* refactor: implement custom ExpoImage wrapper for cache control Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app * refactor(ios): convert Gekidou to CocoaPods Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0 * npm audit * update fastlane * feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository * fix tests by mocking @mattermost/intune * feat: implement Intune MAM integration with comprehensive security enforcement Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls * fix alerts when no server database is present * Unify cache strategy * fix emit config changed after it was stored in the db * Handle Mid-Session Enrollment Detection * fix ADALLogOverrideDisabled missing in Fastfile * fix flow for initial enrollment * fix and add unit tests * enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release * Update intune submodule with addressed feedback * fix validate-intune-clean workflow * feat(intune): add comprehensive error handling and SAML+Entra support Add production-ready error handling for native Entra authentication with user-friendly i18n messages, comprehensive test coverage, and support for Entra login when server requires SAML. * update i18n * update intune submodule * update build-pr token * fix race condition between server auth and intune enrollment * fix CI workflow to build with intune * use deploy key for intune submodule * set the config directly in the submodule .git * debug injection * try setting GIT_SSH_COMMAND * remove action debug * fix server url input * match pod cache with intune hash * Fastfile and envs * have workflows check for intune/.git * have ci cache intune frameworks as well * update Fastlane to set no-cache to artifacts uploaded * fix s3 upload * fix pblist template * Attempt to remove the cache control for PR uploads to s3 * use hash from commit for S3 path * Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain * Fix surface errors from intune login * fix postinstall scripts * use cacheKey for draft md images * remove unnecessary double await during test * Have isMinimumLicenseTier accept valid license sku tier as target * Add missing Auth error messages * remove the last period for intune errors in i18n * do not call unenroll with wipe on manual logout * Fix tests and Intune error messages * do not filter any SSO type regardless of which is used for Intune * fix 412 to not retry * fix tests, app logs sharing and share_extension avatar cache * apply setScreenCapturePolicy on license change Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * re-apply screen capture on enrollment Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * use userData from intunr login and prevent getMe Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * Check for Biometrics and Jailbreak as we used to --------- Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
262 lines
10 KiB
Text
262 lines
10 KiB
Text
#import "AppDelegate.h"
|
|
|
|
#import <AVFoundation/AVFoundation.h>
|
|
|
|
#import <React/RCTBundleURLProvider.h>
|
|
#import <React/RCTLinkingManager.h>
|
|
#import <RNKeychain/RNKeychainManager.h>
|
|
#import <ReactNativeNavigation/ReactNativeNavigation.h>
|
|
#import <UserNotifications/UserNotifications.h>
|
|
#import <TurboLogIOSNative/TurboLog.h>
|
|
|
|
#import "Mattermost-Swift.h"
|
|
#import <os/log.h>
|
|
|
|
#if __has_include(<MSAL/MSAL.h>)
|
|
#import <MSAL/MSAL.h>
|
|
#define HAS_MSAL 1
|
|
#else
|
|
#define HAS_MSAL 0
|
|
#endif
|
|
|
|
#if __has_include(<mattermost_intune/IntuneAccess.h>)
|
|
#import <mattermost_intune/IntuneAccess.h>
|
|
#define HAS_INTUNE 1
|
|
#else
|
|
#define HAS_INTUNE 0
|
|
#endif
|
|
|
|
#define INTUNE_AVAILABLE ((HAS_MSAL) && (HAS_INTUNE))
