From 7c373d6c6d089c42502a70c6abc457606cc670df Mon Sep 17 00:00:00 2001 From: Ioana Alexandru Date: Wed, 31 Jul 2024 13:46:30 +0000 Subject: Check more URIs in notifications Bug: 281044385 Test: presubmit + tested in current release Change-Id: I1ce6bebd9452466d005505dc5b99a0fdc0e05e80 Merged-In: I1ce6bebd9452466d005505dc5b99a0fdc0e05e80 (cherry picked from commit f47b41a138ebd60f7b518fb6a9d8aa8230488422, includes changes from commit 57bf60dd7b6a0a0e9785231f8ec25a458fedde64 and commit 47fa2f79584b0a4e9ca7e9c6b237c4e5cf699032) --- core/java/android/app/Notification.java | 32 ++++++++++++++++--------------- core/java/android/app/Person.java | 17 ++++++++++++++++ core/java/android/widget/RemoteViews.java | 23 ++++++++++++++++++++++ 3 files changed, 57 insertions(+), 15 deletions(-) diff --git a/core/java/android/app/Notification.java b/core/java/android/app/Notification.java index ed8c6be73256..3aeb363b627b 100644 --- a/core/java/android/app/Notification.java +++ b/core/java/android/app/Notification.java @@ -2799,7 +2799,7 @@ public class Notification implements Parcelable ArrayList people = extras.getParcelableArrayList(EXTRA_PEOPLE_LIST); if (people != null && !people.isEmpty()) { for (Person p : people) { - visitor.accept(p.getIconUri()); + p.visitUris(visitor); } } @@ -2818,19 +2818,14 @@ public class Notification implements Parcelable // Notification Listeners might use directly (without the isStyle check). final Person person = extras.getParcelable(EXTRA_MESSAGING_PERSON); if (person != null) { - visitor.accept(person.getIconUri()); + person.visitUris(visitor); } final Parcelable[] messages = extras.getParcelableArray(EXTRA_MESSAGES); if (!ArrayUtils.isEmpty(messages)) { for (MessagingStyle.Message message : MessagingStyle.Message .getMessagesFromBundleArray(messages)) { - visitor.accept(message.getDataUri()); - - Person senderPerson = message.getSenderPerson(); - if (senderPerson != null) { - visitor.accept(senderPerson.getIconUri()); - } + message.visitUris(visitor); } } @@ -2838,12 +2833,7 @@ public class Notification implements Parcelable if (!ArrayUtils.isEmpty(historic)) { for (MessagingStyle.Message message : MessagingStyle.Message .getMessagesFromBundleArray(historic)) { - visitor.accept(message.getDataUri()); - - Person senderPerson = message.getSenderPerson(); - if (senderPerson != null) { - visitor.accept(senderPerson.getIconUri()); - } + message.visitUris(visitor); } } @@ -2852,7 +2842,7 @@ public class Notification implements Parcelable // Extras for CallStyle (same reason for visiting without checking isStyle). Person callPerson = extras.getParcelable(EXTRA_CALL_PERSON); if (callPerson != null) { - visitor.accept(callPerson.getIconUri()); + callPerson.visitUris(visitor); } visitIconUri(visitor, extras.getParcelable(EXTRA_VERIFICATION_ICON)); } @@ -8557,6 +8547,18 @@ public class Notification implements Parcelable return bundles; } + /** + * See {@link Notification#visitUris(Consumer)}. + * + * @hide + */ + public void visitUris(@NonNull Consumer visitor) { + visitor.accept(getDataUri()); + if (mSender != null) { + mSender.visitUris(visitor); + } + } + /** * Returns a list of messages read from the given bundle list, e.g. * {@link #EXTRA_MESSAGES} or {@link #EXTRA_HISTORIC_MESSAGES}. diff --git a/core/java/android/app/Person.java b/core/java/android/app/Person.java index 97a794d4e4ea..c7432c571e43 100644 --- a/core/java/android/app/Person.java +++ b/core/java/android/app/Person.java @@ -24,6 +24,7 @@ import android.os.Parcel; import android.os.Parcelable; import java.util.Objects; +import java.util.function.Consumer; /** * Provides an immutable reference to an entity that appears repeatedly on different surfaces of the @@ -177,6 +178,22 @@ public final class Person implements Parcelable { dest.writeBoolean(mIsBot); } + /** + * Note all {@link Uri} that are referenced internally, with the expectation that Uri permission + * grants will need to be issued to ensure the recipient of this object is able to render its + * contents. + * See b/281044385 for more context and examples about what happens when this isn't done + * correctly. + * + * @hide + */ + public void visitUris(@NonNull Consumer visitor) { + visitor.accept(getIconUri()); + if (mUri != null && !mUri.isEmpty()) { + visitor.accept(Uri.parse(mUri)); + } + } + /** Builder for the immutable {@link Person} class. */ public static class Builder { @Nullable private CharSequence mName; diff --git a/core/java/android/widget/RemoteViews.java b/core/java/android/widget/RemoteViews.java index cecfa08c6e20..0747308eb93a 100644 --- a/core/java/android/widget/RemoteViews.java +++ b/core/java/android/widget/RemoteViews.java @@ -934,6 +934,13 @@ public class RemoteViews implements Parcelable, Filter { return SET_REMOTE_VIEW_ADAPTER_LIST_TAG; } + @Override + public void visitUris(@NonNull Consumer visitor) { + for (RemoteViews remoteViews : list) { + remoteViews.visitUris(visitor); + } + } + int viewTypeCount; ArrayList list; } @@ -1009,6 +1016,13 @@ public class RemoteViews implements Parcelable, Filter { public int getActionTag() { return SET_REMOTE_COLLECTION_ITEMS_ADAPTER_TAG; } + + @Override + public void visitUris(@NonNull Consumer visitor) { + if (mItems != null) { + mItems.visitUris(visitor); + } + } } private class SetRemoteViewsAdapterIntent extends Action { @@ -6757,6 +6771,15 @@ public class RemoteViews implements Parcelable, Filter { Math.max(mViewTypeCount, 1)); } } + + /** + * See {@link RemoteViews#visitUris(Consumer)}. + */ + private void visitUris(@NonNull Consumer visitor) { + for (RemoteViews view : mViews) { + view.visitUris(visitor); + } + } } /** -- cgit v1.2.3-59-g8ed1b