我们在Android应尽量避免使用隐式Intent广播传递信息,为什么这么说?原因有下面几点:
- 意外接收:如果同时维护几个项目,不同项目中难免会存在代码复用的情况,这时若安装了两个注册过同样 Action 广播的APP,一个APP通过
Context.sendBroadcast()
发送的隐式广播也会被另一个APP接收到,并进行相应的操作,可能会产生意想不到的风险。- 敏感信息外泄:发送的隐式广播,可能会被恶意应用注册监听该广播的 receiver 获取到Intent中传递的敏感信息,并进行其他危险的操作。
- Intent拦截:如果发送的广播为使用
Context.sendOrderedBroadcast()
方法发送的有序广播,优先级较高的恶意 receiver 若直接丢弃该广播,会导致服务无法正常使用,或者广播结果被填充恶意数据。基于以上的几点,会发现使用隐式Intent广播风险很高,那么怎么解决这个问题呢?首先,我们需要明确广播是否仅限于应用内使用。若需要在应用间传递广播,应尽量避免传递敏感信息;否则,可以使用
LocalBroadcastManager.sendBroadcast()
实现,这样就避免了意外接收广播,敏感信息外泄和Intent拦截的风险
使用方式
SimpleReceiver
class SimpleReceiver : BroadcastReceiver() {
override fun onReceive(context: Context?, intent: Intent?) {
println(" >>>>> SimpleReceiver -> onReceive <<<<< ")
println(" >>>>> ${Thread.currentThread().name} <<<<<")
}
}
ReceiverActivity
class ReceiverActivity : AppCompatActivity() {
val manager: LocalBroadcastManager by lazy {
LocalBroadcastManager.getInstance(this)
}
val receiver: SimpleReceiver by lazy {
SimpleReceiver()
}
val filter: IntentFilter by lazy {
IntentFilter().apply {
addAction("haha")
}
}
override fun onCreate(savedInstanceState: Bundle?) {
super.onCreate(savedInstanceState)
setContentView(R.layout.activity_receiver)
manager.registerReceiver(receiver, filter)
manager.sendBroadcast(Intent("haha"))
}
override fun onDestroy() {
super.onDestroy()
manager.unregisterReceiver(receiver)
}
}
输出信息
... I/System.out: >>>>> SimpleReceiver -> onReceive <<<<<
... I/System.out: >>>>> main <<<<<
原码解析
属性
// 记录 Receiver 对应的 ReceiverRecord
private final HashMap<BroadcastReceiver, ArrayList<ReceiverRecord>> mReceivers = new HashMap<>();
// 记录 Action 对应的 ReceiverRecord
private final HashMap<String, ArrayList<ReceiverRecord>> mActions = new HashMap<>();
// 记录 Receiver 消息队列
private final ArrayList<BroadcastRecord> mPendingBroadcasts = new ArrayList<>();
ReceiverRecord 记录 receiver 和 filter
private static final class ReceiverRecord {
final IntentFilter filter;
final BroadcastReceiver receiver;
boolean broadcasting;
boolean dead;
ReceiverRecord(IntentFilter _filter, BroadcastReceiver _receiver) {
filter = _filter;
receiver = _receiver;
}
@Override
public String toString() {
StringBuilder builder = new StringBuilder(128);
builder.append("Receiver{");
builder.append(receiver);
builder.append(" filter=");
builder.append(filter);
if (dead) {
builder.append(" DEAD");
}
builder.append("}");
return builder.toString();
}
}
用于记录注册的 receiver 和 对应的 filter
/**
* Register a receive for any local broadcasts that match the given IntentFilter.
* 为任何匹配给定IntentFilter的本地广播注册一个receive
*
* @param receiver The BroadcastReceiver to handle the broadcast.
* 处理广播的广播接收器
*
* @param filter Selects the Intent broadcasts to be received.
* 选择要接收的意图广播
*
* @see #unregisterReceiver
*/
public void registerReceiver(@NonNull BroadcastReceiver receiver,
@NonNull IntentFilter filter) {
synchronized (mReceivers) {
ReceiverRecord entry = new ReceiverRecord(filter, receiver);
// 添加 receiver 到 mReceivers
ArrayList<ReceiverRecord> filters = mReceivers.get(receiver);
if (filters == null) {
filters = new ArrayList<>(1);
mReceivers.put(receiver, filters);
}
filters.add(entry);
// 记录 filter 包含的所有 action
for (int i=0; i<filter.countActions(); i++) {
String action = filter.getAction(i);
ArrayList<ReceiverRecord> entries = mActions.get(action);
if (entries == null) {
entries = new ArrayList<ReceiverRecord>(1);
mActions.put(action, entries);
}
entries.add(entry);
}
}
}
BroadcastRecord 记录 intent 和 receivers
private static final class BroadcastRecord {
final Intent intent;
final ArrayList<ReceiverRecord> receivers;
BroadcastRecord(Intent _intent, ArrayList<ReceiverRecord> _receivers) {
intent = _intent;
receivers = _receivers;
}
}
匹配 intent 里的 action 对应的 receiver, 用于添加到 mPendingBroadcasts 消息队列用于发送
/**
* Broadcast the given intent to all interested BroadcastReceivers. This
* call is asynchronous; it returns immediately, and you will continue
* executing while the receivers are run.
