java.lang.SecurityException:调用者uid XXXXX缺少任何android.permission.GET_ACCOUNTS

时间:2016-04-25 22:02:00

标签: android android-securityexception

注意:这不是重复的,我在类似的StackOverflow问题中尝试了很多解决方案,但在我的情况下它们不起作用。谢谢你的帮助。

此崩溃似乎只发生在运行Android版本低于6.0的设备上。例如,它在运行Android 5.1版的XT1032上崩溃。在这种情况下,每当我调用此方法时,在我的AppCompatActivity的onCreate方法中,

AccountManager.get(this).addOnAccountsUpdatedListener(this, null, true);

它崩溃了,因为它似乎没有所需的权限(我不知道为什么,因为它在清单中)。我相信它并没有真正进入方法,但由于@RequiresPermission行而输入方法时崩溃:

@RequiresPermission(GET_ACCOUNTS)
    public void addOnAccountsUpdatedListener(final OnAccountsUpdateListener listener,
            Handler handler, boolean updateImmediately) { ...

这是堆栈跟踪,还有一些日志记录代码:

V/AccountManagerService: getAccounts: accountType null, caller's uid 10018, pid 23074
V/AccountManagerService:   caller uid 10018 has android.permission.GET_ACCOUNTS
V/AccountManagerService: getAccounts: accountType null, caller's uid 10018, pid 23074
V/AccountManagerService:   caller uid 10018 has android.permission.GET_ACCOUNTS
V/AccountManagerService:   caller uid 10009 has android.permission.INTERACT_ACROSS_USERS
V/AccountManagerService: getAccounts: accountType com.google, caller's uid 10009, pid 1738
V/AccountManagerService:   caller uid 10009 has android.permission.GET_ACCOUNTS
V/AccountManagerService: getAccounts: accountType null, caller's uid 10018, pid 23074
V/AccountManagerService:   caller uid 10018 has android.permission.GET_ACCOUNTS
V/AccountManagerService: getAccounts: accountType null, caller's uid 10156, pid 13722
W/AccountManagerService:   caller uid 10156 lacks any of android.permission.GET_ACCOUNTS

java.lang.RuntimeException: Unable to start activity ComponentInfo{MainActivity}: java.lang.SecurityException: caller uid 10156 lacks any of android.permission.GET_ACCOUNTS
                                                                                             at android.app.ActivityThread.performLaunchActivity(ActivityThread.java:2325)
                                                                                             at android.app.ActivityThread.handleLaunchActivity(ActivityThread.java:2387)
                                                                                             at android.app.ActivityThread.access$800(ActivityThread.java:151)
                                                                                             at android.app.ActivityThread$H.handleMessage(ActivityThread.java:1303)
                                                                                             at android.os.Handler.dispatchMessage(Handler.java:102)
                                                                                             at android.os.Looper.loop(Looper.java:135)
                                                                                             at android.app.ActivityThread.main(ActivityThread.java:5254)
                                                                                             at java.lang.reflect.Method.invoke(Native Method)
                                                                                             at java.lang.reflect.Method.invoke(Method.java:372)
                                                                                             at com.android.internal.os.ZygoteInit$MethodAndArgsCaller.run(ZygoteInit.java:903)
                                                                                             at com.android.internal.os.ZygoteInit.main(ZygoteInit.java:698)
                                                                                          Caused by: java.lang.SecurityException: caller uid 10156 lacks any of android.permission.GET_ACCOUNTS
                                                                                             at android.os.Parcel.readException(Parcel.java:1546)
                                                                                             at android.os.Parcel.readException(Parcel.java:1499)
                                                                                             at android.accounts.IAccountManager$Stub$Proxy.getAccounts(IAccountManager.java:728)
                                                                                             at android.accounts.AccountManager.getAccounts(AccountManager.java:407)
                                                                                             at android.accounts.AccountManager.addOnAccountsUpdatedListener(AccountManager.java:2372)

