Security hardening + code-review fixes

Outcome of a full multi-agent code review. Touches TLS, credential storage,
API versioning, networking correctness, concurrency/lifecycle, and the release
build. See CHANGELOG.md for the full list and the items to port to the iOS app.

Security
- Remove untrusted-TLS support: delete ServerTrustPolicy.AllowSelfSignedForHost
  and its trust-all X509TrustManager; drop the self-signed Settings toggle.
- Enforce HTTPS in normalizedBaseUrl (reject http + embedded credentials);
  add network_security_config (no cleartext, system CAs only) + allowBackup=false.
- Never persist passwords at rest: remember-me stores email only; no password
  pre-fill; clear creds on sign-out / when remember-me is off.
- Match CSRF host lookup to OkHttp's host parsing; stop leaking raw exception text.

Correctness
- Fix API versioning: hardcode v1/v3 per endpoint (docs Sec.4) instead of one
  broken global apiVersion; remove the version plumbing + Settings field.
- Treat "warning" status as success (committed write); fail-fast on a missing
  pagination cursor; close Response on cancellation; tolerant JSON parse; User-Agent.
- Firmware isCompatible fails closed + extra acknowledgment for a non-compatible image.

Concurrency / lifecycle
- Run network I/O on Dispatchers.IO; stale-result generation guards + rethrow
  CancellationException in all loads; host AppState in a ViewModel (survive config
  change); thread-safe cookie jar; reset/upgrade re-entry guard; wire list Retry.

Build
- Enable R8 minify+shrink with kotlinx.serialization keep rules; drop unused
  navigation-compose; add the missing .gitignore.

NOTE: built/verified by static review only (no Android SDK on the dev machine) —
run :app:assembleDebug and a release build before shipping.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jon Vanvik 2026-05-31 17:37:48 +02:00
parent ca3d7d05e0
commit 41098831ae
20 changed files with 505 additions and 191 deletions

View file

@ -20,8 +20,9 @@ compileSdk 36, minSdk 26, JBR 21**.
## What it does (feature parity with iOS)
- **Login / Settings** — URL normalisation (`/api` auto-appended), self-signed
TLS toggle, test-connection probe, remember-me (Android Keystore), sign out.
- **Login / Settings** — HTTPS-only URL normalisation (`/api` auto-appended, `http`
rejected), test-connection probe, remember-me (**email only** — passwords are never
stored, Android Keystore), sign out.
- **Dashboard** — ONU/OLT/controller counts; total OLT traffic; a **Health**
section (abnormal-Rx ONUs, laser-off OLTs) that drills into the affected
devices; ONU-state breakdown; **Detailed stats** (opt-in Rx scan) and
@ -51,4 +52,6 @@ docs/MCMS_API.md the MCMS REST field guide (single source of truth)
```
See [`HANDOFF.md`](HANDOFF.md) for architecture notes, the build/verify loop, the
API gotchas, and what's deliberately trimmed vs iOS.
API gotchas, and what's deliberately trimmed vs iOS. Recent security/correctness
changes — and which of them to bring over to the iOS app — are in
[`CHANGELOG.md`](CHANGELOG.md).