* refactor: implement custom ExpoImage wrapper for cache control
Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app
* refactor(ios): convert Gekidou to CocoaPods
Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0
* npm audit
* update fastlane
* feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection
Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository
* fix tests by mocking @mattermost/intune
* feat: implement Intune MAM integration with comprehensive security enforcement
Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls
* fix alerts when no server database is present
* Unify cache strategy
* fix emit config changed after it was stored in the db
* Handle Mid-Session Enrollment Detection
* fix ADALLogOverrideDisabled missing in Fastfile
* fix flow for initial enrollment
* fix and add unit tests
* enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release
* Update intune submodule with addressed feedback
* fix validate-intune-clean workflow
* feat(intune): add comprehensive error handling and SAML+Entra support
Add production-ready error handling for native Entra authentication with
user-friendly i18n messages, comprehensive test coverage, and support for
Entra login when server requires SAML.
* update i18n
* update intune submodule
* update build-pr token
* fix race condition between server auth and intune enrollment
* fix CI workflow to build with intune
* use deploy key for intune submodule
* set the config directly in the submodule .git
* debug injection
* try setting GIT_SSH_COMMAND
* remove action debug
* fix server url input
* match pod cache with intune hash
* Fastfile and envs
* have workflows check for intune/.git
* have ci cache intune frameworks as well
* update Fastlane to set no-cache to artifacts uploaded
* fix s3 upload
* fix pblist template
* Attempt to remove the cache control for PR uploads to s3
* use hash from commit for S3 path
* Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain
* Fix surface errors from intune login
* fix postinstall scripts
* use cacheKey for draft md images
* remove unnecessary double await during test
* Have isMinimumLicenseTier accept valid license sku tier as target
* Add missing Auth error messages
* remove the last period for intune errors in i18n
* do not call unenroll with wipe on manual logout
* Fix tests and Intune error messages
* do not filter any SSO type regardless of which is used for Intune
* fix 412 to not retry
* fix tests, app logs sharing and share_extension avatar cache
* apply setScreenCapturePolicy on license change
Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
* re-apply screen capture on enrollment
Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
* use userData from intunr login and prevent getMe
Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
* Check for Biometrics and Jailbreak as we used to
---------
Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
* Mobile fix for MM-65084
* Changing test/setup.ts to use a deterministic fill
This avoids the ci issue about parenthesis and is more clear that this is just a fixed sequence for testing, similar to randomUUID above.
* Add setBearerToken and setCSRFToken to Client definition
* Use setClientCredentials and memoize createPkceBundle
* Restoring the preauthSecret back to the Client constructors
This came out of a response to MM-65085: Support Pre Shared Password on server connect where preauthSecret was added in the buildConfig. Claude (correctly imo) identified this as now redundant and so removed it but it is valid to keep it as well. In any case, putting it back to be consistent with ClientTracking and ClientBase.
* Rename PKCE to SAML based terminology, similar to server
* Fix lint issue with too many blank lines at eof
* Removing plain on mobile side
---------
Co-authored-by: Mattermost Build <build@mattermost.com>
* Add watchman watch-del-all to clean script
This ensures watchman watches are reset during cleanup, preventing issues after upgrades.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Use watchman watch-del instead of watch-del-all
Only reset watches for the current project directory instead of all watches.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
* remove some test
* clean error
* use has_coverage_from_main
* revert sentry.test.ts
* remove use of github_token
* trying github.token instead
* see if permissions write will solve the Resource not accessible problem
* would github-token help solve that problem?
* see if permissions on the workflow itself would fix the problem
* trying pull_request_target
* add branches to pull request target
* remove branches for now.
* changed to the proper event_name
* check if it's forked repo.
* using is_fork
* ci(MM-63199): code coverage tracking
* try to download existing coverage file
* read coverage
* add token
* use github.token instead
* passing github token
* github_token passing from workflow
* remove download
* re-add download
* wrong param
* try download all artifacts
* add run-id so to retrieve with download later
* remove read coverage temp
* use run-id to download
* put files into current-coverage
* using last run id
* temporary comment
* can retrieve last run id?
