Merge "Fix delegates access to API with permission checks." into udc-dev
This commit is contained in:
@@ -11337,7 +11337,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
DevicePolicyEventLogger
|
DevicePolicyEventLogger
|
||||||
.createEvent(DevicePolicyEnums.SET_APPLICATION_RESTRICTIONS)
|
.createEvent(DevicePolicyEnums.SET_APPLICATION_RESTRICTIONS)
|
||||||
.setAdmin(caller.getPackageName())
|
.setAdmin(caller.getPackageName())
|
||||||
.setBoolean(/* isDelegate */ who == null)
|
.setBoolean(/* isDelegate */ isCallerDelegate(caller))
|
||||||
.setStrings(packageName)
|
.setStrings(packageName)
|
||||||
.write();
|
.write();
|
||||||
}
|
}
|
||||||
@@ -13378,7 +13378,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
DevicePolicyEventLogger
|
DevicePolicyEventLogger
|
||||||
.createEvent(DevicePolicyEnums.SET_APPLICATION_HIDDEN)
|
.createEvent(DevicePolicyEnums.SET_APPLICATION_HIDDEN)
|
||||||
.setAdmin(caller.getPackageName())
|
.setAdmin(caller.getPackageName())
|
||||||
.setBoolean(/* isDelegate */ who == null)
|
.setBoolean(/* isDelegate */ isCallerDelegate(caller))
|
||||||
.setStrings(packageName, hidden ? "hidden" : "not_hidden",
|
.setStrings(packageName, hidden ? "hidden" : "not_hidden",
|
||||||
parent ? CALLED_FROM_PARENT : NOT_CALLED_FROM_PARENT)
|
parent ? CALLED_FROM_PARENT : NOT_CALLED_FROM_PARENT)
|
||||||
.write();
|
.write();
|
||||||
@@ -13730,7 +13730,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
DevicePolicyEventLogger
|
DevicePolicyEventLogger
|
||||||
.createEvent(DevicePolicyEnums.SET_UNINSTALL_BLOCKED)
|
.createEvent(DevicePolicyEnums.SET_UNINSTALL_BLOCKED)
|
||||||
.setAdmin(caller.getPackageName())
|
.setAdmin(caller.getPackageName())
|
||||||
.setBoolean(/* isDelegate */ who == null)
|
.setBoolean(/* isDelegate */ isCallerDelegate(caller))
|
||||||
.setStrings(packageName)
|
.setStrings(packageName)
|
||||||
.write();
|
.write();
|
||||||
}
|
}
|
||||||
@@ -16280,7 +16280,8 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
.setAdmin(caller.getPackageName())
|
.setAdmin(caller.getPackageName())
|
||||||
.setStrings(permission)
|
.setStrings(permission)
|
||||||
.setInt(grantState)
|
.setInt(grantState)
|
||||||
.setBoolean(/* isDelegate */ admin == null)
|
.setBoolean(
|
||||||
|
/* isDelegate */ isCallerDelegate(caller))
|
||||||
.write();
|
.write();
|
||||||
|
|
||||||
callback.sendResult(Bundle.EMPTY);
|
callback.sendResult(Bundle.EMPTY);
|
||||||
@@ -22183,6 +22184,10 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
private static final HashMap<String, String> DELEGATE_SCOPES = new HashMap<>();
|
private static final HashMap<String, String> DELEGATE_SCOPES = new HashMap<>();
|
||||||
{
|
{
|
||||||
DELEGATE_SCOPES.put(MANAGE_DEVICE_POLICY_RUNTIME_PERMISSIONS, DELEGATION_PERMISSION_GRANT);
|
DELEGATE_SCOPES.put(MANAGE_DEVICE_POLICY_RUNTIME_PERMISSIONS, DELEGATION_PERMISSION_GRANT);
|
||||||
|
DELEGATE_SCOPES.put(MANAGE_DEVICE_POLICY_APP_RESTRICTIONS, DELEGATION_APP_RESTRICTIONS);
|
||||||
|
DELEGATE_SCOPES.put(MANAGE_DEVICE_POLICY_APPS_CONTROL, DELEGATION_BLOCK_UNINSTALL);
|
||||||
|
DELEGATE_SCOPES.put(MANAGE_DEVICE_POLICY_SECURITY_LOGGING, DELEGATION_SECURITY_LOGGING);
|
||||||
|
DELEGATE_SCOPES.put(MANAGE_DEVICE_POLICY_PACKAGE_STATE, DELEGATION_PACKAGE_ACCESS);
|
||||||
}
|
}
|
||||||
|
|
||||||
private static final HashMap<String, String> CROSS_USER_PERMISSIONS =
|
private static final HashMap<String, String> CROSS_USER_PERMISSIONS =
|
||||||
@@ -22371,6 +22376,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
+ permission
|
+ permission
|
||||||
+ ", "
|
+ ", "
|
||||||
+ CROSS_USER_PERMISSIONS.get(permission)
|
+ CROSS_USER_PERMISSIONS.get(permission)
|
||||||
|
+ "(if calling cross-user)"
|
||||||
+ "}");
|
+ "}");
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user