Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[android] Prevent malformed callbackId from reaching app cordova view #436

Merged
merged 1 commit into from
Mar 2, 2019

Conversation

purplecabbage
Copy link
Contributor

Platforms affected

Android

Motivation and Context

Certain poorly formed callbackId(s) could be used to execute js code in the context of the cordova app.

Description

Uses a regex check to make sure the callbackId requested matches the pattern. This is the same pattern matching code that is already used in iOS.

Testing

Manually tested.

Checklist

  • I've run the tests to see all new and existing tests pass
  • I added automated test coverage as appropriate for this change
  • Commit is prefixed with (platform) if this change only applies to one platform (e.g. (android))
  • If this Pull Request resolves an issue, I linked to the issue in the text above (and used the correct keyword to close issues using keywords)
  • I've updated the documentation if necessary

Copy link
Member

@dpogue dpogue left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@purplecabbage purplecabbage merged commit c95dbcb into apache:master Mar 2, 2019
@purplecabbage purplecabbage deleted the ValidateCallbackId branch March 2, 2019 04:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants