Files
codeql/java/ql/src/Security/CWE/CWE-200/AndroidSensitiveNotifications.java
Joe Farebrother 1190352b67 Add qhelp
2024-01-23 09:51:40 +00:00

8 lines
301 B
Java

// BAD: `password` is exposed in a notification.
void confirmPassword(String password) {
NotificationManager manager = NotificationManager.from(this);
manager.send(
new Notification.Builder(this, CHANNEL_ID)
.setContentText("Your password is: " + password)
.build());
}