commit | 6e0ca5609517ce10485a1a44b6f43ec64ea16f3b | [log] [tgz] |
---|---|---|
author | Jake Klinker <jklinker@google.com> | Tue Jan 11 00:38:23 2022 +0000 |
committer | Jake Klinker <jklinker@google.com> | Tue Jan 11 00:41:38 2022 +0000 |
tree | 773fe30b5ce1718bbcdd7f95536fd36e5eea25e0 | |
parent | 92ce41890677fda24459627e86e9d19a0e39f78e [diff] |
Fix isFileUri to recognize URIs with spaces. The underlying framework recognizes " file://..." as a valid URI and fetches the file, allowing for a possible exploit (see b/209965112). This trims the URI so that we can properly recognize it as a file from within our code. Bug: 209965112 Change-Id: I8d9d9100e9a8c3bd64d19015d2177a14ec2306f3 Test: See repro steps on http://b/209965112, was no longer able to repro.