Enforce sysui-held permissions when getting main launch intent

- Because a mutable pending intent is returned, we actually do need to
  enforce that SysUI is the only caller of this method

Bug: 278881947
Bug: 253216640
Bug: 256590334
Test: atest LauncherAppTests

Change-Id: I89dd6891a826f934a247881c6dd9ec5cacf2d082
This commit is contained in:
Winson Chung
2023-05-03 18:00:20 +00:00
parent d944cc28f2
commit d532eb1810
2 changed files with 5 additions and 5 deletions

View File

@@ -765,10 +765,6 @@ public class LauncherApps {
@Nullable
public PendingIntent getMainActivityLaunchIntent(@NonNull ComponentName component,
@Nullable Bundle startActivityOptions, @NonNull UserHandle user) {
if (mContext.checkSelfPermission(android.Manifest.permission.START_TASKS_FROM_RECENTS)
!= PackageManager.PERMISSION_GRANTED) {
Log.w(TAG, "Only allowed for recents.");
}
logErrorForInvalidProfileAccess(user);
if (DEBUG) {
Log.i(TAG, "GetMainActivityLaunchIntent " + component + " " + user);

View File

@@ -1330,7 +1330,11 @@ public class LauncherAppsService extends SystemService {
@Override
public PendingIntent getActivityLaunchIntent(String callingPackage, ComponentName component,
UserHandle user) {
ensureShortcutPermission(callingPackage);
if (mContext.checkPermission(android.Manifest.permission.START_TASKS_FROM_RECENTS,
injectBinderCallingPid(), injectBinderCallingUid())
!= PackageManager.PERMISSION_GRANTED) {
throw new SecurityException("Permission START_TASKS_FROM_RECENTS required");
}
if (!canAccessProfile(user.getIdentifier(), "Cannot start activity")) {
throw new ActivityNotFoundException("Activity could not be found");
}