Commit 0fd2049f authored by Clemens Arbesser's avatar Clemens Arbesser Committed by Commit Bot

[Autofill Assistant] Changed feedback error message to address potential security issue.

Bug: 806868
Change-Id: Iee8f1ff42f8c76b7553ffce55d51ca5e54afd95b
Reviewed-on: https://chromium-review.googlesource.com/c/1340818Reviewed-by: default avatarMathias Carlen <mcarlen@chromium.org>
Commit-Queue: Clemens Arbesser <arbesser@google.com>
Cr-Commit-Position: refs/heads/master@{#609233}
parent d8110958
......@@ -20,7 +20,9 @@ class FeedbackContext extends JSONObject {
return new FeedbackContext(activity, client, details, statusMessage)
.toString(indentSpaces);
} catch (JSONException e) {
return "{\"error\": \"" + e.getMessage() + "\"}";
// Note: it is potentially unsafe to return e.getMessage(): the exception message
// could be wrangled and used as an attack vector when arriving at the JSON parser.
return "{\"error\": \"Failed to convert feedback context to string.\"}";
}
}
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment