You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已声明权限仍触发ContentProvider权限拒绝问题求助

问题分析与解决思路

核心问题原因

你遇到的SecurityException本质是自定义权限未被系统识别:

  • 你使用的com.test.assets.READ_ASSETS是自定义权限,但没有在任何应用的AndroidManifest.xml中通过<permission>标签显式定义,导致Android系统无法验证该权限的合法性,即使service_app声明了<uses-permission>也无效。
  • 额外注意:service_app的服务运行在独立进程:service,不过只要应用全局声明了权限,所有进程都会继承,这不是核心问题,但权限定义缺失是关键。

具体解决步骤

1. 显式定义自定义权限

在content_app的AndroidManifest.xml根节点下添加自定义权限声明(因为它是ContentProvider的提供方,权限应由它定义):

<manifest xmlns:android="http://schemas.android.com/apk/res/android">
    <!-- 新增:定义自定义权限 -->
    <permission
        android:name="com.test.assets.READ_ASSETS"
        android:protectionLevel="normal" /> <!-- 根据需求选择保护级别,normal适合跨应用普通访问权限 -->

    <application>
        <!-- 原有内容不变 -->
    </application>
</manifest>

2. 确保双方应用都声明权限

  • service_app已经声明了<uses-permission android:name="com.test.assets.READ_ASSETS" />,保持不变。
  • 在content_app的AndroidManifest.xml中也添加该权限声明(避免自身访问Provider时出现权限问题,同时确保权限校验逻辑完整):
<manifest xmlns:android="http://schemas.android.com/apk/res/android">
    <permission
        android:name="com.test.assets.READ_ASSETS"
        android:protectionLevel="normal" />

    <!-- 新增:声明使用该权限 -->
    <uses-permission android:name="com.test.assets.READ_ASSETS" />

    <application>
        <!-- 原有内容不变 -->
    </application>
</manifest>

3. 修复代码中的小问题

你的代码里有两处语法错误,可能导致额外异常:

  • String package是Java关键字,改为String packageName
  • Log.e语句括号未闭合,修正后:
public AssetFileDescriptor getAssetFileDescriptor(String packageName) {
    AssetFileDescriptor fileDescriptor = null;
    String provider = packageName + ".ContentProviderAuth";
    Uri fileUri = Uri.parse("content://" + provider + "/AssetList");
    try {
        ContentProviderClient client = mContext.getContentResolver().acquireContentProviderClient(provider);
        if (client != null) {
            fileDescriptor = client.openAssetFile(fileUri, "r");
            client.close();
        }
    } catch (FileNotFoundException e) {
        Log.e("AssetManager", "getAssetFileDescriptor: " + e.toString());
    }
    return fileDescriptor;
}

补充说明

  • 自定义权限的protectionLevel选择:如果是仅信任的应用使用,可改为signature(要求调用方和提供方签名一致);如果是公开给任意应用,用normal或dangerous(后者需要动态申请)。
  • 若后续新增应用,只需在其Manifest中声明<uses-permission android:name="com.test.assets.READ_ASSETS" />,并确保自身的ContentProvider配置正确,即可复用service_app的服务。

内容的提问来源于stack exchange,提问作者kralvarado

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 16:23:18