Skip to content

fix(android): enforce release security boundaries - #2042

Open
damacus wants to merge 1 commit into
codex/chore-relocate-android-phonefrom
codex/fix-android-release-security
Open

fix(android): enforce release security boundaries#2042
damacus wants to merge 1 commit into
codex/chore-relocate-android-phonefrom
codex/fix-android-release-security

Conversation

@damacus

@damacus damacus commented Sep 3, 2026

Copy link
Copy Markdown
Owner

Summary

Make the Android release binary OIDC authorization-code/S256 PKCE only. Password authentication and server overrides compile only into explicitly labelled non-release builds, with a separate generated password transport surface.

Credentials now use Keystore-backed AES-GCM encryption under no-backup storage with atomic replacement. Release HTTP logging is off; opted-in non-release logging is capped at BASIC with registered sensitive-header redaction. Live canary tests require explicit Gradle opt-in and environment credentials, and ordinary aggregate tests skip them.

Release packaging accepts six documented build-time inputs and fails closed while values are missing or invalid. CI uses deliberately invalid placeholders for reproducible compilation; those APKs are not deployable. No live canary was contacted and no production identity configuration was invented.

Related to #2039. No Rails endpoint, contract or authentication behaviour changes are included.

The whole-lane review found an inherited dashboard session-isolation defect: cached data could survive account switching. The separate signed correction in #2045 also isolates bearer credentials per request. Do not treat this PR alone as the completed security remediation; review and land the complete corrected Android lane together.

@damacus
damacus force-pushed the codex/fix-android-release-security branch from 169bde6 to e0d243a Compare September 4, 2026 22:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant