mattermost-mobile/ios/Podfile
Elias Nahum 44eb76bed7
feat(iOS): Add Microsoft Intune MAM integration with multi-server support (#9312)
* refactor: implement custom ExpoImage wrapper for cache control

Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app

* refactor(ios): convert Gekidou to CocoaPods

Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0

* npm audit

* update fastlane

* feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection

Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository

* fix tests by mocking @mattermost/intune

* feat: implement Intune MAM integration with comprehensive security enforcement

Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls

* fix alerts when no server database is present

* Unify cache strategy

* fix emit config changed after it was stored in the db

* Handle Mid-Session Enrollment Detection

* fix ADALLogOverrideDisabled missing in Fastfile

* fix flow for initial enrollment

* fix and add unit tests

* enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release

* Update intune submodule with addressed feedback

* fix validate-intune-clean workflow

* feat(intune): add comprehensive error handling and SAML+Entra support

Add production-ready error handling for native Entra authentication with
user-friendly i18n messages, comprehensive test coverage, and support for
Entra login when server requires SAML.

* update i18n

* update intune submodule

* update build-pr token

* fix race condition between server auth and intune enrollment

* fix CI workflow to build with intune

* use deploy key for intune submodule

* set the config directly in the submodule .git

* debug injection

* try setting GIT_SSH_COMMAND

* remove action debug

* fix server url input

* match pod cache with intune hash

* Fastfile and envs

* have workflows check for intune/.git

* have ci cache intune frameworks as well

* update Fastlane to set no-cache to artifacts uploaded

* fix s3 upload

* fix pblist template

* Attempt to remove the cache control for PR uploads to s3

* use hash from commit for S3 path

* Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain

* Fix surface errors from intune login

* fix postinstall scripts

* use cacheKey for draft md images

* remove unnecessary double await during test

* Have isMinimumLicenseTier accept valid license sku tier as target

* Add missing Auth error messages

* remove the last period for intune errors in i18n

* do not call unenroll with wipe on manual logout

* Fix tests and Intune error messages

* do not filter any SSO type regardless of which is used for Intune

* fix 412 to not retry

* fix tests, app logs sharing and share_extension avatar cache

* apply setScreenCapturePolicy on license change

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* re-apply screen capture on enrollment

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* use userData from intunr login and prevent getMe

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* Check for Biometrics and Jailbreak as we used to

---------

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
2025-12-10 13:07:28 +02:00

109 lines
3.6 KiB
Ruby

def node_require(script)
# Resolve script with node to allow for hoisting
require Pod::Executable.execute_command('node', ['-p',
"require.resolve(
'#{script}',
{paths: [process.argv[1]]},
)", __dir__]).strip
end
require File.join(File.dirname(`node --print "require.resolve('expo/package.json')"`), "scripts/autolinking")
node_require('react-native/scripts/react_native_pods.rb')
node_require('react-native-permissions/scripts/setup.rb')
platform :ios, '15.1' #min_ios_version_supported
prepare_react_native_project!
Pod::UI.puts "Configuring Pod with statically linked Frameworks".green
use_frameworks! :linkage => :static
setup_permissions([
"Camera",
"Microphone",
"Notifications",
"PhotoLibrary"
])
# Conditional Intune MAM support
intune_enabled = ENV['INTUNE_ENABLED'] == '1'
if intune_enabled
puts "🔐 Intune MAM features enabled"
end
config = use_native_modules!
target 'Mattermost' do
# Pods for Mattermost
use_expo_modules!
use_react_native!(
:path => config[:reactNativePath],
# An absolute path to your application root.
:app_path => "#{Pod::Config.instance.installation_root}/.."
)
pod 'React-jsi', :path => '../node_modules/react-native/ReactCommon/jsi', :modular_headers => true
pod 'React-jsc', :path => '../node_modules/react-native/ReactCommon/jsc', :modular_headers => true
pod 'simdjson', path: '../node_modules/@nozbe/simdjson', :modular_headers => true
pod 'Gekidou', :path => './Gekidou'
pod 'CocoaLumberjack', :modular_headers => true
pod 'TurboLogIOSNative', :git => 'https://github.com/larkox/react-native-turbo-log-ios-native.git', :modular_headers => true
# Conditional Intune MAM pod (internal builds only)
if intune_enabled
pod 'mattermost-intune', :path => '../libraries/@mattermost/intune'
end
end
target 'NotificationService' do
inherit! :search_paths
pod 'TurboLogIOSNative', :git => 'https://github.com/larkox/react-native-turbo-log-ios-native.git', :modular_headers => true
pod 'Sentry/HybridSDK', '8.48.0'
pod 'Gekidou', :path => './Gekidou'
end
target 'MattermostShare' do
inherit! :search_paths
pod 'Sentry/HybridSDK', '8.48.0'
pod 'Gekidou', :path => './Gekidou'
pod 'OpenGraph', '1.4.1'
end
post_install do |installer|
# https://github.com/facebook/react-native/blob/main/packages/react-native/scripts/react_native_pods.rb#L197-L202
react_native_post_install(
installer,
config[:reactNativePath],
:mac_catalyst_enabled => false
)
installer.pods_project.targets.each do |t|
t.build_configurations.each do |bc|
bc.build_settings['SWIFT_VERSION'] = '5.9'
bc.build_settings['OTHER_LDFLAGS'] = ['$(inherited)', '-ObjC']
bc.build_settings['STRIP_SWIFT_SYMBOLS'] = 'NO'
bc.build_settings['ENABLE_BITCODE'] = 'NO'
end
end
# ensure stdlib is embedded for Gekidou to work correctly in extensions
%w[NotificationService MattermostShare].each do |ext_name|
target = installer.aggregate_targets.flat_map(&:user_project).flat_map(&:targets).find { |x| x.name == ext_name }
next unless target
target.build_configurations.each do |c|
c.build_settings['APPLICATION_EXTENSION_API_ONLY'] = 'YES'
c.build_settings['ALWAYS_EMBED_SWIFT_STANDARD_LIBRARIES'] = 'YES'
end
end
# make sure the main app is NOT extension-only
app_target = installer.aggregate_targets.flat_map(&:user_project).flat_map(&:targets).find { |t| t.name == 'Mattermost' }
if app_target
app_target.build_configurations.each do |c|
c.build_settings.delete('APPLICATION_EXTENSION_API_ONLY')
end
end
end