Skip to content

[Android] Add breaking change page for hardened entrypoint and cached engine Intent arguments - #13645

Open
camsim99 wants to merge 12 commits into
mainfrom
bc_intents13
Open

camsim99 wants to merge 12 commits into
mainfrom
bc_intents13

Conversation

@camsim99

@camsim99 camsim99 commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Description of what this PR is changing or adding, and why:
Adds breaking change/migration guide for security improvements made to entrypoint and cached engine Intent arguments for the Flutter Android embedding.

Issues fixed by this PR (if any):
flutter/flutter#190452 and flutter/flutter#190450

PRs or commits this PR depends on (if any):
flutter/flutter#190249 (merged)

Presubmit checklist

  • If you are unwilling, or unable, to sign the CLA, even for a tiny, one-word PR, please file an issue instead of a PR.
  • If this PR is not meant to land until a future stable release, mark it as draft with an explanation.
  • This PR follows the Google Developer Documentation Style Guidelines—for example, it doesn't use i.e. or e.g., and it avoids I and we (first-person pronouns).
  • This PR uses semantic line breaks
    of 80 characters or fewer.

@flutter-website-bot

flutter-website-bot commented Jul 29, 2026 •

Copy link
Copy Markdown
Collaborator

Staged preview of the updated docs.flutter.dev site (updated for commit 64fcfd5):

https://flutter-docs-prod--docs-pr13645-bc-intents13-pylga3hu.web.app

@flutter-website-bot

flutter-website-bot commented Jul 29, 2026 •

Copy link
Copy Markdown
Collaborator

Staged preview of the updated flutter.dev site (updated for commit 162b3c8):

https://flutter-dev-230821--www-pr13645-bc-intents13-itlm7li3.web.app

@camsim99 camsim99 changed the title [wip] Breaking change docs for entrypoint args security [Android] Add breaking change page for hardened entrypoint and cached engine Intent arguments Aug 12, 2026
@camsim99 camsim99 closed this Aug 25, 2026
pull Bot pushed a commit to dhc-tech/flutter that referenced this pull request Sep 26, 2026
…ine arguments via `Intent`s (flutter#190249)

> [!WARNING]
> This is a breaking change. Though the motivation for this change is
the security of our users and migration to accommodate this change is
critical, I looked at some top plugins that _might_ have been impacted
to ensure they won't be broken: All 1P plugins,
[`firebase_messaging`](https://pub.dev/packages/firebase_messaging)
v16.5.0,
[`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications)
v22.3.0,
[`awesome_notifications`](https://pub.dev/packages/awesome_notifications)
v0.12.1,
[`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus)
v5.1.1,
[`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent)
v1.9.0,
[`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter),
[`workmanager`](https://pub.dev/packages/workmanager) v0.10.7
[`flutter_background_service`](https://pub.dev/packages/flutter_background_service)
v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1,
[`uni_links`](https://pub.dev/packages/uni_links) v0.5.1


Changes the embedding to only allow setting app launch entry-point and
cached engine related arguments via `Intent`s in debug/profile mode or
when the `Intent` sender is verifiably the app itself. This hardens the
embedding against arbitrary argument injection by a malicious actor,
preventing unauthorized access to sensitive app routes and engine
controls. Below Android 13, it is impossible to verify the `Intent`
sender is verifiably the app itself in all cases, so apps/plugins that
do not migrate and run on those versions will be impacted.

In debug/profile modes, if an unverified `Intent` attempts to set these
arguments, the embedding now logs a detailed warning containing the
target component, the intent details, and the specific `Intent` extra
keys that triggered the verification failure. It also links to the
breaking changes migration guide for help on migrating:
flutter/website#13645

For deep links, the `Intent` is compared against the app's `Intent`
filters to ensure the app should allow that link. This is standard for
the OS; see [Android's Intents and Intent Filters
documentation](https://developer.android.com/guide/components/intents-filters)
for more information on that.

Fixes flutter#190452 and fixes
flutter#190450.

