浏览代码

Disable plugins and file access from the web view

This is probably not required here and good practise as a further hardening.
Lukas Reschke 9 年之前
父节点
当前提交
8af7a5f8cb
共有 1 个文件被更改,包括 4 次插入2 次删除
  1. 4 2
      src/com/owncloud/android/ui/dialog/SamlWebViewDialog.java

+ 4 - 2
src/com/owncloud/android/ui/dialog/SamlWebViewDialog.java

@@ -158,7 +158,9 @@ public class SamlWebViewDialog extends DialogFragment {
             webSettings.setSupportZoom(true);
             webSettings.setBuiltInZoomControls(true);
             webSettings.setDisplayZoomControls(false);
-            
+            webSettings.setAllowFileAccess(false);
+            webSettings.setPluginsEnabled(false);
+
             CookieManager cookieManager = CookieManager.getInstance();
             cookieManager.setAcceptCookie(true);
             cookieManager.removeAllCookie();
@@ -273,4 +275,4 @@ public class SamlWebViewDialog extends DialogFragment {
         super.show(manager, tag);
     }
     
-}
+}