* 将给定的意图广播给所有感兴趣(匹配)的广播接收器, 这个调用是异步的.
* 它立即返回,并且在运行接收器时您将继续执行
*
* @param intent The Intent to broadcast; all receivers matching this
* Intent will receive the broadcast.
* 所有符合此意图的接收器将接收广播
*
* @see #registerReceiver
*
* @return Returns true if the intent has been scheduled for delivery to one or more
* broadcast receivers. (Note tha delivery may not ultimately take place if one of those
* receivers is unregistered before it is dispatched.)
* 如果意图已被安排交付给一个或多个广播接收器,则返回true(请注意,
* 如果其中一个接收方在发送前未注册,则该交付可能不会最终发生)
*/
public boolean sendBroadcast(@NonNull Intent intent) {
synchronized (mReceivers) {
final String action = intent.getAction();
final String type = intent.resolveTypeIfNeeded(
mAppContext.getContentResolver());
final Uri data = intent.getData();
final String scheme = intent.getScheme();
final Set<String> categories = intent.getCategories();
final boolean debug = DEBUG ||
((intent.getFlags() & Intent.FLAG_DEBUG_LOG_RESOLUTION) != 0);
if (debug) Log.v(
TAG, "Resolving type " + type + " scheme " + scheme
+ " of intent " + intent);
// 获取 action 对应的 ReceiverRecord 集合
ArrayList<ReceiverRecord> entries = mActions.get(intent.getAction());
if (entries != null) {
if (debug) Log.v(TAG, "Action list: " + entries);
ArrayList<ReceiverRecord> receivers = null;
for (int i=0; i<entries.size(); i++) {
ReceiverRecord receiver = entries.get(i);
if (debug) Log.v(TAG, "Matching against filter " + receiver.filter);
if (receiver.broadcasting) {
if (debug) {
Log.v(TAG, " Filter's target already added");
}
continue;
}
int match = receiver.filter.match(action, type, scheme, data,
categories, "LocalBroadcastManager");
if (match >= 0) {
if (debug) Log.v(TAG, " Filter matched! match=0x" +
Integer.toHexString(match));
if (receivers == null) {
receivers = new ArrayList<ReceiverRecord>();
}
receivers.add(receiver);
receiver.broadcasting = true;
} else {
if (debug) {
String reason;
switch (match) {
case IntentFilter.NO_MATCH_ACTION: reason = "action"; break;
case IntentFilter.NO_MATCH_CATEGORY: reason = "category"; break;
case IntentFilter.NO_MATCH_DATA: reason = "data"; break;
case IntentFilter.NO_MATCH_TYPE: reason = "type"; break;
default: reason = "unknown reason"; break;
}
Log.v(TAG, " Filter did not match: " + reason);
}
}
}
if (receivers != null) {
for (int i=0; i<receivers.size(); i++) {
receivers.get(i).broadcasting = false;
}
mPendingBroadcasts.add(new BroadcastRecord(intent, receivers));
if (!mHandler.hasMessages(MSG_EXEC_PENDING_BROADCASTS)) {
mHandler.sendEmptyMessage(MSG_EXEC_PENDING_BROADCASTS);
}
return true;
}
}
}
return false;
}
通过 handler 处理消息队列 mPendingBroadcasts
private LocalBroadcastManager(Context context) {
mAppContext = context;
mHandler = new Handler(context.getMainLooper()) {
@Override
public void handleMessage(Message msg) {
switch (msg.what) {
case MSG_EXEC_PENDING_BROADCASTS:
executePendingBroadcasts();
break;
default:
super.handleMessage(msg);
}
}
};
}
void executePendingBroadcasts() {
while (true) {
final BroadcastRecord[] brs;
synchronized (mReceivers) {
final int N = mPendingBroadcasts.size();
if (N <= 0) {
return;
}
brs = new BroadcastRecord[N];
mPendingBroadcasts.toArray(brs);
mPendingBroadcasts.clear();
}
for (int i=0; i<brs.length; i++) {
final BroadcastRecord br = brs[i];
final int nbr = br.receivers.size();
for (int j=0; j<nbr; j++) {
final ReceiverRecord rec = br.receivers.get(j);
if (!rec.dead) {
rec.receiver.onReceive(mAppContext, br.intent);
}
}
}
}
}