mattermost-mobile/app/managers/session_manager.ts
Elias Nahum 44eb76bed7
feat(iOS): Add Microsoft Intune MAM integration with multi-server support (#9312)
* refactor: implement custom ExpoImage wrapper for cache control

Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app

* refactor(ios): convert Gekidou to CocoaPods

Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0

* npm audit

* update fastlane

* feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection

Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository

* fix tests by mocking @mattermost/intune

* feat: implement Intune MAM integration with comprehensive security enforcement

Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls

* fix alerts when no server database is present

* Unify cache strategy

* fix emit config changed after it was stored in the db

* Handle Mid-Session Enrollment Detection

* fix ADALLogOverrideDisabled missing in Fastfile

* fix flow for initial enrollment

* fix and add unit tests

* enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release

* Update intune submodule with addressed feedback

* fix validate-intune-clean workflow

* feat(intune): add comprehensive error handling and SAML+Entra support

Add production-ready error handling for native Entra authentication with
user-friendly i18n messages, comprehensive test coverage, and support for
Entra login when server requires SAML.

* update i18n

* update intune submodule

* update build-pr token

* fix race condition between server auth and intune enrollment

* fix CI workflow to build with intune

* use deploy key for intune submodule

* set the config directly in the submodule .git

* debug injection

* try setting GIT_SSH_COMMAND

* remove action debug

* fix server url input

* match pod cache with intune hash

* Fastfile and envs

* have workflows check for intune/.git

* have ci cache intune frameworks as well

* update Fastlane to set no-cache to artifacts uploaded

* fix s3 upload

* fix pblist template

* Attempt to remove the cache control for PR uploads to s3

* use hash from commit for S3 path

* Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain

* Fix surface errors from intune login

* fix postinstall scripts

* use cacheKey for draft md images

* remove unnecessary double await during test

* Have isMinimumLicenseTier accept valid license sku tier as target

* Add missing Auth error messages

* remove the last period for intune errors in i18n

* do not call unenroll with wipe on manual logout

* Fix tests and Intune error messages

* do not filter any SSO type regardless of which is used for Intune

* fix 412 to not retry

* fix tests, app logs sharing and share_extension avatar cache

* apply setScreenCapturePolicy on license change

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* re-apply screen capture on enrollment

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* use userData from intunr login and prevent getMe

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* Check for Biometrics and Jailbreak as we used to

