diff options
Diffstat (limited to 'packages/meshbay-hub')
| -rw-r--r-- | packages/meshbay-hub/tests/test_android_shell.py | 14 |
1 files changed, 14 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_android_shell.py b/packages/meshbay-hub/tests/test_android_shell.py index 7b2e79f..2990e9b 100644 --- a/packages/meshbay-hub/tests/test_android_shell.py +++ b/packages/meshbay-hub/tests/test_android_shell.py @@ -260,6 +260,20 @@ def test_a_release_is_signed_with_the_release_key_or_not_built(): assert not re.search(r'storePassword = "', build) +def test_only_the_personal_profile_is_backed_up(): + """A copy of the application inside a work profile offers no backup, and + nothing reads another profile's data through a cross-profile URI.""" + activity = _read(SRC / "MainActivity.kt") + assert "Profiles.isPersonal(this)" in activity and "const BACKUP = $backups;" in activity + shim = _strip_js_comments(_read(SHIM)) + gated = shim.split("...(BACKUP ? {", 1)[1].split("} : {}),", 1)[0] + for name in ("photoSync:", "phoneSync:", "contactSync:"): + assert name in gated, name + for path in [*(SRC / "phonesync").rglob("*.kt"), *(SRC / "photos").rglob("*.kt"), + *(APP / "src" / "full").rglob("*.kt")]: + assert not re.search(r"\.ENTERPRISE_\w+", _read(path)), path.name + + def test_the_play_build_cannot_read_text_messages(): """Play's policy keeps READ_SMS for the default SMS application: the Play build has neither the permission nor the code that reads messages.""" |