summaryrefslogtreecommitdiff
path: root/api/api.go
diff options
context:
space:
mode:
author Oli Lan <olilan@google.com> 2022-02-23 13:12:20 +0000
committer Oli Lan <olilan@google.com> 2022-02-25 15:18:29 +0000
commit1325574d3a72fe2f8dba234ef04045565ab1aacb (patch)
treea04822d1031cc4f935c9a8a634a09f6fa0fe76c1 /api/api.go
parente8e79f89005042a51fe180f0e301304f54b4fba5 (diff)
Prevent exfiltration of system files via avatar picker.
This adds mitigations to prevent system files being exfiltrated via the settings content provider when a content URI is provided as a chosen user image. The mitigations are: 1) Copy the image to a new URI rather than the existing takePictureUri prior to cropping. 2) Only allow a system handler to respond to the CROP intent. Bug: 187702830 Test: atest AvatarPhotoControllerTest Change-Id: Idf1ab60878d619ee30505d71e8afe31d8b0c0ebe
Diffstat (limited to 'api/api.go')
0 files changed, 0 insertions, 0 deletions