public final class ShieldStatus
- Object
- ShieldStatus
Outcome of a shield operation.
The single most important distinction in this class is between “I could not reach the
attestation service” (NO_NETWORK, POOR_NETWORK, SERVICE_DOWN, RATE_LIMITED) and
“the attestation service looked at this device and said no” (REJECTED). An app should
almost always treat the first group as a transient condition to retry through, and only the
second as evidence that something is actually wrong with the device it is running on.
Collapsing the two into a single “attestation failed” boolean is the most common way to build
an app that either locks out users on a train or trusts a rooted phone.
This is a class of constants rather than an enum because the vocabulary is wire-visible: the
attestation engine may report a status that this build of the framework predates, and
getId() round-trips it rather than failing to resolve.
Fields
public static final ShieldStatus OK | The operation succeeded and any token returned is usable. |
public static final ShieldStatus UNPROTECTED | The app was built without the enterprise attestation engine. |
public static final ShieldStatus NOT_INITIALIZED | AppShield.init(ShieldConfig) has not been called yet. |
public static final ShieldStatus NO_NETWORK | The device has no connectivity. |
public static final ShieldStatus POOR_NETWORK | The request timed out or DNS failed. |
public static final ShieldStatus SERVICE_DOWN | The attestation service answered with a server error. |
public static final ShieldStatus RATE_LIMITED | This device is asking too often and is being throttled. |
public static final ShieldStatus REJECTED | The service evaluated this device and declined to issue a token. |
public static final ShieldStatus PIN_MISMATCH | The certificate chain presented by a protected host matched no configured pin. |
Methods
public String getId() | The stable wire identifier, e.g. rateLimited. |
public boolean isSuccess() | True only for OK. |
public boolean isTransient() | True when the failure is about reaching the service rather than about this device. |
public static ShieldStatus forId(String id) | Resolves a wire identifier to a constant, or synthesises a non-success status for an identifier this build does not know about. |
public String toString() | Returns a string representation of the object. |
public boolean equals(Object o) | Indicates whether some other object is “equal to” this one. |
public int hashCode() | Returns a hash code value for the object. |
Inherited methods
Field details
OK
public static final ShieldStatus OKUNPROTECTED
public static final ShieldStatus UNPROTECTEDNOT_INITIALIZED
public static final ShieldStatus NOT_INITIALIZEDAppShield.init(ShieldConfig) has not been called yet.NO_NETWORK
public static final ShieldStatus NO_NETWORKPOOR_NETWORK
public static final ShieldStatus POOR_NETWORKSERVICE_DOWN
public static final ShieldStatus SERVICE_DOWNRATE_LIMITED
public static final ShieldStatus RATE_LIMITEDREJECTED
public static final ShieldStatus REJECTEDPIN_MISMATCH
public static final ShieldStatus PIN_MISMATCHMethod details
getId
public String getId()rateLimited.isSuccess
public boolean isSuccess()OK. Every other status means no usable token was produced.isTransient
public boolean isTransient()REJECTED and PIN_MISMATCH, which describe the device and
the connection respectively.forId
public static ShieldStatus forId(String id)toString
public String toString()equals
public boolean equals(Object o)hashCode
public int hashCode()