Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing response code validation after performing network operation #27

Open
amazuerar opened this issue Aug 15, 2021 · 0 comments
Open

Comments

@amazuerar
Copy link

Dear Developer!

My name is Alejandro Mazuera-Rozo, I am a PhD Student at Universidad de los Andes, and at Università della Svizzera italiana. I am part of a research on the usage of network libraries within Android apps. As result of this we identified some code locations that might have network related problems.

In this case, we present the code locations that are related to a missing validation of the response code when performing network operations. When you make an HTTP request, your application should validate the response status code before manipulating it, otherwise it could cause misbehaviour within the app.

In order to address this issue we recommend you to visit:

  1. https://developer.android.com/training/volley/requestqueue

Potential Code Location missing Response Code validation

  1. When a new request is being added to the Volley queue:

if (!DashHelper.getInstance(this).addRequest(stringRequest)) {

  1. There is no previous validation of statusCode when assigning response inside the onResponse() method
    NSStringRequest stringRequest = new NSStringRequest(getApplicationContext(),
    Request.Method.GET, targetURL,
    new Response.Listener<String>() {
    CensusHistory censusResponse = null;
    @Override
    public void onResponse(String response) {
    Persister serializer = new Persister();
    try {
    censusResponse = serializer.read(CensusHistory.class, response);
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant