commit | 70d27f1906eeb3c8ccda870b99a7aa2d5d723c7f | [log] [tgz] |
---|---|---|
author | Ioana Alexandru <aioana@google.com> | Fri May 12 15:41:09 2023 +0000 |
committer | Ioana Alexandru <aioana@google.com> | Tue May 16 10:44:53 2023 +0000 |
tree | 926bd03a28dbfe9f9c23ff9df51b1f2f559b5e66 | |
parent | 2d3194900d7c417db78758fdff63c602b62e8945 [diff] |
Implement visitUris for RemoteViews ViewGroupActionAdd. This is to prevent a vulnerability where notifications can show resources belonging to other users, since the URI in the nested views was not being checked. Bug: 277740082 Test: atest RemoteViewsTest NotificationVisitUrisTest Change-Id: I5c71f0bad0a6f6361eb5ceffe8d1e47e936d78f8