ChatStorage.java: getHistory(1) returns a single message, remove unneeded security (#2091)

This commit is contained in:
Gautier Pelloux-Prayer 2015-04-28 13:54:22 +02:00
parent d62252ed22
commit e86833a9a1

View file

@ -47,7 +47,7 @@ public class ChatStorage {
private static final int OUTGOING = 0; private static final int OUTGOING = 0;
private static final int READ = 1; private static final int READ = 1;
private static final int NOT_READ = 0; private static final int NOT_READ = 0;
private static ChatStorage instance; private static ChatStorage instance;
private Context context; private Context context;
private SQLiteDatabase db; private SQLiteDatabase db;
@ -66,7 +66,7 @@ public class ChatStorage {
instance.close(); instance.close();
instance = new ChatStorage(LinphoneService.instance().getApplicationContext()); instance = new ChatStorage(LinphoneService.instance().getApplicationContext());
} }
private boolean isVersionUsingNewChatStorage() { private boolean isVersionUsingNewChatStorage() {
try { try {
return context.getPackageManager().getPackageInfo(context.getPackageName(), 0).versionCode >= 2200; return context.getPackageManager().getPackageInfo(context.getPackageName(), 0).versionCode >= 2200;
@ -75,7 +75,7 @@ public class ChatStorage {
} }
return true; return true;
} }
private ChatStorage(Context c) { private ChatStorage(Context c) {
context = c; context = c;
boolean useLinphoneStorage = c.getResources().getBoolean(R.bool.use_linphone_chat_storage); boolean useLinphoneStorage = c.getResources().getBoolean(R.bool.use_linphone_chat_storage);
@ -84,24 +84,24 @@ public class ChatStorage {
updateNeeded = updateNeeded && !isVersionUsingNewChatStorage(); updateNeeded = updateNeeded && !isVersionUsingNewChatStorage();
useNativeAPI = useLinphoneStorage && !updateNeeded; useNativeAPI = useLinphoneStorage && !updateNeeded;
Log.d("Using native API: " + useNativeAPI); Log.d("Using native API: " + useNativeAPI);
if (!useNativeAPI) { if (!useNativeAPI) {
ChatHelper chatHelper = new ChatHelper(context); ChatHelper chatHelper = new ChatHelper(context);
db = chatHelper.getWritableDatabase(); db = chatHelper.getWritableDatabase();
} }
} }
public void close() { public void close() {
if (!useNativeAPI) { if (!useNativeAPI) {
db.close(); db.close();
} }
} }
public void updateMessageStatus(String to, String message, int status) { public void updateMessageStatus(String to, String message, int status) {
if (useNativeAPI) { if (useNativeAPI) {
return; return;
} }
String[] whereArgs = { String.valueOf(OUTGOING), to, message }; String[] whereArgs = { String.valueOf(OUTGOING), to, message };
Cursor c = db.query(TABLE_NAME, null, "direction LIKE ? AND remoteContact LIKE ? AND message LIKE ?", whereArgs, null, null, "id DESC"); Cursor c = db.query(TABLE_NAME, null, "direction LIKE ? AND remoteContact LIKE ? AND message LIKE ?", whereArgs, null, null, "id DESC");
@ -114,29 +114,29 @@ public class ChatStorage {
} }
} }
c.close(); c.close();
if (id != null && id.length() > 0) { if (id != null && id.length() > 0) {
int intID = Integer.parseInt(id); int intID = Integer.parseInt(id);
updateMessageStatus(to, intID, status); updateMessageStatus(to, intID, status);
} }
} }
public void updateMessageStatus(String to, int id, int status) { public void updateMessageStatus(String to, int id, int status) {
if (useNativeAPI) { if (useNativeAPI) {
return; return;
} }
ContentValues values = new ContentValues(); ContentValues values = new ContentValues();
values.put("status", status); values.put("status", status);
db.update(TABLE_NAME, values, "id LIKE " + id, null); db.update(TABLE_NAME, values, "id LIKE " + id, null);
