Conversation
|
Staged preview of the updated docs.flutter.dev site (updated for commit 64fcfd5): https://flutter-docs-prod--docs-pr13645-bc-intents13-pylga3hu.web.app |
|
Staged preview of the updated flutter.dev site (updated for commit 162b3c8): https://flutter-dev-230821--www-pr13645-bc-intents13-itlm7li3.web.app |
Intent arguments
…ine arguments via `Intent`s (flutter#190249) > [!WARNING] > This is a breaking change. Though the motivation for this change is the security of our users and migration to accommodate this change is critical, I looked at some top plugins that _might_ have been impacted to ensure they won't be broken: All 1P plugins, [`firebase_messaging`](https://pub.dev/packages/firebase_messaging) v16.5.0, [`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications) v22.3.0, [`awesome_notifications`](https://pub.dev/packages/awesome_notifications) v0.12.1, [`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus) v5.1.1, [`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent) v1.9.0, [`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter), [`workmanager`](https://pub.dev/packages/workmanager) v0.10.7 [`flutter_background_service`](https://pub.dev/packages/flutter_background_service) v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1, [`uni_links`](https://pub.dev/packages/uni_links) v0.5.1 Changes the embedding to only allow setting app launch entry-point and cached engine related arguments via `Intent`s in debug/profile mode or when the `Intent` sender is verifiably the app itself. This hardens the embedding against arbitrary argument injection by a malicious actor, preventing unauthorized access to sensitive app routes and engine controls. Below Android 13, it is impossible to verify the `Intent` sender is verifiably the app itself in all cases, so apps/plugins that do not migrate and run on those versions will be impacted. In debug/profile modes, if an unverified `Intent` attempts to set these arguments, the embedding now logs a detailed warning containing the target component, the intent details, and the specific `Intent` extra keys that triggered the verification failure. It also links to the breaking changes migration guide for help on migrating: flutter/website#13645 For deep links, the `Intent` is compared against the app's `Intent` filters to ensure the app should allow that link. This is standard for the OS; see [Android's Intents and Intent Filters documentation](https://developer.android.com/guide/components/intents-filters) for more information on that. Fixes flutter#190452 and fixes flutter#190450. ## Pre-launch Checklist - [x] I read the [Contributor Guide] and followed the process outlined there for submitting PRs. - [x] I read the [AI contribution guidelines] and understand my responsibilities, or I am not using AI tools. - [x] I read the [Tree Hygiene] wiki page, which explains my responsibilities. - [x] I read and followed the [Flutter Style Guide], including [Features we expect every widget to implement]. - [x] I signed the [CLA]. - [x] I listed at least one issue that this PR fixes in the description above. - [x] I updated/added relevant documentation (doc comments with `///`). - [x] I added new tests to check the change I am making, or this PR is [test-exempt]. - [x] I followed the [breaking change policy] and added [Data Driven Fixes] where supported. - [ ] All existing and new tests are passing. If you need help, consider asking for advice on the #hackers-new channel on [Discord]. If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance. **Note**: The Flutter team is currently trialing the use of [Gemini Code Assist for GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code). Comments from the `gemini-code-assist` bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed. <!-- Links --> [Contributor Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview [AI contribution guidelines]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines [Tree Hygiene]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md [test-exempt]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests [Flutter Style Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md [Features we expect every widget to implement]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement [CLA]: https://cla.developers.google.com/ [flutter/tests]: https://github.com/flutter/tests [breaking change policy]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes [Discord]: https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md [Data Driven Fixes]: https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md --------- Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
