summaryrefslogtreecommitdiff
path: root/tools/aapt2/java/JavaClassGenerator.cpp
diff options
context:
space:
mode:
authorWinson <chiuwinson@google.com>2020-12-09 17:00:23 -0800
committerWinson Chiu <chiuwinson@google.com>2021-01-12 16:48:52 +0000
commit5a90c4c75b97ab1e2d0cb1c9abffb4e6969224af (patch)
treedd02f4c1632b59241a9f02f28d33793631fe310a /tools/aapt2/java/JavaClassGenerator.cpp
parent948bd61f09dbb83f7b18db27aaa5a651bdd70c38 (diff)
Only allow BROWSABLE && DEFAULT Intents to be always opened
Auto verification of app links requires that an intent filter declare action=VIEW, scheme=HTTP(S), category=BROWSABLE. However, PackageManagerService was not taking that into account, missing the category requirement. But the app info Settings UI did take category into account, so it was possible for a user to set an application to automatically open web URIs without understanding that this also granted domains that were not visible in the app info UI. To resolve both this, this change makes it so that both auto verification and the Settings state can only consider the app as "always" open only if the Intent contains both BROWSABLE and DEFAULT. Bug: 175139501 Bug: 175319005 Test: manual, see bug for reproduction steps Merged-In: Ib957258735893bf2779bed19bd400c6726ee6478 Change-Id: Ib957258735893bf2779bed19bd400c6726ee6478 (cherry picked from commit 4266f938c6705466d3844385c2031d1e80ee7b2d)
Diffstat (limited to 'tools/aapt2/java/JavaClassGenerator.cpp')
0 files changed, 0 insertions, 0 deletions