## Pre-launch Checklist

- [x] I read the [Contributor Guide] and followed the process outlined
there for submitting PRs.
- [x] I read the [AI contribution guidelines] and understand my
responsibilities, or I am not using AI tools.
- [x] I read the [Tree Hygiene] wiki page, which explains my
responsibilities.
- [x] I read and followed the [Flutter Style Guide], including [Features
we expect every widget to implement].
- [x] I signed the [CLA].
- [x] I listed at least one issue that this PR fixes in the description
above.
- [x] I updated/added relevant documentation (doc comments with `///`).
- [x] I added new tests to check the change I am making, or this PR is
[test-exempt].
- [x] I followed the [breaking change policy] and added [Data Driven
Fixes] where supported.
- [ ] All existing and new tests are passing.

If you need help, consider asking for advice on the #hackers-new channel
on [Discord].

If this change needs to override an active code freeze, provide a
comment explaining why. The code freeze workflow can be overridden by
code reviewers. See pinned issues for any active code freezes with
guidance.

**Note**: The Flutter team is currently trialing the use of [Gemini Code
Assist for
GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code).
Comments from the `gemini-code-assist` bot should not be taken as
authoritative feedback from the Flutter team. If you find its comments
useful you can update your code accordingly, but if you are unsure or
disagree with the feedback, please feel free to wait for a Flutter team
member's review for guidance on which automated comments should be
addressed.

<!-- Links -->
[Contributor Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview
[AI contribution guidelines]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines
[Tree Hygiene]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md
[test-exempt]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests
[Flutter Style Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md
[Features we expect every widget to implement]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement
[CLA]: https://cla.developers.google.com/
[flutter/tests]: https://github.com/flutter/tests
[breaking change policy]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes
[Discord]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md
[Data Driven Fixes]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md

---------

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
DanTup pushed a commit to DanTup/flutter that referenced this pull request Sep 28, 2026
…ine arguments via `Intent`s (flutter#190249)

> [!WARNING]
> This is a breaking change. Though the motivation for this change is
the security of our users and migration to accommodate this change is
critical, I looked at some top plugins that _might_ have been impacted
to ensure they won't be broken: All 1P plugins,
[`firebase_messaging`](https://pub.dev/packages/firebase_messaging)
v16.5.0,
[`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications)
v22.3.0,
[`awesome_notifications`](https://pub.dev/packages/awesome_notifications)
v0.12.1,
[`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus)
v5.1.1,
[`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent)
v1.9.0,
[`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter),
[`workmanager`](https://pub.dev/packages/workmanager) v0.10.7
[`flutter_background_service`](https://pub.dev/packages/flutter_background_service)
v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1,
[`uni_links`](https://pub.dev/packages/uni_links) v0.5.1


Changes the embedding to only allow setting app launch entry-point and
cached engine related arguments via `Intent`s in debug/profile mode or
when the `Intent` sender is verifiably the app itself. This hardens the
embedding against arbitrary argument injection by a malicious actor,
preventing unauthorized access to sensitive app routes and engine
controls. Below Android 13, it is impossible to verify the `Intent`
sender is verifiably the app itself in all cases, so apps/plugins that
do not migrate and run on those versions will be impacted.

In debug/profile modes, if an unverified `Intent` attempts to set these
arguments, the embedding now logs a detailed warning containing the
target component, the intent details, and the specific `Intent` extra
keys that triggered the verification failure. It also links to the
breaking changes migration guide for help on migrating:
flutter/website#13645

For deep links, the `Intent` is compared against the app's `Intent`
filters to ensure the app should allow that link. This is standard for
the OS; see [Android's Intents and Intent Filters
documentation](https://developer.android.com/guide/components/intents-filters)
for more information on that.

Fixes flutter#190452 and fixes
flutter#190450.

## Pre-launch Checklist

- [x] I read the [Contributor Guide] and followed the process outlined
there for submitting PRs.
- [x] I read the [AI contribution guidelines] and understand my
responsibilities, or I am not using AI tools.
- [x] I read the [Tree Hygiene] wiki page, which explains my
responsibilities.
- [x] I read and followed the [Flutter Style Guide], including [Features
we expect every widget to implement].
- [x] I signed the [CLA].
- [x] I listed at least one issue that this PR fixes in the description
above.
- [x] I updated/added relevant documentation (doc comments with `///`).
- [x] I added new tests to check the change I am making, or this PR is
[test-exempt].
- [x] I followed the [breaking change policy] and added [Data Driven
Fixes] where supported.
- [ ] All existing and new tests are passing.

