4 Commits

Author SHA1 Message Date
c69d704881 Merge pull request 'fix(security): declare explicit network security config to forbid cleartext' (#20) from fix/manifest-cleartext-traffic into main
All checks were successful
SonarQube / analysis (push) Successful in 1m4s
Reviewed-on: #20
Reviewed-by: Colby Whitlock <whitlocktech@gmail.com>
2026-07-21 05:25:36 +00:00
26b8eecde6 fix(security): declare explicit network security config to forbid cleartext
All checks were successful
PR Checks / android-build (pull_request) Successful in 10m30s
The app is purely an HTTPS API client, but the manifest left
usesCleartextTraffic implicit, which SonarQube S5332 flags (cleartext is
implicitly permitted on older Android and a merged library manifest could
re-enable it). Add an explicit network security config:

- main/release: base-config cleartextTrafficPermitted="false" (no cleartext).
- debug override (app/src/debug/res/xml): re-permits cleartext to loopback
  (127.0.0.1/localhost) only, for local dev against http://127.0.0.1:3000.

This mirrors ServerUrl's rule (HTTPS required in release, HTTP allowed in
debug via allowInsecureHttp = BuildConfig.DEBUG) at the platform socket
layer. It also fixes a latent gap: at targetSdk 28+ the platform default
already blocks cleartext, so the debug loopback path only actually works
with the explicit domain-config now added.

Docs updated in RunicGateway/docs (android/PLAN.md M1).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-20 23:39:12 -05:00
f729b772fc Merge pull request 'ci(sonarqube): add non-blocking SonarQube analysis (project key Runic-Gateway-Android-app)' (#19) from ci/sonarqube-fix-project-key into main
All checks were successful
SonarQube / analysis (push) Successful in 57s
Reviewed-on: #19
Reviewed-by: Colby Whitlock <whitlocktech@gmail.com>
2026-07-21 04:32:35 +00:00
402d750138 ci(sonarqube): add non-blocking SonarQube analysis on push to main
All checks were successful
PR Checks / android-build (pull_request) Successful in 10m42s
Mirrors the website repo's setup: a source-based scan of app/src/main
(Kotlin) that reports to the self-hosted SonarQube server after merge,
never gating PRs.

Uses the existing SonarQube project key Runic-Gateway-Android-app (the
server rejects re-creating a case-variant key). Supersedes #18.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-20 23:20:35 -05:00
5 changed files with 40 additions and 3 deletions

View File

@@ -8,7 +8,7 @@
# Prerequisites (one-time, in the Gitea UI — Repo → Settings → Actions):
# • Secret SONAR_TOKEN — a SonarQube "Analysis" token generated at
# My Account → Security in SonarQube for the
# runic-gateway-android-app project (or a global one).
# Runic-Gateway-Android-app project (or a global one).
# • Variable SONAR_HOST_URL — the SonarQube base URL on your LAN, e.g.
# http://192.168.0.56:9000
# (kept as a variable, not committed, so the internal address stays out of git.)

View File

@@ -0,0 +1,20 @@
<?xml version="1.0" encoding="utf-8"?>
<!-- SPDX-License-Identifier: GPL-3.0-or-later -->
<!--
Debug-only override of the main network_security_config.xml. Keeps the secure
base posture (no cleartext) but re-permits cleartext to loopback so debug builds
can reach a local website backend at http://127.0.0.1:3000 / http://localhost:3000
(ServerUrl allows plain HTTP only when allowInsecureHttp = BuildConfig.DEBUG).
Because the platform default already blocks cleartext at targetSdk 28+, this
domain-config is what actually makes the debug local-dev path work at runtime.
This file is compiled only into debug builds; release builds use the main
source set's config and permit no cleartext at all.
-->
<network-security-config>
<base-config cleartextTrafficPermitted="false" />
<domain-config cleartextTrafficPermitted="true">
<domain includeSubdomains="false">127.0.0.1</domain>
<domain includeSubdomains="false">localhost</domain>
</domain-config>
</network-security-config>

View File

@@ -20,6 +20,7 @@
android:fullBackupContent="@xml/backup_rules"
android:icon="@mipmap/ic_launcher"
android:label="@string/app_name"
android:networkSecurityConfig="@xml/network_security_config"
android:roundIcon="@mipmap/ic_launcher_round"
android:supportsRtl="true"
android:theme="@style/Theme.RunicGateway">

View File

@@ -0,0 +1,16 @@
<?xml version="1.0" encoding="utf-8"?>
<!-- SPDX-License-Identifier: GPL-3.0-or-later -->
<!--
The app is purely an HTTPS API client of a shard's website backend, so the base
posture forbids all cleartext (HTTP) traffic. This makes explicit what minSdk 29 /
targetSdk 35 already default to, satisfies the "usesCleartextTraffic implicitly
enabled" scanner finding, and stops any merged library manifest from re-enabling
cleartext. It also mirrors ServerUrl's release-build rule (HTTPS required) at the
platform socket layer — defense in depth.
The debug variant overrides this file (app/src/debug/res/xml/) to re-permit
cleartext to loopback only, for local dev against http://127.0.0.1:3000.
-->
<network-security-config>
<base-config cleartextTrafficPermitted="false" />
</network-security-config>

View File

@@ -1,9 +1,9 @@
# SonarQube analysis config for the Android-app repo.
# Consumed by the scanner in .gitea/workflows/sonarqube.yml on push to main.
# The project key must match the one created in SonarQube (dashboard URL
# ?id=runic-gateway-android-app).
# ?id=Runic-Gateway-Android-app).
sonar.projectKey=runic-gateway-android-app
sonar.projectKey=Runic-Gateway-Android-app
sonar.projectName=runic gateway android app
# Analysed application code. The single :app module's Kotlin sources.