* refactor: implement custom ExpoImage wrapper for cache control Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app * refactor(ios): convert Gekidou to CocoaPods Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0 * npm audit * update fastlane * feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository * fix tests by mocking @mattermost/intune * feat: implement Intune MAM integration with comprehensive security enforcement Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls * fix alerts when no server database is present * Unify cache strategy * fix emit config changed after it was stored in the db * Handle Mid-Session Enrollment Detection * fix ADALLogOverrideDisabled missing in Fastfile * fix flow for initial enrollment * fix and add unit tests * enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release * Update intune submodule with addressed feedback * fix validate-intune-clean workflow * feat(intune): add comprehensive error handling and SAML+Entra support Add production-ready error handling for native Entra authentication with user-friendly i18n messages, comprehensive test coverage, and support for Entra login when server requires SAML. * update i18n * update intune submodule * update build-pr token * fix race condition between server auth and intune enrollment * fix CI workflow to build with intune * use deploy key for intune submodule * set the config directly in the submodule .git * debug injection * try setting GIT_SSH_COMMAND * remove action debug * fix server url input * match pod cache with intune hash * Fastfile and envs * have workflows check for intune/.git * have ci cache intune frameworks as well * update Fastlane to set no-cache to artifacts uploaded * fix s3 upload * fix pblist template * Attempt to remove the cache control for PR uploads to s3 * use hash from commit for S3 path * Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain * Fix surface errors from intune login * fix postinstall scripts * use cacheKey for draft md images * remove unnecessary double await during test * Have isMinimumLicenseTier accept valid license sku tier as target * Add missing Auth error messages * remove the last period for intune errors in i18n * do not call unenroll with wipe on manual logout * Fix tests and Intune error messages * do not filter any SSO type regardless of which is used for Intune * fix 412 to not retry * fix tests, app logs sharing and share_extension avatar cache * apply setScreenCapturePolicy on license change Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * re-apply screen capture on enrollment Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * use userData from intunr login and prevent getMe Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * Check for Biometrics and Jailbreak as we used to --------- Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
109 lines
3.6 KiB
Ruby
109 lines
3.6 KiB
Ruby
def node_require(script)
|
|
# Resolve script with node to allow for hoisting
|
|
require Pod::Executable.execute_command('node', ['-p',
|
|
"require.resolve(
|
|
'#{script}',
|
|
{paths: [process.argv[1]]},
|
|
)", __dir__]).strip
|
|
end
|
|
|
|
require File.join(File.dirname(`node --print "require.resolve('expo/package.json')"`), "scripts/autolinking")
|
|
|
|
node_require('react-native/scripts/react_native_pods.rb')
|
|
node_require('react-native-permissions/scripts/setup.rb')
|
|
|
|
platform :ios, '15.1' #min_ios_version_supported
|
|
prepare_react_native_project!
|
|
|
|
Pod::UI.puts "Configuring Pod with statically linked Frameworks".green
|
|
use_frameworks! :linkage => :static
|
|
|
|
setup_permissions([
|
|
"Camera",
|
|
"Microphone",
|
|
"Notifications",
|
|
"PhotoLibrary"
|
|
])
|
|
|
|
# Conditional Intune MAM support
|
|
intune_enabled = ENV['INTUNE_ENABLED'] == '1'
|
|
|
|
if intune_enabled
|
|
puts "🔐 Intune MAM features enabled"
|
|
end
|
|
|
|
config = use_native_modules!
|
|
|
|
target 'Mattermost' do
|
|
# Pods for Mattermost
|
|
|
|
use_expo_modules!
|
|
|
|
use_react_native!(
|
|
:path => config[:reactNativePath],
|
|
# An absolute path to your application root.
|
|
:app_path => "#{Pod::Config.instance.installation_root}/.."
|
|
)
|
|
|
|
pod 'React-jsi', :path => '../node_modules/react-native/ReactCommon/jsi', :modular_headers => true
|
|
pod 'React-jsc', :path => '../node_modules/react-native/ReactCommon/jsc', :modular_headers => true
|
|
pod 'simdjson', path: '../node_modules/@nozbe/simdjson', :modular_headers => true
|
|
pod 'Gekidou', :path => './Gekidou'
|
|
pod 'CocoaLumberjack', :modular_headers => true
|
|
pod 'TurboLogIOSNative', :git => 'https://github.com/larkox/react-native-turbo-log-ios-native.git', :modular_headers => true
|
|
|
|
# Conditional Intune MAM pod (internal builds only)
|
|
if intune_enabled
|
|
pod 'mattermost-intune', :path => '../libraries/@mattermost/intune'
|
|
end
|
|
end
|
|
|
|
target 'NotificationService' do
|
|
inherit! :search_paths
|
|
pod 'TurboLogIOSNative', :git => 'https://github.com/larkox/react-native-turbo-log-ios-native.git', :modular_headers => true
|
|
pod 'Sentry/HybridSDK', '8.48.0'
|
|
pod 'Gekidou', :path => './Gekidou'
|
|
end
|
|
|
|
target 'MattermostShare' do
|
|
inherit! :search_paths
|
|
pod 'Sentry/HybridSDK', '8.48.0'
|
|
pod 'Gekidou', :path => './Gekidou'
|
|
pod 'OpenGraph', '1.4.1'
|
|
end
|
|
|
|
post_install do |installer|
|
|
# https://github.com/facebook/react-native/blob/main/packages/react-native/scripts/react_native_pods.rb#L197-L202
|
|
react_native_post_install(
|
|
installer,
|
|
config[:reactNativePath],
|
|
:mac_catalyst_enabled => false
|
|
)
|
|
|
|
installer.pods_project.targets.each do |t|
|
|
t.build_configurations.each do |bc|
|
|
bc.build_settings['SWIFT_VERSION'] = '5.9'
|
|
bc.build_settings['OTHER_LDFLAGS'] = ['$(inherited)', '-ObjC']
|
|
bc.build_settings['STRIP_SWIFT_SYMBOLS'] = 'NO'
|
|
bc.build_settings['ENABLE_BITCODE'] = 'NO'
|
|
end
|
|
end
|
|
|
|
# ensure stdlib is embedded for Gekidou to work correctly in extensions
|
|
%w[NotificationService MattermostShare].each do |ext_name|
|
|
target = installer.aggregate_targets.flat_map(&:user_project).flat_map(&:targets).find { |x| x.name == ext_name }
|
|
next unless target
|
|
target.build_configurations.each do |c|
|
|
c.build_settings['APPLICATION_EXTENSION_API_ONLY'] = 'YES'
|
|
c.build_settings['ALWAYS_EMBED_SWIFT_STANDARD_LIBRARIES'] = 'YES'
|
|
end
|
|
end
|
|
|
|
# make sure the main app is NOT extension-only
|
|
app_target = installer.aggregate_targets.flat_map(&:user_project).flat_map(&:targets).find { |t| t.name == 'Mattermost' }
|
|
if app_target
|
|
app_target.build_configurations.each do |c|
|
|
c.build_settings.delete('APPLICATION_EXTENSION_API_ONLY')
|
|
end
|
|
end
|
|
end
|