…ine arguments via `Intent`s (flutter#190249) > [!WARNING] > This is a breaking change. Though the motivation for this change is the security of our users and migration to accommodate this change is critical, I looked at some top plugins that _might_ have been impacted to ensure they won't be broken: All 1P plugins, [`firebase_messaging`](https://pub.dev/packages/firebase_messaging) v16.5.0, [`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications) v22.3.0, [`awesome_notifications`](https://pub.dev/packages/awesome_notifications) v0.12.1, [`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus) v5.1.1, [`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent) v1.9.0, [`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter), [`workmanager`](https://pub.dev/packages/workmanager) v0.10.7 [`flutter_background_service`](https://pub.dev/packages/flutter_background_service) v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1, [`uni_links`](https://pub.dev/packages/uni_links) v0.5.1 Changes the embedding to only allow setting app launch entry-point and cached engine related arguments via `Intent`s in debug/profile mode or when the `Intent` sender is verifiably the app itself. This hardens the embedding against arbitrary argument injection by a malicious actor, preventing unauthorized access to sensitive app routes and engine controls. Below Android 13, it is impossible to verify the `Intent` sender is verifiably the app itself in all cases, so apps/plugins that do not migrate and run on those versions will be impacted. In debug/profile modes, if an unverified `Intent` attempts to set these arguments, the embedding now logs a detailed warning containing the target component, the intent details, and the specific `Intent` extra keys that triggered the verification failure. It also links to the breaking changes migration guide for help on migrating: flutter/website#13645 For deep links, the `Intent` is compared against the app's `Intent` filters to ensure the app should allow that link. This is standard for the OS; see [Android's Intents and Intent Filters documentation](https://developer.android.com/guide/components/intents-filters) for more information on that. Fixes flutter#190452 and fixes flutter#190450. ## Pre-launch Checklist - [x] I read the [Contributor Guide] and followed the process outlined there for submitting PRs. - [x] I read the [AI contribution guidelines] and understand my responsibilities, or I am not using AI tools. - [x] I read the [Tree Hygiene] wiki page, which explains my responsibilities. - [x] I read and followed the [Flutter Style Guide], including [Features we expect every widget to implement]. - [x] I signed the [CLA]. - [x] I listed at least one issue that this PR fixes in the description above. - [x] I updated/added relevant documentation (doc comments with `///`). - [x] I added new tests to check the change I am making, or this PR is [test-exempt]. - [x] I followed the [breaking change policy] and added [Data Driven Fixes] where supported. - [ ] All existing and new tests are passing. If you need help, consider asking for advice on the #hackers-new channel on [Discord]. If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance. **Note**: The Flutter team is currently trialing the use of [Gemini Code Assist for GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code). Comments from the `gemini-code-assist` bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed. <!-- Links --> [Contributor Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview [AI contribution guidelines]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines [Tree Hygiene]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md [test-exempt]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests [Flutter Style Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md [Features we expect every widget to implement]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement [CLA]: https://cla.developers.google.com/ [flutter/tests]: https://github.com/flutter/tests [breaking change policy]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes [Discord]: https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md [Data Driven Fixes]: https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md --------- Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
There was a problem hiding this comment.
Code Review
This pull request adds a new breaking change document detailing stricter Android Intent verification for app entrypoints in the Flutter Android embedder, which is designed to prevent security vulnerabilities. It also updates the breaking changes index file. The review feedback correctly points out that the new entry in the breaking changes index is not sorted alphabetically, violating the document's explicit sorting convention.
| * [Added enabled property and made onChanged optional for DropdownButton][] | ||
| * [Migrate to standalone `material_ui` and `cupertino_ui` packages][] | ||
| * [Stricter Android `Intent` Verification for App Entrypoints][] | ||
| * [Restrict command-line flags for prebuilt Android release binaries][] | ||
| * [Removal of `useInheritedMediaQuery`][] | ||
|
|
||
| [Added enabled property and made onChanged optional for DropdownButton]: /release/breaking-changes/dropdownbutton-enabled-property | ||
| [Stricter Android `Intent` Verification for App Entrypoints]: /release/breaking-changes/stricter-android-entrypoint-intent-verification | ||
| [Migrate to standalone `material_ui` and `cupertino_ui` packages]: /release/breaking-changes/material-ui-and-cupertino-ui | ||
| [Restrict command-line flags for prebuilt Android release binaries]: /release/breaking-changes/restrict-command-line-flags-prebuilt-android-release-binaries | ||
| [Removal of `useInheritedMediaQuery`]: /release/breaking-changes/remove-useInheritedMediaQuery |
There was a problem hiding this comment.
The breaking changes list and reference links should be sorted in alphabetical order, as noted in the section header ("They're sorted by release and listed in alphabetical order:"). Currently, "Stricter Android Intent Verification..." is placed out of order.