什么是来电者uid,为什么使用具有权限的10156代替1001810009

我验证了我的AuthenticationService中的帐户类型字符串与authenticator.xml的accountType相同,并且它们都使用硬编码字符串(不是字符串资源)。

public class AuthenticationService extends Service {

    public static final String ACCOUNT_TYPE = "com.mywebsite";
    ...
    public static boolean createAccount(String username,...) {

        AccountManager am = AccountManager.get(Application.getInstance());
        Account account = new Account(username, ACCOUNT_TYPE);

我的身份验证员:

<account-authenticator xmlns:android="http://schemas.android.com/apk/res/android"
                       android:accountType="com.mywebsite"
                       android:icon="@mipmap/ic_launcher"
                       android:smallIcon="@mipmap/ic_launcher"
                       android:label="@string/app_name"
    />

我也有这个: <uses-permission android:name="android.permission.GET_ACCOUNTS" /><manifest>标记中,而不是<application>标记。清单:

<?xml version="1.0" encoding="utf-8"?>
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
    package="com.mywebsite.android.department.departmentname” >

    <uses-permission android:name="android.permission.INTERNET" />
    <uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />
    <uses-permission android:name="android.permission.WRITE_EXTERNAL_STORAGE" />
    <uses-permission android:name="android.permission.ACCESS_COARSE_LOCATION" />
    <uses-permission android:name="android.permission.ACCESS_FINE_LOCATION" />
    <uses-permission android:name="com.google.android.providers.gsf.permission.READ_GSERVICES" />
    <uses-permission android:name="android.permission.GET_ACCOUNTS" />
    <uses-permission android:name="android.permission.USE_CREDENTIALS" />
    <uses-permission android:name="android.permission.MANAGE_ACCOUNTS" />
    <uses-permission android:name="android.permission.AUTHENTICATE_ACCOUNTS" />
    <uses-permission android:name="android.permission.WRITE_SYNC_SETTINGS" />
    <uses-permission android:name="android.permission.READ_SYNC_SETTINGS" />
    <uses-permission android:name="android.permission.READ_CALENDAR" />
    <uses-permission android:name="android.permission.WRITE_CALENDAR" />
    <uses-permission android:name="android.permission.WAKE_LOCK"/>
    <uses-permission android:name="com.google.android.c2dm.permission.RECEIVE"/>
    <uses-permission android:name="android.permission.READ_LOGS"/>

    <application
        android:name=".Application"
        android:icon="@mipmap/ic_launcher"
        android:label="@string/app_name”>
        <service android:name=".auth.AuthenticationService" >
            <intent-filter>
                <action android:name="android.accounts.AccountAuthenticator" />
            </intent-filter>

            <meta-data
                android:name="android.accounts.AccountAuthenticator"
                android:resource="@xml/authenticator" />
        </service>

    </application>

</manifest>

这似乎是Android文档中的线索,但它似乎与我的错误无关,因为我确实拥有清单(http://developer.android.com/reference/android/Manifest.permission.html#GET_ACCOUNTS)中的权限:

  

注意:从Android 6.0(API级别23)开始,如果应用程序共享   管理帐户的验证者的签名,但它没有   需要“GET_ACCOUNTS”权限才能阅读有关该帐户的信息。   在Android 5.1及更低版本中,所有应用都需要“GET_ACCOUNTS”权限   阅读有关任何帐户的信息。

1 个答案:

答案 0 :(得分:5)

事实证明,我正在使用的库存在冲突。具体来说,图书馆的支持团队告诉我:

  

图层SDK使用a请求GET_ACCOUNTS权限   maxSdkVersion of 18.看来当清单出现时   合并这会覆盖清单中的权限请求,   因此不要求19 +的许可。

解决方案是改变我的清单:

<uses-permission android:name="android.permission.GET_ACCOUNTS" />

到此:

<uses-permission android:name="android.permission.GET_ACCOUNTS" tools:node="replace" />

具体而言,添加tools:node="replace"

有关详情,请参阅我对其他问题的回答:https://stackoverflow.com/a/37013603/2423194