From be8b7fcff56a1104e7cd974cc0f506d90f1299a8 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Sat, 10 Oct 2026 14:41:02 +0200 Subject: feat(android): back up the personal profile only A copy of the application inside a work profile offers no backup, and no source reads another profile. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/tests/test_android_shell.py | 14 ++++++++++++++ 1 file changed, 14 insertions(+) (limited to 'packages/meshbay-hub/tests/test_android_shell.py') diff --git a/packages/meshbay-hub/tests/test_android_shell.py b/packages/meshbay-hub/tests/test_android_shell.py index 7b2e79f..2990e9b 100644 --- a/packages/meshbay-hub/tests/test_android_shell.py +++ b/packages/meshbay-hub/tests/test_android_shell.py @@ -260,6 +260,20 @@ def test_a_release_is_signed_with_the_release_key_or_not_built(): assert not re.search(r'storePassword = "', build) +def test_only_the_personal_profile_is_backed_up(): + """A copy of the application inside a work profile offers no backup, and + nothing reads another profile's data through a cross-profile URI.""" + activity = _read(SRC / "MainActivity.kt") + assert "Profiles.isPersonal(this)" in activity and "const BACKUP = $backups;" in activity + shim = _strip_js_comments(_read(SHIM)) + gated = shim.split("...(BACKUP ? {", 1)[1].split("} : {}),", 1)[0] + for name in ("photoSync:", "phoneSync:", "contactSync:"): + assert name in gated, name + for path in [*(SRC / "phonesync").rglob("*.kt"), *(SRC / "photos").rglob("*.kt"), + *(APP / "src" / "full").rglob("*.kt")]: + assert not re.search(r"\.ENTERPRISE_\w+", _read(path)), path.name + + def test_the_play_build_cannot_read_text_messages(): """Play's policy keeps READ_SMS for the default SMS application: the Play build has neither the permission nor the code that reads messages.""" -- cgit v1.2.3