Files
Amber/.github/workflows/check-offline-permissions.yml
T
Claude 0fef2bcfad Check for CHANGE_NETWORK_STATE and ACCESS_NETWORK_STATE in offline manifest
Expand the offline permissions check workflow to also verify that
CHANGE_NETWORK_STATE and ACCESS_NETWORK_STATE are not present in the
merged manifest, in addition to the existing INTERNET permission check.

https://claude.ai/code/session_01AoRYewAhR6nhY6hGJhLPem
2026-03-18 10:52:49 +00:00

62 lines
1.9 KiB
YAML

name: Check Offline Build Permissions
on:
pull_request:
branches: [master]
push:
branches: [master]
jobs:
check-offline-permissions:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- name: Set up JDK 21
uses: actions/setup-java@v4
with:
distribution: 'temurin'
java-version: 21
- name: Cache Gradle
uses: actions/cache@v4
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: ${{ runner.os }}-gradle-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: |
${{ runner.os }}-gradle-
- name: Create keystore.properties
run: touch keystore.properties
- name: Generate merged manifest for offline build
run: ./gradlew processOfflineDebugManifest --no-daemon
- name: Check for network permissions in offline merged manifest
run: |
MANIFEST=$(find app/build/intermediates/merged_manifests -name "AndroidManifest.xml" | grep -i offline | head -1)
if [ -z "$MANIFEST" ]; then
echo "ERROR: Could not find merged manifest for offline build"
exit 1
fi
echo "Checking: $MANIFEST"
FAILED=0
for PERMISSION in android.permission.INTERNET android.permission.CHANGE_NETWORK_STATE android.permission.ACCESS_NETWORK_STATE; do
if grep -q "$PERMISSION" "$MANIFEST"; then
echo ""
echo "ERROR: $PERMISSION found in offline build manifest!"
echo "The offline flavor must not include network permissions."
echo ""
echo "Offending lines:"
grep "$PERMISSION" "$MANIFEST"
FAILED=1
else
echo "OK: No $PERMISSION in offline build manifest"
fi
done
exit $FAILED