89 lines
4.2 KiB
XML
89 lines
4.2 KiB
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<!-- CalDAV sync and UnifiedPush; everything here needs the network. -->
|
|
<manifest xmlns:android="http://schemas.android.com/apk/res/android">
|
|
|
|
<!-- CalDAV sync. ACCESS_NETWORK_STATE is merged in by work-runtime anyway,
|
|
but it shows in F-Droid's permission diff, so declare it deliberately
|
|
rather than letting it appear from nowhere.
|
|
|
|
READ_SYNC_SETTINGS / WRITE_SYNC_SETTINGS are what the ContentResolver
|
|
sync APIs need. No FOREGROUND_SERVICE: sync is a plain worker, and the
|
|
dataSync FGS type would bring the Android 15 six-hours-per-24 budget
|
|
(whose failure mode is a fatal RemoteServiceException) and a Play
|
|
requirement for a video demo.
|
|
|
|
Two more permissions appear in the merged manifest without being
|
|
declared here, and both come from work-runtime: WAKE_LOCK, and
|
|
FOREGROUND_SERVICE. The latter is not us taking the FGS route — below
|
|
API 31 WorkManager implements expedited work with a foreground service,
|
|
and minSdk is 29, so it is load-bearing for the "Sync now" button.
|
|
Removing it with tools:node="remove" would break expedited work on
|
|
exactly the older devices that need it most. Noted because it shows in
|
|
F-Droid's permission diff and would otherwise look unexplained. -->
|
|
<uses-permission android:name="android.permission.INTERNET" />
|
|
<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />
|
|
<uses-permission android:name="android.permission.READ_SYNC_SETTINGS" />
|
|
<uses-permission android:name="android.permission.WRITE_SYNC_SETTINGS" />
|
|
|
|
<queries>
|
|
<!-- Custom Tabs provider detection. Without this entry it silently finds
|
|
nothing on API 30+, and the Nextcloud login flow falls back to an
|
|
external browser for no visible reason. -->
|
|
<intent>
|
|
<action android:name="android.support.customtabs.action.CustomTabsService" />
|
|
</intent>
|
|
</queries>
|
|
|
|
<application android:networkSecurityConfig="@xml/network_security_config">
|
|
|
|
<!-- Sync plumbing. The stub provider exists only to give the sync
|
|
adapter an authority to register against: Agendula publishes no real
|
|
ContentProvider since :provider was deleted, and without an authority
|
|
ContentService.hasAuthorityAccess() makes every ContentResolver sync
|
|
call a silent no-op at targetSdk >= 34. -->
|
|
<provider
|
|
android:name=".data.sync.SyncStubProvider"
|
|
android:authorities="${applicationId}.sync"
|
|
android:exported="false"
|
|
android:syncable="true" />
|
|
|
|
<!-- Exported and guarded by ACCOUNT_MANAGER. Note that
|
|
android.permission.ACCOUNT_AUTHENTICATOR does not exist. -->
|
|
<service
|
|
android:name=".data.sync.AuthenticatorService"
|
|
android:exported="true"
|
|
android:permission="android.permission.ACCOUNT_MANAGER">
|
|
<intent-filter>
|
|
<action android:name="android.accounts.AccountAuthenticator" />
|
|
</intent-filter>
|
|
<meta-data
|
|
android:name="android.accounts.AccountAuthenticator"
|
|
android:resource="@xml/authenticator" />
|
|
</service>
|
|
|
|
<service
|
|
android:name=".data.sync.SyncAdapterService"
|
|
android:exported="true"
|
|
android:permission="android.permission.BIND_SYNC_ADAPTER">
|
|
<intent-filter>
|
|
<action android:name="android.content.SyncAdapter" />
|
|
</intent-filter>
|
|
<meta-data
|
|
android:name="android.content.SyncAdapter"
|
|
android:resource="@xml/sync_adapter" />
|
|
</service>
|
|
|
|
<!-- UnifiedPush: the connector binds this to deliver endpoints and
|
|
WebDAV-Push messages. Not exported; the connector's own receiver is
|
|
what distributors talk to. -->
|
|
<service
|
|
android:name=".data.sync.push.AgendulaPushService"
|
|
android:exported="false">
|
|
<intent-filter>
|
|
<action android:name="org.unifiedpush.android.connector.PUSH_EVENT" />
|
|
</intent-filter>
|
|
</service>
|
|
</application>
|
|
|
|
</manifest>
|