} }
public int saveTextMessage(String from, String to, String message, long time) { public int saveTextMessage(String from, String to, String message, long time) {
if (useNativeAPI) { if (useNativeAPI) {
return -1; return -1;
} }
ContentValues values = new ContentValues(); ContentValues values = new ContentValues();
if (from.equals("")) { if (from.equals("")) {
values.put("localContact", from); values.put("localContact", from);
@ -155,12 +155,12 @@ public class ChatStorage {
values.put("time", time); values.put("time", time);
return (int) db.insert(TABLE_NAME, null, values); return (int) db.insert(TABLE_NAME, null, values);
} }
public int saveImageMessage(String from, String to, Bitmap image, String url, long time) { public int saveImageMessage(String from, String to, Bitmap image, String url, long time) {
if (useNativeAPI) { if (useNativeAPI) {
return -1; return -1;
} }
ContentValues values = new ContentValues(); ContentValues values = new ContentValues();
if (from.equals("")) { if (from.equals("")) {
values.put("localContact", from); values.put("localContact", from);
@ -176,73 +176,73 @@ public class ChatStorage {
values.put("status", LinphoneChatMessage.State.Idle.toInt()); values.put("status", LinphoneChatMessage.State.Idle.toInt());
} }
values.put("url", url); values.put("url", url);
if (image != null) { if (image != null) {
ByteArrayOutputStream baos = new ByteArrayOutputStream(); ByteArrayOutputStream baos = new ByteArrayOutputStream();
image.compress(CompressFormat.JPEG, 100, baos); image.compress(CompressFormat.JPEG, 100, baos);
values.put("image", baos.toByteArray()); values.put("image", baos.toByteArray());
} }
values.put("time", time); values.put("time", time);
return (int) db.insert(TABLE_NAME, null, values); return (int) db.insert(TABLE_NAME, null, values);
} }
public void saveImage(int id, Bitmap image) { public void saveImage(int id, Bitmap image) {
if (useNativeAPI) { if (useNativeAPI) {
//Handled before this point //Handled before this point
return; return;
} }
if (image == null) if (image == null)
return; return;
ContentValues values = new ContentValues(); ContentValues values = new ContentValues();
ByteArrayOutputStream baos = new ByteArrayOutputStream(); ByteArrayOutputStream baos = new ByteArrayOutputStream();
image.compress(CompressFormat.JPEG, 100, baos); image.compress(CompressFormat.JPEG, 100, baos);
values.put("image", baos.toByteArray()); values.put("image", baos.toByteArray());
db.update(TABLE_NAME, values, "id LIKE " + id, null); db.update(TABLE_NAME, values, "id LIKE " + id, null);
} }
public int saveDraft(String to, String message) { public int saveDraft(String to, String message) {
if (useNativeAPI) { if (useNativeAPI) {
//TODO //TODO
return -1; return -1;
} }
ContentValues values = new ContentValues(); ContentValues values = new ContentValues();
values.put("remoteContact", to); values.put("remoteContact", to);
values.put("message", message); values.put("message", message);
return (int) db.insert(DRAFT_TABLE_NAME, null, values); return (int) db.insert(DRAFT_TABLE_NAME, null, values);
} }
public void updateDraft(String to, String message) { public void updateDraft(String to, String message) {
if (useNativeAPI) { if (useNativeAPI) {
//TODO //TODO
return; return;
} }
ContentValues values = new ContentValues(); ContentValues values = new ContentValues();
values.put("message", message); values.put("message", message);
db.update(DRAFT_TABLE_NAME, values, "remoteContact LIKE \"" + to + "\"", null); db.update(DRAFT_TABLE_NAME, values, "remoteContact LIKE \"" + to + "\"", null);
