[Question] Does MASTG-TEST-0058 excludeFromBackup recommendation contradict MASTG-TEST-0215? #3181
-
MASTG ChapterMASTG-TEST-0058.md Static Analysis File Line Number22 ContextThe description recommends to use the isExcludedfromBackupKey system property. But according to MASTG-TEST-0215 using that very flag is a security vulnerability. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
Hi, I'm new here. Thanks for all your work, it's really amazing! I just watched the talk from t2con2024 and then looked into the iOS tests. Maybe I misunderstood something but I think the recommendation from the first test is in contradiction with the newer test. I tried joining you slack to reach out about this, but I was unable to join. In the invitation link it requires me to specify an |
Beta Was this translation helpful? Give feedback.
-
Hi @Evylon, and welcome to the MAS project! There are several things to consider:
MASTG-TEST-0058 (MASTG v1, old)MASTG-TEST-0058 is a v1 test and may contain inaccurate or outdated information. In this case, the test states "You can use the NSURLIsExcludedFromBackupKey ... to exclude files and directories from backups."
MASTG-TEST-0215 (MASTG v2, new)Includes current and more accurate information and provides a link to the iOS documentation where Apple explains that this method doesn't guarantee the actual exclusion.
|
Beta Was this translation helpful? Give feedback.
Hi @Evylon, and welcome to the MAS project!
There are several things to consider:
MASTG-TEST-0058 (MASTG v1, old)
MASTG-TEST-0058 is a v1 test and may contain inaccurate or outdated information. In this case, the test states "You can use the NSURLIsExcludedFromBackupKey ... to exclude files and directories fro…