Unsafe implementation of the HostnameVerifier interface
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 38/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- java
- Lĩnh vực
- mobile-dev, networking, security
Hướng nghiên cứu
Tìm trong mã nguồn Java các cách sử dụng HostnameVerifier và setHostnameVerifier, sau đó kiểm tra verifier tùy chỉnh và đường dẫn kết nối accordion được thể hiện trong issue. Được coi là hoàn tất khi implementation không còn mặc định tin cậy mọi hostname mà thay vào đó thực thi các bước kiểm tra hostname mong đợi mà không suppress các lỗi verification.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Google now is blocking updates to apps that include libraries that have "unsafe" HostnameVerifier implementations. They seem to pattern match the code so always returning true even from a HostnameVerifier that is only used in a safe context the fact that it always returns true seems to trip the filter.
https://support.google.com/faqs/answer/7188426
To properly handle hostname verification, change the implementation of your custom HostnameVerifier interface to perform the following actions:
- If you are using the HostnameVerifier interface, change the implementation of the verify method to return false whenever the hostname of the server does not meet your expectations.
- If you are using the X509HostnameVerifier interface, change the implementation of the verify methods (variants 1, 2, 3) to raise an SSLException whenever the hostname of the server does not meet your expectations. Ensure that the Exceptions raised within your verify implementation are not caught and suppressed within the method. Suppressing Exceptions in this manner would cause verify to exit normally, leading the app to trust all hostnames.
package com.deezer.sdk.network.b;
...
public class Blues {
...
private static final HostnameVerifier bagpipes = new HostnameVerifier() {
public final boolean verify(String hostname, SSLSession session) {
return true;
}
};
...
private static HttpURLConnection accordion(String var0, String var1, boolean var2) throws IOException {
Object var3;
if (var2) {
((HttpsURLConnection)(var3 = (HttpsURLConnection)(new URL(var0)).openConnection())).setHostnameVerifier(bagpipes);
} else {
var3 = (HttpURLConnection)(new URL(var0)).openConnection();
}
((HttpURLConnection)var3).setRequestProperty("User-Agent", var1);
return (HttpURLConnection)var3;
}
...
}
- Ngôn ngữ chính
- Java
- Star
- 42
- Fork
- 25
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của deezer/android-sample
-
SDK url leads to empty pageĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 25/100
deezer/android-sample#23 · 1 reaction ·
-
Unsafe implementation of the HostnameVerifier, Play Store rejects apps with this library (v0.11.2).Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
deezer/android-sample#22 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
deezer/android-sample#21 · 1 bình luận ·
-
SSL ErrorĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 20/100
deezer/android-sample#19 ·
-
App lags when track is playingĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
deezer/android-sample#18 · 3 bình luận ·
Tất cả issue của deezer/android-sample
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Content
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
RunestoneInteractive/rs#1559 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
inu-appcenter/memorIN-backend#298 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
opendataloader-project/opendataloader-pdf#757 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
redhat-developer/intellij-quarkus#1626 ·