)]}'
{
  "commit": "1b48ca6b7f44bacdb7b9469bfaf08fe4881ea0ae",
  "tree": "62f5281c10f940793dd6a0eadc8c9bf2a6fba344",
  "parents": [
    "d06f5f0f745ad8c765867fa28043f29425bde3a4"
  ],
  "author": {
    "name": "Oli Lan",
    "email": "olilan@google.com",
    "time": "Fri Aug 26 17:35:21 2022 +0100"
  },
  "committer": {
    "name": "Oli Lan",
    "email": "olilan@google.com",
    "time": "Fri Aug 26 17:16:55 2022 +0000"
  },
  "message": "Prevent exfiltration of system files via avatar picker.\n\nThis adds mitigations to prevent system files being exfiltrated\nvia the settings content provider when a content URI is provided\nas a chosen user image.\n\nThe mitigations are:\n\n1) Copy the image to a new URI rather than the existing takePictureUri\nprior to cropping.\n\n2) Only allow a system handler to respond to the CROP intent.\n\nThis is a fixed version of ag/17071224, to address b/239513606.\n\nBug: 187702830\nTest: build and check functionality\nChange-Id: Ie352d07bbcfc7e0b0a1db1dbe3fd43085e0ecbb6\nMerged-In: Idf1ab60878d619ee30505d71e8afe31d8b0c0ebe\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "f9584a3e15e9a7a789316b42307ae859b5959b99",
      "old_mode": 33188,
      "old_path": "packages/SettingsLib/src/com/android/settingslib/users/EditUserPhotoController.java",
      "new_id": "0c6cd048619cb6a12cc3b59f0b2665315465bba9",
      "new_mode": 33188,
      "new_path": "packages/SettingsLib/src/com/android/settingslib/users/EditUserPhotoController.java"
    }
  ]
}
