tree f5fb48cd33c18163257b076b82df95129c1a1494
parent 521e442b90ee20368be5d4dd33ec67e1f89872c7
author Rohan Shah <shahrk@google.com> 1455155152 -0800
committer The Android Automerger <android-build@android.com> 1456535211 -0800

Patch Exchange Autodiscover Code for Security Issue

The change removes the unauthenticated GET fallback attempt for the
Autodiscover process. Given that the Autodiscover code is functionally broken
and this fallback attempt wouldn't succeed unless an attacker faked a success
response, a good way to patch the security issue is to disable the attempt.

The change also updates the request content type, disables automatic
redirects, and allows for parsing namespaces to help the first two attempts
succeed. As this is not meant to be a functional patch but a security patch,
there are no further changes to the Autodiscover code.

BUG: 26488455
Change-Id: I0fc93c95e755c8fa60e94da5bec4b3b4c49cdfc1
