mattermost-mobile/app/screens/gallery/renderers/document/document.tsx
Elias Nahum 44eb76bed7
feat(iOS): Add Microsoft Intune MAM integration with multi-server support (#9312)
* refactor: implement custom ExpoImage wrapper for cache control

Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app

* refactor(ios): convert Gekidou to CocoaPods

Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0

* npm audit

* update fastlane

* feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection

Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository

* fix tests by mocking @mattermost/intune

* feat: implement Intune MAM integration with comprehensive security enforcement

Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls

* fix alerts when no server database is present

* Unify cache strategy

* fix emit config changed after it was stored in the db

* Handle Mid-Session Enrollment Detection

* fix ADALLogOverrideDisabled missing in Fastfile

* fix flow for initial enrollment

* fix and add unit tests

* enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release

* Update intune submodule with addressed feedback

* fix validate-intune-clean workflow

* feat(intune): add comprehensive error handling and SAML+Entra support

Add production-ready error handling for native Entra authentication with
user-friendly i18n messages, comprehensive test coverage, and support for
Entra login when server requires SAML.

* update i18n

* update intune submodule

* update build-pr token

* fix race condition between server auth and intune enrollment

* fix CI workflow to build with intune

* use deploy key for intune submodule

* set the config directly in the submodule .git

* debug injection

* try setting GIT_SSH_COMMAND

* remove action debug

* fix server url input

* match pod cache with intune hash

* Fastfile and envs

* have workflows check for intune/.git

* have ci cache intune frameworks as well

* update Fastlane to set no-cache to artifacts uploaded

* fix s3 upload

* fix pblist template

* Attempt to remove the cache control for PR uploads to s3

* use hash from commit for S3 path

* Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain

* Fix surface errors from intune login

* fix postinstall scripts

* use cacheKey for draft md images

* remove unnecessary double await during test

* Have isMinimumLicenseTier accept valid license sku tier as target

* Add missing Auth error messages

* remove the last period for intune errors in i18n

* do not call unenroll with wipe on manual logout

* Fix tests and Intune error messages

* do not filter any SSO type regardless of which is used for Intune

* fix 412 to not retry

* fix tests, app logs sharing and share_extension avatar cache

* apply setScreenCapturePolicy on license change

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* re-apply screen capture on enrollment

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* use userData from intunr login and prevent getMe

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* Check for Biometrics and Jailbreak as we used to

