forked from GrakovNe/lissen-android
-
-
Notifications
You must be signed in to change notification settings - Fork 1
Download Enhancements, Integrate Clarity analytics, database migrations, and cache redesign #8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
37 commits
Select commit
Hold shift + click to select a range
3dae591
feat: Implement database migration to version 16 with a dedicated UI,…
9d0f06a
feat: Filter cached book queries to only include books that have at l…
71cbf62
feat: enhance cached items screen with storage statistics, detailed b…
01f3521
feat: introduce a new download modal with enhanced options for segmen…
714d9b2
feat: Allow subtitles to span two lines and refine download modal mon…
de72283
feat: Introduce `Queued` cache status, replace the shimmering downloa…
a106485
feat: enhance caching progress reporting with notification throttling…
41717a8
feat: Remove thumbnail cache clearing functionality and associated UI…
f936b5c
feat: Integrate Microsoft Clarity for analytics tracking and UI maski…
3a2ce89
feat: Implement analytics consent, overhaul persistent caching with d…
ecd3041
feat: Update CachedItemsSettingsScreen to navigate to the library whe…
331716d
feat: Implement bulk selection for cached items in settings, add meta…
dba6ec3
feat: Implement progressive image loading with blurred thumbnails, ad…
b8a4d87
Fix: Adjust `_preparingBookId` clearing to occur upon playback start …
684ec8c
feat: Optimize playback readiness by decoupling cover art updates, en…
5b66d4c
fix: forced server availability check, pull down to refresh, continue…
52c1e27
fix: show spinner for player buttons when the playback is being prepared
fc0fa44
fix: initial launch playback freeze by moving the exo player initiali…
74fc260
add changelog generation
826141a
Add update checker service
1b5bd36
fix book deletion glitch
cc16ea0
add code rabbit
1eefb8f
feat: Prevent analytics consent bottom sheet dismissal by swipe and r…
a509960
feat: Implement structured concurrency for playback operations and re…
5b3247a
feat: Implement animated download completion effect and theme-aware i…
a05001c
feat: Implement an animated download success shine effect in `Downloa…
1d7160e
feat: Refactor `VerticalScrollbar` to accept a lazy color lambda and …
b31fcce
feat: Display a loading indicator and disable the delete button while…
6833e85
feat: Display a loading indicator in BookDetailScreen while book deta…
9e7d44b
refactor: delegate book metadata caching to `LocalCacheRepository` an…
229ed16
feat: Migrate crash reporting from ACRA to Firebase Crashlytics and i…
6ddf4e2
feat: Add Firebase Crashlytics exception reporting to various error h…
e1833a4
feat: Implement initial retry logic for server availability checks wi…
92828f4
feat: Implement optimized library synchronization using `updatedAt` t…
073c97d
fix: Improve analytics robustness, enhance playback service thread sa…
382da19
fix: correct typo from "app_crach_toast" to "app_crash_toast" in mult…
49ec6f3
chore: bump app version to 1.1.0 and update version code
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
| language: "en-US" | ||
| reviews: | ||
| auto_title_placeholder: "@coderabbit title" |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,48 @@ | ||
| { | ||
| "project_info": { | ||
| "project_number": "139954826172", | ||
| "project_id": "kahani-app-android", | ||
| "storage_bucket": "kahani-app-android.firebasestorage.app" | ||
| }, | ||
| "client": [ | ||
| { | ||
| "client_info": { | ||
| "mobilesdk_app_id": "1:139954826172:android:0f4f76f1de010ba41699b9", | ||
| "android_client_info": { | ||
| "package_name": "com.kahani.app" | ||
| } | ||
| }, | ||
| "oauth_client": [], | ||
| "api_key": [ | ||
| { | ||
| "current_key": "AIzaSyAB8o-65tB6TzUbdaqVAP9XnTl1wgC6dks" | ||
| } | ||
| ], | ||
| "services": { | ||
| "appinvite_service": { | ||
| "other_platform_oauth_client": [] | ||
| } | ||
| } | ||
| }, | ||
| { | ||
| "client_info": { | ||
| "mobilesdk_app_id": "1:139954826172:android:1d7d97392c6e248f1699b9", | ||
| "android_client_info": { | ||
| "package_name": "com.kahani.app.debug" | ||
| } | ||
| }, | ||
| "oauth_client": [], | ||
| "api_key": [ | ||
| { | ||
| "current_key": "AIzaSyAB8o-65tB6TzUbdaqVAP9XnTl1wgC6dks" | ||
| } | ||
| ], | ||
| "services": { | ||
| "appinvite_service": { | ||
| "other_platform_oauth_client": [] | ||
| } | ||
| } | ||
| } | ||
| ], | ||
| "configuration_version": "1" | ||
| } | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
GCP API key committed to repository — ensure it is restricted in Cloud Console.
While
google-services.jsonis routinely committed to Android projects (and Google documents it as safe to include in source control), the Firebase/GCP API key on Lines 18 and 37 is nonetheless visible to anyone with repo access. Static analysis (Gitleaks) correctly flags this.Mitigations to apply:
.gitignorepatterns are intentional — some teams choose to distribute this file via CI secrets instead of checking it in for public repos.No code change needed if the key is properly restricted, but leaving it unrestricted in a public repo is a security posture gap.
Also applies to: 35-38
🧰 Tools
🪛 Gitleaks (8.30.0)
[high] 18-18: Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.
(gcp-api-key)
🤖 Prompt for AI Agents