#!/bin/sh set -eu ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) manifest="$ROOT/android/app/src/main/AndroidManifest.xml" english_strings="$ROOT/android/app/src/main/res/values/strings.xml" russian_strings="$ROOT/android/app/src/main/res/values-ru/strings.xml" ukrainian_strings="$ROOT/android/app/src/main/res/values-uk/strings.xml" english_listing="$ROOT/android/play-store/store-listing-en-US.md" russian_listing="$ROOT/android/play-store/store-listing-ru-RU.md" ukrainian_listing="$ROOT/android/play-store/store-listing-uk-UA.md" declaration="$ROOT/android/play-store/location-and-fgs-declaration.md" require_literal() { file=$1 value=$2 description=$3 if ! grep -Fq "$value" "$file"; then echo "Android Play policy check failed: $description" >&2 echo "Missing from ${file#"$ROOT/"}: $value" >&2 exit 1 fi } for permission in \ android.permission.ACCESS_COARSE_LOCATION \ android.permission.ACCESS_FINE_LOCATION \ android.permission.USE_LOCATION_BUTTON \ android.permission.FOREGROUND_SERVICE \ android.permission.FOREGROUND_SERVICE_LOCATION; do require_literal \ "$manifest" \ "android:name=\"$permission\"" \ "the manifest no longer declares $permission" done require_literal \ "$manifest" \ 'android:name=".TrackingService"' \ 'the native live-location service is missing' require_literal \ "$manifest" \ 'android:foregroundServiceType="location"' \ 'TrackingService is not declared as a location foreground service' for route in \ 'android:path="/requests"' \ 'android:pathPrefix="/requests/"' \ 'android:path="/activities"' \ 'android:pathPrefix="/activities/"' \ 'android:path="/users/log-in"' \ 'android:path="/safety"'; do require_literal "$manifest" "$route" \ "the verified App Link allowlist is missing $route" done if grep -Fq 'android:pathPrefix="/auth' "$manifest" || grep -Fq 'android:path="/auth' "$manifest"; then echo "Android Play policy check failed: browser authentication callbacks are claimed as App Links." >&2 exit 1 fi if grep -Fq 'android.permission.ACCESS_BACKGROUND_LOCATION' "$manifest"; then echo "Android Play policy check failed: ACCESS_BACKGROUND_LOCATION was added." >&2 echo "The reviewed flow starts a user-visible location foreground service from the foreground; adding background permission requires a new policy and product review." >&2 exit 1 fi if grep -Fq 'onlyForLocationButton' "$manifest"; then echo "Android Play policy check failed: onlyForLocationButton is incompatible with the separate live-location foreground-service flow." >&2 exit 1 fi for strings in "$english_strings" "$russian_strings" "$ukrainian_strings"; do require_literal "$strings" 'name="tracking_disclosure_title"' \ 'a locale is missing the live-location disclosure title' require_literal "$strings" 'name="tracking_disclosure_detail"' \ 'a locale is missing the live-location disclosure detail' require_literal "$strings" 'name="tracking_disclosure_continue"' \ 'a locale is missing the affirmative live-location action' require_literal "$strings" 'name="tracking_stop_action"' \ 'a locale is missing the persistent-notification Stop action' done for phrase in \ 'collects and sends your precise location' \ 'matched requester or helper' \ 'background when the app is minimized or not in use' \ 'persistent notification remains visible' \ 'current raw position is then deleted'; do require_literal "$english_strings" "$phrase" \ "the English prominent disclosure no longer states: $phrase" done require_literal "$english_listing" 'including in the background while the app is minimized or not in use' \ 'the English store listing no longer discloses minimized-app location sharing' require_literal "$russian_listing" 'в том числе в фоновом режиме' \ 'the Russian store listing no longer discloses background location sharing' require_literal "$ukrainian_listing" 'зокрема у фоновому режимі' \ 'the Ukrainian store listing no longer discloses background location sharing' # These are literal Markdown fragments; the backticks are not shell syntax. # shellcheck disable=SC2016 for phrase in \ 'Foreground service type: `location`' \ 'does not request `ACCESS_BACKGROUND_LOCATION`' \ 'User-initiated location sharing' \ 'Persistent notification' \ 'Video evidence script'; do require_literal "$declaration" "$phrase" \ "the Play Console declaration guide is incomplete: $phrase" done echo "Android Play location/foreground-service policy contract passed."