From bc22d8638b0c3ba4e5c6a5c874588d74403f309b Mon Sep 17 00:00:00 2001 From: Nate Fischer Date: Fri, 14 Feb 2020 15:04:56 -0800 Subject: [PATCH] WebView: deprecate 'Secure' cookies for insecure schemes No change to logic, only docs. This announces 'Secure' cookies are deprecated for insecure URL schemes (only "https://" is considered secure). This doesn't mention target SDK, because apps should follow this guidance for all WebView versions, target SDKs, and OS levels. Bug: 149589092 Test: m offline-sdk-docs -j4 Change-Id: I07c2b5341588d354f7f8219ce71a3d2ca04bc982 --- core/java/android/webkit/CookieManager.java | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/core/java/android/webkit/CookieManager.java b/core/java/android/webkit/CookieManager.java index 3824c22a40a73..ff80ef7b2e944 100644 --- a/core/java/android/webkit/CookieManager.java +++ b/core/java/android/webkit/CookieManager.java @@ -102,6 +102,9 @@ public abstract class CookieManager { * path and name will be replaced with the new cookie. The cookie being set * will be ignored if it is expired. * + *

Note: if specifying a {@code value} containing the {@code "Secure"} + * attribute, {@code url} must use the {@code "https://"} scheme. + * * @param url the URL for which the cookie is to be set * @param value the cookie as a string, using the format of the 'Set-Cookie' * HTTP response header @@ -122,6 +125,9 @@ public abstract class CookieManager { * completes or whether it succeeded, and in this case it is safe to call the method from a * thread without a Looper. * + *

Note: if specifying a {@code value} containing the {@code "Secure"} + * attribute, {@code url} must use the {@code "https://"} scheme. + * * @param url the URL for which the cookie is to be set * @param value the cookie as a string, using the format of the 'Set-Cookie' * HTTP response header