Merge "Do not require USE_FINGERPRINT for getAuthenticatorId." into mnc-dev
This commit is contained in:
@@ -108,15 +108,10 @@ public class KeyStore {
|
|||||||
}
|
}
|
||||||
|
|
||||||
public static Context getApplicationContext() {
|
public static Context getApplicationContext() {
|
||||||
ActivityThread activityThread = ActivityThread.currentActivityThread();
|
Application application = ActivityThread.currentApplication();
|
||||||
if (activityThread == null) {
|
|
||||||
throw new IllegalStateException(
|
|
||||||
"Failed to obtain application Context: no ActivityThread");
|
|
||||||
}
|
|
||||||
Application application = activityThread.getApplication();
|
|
||||||
if (application == null) {
|
if (application == null) {
|
||||||
throw new IllegalStateException(
|
throw new IllegalStateException(
|
||||||
"Failed to obtain application Context: no Application");
|
"Failed to obtain application Context from ActivityThread");
|
||||||
}
|
}
|
||||||
return application;
|
return application;
|
||||||
}
|
}
|
||||||
@@ -698,16 +693,13 @@ public class KeyStore {
|
|||||||
}
|
}
|
||||||
|
|
||||||
private long getFingerprintOnlySid() {
|
private long getFingerprintOnlySid() {
|
||||||
FingerprintManager fingerprintManager =
|
FingerprintManager fingerprintManager = mContext.getSystemService(FingerprintManager.class);
|
||||||
mContext.getSystemService(FingerprintManager.class);
|
|
||||||
if (fingerprintManager == null) {
|
if (fingerprintManager == null) {
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!fingerprintManager.isHardwareDetected()) {
|
// TODO: Restore USE_FINGERPRINT permission check in
|
||||||
return 0;
|
// FingerprintManager.getAuthenticatorId once the ID is no longer needed here.
|
||||||
}
|
|
||||||
|
|
||||||
return fingerprintManager.getAuthenticatorId();
|
return fingerprintManager.getAuthenticatorId();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -101,13 +101,10 @@ public abstract class KeymasterUtils {
|
|||||||
// fingerprint-only auth.
|
// fingerprint-only auth.
|
||||||
FingerprintManager fingerprintManager =
|
FingerprintManager fingerprintManager =
|
||||||
KeyStore.getApplicationContext().getSystemService(FingerprintManager.class);
|
KeyStore.getApplicationContext().getSystemService(FingerprintManager.class);
|
||||||
if ((fingerprintManager == null) || (!fingerprintManager.isHardwareDetected())) {
|
// TODO: Restore USE_FINGERPRINT permission check in
|
||||||
throw new IllegalStateException(
|
// FingerprintManager.getAuthenticatorId once the ID is no longer needed here.
|
||||||
"This device does not support keys which require authentication for every"
|
long fingerprintOnlySid =
|
||||||
+ " use -- this requires fingerprint authentication which is not"
|
(fingerprintManager != null) ? fingerprintManager.getAuthenticatorId() : 0;
|
||||||
+ " available on this device");
|
|
||||||
}
|
|
||||||
long fingerprintOnlySid = fingerprintManager.getAuthenticatorId();
|
|
||||||
if (fingerprintOnlySid == 0) {
|
if (fingerprintOnlySid == 0) {
|
||||||
throw new IllegalStateException(
|
throw new IllegalStateException(
|
||||||
"At least one fingerprint must be enrolled to create keys requiring user"
|
"At least one fingerprint must be enrolled to create keys requiring user"
|
||||||
|
|||||||
@@ -706,9 +706,22 @@ public class FingerprintService extends SystemService implements IBinder.DeathRe
|
|||||||
|
|
||||||
@Override // Binder call
|
@Override // Binder call
|
||||||
public long getAuthenticatorId(String opPackageName) {
|
public long getAuthenticatorId(String opPackageName) {
|
||||||
if (!canUseFingerprint(opPackageName)) {
|
// In this method, we're not checking whether the caller is permitted to use fingerprint
|
||||||
return 0;
|
// API because current authenticator ID is leaked (in a more contrived way) via Android
|
||||||
}
|
// Keystore (android.security.keystore package): the user of that API can create a key
|
||||||
|
// which requires fingerprint authentication for its use, and then query the key's
|
||||||
|
// characteristics (hidden API) which returns, among other things, fingerprint
|
||||||
|
// authenticator ID which was active at key creation time.
|
||||||
|
//
|
||||||
|
// Reason: The part of Android Keystore which runs inside an app's process invokes this
|
||||||
|
// method in certain cases. Those cases are not always where the developer demonstrates
|
||||||
|
// explicit intent to use fingerprint functionality. Thus, to avoiding throwing an
|
||||||
|
// unexpected SecurityException this method does not check whether its caller is
|
||||||
|
// permitted to use fingerprint API.
|
||||||
|
//
|
||||||
|
// The permission check should be restored once Android Keystore no longer invokes this
|
||||||
|
// method from inside app processes.
|
||||||
|
|
||||||
return FingerprintService.this.getAuthenticatorId();
|
return FingerprintService.this.getAuthenticatorId();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user