Enforce sysui-held permissions when getting main launch intent
- Because a mutable pending intent is returned, we actually do need to enforce that SysUI is the only caller of this method Bug: 278881947 Bug: 253216640 Bug: 256590334 Test: atest LauncherAppTests Change-Id: I89dd6891a826f934a247881c6dd9ec5cacf2d082
This commit is contained in:
@@ -765,10 +765,6 @@ public class LauncherApps {
|
||||
@Nullable
|
||||
public PendingIntent getMainActivityLaunchIntent(@NonNull ComponentName component,
|
||||
@Nullable Bundle startActivityOptions, @NonNull UserHandle user) {
|
||||
if (mContext.checkSelfPermission(android.Manifest.permission.START_TASKS_FROM_RECENTS)
|
||||
!= PackageManager.PERMISSION_GRANTED) {
|
||||
Log.w(TAG, "Only allowed for recents.");
|
||||
}
|
||||
logErrorForInvalidProfileAccess(user);
|
||||
if (DEBUG) {
|
||||
Log.i(TAG, "GetMainActivityLaunchIntent " + component + " " + user);
|
||||
|
||||
@@ -1330,7 +1330,11 @@ public class LauncherAppsService extends SystemService {
|
||||
@Override
|
||||
public PendingIntent getActivityLaunchIntent(String callingPackage, ComponentName component,
|
||||
UserHandle user) {
|
||||
ensureShortcutPermission(callingPackage);
|
||||
if (mContext.checkPermission(android.Manifest.permission.START_TASKS_FROM_RECENTS,
|
||||
injectBinderCallingPid(), injectBinderCallingUid())
|
||||
!= PackageManager.PERMISSION_GRANTED) {
|
||||
throw new SecurityException("Permission START_TASKS_FROM_RECENTS required");
|
||||
}
|
||||
if (!canAccessProfile(user.getIdentifier(), "Cannot start activity")) {
|
||||
throw new ActivityNotFoundException("Activity could not be found");
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user