diff options
author | Michael Wright <michaelwr@google.com> | 2016-03-22 15:17:35 -0700 |
---|---|---|
committer | Michael Wright <michaelwr@google.com> | 2016-03-31 15:34:49 -0700 |
commit | c8eda3e20a95b2c96ef4ccd0213347ea1e4887ae (patch) | |
tree | 4654a7a9f8990d10d47ddba8a149215c8443c82f /src | |
parent | 895caebccb2ddad703b087baac757f5dcb5822ab (diff) | |
download | android_packages_apps_PackageInstaller-c8eda3e20a95b2c96ef4ccd0213347ea1e4887ae.tar.gz android_packages_apps_PackageInstaller-c8eda3e20a95b2c96ef4ccd0213347ea1e4887ae.tar.bz2 android_packages_apps_PackageInstaller-c8eda3e20a95b2c96ef4ccd0213347ea1e4887ae.zip |
Take advantage of new MotionEvent flag to prevent tapjacking.
Bug: 26677796
Change-Id: I563541f0a42564b854af0f8037c1d4741c79a2ac
Diffstat (limited to 'src')
-rw-r--r-- | src/com/android/packageinstaller/permission/ui/SecureButtonView.java | 56 |
1 files changed, 56 insertions, 0 deletions
diff --git a/src/com/android/packageinstaller/permission/ui/SecureButtonView.java b/src/com/android/packageinstaller/permission/ui/SecureButtonView.java new file mode 100644 index 00000000..624744e5 --- /dev/null +++ b/src/com/android/packageinstaller/permission/ui/SecureButtonView.java @@ -0,0 +1,56 @@ +/* + * Copyright (C) 2016 The Android Open Source Project + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +package com.android.packageinstaller.permission.ui; + +import android.content.Context; +import android.util.AttributeSet; +import android.view.MotionEvent; +import android.widget.Button; + +/** + * Extension of Button that uses the hidden MotionEvent flag for partially obscured windows to + * prevent tapjacking attacks. + */ +public class SecureButtonView extends Button { + + public SecureButtonView(Context context) { + this(context, null); + } + + public SecureButtonView(Context context, AttributeSet attrs) { + this(context, attrs, 0); + } + + public SecureButtonView(Context context, AttributeSet attrs, int defStyleAttr) { + this(context, attrs, defStyleAttr, 0); + } + + public SecureButtonView(Context context, AttributeSet attrs, int defStyleAttr, + int defStyleRes) { + super(context, attrs, defStyleAttr, defStyleRes); + } + + @Override + public boolean onFilterTouchEventForSecurity(MotionEvent event) { + if ((event.getFlags() & MotionEvent.FLAG_WINDOW_IS_OBSCURED) != 0 + || (event.getFlags() & MotionEvent.FLAG_WINDOW_IS_PARTIALLY_OBSCURED) != 0) { + // Window is obscured, drop this touch. + return false; + } + return true; + } +} |