---------

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
2025-12-10 13:07:28 +02:00

174 lines
6.7 KiB
TypeScript

// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See LICENSE.txt for license information.
import {AppState, type AppStateStatus, DeviceEventEmitter, Platform} from 'react-native';
import {storeGlobal, storeOnboardingViewedValue} from '@actions/app/global';
import {cancelAllSessionNotifications, terminateSession} from '@actions/local/session';
import {logout, scheduleSessionNotification} from '@actions/remote/session';
import {Events, Launch} from '@constants';
import {GLOBAL_IDENTIFIERS} from '@constants/database';
import DatabaseManager from '@database/manager';
import {getAllServerCredentials} from '@init/credentials';
import {relaunchApp} from '@init/launch';
import IntuneManager from '@managers/intune_manager';
import SecurityManager from '@managers/security_manager';
import {queryGlobalValue} from '@queries/app/global';
import {getAllServers, getServerDisplayName} from '@queries/app/servers';
import {getThemeFromState} from '@screens/navigation';
import EphemeralStore from '@store/ephemeral_store';
import {deleteFileCacheByDir} from '@utils/file';
import {isMainActivity} from '@utils/helpers';
import {addNewServer} from '@utils/server';
import type {LaunchType} from '@typings/launch';
type LogoutCallbackArg = {
serverUrl: string;
removeServer: boolean;
}
export class SessionManagerSingleton {
private previousAppState: AppStateStatus;
private scheduling = false;
private terminatingSessionUrl = new Set<string>();
constructor() {
if (Platform.OS === 'android') {
AppState.addEventListener('blur', () => {
this.onAppStateChange('inactive');
});
AppState.addEventListener('focus', () => {
this.onAppStateChange('active');
});
} else {
AppState.addEventListener('change', this.onAppStateChange);
}
DeviceEventEmitter.addListener(Events.SERVER_LOGOUT, this.onLogout);
DeviceEventEmitter.addListener(Events.SESSION_EXPIRED, this.onSessionExpired);
this.previousAppState = AppState.currentState;
}
init() {
cancelAllSessionNotifications();
let updateToMigrationDone = false;
queryGlobalValue(GLOBAL_IDENTIFIERS.CACHE_MIGRATION)?.fetch().then((records) => {
const cacheMigrationDone = Boolean(records?.[0]?.value);
if (!cacheMigrationDone) {
if (Platform.OS === 'ios') {
deleteFileCacheByDir('com.hackemist.SDImageCache');
} else if (Platform.OS === 'android') {
deleteFileCacheByDir('image_cache');
deleteFileCacheByDir('image_manager_disk_cache');
}
updateToMigrationDone = true;
}
}).finally(() => {
if (updateToMigrationDone) {
storeGlobal(GLOBAL_IDENTIFIERS.CACHE_MIGRATION, true);
}
});
}
private scheduleAllSessionNotifications = async () => {
if (!this.scheduling) {
this.scheduling = true;
const serverCredentials = await getAllServerCredentials();
const promises: Array<Promise<{error: unknown} | {error?: undefined}>> = [];
for (const {serverUrl} of serverCredentials) {
promises.push(scheduleSessionNotification(serverUrl));
}
await Promise.all(promises);
this.scheduling = false;
}
};
private onAppStateChange = async (appState: AppStateStatus) => {
if (appState === this.previousAppState || !isMainActivity()) {
return;
}
this.previousAppState = appState;
switch (appState) {
case 'active':
setTimeout(cancelAllSessionNotifications, 750);
break;
case 'inactive':
this.scheduleAllSessionNotifications();
break;
}
};
private onLogout = async ({serverUrl, removeServer}: LogoutCallbackArg) => {
if (this.terminatingSessionUrl.has(serverUrl)) {
return;
}
try {
this.terminatingSessionUrl.add(serverUrl);
const activeServerUrl = await DatabaseManager.getActiveServerUrl();
const activeServerDisplayName = await DatabaseManager.getActiveServerDisplayName();
await terminateSession(serverUrl, removeServer);
SecurityManager.removeServer(serverUrl);
// We do not unenroll with Wipe as we already removed all the data during terminateSession
await IntuneManager.unenrollServer(serverUrl, false);
if (activeServerUrl === serverUrl) {
let displayName = '';
let launchType: LaunchType = Launch.AddServer;
if (!Object.keys(DatabaseManager.serverDatabases).length) {
EphemeralStore.theme = undefined;
launchType = Launch.Normal;
if (activeServerDisplayName) {
displayName = activeServerDisplayName;
}
}
// set the onboardingViewed value to false so the launch will show the onboarding screen after all servers were removed
const servers = await getAllServers();
if (!servers.length) {
await storeOnboardingViewedValue(false);
}
relaunchApp({launchType, serverUrl, displayName});
}
} finally {
this.terminatingSessionUrl.delete(serverUrl);
}
};
private onSessionExpired = async (serverUrl: string) => {
this.terminatingSessionUrl.add(serverUrl);
try {
// logout is not doing anything in this scenario, but we keep it
// to keep the same flow as other logout scenarios.
await logout(serverUrl, undefined, {skipServerLogout: true, skipEvents: true});
await terminateSession(serverUrl, false);
SecurityManager.removeServer(serverUrl);
await IntuneManager.unenrollServer(serverUrl, true);
const activeServerUrl = await DatabaseManager.getActiveServerUrl();
const serverDisplayName = await getServerDisplayName(serverUrl);
await relaunchApp({launchType: Launch.Normal, serverUrl, displayName: serverDisplayName});
if (activeServerUrl) {
addNewServer(getThemeFromState(), serverUrl, serverDisplayName);
} else {
EphemeralStore.theme = undefined;
}
} finally {
this.terminatingSessionUrl.delete(serverUrl);
}
};
}
const SessionManager = new SessionManagerSingleton();
export default SessionManager;