Files
Amber/.github/workflows/check-offline-permissions.yml
T
Claude 12a437a858 Add workflow to check for INTERNET permission in offline build
Runs on every push/PR to master. Processes the merged manifest for
the offlineDebug variant and fails if android.permission.INTERNET is
present — catching any accidental re-introduction of network access
in the offline flavor.

https://claude.ai/code/session_01CrqXjZyMNnBkPtxjW9tTvR
2026-03-16 19:22:59 +00:00

58 lines
1.7 KiB
YAML

name: Check Offline Build Permissions
on:
pull_request:
branches: [master]
push:
branches: [master]
jobs:
check-offline-permissions:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- name: Set up JDK 21
uses: actions/setup-java@v4
with:
distribution: 'temurin'
java-version: 21
- name: Cache Gradle
uses: actions/cache@v4
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: ${{ runner.os }}-gradle-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: |
${{ runner.os }}-gradle-
- name: Create keystore.properties
run: touch keystore.properties
- name: Generate merged manifest for offline build
run: ./gradlew processOfflineDebugManifest --no-daemon
- name: Check for INTERNET permission in offline merged manifest
run: |
MANIFEST=$(find app/build/intermediates/merged_manifests -name "AndroidManifest.xml" | grep -i offline | head -1)
if [ -z "$MANIFEST" ]; then
echo "ERROR: Could not find merged manifest for offline build"
exit 1
fi
echo "Checking: $MANIFEST"
if grep -q 'android.permission.INTERNET' "$MANIFEST"; then
echo ""
echo "ERROR: android.permission.INTERNET found in offline build manifest!"
echo "The offline flavor must not include INTERNET permission."
echo ""
echo "Offending lines:"
grep 'android.permission.INTERNET' "$MANIFEST"
exit 1
else
echo "OK: No INTERNET permission in offline build manifest"
fi