---------

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
2025-12-10 13:07:28 +02:00

169 lines
6.1 KiB
TypeScript

// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See LICENSE.txt for license information.
import React, {useCallback, useMemo, useState} from 'react';
import {defineMessages, useIntl} from 'react-intl';
import {DeviceEventEmitter, StyleSheet, Text, View} from 'react-native';
import {RectButton, Pressable} from 'react-native-gesture-handler';
import Animated from 'react-native-reanimated';
import FileIcon from '@components/files/file_icon';
import {Events, Preferences} from '@constants';
import {useServerUrl} from '@context/server';
import SecurityManager from '@managers/security_manager';
import DownloadWithAction from '@screens/gallery/footer/download_with_action';
import {buttonBackgroundStyle, buttonTextStyle} from '@utils/buttonStyles';
import {isDocument, isPdf} from '@utils/file';
import {galleryItemToFileInfo} from '@utils/gallery';
import {changeOpacity} from '@utils/theme';
import {typography} from '@utils/typography';
import type {GalleryAction, GalleryItemType} from '@typings/screens/gallery';
type Props = {
canDownloadFiles: boolean;
enableSecureFilePreview: boolean;
item: GalleryItemType;
hideHeaderAndFooter: (hide?: boolean) => void;
}
const styles = StyleSheet.create({
container: {
alignItems: 'center',
justifyContent: 'center',
flex: 1,
maxWidth: 600,
},
filename: {
color: '#FFF',
...typography('Body', 200, 'SemiBold'),
marginVertical: 8,
paddingHorizontal: 25,
textAlign: 'center',
},
unsupported: {
color: '#FFF',
...typography('Body', 100, 'SemiBold'),
marginTop: 10,
paddingHorizontal: 25,
opacity: 0.64,
textAlign: 'center',
},
});
const messages = defineMessages({
unsupported: {
id: 'gallery.unsupported',
defaultMessage: "Preview isn't supported for this file type. Try downloading or sharing to open it in another app.",
},
unsupportedAndBlockedDownload: {
id: 'gallery.unsupported_and_blocked_download',
defaultMessage: "Preview isn't supported for this file type, and downloads are disabled by your administrator.",
},
openFile: {
id: 'gallery.open_file',
defaultMessage: 'Open file',
},
onlyPdf: {
id: 'gallery.only_pdf',
defaultMessage: 'Only PDF files are supported for secure file preview.',
},
});
const DocumentRenderer = ({canDownloadFiles, enableSecureFilePreview, item, hideHeaderAndFooter}: Props) => {
const {formatMessage} = useIntl();
const serverUrl = useServerUrl();
const file = useMemo(() => galleryItemToFileInfo(item), [item]);
const [enabled, setEnabled] = useState(true);
const isSupported = useMemo(() => isDocument(file), [file]);
const canOpenFile = useMemo(() => {
if (!isSupported) {
return false;
}
if (enableSecureFilePreview && isPdf(file)) {
return true;
}
return !enableSecureFilePreview && canDownloadFiles;
}, [canDownloadFiles, enableSecureFilePreview, file, isSupported]);
const optionText = useMemo(() => {
const allowSaveToLocation = SecurityManager.canSaveToLocation(serverUrl, 'FilesApp');
if (enableSecureFilePreview && !isPdf(file)) {
return formatMessage(messages.onlyPdf);
} else if (!isSupported && allowSaveToLocation) {
return formatMessage(messages.unsupported);
} else if (!isSupported && !allowSaveToLocation) {
return formatMessage(messages.unsupportedAndBlockedDownload);
}
return formatMessage(messages.openFile);
}, [enableSecureFilePreview, file, formatMessage, isSupported, serverUrl]);
const setGalleryAction = useCallback((action: GalleryAction) => {
DeviceEventEmitter.emit(Events.GALLERY_ACTIONS, action);
if (action === 'none') {
setEnabled(true);
}
}, []);
const handleOpenFile = useCallback(() => {
setEnabled(false);
}, []);
const handlePdfPreview = useCallback(() => {
if (enableSecureFilePreview && isPdf(file)) {
DeviceEventEmitter.emit(Events.CLOSE_GALLERY);
return;
}
hideHeaderAndFooter();
}, [file, enableSecureFilePreview, hideHeaderAndFooter]);
return (
<>
<Pressable onPress={handlePdfPreview}>
<Animated.View style={styles.container}>
<FileIcon
backgroundColor='transparent'
file={file}
iconSize={120}
/>
<Text
numberOfLines={2}
style={styles.filename}
>
{item.name}
</Text>
{!isSupported &&
<Text style={styles.unsupported}>{optionText}</Text>
}
{canOpenFile &&
<View style={{marginTop: 16}}>
<RectButton
enabled={enabled}
exclusive={true}
onPress={handleOpenFile}
rippleColor={changeOpacity('#fff', 0.16)}
>
<View style={buttonBackgroundStyle(Preferences.THEMES.onyx, 'lg', 'primary', enabled ? 'default' : 'disabled')}>
<Text style={buttonTextStyle(Preferences.THEMES.onyx, 'lg', 'primary', enabled ? 'default' : 'disabled')} >{optionText}</Text>
</View>
</RectButton>
</View>
}
</Animated.View>
</Pressable>
{!enabled &&
<DownloadWithAction
action='opening'
enableSecureFilePreview={enableSecureFilePreview}
setAction={setGalleryAction}
item={item}
onDownloadSuccess={handlePdfPreview}
/>
}
</>
);
};
export default DocumentRenderer;