From 66026773bbf1d7631743a5b892a4f768c694f868 Mon Sep 17 00:00:00 2001 From: Amith Yamasani Date: Wed, 25 Sep 2013 14:05:33 -0700 Subject: [PATCH] Make sure that external callers cannot pass in the confirm bypass extra Security fix for vulnerability where an app could launch into the screen lock change dialog without first confirming the existing password/pattern. Also, make sure that the fragments are launched with the correct corresponding activity. Bug: 9858403 Change-Id: I0f2c00a44abeb624c6fba0497bf6036a6f1a4564 --- AndroidManifest.xml | 6 +++++- src/com/android/settings/ChooseLockGeneric.java | 10 ++++++++-- src/com/android/settings/ChooseLockPassword.java | 3 +++ src/com/android/settings/ChooseLockPattern.java | 5 ++++- 4 files changed, 20 insertions(+), 4 deletions(-) diff --git a/AndroidManifest.xml b/AndroidManifest.xml index 6b03d511b08..a34479dd1a3 100644 --- a/AndroidManifest.xml +++ b/AndroidManifest.xml @@ -1035,7 +1035,6 @@ - @@ -1051,6 +1050,11 @@ + +