Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Unsafe implementation of the HostnameVerifier interface

Đang mở
#20 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
38/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
java

Hướng nghiên cứu

Tìm trong mã nguồn Java các cách sử dụng HostnameVerifier và setHostnameVerifier, sau đó kiểm tra verifier tùy chỉnh và đường dẫn kết nối accordion được thể hiện trong issue. Được coi là hoàn tất khi implementation không còn mặc định tin cậy mọi hostname mà thay vào đó thực thi các bước kiểm tra hostname mong đợi mà không suppress các lỗi verification.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Google now is blocking updates to apps that include libraries that have "unsafe" HostnameVerifier implementations. They seem to pattern match the code so always returning true even from a HostnameVerifier that is only used in a safe context the fact that it always returns true seems to trip the filter.

https://support.google.com/faqs/answer/7188426

To properly handle hostname verification, change the implementation of your custom HostnameVerifier interface to perform the following actions:

  • If you are using the HostnameVerifier interface, change the implementation of the verify method to return false whenever the hostname of the server does not meet your expectations.
  • If you are using the X509HostnameVerifier interface, change the implementation of the verify methods (variants 1, 2, 3) to raise an SSLException whenever the hostname of the server does not meet your expectations. Ensure that the Exceptions raised within your verify implementation are not caught and suppressed within the method. Suppressing Exceptions in this manner would cause verify to exit normally, leading the app to trust all hostnames.
package com.deezer.sdk.network.b;

...

public class Blues {
  
  ...
  
  private static final HostnameVerifier bagpipes = new HostnameVerifier() {
      public final boolean verify(String hostname, SSLSession session) {
          return true;
      }
  };

  ...

  private static HttpURLConnection accordion(String var0, String var1, boolean var2) throws IOException {
      Object var3;
      if (var2) {
          ((HttpsURLConnection)(var3 = (HttpsURLConnection)(new URL(var0)).openConnection())).setHostnameVerifier(bagpipes);
      } else {
          var3 = (HttpURLConnection)(new URL(var0)).openConnection();
      }

      ((HttpURLConnection)var3).setRequestProperty("User-Agent", var1);
      return (HttpURLConnection)var3;
  }

  ...

}
Ngôn ngữ chính
Java
Star
42
Fork
25
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của deezer/android-sample

Tất cả issue của deezer/android-sample

Issue tương tự

Thêm issue về Java

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.