From b95c90ce2d10a93c680b2ddbdf7ad61feb3abf5a Mon Sep 17 00:00:00 2001 From: Bo Zhu Date: Tue, 10 Apr 2018 13:58:25 -0700 Subject: [PATCH] Add an API to check whether the recoverable keystore is enabled Bug: 77690455 Test: It builds Change-Id: I94be0e341d8a3e0fa9a5f9af8beda60e08a449e8 --- api/system-current.txt | 1 + .../keystore/recovery/RecoveryController.java | 13 +++++++++++++ 2 files changed, 14 insertions(+) diff --git a/api/system-current.txt b/api/system-current.txt index 76a71cd7c44ef..85c1f5639ef1e 100644 --- a/api/system-current.txt +++ b/api/system-current.txt @@ -4397,6 +4397,7 @@ package android.security.keystore.recovery { method public java.security.Key importKey(java.lang.String, byte[]) throws android.security.keystore.recovery.InternalRecoveryServiceException, android.security.keystore.recovery.LockScreenRequiredException; method public deprecated void initRecoveryService(java.lang.String, byte[]) throws java.security.cert.CertificateException, android.security.keystore.recovery.InternalRecoveryServiceException; method public void initRecoveryService(java.lang.String, byte[], byte[]) throws java.security.cert.CertificateException, android.security.keystore.recovery.InternalRecoveryServiceException; + method public static boolean isRecoverableKeyStoreEnabled(android.content.Context); method public void removeKey(java.lang.String) throws android.security.keystore.recovery.InternalRecoveryServiceException; method public void setRecoverySecretTypes(int[]) throws android.security.keystore.recovery.InternalRecoveryServiceException; method public deprecated void setRecoveryStatus(java.lang.String, java.lang.String, int) throws android.security.keystore.recovery.InternalRecoveryServiceException, android.content.pm.PackageManager.NameNotFoundException; diff --git a/core/java/android/security/keystore/recovery/RecoveryController.java b/core/java/android/security/keystore/recovery/RecoveryController.java index f351c5afa5792..b84843bf120dd 100644 --- a/core/java/android/security/keystore/recovery/RecoveryController.java +++ b/core/java/android/security/keystore/recovery/RecoveryController.java @@ -20,6 +20,7 @@ import android.annotation.NonNull; import android.annotation.Nullable; import android.annotation.RequiresPermission; import android.annotation.SystemApi; +import android.app.KeyguardManager; import android.app.PendingIntent; import android.content.Context; import android.content.pm.PackageManager.NameNotFoundException; @@ -287,6 +288,18 @@ public class RecoveryController { return new RecoveryController(lockSettings, KeyStore.getInstance()); } + /** + * Checks whether the recoverable key store is currently available. + * + *

If it returns true, the device must currently be using a screen lock that is supported for + * use with the recoverable key store, i.e. AOSP PIN, pattern or password. + */ + @RequiresPermission(android.Manifest.permission.RECOVER_KEYSTORE) + public static boolean isRecoverableKeyStoreEnabled(@NonNull Context context) { + KeyguardManager keyguardManager = context.getSystemService(KeyguardManager.class); + return keyguardManager != null && keyguardManager.isDeviceSecure(); + } + /** * @deprecated Use {@link #initRecoveryService(String, byte[], byte[])} instead. */