Merge "Unset StrongAuthFlags when unlocking a user profile" into udc-dev
This commit is contained in:
@@ -1516,11 +1516,6 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
&& !getSeparateProfileChallengeEnabledInternal(userId);
|
&& !getSeparateProfileChallengeEnabledInternal(userId);
|
||||||
}
|
}
|
||||||
|
|
||||||
private boolean isProfileWithSeparatedLock(int userId) {
|
|
||||||
return isCredentialSharableWithParent(userId)
|
|
||||||
&& getSeparateProfileChallengeEnabledInternal(userId);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Send credentials for user {@code userId} to {@link RecoverableKeyStoreManager} during an
|
* Send credentials for user {@code userId} to {@link RecoverableKeyStoreManager} during an
|
||||||
* unlock operation.
|
* unlock operation.
|
||||||
@@ -2784,9 +2779,19 @@ public class LockSettingsService extends ILockSettings.Stub {
|
|||||||
|
|
||||||
activateEscrowTokens(sp, userId);
|
activateEscrowTokens(sp, userId);
|
||||||
|
|
||||||
if (isProfileWithSeparatedLock(userId)) {
|
if (isCredentialSharableWithParent(userId)) {
|
||||||
setDeviceUnlockedForUser(userId);
|
if (getSeparateProfileChallengeEnabledInternal(userId)) {
|
||||||
|
setDeviceUnlockedForUser(userId);
|
||||||
|
} else {
|
||||||
|
// Here only clear StrongAuthFlags for a profile that has a unified challenge.
|
||||||
|
// StrongAuth for a profile with a separate challenge is handled differently and
|
||||||
|
// is cleared after the user successfully confirms the separate challenge to enter
|
||||||
|
// the profile. StrongAuth for the full user (e.g. userId 0) is also handled
|
||||||
|
// separately by Keyguard.
|
||||||
|
mStrongAuth.reportUnlock(userId);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
mStrongAuth.reportSuccessfulStrongAuthUnlock(userId);
|
mStrongAuth.reportSuccessfulStrongAuthUnlock(userId);
|
||||||
|
|
||||||
onSyntheticPasswordUnlocked(userId, sp);
|
onSyntheticPasswordUnlocked(userId, sp);
|
||||||
|
|||||||
Reference in New Issue
Block a user