From a whole-repo security review (no critical/high issues; TLS cert and hostname validation were already intact): - Don't offer the plaintext "None" transport in manual account setup; it would send credentials in the clear. The enum value stays only for local test servers. - Relabel the advanced toggle "Allow insecure STARTTLS fallback" with a warning subtitle: it relaxes (does not enable) STARTTLS and permits a plaintext downgrade when on. Default stays off/secure. - Set mail.<proto>.ssl.checkserveridentity=true explicitly on IMAP/SMTP as insurance over the (already-true) Angus default. - Add a Content-Security-Policy meta to the reader WebView (JavaScript is already disabled). - Strip Log.d/Log.v in release builds and drop the account address from the IDLE log; mark new-mail notifications VISIBILITY_PRIVATE. Add opt-in at-rest encryption of the Room cache (Settings -> "Encrypt local cache", off by default) using SQLCipher. The DB passphrase is a random key sealed by the existing Keystore crypto and kept in a separate DataStore. DatabaseEncryption performs a self-healing, atomic plaintext<->encrypted migration at startup that preserves PRAGMA user_version, so toggling applies on next launch without data loss. Verified end-to-end on an API 37 emulator (DatabaseEncryptionTest round-trip, 7 instrumented tests) plus 12 unit tests and a release R8 build. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
165 lines
6.3 KiB
Kotlin
165 lines
6.3 KiB
Kotlin
// SPDX-License-Identifier: GPL-3.0-or-later
|
|
import java.util.Properties
|
|
|
|
plugins {
|
|
// Applied by id; the plugins themselves come from the root buildscript classpath.
|
|
// We deliberately do NOT apply org.jetbrains.kotlin.android — AGP's built-in Kotlin
|
|
// handles Kotlin compilation (using KGP 2.4.0 from the buildscript classpath).
|
|
id("com.android.application")
|
|
id("org.jetbrains.kotlin.plugin.compose")
|
|
id("com.google.devtools.ksp")
|
|
id("com.google.dagger.hilt.android")
|
|
}
|
|
|
|
// Read the Gmail OAuth client id from secrets.properties (git-ignored). Empty when absent.
|
|
val secretsFile = rootProject.file("secrets.properties")
|
|
val secrets = Properties().apply {
|
|
if (secretsFile.exists()) secretsFile.inputStream().use { load(it) }
|
|
}
|
|
val gmailOAuthClientId: String = secrets.getProperty("GMAIL_OAUTH_CLIENT_ID", "")
|
|
|
|
// For a Google installed-app OAuth client, AppAuth's redirect is the reversed client
|
|
// id as a custom URI scheme. Fall back to a placeholder so the manifest stays valid
|
|
// until a real client id is set in secrets.properties.
|
|
val gmailRedirectScheme: String = if (gmailOAuthClientId.endsWith(".apps.googleusercontent.com")) {
|
|
"com.googleusercontent.apps." + gmailOAuthClientId.removeSuffix(".apps.googleusercontent.com")
|
|
} else {
|
|
"org.libremail.oauth"
|
|
}
|
|
|
|
// Microsoft (Outlook) OAuth public client id — a GUID, not a secret. Overridable via
|
|
// secrets.properties; defaults to the app's registered client id.
|
|
val outlookOAuthClientId: String = secrets.getProperty(
|
|
"OUTLOOK_OAUTH_CLIENT_ID",
|
|
"04e4aa5e-ed1f-47f9-b567-b99a0b29b3df",
|
|
)
|
|
|
|
// Optional release signing, configured via git-ignored secrets.properties. When absent, release
|
|
// builds fall back to the debug key (installable for testing, but not publishable).
|
|
val releaseStoreFile: String? = secrets.getProperty("RELEASE_STORE_FILE")
|
|
|
|
android {
|
|
namespace = "org.libremail"
|
|
compileSdk = 37
|
|
|
|
defaultConfig {
|
|
applicationId = "org.libremail.app"
|
|
minSdk = 33
|
|
targetSdk = 37
|
|
versionCode = 1
|
|
versionName = "0.1.0"
|
|
|
|
testInstrumentationRunner = "androidx.test.runner.AndroidJUnitRunner"
|
|
|
|
buildConfigField("String", "GMAIL_OAUTH_CLIENT_ID", "\"$gmailOAuthClientId\"")
|
|
buildConfigField("String", "GMAIL_OAUTH_REDIRECT_URI", "\"$gmailRedirectScheme:/oauth2redirect\"")
|
|
buildConfigField("String", "OUTLOOK_OAUTH_CLIENT_ID", "\"$outlookOAuthClientId\"")
|
|
buildConfigField("String", "OUTLOOK_OAUTH_REDIRECT_URI", "\"org.libremail.outlook://oauth2redirect\"")
|
|
// AppAuth captures the OAuth redirect via this custom scheme.
