Use real gatekeeper HAT for resetting lockout
The code is slightly confusing in that synthetic password response also
contains a gatekeeper response. This is not the actual response that
contains the challenge. Instead, we should be using the second response
from gateeper, which is the real gatekeeper auth token.
Fixes: 133444358
Test: Before change, get locked out, enter password, user stays locked out
After change, get locked out, enter password, lockout is reset
Change-Id: Ia869fe5d1ebdb91263b3494da2fba5f3c6304047
This commit is contained in:
@@ -2548,9 +2548,8 @@ public class LockSettingsService extends ILockSettings.Stub {
|
||||
// Reset lockout only if user has enrolled templates
|
||||
if (mInjector.hasEnrolledBiometrics()) {
|
||||
BiometricManager bm = mContext.getSystemService(BiometricManager.class);
|
||||
Slog.i(TAG, "Resetting lockout, length: "
|
||||
+ authResult.gkResponse.getPayload().length);
|
||||
bm.resetLockout(authResult.gkResponse.getPayload());
|
||||
Slog.i(TAG, "Resetting lockout, length: " + response.getPayload().length);
|
||||
bm.resetLockout(response.getPayload());
|
||||
|
||||
if (!hasChallenge && pm.hasSystemFeature(PackageManager.FEATURE_FACE)) {
|
||||
mContext.getSystemService(FaceManager.class).revokeChallenge();
|
||||
|
||||
Reference in New Issue
Block a user