diff --git a/darwin/mapkit_flutter/Sources/mapkit_flutter/MapView/MapKitViewHost.swift b/darwin/mapkit_flutter/Sources/mapkit_flutter/MapView/MapKitViewHost.swift index 539f4b6..9f851d8 100644 --- a/darwin/mapkit_flutter/Sources/mapkit_flutter/MapView/MapKitViewHost.swift +++ b/darwin/mapkit_flutter/Sources/mapkit_flutter/MapView/MapKitViewHost.swift @@ -205,6 +205,9 @@ public class MapKitViewHost: NSObject, @preconcurrency MapKitHostApi { #endif func addTileOverlay(overlay overlayData: PlatformTileOverlay) throws { + guard overlayData.urlTemplate.hasPrefix("https://") || overlayData.urlTemplate.hasPrefix("http://") else { + throw mapKitError("invalid-url-template", "Tile overlay urlTemplate must use https:// or http:// scheme.") + } let overlay = FlutterTileOverlay(fromPlatform: overlayData) if !overlay.id.isEmpty, tileOverlays[overlay.id] != nil { try removeTileOverlay(tileOverlayId: overlay.id) diff --git a/lib/src/mk_tile_overlay.dart b/lib/src/mk_tile_overlay.dart index b1cccc3..e46f839 100644 --- a/lib/src/mk_tile_overlay.dart +++ b/lib/src/mk_tile_overlay.dart @@ -67,16 +67,22 @@ final class MKTileOverlay { /// Creates a new Platform object. /// /// See: https://developer.apple.com/documentation/mapkit - PlatformTileOverlay toPlatform() => PlatformTileOverlay( - id: id.value, - urlTemplate: urlTemplate, - minimumZ: minimumZ, - maximumZ: maximumZ, - tileSize: tileSize, - canReplaceMapContent: canReplaceMapContent, - alpha: alpha, - level: level, - ); + PlatformTileOverlay toPlatform() { + if (!urlTemplate.startsWith('https://') && + !urlTemplate.startsWith('http://')) { + throw ArgumentError('urlTemplate must use https:// or http:// scheme'); + } + return PlatformTileOverlay( + id: id.value, + urlTemplate: urlTemplate, + minimumZ: minimumZ, + maximumZ: maximumZ, + tileSize: tileSize, + canReplaceMapContent: canReplaceMapContent, + alpha: alpha, + level: level, + ); + } @override bool operator ==(Object other) => diff --git a/test/mk_tile_overlay_test.dart b/test/mk_tile_overlay_test.dart index 976f36e..9a997ad 100644 --- a/test/mk_tile_overlay_test.dart +++ b/test/mk_tile_overlay_test.dart @@ -50,6 +50,14 @@ void main() { ), ).throws(); }); + + test('rejects invalid url template scheme in toPlatform()', () { + const overlay = MKTileOverlay( + id: MKTileOverlayId('bad_scheme'), + urlTemplate: 'file:///etc/passwd', + ); + check(() => overlay.toPlatform()).throws(); + }); }); group('equality', () {