diff options
| author | 2022-02-23 13:12:20 +0000 | |
|---|---|---|
| committer | 2022-02-25 15:18:29 +0000 | |
| commit | 1325574d3a72fe2f8dba234ef04045565ab1aacb (patch) | |
| tree | a04822d1031cc4f935c9a8a634a09f6fa0fe76c1 /api/api.go | |
| parent | e8e79f89005042a51fe180f0e301304f54b4fba5 (diff) | |
Prevent exfiltration of system files via avatar picker.
This adds mitigations to prevent system files being exfiltrated
via the settings content provider when a content URI is provided
as a chosen user image.
The mitigations are:
1) Copy the image to a new URI rather than the existing takePictureUri
prior to cropping.
2) Only allow a system handler to respond to the CROP intent.
Bug: 187702830
Test: atest AvatarPhotoControllerTest
Change-Id: Idf1ab60878d619ee30505d71e8afe31d8b0c0ebe
Diffstat (limited to 'api/api.go')
0 files changed, 0 insertions, 0 deletions