Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 73094fbc authored by Amith Yamasani's avatar Amith Yamasani Committed by Android (Google) Code Review
Browse files

Merge "Don't allow non-authorized apps to access auth tokens" into jb-mr2-dev

parents 60ac308e d20ea2f1
Loading
Loading
Loading
Loading
+5 −0
Original line number Diff line number Diff line
@@ -1265,6 +1265,11 @@ public class AccountManagerService
        final boolean customTokens =
            authenticatorInfo != null && authenticatorInfo.type.customTokens;

        // Check to see that the app is authorized to access the account, in case it's a
        // restricted account.
        if (!ArrayUtils.contains(getAccounts((String) null), account)) {
            throw new IllegalArgumentException("no such account");
        }
        // skip the check if customTokens
        final int callerUid = Binder.getCallingUid();
        final boolean permissionGranted = customTokens ||