|
|
|
|
@implementation AppDelegate
|
|
|
|
@synthesize orientationLock;
|
|
|
|
NSString* const NOTIFICATION_MESSAGE_ACTION = @"message";
|
|
NSString* const NOTIFICATION_CLEAR_ACTION = @"clear";
|
|
NSString* const NOTIFICATION_UPDATE_BADGE_ACTION = @"update_badge";
|
|
NSString* const NOTIFICATION_TEST_ACTION = @"test";
|
|
|
|
-(void)application:(UIApplication *)application handleEventsForBackgroundURLSession:(NSString *)identifier completionHandler:(void (^)(void))completionHandler {
|
|
os_log(OS_LOG_DEFAULT, "Mattermost will attach session from handleEventsForBackgroundURLSession!! identifier=%{public}@", identifier);
|
|
[[GekidouWrapper default] attachSession:identifier completionHandler:completionHandler];
|
|
os_log(OS_LOG_DEFAULT, "Mattermost session ATTACHED from handleEventsForBackgroundURLSession!! identifier=%{public}@", identifier);
|
|
}
|
|
|
|
- (BOOL)application:(UIApplication *)application didFinishLaunchingWithOptions:(NSDictionary *)launchOptions
|
|
{
|
|
NSString *appGroupId = [[NSBundle mainBundle] objectForInfoDictionaryKey:@"AppGroupIdentifier"];
|
|
NSURL *containerURL = [[NSFileManager defaultManager] containerURLForSecurityApplicationGroupIdentifier:appGroupId];
|
|
containerURL = [containerURL URLByAppendingPathComponent:@"Logs"];
|
|
NSError *error = nil;
|
|
[TurboLog configureWithDailyRolling:FALSE maximumFileSize:1024*1024 maximumNumberOfFiles:2 logsDirectory:containerURL.path logsFilename:@"MMLogs" error:&error];
|
|
if (error) {
|
|
NSLog(@"Failed to configure TurboLog: %@", error.localizedDescription);
|
|
}
|
|
[TurboLog writeWithLogLevel:TurboLogLevelInfo message:@[@"Configured turbolog"]];
|
|
|
|
// Configure Gekidou to use TurboLog via wrapper
|
|
[[GekidouWrapper default] configureTurboLogForGekidou];
|
|
|
|
#if INTUNE_AVAILABLE
|
|
// Initialize Intune MAM delegates BEFORE React Native
|
|
[IntuneAccess initializeIntuneDelegates];
|
|
#endif
|
|
|
|
OrientationManager.shared.delegate = self;
|
|
|
|
// Clear keychain on first run in case of reinstallation
|
|
if (![[NSUserDefaults standardUserDefaults] objectForKey:@"FirstRun"]) {
|
|
|
|
RNKeychainManager *keychain = [[RNKeychainManager alloc] init];
|
|
NSArray<NSString*> *servers = [keychain getAllServersForInternetPasswords];
|
|
[TurboLog writeWithLogLevel:TurboLogLevelInfo message:@[@"Servers", servers]];
|
|
for (NSString *server in servers) {
|
|
[keychain deleteCredentialsForServer:server withOptions:nil];
|
|
}
|
|
|
|
[[NSUserDefaults standardUserDefaults] setValue:@YES forKey:@"FirstRun"];
|
|
[[NSUserDefaults standardUserDefaults] synchronize];
|
|
}
|
|
|
|
[[AVAudioSession sharedInstance] setCategory:AVAudioSessionCategoryPlayback error: nil];
|
|
[[GekidouWrapper default] setPreference:@"true" forKey:@"ApplicationIsRunning"];
|
|
|
|
[RNNotifications startMonitorNotifications];
|
|
|
|
os_log(OS_LOG_DEFAULT, "Mattermost started!!");
|
|
[ReactNativeNavigation bootstrapWithDelegate:self launchOptions:launchOptions];
|
|
|
|
#if INTUNE_AVAILABLE
|
|
// Restore enrollments if needed (silent, non-blocking)
|
|
[IntuneAccess checkAndRestoreEnrollmentOnLaunch];
|
|
#endif
|
|
|
|
return YES;
|
|
}
|
|
|
|
-(BOOL)bridgelessEnabled {
|
|
return NO;
|
|
}
|
|
|
|
- (void)application:(UIApplication *)application didRegisterForRemoteNotificationsWithDeviceToken:(NSData *)deviceToken
|
|
{
|
|
[RNNotifications didRegisterForRemoteNotificationsWithDeviceToken:deviceToken];
|
|
}
|
|
|
|
- (void)application:(UIApplication *)application didFailToRegisterForRemoteNotificationsWithError:(NSError *)error {
|
|
[RNNotifications didFailToRegisterForRemoteNotificationsWithError:error];
|
|
}
|
|
|
|
// Required for the notification event.
