* refactor: implement custom ExpoImage wrapper for cache control Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app * refactor(ios): convert Gekidou to CocoaPods Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0 * npm audit * update fastlane * feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository * fix tests by mocking @mattermost/intune * feat: implement Intune MAM integration with comprehensive security enforcement Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls * fix alerts when no server database is present * Unify cache strategy * fix emit config changed after it was stored in the db * Handle Mid-Session Enrollment Detection * fix ADALLogOverrideDisabled missing in Fastfile * fix flow for initial enrollment * fix and add unit tests * enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release * Update intune submodule with addressed feedback * fix validate-intune-clean workflow * feat(intune): add comprehensive error handling and SAML+Entra support Add production-ready error handling for native Entra authentication with user-friendly i18n messages, comprehensive test coverage, and support for Entra login when server requires SAML. * update i18n * update intune submodule * update build-pr token * fix race condition between server auth and intune enrollment * fix CI workflow to build with intune * use deploy key for intune submodule * set the config directly in the submodule .git * debug injection * try setting GIT_SSH_COMMAND * remove action debug * fix server url input * match pod cache with intune hash * Fastfile and envs * have workflows check for intune/.git * have ci cache intune frameworks as well * update Fastlane to set no-cache to artifacts uploaded * fix s3 upload * fix pblist template * Attempt to remove the cache control for PR uploads to s3 * use hash from commit for S3 path * Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain * Fix surface errors from intune login * fix postinstall scripts * use cacheKey for draft md images * remove unnecessary double await during test * Have isMinimumLicenseTier accept valid license sku tier as target * Add missing Auth error messages * remove the last period for intune errors in i18n * do not call unenroll with wipe on manual logout * Fix tests and Intune error messages * do not filter any SSO type regardless of which is used for Intune * fix 412 to not retry * fix tests, app logs sharing and share_extension avatar cache * apply setScreenCapturePolicy on license change Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * re-apply screen capture on enrollment Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * use userData from intunr login and prevent getMe Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * Check for Biometrics and Jailbreak as we used to --------- Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
94 lines
3.3 KiB
TypeScript
94 lines
3.3 KiB
TypeScript
// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
|
|
// See LICENSE.txt for license information.
|
|
|
|
import {Navigation} from 'react-native-navigation';
|
|
|
|
import {doPing} from '@actions/remote/general';
|
|
import {fetchConfigAndLicense} from '@actions/remote/systems';
|
|
import {Screens} from '@constants';
|
|
import DatabaseManager from '@database/manager';
|
|
import SecurityManager from '@managers/security_manager';
|
|
import WebsocketManager from '@managers/websocket_manager';
|
|
import {getServer, getServerByIdentifier} from '@queries/app/servers';
|
|
import {logError} from '@utils/log';
|
|
import {canReceiveNotifications} from '@utils/push_proxy';
|
|
import {alertServerAlreadyConnected, alertServerError, loginToServer} from '@utils/server';
|
|
|
|
import type {IntlShape} from 'react-intl';
|
|
|
|
export async function switchToServer(serverUrl: string, theme: Theme, intl: IntlShape, callback?: () => void) {
|
|
const server = await getServer(serverUrl);
|
|
if (!server) {
|
|
logError(`Switch to Server with url ${serverUrl} not found`);
|
|
return;
|
|
}
|
|
if (server.lastActiveAt) {
|
|
const isJailbroken = await SecurityManager.isDeviceJailbroken(server.url);
|
|
if (isJailbroken) {
|
|
return;
|
|
}
|
|
|
|
const authenticated = await SecurityManager.authenticateWithBiometricsIfNeeded(server.url);
|
|
if (authenticated) {
|
|
Navigation.updateProps(Screens.HOME, {extra: undefined});
|
|
DatabaseManager.setActiveServerDatabase(server.url, {
|
|
skipJailbreakCheck: true,
|
|
skipBiometricCheck: true,
|
|
skipMAMEnrollmentCheck: false,
|
|
forceSwitch: false,
|
|
});
|
|
WebsocketManager.initializeClient(server.url, 'Server Switch');
|
|
}
|
|
|
|
return;
|
|
}
|
|
|
|
switchToServerAndLogin(serverUrl, theme, intl, callback);
|
|
}
|
|
|
|
export async function switchToServerAndLogin(serverUrl: string, theme: Theme, intl: IntlShape, callback?: () => void) {
|
|
const server = await getServer(serverUrl);
|
|
if (!server) {
|
|
logError(`Switch to Server with url ${serverUrl} not found`);
|
|
return;
|
|
}
|
|
|
|
const result = await doPing(server.url, true);
|
|
if (result.error) {
|
|
alertServerError(intl, result.error);
|
|
callback?.();
|
|
return;
|
|
}
|
|
|
|
const data = await fetchConfigAndLicense(server.url, true);
|
|
if (data.error) {
|
|
alertServerError(intl, data.error);
|
|
callback?.();
|
|
return;
|
|
}
|
|
|
|
const existingServer = await getServerByIdentifier(data.config!.DiagnosticId);
|
|
if (existingServer && existingServer.lastActiveAt > 0) {
|
|
alertServerAlreadyConnected(intl);
|
|
callback?.();
|
|
return;
|
|
}
|
|
|
|
if (data.config?.MobileJailbreakProtection === 'true') {
|
|
const isJailbroken = await SecurityManager.isDeviceJailbroken(server.url);
|
|
if (isJailbroken) {
|
|
callback?.();
|
|
return;
|
|
}
|
|
}
|
|
|
|
let authenticated = true;
|
|
if (data.config?.MobileEnableBiometrics === 'true') {
|
|
authenticated = await SecurityManager.authenticateWithBiometrics(server.url, data.config?.SiteName);
|
|
}
|
|
|
|
if (authenticated) {
|
|
canReceiveNotifications(server.url, result.canReceiveNotifications as string, intl);
|
|
loginToServer(theme, server.url, server.displayName, data.config!, data.license!);
|
|
}
|
|
}
|