|
|
manifestPlaceholders["appAuthRedirectScheme"] = gmailRedirectScheme
|
|
}
|
|
|
|
signingConfigs {
|
|
if (releaseStoreFile != null) {
|
|
create("release") {
|
|
storeFile = file(releaseStoreFile)
|
|
storePassword = secrets.getProperty("RELEASE_STORE_PASSWORD")
|
|
keyAlias = secrets.getProperty("RELEASE_KEY_ALIAS")
|
|
keyPassword = secrets.getProperty("RELEASE_KEY_PASSWORD")
|
|
}
|
|
}
|
|
}
|
|
|
|
buildTypes {
|
|
release {
|
|
isMinifyEnabled = true
|
|
proguardFiles(
|
|
getDefaultProguardFile("proguard-android-optimize.txt"),
|
|
"proguard-rules.pro",
|
|
)
|
|
// Use a dedicated release keystore when configured in secrets.properties; otherwise fall
|
|
// back to the debug key so the build is still installable for local testing.
|
|
signingConfig = if (releaseStoreFile != null) {
|
|
signingConfigs.getByName("release")
|
|
} else {
|
|
signingConfigs.getByName("debug")
|
|
}
|
|
}
|
|
}
|
|
|
|
buildFeatures {
|
|
compose = true
|
|
buildConfig = true
|
|
}
|
|
|
|
packaging {
|
|
resources {
|
|
// Angus Mail / Jakarta Activation (added later) ship duplicate META-INF entries.
|
|
excludes += setOf(
|
|
"/META-INF/{AL2.0,LGPL2.1}",
|
|
"/META-INF/DEPENDENCIES",
|
|
"/META-INF/LICENSE*",
|
|
"/META-INF/NOTICE*",
|
|
"/META-INF/INDEX.LIST",
|
|
)
|
|
}
|
|
}
|
|
}
|
|
|
|
// Export Room schemas so migrations can be validated by instrumented MigrationTestHelper tests.
|
|
ksp {
|
|
arg("room.schemaLocation", "$projectDir/schemas")
|
|
}
|
|
|
|
dependencies {
|
|
implementation(libs.androidx.core.ktx)
|
|
implementation(libs.androidx.lifecycle.runtime.ktx)
|
|
implementation(libs.androidx.lifecycle.runtime.compose)
|
|
implementation(libs.androidx.lifecycle.viewmodel.compose)
|
|
implementation(libs.androidx.activity.compose)
|
|
implementation(libs.androidx.navigation.compose)
|
|
implementation(libs.kotlinx.coroutines.android)
|
|
|
|
// Email transport (IMAP/SMTP) + OAuth
|
|
implementation(libs.angus.mail)
|
|
implementation(libs.appauth)
|
|
|
|
implementation(platform(libs.androidx.compose.bom))
|
|
implementation(libs.androidx.compose.ui)
|
|
implementation(libs.androidx.compose.ui.graphics)
|
|
implementation(libs.androidx.compose.ui.tooling.preview)
|
|
implementation(libs.androidx.compose.material3)
|
|
implementation(libs.androidx.compose.material.icons.core)
|
|
debugImplementation(libs.androidx.compose.ui.tooling)
|
|
debugImplementation(libs.androidx.compose.ui.test.manifest)
|
|
|
|
implementation(libs.hilt.android)
|
|
ksp(libs.hilt.compiler)
|
|
compileOnly(libs.error.prone.annotations)
|
|
implementation(libs.androidx.hilt.navigation.compose)
|
|
implementation(libs.androidx.hilt.work)
|
|
ksp(libs.androidx.hilt.compiler)
|
|
|
|
implementation(libs.androidx.work.runtime.ktx)
|
|
implementation(libs.androidx.datastore.preferences)
|
|
|
|
implementation(libs.androidx.room.runtime)
|
|
implementation(libs.androidx.room.ktx)
|
|
ksp(libs.androidx.room.compiler)
|
|
implementation(libs.sqlcipher.android)
|
|
|
|
testImplementation(libs.junit)
|
|
testImplementation(libs.kotlin.test)
|
|
testImplementation(libs.kotlinx.coroutines.test)
|
|
testImplementation(libs.turbine)
|
|
testImplementation(libs.mockk)
|
|
testImplementation(libs.greenmail)
|
|
// The real org.json for unit tests (android.jar ships a stubbed, no-op version).
|
|
testImplementation("org.json:json:20231013")
|
|
|
|
androidTestImplementation(libs.androidx.junit)
|
|
androidTestImplementation(libs.androidx.espresso.core)
|
|
androidTestImplementation(platform(libs.androidx.compose.bom))
|
|
androidTestImplementation(libs.androidx.compose.ui.test.junit4)
|
|
}
|