|
|
|
|
-(void)application:(UIApplication *)application didReceiveRemoteNotification:(nonnull NSDictionary *)userInfo fetchCompletionHandler:(nonnull void (^)(UIBackgroundFetchResult))completionHandler {
|
|
UIApplicationState state = [UIApplication sharedApplication].applicationState;
|
|
NSString* action = [userInfo objectForKey:@"type"];
|
|
BOOL isClearAction = (action && [action isEqualToString: NOTIFICATION_CLEAR_ACTION]);
|
|
BOOL isTestAction = (action && [action isEqualToString: NOTIFICATION_TEST_ACTION]);
|
|
|
|
if (isTestAction) {
|
|
completionHandler(UIBackgroundFetchResultNoData);
|
|
return;
|
|
}
|
|
|
|
if (![[GekidouWrapper default] verifySignature:userInfo]) {
|
|
NSMutableDictionary *notification = [userInfo mutableCopy];
|
|
[notification setValue:@"false" forKey:@"verified"];
|
|
[RNNotifications didReceiveBackgroundNotification:notification withCompletionHandler:completionHandler];
|
|
return;
|
|
}
|
|
|
|
if (isClearAction) {
|
|
// When CRT is OFF:
|
|
// If received a notification that a channel was read, remove all notifications from that channel (only with app in foreground/background)
|
|
// When CRT is ON:
|
|
// When rootId is nil, clear channel's root post notifications or else clear all thread notifications
|
|
[[NotificationHelper default] clearChannelOrThreadNotificationsWithUserInfo:userInfo];
|
|
[[GekidouWrapper default] postNotificationReceipt:userInfo];
|
|
[RNNotifications didReceiveBackgroundNotification:userInfo withCompletionHandler:completionHandler];
|
|
return;
|
|
}
|
|
|
|
if (state != UIApplicationStateActive) {
|
|
[[GekidouWrapper default] fetchDataForPushNotification:userInfo withContentHandler:^(NSData * _Nullable data) {
|
|
NSMutableDictionary *notification = [userInfo mutableCopy];
|
|
if (notification == nil) {
|
|
[TurboLog writeWithLogLevel:TurboLogLevelError message:@[@"Mattermost AppDelegate: Failed to copy userInfo dictionary"]];
|
|
completionHandler(UIBackgroundFetchResultFailed);
|
|
return;
|
|
}
|
|
|
|
if (data != nil) {
|
|
NSError *jsonError = nil;
|
|
id json = [NSJSONSerialization JSONObjectWithData:data options:NULL error:&jsonError];
|
|
if (jsonError) {
|
|
[TurboLog writeWithLogLevel:TurboLogLevelError message:@[@"Mattermost AppDelegate: JSON serialization error", jsonError.localizedDescription]];
|
|
} else if (json != nil) {
|
|
[notification setObject:json forKey:@"data"];
|
|
} else {
|
|
[TurboLog writeWithLogLevel:TurboLogLevelWarning message:@[@"Mattermost AppDelegate: JSON serialization returned nil without error"]];
|
|
}
|
|
}
|
|
[RNNotifications didReceiveBackgroundNotification:notification withCompletionHandler:completionHandler];
|
|
}];
|
|
} else {
|
|
completionHandler(UIBackgroundFetchResultNewData);
|
|
}
|
|
}
|
|
|
|
// Required for deeplinking
|
|
- (BOOL)application:(UIApplication *)application openURL:(NSURL *)url options:(NSDictionary<UIApplicationOpenURLOptionsKey,id> *)options{
|
|
return [RCTLinkingManager application:application openURL:url options:options];
|
|
}
|
|
|
|
- (BOOL)application:(UIApplication *)application openURL:(NSURL *)url sourceApplication:(NSString *)sourceApplication annotation:(id)annotation {
|
|
return [RCTLinkingManager application:application openURL:url sourceApplication:sourceApplication annotation:annotation];
|
|
}
|
|
|
|
// Helper method to handle MSAL URL schemes
|
|
- (BOOL)handleMSALURL:(NSURL *)url {
|
|
#if INTUNE_AVAILABLE
|
|
NSString *urlString = url.absoluteString;
|
|
NSString *bundleId = [[NSBundle mainBundle] bundleIdentifier];
|
|
NSString *expectedPrefix = [NSString stringWithFormat:@"msauth.%@", bundleId];
|
|
|
|
if ([urlString hasPrefix:expectedPrefix]) {
|
|
[TurboLog writeWithLogLevel:TurboLogLevelInfo message:@[@"[Intune] MSAL URL handled"]];
|
|
return [MSALPublicClientApplication handleMSALResponse:url sourceApplication:nil];
|
|
}
|
|
#endif
|
|
return NO;
|
|
}
|
|
|
|
// Only if your app is using [Universal Links](https://developer.apple.com/library/prerelease/ios/documentation/General/Conceptual/AppSearch/UniversalLinks.html).
