diff options
author | Michael Wright <michaelwr@google.com> | 2016-03-22 15:17:35 -0700 |
---|---|---|
committer | Jessica Wagantall <jwagantall@cyngn.com> | 2016-06-07 14:41:56 -0700 |
commit | 91c6759a02be2a8afe411cc656a3bcab554415dc (patch) | |
tree | 8c9e36be4396fa7e8d4398951e0bc8b1a8c4d3bb /src/com | |
parent | f806bb151277ac4dc99134b97bb5184c1eab3835 (diff) | |
download | android_packages_apps_PackageInstaller-91c6759a02be2a8afe411cc656a3bcab554415dc.tar.gz android_packages_apps_PackageInstaller-91c6759a02be2a8afe411cc656a3bcab554415dc.tar.bz2 android_packages_apps_PackageInstaller-91c6759a02be2a8afe411cc656a3bcab554415dc.zip |
DO NOT MERGE Take advantage of new MotionEvent flag to prevent tapjacking.
Ticket: CYNGNOS-2707
Bug: 26677796
Change-Id: I563541f0a42564b854af0f8037c1d4741c79a2ac
(cherry picked from commit b431433dabd769d0e1688a49dad100b7b65ff66b)
Diffstat (limited to 'src/com')
-rw-r--r-- | src/com/android/packageinstaller/permission/ui/SecureButtonView.java | 56 |
1 files changed, 56 insertions, 0 deletions
diff --git a/src/com/android/packageinstaller/permission/ui/SecureButtonView.java b/src/com/android/packageinstaller/permission/ui/SecureButtonView.java new file mode 100644 index 00000000..624744e5 --- /dev/null +++ b/src/com/android/packageinstaller/permission/ui/SecureButtonView.java @@ -0,0 +1,56 @@ +/* + * Copyright (C) 2016 The Android Open Source Project + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +package com.android.packageinstaller.permission.ui; + +import android.content.Context; +import android.util.AttributeSet; +import android.view.MotionEvent; +import android.widget.Button; + +/** + * Extension of Button that uses the hidden MotionEvent flag for partially obscured windows to + * prevent tapjacking attacks. + */ +public class SecureButtonView extends Button { + + public SecureButtonView(Context context) { + this(context, null); + } + + public SecureButtonView(Context context, AttributeSet attrs) { + this(context, attrs, 0); + } + + public SecureButtonView(Context context, AttributeSet attrs, int defStyleAttr) { + this(context, attrs, defStyleAttr, 0); + } + + public SecureButtonView(Context context, AttributeSet attrs, int defStyleAttr, + int defStyleRes) { + super(context, attrs, defStyleAttr, defStyleRes); + } + + @Override + public boolean onFilterTouchEventForSecurity(MotionEvent event) { + if ((event.getFlags() & MotionEvent.FLAG_WINDOW_IS_OBSCURED) != 0 + || (event.getFlags() & MotionEvent.FLAG_WINDOW_IS_PARTIALLY_OBSCURED) != 0) { + // Window is obscured, drop this touch. + return false; + } + return true; + } +} |