aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-android/README.md
blob: 68f6dadfb03be6e32cbd0053f8a660f073e379ab (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
# MeshBay — Android client

A client, not a host: no node runs on a phone (`docs/MESHBAY_DESIGN.md` §11.3).

The shell is a system WebView showing the interface **from the package** —
`meshbay-hub/src/meshbay_hub/static/` copied at build time into
`build/generated/`, never committed (§8.3) — with a bridge
(`app/src/main/assets/bridge/meshbay-bridge.js`) that offers the page the same
`window.meshbay` as the desktop preload, wherever it offers anything at all.
Hub calls leave from native code, to the signed-in hub only. The device key,
the bundle key and every node identity are held natively under an Android
Keystore key; the page is told public keys and handed signatures, asked for by
kind — never bytes. `meshbay-hub/tests/vectors/keyring.json` holds that keyring
to the desktop's and to the specification.

Downloads are written to disk as they arrive — into the folder chosen in
Settings (a Storage Access Framework tree, as `<name>.part` until complete) or
the system Downloads collection (a pending entry until complete) — and the
page holds an opaque id, never a URI. Uploads come through the system picker.

Casting: the page pushes the decrypted stream to a local HTTP relay (a port of
the desktop's `cast-relay.js`, bound to the Wi-Fi address only); receivers are
found and driven through the platform cast SDK with the default media receiver.
While a cast runs, a media-playback foreground service holds the CPU and the
Wi-Fi, and the WebView is kept reported visible — without that, Chromium
freezes the page 60 s after the screen goes off. Where play services are
absent, the page is offered no cast at all.

```bash
# needs JDK 17+ and an Android SDK (ANDROID_HOME, or sdk.dir in local.properties)
./gradlew assembleDebug        # app/build/outputs/apk/debug/app-debug.apk
./gradlew testDebugUnitTest    # JVM unit tests
```

The security contract is also pinned from the Python suite by reading this
source: `packages/meshbay-hub/tests/test_android_shell.py`.

Not built yet: phone-specific behaviour (back button, network handover,
keeping a download alive with the screen off), signed releases.