Merge pull request 'fix(security): declare explicit network security config to forbid cleartext' (#20) from fix/manifest-cleartext-traffic into main
All checks were successful
SonarQube / analysis (push) Successful in 1m4s
All checks were successful
SonarQube / analysis (push) Successful in 1m4s
Reviewed-on: #20 Reviewed-by: Colby Whitlock <whitlocktech@gmail.com>
This commit is contained in:
20
app/src/debug/res/xml/network_security_config.xml
Normal file
20
app/src/debug/res/xml/network_security_config.xml
Normal file
@@ -0,0 +1,20 @@
|
|||||||
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
|
<!-- SPDX-License-Identifier: GPL-3.0-or-later -->
|
||||||
|
<!--
|
||||||
|
Debug-only override of the main network_security_config.xml. Keeps the secure
|
||||||
|
base posture (no cleartext) but re-permits cleartext to loopback so debug builds
|
||||||
|
can reach a local website backend at http://127.0.0.1:3000 / http://localhost:3000
|
||||||
|
(ServerUrl allows plain HTTP only when allowInsecureHttp = BuildConfig.DEBUG).
|
||||||
|
Because the platform default already blocks cleartext at targetSdk 28+, this
|
||||||
|
domain-config is what actually makes the debug local-dev path work at runtime.
|
||||||
|
|
||||||
|
This file is compiled only into debug builds; release builds use the main
|
||||||
|
source set's config and permit no cleartext at all.
|
||||||
|
-->
|
||||||
|
<network-security-config>
|
||||||
|
<base-config cleartextTrafficPermitted="false" />
|
||||||
|
<domain-config cleartextTrafficPermitted="true">
|
||||||
|
<domain includeSubdomains="false">127.0.0.1</domain>
|
||||||
|
<domain includeSubdomains="false">localhost</domain>
|
||||||
|
</domain-config>
|
||||||
|
</network-security-config>
|
||||||
@@ -20,6 +20,7 @@
|
|||||||
android:fullBackupContent="@xml/backup_rules"
|
android:fullBackupContent="@xml/backup_rules"
|
||||||
android:icon="@mipmap/ic_launcher"
|
android:icon="@mipmap/ic_launcher"
|
||||||
android:label="@string/app_name"
|
android:label="@string/app_name"
|
||||||
|
android:networkSecurityConfig="@xml/network_security_config"
|
||||||
android:roundIcon="@mipmap/ic_launcher_round"
|
android:roundIcon="@mipmap/ic_launcher_round"
|
||||||
android:supportsRtl="true"
|
android:supportsRtl="true"
|
||||||
android:theme="@style/Theme.RunicGateway">
|
android:theme="@style/Theme.RunicGateway">
|
||||||
|
|||||||
16
app/src/main/res/xml/network_security_config.xml
Normal file
16
app/src/main/res/xml/network_security_config.xml
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
|
<!-- SPDX-License-Identifier: GPL-3.0-or-later -->
|
||||||
|
<!--
|
||||||
|
The app is purely an HTTPS API client of a shard's website backend, so the base
|
||||||
|
posture forbids all cleartext (HTTP) traffic. This makes explicit what minSdk 29 /
|
||||||
|
targetSdk 35 already default to, satisfies the "usesCleartextTraffic implicitly
|
||||||
|
enabled" scanner finding, and stops any merged library manifest from re-enabling
|
||||||
|
cleartext. It also mirrors ServerUrl's release-build rule (HTTPS required) at the
|
||||||
|
platform socket layer — defense in depth.
|
||||||
|
|
||||||
|
The debug variant overrides this file (app/src/debug/res/xml/) to re-permit
|
||||||
|
cleartext to loopback only, for local dev against http://127.0.0.1:3000.
|
||||||
|
-->
|
||||||
|
<network-security-config>
|
||||||
|
<base-config cleartextTrafficPermitted="false" />
|
||||||
|
</network-security-config>
|
||||||
Reference in New Issue
Block a user