Android

Document permissions with the Storage Access Framework

Intents, storage, permissions, WebView and inter-app communication.

Android components1 min readEditorial methods

Selecting a document grants access to a resource, not unrestricted trust in its contents. Treat the returned URI as external input.

Evaluation approach

Limit size, types and parsing resources. If persistent URI permission is needed, manage its scope and revocation.

Application example

Reject oversized or unexpected contract files safely. A selected filename is not authentication evidence.

Limits and considerations

Provider metadata alone does not validate actual content.

Why filenames are not trustworthy

Names, MIME metadata and content may disagree. Avoid classification based on one alone. Apply resource limits before parsing and explain supported formats in concise rejection messages.

Checks and decisions

  • Set size limits
  • Handle permission loss
  • Validate formats

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.