【问题标题】:Query Android content provider from command line (adb shell)从命令行查询 Android 内容提供程序(adb shell)
【发布时间】:2015-01-16 16:08:05
【问题描述】:

有一个基于意图启动活动的命令:am start。还要发送广播:am broadcast

我认为可能应该有一个 shell 命令来查询内容提供者,可能类似于:

query content://com.myapp.authority/path --where 'column=?' --arg 1 --order 'column desc'

或类似的。

有吗?

【问题讨论】:

  • 如何使我的应用程序免受此类恶意数据注入的影响?即如何免受“adb shell content insert --uri”的影响

标签: android adb android-contentprovider android-shell


【解决方案1】:

有一个content命令:

usage: adb shell content [subcommand] [options]

usage: adb shell content insert --uri <URI> [--user <USER_ID>] --bind <BINDING> [--bind <BINDING>...]
  <URI> a content provider URI.
  <BINDING> binds a typed value to a column and is formatted:
  <COLUMN_NAME>:<TYPE>:<COLUMN_VALUE> where:
  <TYPE> specifies data type such as:
  b - boolean, s - string, i - integer, l - long, f - float, d - double
  Note: Omit the value for passing an empty string, e.g column:s:
  Example:
  # Add "new_setting" secure setting with value "new_value".
  adb shell content insert --uri content://settings/secure --bind name:s:new_setting --bind value:s:new_value

usage: adb shell content update --uri <URI> [--user <USER_ID>] [--where <WHERE>]
  <WHERE> is a SQL style where clause in quotes (You have to escape single quotes - see example below).
  Example:
  # Change "new_setting" secure setting to "newer_value".
  adb shell content update --uri content://settings/secure --bind value:s:newer_value --where "name='new_setting'"

usage: adb shell content delete --uri <URI> [--user <USER_ID>] --bind <BINDING> [--bind <BINDING>...] [--where <WHERE>]
  Example:
  # Remove "new_setting" secure setting.
  adb shell content delete --uri content://settings/secure --where "name='new_setting'"

usage: adb shell content query --uri <URI> [--user <USER_ID>] [--projection <PROJECTION>] [--where <WHERE>] [--sort <SORT_ORDER>]
  <PROJECTION> is a list of colon separated column names and is formatted:
  <COLUMN_NAME>[:<COLUMN_NAME>...]
  <SORT_ORDER> is the order in which rows in the result should be sorted.
  Example:
  # Select "name" and "value" columns from secure settings where "name" is equal to "new_setting" and sort the result by name in ascending order.
  adb shell content query --uri content://settings/secure --projection name:value --where "name='new_setting'" --sort "name ASC"

usage: adb shell content call --uri <URI> --method <METHOD> [--arg <ARG>]
       [--extra <BINDING> ...]
  <METHOD> is the name of a provider-defined method
  <ARG> is an optional string argument
  <BINDING> is like --bind above, typed data of the form <KEY>:{b,s,i,l,f,d}:<VAL>

【讨论】:

  • 如何使我的应用程序免受这种恶意数据注入的影响?即如何免受“adb shell content insert --uri”的影响?
  • 要保护 ContentProvider,请在您的 AndroidManifest.xml 中添加权限使用,如下所示:&lt;permission android:name="com.yourApp.permission.WRITE_PROVIDER" android:protectionLevel="signature" /&gt; &lt;uses-permission android:name="com.yourApp.permission.WRITE_PROVIDER" /&gt; &lt;provider android:name="YourProvider" android:authorities="com.your_app.authority" ` ...` android:writePermission="com.yourApp.permission.WRITE_PROVIDER" ... /&gt;
  • 我正在尝试使用此查询来获取屏幕方向,但它不起作用。我的命令adb shell content query --uri content://settings/system -projection name:value --where "name='user_rotation'"
  • @kanna 在您的情况下,将 "name='user_rotation'" 更改为 "name=\'user_rotation\'"
【解决方案2】:
adb shell content query --uri content://com.myapp.authority/path --where column=x --arg 1 --sort column_name DESC

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2011-02-06
    • 2014-12-05
    • 1970-01-01
    • 2015-12-06
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多