Android webview security loadDataWithBaseURL
A quick lesson in web views in Android. Normally they are a big risky area, be it adding JavaScript interfaces (http://labs.mwrinfosecurity.com/blog/2012/04/30/building-android-javajavascript-bridges/), or just generally enabling javascript and opening yourself up to webkit exploits (which given how little the OEMs update their firmware, is not hard to do).
So another interesting bit to concern yourself with is found on the following page's code:
http://www.androidsnippets.com/webview-with-custom-html-and-local-images
The code is as follows:
/**
* This code loads a custom HTML from a string which references a local image
* - for this to work, simply place the image in the directory /assets/
*/
public void loadHTML() {
final String mimeType = "text/html";
final String encoding = "utf-8";
final String html = "
Header
Custom HTML
";
WebView wv = (WebView) findViewById(R.id.wv1);
wv.loadDataWithBaseURL("fake://not/needed", html, mimeType, encoding, "");