Java


JAVA.JS.ME : Missing JavaScript Execution (Java)

Summary

JavaScript is enabled, but there is no explicit JavaScript execution.

The Android security tips recommend that enabling of JavaScript should only be enabled if strictly necessary for a JavaScript execution.

Properties

Class Name Missing JavaScript Execution (Java)
Significance reliability
Mnemonic JAVA.JS.ME
Categories
CWE CWE:749 Exposed Dangerous Method or Function
Availability Available for Java only.

Android Only. Warnings of this class will only be reported in Android code: that is, code that uses the Android API.

Enabling Checks for this warning class are enabled by default. To disable them, add the following WARNING_FILTER rule to the project configuration file.
WARNING_FILTER += discard class="Missing JavaScript Execution (Java)"

Example

package example.javascriptExecutionChecker;

import android.app.Activity;
import android.os.Bundle;
import android.webkit.WebView;

public class JavascriptExecutionExample extends Activity {

  WebView myWebView;

  public void onCreate(Bundle savedInstanceState) {
      super.onCreate(savedInstanceState);
      myWebView = new WebView(this);
      myWebView.getSettings().setJavaScriptEnabled(true); // "Missing JavaScript Execution (Java)" warning issued here 
      setContentView(myWebView);
  }
}

Relevant Configuration File Parameters

The following configuration file parameters affect checks for this warning class.