* refactor: implement custom ExpoImage wrapper for cache control Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app * refactor(ios): convert Gekidou to CocoaPods Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0 * npm audit * update fastlane * feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository * fix tests by mocking @mattermost/intune * feat: implement Intune MAM integration with comprehensive security enforcement Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls * fix alerts when no server database is present * Unify cache strategy * fix emit config changed after it was stored in the db * Handle Mid-Session Enrollment Detection * fix ADALLogOverrideDisabled missing in Fastfile * fix flow for initial enrollment * fix and add unit tests * enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release * Update intune submodule with addressed feedback * fix validate-intune-clean workflow * feat(intune): add comprehensive error handling and SAML+Entra support Add production-ready error handling for native Entra authentication with user-friendly i18n messages, comprehensive test coverage, and support for Entra login when server requires SAML. * update i18n * update intune submodule * update build-pr token * fix race condition between server auth and intune enrollment * fix CI workflow to build with intune * use deploy key for intune submodule * set the config directly in the submodule .git * debug injection * try setting GIT_SSH_COMMAND * remove action debug * fix server url input * match pod cache with intune hash * Fastfile and envs * have workflows check for intune/.git * have ci cache intune frameworks as well * update Fastlane to set no-cache to artifacts uploaded * fix s3 upload * fix pblist template * Attempt to remove the cache control for PR uploads to s3 * use hash from commit for S3 path * Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain * Fix surface errors from intune login * fix postinstall scripts * use cacheKey for draft md images * remove unnecessary double await during test * Have isMinimumLicenseTier accept valid license sku tier as target * Add missing Auth error messages * remove the last period for intune errors in i18n * do not call unenroll with wipe on manual logout * Fix tests and Intune error messages * do not filter any SSO type regardless of which is used for Intune * fix 412 to not retry * fix tests, app logs sharing and share_extension avatar cache * apply setScreenCapturePolicy on license change Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * re-apply screen capture on enrollment Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * use userData from intunr login and prevent getMe Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * Check for Biometrics and Jailbreak as we used to --------- Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
145 lines
7.4 KiB
YAML
145 lines
7.4 KiB
YAML
---
|
|
name: Validate Intune Clean
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- 'ios/Podfile'
|
|
- 'ios/Podfile.lock'
|
|
- 'package.json'
|
|
- 'package-lock.json'
|
|
- 'ios/Mattermost/Info.plist'
|
|
- 'ios/Mattermost/Mattermost.entitlements'
|
|
- 'ios/Mattermost.xcodeproj/project.pbxproj'
|
|
|
|
jobs:
|
|
validate-podfile-lock:
|
|
name: Validate Podfile.lock is OSS-only
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: ci/checkout-repo
|
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
|
|
|
- name: Check Podfile.lock for Intune references
|
|
run: |
|
|
if grep -q "mattermost-intune\|IntuneMAMSwift" ios/Podfile.lock; then
|
|
echo ""
|
|
echo "❌ ERROR: Podfile.lock contains Intune dependencies"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "The committed Podfile.lock should only contain OSS dependencies."
|
|
echo "Please restore the OSS version:"
|
|
echo ""
|
|
echo " git checkout main -- ios/Podfile.lock"
|
|
echo ""
|
|
echo "Or run: npm run intune:disable"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
echo "✅ Podfile.lock is clean (OSS-only)"
|
|
|
|
- name: Check for package.json Intune reference
|
|
run: |
|
|
# Check only dependencies and devDependencies sections (not scripts)
|
|
if jq -e '.dependencies."@mattermost/intune" // .devDependencies."@mattermost/intune"' package.json > /dev/null 2>&1; then
|
|
echo ""
|
|
echo "❌ ERROR: package.json contains @mattermost/intune dependency"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "The Intune library should NOT be in package.json dependencies."
|
|
echo "It is installed via --no-save flag during internal builds only."
|
|
echo ""
|
|
echo "The 'intune:link' script is OK - only dependencies are checked."
|
|
echo ""
|
|
echo "Please remove the @mattermost/intune entry from dependencies."
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
echo "✅ package.json is clean (no Intune in dependencies)"
|
|
|
|
- name: Check for package-lock.json Intune reference
|
|
run: |
|
|
if grep -q "@mattermost/intune" package-lock.json 2>/dev/null; then
|
|
echo ""
|
|
echo "❌ ERROR: package-lock.json contains @mattermost/intune"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "The Intune library should NOT be in package-lock.json."
|
|
echo ""
|
|
echo "Please run: npm install (without INTUNE_ENABLED set)"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
echo "✅ package-lock.json is clean (no Intune reference)"
|
|
|
|
- name: Check Info.plist for Intune configuration
|
|
run: |
|
|
if grep -q "IntuneMAMSettings\|msauth\.com\.microsoft\.intunemam\|mattermost-intunemam\|mmauthbeta-intunemam\|intunemam-mtd\|msauthv2\|msauthv3" ios/Mattermost/Info.plist; then
|
|
echo ""
|
|
echo "❌ ERROR: Info.plist contains Intune configuration"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "The Info.plist should NOT contain Intune-specific settings."
|
|
echo "Intune configuration is applied by Fastlane during internal builds only."
|
|
echo ""
|
|
echo "Please restore the OSS version:"
|
|
echo ""
|
|
echo " git checkout main -- ios/Mattermost/Info.plist"
|
|
echo ""
|
|
echo "Or run: npm run intune:disable"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
echo "✅ Info.plist is clean (no Intune configuration)"
|
|
|
|
- name: Check entitlements for Intune keychain groups
|
|
run: |
|
|
if grep -q "com\.microsoft\.adalcache\|com\.microsoft\.intune\.mam\|\.intunemam" ios/Mattermost/Mattermost.entitlements 2>/dev/null; then
|
|
echo ""
|
|
echo "❌ ERROR: Mattermost.entitlements contains Intune keychain groups"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "The entitlements should NOT contain Intune-specific keychain groups."
|
|
echo "Intune keychain groups are added by Fastlane during internal builds only."
|
|
echo ""
|
|
echo "Please restore the OSS version:"
|
|
echo ""
|
|
echo " git checkout main -- ios/Mattermost/Mattermost.entitlements"
|
|
echo ""
|
|
echo "Or run: npm run intune:disable"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
echo "✅ Mattermost.entitlements is clean (no Intune keychain groups)"
|
|
|
|
- name: Check project.pbxproj for Intune frameworks
|
|
run: |
|
|
if grep -q "MSAL\|IntuneMAM\|IntuneMAMSwift" ios/Mattermost.xcodeproj/project.pbxproj 2>/dev/null; then
|
|
echo ""
|
|
echo "❌ ERROR: project.pbxproj contains Intune framework references"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "The project.pbxproj should NOT contain Intune framework references."
|
|
echo "Intune frameworks (MSAL, IntuneMAM, IntuneMAMSwift) are added by Fastlane during internal builds only."
|
|
echo ""
|
|
echo "Please restore the OSS version:"
|
|
echo ""
|
|
echo " git checkout main -- ios/Mattermost.xcodeproj/project.pbxproj"
|
|
echo ""
|
|
echo "Or run: npm run intune:disable"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
echo "✅ project.pbxproj is clean (no Intune framework references)"
|