From b36e753f77145730a6b26958177ac73dd18c5d45 Mon Sep 17 00:00:00 2001 From: Rubin Xu Date: Wed, 30 Jan 2019 12:29:43 +0000 Subject: [PATCH] Clarify the behaviour of isActivePasswordSufficient Bug: 123620877 Test: make -j32 ds-docs Change-Id: Ied91e8f44e07894449aa15902fe6b5e0fbc408d4 --- .../app/admin/DevicePolicyManager.java | 58 +++++++++++++------ 1 file changed, 39 insertions(+), 19 deletions(-) diff --git a/core/java/android/app/admin/DevicePolicyManager.java b/core/java/android/app/admin/DevicePolicyManager.java index a32e01fb68e59..c6f624641c9c4 100644 --- a/core/java/android/app/admin/DevicePolicyManager.java +++ b/core/java/android/app/admin/DevicePolicyManager.java @@ -59,7 +59,6 @@ import android.os.Build; import android.os.Bundle; import android.os.ParcelFileDescriptor; import android.os.Parcelable; -import android.os.ParcelableException; import android.os.PersistableBundle; import android.os.Process; import android.os.RemoteCallback; @@ -3321,27 +3320,48 @@ public class DevicePolicyManager { } /** - * Determine whether the current password the user has set is sufficient to meet the policy - * requirements (e.g. quality, minimum length) that have been requested by the admins of this - * user and its participating profiles. Restrictions on profiles that have a separate challenge - * are not taken into account. The user must be unlocked in order to perform the check. - *

- * On devices not supporting {@link PackageManager#FEATURE_SECURE_LOCK_SCREEN} feature, the - * password is always treated as empty - i.e. this method will always return false on such - * devices, provided any password requirements were set. - *

- * The calling device admin must have requested - * {@link DeviceAdminInfo#USES_POLICY_LIMIT_PASSWORD} to be able to call this method; if it has - * not, a security exception will be thrown. - *

- * This method can be called on the {@link DevicePolicyManager} instance returned by + * Determines whether the calling user's current password meets policy requirements + * (e.g. quality, minimum length). The user must be unlocked to perform this check. + * + *

Policy requirements which affect this check can be set by admins of the user, but also + * by the admin of a managed profile associated with the calling user (when the managed profile + * doesn't have a separate work challenge). When a managed profile has a separate work + * challenge, its policy requirements only affect the managed profile. + * + *

Depending on the user, this method checks the policy requirement against one of the + * following passwords: + *