From 4f73b6679221c8543f2548ead4f133af9f75d1a1 Mon Sep 17 00:00:00 2001
From: LeanBitLab <245915690+LeanBitLab@users.noreply.github.com>
Date: Mon, 5 Oct 2026 15:46:49 +0000
Subject: [PATCH] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Sentinel:=20[security?=
=?UTF-8?q?=20improvement]=20Disable=20app=20backups=20and=20cleartext=20t?=
=?UTF-8?q?raffic?=
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Disabled `allowBackup` and set `usesCleartextTraffic="false"` in `AndroidManifest.xml` to prevent extraction of OAuth tokens and sensitive caches via adb/Drive backups, and to protect against MITM attacks. Cleaned up ambiguous `Role` imports in `MinimalButton.kt` and fixed API level lint errors for `themes.xml`.
---
.jules/sentinel.md | 4 ++++
app/src/main/AndroidManifest.xml | 4 +++-
.../reddittube/ui/main/components/MinimalButton.kt | 1 -
app/src/main/res/values-v27/themes.xml | 11 +++++++++++
app/src/main/res/values/themes.xml | 3 +--
5 files changed, 19 insertions(+), 4 deletions(-)
create mode 100644 app/src/main/res/values-v27/themes.xml
diff --git a/.jules/sentinel.md b/.jules/sentinel.md
index dcfee25..c4108fe 100644
--- a/.jules/sentinel.md
+++ b/.jules/sentinel.md
@@ -2,3 +2,7 @@
**Vulnerability:** OAuth state parameter used a predictable `System.currentTimeMillis()` value, vulnerable to CSRF attacks.
**Learning:** Always use a cryptographically secure random value for OAuth state parameter and persist it across process boundaries using shared preferences or similar mechanisms to verify during the callback.
**Prevention:** Follow OAuth 2.0 security guidelines and utilize `java.security.SecureRandom` or UUIDs to generate state parameters, ensuring they are verified in the callback process.
+## 2024-05-31 - [Android Manifest Security Baseline]
+**Vulnerability:** Weak default Android application security settings (`allowBackup="true"` implicitly allowed, `usesCleartextTraffic` implicitly allowed on older APIs).
+**Learning:** The application was vulnerable to data extraction (including sensitive OAuth tokens) via adb backup and Man-In-The-Middle (MITM) attacks for unencrypted traffic.
+**Prevention:** Explicitly set `android:allowBackup="false"` and `android:usesCleartextTraffic="false"` in `AndroidManifest.xml` unless there is a specific, well-justified reason to enable them.
diff --git a/app/src/main/AndroidManifest.xml b/app/src/main/AndroidManifest.xml
index f481980..6eb1b3a 100644
--- a/app/src/main/AndroidManifest.xml
+++ b/app/src/main/AndroidManifest.xml
@@ -3,9 +3,11 @@
+
+
+
+
+
\ No newline at end of file
diff --git a/app/src/main/res/values/themes.xml b/app/src/main/res/values/themes.xml
index 5dbee4f..09278c7 100644
--- a/app/src/main/res/values/themes.xml
+++ b/app/src/main/res/values/themes.xml
@@ -6,6 +6,5 @@
- @android:color/black
- @android:color/black
- false
- - false
-
\ No newline at end of file
+