diff options
author | Brahmaji K <bkomma@codeaurora.org> | 2016-03-15 16:37:16 +0530 |
---|---|---|
committer | Steve Kondik <shade@chemlab.org> | 2016-05-21 05:05:57 -0700 |
commit | cca9cb7a8a64b21280045fe76c0902dbab75f386 (patch) | |
tree | 0ad48022c6687f934a873340fbb20438be8179c9 /packages/Keyguard | |
parent | 931814deddeee311865c7db8d8c8a4f29ff83a0b (diff) | |
download | frameworks_base-cca9cb7a8a64b21280045fe76c0902dbab75f386.zip frameworks_base-cca9cb7a8a64b21280045fe76c0902dbab75f386.tar.gz frameworks_base-cca9cb7a8a64b21280045fe76c0902dbab75f386.tar.bz2 |
keyguard: Fix password doesnot sanitize after verification
Add sanitizePassword call after the verification is success so
that the password/pin/pattern goes to default_password. This
will avoid security vulnerability.
Change-Id: I711b9e38e1812bad9fa7ab8d0ab9e35963138a69
Diffstat (limited to 'packages/Keyguard')
-rw-r--r-- | packages/Keyguard/src/com/android/keyguard/KeyguardAbsKeyInputView.java | 1 | ||||
-rw-r--r-- | packages/Keyguard/src/com/android/keyguard/KeyguardPatternView.java | 1 |
2 files changed, 2 insertions, 0 deletions
diff --git a/packages/Keyguard/src/com/android/keyguard/KeyguardAbsKeyInputView.java b/packages/Keyguard/src/com/android/keyguard/KeyguardAbsKeyInputView.java index b03871a..7fbd658 100644 --- a/packages/Keyguard/src/com/android/keyguard/KeyguardAbsKeyInputView.java +++ b/packages/Keyguard/src/com/android/keyguard/KeyguardAbsKeyInputView.java @@ -147,6 +147,7 @@ public abstract class KeyguardAbsKeyInputView extends LinearLayout private void onPasswordChecked(boolean matched, int timeoutMs, boolean isValidPassword) { if (matched) { + mLockPatternUtils.sanitizePassword(); mDismissing = true; mCallback.reportUnlockAttempt(true, 0); mCallback.dismiss(true); diff --git a/packages/Keyguard/src/com/android/keyguard/KeyguardPatternView.java b/packages/Keyguard/src/com/android/keyguard/KeyguardPatternView.java index f40d4fe..446f6c1 100644 --- a/packages/Keyguard/src/com/android/keyguard/KeyguardPatternView.java +++ b/packages/Keyguard/src/com/android/keyguard/KeyguardPatternView.java @@ -262,6 +262,7 @@ public class KeyguardPatternView extends LinearLayout implements KeyguardSecurit private void onPatternChecked(boolean matched, int timeoutMs, boolean isValidPattern) { if (matched) { + mLockPatternUtils.sanitizePassword(); mCallback.reportUnlockAttempt(true, 0); mLockPatternView.setDisplayMode(LockPatternView.DisplayMode.Correct); mCallback.dismiss(true); |