From aaa1b446fcfb3fbf0b919a90ae3ed1bb155a0111 Mon Sep 17 00:00:00 2001 From: Alex Johnston Date: Fri, 14 Feb 2020 14:13:22 +0000 Subject: [PATCH] Modified DPM KEYGUARD_DISABLE_SECURE_NOTIFICATIONS restriction * Introduced logic that allows the profile owner of an organization-owned device (COPE PO) to set the restriction KEYGUARD_DISABLE_SECURE_NOTIFICATIONS on the parent profile. Bug: 149007069 Test: Manual testing with TestDPC atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testSetKeyguardDisabledFeatures atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetKeyguardDisabledFeatures atest com.android.cts.devicepolicy.MixedManagedProfileOwnerTest#testSetKeyguardDisabledFeatures atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetKeyguardDisabledFeaturesLogged Change-Id: I06d8985471bdae3386ba68d67467f136668a4ca4 --- .../android/app/admin/DevicePolicyManager.java | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/core/java/android/app/admin/DevicePolicyManager.java b/core/java/android/app/admin/DevicePolicyManager.java index 4a5a23ab36f81..34798f7b3eee8 100644 --- a/core/java/android/app/admin/DevicePolicyManager.java +++ b/core/java/android/app/admin/DevicePolicyManager.java @@ -4741,7 +4741,8 @@ public class DevicePolicyManager { * @hide */ public static final int ORG_OWNED_PROFILE_KEYGUARD_FEATURES_PARENT_ONLY = - KEYGUARD_DISABLE_SECURE_CAMERA; + DevicePolicyManager.KEYGUARD_DISABLE_SECURE_CAMERA + | DevicePolicyManager.KEYGUARD_DISABLE_SECURE_NOTIFICATIONS; /** * Keyguard features that when set on a normal or organization-owned managed profile, have @@ -6146,14 +6147,17 @@ public class DevicePolicyManager { * * {@link #KEYGUARD_DISABLE_TRUST_AGENTS}, {@link #KEYGUARD_DISABLE_FINGERPRINT}, - * {@link #KEYGUARD_DISABLE_FACE}, {@link #KEYGUARD_DISABLE_IRIS} and - * {@link #KEYGUARD_DISABLE_SECURE_CAMERA} can also be set on the {@link DevicePolicyManager} - * instance returned by {@link #getParentProfileInstance(ComponentName)} in order to set - * restrictions on the parent profile. {@link #KEYGUARD_DISABLE_SECURE_CAMERA} can only be set - * on the parent profile instance if the calling device admin is the profile owner of an - * organization-owned managed profile. + * {@link #KEYGUARD_DISABLE_FACE}, {@link #KEYGUARD_DISABLE_IRIS}, + * {@link #KEYGUARD_DISABLE_SECURE_CAMERA} and {@link #KEYGUARD_DISABLE_SECURE_NOTIFICATIONS} + * can also be set on the {@link DevicePolicyManager} instance returned by + * {@link #getParentProfileInstance(ComponentName)} in order to set restrictions on the parent + * profile. {@link #KEYGUARD_DISABLE_SECURE_CAMERA} can only be set on the parent profile + * instance if the calling device admin is the profile owner of an organization-owned + * managed profile. *

* Requests to disable other features on a managed profile will be ignored. *