diff options
author | Carlos Valdivia <carlosvaldivia@google.com> | 2016-05-07 21:46:15 -0700 |
---|---|---|
committer | Carlos Valdivia <carlosvaldivia@google.com> | 2016-05-07 21:46:15 -0700 |
commit | 06329e5fb214ce6c2179b7fc7740c0fba41f084a (patch) | |
tree | 94dfcf4983106c10ce8d50dcf3065d854878caed /docs/html/sdk/api_diff/22/changes | |
parent | dce92891df42d5ad8cdcb6ecade5b2801a14f090 (diff) |
[Security] Prevent malicious notifications from AMS.
There was a hole in the getAuthToken logic that allowed notifications
resulting from getAuthToken requests using notifyOnAuthFailure=true to
launch arbitrary activites on the device. This is because the
getAuthToken session overrode onResult (unlike addAccount, updateCreds,
or confirmCreds).
Bug: 13787929
Change-Id: Ife1d48835f48416c2f0690f1413a076b69215190
Diffstat (limited to 'docs/html/sdk/api_diff/22/changes')
0 files changed, 0 insertions, 0 deletions