* remove hard-coding
* echo into github_env vs export
* comparing new and old
* comparison improvement
* post to github
* fix coverage text
* refactor to main from current-coverage
* formatting changes
* fix missing content
* small tweaking
* showing the Warning to make sure
* formatting
* remove +
* checking to see if the error shows via echo
* revert the change to error
* separate to a new file
* comment the actual test for now
* prep node deps
* only run certain things on main
* trying cache-hit
* real trying cache-hit
* testing to make sure cache-run-id runs
* save-always true
* save-always deprecated
* let's try different strategy
* add key
* restore-key adding a -
* only perform on `main`
* only run on main or if its a PR
* coverage_threshold
* remove comments
* add total
* removing unneeded comments
* calculate total
* run test in `release-*` only
* making sure that only PR will run
* only do more steps if upload-coverage successful
* trying thollander/actions-comment-pull-request
* using diff way to comment.
* comment on how things work
* testing to trigger warning and see if comment is updated vs new comment
* omit echo messages
* see if giving github token would work.
* wrong use of param
* try without github token
* adding a very simple change to see where it lands
* using cache hit instead.
* creating the cache again. how did i lose it?
* revert back
* cache-hit might be off
* debug
* debug with failing cache restoration
* check for run-id.txt instead
* all into action
* missing "
* remove unneeded actions
* change threshold to 0.5
* relative time
* skeptical about date formatting
* revert back to the threshold trigger
* below 80% total coverage threshold
* only show one error/warning at time.
* testing if the coverage drop below 80
* debug output
* add Reset Test Coverage label use
* try using contains vs direct comparsion
* remove the label checker
* temp change
* ooops
* revert back
* let's post before exiting
* consistency
* total coverage threshold reset to 80%
* experimental github action
* start mtmproxy then kill it
* suspend test for now
* dont need to be in a PR to trigger
* trying again with mitmdump
* where is .mitmproxy folder?
* run with +e
* not sure why exit code 1
* if this is a better path
* let's try killing using trap?
* trying a different path
* maybe using ~ would work?
* looking at output to networksetup command
* minor mistake
* throttling bandwidth
* lets try with sudo
* missing sudo
* using mitmdump
* remove spaces
* tried diff path
* change to the proper file
* upload artifacts
* install cert
* added cert to simulator
* getting simulator UDID
* proper scoped var
* using github outputs
* getenv doesn't have IOS_SIMULATOR_UDID
* using echo command
* maybe forgot to scope outputs
* lets run the command directly
* changed to iPhone 14
* let me see all the devices
* try something new
* rearrange my steps to get cert
* getenv booted
* remove too many outputs
* using mm mobile test server
* tie it all together with detox test
* removed dependency for another job
* put dependency on a job
* simplify process even more
* add github-token on download artifact
* add run-id, hopefully that's what needed to download
* incorrect speed for download
* update to the correct dummynet syntax
* proper mitmdump flow report
* update allow-hosts
* commenting out mitmdump for now
* back to rahim-experiments
* overly commented out
* cacert not --ca-cert
* maybe i allow the wrong host?
* maybe i just forgotr to kill mitmdump after I'm done?
* using pm2
* reinstate jobs. and longer timeout for detox
* need sudo
* recording videos and limiting to 1 test
* just want to run 1 test.
* back to experimenting
* using wget
* test using chrome
* using chrome and add delay
* ok test again with detox
* go back to testing all server_login
* compare booted simulators
* few more experiments
* no \
* using github_outputs
* using fromJSON
* too many $
* can i do this another way?
* two runs to get the it assigned
* try again
* .
* trying to access devices array
* try again
* using jq
* keep it simple
* might not need outputs
* forgot pipe
* will this work?
