Merge "Unset StrongAuthFlags when unlocking a user profile" into udc-dev am: 5be7b203d8

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/22308727

Change-Id: I3ae1d9403377d192f0a9be730ab0967950ebe775
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Haining Chen
2023-04-06 15:51:09 +00:00
committed by Automerger Merge Worker

View File

@@ -1516,11 +1516,6 @@ public class LockSettingsService extends ILockSettings.Stub {
&& !getSeparateProfileChallengeEnabledInternal(userId);
}
private boolean isProfileWithSeparatedLock(int userId) {
return isCredentialSharableWithParent(userId)
&& getSeparateProfileChallengeEnabledInternal(userId);
}
/**
* Send credentials for user {@code userId} to {@link RecoverableKeyStoreManager} during an
* unlock operation.
@@ -2784,9 +2779,19 @@ public class LockSettingsService extends ILockSettings.Stub {
activateEscrowTokens(sp, userId);
if (isProfileWithSeparatedLock(userId)) {
setDeviceUnlockedForUser(userId);
if (isCredentialSharableWithParent(userId)) {
if (getSeparateProfileChallengeEnabledInternal(userId)) {
setDeviceUnlockedForUser(userId);
} else {
// Here only clear StrongAuthFlags for a profile that has a unified challenge.
// StrongAuth for a profile with a separate challenge is handled differently and
// is cleared after the user successfully confirms the separate challenge to enter
// the profile. StrongAuth for the full user (e.g. userId 0) is also handled
// separately by Keyguard.
mStrongAuth.reportUnlock(userId);
}
}
mStrongAuth.reportSuccessfulStrongAuthUnlock(userId);
onSyntheticPasswordUnlocked(userId, sp);