{ "id": "161665", "key": "TIMOB-23619", "fields": { "issuetype": { "id": "4", "description": "An improvement or enhancement to an existing feature or task.", "name": "Improvement", "subtask": false }, "project": { "id": "10153", "key": "TIMOB", "name": "Titanium SDK/CLI", "projectCategory": { "id": "10100", "description": "Titanium and related SDKs used in application development", "name": "Client" } }, "fixVersions": [], "resolution": { "id": "2", "description": "The problem described is an issue which will never be fixed.", "name": "Won't Fix" }, "resolutiondate": "2016-07-13T11:39:24.000+0000", "created": "2016-07-11T09:11:03.000+0000", "priority": { "name": "None", "id": "6" }, "labels": [], "versions": [], "issuelinks": [], "assignee": { "name": "msamah", "key": "msamah", "displayName": "Ashraf Abu", "active": false, "timeZone": "Asia/Singapore" }, "updated": "2017-03-23T22:44:48.000+0000", "status": { "description": "The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.", "name": "Closed", "id": "6", "statusCategory": { "id": 3, "key": "done", "colorName": "green", "name": "Done" } }, "components": [ { "id": "10202", "name": "Android", "description": "Android Platform" } ], "description": "In the attachment there is a security report about Android. There are 8 issues. Many of which are about SSL.", "attachment": [ { "id": "59755", "filename": "net.roamler (1).pdf", "author": { "name": "topener", "key": "topener", "displayName": "Rene Pot", "active": true, "timeZone": "Europe/Berlin" }, "created": "2016-07-11T09:10:54.000+0000", "size": 8861, "mimeType": "application/pdf" } ], "flagged": false, "summary": "Android: Security report reveals many issues about SSL", "creator": { "name": "topener", "key": "topener", "displayName": "Rene Pot", "active": true, "timeZone": "Europe/Berlin" }, "subtasks": [], "reporter": { "name": "topener", "key": "topener", "displayName": "Rene Pot", "active": true, "timeZone": "Europe/Berlin" }, "environment": "The app has been build with Ti SDK 5.0.2.GA & alloy 1.7.33", "closedSprints": [ { "id": 678, "state": "closed", "name": "2016 Sprint 14 SDK", "startDate": "2016-07-02T00:25:57.921Z", "endDate": "2016-07-16T00:25:00.000Z", "completeDate": "2016-07-18T03:18:29.729Z", "originBoardId": 114 } ], "comment": { "comments": [ { "id": "390593", "author": { "name": "msamah", "key": "msamah", "displayName": "Ashraf Abu", "active": false, "timeZone": "Asia/Singapore" }, "body": "Based on that report, here's the SSL issues:\r\n\r\nIssue 3: This is used only in development. In Production, this class is not used.\r\nIssue 6: It's a feature to can be used to disable/ignore this.\r\nIssue 7: Same as Issue 3.\r\nIssue 8: We are using it for our bindings. This is already noted in the docs [https://developer.android.com/reference/android/webkit/WebView.html#addJavascriptInterface(java.lang.Object, java.lang.String)]\r\n\r\nPlease note, a number of the issues listed also include Facebook classes.\r\n\r\nThe issues listed has a valid reason to be there and they've actually been noted before to not cause issues.\r\n\r\nThanks for the report [~topener].", "updateAuthor": { "name": "msamah", "key": "msamah", "displayName": "Ashraf Abu", "active": false, "timeZone": "Asia/Singapore" }, "created": "2016-07-13T11:36:06.000+0000", "updated": "2016-07-13T11:37:56.000+0000" }, { "id": "390595", "author": { "name": "msamah", "key": "msamah", "displayName": "Ashraf Abu", "active": false, "timeZone": "Asia/Singapore" }, "body": "Perhaps issue 8 can have some improvements.\r\nBesides that, I'll resolve this issue as Won't Fix.", "updateAuthor": { "name": "msamah", "key": "msamah", "displayName": "Ashraf Abu", "active": false, "timeZone": "Asia/Singapore" }, "created": "2016-07-13T11:40:10.000+0000", "updated": "2016-07-13T11:40:10.000+0000" }, { "id": "415491", "author": { "name": "lmorris", "key": "lmorris", "displayName": "Lee Morris", "active": false, "timeZone": "America/Los_Angeles" }, "body": "Closing ticket as Won't Fix with reference to the above comments.", "updateAuthor": { "name": "lmorris", "key": "lmorris", "displayName": "Lee Morris", "active": false, "timeZone": "America/Los_Angeles" }, "created": "2017-03-23T22:44:48.000+0000", "updated": "2017-03-23T22:44:48.000+0000" } ], "maxResults": 6, "total": 6, "startAt": 0 } } }