Implements the verifiable pure-Kotlin core of the Android client per
docs/ANDROID_CLIENT_PLAN.md, mirroring the iOS SPM package set as Gradle modules.
Built + reviewed via multi-agent workflow (explore→implement→verify→review),
then review findings fixed with regression tests.
Modules (all pure JVM, kotlin("jvm"); Android-framework modules scaffolded but
gated off in settings — no Android SDK in this env):
- :wire-protocol — frozen wire contract (sealed Client/ServerMessage, enums,
HostEndpoint CSWSH origin derivation, transport interfaces), hand-rolled codec
byte-identical to the server's JSON.stringify + tolerant kotlinx decode.
- :session-core — ReconnectMachine (1→2→4→8→16→30 backoff), PingScheduler,
GateTracker (two-line epoch guard), AwayDigest, UnreadLedger, TitleSanitizer,
KeyByteMap (byte-matches public/keybar.ts).
- :api-client — all REST routes, tolerant decode, Origin-iff-guarded, prefs
unknown-key preservation, pairing probe + host-tier classifier.
- :client-tls — pure half: PKCS#12 parse, X509KeyManager alias logic,
CertificateSummary, provider-agnostic wrong-passphrase classification.
- :test-support — FakeTransport / FakeHttpTransport / virtual-clock fakes.
Verify: ./gradlew clean test → 218 tests, 0 failures (wire-protocol 47,
session-core 60, api-client 69, client-tls 27, test-support 15).
Review (3 lenses, 8/10 each) findings fixed: sessionId JSON-injection escape,
CancellationException propagation in PingScheduler, PairingProbe close-on-cancel
leak, HostEndpoint trim, HostClassifier hoisted to :wire-protocol (type unified),
BouncyCastle-portable wrong-passphrase detection, lone-surrogate escaping.
Known gap (documented, deferred): /push/fcm-token has no server route yet —
plan task A33 (src/push/fcm.ts) delivers it.
31 lines
1.3 KiB
Plaintext
31 lines
1.3 KiB
Plaintext
// ─────────────────────────────────────────────────────────────────────────────
|
|
// :client-tls-android — the FRAMEWORK half of ClientTLS: AndroidKeyStore import
|
|
// (device-bound, non-exportable key), Tink AEAD cert-chain-at-rest storage, and
|
|
// connectionPool.evictAll() on rotation. Tested instrumented on a real device.
|
|
// Depends on the pure :client-tls module for the parse/selection logic.
|
|
//
|
|
// SCAFFOLD STUB ONLY — COMMENTED OUT in settings.gradle.kts (no Android SDK here).
|
|
// TODO(android-sdk): enable when an Android SDK is available.
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
/*
|
|
plugins {
|
|
id("com.android.library")
|
|
alias(libs.plugins.kotlin.android)
|
|
}
|
|
|
|
android {
|
|
namespace = "wang.yaojia.webterm.tlsandroid"
|
|
compileSdk = 35
|
|
defaultConfig { minSdk = 29 }
|
|
}
|
|
|
|
kotlin { jvmToolchain(17) }
|
|
|
|
dependencies {
|
|
api(project(":client-tls"))
|
|
implementation(project(":wire-protocol"))
|
|
// implementation("com.google.crypto.tink:tink-android:1.15.0")
|
|
}
|
|
*/
|