* will first element of an array works
* see if we got the udid
* did we get it wrong?
* will this work?
* let's assign?
* we have to put into string
* ok 1 more
* will it have quotes?
* echo in an echo
* is this working?
* let's hope this works.
* it's actually using 17.4 iPhone 14 not 17.0
* broke because i add &
* removed failed step
* lowering ping and going back to 10 parallel test
* double-up ONE_SEC to see if tests will pass
* why curl failed after?
* getting more data from failures
* let's get more logs with pm and mitmdump
* more logging and improvement
* silly error!
* problem with throttling, let's figure out where we can improve
* increase timeout for low-bandwidth
* increased delay + run all tests
* lets see if this will be better for throttling
* try set +e to see if it will return failure
* check disk space.
* deleting zip and trash to free up space.
* try to do pfctl twice to see if that would help
* making bandwidth-throttling a composite action
* would 5 seconds make a diff?
* add shell
* throttle bandwidth experiment
* fix quick problem
* 5s sleep, and throttling at the right time
* the throttling was working better earlier.
* add a flush in between
* no exit, see if it works well
* trying continue-on-error
* resetting with continue-on-error vs checking for if steps before worked
* adding flush before throttling to see if it makes a diff
* put it back where we think is the best spot
* change timeout to 60 and some cleanup
* forgot a simple $
* move network throttling again to see if this is better?
* rearranging
* move throttling back to where it used to work well
making bandwidth-throttling action taking inputs
* forgot shell
* inputs not input, and continue-on-error
* getting host from site_1_url
* update the sed script
* move more steps into composite action file
* add shell
* add more shell
* action cleanup
* see if our reset network setting works
* delete unused files
* more clean up
* wrong indentation
* wrong context
* see if not having low bandwidth enabled would cause stuff to break
* will it fail on non-existent step name?
* things are failing after proxy started
* start using low_bandwidth_mode input
* incorrect use of curly bracket
* low_bandwidth_mode vs low_bandwidth
* correcting the use of curly bracket in if check
* low_bandwidth_mode correction
* why would https:// makes a diff?
* just going to start pm2 after stopping
* move things around again
* some more re-arranging
* exit 1
* rearranged too much
* clean up
* start-proxy action
* incorrect variable name
* use test_server_url instead
* reverting back to original
* use pull_request
* using env var prepend
* using existing artifact
* not in ""
* not going to prepend anymore
* incorrectly removed input instead of env
* close to final
* using original e2e-detox-template
* timeout-minutes need to be higher for low_bandwidth.
* using label instead of push to branch
* add check-label
* remove unneeded test
* renamed ci.yml back to original
* different way to remove label
remove experiment files
reinstate ci.yml
* remove experiment file
* see label again
* output labels
* another experiment
* test again
* fix issue when checking for low bandwidth
* revert changes to package.json in detox/
* changed download to upload in the description
* changes based on review
* add github.event.label.name to the group "id" per @mvitale1989 suggestion
---------
Co-authored-by: Mattermost Build <build@mattermost.com>
* notification ringing, settings screen, native code patch, ringing mp3s
* i18n
* play preview on first press
* prevent playing from background (only affects Android) to match iOS beh
* stop ringing/vibration on entering background
* ring when coming back from background and new incoming call is present
* no push notification sound when it's a call; improve ringing
* move sounds to asset folder; copy on postinstall for android bundling
* make Ringtone type a string enum
* make Android ring async + await ring and stop; changes from PR comments
* missing fields after merge
* release lock on an exception
* cancel sample ringing when turning notifications off
* copy sound files for android build
* typo
* update snapshots
* testing if the problem is copying the mp3 files
* fix android mp3 assets when building for non-release
* add sounds to .gitignore
---------
Co-authored-by: Mattermost Build <build@mattermost.com>
Co-authored-by: Elias Nahum <nahumhbl@gmail.com>