fix(android): enforce release security boundaries - #2042
Open
damacus wants to merge 1 commit into
Open
Conversation
This was referenced Sep 3, 2026
damacus
force-pushed
the
codex/fix-android-release-security
branch
from
September 3, 2026 21:57
4aab297 to
325a0a0
Compare
damacus
force-pushed
the
codex/fix-android-release-security
branch
from
September 3, 2026 22:16
325a0a0 to
169bde6
Compare
damacus
force-pushed
the
codex/fix-android-release-security
branch
from
September 4, 2026 22:56
169bde6 to
e0d243a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Make the Android release binary OIDC authorization-code/S256 PKCE only. Password authentication and server overrides compile only into explicitly labelled non-release builds, with a separate generated password transport surface.
Credentials now use Keystore-backed AES-GCM encryption under no-backup storage with atomic replacement. Release HTTP logging is off; opted-in non-release logging is capped at BASIC with registered sensitive-header redaction. Live canary tests require explicit Gradle opt-in and environment credentials, and ordinary aggregate tests skip them.
Release packaging accepts six documented build-time inputs and fails closed while values are missing or invalid. CI uses deliberately invalid placeholders for reproducible compilation; those APKs are not deployable. No live canary was contacted and no production identity configuration was invented.
Related to #2039. No Rails endpoint, contract or authentication behaviour changes are included.
The whole-lane review found an inherited dashboard session-isolation defect: cached data could survive account switching. The separate signed correction in #2045 also isolates bearer credentials per request. Do not treat this PR alone as the completed security remediation; review and land the complete corrected Android lane together.