If you need help, consider asking for advice on the #hackers-new channel
on [Discord].

If this change needs to override an active code freeze, provide a
comment explaining why. The code freeze workflow can be overridden by
code reviewers. See pinned issues for any active code freezes with
guidance.

**Note**: The Flutter team is currently trialing the use of [Gemini Code
Assist for
GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code).
Comments from the `gemini-code-assist` bot should not be taken as
authoritative feedback from the Flutter team. If you find its comments
useful you can update your code accordingly, but if you are unsure or
disagree with the feedback, please feel free to wait for a Flutter team
member's review for guidance on which automated comments should be
addressed.

<!-- Links -->
[Contributor Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview
[AI contribution guidelines]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines
[Tree Hygiene]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md
[test-exempt]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests
[Flutter Style Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md
[Features we expect every widget to implement]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement
[CLA]: https://cla.developers.google.com/
[flutter/tests]: https://github.com/flutter/tests
[breaking change policy]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes
[Discord]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md
[Data Driven Fixes]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md

---------

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
@camsim99 camsim99 reopened this Sep 28, 2026
@camsim99
camsim99 marked this pull request as ready for review September 28, 2026 17:23
@camsim99
camsim99 requested review from a team and sfshaza2 as code owners September 28, 2026 17:23

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds a new breaking change document detailing stricter Android Intent verification for app entrypoints in the Flutter Android embedder, which is designed to prevent security vulnerabilities. It also updates the breaking changes index file. The review feedback correctly points out that the new entry in the breaking changes index is not sorted alphabetically, violating the document's explicit sorting convention.

Comment on lines 39 to 49
* [Added enabled property and made onChanged optional for DropdownButton][]
* [Migrate to standalone `material_ui` and `cupertino_ui` packages][]
* [Stricter Android `Intent` Verification for App Entrypoints][]
* [Restrict command-line flags for prebuilt Android release binaries][]
* [Removal of `useInheritedMediaQuery`][]

[Added enabled property and made onChanged optional for DropdownButton]: /release/breaking-changes/dropdownbutton-enabled-property
[Stricter Android `Intent` Verification for App Entrypoints]: /release/breaking-changes/stricter-android-entrypoint-intent-verification
[Migrate to standalone `material_ui` and `cupertino_ui` packages]: /release/breaking-changes/material-ui-and-cupertino-ui
[Restrict command-line flags for prebuilt Android release binaries]: /release/breaking-changes/restrict-command-line-flags-prebuilt-android-release-binaries
[Removal of `useInheritedMediaQuery`]: /release/breaking-changes/remove-useInheritedMediaQuery

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The breaking changes list and reference links should be sorted in alphabetical order, as noted in the section header ("They're sorted by release and listed in alphabetical order:"). Currently, "Stricter Android Intent Verification..." is placed out of order.

Please reorder the list items and reference links as follows:

* [Added enabled property and made onChanged optional for DropdownButton][]
* [Migrate to standalone `material_ui` and `cupertino_ui` packages][]
* [Removal of `useInheritedMediaQuery`][]
* [Restrict command-line flags for prebuilt Android release binaries][]
* [Stricter Android `Intent` Verification for App Entrypoints][]

[Added enabled property and made onChanged optional for DropdownButton]: /release/breaking-changes/dropdownbutton-enabled-property
[Migrate to standalone `material_ui` and `cupertino_ui` packages]: /release/breaking-changes/material-ui-and-cupertino-ui
[Removal of `useInheritedMediaQuery`]: /release/breaking-changes/remove-useInheritedMediaQuery
[Restrict command-line flags for prebuilt Android release binaries]: /release/breaking-changes/restrict-command-line-flags-prebuilt-android-release-binaries
[Stricter Android `Intent` Verification for App Entrypoints]: /release/breaking-changes/stricter-android-entrypoint-intent-verification
References
  1. The repository style guide emphasizes respecting the repository structure and following established conventions. The breaking changes index explicitly states that entries are sorted in alphabetical order. (link)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is necessarily true but I can fix if so!

