diff options
author | Gary Mai <garymai@google.com> | 2018-10-30 17:45:26 -0700 |
---|---|---|
committer | android-build-merger <android-build-merger@google.com> | 2018-10-30 17:45:26 -0700 |
commit | f7a8623a09a6fe0d38b16fcfd81316f29235480d (patch) | |
tree | aa852c44fae73d65b145f7f65504109d7bc08d88 /tests/src/com | |
parent | 66def1143098399643424bbe622f6b61f58f2161 (diff) | |
parent | acdfb82c89a58e0493f786e074862dbfda93399a (diff) | |
download | Contacts-f7a8623a09a6fe0d38b16fcfd81316f29235480d.tar.gz |
[automerger] Patch URI vulnerability in contact photo editing am: ccfd94b965 am: 2fc4d78bfc am: fc6e94648d am: 3ffe76ed9c am: 456f745849 am: 9df22bbe22 am: b96186029f am: 655ad64631
am: acdfb82c89
Change-Id: I37aba4e1ee00a729115fd4cc325b5a2147787a4d
Diffstat (limited to 'tests/src/com')
-rw-r--r-- | tests/src/com/android/contacts/util/ContactPhotoUtilsTest.java | 49 |
1 files changed, 49 insertions, 0 deletions
diff --git a/tests/src/com/android/contacts/util/ContactPhotoUtilsTest.java b/tests/src/com/android/contacts/util/ContactPhotoUtilsTest.java new file mode 100644 index 000000000..d17b98c2d --- /dev/null +++ b/tests/src/com/android/contacts/util/ContactPhotoUtilsTest.java @@ -0,0 +1,49 @@ +package com.android.contacts.util; + +import android.net.Uri; +import android.test.AndroidTestCase; +import android.test.suitebuilder.annotation.SmallTest; + +/** + * Test cases for {@link ContactPhotoUtils}. + * + * adb shell am instrument -w -e class com.android.contacts.util.ContactPhotoUtilsTest \ + * com.android.contacts.tests/android.test.InstrumentationTestRunner + */ +@SmallTest +public class ContactPhotoUtilsTest extends AndroidTestCase { + + private Uri tempUri; + + @Override + protected void setUp() throws Exception { + tempUri = ContactPhotoUtils.generateTempImageUri(getContext()); + } + + protected void tearDown() throws Exception { + getContext().getContentResolver().delete(tempUri, null, null); + } + + public void testFileUriDataPathFails() { + String filePath = + "file:///data/data/com.android.contacts/shared_prefs/com.android.contacts.xml"; + + assertFalse( + ContactPhotoUtils.savePhotoFromUriToUri(getContext(), Uri.parse(filePath), tempUri, false)); + } + + public void testFileUriCanonicalDataPathFails() { + String filePath = + "file:///storage/../data/data/com.android.contacts/shared_prefs/com.android.contacts.xml"; + + assertFalse( + ContactPhotoUtils.savePhotoFromUriToUri(getContext(), Uri.parse(filePath), tempUri, false)); + } + + public void testContentUriInternalPasses() { + Uri internal = ContactPhotoUtils.generateTempImageUri(getContext()); + + assertTrue( + ContactPhotoUtils.savePhotoFromUriToUri(getContext(), internal, tempUri, true)); + } +} |