseLong(value);
} }
@@ -680,7 +681,6 @@ public class LockSettingsService extends ILockSettings.Stub {
@Override @Override
public String getString(String key, String defaultValue, int userId) throws RemoteException { public String getString(String key, String defaultValue, int userId) throws RemoteException {
checkReadPermission(key, userId); checkReadPermission(key, userId);
return getStringUnchecked(key, defaultValue, userId); return getStringUnchecked(key, defaultValue, userId);
} }
@@ -899,7 +899,7 @@ public class LockSettingsService extends ILockSettings.Stub {
} }
} }
public void setLockPatternInternal(String pattern, String savedCredential, int userId) private void setLockPatternInternal(String pattern, String savedCredential, int userId)
throws RemoteException { throws RemoteException {
byte[] currentHandle = getCurrentHandle(userId); byte[] currentHandle = getCurrentHandle(userId);
@@ -962,7 +962,7 @@ public class LockSettingsService extends ILockSettings.Stub {
} }
} }
public void setLockPasswordInternal(String password, String savedCredential, int userId) private void setLockPasswordInternal(String password, String savedCredential, int userId)
throws RemoteException { throws RemoteException {
byte[] currentHandle = getCurrentHandle(userId); byte[] currentHandle = getCurrentHandle(userId);
if (password == null) { if (password == null) {
@@ -1156,6 +1156,7 @@ public class LockSettingsService extends ILockSettings.Stub {
@Override @Override
public void resetKeyStore(int userId) throws RemoteException { public void resetKeyStore(int userId) throws RemoteException {
checkWritePermission(userId);
if (DEBUG) Slog.v(TAG, "Reset keystore for user: " + userId); if (DEBUG) Slog.v(TAG, "Reset keystore for user: " + userId);
int managedUserId = -1; int managedUserId = -1;
String managedUserDecryptedPassword = null; String managedUserDecryptedPassword = null;
@@ -1558,6 +1559,7 @@ public class LockSettingsService extends ILockSettings.Stub {
LockPatternUtils.LOCK_PASSWORD_SALT_KEY, LockPatternUtils.LOCK_PASSWORD_SALT_KEY,
LockPatternUtils.PASSWORD_HISTORY_KEY, LockPatternUtils.PASSWORD_HISTORY_KEY,
LockPatternUtils.PASSWORD_TYPE_KEY, LockPatternUtils.PASSWORD_TYPE_KEY,
SEPARATE_PROFILE_CHALLENGE_KEY
}; };
private static final String[] SETTINGS_TO_BACKUP = new String[] { private static final String[] SETTINGS_TO_BACKUP = new String[] {