Please reorder the list items and reference links as follows:
* [Added enabled property and made onChanged optional for DropdownButton][]
* [Migrate to standalone `material_ui` and `cupertino_ui` packages][]
* [Removal of `useInheritedMediaQuery`][]
* [Restrict command-line flags for prebuilt Android release binaries][]
* [Stricter Android `Intent` Verification for App Entrypoints][]
[Added enabled property and made onChanged optional for DropdownButton]: /release/breaking-changes/dropdownbutton-enabled-property
[Migrate to standalone `material_ui` and `cupertino_ui` packages]: /release/breaking-changes/material-ui-and-cupertino-ui
[Removal of `useInheritedMediaQuery`]: /release/breaking-changes/remove-useInheritedMediaQuery
[Restrict command-line flags for prebuilt Android release binaries]: /release/breaking-changes/restrict-command-line-flags-prebuilt-android-release-binaries
[Stricter Android `Intent` Verification for App Entrypoints]: /release/breaking-changes/stricter-android-entrypoint-intent-verificationReferences
- The repository style guide emphasizes respecting the repository structure and following established conventions. The breaking changes index explicitly states that entries are sorted in alphabetical order. (link)
There was a problem hiding this comment.
I don't think this is necessarily true but I can fix if so!
…ine arguments via `Intent`s (flutter#190249) > [!WARNING] > This is a breaking change. Though the motivation for this change is the security of our users and migration to accommodate this change is critical, I looked at some top plugins that _might_ have been impacted to ensure they won't be broken: All 1P plugins, [`firebase_messaging`](https://pub.dev/packages/firebase_messaging) v16.5.0, [`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications) v22.3.0, [`awesome_notifications`](https://pub.dev/packages/awesome_notifications) v0.12.1, [`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus) v5.1.1, [`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent) v1.9.0, [`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter), [`workmanager`](https://pub.dev/packages/workmanager) v0.10.7 [`flutter_background_service`](https://pub.dev/packages/flutter_background_service) v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1, [`uni_links`](https://pub.dev/packages/uni_links) v0.5.1 Changes the embedding to only allow setting app launch entry-point and cached engine related arguments via `Intent`s in debug/profile mode or when the `Intent` sender is verifiably the app itself. This hardens the embedding against arbitrary argument injection by a malicious actor, preventing unauthorized access to sensitive app routes and engine controls. Below Android 13, it is impossible to verify the `Intent` sender is verifiably the app itself in all cases, so apps/plugins that do not migrate and run on those versions will be impacted. In debug/profile modes, if an unverified `Intent` attempts to set these arguments, the embedding now logs a detailed warning containing the target component, the intent details, and the specific `Intent` extra keys that triggered the verification failure. It also links to the breaking changes migration guide for help on migrating: flutter/website#13645 For deep links, the `Intent` is compared against the app's `Intent` filters to ensure the app should allow that link. This is standard for the OS; see [Android's Intents and Intent Filters documentation](https://developer.android.com/guide/components/intents-filters) for more information on that. Fixes flutter#190452 and fixes flutter#190450. ## Pre-launch Checklist - [x] I read the [Contributor Guide] and followed the process outlined there for submitting PRs. - [x] I read the [AI contribution guidelines] and understand my responsibilities, or I am not using AI tools. - [x] I read the [Tree Hygiene] wiki page, which explains my responsibilities. - [x] I read and followed the [Flutter Style Guide], including [Features we expect every widget to implement]. - [x] I signed the [CLA]. - [x] I listed at least one issue that this PR fixes in the description above. - [x] I updated/added relevant documentation (doc comments with `///`). - [x] I added new tests to check the change I am making, or this PR is [test-exempt]. - [x] I followed the [breaking change policy] and added [Data Driven Fixes] where supported. - [ ] All existing and new tests are passing. If you need help, consider asking for advice on the #hackers-new channel on [Discord]. If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance. **Note**: The Flutter team is currently trialing the use of [Gemini Code Assist for GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code). Comments from the `gemini-code-assist` bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed. <!-- Links --> [Contributor Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview [AI contribution guidelines]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines [Tree Hygiene]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md [test-exempt]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests [Flutter Style Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md [Features we expect every widget to implement]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement [CLA]: https://cla.developers.google.com/ [flutter/tests]: https://github.com/flutter/tests [breaking change policy]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes [Discord]: https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md [Data Driven Fixes]: https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md --------- Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
|
@Sfshaza The change related to this page will be part of the next stable release, so hoping to get it landed in ~a week. Sorry for the short timeline, but can I get a review on this? Thank you in advance! |
Description of what this PR is changing or adding, and why:
Adds breaking change/migration guide for security improvements made to entrypoint and cached engine
Intentarguments for the Flutter Android embedding.Issues fixed by this PR (if any):
flutter/flutter#190452 and flutter/flutter#190450
PRs or commits this PR depends on (if any):
flutter/flutter#190249 (merged)
Presubmit checklist
of 80 characters or fewer.