Class ShieldStatus
Outcome of a shield operation.
The single most important distinction in this class is between "I could not reach the
attestation service" (NO_NETWORK, POOR_NETWORK, SERVICE_DOWN, RATE_LIMITED) and
"the attestation service looked at this device and said no" (REJECTED). An app should
almost always treat the first group as a transient condition to retry through, and only the
second as evidence that something is actually wrong with the device it is running on.
Collapsing the two into a single "attestation failed" boolean is the most common way to build
an app that either locks out users on a train or trusts a rooted phone.
This is a class of constants rather than an enum because the vocabulary is wire-visible: the
attestation engine may report a status that this build of the framework predates, and
getId() round-trips it rather than failing to resolve.
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final ShieldStatusThe device has no connectivity.static final ShieldStatusAppShield.init(ShieldConfig)has not been called yet.static final ShieldStatusThe operation succeeded and any token returned is usable.static final ShieldStatusThe certificate chain presented by a protected host matched no configured pin.static final ShieldStatusThe request timed out or DNS failed.static final ShieldStatusThis device is asking too often and is being throttled.static final ShieldStatusThe service evaluated this device and declined to issue a token.static final ShieldStatusThe attestation service answered with a server error.static final ShieldStatusThe app was built without the enterprise attestation engine. -
Method Summary
Modifier and TypeMethodDescriptionbooleanIndicates whether some other object is "equal to" this one.static ShieldStatusResolves a wire identifier to a constant, or synthesises a non-success status for an identifier this build does not know about.getId()The stable wire identifier, e.g.inthashCode()Returns a hash code value for the object.booleanTrue only forOK.booleanTrue when the failure is about reaching the service rather than about this device.toString()Returns a string representation of the object.
-
Field Details
-
OK
The operation succeeded and any token returned is usable. -
UNPROTECTED
The app was built without the enterprise attestation engine. Everything degrades to a no-op: no token is issued, no pin is enforced, and no request is blocked. -
NOT_INITIALIZED
AppShield.init(ShieldConfig)has not been called yet. -
NO_NETWORK
The device has no connectivity. Transient. -
POOR_NETWORK
The request timed out or DNS failed. Transient. -
SERVICE_DOWN
The attestation service answered with a server error. Transient. -
RATE_LIMITED
This device is asking too often and is being throttled. Transient, but back off before retrying rather than looping. -
REJECTED
The service evaluated this device and declined to issue a token. Not transient: the device itself is what failed the policy. Retrying will not help. -
PIN_MISMATCH
The certificate chain presented by a protected host matched no configured pin. The request was refused before any request body was sent.
-
-
Method Details
-
getId
The stable wire identifier, e.g.rateLimited. -
isSuccess
public boolean isSuccess()True only forOK. Every other status means no usable token was produced. -
isTransient
public boolean isTransient()True when the failure is about reaching the service rather than about this device. Retrying later may succeed. False forREJECTEDandPIN_MISMATCH, which describe the device and the connection respectively. -
forId
Resolves a wire identifier to a constant, or synthesises a non-success status for an identifier this build does not know about. Never returns null. -
toString
Description copied from class:ObjectReturns a string representation of the object. In general, the toString method returns a string that "textually represents" this object. The result should be a concise but informative representation that is easy for a person to read. It is recommended that all subclasses override this method. The toString method for class Object returns a string consisting of the name of the class of which the object is an instance, the at-sign character `@', and the unsigned hexadecimal representation of the hash code of the object. In other words, this method returns a string equal to the value of: getClass().getName() + '@' + Integer.toHexString(hashCode()) -
equals
Description copied from class:ObjectIndicates whether some other object is "equal to" this one. The equals method implements an equivalence relation: It is reflexive: for any reference value x, x.equals(x) should return true. It is symmetric: for any reference values x and y, x.equals(y) should return true if and only if y.equals(x) returns true. It is transitive: for any reference values x, y, and z, if x.equals(y) returns true and y.equals(z) returns true, then x.equals(z) should return true. It is consistent: for any reference values x and y, multiple invocations of x.equals(y) consistently return true or consistently return false, provided no information used in equals comparisons on the object is modified. For any non-null reference value x, x.equals(null) should return false. The equals method for class Object implements the most discriminating possible equivalence relation on objects; that is, for any reference values x and y, this method returns true if and only if x and y refer to the same object (x==y has the value true). -
hashCode
public int hashCode()Description copied from class:ObjectReturns a hash code value for the object. This method is supported for the benefit of hashtables such as those provided by java.util.Hashtable. The general contract of hashCode is: Whenever it is invoked on the same object more than once during an execution of a Java application, the hashCode method must consistently return the same integer, provided no information used in equals comparisons on the object is modified. This integer need not remain consistent from one execution of an application to another execution of the same application. If two objects are equal according to the equals(Object) method, then calling the hashCode method on each of the two objects must produce the same integer result. It is not required that if two objects are unequal according to the equals(java.lang.Object) method, then calling the hashCode method on each of the two objects must produce distinct integer results. However, the programmer should be aware that producing distinct integer results for unequal objects may improve the performance of hashtables. As much as is reasonably practical, the hashCode method defined by class Object does return distinct integers for distinct objects. (This is typically implemented by converting the internal address of the object into an integer, but this implementation technique is not required by the JavaTM programming language.)
-