mattermost-mobile/.github/workflows/validate-intune-clean.yml
Elias Nahum 44eb76bed7
feat(iOS): Add Microsoft Intune MAM integration with multi-server support (#9312)
* refactor: implement custom ExpoImage wrapper for cache control

Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app

* refactor(ios): convert Gekidou to CocoaPods

Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0

* npm audit

* update fastlane

* feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection

Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository

* fix tests by mocking @mattermost/intune

* feat: implement Intune MAM integration with comprehensive security enforcement

Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls

* fix alerts when no server database is present

* Unify cache strategy

* fix emit config changed after it was stored in the db

* Handle Mid-Session Enrollment Detection

* fix ADALLogOverrideDisabled missing in Fastfile

* fix flow for initial enrollment

* fix and add unit tests

* enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release

* Update intune submodule with addressed feedback

* fix validate-intune-clean workflow

* feat(intune): add comprehensive error handling and SAML+Entra support

Add production-ready error handling for native Entra authentication with
user-friendly i18n messages, comprehensive test coverage, and support for
Entra login when server requires SAML.

* update i18n

* update intune submodule

* update build-pr token

* fix race condition between server auth and intune enrollment

* fix CI workflow to build with intune

* use deploy key for intune submodule

* set the config directly in the submodule .git

* debug injection

* try setting GIT_SSH_COMMAND

* remove action debug

* fix server url input

* match pod cache with intune hash

* Fastfile and envs

* have workflows check for intune/.git

* have ci cache intune frameworks as well

* update Fastlane to set no-cache to artifacts uploaded

* fix s3 upload

* fix pblist template

* Attempt to remove the cache control for PR uploads to s3

* use hash from commit for S3 path

* Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain

* Fix surface errors from intune login

* fix postinstall scripts

* use cacheKey for draft md images

* remove unnecessary double await during test

* Have isMinimumLicenseTier accept valid license sku tier as target

* Add missing Auth error messages

* remove the last period for intune errors in i18n

* do not call unenroll with wipe on manual logout

* Fix tests and Intune error messages

* do not filter any SSO type regardless of which is used for Intune

* fix 412 to not retry

* fix tests, app logs sharing and share_extension avatar cache

* apply setScreenCapturePolicy on license change

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* re-apply screen capture on enrollment

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* use userData from intunr login and prevent getMe

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* Check for Biometrics and Jailbreak as we used to

---------

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
2025-12-10 13:07:28 +02:00

145 lines
7.4 KiB
YAML

---
name: Validate Intune Clean
on:
pull_request:
paths:
- 'ios/Podfile'
- 'ios/Podfile.lock'
- 'package.json'
- 'package-lock.json'
- 'ios/Mattermost/Info.plist'
- 'ios/Mattermost/Mattermost.entitlements'
- 'ios/Mattermost.xcodeproj/project.pbxproj'
jobs:
validate-podfile-lock:
name: Validate Podfile.lock is OSS-only
runs-on: ubuntu-latest
steps:
- name: ci/checkout-repo
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Check Podfile.lock for Intune references
run: |
if grep -q "mattermost-intune\|IntuneMAMSwift" ios/Podfile.lock; then
echo ""
echo "❌ ERROR: Podfile.lock contains Intune dependencies"
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
echo "The committed Podfile.lock should only contain OSS dependencies."
echo "Please restore the OSS version:"
echo ""
echo " git checkout main -- ios/Podfile.lock"
echo ""
echo "Or run: npm run intune:disable"
echo ""
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
exit 1
fi
echo "✅ Podfile.lock is clean (OSS-only)"
- name: Check for package.json Intune reference
run: |
# Check only dependencies and devDependencies sections (not scripts)
if jq -e '.dependencies."@mattermost/intune" // .devDependencies."@mattermost/intune"' package.json > /dev/null 2>&1; then
echo ""
echo "❌ ERROR: package.json contains @mattermost/intune dependency"
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
echo "The Intune library should NOT be in package.json dependencies."
echo "It is installed via --no-save flag during internal builds only."
echo ""
echo "The 'intune:link' script is OK - only dependencies are checked."
echo ""
echo "Please remove the @mattermost/intune entry from dependencies."
echo ""
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
exit 1
fi
echo "✅ package.json is clean (no Intune in dependencies)"
- name: Check for package-lock.json Intune reference
run: |
if grep -q "@mattermost/intune" package-lock.json 2>/dev/null; then
echo ""
echo "❌ ERROR: package-lock.json contains @mattermost/intune"
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
echo "The Intune library should NOT be in package-lock.json."
echo ""
echo "Please run: npm install (without INTUNE_ENABLED set)"
echo ""
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
exit 1
fi
echo "✅ package-lock.json is clean (no Intune reference)"
- name: Check Info.plist for Intune configuration
run: |
if grep -q "IntuneMAMSettings\|msauth\.com\.microsoft\.intunemam\|mattermost-intunemam\|mmauthbeta-intunemam\|intunemam-mtd\|msauthv2\|msauthv3" ios/Mattermost/Info.plist; then
echo ""
echo "❌ ERROR: Info.plist contains Intune configuration"
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
echo "The Info.plist should NOT contain Intune-specific settings."
echo "Intune configuration is applied by Fastlane during internal builds only."
echo ""
echo "Please restore the OSS version:"
echo ""
echo " git checkout main -- ios/Mattermost/Info.plist"
echo ""
echo "Or run: npm run intune:disable"
echo ""
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
exit 1
fi
echo "✅ Info.plist is clean (no Intune configuration)"
- name: Check entitlements for Intune keychain groups
run: |
if grep -q "com\.microsoft\.adalcache\|com\.microsoft\.intune\.mam\|\.intunemam" ios/Mattermost/Mattermost.entitlements 2>/dev/null; then
echo ""
echo "❌ ERROR: Mattermost.entitlements contains Intune keychain groups"
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
echo "The entitlements should NOT contain Intune-specific keychain groups."
echo "Intune keychain groups are added by Fastlane during internal builds only."
echo ""
echo "Please restore the OSS version:"
echo ""
echo " git checkout main -- ios/Mattermost/Mattermost.entitlements"
echo ""
echo "Or run: npm run intune:disable"
echo ""
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
exit 1
fi
echo "✅ Mattermost.entitlements is clean (no Intune keychain groups)"
- name: Check project.pbxproj for Intune frameworks
run: |
if grep -q "MSAL\|IntuneMAM\|IntuneMAMSwift" ios/Mattermost.xcodeproj/project.pbxproj 2>/dev/null; then
echo ""
echo "❌ ERROR: project.pbxproj contains Intune framework references"
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
echo "The project.pbxproj should NOT contain Intune framework references."
echo "Intune frameworks (MSAL, IntuneMAM, IntuneMAMSwift) are added by Fastlane during internal builds only."
echo ""
echo "Please restore the OSS version:"
echo ""
echo " git checkout main -- ios/Mattermost.xcodeproj/project.pbxproj"
echo ""
echo "Or run: npm run intune:disable"
echo ""
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo ""
exit 1
fi
echo "✅ project.pbxproj is clean (no Intune framework references)"