commit | f5d3e74ecc2b973941d8adbe40c6b23094b5abb7 | [log] [tgz] |
---|---|---|
author | Carlos Valdivia <carlosvaldivia@google.com> | Sun Sep 07 17:45:58 2014 -0700 |
committer | Carlos Valdivia <carlosvaldivia@google.com> | Sun Sep 07 17:45:58 2014 -0700 |
tree | 61bff12de48e8a7860b883e98e2495f29cde9619 | |
parent | 30c50b15d0d716567c71d590aa835dc4a27591d6 [diff] |
SECURITY: Don't pass a usable Pending Intent to 3rd parties. Unfortunately the Settings app has super powers. We shouldn't let untrusted 3rd party authenticators re-purpose those powers to their own nefarious ends. This means that we shouldn't pass along PendingIntents that can have addressing information (component, action, category) filled in by third parties. Bug: 17356824 Change-Id: I397d26c5f465ddfb0e58bbc66cd44756e58cc507