From 26432b534efadc88eaf58a37e63b9a9b8e34cfc3 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 16 Mar 2026 18:55:31 +0000 Subject: [PATCH 1/3] Remove INTERNET permission from main manifest for offline flavor The INTERNET permission was declared in main/AndroidManifest.xml, causing it to be merged into both the free and offline build variants. Since the offline flavor has no network stack, it should not request INTERNET permission. The free/AndroidManifest.xml already declares android.permission.INTERNET, so the free flavor is unaffected by this change. --- app/src/main/AndroidManifest.xml | 1 - 1 file changed, 1 deletion(-) diff --git a/app/src/main/AndroidManifest.xml b/app/src/main/AndroidManifest.xml index 6a287b31..08a755fd 100644 --- a/app/src/main/AndroidManifest.xml +++ b/app/src/main/AndroidManifest.xml @@ -8,7 +8,6 @@ - From 37c11c6ec6ee25940281c95cbbe2a44ff9375e67 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 16 Mar 2026 19:00:52 +0000 Subject: [PATCH 2/3] Restrict internet permissions and network deps to free flavor only - Add tools:node="remove" for INTERNET, CHANGE_NETWORK_STATE, and ACCESS_NETWORK_STATE in the offline manifest to explicitly strip any internet permissions injected by library AARs during manifest merge - Move coil-okhttp (OkHttp network backend for Coil) from implementation to freeImplementation; remove duplicate okhttpCoroutines plain dep - kmp-tor was already freeImplementation; this completes the isolation --- app/build.gradle | 5 ++--- app/src/offline/AndroidManifest.xml | 5 +++++ 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/app/build.gradle b/app/build.gradle index 6620ef41..e7a4fdc0 100644 --- a/app/build.gradle +++ b/app/build.gradle @@ -243,9 +243,8 @@ dependencies { implementation libs.coil.gif // view svgs implementation libs.coil.svg - // enables network for coil - implementation libs.coil.okhttp - implementation libs.okhttpCoroutines + // enables network for coil (free only — offline has no network stack) + freeImplementation libs.coil.okhttp implementation libs.storage diff --git a/app/src/offline/AndroidManifest.xml b/app/src/offline/AndroidManifest.xml index 269ea875..1b5ef245 100644 --- a/app/src/offline/AndroidManifest.xml +++ b/app/src/offline/AndroidManifest.xml @@ -2,6 +2,11 @@ + + + + + Date: Mon, 16 Mar 2026 19:39:22 +0000 Subject: [PATCH 3/3] Revert okhttp/coil to implementation; rely on manifest remove for offline The okhttp package files (OkHttpWebSocket, HttpClientManager, interceptors) and TrustScoreService all live in the main source set and need okhttp to compile in both flavors. They are guarded by BuildFlavorChecker at runtime. The tools:node="remove" in offline/AndroidManifest.xml is sufficient to strip INTERNET/network permissions from the offline APK during manifest merge, regardless of what library AARs declare. --- app/build.gradle | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/app/build.gradle b/app/build.gradle index e7a4fdc0..6620ef41 100644 --- a/app/build.gradle +++ b/app/build.gradle @@ -243,8 +243,9 @@ dependencies { implementation libs.coil.gif // view svgs implementation libs.coil.svg - // enables network for coil (free only — offline has no network stack) - freeImplementation libs.coil.okhttp + // enables network for coil + implementation libs.coil.okhttp + implementation libs.okhttpCoroutines implementation libs.storage