Merge "Throw on revoked location permission - framework"

This commit is contained in:
Nathan Harold
2018-08-02 22:16:07 +00:00
committed by Gerrit Code Review
2 changed files with 9 additions and 6 deletions

View File

@@ -1789,7 +1789,8 @@ class TelephonyRegistry extends ITelephonyRegistry.Stub {
long token = Binder.clearCallingIdentity(); long token = Binder.clearCallingIdentity();
try { try {
return LocationAccessPolicy.canAccessCellLocation(mContext, return LocationAccessPolicy.canAccessCellLocation(mContext,
r.callingPackage, r.callerUid, r.callerPid); r.callingPackage, r.callerUid, r.callerPid,
/*throwOnDeniedPermission*/ false);
} finally { } finally {
Binder.restoreCallingIdentity(token); Binder.restoreCallingIdentity(token);
} }

View File

@@ -48,10 +48,11 @@ public final class LocationAccessPolicy {
* @param pkgName Package name of the application requesting access * @param pkgName Package name of the application requesting access
* @param uid The uid of the package * @param uid The uid of the package
* @param pid The pid of the package * @param pid The pid of the package
* @param throwOnDeniedPermission Whether to throw if the location permission is denied.
* @return boolean true or false if permissions is granted * @return boolean true or false if permissions is granted
*/ */
public static boolean canAccessCellLocation(@NonNull Context context, @NonNull String pkgName, public static boolean canAccessCellLocation(@NonNull Context context, @NonNull String pkgName,
int uid, int pid) throws SecurityException { int uid, int pid, boolean throwOnDeniedPermission) throws SecurityException {
Trace.beginSection("TelephonyLocationCheck"); Trace.beginSection("TelephonyLocationCheck");
try { try {
// Always allow the phone process and system server to access location. This avoid // Always allow the phone process and system server to access location. This avoid
@@ -68,10 +69,11 @@ public final class LocationAccessPolicy {
// where a legacy app the user is not using tracks their location. // where a legacy app the user is not using tracks their location.
// Granting ACCESS_FINE_LOCATION to an app automatically grants it // Granting ACCESS_FINE_LOCATION to an app automatically grants it
// ACCESS_COARSE_LOCATION. // ACCESS_COARSE_LOCATION.
if (throwOnDeniedPermission) {
if (context.checkPermission(Manifest.permission.ACCESS_COARSE_LOCATION, pid, uid) == context.enforcePermission(Manifest.permission.ACCESS_COARSE_LOCATION,
PackageManager.PERMISSION_DENIED) { pid, uid, "canAccessCellLocation");
if (DBG) Log.w(TAG, "Permission checked failed (" + pid + "," + uid + ")"); } else if (context.checkPermission(Manifest.permission.ACCESS_COARSE_LOCATION,
pid, uid) == PackageManager.PERMISSION_DENIED) {
return false; return false;
} }
final int opCode = AppOpsManager.permissionToOpCode( final int opCode = AppOpsManager.permissionToOpCode(