From 4f73b6679221c8543f2548ead4f133af9f75d1a1 Mon Sep 17 00:00:00 2001 From: LeanBitLab <245915690+LeanBitLab@users.noreply.github.com> Date: Mon, 5 Oct 2026 15:46:49 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Sentinel:=20[security?= =?UTF-8?q?=20improvement]=20Disable=20app=20backups=20and=20cleartext=20t?= =?UTF-8?q?raffic?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Disabled `allowBackup` and set `usesCleartextTraffic="false"` in `AndroidManifest.xml` to prevent extraction of OAuth tokens and sensitive caches via adb/Drive backups, and to protect against MITM attacks. Cleaned up ambiguous `Role` imports in `MinimalButton.kt` and fixed API level lint errors for `themes.xml`. --- .jules/sentinel.md | 4 ++++ app/src/main/AndroidManifest.xml | 4 +++- .../reddittube/ui/main/components/MinimalButton.kt | 1 - app/src/main/res/values-v27/themes.xml | 11 +++++++++++ app/src/main/res/values/themes.xml | 3 +-- 5 files changed, 19 insertions(+), 4 deletions(-) create mode 100644 app/src/main/res/values-v27/themes.xml diff --git a/.jules/sentinel.md b/.jules/sentinel.md index dcfee25..c4108fe 100644 --- a/.jules/sentinel.md +++ b/.jules/sentinel.md @@ -2,3 +2,7 @@ **Vulnerability:** OAuth state parameter used a predictable `System.currentTimeMillis()` value, vulnerable to CSRF attacks. **Learning:** Always use a cryptographically secure random value for OAuth state parameter and persist it across process boundaries using shared preferences or similar mechanisms to verify during the callback. **Prevention:** Follow OAuth 2.0 security guidelines and utilize `java.security.SecureRandom` or UUIDs to generate state parameters, ensuring they are verified in the callback process. +## 2024-05-31 - [Android Manifest Security Baseline] +**Vulnerability:** Weak default Android application security settings (`allowBackup="true"` implicitly allowed, `usesCleartextTraffic` implicitly allowed on older APIs). +**Learning:** The application was vulnerable to data extraction (including sensitive OAuth tokens) via adb backup and Man-In-The-Middle (MITM) attacks for unencrypted traffic. +**Prevention:** Explicitly set `android:allowBackup="false"` and `android:usesCleartextTraffic="false"` in `AndroidManifest.xml` unless there is a specific, well-justified reason to enable them. diff --git a/app/src/main/AndroidManifest.xml b/app/src/main/AndroidManifest.xml index f481980..6eb1b3a 100644 --- a/app/src/main/AndroidManifest.xml +++ b/app/src/main/AndroidManifest.xml @@ -3,9 +3,11 @@ + + + + + \ No newline at end of file diff --git a/app/src/main/res/values/themes.xml b/app/src/main/res/values/themes.xml index 5dbee4f..09278c7 100644 --- a/app/src/main/res/values/themes.xml +++ b/app/src/main/res/values/themes.xml @@ -6,6 +6,5 @@ @android:color/black @android:color/black false - false - \ No newline at end of file +