Monorepo: Gitea CI, docs, auth/sync, backend APIs, gitignore
- Add Gitea Actions workflow; point README to gitea.d-bis.org/Sankofa_Phoenix/SMOA - Expand .gitignore for Spring H2 data, secrets, Kotlin .kotlin/, tooling - Track docs/api/generated ReDoc bundle; refresh api docs README - Android: network/auth/sync, UI shell, tests; backend credentials/integrity APIs - Docs, scripts (generate-api-docs), modules and core updates Made-with: Cursor
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
# Building SMOA
|
||||
|
||||
## Requirements
|
||||
|
||||
- **JDK 17** (`JAVA_HOME` pointing at a JDK with `bin/java`)
|
||||
- **Android SDK** with **Platform 34** (match `AppConfig.compileSdk`) for `:app:assembleDebug`
|
||||
|
||||
## Commands
|
||||
|
||||
```bash
|
||||
# Recommended one-liner (backend tests + debug APK):
|
||||
./gradlew smoaVerify --no-daemon
|
||||
|
||||
# Or from repo root:
|
||||
./scripts/build-all.sh
|
||||
|
||||
# Individual targets:
|
||||
./gradlew :backend:test # Spring Boot unit/integration tests
|
||||
./gradlew :app:assembleDebug # Android debug APK
|
||||
./gradlew build # Full multi-project (needs Android SDK)
|
||||
```
|
||||
|
||||
Debug APK output: `app/build/outputs/apk/debug/app-debug.apk`
|
||||
|
||||
## CI
|
||||
|
||||
Gitea Actions runs `./gradlew smoaVerify --no-daemon` on push and pull requests
|
||||
(see `.gitea/workflows/ci.yml`).
|
||||
@@ -0,0 +1,22 @@
|
||||
# Keeping OpenAPI in sync
|
||||
|
||||
## Source of truth
|
||||
|
||||
The **running Spring Boot app** exposes the authoritative contract:
|
||||
|
||||
- **OpenAPI JSON:** `GET /v3/api-docs`
|
||||
- **Swagger UI:** `/swagger-ui.html`
|
||||
|
||||
The static file `docs/api/api-specification.yaml` is a **human-maintained reference** for design reviews. It can drift from springdoc.
|
||||
|
||||
## Optional CI drift check
|
||||
|
||||
1. Start the backend locally: `./gradlew :backend:bootRun` (or run the JAR).
|
||||
2. Export: `curl -s http://localhost:8080/v3/api-docs -o /tmp/smoa-openapi.json`
|
||||
3. Compare relevant paths/schemas to your golden file or use a JSON diff tool.
|
||||
|
||||
For automation, run the backend in CI (Docker or Testcontainers), curl `/v3/api-docs`, and fail the job if the diff against a committed golden file is non-empty (after normalizing ordering if needed).
|
||||
|
||||
## Script
|
||||
|
||||
See `scripts/export-openapi-local.sh` for a minimal local export (requires a reachable backend).
|
||||
@@ -0,0 +1,41 @@
|
||||
# Enterprise security configuration (SMOA Android)
|
||||
|
||||
Build-time Gradle properties (`-P` or `gradle.properties`) map to `BuildConfig` and runtime behavior.
|
||||
|
||||
## TLS certificate pinning
|
||||
|
||||
1. Obtain SPKI SHA-256 pins for your API host (e.g. `openssl s_client -connect host:443 | openssl x509 -pubkey -noout | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | openssl enc -base64` → prefix with `sha256/`).
|
||||
2. Set **backend base URL** so the host can be resolved: `-Psmoa.backend.baseUrl=https://api.example.com/`
|
||||
3. Set pins: `-Psmoa.tls.pins=sha256/PRIMARY==,sha256/BACKUP==`
|
||||
|
||||
Pinning applies only when `SMOA_BACKEND_BASE_URL` yields a host. Config-only deployments should still set a canonical backend URL for pinning, or extend `NetworkPinningConfig` to read `RemoteEndpointStore`.
|
||||
|
||||
## OIDC / OAuth
|
||||
|
||||
Set issuer, client id, and redirect URI matching your IdP and app manifest intent-filter:
|
||||
|
||||
- `smoa.oidc.issuer`
|
||||
- `smoa.oidc.clientId`
|
||||
- `smoa.oidc.redirectUri`
|
||||
|
||||
Tokens are stored in **`SecureTokenStore`** (encrypted). **`AuthTokenInterceptor`** adds `Authorization: Bearer` when an access token exists. Wire **AppAuth** or your SSO WebView** to call `SecureTokenStore.persistTokens(...)` after code exchange.
|
||||
|
||||
## Session lock
|
||||
|
||||
`smoa.session.timeoutMinutes` (default **15**). Set to **0** to disable background lock. Unlock uses the same biometric flow as sign-in (`SessionLockOverlay`).
|
||||
|
||||
## Play Integrity
|
||||
|
||||
Set `smoa.playIntegrity.cloudProjectNumber` to your Google Cloud project number linked in Play Console. Use **User settings → Run Play Integrity** for a smoke test; verify tokens on your backend with Google’s API.
|
||||
|
||||
## Classification label
|
||||
|
||||
`smoa.classification.buildMarking` is shown in User settings and should match your security office’s build marking policy (not a substitute for data labeling in content).
|
||||
|
||||
## Knox / MDM
|
||||
|
||||
`KnoxEnterpriseProbe` only detects Knox classes on the classpath. For enforcement, integrate **Samsung Knox SDK** or your **UEM** (VMware Workspace ONE, Intune, etc.) per deployment standards.
|
||||
|
||||
## Biometric-gated AES key
|
||||
|
||||
`BiometricSecretsVault` creates a **user-authentication-required** AES key in AndroidKeyStore for wrapping secrets. Complete cipher + `BiometricPrompt.CryptoObject` wiring when binding refresh-token protection to your IdP flow.
|
||||
Reference in New Issue
Block a user