aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_android_shell.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/tests/test_android_shell.py')
-rw-r--r--packages/meshbay-hub/tests/test_android_shell.py41
1 files changed, 39 insertions, 2 deletions
diff --git a/packages/meshbay-hub/tests/test_android_shell.py b/packages/meshbay-hub/tests/test_android_shell.py
index e569bb7..129732c 100644
--- a/packages/meshbay-hub/tests/test_android_shell.py
+++ b/packages/meshbay-hub/tests/test_android_shell.py
@@ -135,11 +135,15 @@ def test_the_shim_offers_desktop_channels_and_native_answers_each():
preload = set(re.findall(r"ipcRenderer\.invoke\('([\w:-]+)'", preload_js))
native = set()
for path in (SRC / "bridge" / "Channels.kt", SRC / "bridge" / "KeyChannels.kt",
- SRC / "cast" / "CastChannels.kt"):
+ SRC / "cast" / "CastChannels.kt", SRC / "notify" / "PushChannels.kt"):
native |= set(re.findall(r'^\s*"([\w:-]+)" ->', _read(path), flags=re.M))
shim = _shim_channels()
assert shim, "no channel found in the shim"
- assert shim <= preload, f"channels the desktop does not have: {shim - preload}"
+ # A phone has a push distributor to talk to and a desktop does not; that
+ # family is the one the desktop lacks rather than the one it shares.
+ phone_only = {c for c in shim if c.startswith("push:")}
+ assert phone_only, "the push channels are gone from the shim"
+ assert shim - phone_only <= preload, f"channels the desktop does not have: {shim - preload}"
assert shim == native, f"shim and native disagree: {shim ^ native}"
@@ -196,6 +200,28 @@ def test_nothing_is_granted_and_video_may_go_fullscreen():
assert "override fun onHideCustomView" in activity
+def test_a_notification_is_drawn_only_when_it_opened_and_leads_inside_the_page():
+ """The distributor is another application: its receiver must not be ours
+ to call, a message nobody encrypted to this phone is not drawn, and the
+ link a notification carries is a route in the page, never a URL."""
+ manifest = _read(APP / "src" / "main" / "AndroidManifest.xml")
+ service = manifest.split('android:name=".notify.PushReceiver"', 1)[1].split("</service>", 1)[0]
+ assert 'android:exported="false"' in service
+ job = manifest.split('android:name=".notify.PollJob"', 1)[1].split("/>", 1)[0]
+ assert 'android:exported="false"' in job and "BIND_JOB_SERVICE" in job
+ # The background fetch carries the poll secret, never a session token.
+ poll = _read(SRC / "notify" / "PollJob.kt")
+ assert "/v1/push/poll" in poll and "Authorization" not in poll
+ receiver = _read(SRC / "notify" / "PushReceiver.kt")
+ assert "!message.decrypted" in receiver
+ notifier = _read(SRC / "notify" / "Notifier.kt")
+ assert 'Regex("^#/[A-Za-z0-9/_-]{0,200}$")' in notifier
+ assert "FLAG_IMMUTABLE" in notifier
+ activity = _read(SRC / "MainActivity.kt")
+ assert activity.count("Notifier.linkOf(intent)") == 2
+ assert 'location.hash = ${JSONObject.quote(link)}' in activity
+
+
def test_no_backup_carries_the_keys_away():
manifest = _read(APP / "src" / "main" / "AndroidManifest.xml")
assert 'android:allowBackup="false"' in manifest
@@ -215,6 +241,17 @@ def test_the_version_is_the_packages_version():
assert not re.search(r'versionName = "\d', build)
+def test_a_release_is_signed_with_the_release_key_or_not_built():
+ """The key's path and passwords come from outside the repository, and a
+ release build without them stops instead of signing with the debug key."""
+ build = _strip_js_comments(_read(APP / "build.gradle.kts"))
+ assert 'signingConfigs.getByName("debug")' not in build
+ assert 'signingConfigs.findByName("release")' in build
+ assert 'providers.gradleProperty("meshbayReleaseStorePassword")' in build
+ assert '"preReleaseBuild"' in build and "throw GradleException" in build
+ assert not re.search(r'storePassword = "', build)
+
+
@pytest.mark.skipif(not os.environ.get("ANDROID_HOME") or shutil.which("java") is None,
reason="no Android SDK in the environment")
def test_the_jvm_unit_tests_pass():