From a whole-repo security review (no critical/high issues; TLS cert and hostname validation were already intact): - Don't offer the plaintext "None" transport in manual account setup; it would send credentials in the clear. The enum value stays only for local test servers. - Relabel the advanced toggle "Allow insecure STARTTLS fallback" with a warning subtitle: it relaxes (does not enable) STARTTLS and permits a plaintext downgrade when on. Default stays off/secure. - Set mail.<proto>.ssl.checkserveridentity=true explicitly on IMAP/SMTP as insurance over the (already-true) Angus default. - Add a Content-Security-Policy meta to the reader WebView (JavaScript is already disabled). - Strip Log.d/Log.v in release builds and drop the account address from the IDLE log; mark new-mail notifications VISIBILITY_PRIVATE. Add opt-in at-rest encryption of the Room cache (Settings -> "Encrypt local cache", off by default) using SQLCipher. The DB passphrase is a random key sealed by the existing Keystore crypto and kept in a separate DataStore. DatabaseEncryption performs a self-healing, atomic plaintext<->encrypted migration at startup that preserves PRAGMA user_version, so toggling applies on next launch without data loss. Verified end-to-end on an API 37 emulator (DatabaseEncryptionTest round-trip, 7 instrumented tests) plus 12 unit tests and a release R8 build. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
33 lines
1.3 KiB
Prolog
33 lines
1.3 KiB
Prolog
# SPDX-License-Identifier: GPL-3.0-or-later
|
|
# R8/ProGuard keep rules for LibreMail's release build.
|
|
|
|
# --- Jakarta / Angus Mail (IMAP/SMTP) ---
|
|
# Protocol providers (IMAP/SMTP stores and transports) are discovered via reflection and
|
|
# META-INF service files, so keep the mail and activation classes and their members intact.
|
|
-keep class jakarta.mail.** { *; }
|
|
-keep class jakarta.activation.** { *; }
|
|
-keep class org.eclipse.angus.mail.** { *; }
|
|
-keep class org.eclipse.angus.activation.** { *; }
|
|
-dontwarn jakarta.mail.**
|
|
-dontwarn jakarta.activation.**
|
|
-dontwarn org.eclipse.angus.**
|
|
-dontwarn com.sun.activation.**
|
|
|
|
# --- AppAuth ---
|
|
# AppAuth (de)serializes its models (AuthState, token responses) reflectively.
|
|
-keep class net.openid.appauth.** { *; }
|
|
-dontwarn net.openid.appauth.**
|
|
|
|
# --- Strip debug/verbose logging from release builds ---
|
|
# Drops Log.d/Log.v calls (and the evaluation of their arguments) so nothing like an
|
|
# account address is ever written to logcat in a release build.
|
|
-assumenosideeffects class android.util.Log {
|
|
public static *** d(...);
|
|
public static *** v(...);
|
|
}
|
|
|
|
# --- SQLCipher (opt-in encrypted cache) ---
|
|
# JNI-bound classes referenced by the native library; keep them intact.
|
|
-keep class net.zetetic.database.** { *; }
|
|
-dontwarn net.zetetic.database.**
|