breautek opened a new pull request, #901:
URL: https://github.com/apache/cordova-plugin-camera/pull/901

   <!--
   Please make sure the checklist boxes are all checked before submitting the 
PR. The checklist is intended as a quick reference, for complete details please 
see our Contributor Guidelines:
   
   http://cordova.apache.org/contribute/contribute_guidelines.html
   
   Thanks!
   -->
   
   ### Platforms affected
   
   Android
   
   ### Motivation and Context
   <!-- Why is this change required? What problem does it solve? -->
   <!-- If it fixes an open issue, please link to the issue here. -->
   
   The file provider is what grants app delegates (such as the camera app) 
access for reading and/or writing. It is what allows the camera intent to write 
it's image to the app's internal cache directory. The previous configuration 
allowed access to the entire cache directory which could be perceived as a 
security risk.
   
   Using a sub-directory will at least isolate access to that specific 
directory and won't expose other cache files that the app may have stored. The 
chosen directory is something that should only be used by this plugin, and the 
directory will be mostly empty assuming that users call the `cleanup` API. 
Worst case scenario it may have images that was previously captured by the user.
   
   ### Description
   <!-- Describe your changes in detail -->
   
   Update to provider to path to use a subdirectory, and updated the create 
code to use subdirectory.
   
   ### Testing
   <!-- Please describe in detail how you tested your changes. -->
   
   Tested on using android simulator using `getPicture` API.
   Paramedic tests also passes.
   
   ### Checklist
   
   - [x] I've run the tests to see all new and existing tests pass
   - [x] I added automated test coverage as appropriate for this change
   - [x] Commit is prefixed with `(platform)` if this change only applies to 
one platform (e.g. `(android)`)
   - [x] If this Pull Request resolves an issue, I linked to the issue in the 
text above (and used the correct [keyword to close issues using 
keywords](https://help.github.com/articles/closing-issues-using-keywords/))
   - [x] I've updated the documentation if necessary
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscr...@cordova.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@cordova.apache.org
For additional commands, e-mail: issues-h...@cordova.apache.org

Reply via email to