diff options
| author | 2023-10-03 00:17:25 +0000 | |
|---|---|---|
| committer | 2023-10-03 00:17:25 +0000 | |
| commit | 75aa57b517f95ba23da1c834b510ec60b51be34e (patch) | |
| tree | 709061fd879f84917e029a11fc2d6893ddec53e2 | |
| parent | 38045ac254f4022516351dc1c230e7d338ba429e (diff) | |
| parent | 2721e6e8d3af44eb568ea06eb9c98b25e961902b (diff) | |
Merge "Validate userId when publishing shortcuts" into rvc-dev am: 72aee14094 am: fedf1c8c14 am: 4934f58cc8 am: 782e7bc3e2 am: 4a0b42a72c am: 63fe378e16 am: 2828a742bc am: fb722bc9e7 am: 2721e6e8d3
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/24182288
Change-Id: I1e23591140c0c76c0c432811ae03fb433248f537
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
| -rw-r--r-- | services/core/java/com/android/server/pm/ShortcutService.java | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/services/core/java/com/android/server/pm/ShortcutService.java b/services/core/java/com/android/server/pm/ShortcutService.java index 3e4dd1637387..c6aba2ab9cbe 100644 --- a/services/core/java/com/android/server/pm/ShortcutService.java +++ b/services/core/java/com/android/server/pm/ShortcutService.java @@ -1743,6 +1743,10 @@ public class ShortcutService extends IShortcutService.Stub { android.util.EventLog.writeEvent(0x534e4554, "109824443", -1, ""); throw new SecurityException("Shortcut package name mismatch"); } + final int callingUid = injectBinderCallingUid(); + if (UserHandle.getUserId(callingUid) != si.getUserId()) { + throw new SecurityException("User-ID in shortcut doesn't match the caller"); + } } private void verifyShortcutInfoPackages( |