} }
public void deleteDraft(String to) { public void deleteDraft(String to) {
if (useNativeAPI) { if (useNativeAPI) {
//TODO //TODO
return; return;
} }
db.delete(DRAFT_TABLE_NAME, "remoteContact LIKE \"" + to + "\"", null); db.delete(DRAFT_TABLE_NAME, "remoteContact LIKE \"" + to + "\"", null);
} }
public String getDraft(String to) { public String getDraft(String to) {
if (useNativeAPI) { if (useNativeAPI) {
//TODO //TODO
return ""; return "";
} }
Cursor c = db.query(DRAFT_TABLE_NAME, null, "remoteContact LIKE \"" + to + "\"", null, null, null, "id ASC"); Cursor c = db.query(DRAFT_TABLE_NAME, null, "remoteContact LIKE \"" + to + "\"", null, null, null, "id ASC");
String message = null; String message = null;
@ -254,13 +254,13 @@ public class ChatStorage {
} }
} }
c.close(); c.close();
return message; return message;
} }
public List<String> getDrafts() { public List<String> getDrafts() {
List<String> drafts = new ArrayList<String>(); List<String> drafts = new ArrayList<String>();
if (useNativeAPI) { if (useNativeAPI) {
//TODO //TODO
} else { } else {
@ -276,16 +276,16 @@ public class ChatStorage {
} }
c.close(); c.close();
} }
return drafts; return drafts;
} }
public List<ChatMessage> getMessages(String correspondent) { public List<ChatMessage> getMessages(String correspondent) {
List<ChatMessage> chatMessages = new ArrayList<ChatMessage>(); List<ChatMessage> chatMessages = new ArrayList<ChatMessage>();
if (!useNativeAPI) { if (!useNativeAPI) {
Cursor c = db.query(TABLE_NAME, null, "remoteContact LIKE \"" + correspondent + "\"", null, null, null, "id ASC"); Cursor c = db.query(TABLE_NAME, null, "remoteContact LIKE \"" + correspondent + "\"", null, null, null, "id ASC");
while (c.moveToNext()) { while (c.moveToNext()) {
try { try {
String message, timestamp, url; String message, timestamp, url;
@ -297,7 +297,7 @@ public class ChatStorage {
byte[] rawImage = c.getBlob(c.getColumnIndex("image")); byte[] rawImage = c.getBlob(c.getColumnIndex("image"));
int read = c.getInt(c.getColumnIndex("read")); int read = c.getInt(c.getColumnIndex("read"));
url = c.getString(c.getColumnIndex("url")); url = c.getString(c.getColumnIndex("url"));
ChatMessage chatMessage = new ChatMessage(id, message, rawImage, timestamp, direction == INCOMING, status, read == READ); ChatMessage chatMessage = new ChatMessage(id, message, rawImage, timestamp, direction == INCOMING, status, read == READ);
chatMessage.setUrl(url); chatMessage.setUrl(url);
chatMessages.add(chatMessage); chatMessages.add(chatMessage);
@ -311,26 +311,26 @@ public class ChatStorage {
LinphoneChatMessage[] history = room.getHistory(); LinphoneChatMessage[] history = room.getHistory();
for (int i = 0; i < history.length; i++) { for (int i = 0; i < history.length; i++) {
LinphoneChatMessage message = history[i]; LinphoneChatMessage message = history[i];
Bitmap bm = null; Bitmap bm = null;
String url = message.getExternalBodyUrl(); String url = message.getExternalBodyUrl();
if (url != null && !url.startsWith("http")) { if (url != null && !url.startsWith("http")) {
bm = BitmapFactory.decodeFile(url); bm = BitmapFactory.decodeFile(url);
} }
ChatMessage chatMessage = new ChatMessage(i+1, message.getText(), bm, ChatMessage chatMessage = new ChatMessage(i+1, message.getText(), bm,
String.valueOf(message.getTime()), !message.isOutgoing(), String.valueOf(message.getTime()), !message.isOutgoing(),
message.getStatus().toInt(), message.isRead()); message.getStatus().toInt(), message.isRead());
chatMessage.setUrl(url); chatMessage.setUrl(url);
chatMessages.add(chatMessage); chatMessages.add(chatMessage);
