Prevent sharesheet from previewing unowned URIs
Bug: 261036568 Test: manually via supplied tool (see bug) Change-Id: I582bacca197d814204b48b917a550f72dbde87d6 Merged-In: Ib3f5839d00c7cf09bca3b01fc0a8a6f0f4960993 Merged-In: Iee1a75ef6ecbf471badeb42d8ebea11e74d884c1 Merged-In: I83e93c373538460e38ec17f1fd8e39d7aea95c10
This commit is contained in:
@@ -16,6 +16,8 @@
|
|||||||
|
|
||||||
package com.android.internal.app;
|
package com.android.internal.app;
|
||||||
|
|
||||||
|
import static android.content.ContentProvider.getUserIdFromUri;
|
||||||
|
|
||||||
import static java.lang.annotation.RetentionPolicy.SOURCE;
|
import static java.lang.annotation.RetentionPolicy.SOURCE;
|
||||||
|
|
||||||
import android.animation.Animator;
|
import android.animation.Animator;
|
||||||
@@ -149,6 +151,7 @@ import java.util.HashSet;
|
|||||||
import java.util.List;
|
import java.util.List;
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
import java.util.Set;
|
import java.util.Set;
|
||||||
|
import java.util.stream.Collectors;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* The Chooser Activity handles intent resolution specifically for sharing intents -
|
* The Chooser Activity handles intent resolution specifically for sharing intents -
|
||||||
@@ -1375,7 +1378,7 @@ public class ChooserActivity extends ResolverActivity implements
|
|||||||
|
|
||||||
ImageView previewThumbnailView = contentPreviewLayout.findViewById(
|
ImageView previewThumbnailView = contentPreviewLayout.findViewById(
|
||||||
R.id.content_preview_thumbnail);
|
R.id.content_preview_thumbnail);
|
||||||
if (previewThumbnail == null) {
|
if (!validForContentPreview(previewThumbnail)) {
|
||||||
previewThumbnailView.setVisibility(View.GONE);
|
previewThumbnailView.setVisibility(View.GONE);
|
||||||
} else {
|
} else {
|
||||||
mPreviewCoord = new ContentPreviewCoordinator(contentPreviewLayout, false);
|
mPreviewCoord = new ContentPreviewCoordinator(contentPreviewLayout, false);
|
||||||
@@ -1403,6 +1406,10 @@ public class ChooserActivity extends ResolverActivity implements
|
|||||||
String action = targetIntent.getAction();
|
String action = targetIntent.getAction();
|
||||||
if (Intent.ACTION_SEND.equals(action)) {
|
if (Intent.ACTION_SEND.equals(action)) {
|
||||||
Uri uri = targetIntent.getParcelableExtra(Intent.EXTRA_STREAM);
|
Uri uri = targetIntent.getParcelableExtra(Intent.EXTRA_STREAM);
|
||||||
|
if (!validForContentPreview(uri)) {
|
||||||
|
contentPreviewLayout.setVisibility(View.GONE);
|
||||||
|
return contentPreviewLayout;
|
||||||
|
}
|
||||||
imagePreview.findViewById(R.id.content_preview_image_1_large)
|
imagePreview.findViewById(R.id.content_preview_image_1_large)
|
||||||
.setTransitionName(ChooserActivity.FIRST_IMAGE_PREVIEW_TRANSITION_NAME);
|
.setTransitionName(ChooserActivity.FIRST_IMAGE_PREVIEW_TRANSITION_NAME);
|
||||||
mPreviewCoord.loadUriIntoView(R.id.content_preview_image_1_large, uri, 0);
|
mPreviewCoord.loadUriIntoView(R.id.content_preview_image_1_large, uri, 0);
|
||||||
@@ -1412,7 +1419,7 @@ public class ChooserActivity extends ResolverActivity implements
|
|||||||
List<Uri> uris = targetIntent.getParcelableArrayListExtra(Intent.EXTRA_STREAM);
|
List<Uri> uris = targetIntent.getParcelableArrayListExtra(Intent.EXTRA_STREAM);
|
||||||
List<Uri> imageUris = new ArrayList<>();
|
List<Uri> imageUris = new ArrayList<>();
|
||||||
for (Uri uri : uris) {
|
for (Uri uri : uris) {
|
||||||
if (isImageType(resolver.getType(uri))) {
|
if (validForContentPreview(uri) && isImageType(resolver.getType(uri))) {
|
||||||
imageUris.add(uri);
|
imageUris.add(uri);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -1521,9 +1528,16 @@ public class ChooserActivity extends ResolverActivity implements
|
|||||||
String action = targetIntent.getAction();
|
String action = targetIntent.getAction();
|
||||||
if (Intent.ACTION_SEND.equals(action)) {
|
if (Intent.ACTION_SEND.equals(action)) {
|
||||||
Uri uri = targetIntent.getParcelableExtra(Intent.EXTRA_STREAM);
|
Uri uri = targetIntent.getParcelableExtra(Intent.EXTRA_STREAM);
|
||||||
|
if (!validForContentPreview(uri)) {
|
||||||
|
contentPreviewLayout.setVisibility(View.GONE);
|
||||||
|
return contentPreviewLayout;
|
||||||
|
}
|
||||||
loadFileUriIntoView(uri, contentPreviewLayout);
|
loadFileUriIntoView(uri, contentPreviewLayout);
|
||||||
} else {
|
} else {
|
||||||
List<Uri> uris = targetIntent.getParcelableArrayListExtra(Intent.EXTRA_STREAM);
|
List<Uri> uris = targetIntent.getParcelableArrayListExtra(Intent.EXTRA_STREAM);
|
||||||
|
uris = uris.stream()
|
||||||
|
.filter(ChooserActivity::validForContentPreview)
|
||||||
|
.collect(Collectors.toList());
|
||||||
int uriCount = uris.size();
|
int uriCount = uris.size();
|
||||||
|
|
||||||
if (uriCount == 0) {
|
if (uriCount == 0) {
|
||||||
@@ -1577,6 +1591,24 @@ public class ChooserActivity extends ResolverActivity implements
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Indicate if the incoming content URI should be allowed.
|
||||||
|
*
|
||||||
|
* @param uri the uri to test
|
||||||
|
* @return true if the URI is allowed for content preview
|
||||||
|
*/
|
||||||
|
private static boolean validForContentPreview(Uri uri) throws SecurityException {
|
||||||
|
if (uri == null) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
int userId = getUserIdFromUri(uri, UserHandle.USER_CURRENT);
|
||||||
|
if (userId != UserHandle.USER_CURRENT && userId != UserHandle.myUserId()) {
|
||||||
|
Log.e(TAG, "dropped invalid content URI belonging to user " + userId);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
@VisibleForTesting
|
@VisibleForTesting
|
||||||
protected boolean isImageType(String mimeType) {
|
protected boolean isImageType(String mimeType) {
|
||||||
return mimeType != null && mimeType.startsWith("image/");
|
return mimeType != null && mimeType.startsWith("image/");
|
||||||
|
|||||||
Reference in New Issue
Block a user