who_need_help/scripts/android-play-policy-check.sh

116 lines
4.5 KiB
Bash
Executable File
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

#!/bin/sh
set -eu
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
manifest="$ROOT/android/app/src/main/AndroidManifest.xml"
english_strings="$ROOT/android/app/src/main/res/values/strings.xml"
russian_strings="$ROOT/android/app/src/main/res/values-ru/strings.xml"
ukrainian_strings="$ROOT/android/app/src/main/res/values-uk/strings.xml"
english_listing="$ROOT/android/play-store/store-listing-en-US.md"
russian_listing="$ROOT/android/play-store/store-listing-ru-RU.md"
ukrainian_listing="$ROOT/android/play-store/store-listing-uk-UA.md"
declaration="$ROOT/android/play-store/location-and-fgs-declaration.md"
require_literal() {
file=$1
value=$2
description=$3
if ! grep -Fq "$value" "$file"; then
echo "Android Play policy check failed: $description" >&2
echo "Missing from ${file#"$ROOT/"}: $value" >&2
exit 1
fi
}
for permission in \
android.permission.ACCESS_COARSE_LOCATION \
android.permission.ACCESS_FINE_LOCATION \
android.permission.USE_LOCATION_BUTTON \
android.permission.FOREGROUND_SERVICE \
android.permission.FOREGROUND_SERVICE_LOCATION; do
require_literal \
"$manifest" \
"android:name=\"$permission\"" \
"the manifest no longer declares $permission"
done
require_literal \
"$manifest" \
'android:name=".TrackingService"' \
'the native live-location service is missing'
require_literal \
"$manifest" \
'android:foregroundServiceType="location"' \
'TrackingService is not declared as a location foreground service'
for route in \
'android:path="/requests"' \
'android:pathPrefix="/requests/"' \
'android:path="/activities"' \
'android:pathPrefix="/activities/"' \
'android:path="/users/log-in"' \
'android:path="/safety"'; do
require_literal "$manifest" "$route" \
"the verified App Link allowlist is missing $route"
done
if grep -Fq 'android:pathPrefix="/auth' "$manifest" ||
grep -Fq 'android:path="/auth' "$manifest"; then
echo "Android Play policy check failed: browser authentication callbacks are claimed as App Links." >&2
exit 1
fi
if grep -Fq 'android.permission.ACCESS_BACKGROUND_LOCATION' "$manifest"; then
echo "Android Play policy check failed: ACCESS_BACKGROUND_LOCATION was added." >&2
echo "The reviewed flow starts a user-visible location foreground service from the foreground; adding background permission requires a new policy and product review." >&2
exit 1
fi
if grep -Fq 'onlyForLocationButton' "$manifest"; then
echo "Android Play policy check failed: onlyForLocationButton is incompatible with the separate live-location foreground-service flow." >&2
exit 1
fi
for strings in "$english_strings" "$russian_strings" "$ukrainian_strings"; do
require_literal "$strings" 'name="tracking_disclosure_title"' \
'a locale is missing the live-location disclosure title'
require_literal "$strings" 'name="tracking_disclosure_detail"' \
'a locale is missing the live-location disclosure detail'
require_literal "$strings" 'name="tracking_disclosure_continue"' \
'a locale is missing the affirmative live-location action'
require_literal "$strings" 'name="tracking_stop_action"' \
'a locale is missing the persistent-notification Stop action'
done
for phrase in \
'collects and sends your precise location' \
'matched requester or helper' \
'background when the app is minimized or not in use' \
'persistent notification remains visible' \
'current raw position is then deleted'; do
require_literal "$english_strings" "$phrase" \
"the English prominent disclosure no longer states: $phrase"
done
require_literal "$english_listing" 'including in the background while the app is minimized or not in use' \
'the English store listing no longer discloses minimized-app location sharing'
require_literal "$russian_listing" 'в том числе в фоновом режиме' \
'the Russian store listing no longer discloses background location sharing'
require_literal "$ukrainian_listing" 'зокрема у фоновому режимі' \
'the Ukrainian store listing no longer discloses background location sharing'
# These are literal Markdown fragments; the backticks are not shell syntax.
# shellcheck disable=SC2016
for phrase in \
'Foreground service type: `location`' \
'does not request `ACCESS_BACKGROUND_LOCATION`' \
'User-initiated location sharing' \
'Persistent notification' \
'Video evidence script'; do
require_literal "$declaration" "$phrase" \
"the Play Console declaration guide is incomplete: $phrase"
done
echo "Android Play location/foreground-service policy contract passed."