Files
agendula/app/src/full/res/xml/network_security_config.xml
T

35 lines
1.7 KiB
XML

<?xml version="1.0" encoding="utf-8"?>
<!--
Since Android 7 a user who correctly installs their private CA into the
system store is *still* not trusted by apps — user CAs are excluded from the
default trust anchors. That breaks exactly the self-hosting audience this app
is for, so they are added back here.
Cleartext stays off. It has been the default since API 28, and CalDavDiscovery
refuses a typed http:// address for the same reason: credentials are never
sent over an unencrypted connection. Any escape hatch has to be a narrow,
warned, per-account opt-in — Play's User Data policy requires modern
cryptography in transit — and this file is not the place for it.
⚠️ KNOWN TRADE-OFF, and it is the widest form of this. base-config applies to
*all* traffic, so any CA in the user store — a corporate MDM profile, a "free
VPN" app's certificate, one installed during some earlier debugging — can
transparently intercept the CalDAV connection and read the app password out
of the Authorization header. Without this file
a correctly installed private CA is simply not trusted, which is the
self-hosting case the app exists to serve.
The narrower posture is cert4android's: trust nothing extra by default, and
ask the user per connection via its bound service + notification. That is
what should replace this block rather than
sit alongside it.
-->
<network-security-config>
<base-config cleartextTrafficPermitted="false">
<trust-anchors>
<certificates src="system" />
<certificates src="user" />
</trust-anchors>
</base-config>
</network-security-config>