|
|
- (BOOL)application:(UIApplication *)application continueUserActivity:(NSUserActivity *)userActivity
|
|
restorationHandler:(void (^)(NSArray<id<UIUserActivityRestoring>> *restorableObjects))restorationHandler
|
|
{
|
|
return [RCTLinkingManager application:application continueUserActivity:userActivity restorationHandler:restorationHandler];
|
|
}
|
|
|
|
-(void)applicationDidBecomeActive:(UIApplication *)application {
|
|
[[GekidouWrapper default] setPreference:@"true" forKey:@"ApplicationIsForeground"];
|
|
}
|
|
|
|
-(void)applicationWillResignActive:(UIApplication *)application {
|
|
[[GekidouWrapper default] setPreference:@"false" forKey:@"ApplicationIsForeground"];
|
|
}
|
|
|
|
-(void)applicationDidEnterBackground:(UIApplication *)application {
|
|
[[GekidouWrapper default] setPreference:@"false" forKey:@"ApplicationIsForeground"];
|
|
}
|
|
|
|
-(void)applicationWillTerminate:(UIApplication *)application {
|
|
[[GekidouWrapper default] setPreference:@"false" forKey:@"ApplicationIsForeground"];
|
|
[[GekidouWrapper default] setPreference:@"false" forKey:@"ApplicationIsRunning"];
|
|
}
|
|
|
|
- (UIInterfaceOrientationMask)application:(UIApplication *)application supportedInterfaceOrientationsForWindow:(UIWindow *)window {
|
|
return self.orientationLock;
|
|
}
|
|
|
|
- (NSArray<id<RCTBridgeModule>> *)extraModulesForBridge:(RCTBridge *)bridge
|
|
{
|
|
NSMutableArray<id<RCTBridgeModule>> *extraModules = [NSMutableArray new];
|
|
[extraModules addObjectsFromArray:[ReactNativeNavigation extraModulesForBridge:bridge]];
|
|
|
|
// You can inject any extra modules that you would like here, more information at:
|
|
// https://facebook.github.io/react-native/docs/native-modules-ios.html#dependency-injection
|
|
return extraModules;
|
|
}
|
|
|
|
- (NSURL *)sourceURLForBridge:(RCTBridge *)bridge
|
|
{
|
|
return [self bundleURL];
|
|
}
|
|
|
|
- (NSURL *)bundleURL
|
|
{
|
|
#if DEBUG
|
|
return [[RCTBundleURLProvider sharedSettings] jsBundleURLForBundleRoot:@"index"];
|
|
#else
|
|
return [[NSBundle mainBundle] URLForResource:@"main" withExtension:@"jsbundle"];
|
|
#endif
|
|
}
|
|
|
|
- (NSMutableArray<UIKeyCommand *> *)keyCommands {
|
|
return [MattermostHardwareKeyboardWrapper registerKeyCommandsWithEnterPressed:
|
|
@selector(sendEnter:) shiftEnterPressed:@selector(sendShiftEnter:) findChannels:@selector(sendFindChannels:)];
|
|
}
|
|
|
|
- (void)sendEnter:(UIKeyCommand *)sender {
|
|
[MattermostHardwareKeyboardWrapper enterKeyPressed];
|
|
}
|
|
|
|
- (void)sendShiftEnter:(UIKeyCommand *)sender {
|
|
[MattermostHardwareKeyboardWrapper shiftEnterKeyPressed];
|
|
}
|
|
|
|
- (void)sendFindChannels:(UIKeyCommand *)sender {
|
|
[MattermostHardwareKeyboardWrapper findChannels];
|
|
}
|
|
|
|
@end
|