} }
} }
return chatMessages; return chatMessages;
} }
public String getTextMessageForId(LinphoneChatRoom chatroom, int id) { public String getTextMessageForId(LinphoneChatRoom chatroom, int id) {
String message = null; String message = null;
if (useNativeAPI) { if (useNativeAPI) {
LinphoneChatMessage[] history = chatroom.getHistory(); LinphoneChatMessage[] history = chatroom.getHistory();
for (LinphoneChatMessage msg : history) { for (LinphoneChatMessage msg : history) {
@ -341,7 +341,7 @@ public class ChatStorage {
} }
} else { } else {
Cursor c = db.query(TABLE_NAME, null, "id LIKE " + id, null, null, null, null); Cursor c = db.query(TABLE_NAME, null, "id LIKE " + id, null, null, null, null);
if (c.moveToFirst()) { if (c.moveToFirst()) {
try { try {
message = c.getString(c.getColumnIndex("message")); message = c.getString(c.getColumnIndex("message"));
@ -351,10 +351,10 @@ public class ChatStorage {
} }
c.close(); c.close();
} }
return message; return message;
} }
public LinphoneChatMessage getMessage(LinphoneChatRoom chatroom, int id) { public LinphoneChatMessage getMessage(LinphoneChatRoom chatroom, int id) {
if (useNativeAPI) { if (useNativeAPI) {
LinphoneChatMessage[] history = chatroom.getHistory(); LinphoneChatMessage[] history = chatroom.getHistory();
@ -366,7 +366,7 @@ public class ChatStorage {
} }
return null; return null;
} }
public void removeDiscussion(String correspondent) { public void removeDiscussion(String correspondent) {
if (useNativeAPI) { if (useNativeAPI) {
LinphoneChatRoom chatroom = LinphoneManager.getLc().getOrCreateChatRoom(correspondent); LinphoneChatRoom chatroom = LinphoneManager.getLc().getOrCreateChatRoom(correspondent);
@ -375,30 +375,29 @@ public class ChatStorage {
db.delete(TABLE_NAME, "remoteContact LIKE \"" + correspondent + "\"", null); db.delete(TABLE_NAME, "remoteContact LIKE \"" + correspondent + "\"", null);
} }
} }
public ArrayList<String> getChatList() { public ArrayList<String> getChatList() {
ArrayList<String> chatList = new ArrayList<String>(); ArrayList<String> chatList = new ArrayList<String>();
if (useNativeAPI) { if (useNativeAPI) {
LinphoneChatRoom[] chats = LinphoneManager.getLc().getChatRooms(); LinphoneChatRoom[] chats = LinphoneManager.getLc().getChatRooms();
List<LinphoneChatRoom> rooms = new ArrayList<LinphoneChatRoom>(); List<LinphoneChatRoom> rooms = new ArrayList<LinphoneChatRoom>();
for (LinphoneChatRoom chatroom : chats) { for (LinphoneChatRoom chatroom : chats) {
if (chatroom.getHistory(1).length > 0) { if (chatroom.getHistory(1).length > 0) {
rooms.add(chatroom); rooms.add(chatroom);
} }
} }
if (rooms.size() > 1) { if (rooms.size() > 1) {
Collections.sort(rooms, new Comparator<LinphoneChatRoom>() { Collections.sort(rooms, new Comparator<LinphoneChatRoom>() {
@Override @Override
public int compare(LinphoneChatRoom a, LinphoneChatRoom b) { public int compare(LinphoneChatRoom a, LinphoneChatRoom b) {
LinphoneChatMessage[] messagesA = a.getHistory(1); LinphoneChatMessage[] messagesA = a.getHistory(1);
LinphoneChatMessage[] messagesB = b.getHistory(1); LinphoneChatMessage[] messagesB = b.getHistory(1);
long atime, btime; long atime = messagesA[0].getTime();
// /!\ Warning: Have to take the second element because it returns two even when asking for only one... long btime = messagesB[0].getTime();
atime = messagesA.length > 1 ? messagesA[1].getTime() : messagesA[0].getTime();
btime = messagesA.length > 1 ? messagesB[1].getTime() : messagesB[0].getTime();
if (atime > btime) if (atime > btime)
return -1; return -1;
else if (btime > atime) else if (btime > atime)
