Only return password for account session flow if the caller is signed
with system key and have get_password permission. Bug: 30455516 Change-Id: I78484c59e4de1dff685ab91a0a8e7a756fffd9bf
This commit is contained in:
@@ -2676,8 +2676,6 @@ public class AccountManager {
|
|||||||
* <ul>
|
* <ul>
|
||||||
* <li>{@link #KEY_ACCOUNT_SESSION_BUNDLE} - encrypted Bundle for
|
* <li>{@link #KEY_ACCOUNT_SESSION_BUNDLE} - encrypted Bundle for
|
||||||
* adding the the to the device later.
|
* adding the the to the device later.
|
||||||
* <li>{@link #KEY_PASSWORD} - optional, the password or password
|
|
||||||
* hash of the account.
|
|
||||||
* <li>{@link #KEY_ACCOUNT_STATUS_TOKEN} - optional, token to check
|
* <li>{@link #KEY_ACCOUNT_STATUS_TOKEN} - optional, token to check
|
||||||
* status of the account
|
* status of the account
|
||||||
* </ul>
|
* </ul>
|
||||||
@@ -2765,8 +2763,6 @@ public class AccountManager {
|
|||||||
* <ul>
|
* <ul>
|
||||||
* <li>{@link #KEY_ACCOUNT_SESSION_BUNDLE} - encrypted Bundle for
|
* <li>{@link #KEY_ACCOUNT_SESSION_BUNDLE} - encrypted Bundle for
|
||||||
* updating the local credentials on device later.
|
* updating the local credentials on device later.
|
||||||
* <li>{@link #KEY_PASSWORD} - optional, the password or password
|
|
||||||
* hash of the account
|
|
||||||
* <li>{@link #KEY_ACCOUNT_STATUS_TOKEN} - optional, token to check
|
* <li>{@link #KEY_ACCOUNT_STATUS_TOKEN} - optional, token to check
|
||||||
* status of the account
|
* status of the account
|
||||||
* </ul>
|
* </ul>
|
||||||
|
|||||||
@@ -2685,10 +2685,9 @@ public class AccountManagerService
|
|||||||
boolean isPasswordForwardingAllowed = isPermitted(
|
boolean isPasswordForwardingAllowed = isPermitted(
|
||||||
callerPkg, uid, Manifest.permission.GET_PASSWORD);
|
callerPkg, uid, Manifest.permission.GET_PASSWORD);
|
||||||
|
|
||||||
int usrId = UserHandle.getCallingUserId();
|
|
||||||
long identityToken = clearCallingIdentity();
|
long identityToken = clearCallingIdentity();
|
||||||
try {
|
try {
|
||||||
UserAccounts accounts = getUserAccounts(usrId);
|
UserAccounts accounts = getUserAccounts(userId);
|
||||||
logRecordWithUid(accounts, DebugDbHelper.ACTION_CALLED_START_ACCOUNT_ADD,
|
logRecordWithUid(accounts, DebugDbHelper.ACTION_CALLED_START_ACCOUNT_ADD,
|
||||||
TABLE_ACCOUNTS, uid);
|
TABLE_ACCOUNTS, uid);
|
||||||
new StartAccountSession(
|
new StartAccountSession(
|
||||||
@@ -2749,10 +2748,6 @@ public class AccountManagerService
|
|||||||
checkKeyIntent(
|
checkKeyIntent(
|
||||||
Binder.getCallingUid(),
|
Binder.getCallingUid(),
|
||||||
intent);
|
intent);
|
||||||
// Omit passwords if the caller isn't permitted to see them.
|
|
||||||
if (!mIsPasswordForwardingAllowed) {
|
|
||||||
result.remove(AccountManager.KEY_PASSWORD);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
IAccountManagerResponse response;
|
IAccountManagerResponse response;
|
||||||
if (mExpectActivityLaunch && result != null
|
if (mExpectActivityLaunch && result != null
|
||||||
@@ -2782,6 +2777,11 @@ public class AccountManagerService
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Omit passwords if the caller isn't permitted to see them.
|
||||||
|
if (!mIsPasswordForwardingAllowed) {
|
||||||
|
result.remove(AccountManager.KEY_PASSWORD);
|
||||||
|
}
|
||||||
|
|
||||||
// Strip auth token from result.
|
// Strip auth token from result.
|
||||||
result.remove(AccountManager.KEY_AUTHTOKEN);
|
result.remove(AccountManager.KEY_AUTHTOKEN);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user