commit | 0b258f030a589c83b8499d2f994c268bee92abba | [log] [tgz] |
---|---|---|
author | Jake Klinker <jklinker@google.com> | Tue Jan 11 00:38:23 2022 +0000 |
committer | Jake Klinker <jklinker@google.com> | Tue Jan 11 00:38:25 2022 +0000 |
tree | 005f1f4b4942fd1cddf4d1eb82960d3646665c1b | |
parent | f3a176524cc9d68343c29c46f672d03047f102d2 [diff] |
Fix isFileUri to recognize URIs with spaces. The underlying framework recognizes " file://..." as a valid URI and fetches the file, allowing for a possible exploit (see b/209965112). This trims the URI so that we can properly recognize it as a file from within our code. Bug: 209965112 Change-Id: I8d9d9100e9a8c3bd64d19015d2177a14ec2306f3 Test: See repro steps on http://b/209965112, was no longer able to repro.