Silent self-update, active sessions with real client IPs, genre/year browsing, handoff fix #119
@@ -28,9 +28,9 @@
|
||||
android:fullBackupContent="@xml/backup_rules"
|
||||
android:icon="@mipmap/ic_launcher"
|
||||
android:label="@string/app_name"
|
||||
android:networkSecurityConfig="@xml/network_security_config"
|
||||
android:supportsRtl="true"
|
||||
android:theme="@style/Theme.Minstrel"
|
||||
android:usesCleartextTraffic="true"
|
||||
tools:targetApi="34">
|
||||
|
||||
<!-- Portrait-locked until a tablet/landscape layout exists.
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<!--
|
||||
Replaces a bare android:usesCleartextTraffic="true" on <application> (#2439).
|
||||
|
||||
Cleartext is still permitted app-wide, and it has to be. Two independent
|
||||
reasons, neither of which can be narrowed to a domain list:
|
||||
|
||||
1. The Minstrel server's host is entered by the user at runtime. Plenty of
|
||||
self-hosters run it over plain HTTP on a LAN; refusing that would break
|
||||
real installs rather than secure anyone.
|
||||
|
||||
2. UPnP / DLNA / Sonos. Device-description and SOAP control URLs arrive in
|
||||
SSDP responses at runtime and are plain HTTP essentially without
|
||||
exception — see player/output/upnp/{UpnpDiscoveryController,SoapClient}.
|
||||
|
||||
A <domain-config> would be the way to scope this, but it matches literal
|
||||
hostnames rather than CIDR ranges, and both sets of hosts above are unknowable
|
||||
until runtime. So a permissive base-config is an honest description of our
|
||||
situation — the gain over the manifest attribute is that the reasoning now
|
||||
lives somewhere, and there is one place to tighten if a future settings screen
|
||||
can distinguish a LAN server from a WAN one.
|
||||
|
||||
Worth stating because it looks worse than it is: this is NOT a tamper risk for
|
||||
the in-app updater. An APK altered in transit and re-signed is rejected by the
|
||||
platform as a signature mismatch on update, so the boundary there is enforced
|
||||
regardless of transport.
|
||||
|
||||
Trust anchors are deliberately left at the platform default (system CAs only).
|
||||
Adding <certificates src="user" /> would let self-hosters use HTTPS with their
|
||||
own private CA — attractive for this product, and what Mihon does — but it
|
||||
also makes the app trust every CA on the device, including a corporate MITM
|
||||
proxy. That's an operator decision, not a default worth assuming.
|
||||
-->
|
||||
<network-security-config xmlns:tools="http://schemas.android.com/tools">
|
||||
<base-config
|
||||
cleartextTrafficPermitted="true"
|
||||
tools:ignore="InsecureBaseConfiguration" />
|
||||
</network-security-config>
|
||||
Reference in New Issue
Block a user