release: harden Android network security
This commit is contained in:
@@ -205,19 +205,45 @@ try {
|
||||
$application = $decodedManifest.manifest.application
|
||||
$debuggable = $application.GetAttribute('debuggable', $androidNamespace) -eq 'true'
|
||||
$usesCleartextTraffic = $application.GetAttribute('usesCleartextTraffic', $androidNamespace) -eq 'true'
|
||||
$networkSecurityConfig = $application.GetAttribute('networkSecurityConfig', $androidNamespace)
|
||||
if ($BuildKind -eq 'custom-base' -and -not $debuggable) {
|
||||
throw 'Custom base APK must remain debuggable.'
|
||||
}
|
||||
if ($BuildKind -eq 'dcloud-test' -and $debuggable) {
|
||||
throw 'DCloud internal test APK must not be debuggable.'
|
||||
}
|
||||
if ($BuildKind -in @('dcloud-test', 'release') -and $usesCleartextTraffic) {
|
||||
throw "$BuildKind APK must not allow cleartext HTTP traffic."
|
||||
}
|
||||
if ($BuildKind -in @('dcloud-test', 'release')) {
|
||||
if ($networkSecurityConfig -ne '@xml/network_security_config') {
|
||||
throw "$BuildKind APK must reference @xml/network_security_config."
|
||||
}
|
||||
$decodedNetworkSecurityPath = Join-Path $decodePath 'res\xml\network_security_config.xml'
|
||||
if (-not (Test-Path -LiteralPath $decodedNetworkSecurityPath)) {
|
||||
throw "$BuildKind APK is missing res/xml/network_security_config.xml."
|
||||
}
|
||||
$decodedNetworkSecurity = Get-Content -Raw -Encoding UTF8 -LiteralPath $decodedNetworkSecurityPath
|
||||
if ($decodedNetworkSecurity -notmatch 'cleartextTrafficPermitted=\"false\"') {
|
||||
throw "$BuildKind APK network security config must reject cleartext traffic."
|
||||
}
|
||||
if ($decodedNetworkSecurity -match 'cleartextTrafficPermitted=\"true\"') {
|
||||
throw "$BuildKind APK network security config must not contain a cleartext exception."
|
||||
}
|
||||
if ($decodedNetworkSecurity -notmatch '<certificates src=\"system\"\s*/>') {
|
||||
throw "$BuildKind APK network security config must trust system certificates only."
|
||||
}
|
||||
if ($decodedNetworkSecurity -match '<certificates src=\"(?!system\")[^\"]+\"') {
|
||||
throw "$BuildKind APK network security config must not trust user or bundled certificates."
|
||||
}
|
||||
if ($decodedNetworkSecurity -match '<debug-overrides\b') {
|
||||
throw "$BuildKind APK network security config must not contain debug trust overrides."
|
||||
}
|
||||
}
|
||||
if ($BuildKind -eq 'release') {
|
||||
if ($debuggable) {
|
||||
throw 'Release APK must not be debuggable.'
|
||||
}
|
||||
if ($usesCleartextTraffic) {
|
||||
throw 'Release APK must not allow cleartext HTTP traffic.'
|
||||
}
|
||||
if ([string]::IsNullOrWhiteSpace($ExpectedSignerSha256)) {
|
||||
throw 'Release verification requires -ExpectedSignerSha256 for the enterprise signing certificate.'
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user