public final class ShieldStatus

  1. Object
  2. ShieldStatus

Outcome of a shield operation.

The single most important distinction in this class is between “I could not reach the attestation service” (NO_NETWORK, POOR_NETWORK, SERVICE_DOWN, RATE_LIMITED) and “the attestation service looked at this device and said no” (REJECTED). An app should almost always treat the first group as a transient condition to retry through, and only the second as evidence that something is actually wrong with the device it is running on. Collapsing the two into a single “attestation failed” boolean is the most common way to build an app that either locks out users on a train or trusts a rooted phone.

This is a class of constants rather than an enum because the vocabulary is wire-visible: the attestation engine may report a status that this build of the framework predates, and getId() round-trips it rather than failing to resolve.

Fields

public static final ShieldStatus OKThe operation succeeded and any token returned is usable.
public static final ShieldStatus UNPROTECTEDThe app was built without the enterprise attestation engine.
public static final ShieldStatus NOT_INITIALIZEDAppShield.init(ShieldConfig) has not been called yet.
public static final ShieldStatus NO_NETWORKThe device has no connectivity.
public static final ShieldStatus POOR_NETWORKThe request timed out or DNS failed.
public static final ShieldStatus SERVICE_DOWNThe attestation service answered with a server error.
public static final ShieldStatus RATE_LIMITEDThis device is asking too often and is being throttled.
public static final ShieldStatus REJECTEDThe service evaluated this device and declined to issue a token.
public static final ShieldStatus PIN_MISMATCHThe certificate chain presented by a protected host matched no configured pin.

Methods

public String getId()The stable wire identifier, e.g. rateLimited.
public boolean isSuccess()True only for OK.
public boolean isTransient()True when the failure is about reaching the service rather than about this device.
public static ShieldStatus forId(String id)Resolves a wire identifier to a constant, or synthesises a non-success status for an identifier this build does not know about.
public String toString()Returns a string representation of the object.
public boolean equals(Object o)Indicates whether some other object is “equal to” this one.
public int hashCode()Returns a hash code value for the object.

Inherited methods

Field details

OK

public static final ShieldStatus OK
The operation succeeded and any token returned is usable.

UNPROTECTED

public static final ShieldStatus UNPROTECTED
The app was built without the enterprise attestation engine. Everything degrades to a no-op: no token is issued, no pin is enforced, and no request is blocked.

NOT_INITIALIZED

public static final ShieldStatus NOT_INITIALIZED
AppShield.init(ShieldConfig) has not been called yet.

NO_NETWORK

public static final ShieldStatus NO_NETWORK
The device has no connectivity. Transient.

POOR_NETWORK

public static final ShieldStatus POOR_NETWORK
The request timed out or DNS failed. Transient.

SERVICE_DOWN

public static final ShieldStatus SERVICE_DOWN
The attestation service answered with a server error. Transient.

RATE_LIMITED

public static final ShieldStatus RATE_LIMITED
This device is asking too often and is being throttled. Transient, but back off before retrying rather than looping.

REJECTED

public static final ShieldStatus REJECTED
The service evaluated this device and declined to issue a token. Not transient: the device itself is what failed the policy. Retrying will not help.

PIN_MISMATCH

public static final ShieldStatus PIN_MISMATCH
The certificate chain presented by a protected host matched no configured pin. The request was refused before any request body was sent.

Method details

getId

public String getId()
The stable wire identifier, e.g. rateLimited.

isSuccess

public boolean isSuccess()
True only for OK. Every other status means no usable token was produced.

isTransient

public boolean isTransient()
True when the failure is about reaching the service rather than about this device. Retrying later may succeed. False for REJECTED and PIN_MISMATCH, which describe the device and the connection respectively.

forId

public static ShieldStatus forId(String id)
Resolves a wire identifier to a constant, or synthesises a non-success status for an identifier this build does not know about. Never returns null.

toString

public String toString()
Returns a string representation of the object. In general, the toString method returns a string that “textually represents” this object. The result should be a concise but informative representation that is easy for a person to read. It is recommended that all subclasses override this method. The toString method for class Object returns a string consisting of the name of the class of which the object is an instance, the at-sign character `@’, and the unsigned hexadecimal representation of the hash code of the object. In other words, this method returns a string equal to the value of: getClass().getName() + ‘@’ + Integer.toHexString(hashCode())

equals

public boolean equals(Object o)
Indicates whether some other object is “equal to” this one. The equals method implements an equivalence relation: It is reflexive: for any reference value x, x.equals(x) should return true. It is symmetric: for any reference values x and y, x.equals(y) should return true if and only if y.equals(x) returns true. It is transitive: for any reference values x, y, and z, if x.equals(y) returns true and y.equals(z) returns true, then x.equals(z) should return true. It is consistent: for any reference values x and y, multiple invocations of x.equals(y) consistently return true or consistently return false, provided no information used in equals comparisons on the object is modified. For any non-null reference value x, x.equals(null) should return false. The equals method for class Object implements the most discriminating possible equivalence relation on objects; that is, for any reference values x and y, this method returns true if and only if x and y refer to the same object (x==y has the value true).

hashCode

public int hashCode()
Returns a hash code value for the object. This method is supported for the benefit of hashtables such as those provided by java.util.Hashtable. The general contract of hashCode is: Whenever it is invoked on the same object more than once during an execution of a Java application, the hashCode method must consistently return the same integer, provided no information used in equals comparisons on the object is modified. This integer need not remain consistent from one execution of an application to another execution of the same application. If two objects are equal according to the equals(Object) method, then calling the hashCode method on each of the two objects must produce the same integer result. It is not required that if two objects are unequal according to the equals(java.lang.Object) method, then calling the hashCode method on each of the two objects must produce distinct integer results. However, the programmer should be aware that producing distinct integer results for unequal objects may improve the performance of hashtables. As much as is reasonably practical, the hashCode method defined by class Object does return distinct integers for distinct objects. (This is typically implemented by converting the internal address of the object into an integer, but this implementation technique is not required by the JavaTM programming language.)