test(android): verify development App Links

This commit is contained in:
SimpleTest 2026-07-24 02:10:54 +03:00
parent 17478f6303
commit 89851097fd
2 changed files with 41 additions and 14 deletions

View File

@ -1419,7 +1419,10 @@ None of the observations below describe the current delivery path.
main-frame loads, asserted both DOMs, rejected an unrelated HTTPS origin, main-frame loads, asserted both DOMs, rejected an unrelated HTTPS origin,
found no load/TLS error, and captured the rendered phone screenshots. found no load/TLS error, and captured the rendered phone screenshots.
Evidence is retained at Evidence is retained at
`output/android-development-smoke/20260723225620-2568739`. Its run-scoped `output/android-development-smoke/20260723230559-2828624`. The Android 17
verifier reported the development host as `verified`; a real implicit
`/safety` intent cold-started `org.whoneedhelp.mobile.development`, while an
unrelated HTTPS origin remained assigned to Chrome. Its run-scoped
container, AVD volume, and image were all absent after cleanup. container, AVD volume, and image were all absent after cleanup.
- This replay exposed and fixed two stale checks rather than treating a build as - This replay exposed and fixed two stale checks rather than treating a build as
runtime proof. Development/staging APKs deliberately have Android debugging runtime proof. Development/staging APKs deliberately have Android debugging
@ -1478,14 +1481,12 @@ None of the observations below describe the current delivery path.
publishes environment-specific `/.well-known/assetlinks.json`. The online publishes environment-specific `/.well-known/assetlinks.json`. The online
development response now agrees with development response now agrees with
`org.whoneedhelp.mobile.development` and its signed certificate, and the `org.whoneedhelp.mobile.development` and its signed certificate, and the
explicit same-origin deep link rendered in the API 37 smoke. Android still verified implicit same-origin App Link rendered in the API 37 smoke. Before
reported the fresh emulator's domain-verification state as `none`, so a a Play release, register the application, add the Play App Signing
verified implicit App Link has not yet been observed on a device. Before a certificate fingerprint alongside any sideload/upload fingerprint, repeat
Play release, register the application, add the Play App Signing certificate domain verification with that Play certificate, and complete store
fingerprint alongside any sideload/upload fingerprint, repeat Android's policy/release work. A dedicated upload key and signed APK/AAB exist, but no
domain verification on a device, and complete store policy/release work. A Play application has been registered.
dedicated upload key and signed APK/AAB exist, but no Play application has
been registered.
- Operate PostgreSQL/PostGIS with off-site backups, recovery testing, monitoring, - Operate PostgreSQL/PostGIS with off-site backups, recovery testing, monitoring,
and the availability model selected for real usage. and the availability model selected for real usage.
- The development Brevo SMTP transport and sender have completed both an - The development Brevo SMTP transport and sender have completed both an

View File

@ -235,24 +235,49 @@ if grep -Fq 'Authority: "example.com"' "$output/package.txt"; then
exit 1 exit 1
fi fi
docker exec "$container" adb shell cmd package resolve-activity --brief \ docker exec "$container" adb shell pm set-app-links \
--package "$package" 0 all >"$output/app-links-reset.txt"
docker exec "$container" adb shell pm verify-app-links \
--re-verify "$package" >"$output/app-links-reverify.txt"
# Android's official App Links test guidance requires at least 20 seconds after
# installation for the asynchronous domain-verification agent to finish.
sleep 20
docker exec "$container" adb shell pm get-app-links "$package" \
>"$output/app-links.txt"
docker exec "$container" adb shell pm get-app-links --user 0 "$package" \
>"$output/app-links-user.txt"
if ! awk -v host="$expected_host:" '
$1 == host && $2 == "verified" { verified = 1 }
END { exit verified ? 0 : 1 }
' "$output/app-links.txt"; then
echo "Android did not verify the $variant App Link host." >&2
exit 1
fi
docker exec "$container" adb shell am start -W \
-a android.intent.action.VIEW \ -a android.intent.action.VIEW \
-c android.intent.category.BROWSABLE \ -c android.intent.category.BROWSABLE \
-d "$same_origin" >"$output/same-origin-resolver.txt" -d "$same_origin" >"$output/same-origin-app-link-start.txt"
docker exec "$container" adb shell cmd package resolve-activity --brief \ docker exec "$container" adb shell cmd package resolve-activity --brief \
--user 0 \
-a android.intent.action.VIEW \ -a android.intent.action.VIEW \
-c android.intent.category.BROWSABLE \ -c android.intent.category.BROWSABLE \
-d "$external_origin" >"$output/external-origin-resolver.txt" -d "$external_origin" >"$output/external-origin-resolver.txt"
if ! grep -Fq "Activity: $package/$activity" "$output/same-origin-app-link-start.txt"; then
echo "The verified $variant App Link did not open the application." >&2
exit 1
fi
if grep -Fq "$package/" "$output/external-origin-resolver.txt"; then if grep -Fq "$package/" "$output/external-origin-resolver.txt"; then
echo "The $variant APK incorrectly claimed an external HTTPS origin." >&2 echo "The $variant APK incorrectly claimed an external HTTPS origin." >&2
exit 1 exit 1
fi fi
docker exec "$container" adb shell pm get-app-links "$package" \
>"$output/app-links.txt"
docker exec "$container" adb logcat -c docker exec "$container" adb logcat -c
docker exec "$container" adb shell am start -W \ docker exec "$container" adb shell am start -W \
-n "$package/$activity" >"$output/home-start.txt" -n "$package/$activity" >"$output/home-start.txt"
@ -357,6 +382,7 @@ fi
printf 'home_loaded=true\n' printf 'home_loaded=true\n'
printf 'home_dom_assertion=true\n' printf 'home_dom_assertion=true\n'
printf 'same_origin_manifest_filter=true\n' printf 'same_origin_manifest_filter=true\n'
printf 'same_origin_app_link_verified=true\n'
printf 'same_origin_deep_link_loaded=true\n' printf 'same_origin_deep_link_loaded=true\n'
printf 'safety_dom_assertion=true\n' printf 'safety_dom_assertion=true\n'
printf 'external_origin_manifest_filter=false\n' printf 'external_origin_manifest_filter=false\n'