commit | e2ee0f86ab8c2c0c2ac34709282b9d52a6344be5 | [log] [tgz] |
---|---|---|
author | Ioana Alexandru <aioana@google.com> | Fri May 12 15:41:09 2023 +0000 |
committer | Android Build Coastguard Worker <android-build-coastguard-worker@google.com> | Wed Jun 14 00:37:13 2023 +0000 |
tree | 9b30021573e5d61c5e47d488987cff3f8bbed374 | |
parent | 40659fabbd69dd0b757c7cfac09f443f63aea280 [diff] |
Implement visitUris for RemoteViews ViewGroupActionAdd. This is to prevent a vulnerability where notifications can show resources belonging to other users, since the URI in the nested views was not being checked. Bug: 277740082 Test: atest RemoteViewsTest NotificationVisitUrisTest (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:850fd984e5f346645b5a941ed7307387c7e4c4de) Merged-In: I5c71f0bad0a6f6361eb5ceffe8d1e47e936d78f8 Change-Id: I5c71f0bad0a6f6361eb5ceffe8d1e47e936d78f8