DanTup pushed a commit to DanTup/flutter that referenced this pull request Sep 28, 2026
…ine arguments via `Intent`s (flutter#190249)

> [!WARNING]
> This is a breaking change. Though the motivation for this change is
the security of our users and migration to accommodate this change is
critical, I looked at some top plugins that _might_ have been impacted
to ensure they won't be broken: All 1P plugins,
[`firebase_messaging`](https://pub.dev/packages/firebase_messaging)
v16.5.0,
[`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications)
v22.3.0,
[`awesome_notifications`](https://pub.dev/packages/awesome_notifications)
v0.12.1,
[`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus)
v5.1.1,
[`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent)
v1.9.0,
[`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter),
[`workmanager`](https://pub.dev/packages/workmanager) v0.10.7
[`flutter_background_service`](https://pub.dev/packages/flutter_background_service)
v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1,
[`uni_links`](https://pub.dev/packages/uni_links) v0.5.1


Changes the embedding to only allow setting app launch entry-point and
cached engine related arguments via `Intent`s in debug/profile mode or
when the `Intent` sender is verifiably the app itself. This hardens the
embedding against arbitrary argument injection by a malicious actor,
preventing unauthorized access to sensitive app routes and engine
controls. Below Android 13, it is impossible to verify the `Intent`
sender is verifiably the app itself in all cases, so apps/plugins that
do not migrate and run on those versions will be impacted.

In debug/profile modes, if an unverified `Intent` attempts to set these
arguments, the embedding now logs a detailed warning containing the
target component, the intent details, and the specific `Intent` extra
keys that triggered the verification failure. It also links to the
breaking changes migration guide for help on migrating:
flutter/website#13645

For deep links, the `Intent` is compared against the app's `Intent`
filters to ensure the app should allow that link. This is standard for
the OS; see [Android's Intents and Intent Filters
documentation](https://developer.android.com/guide/components/intents-filters)
for more information on that.

Fixes flutter#190452 and fixes
flutter#190450.

## Pre-launch Checklist

- [x] I read the [Contributor Guide] and followed the process outlined
there for submitting PRs.
- [x] I read the [AI contribution guidelines] and understand my
responsibilities, or I am not using AI tools.
- [x] I read the [Tree Hygiene] wiki page, which explains my
responsibilities.
- [x] I read and followed the [Flutter Style Guide], including [Features
we expect every widget to implement].
- [x] I signed the [CLA].
- [x] I listed at least one issue that this PR fixes in the description
above.
- [x] I updated/added relevant documentation (doc comments with `///`).
- [x] I added new tests to check the change I am making, or this PR is
[test-exempt].
- [x] I followed the [breaking change policy] and added [Data Driven
Fixes] where supported.
- [ ] All existing and new tests are passing.

If you need help, consider asking for advice on the #hackers-new channel
on [Discord].

If this change needs to override an active code freeze, provide a
comment explaining why. The code freeze workflow can be overridden by
code reviewers. See pinned issues for any active code freezes with
guidance.

**Note**: The Flutter team is currently trialing the use of [Gemini Code
Assist for
GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code).
Comments from the `gemini-code-assist` bot should not be taken as
authoritative feedback from the Flutter team. If you find its comments
useful you can update your code accordingly, but if you are unsure or
disagree with the feedback, please feel free to wait for a Flutter team
member's review for guidance on which automated comments should be
addressed.

<!-- Links -->
[Contributor Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview
[AI contribution guidelines]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines
[Tree Hygiene]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md
[test-exempt]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests
[Flutter Style Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md
[Features we expect every widget to implement]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement
[CLA]: https://cla.developers.google.com/
[flutter/tests]: https://github.com/flutter/tests
[breaking change policy]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes
[Discord]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md
[Data Driven Fixes]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md

---------

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
@camsim99

camsim99 commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

@Sfshaza The change related to this page will be part of the next stable release, so hoping to get it landed in ~a week. Sorry for the short timeline, but can I get a review on this? Thank you in advance!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants