Merge "WebView: Update setAllowFileAccess doc to reflect new default value" into rvc-dev am: 44e0da66e2 am: e1eaa48d35

Change-Id: I746f1ef936446721f4cb98c51ba92ceb0ee485d2
This commit is contained in:
Automerger Merge Worker
2020-02-26 18:08:23 +00:00

View File

@@ -369,10 +369,22 @@ public abstract class WebSettings {
public abstract boolean getDisplayZoomControls(); public abstract boolean getDisplayZoomControls();
/** /**
* Enables or disables file access within WebView. File access is enabled by * Enables or disables file access within WebView.
* default. Note that this enables or disables file system access only. * Note that this enables or disables file system access only. Assets and resources
* Assets and resources are still accessible using file:///android_asset and * are still accessible using file:///android_asset and file:///android_res.
* file:///android_res. * <p class="note">
* <b>Note:</b> Apps should not open {@code file://} URLs from any external source in
* WebView, don't enable this if your app accepts arbitrary URLs from external sources.
* It's recommended to always use
* <a href="{@docRoot}reference/androidx/webkit/WebViewAssetLoader">
* androidx.webkit.WebViewAssetLoader</a> to access files including assets and resources over
* {@code http(s)://} schemes, instead of {@code file://} URLs. To prevent possible security
* issues targeting {@link android.os.Build.VERSION_CODES#Q} and earlier, you should explicitly
* set this value to {@code false}.
* <p>
* The default value is {@code true} for apps targeting
* {@link android.os.Build.VERSION_CODES#Q} and below, and {@code false} when targeting
* {@link android.os.Build.VERSION_CODES#R} and above.
*/ */
public abstract void setAllowFileAccess(boolean allow); public abstract void setAllowFileAccess(boolean allow);