summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJoe Fernandez <joefernandez@google.com>2015-04-23 17:45:19 +0000
committerAndroid Git Automerger <android-git-automerger@android.com>2015-04-23 17:45:19 +0000
commit1009c8de23920c4a368edf7f1e2ecde63e40ec82 (patch)
treeafd9a96bccd442e254cc8c07d6aa5bb6228b3fe5
parent66b087d8c13e71a587904eaf305d5fc143c57026 (diff)
parent92ae292e864287abcb1a78c117263f64b303b885 (diff)
downloadframeworks_base-1009c8de23920c4a368edf7f1e2ecde63e40ec82.zip
frameworks_base-1009c8de23920c4a368edf7f1e2ecde63e40ec82.tar.gz
frameworks_base-1009c8de23920c4a368edf7f1e2ecde63e40ec82.tar.bz2
am 92ae292e: Merge "docs: Add text to JavaDocs regarding browser file access vulnerability" into lmp-mr1-ub-docs
* commit '92ae292e864287abcb1a78c117263f64b303b885': docs: Add text to JavaDocs regarding browser file access vulnerability
-rw-r--r--core/java/android/webkit/WebSettings.java8
1 files changed, 6 insertions, 2 deletions
diff --git a/core/java/android/webkit/WebSettings.java b/core/java/android/webkit/WebSettings.java
index 1d2c311..ef9aaf1 100644
--- a/core/java/android/webkit/WebSettings.java
+++ b/core/java/android/webkit/WebSettings.java
@@ -900,7 +900,9 @@ public abstract class WebSettings {
* and therefore secure policy, this setting should be disabled.
* Note that this setting affects only JavaScript access to file scheme
* resources. Other access to such resources, for example, from image HTML
- * elements, is unaffected.
+ * elements, is unaffected. To prevent possible violation of same domain policy
+ * on {@link android.os.Build.VERSION_CODES#ICE_CREAM_SANDWICH} and earlier
+ * devices, you should explicitly set this value to {@code false}.
* <p>
* The default value is true for API level
* {@link android.os.Build.VERSION_CODES#ICE_CREAM_SANDWICH_MR1} and below,
@@ -920,7 +922,9 @@ public abstract class WebSettings {
* the value of {@link #getAllowUniversalAccessFromFileURLs} is true.
* Note too, that this setting affects only JavaScript access to file scheme
* resources. Other access to such resources, for example, from image HTML
- * elements, is unaffected.
+ * elements, is unaffected. To prevent possible violation of same domain policy
+ * on {@link android.os.Build.VERSION_CODES#ICE_CREAM_SANDWICH} and earlier
+ * devices, you should explicitly set this value to {@code false}.
* <p>
* The default value is true for API level
* {@link android.os.Build.VERSION_CODES#ICE_CREAM_SANDWICH_MR1} and below,