Conversation
… WebView - Move keystore storePassword/keyPassword out of build.gradle (committed in plaintext) into local.properties via Gradle project properties. The keystore file itself was already gitignored but the passwords were not — anyone with repo access could sign release APKs. - Set android:allowBackup="false" to prevent ADB backup extraction of SharedPreferences (server URLs, bookmarks, capture config). - Explicitly disable setAllowFileAccessFromFileURLs and setAllowUniversalAccessFromFileURLs for pre-API-30 devices (minSdk 26).
evnchn
added a commit
that referenced
this pull request
Aug 14, 2026
`./gradlew build` runs validateSigningRelease, which requires app/chromeclone.keystore. That file is gitignored and generated per-checkout, so it never exists on a runner — every run failed with `Execution failed for task ':app:validateSigningRelease'`. Build assembleDebug / testDebugUnitTest / lintDebug instead. Debug does not touch the release signing config, so CI also stays green once the keystore credentials move out of build.gradle into local.properties (PR #1) — which a runner will not have either. Also: - Drop the redundant `test` and `lint` steps (`build` already ran both). - if-no-files-found: error on the APK upload, so a missing artifact fails loudly instead of passing silently. - Add concurrency guard, timeout-minutes, permissions: read and workflow_dispatch. - Upload the lint report for triage. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security audit fixes for three issues found during code review. Further findings (cleartext traffic policy, unencrypted WebSocket, EncryptedSharedPreferences) require product decisions and are tracked separately.
Changes
1. Remove hardcoded keystore passwords from
build.gradle— CRITICALThe release signing config had
storePassword "chromeclone123"andkeyPassword "chromeclone123"committed in plaintext. While the.keystorefile itself was gitignored, the passwords were not — anyone with read access to the repo could sign release APKs with the same key.Fix: Passwords are now read from Gradle project properties (
CHROMECLONE_STORE_PASSWORD,CHROMECLONE_KEY_PASSWORD), which should be set inlocal.properties(already gitignored) or via-Pon the command line.2. Disable ADB backup — HIGH
android:allowBackup="true"allowed extraction of all app data (SharedPreferences containing server URLs, bookmarks, capture config) viaadb backup.Fix: Set
android:allowBackup="false".3. Harden WebView file-access settings — MEDIUM
setAllowFileAccess(true)is needed forfile:///android_asset/pages, but on pre-API-30 devices (minSdk is 26)setAllowFileAccessFromFileURLsandsetAllowUniversalAccessFromFileURLsdefault totrue, allowing file:// pages to read other local files and make cross-origin requests.Fix: Explicitly set both to
false.Migration note
After merging, each developer must add to their
local.properties:Remaining items (need product decisions)
usesCleartextTraffic="true"+MIXED_CONTENT_ALWAYS_ALLOW(browser needs HTTP but should scope it)ws://WebSocket to VLM service (screen/camera frames in plaintext on LAN)SharedPreferencesfor server URL → considerEncryptedSharedPreferencesREQUEST_IGNORE_BATTERY_OPTIMIZATIONSpermission scope