@ -408,7 +407,7 @@ public class ChatStorage {
} }
}); });
} }
for (LinphoneChatRoom chatroom : rooms) { for (LinphoneChatRoom chatroom : rooms) {
chatList.add(chatroom.getPeerAddress().asStringUriOnly()); chatList.add(chatroom.getPeerAddress().asStringUriOnly());
} }
@ -423,7 +422,7 @@ public class ChatStorage {
} }
c.close(); c.close();
} }
return chatList; return chatList;
} }
@ -440,7 +439,7 @@ public class ChatStorage {
db.delete(TABLE_NAME, "id LIKE " + id, null); db.delete(TABLE_NAME, "id LIKE " + id, null);
} }
} }
public void markMessageAsRead(int id) { public void markMessageAsRead(int id) {
if (!useNativeAPI) { if (!useNativeAPI) {
ContentValues values = new ContentValues(); ContentValues values = new ContentValues();
@ -448,13 +447,13 @@ public class ChatStorage {
db.update(TABLE_NAME, values, "id LIKE " + id, null); db.update(TABLE_NAME, values, "id LIKE " + id, null);
} }
} }
public void markConversationAsRead(LinphoneChatRoom chatroom) { public void markConversationAsRead(LinphoneChatRoom chatroom) {
if (useNativeAPI) { if (useNativeAPI) {
chatroom.markAsRead(); chatroom.markAsRead();
} }
} }
public int getUnreadMessageCount() { public int getUnreadMessageCount() {
int count; int count;
if (!useNativeAPI) { if (!useNativeAPI) {
@ -489,10 +488,10 @@ public class ChatStorage {
//Handled before this point //Handled before this point
return null; return null;
} }
String[] columns = { "image" }; String[] columns = { "image" };
Cursor c = db.query(TABLE_NAME, columns, "id LIKE " + id + "", null, null, null, null); Cursor c = db.query(TABLE_NAME, columns, "id LIKE " + id + "", null, null, null, null);
if (c.moveToFirst()) { if (c.moveToFirst()) {
byte[] rawImage = c.getBlob(c.getColumnIndex("image")); byte[] rawImage = c.getBlob(c.getColumnIndex("image"));
c.close(); c.close();
@ -504,20 +503,20 @@ public class ChatStorage {
} }
class ChatHelper extends SQLiteOpenHelper { class ChatHelper extends SQLiteOpenHelper {
private static final int DATABASE_VERSION = 15; private static final int DATABASE_VERSION = 15;
private static final String DATABASE_NAME = "linphone-android"; private static final String DATABASE_NAME = "linphone-android";
ChatHelper(Context context) { ChatHelper(Context context) {
super(context, DATABASE_NAME, null, DATABASE_VERSION); super(context, DATABASE_NAME, null, DATABASE_VERSION);
} }
@Override @Override
public void onCreate(SQLiteDatabase db) { public void onCreate(SQLiteDatabase db) {
db.execSQL("CREATE TABLE " + TABLE_NAME + " (id INTEGER PRIMARY KEY AUTOINCREMENT, localContact TEXT NOT NULL, remoteContact TEXT NOT NULL, direction INTEGER, message TEXT, image BLOB, url TEXT, time NUMERIC, read INTEGER, status INTEGER);"); db.execSQL("CREATE TABLE " + TABLE_NAME + " (id INTEGER PRIMARY KEY AUTOINCREMENT, localContact TEXT NOT NULL, remoteContact TEXT NOT NULL, direction INTEGER, message TEXT, image BLOB, url TEXT, time NUMERIC, read INTEGER, status INTEGER);");
db.execSQL("CREATE TABLE " + DRAFT_TABLE_NAME + " (id INTEGER PRIMARY KEY AUTOINCREMENT, remoteContact TEXT NOT NULL, message TEXT);"); db.execSQL("CREATE TABLE " + DRAFT_TABLE_NAME + " (id INTEGER PRIMARY KEY AUTOINCREMENT, remoteContact TEXT NOT NULL, message TEXT);");
} }
@Override @Override
public void onUpgrade(SQLiteDatabase db, int oldVersion, int newVersion) { public void onUpgrade(SQLiteDatabase db, int oldVersion, int newVersion) {
db.execSQL("DROP TABLE IF EXISTS " + TABLE_NAME + ";"); db.execSQL("DROP TABLE IF EXISTS " + TABLE_NAME + ";");
@ -525,4 +524,4 @@ public class ChatStorage {
onCreate(db); onCreate(db);
} }
} }
} }