* refactor: implement custom ExpoImage wrapper for cache control Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app * refactor(ios): convert Gekidou to CocoaPods Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0 * npm audit * update fastlane * feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository * fix tests by mocking @mattermost/intune * feat: implement Intune MAM integration with comprehensive security enforcement Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls * fix alerts when no server database is present * Unify cache strategy * fix emit config changed after it was stored in the db * Handle Mid-Session Enrollment Detection * fix ADALLogOverrideDisabled missing in Fastfile * fix flow for initial enrollment * fix and add unit tests * enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release * Update intune submodule with addressed feedback * fix validate-intune-clean workflow * feat(intune): add comprehensive error handling and SAML+Entra support Add production-ready error handling for native Entra authentication with user-friendly i18n messages, comprehensive test coverage, and support for Entra login when server requires SAML. * update i18n * update intune submodule * update build-pr token * fix race condition between server auth and intune enrollment * fix CI workflow to build with intune * use deploy key for intune submodule * set the config directly in the submodule .git * debug injection * try setting GIT_SSH_COMMAND * remove action debug * fix server url input * match pod cache with intune hash * Fastfile and envs * have workflows check for intune/.git * have ci cache intune frameworks as well * update Fastlane to set no-cache to artifacts uploaded * fix s3 upload * fix pblist template * Attempt to remove the cache control for PR uploads to s3 * use hash from commit for S3 path * Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain * Fix surface errors from intune login * fix postinstall scripts * use cacheKey for draft md images * remove unnecessary double await during test * Have isMinimumLicenseTier accept valid license sku tier as target * Add missing Auth error messages * remove the last period for intune errors in i18n * do not call unenroll with wipe on manual logout * Fix tests and Intune error messages * do not filter any SSO type regardless of which is used for Intune * fix 412 to not retry * fix tests, app logs sharing and share_extension avatar cache * apply setScreenCapturePolicy on license change Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * re-apply screen capture on enrollment Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * use userData from intunr login and prevent getMe Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * Check for Biometrics and Jailbreak as we used to --------- Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
152 lines
6.7 KiB
Bash
Executable file
152 lines
6.7 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
|
|
# Intune protection: prevent committing Podfile.lock with Intune dependencies
|
|
if git diff --cached --name-only | grep -q "^ios/Podfile.lock$"; then
|
|
if grep -q "mattermost-intune\|IntuneMAMSwift" ios/Podfile.lock; then
|
|
echo ""
|
|
echo "❌ COMMIT BLOCKED"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "Your Podfile.lock contains Intune dependencies."
|
|
echo "Only the OSS version should be committed."
|
|
echo ""
|
|
echo "To fix this:"
|
|
echo " 1. Restore OSS lockfile:"
|
|
echo " git checkout -- ios/Podfile.lock"
|
|
echo ""
|
|
echo " 2. OR disable Intune completely:"
|
|
echo " npm run intune:disable"
|
|
echo ""
|
|
echo " 3. Then retry your commit"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
# Intune protection: prevent committing submodule content
|
|
if git diff --cached --name-only | grep -q "^libraries/@mattermost/intune/"; then
|
|
# Exclude .gitkeep which is allowed
|
|
if git diff --cached --name-only | grep "^libraries/@mattermost/intune/" | grep -v ".gitkeep$" | grep -q .; then
|
|
echo ""
|
|
echo "❌ COMMIT BLOCKED"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "You are attempting to commit files from the Intune submodule."
|
|
echo "The Intune library should only be modified in its own repository:"
|
|
echo " github.com/mattermost/mattermost-mobile-intune"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
# Intune protection: prevent committing Info.plist with Intune configuration
|
|
if git diff --cached --name-only | grep -q "^ios/Mattermost/Info.plist$"; then
|
|
if grep -q "IntuneMAMSettings\|msauth\.com\.microsoft\.intunemam\|mattermost-intunemam\|mmauthbeta-intunemam\|intunemam-mtd\|msauthv2\|msauthv3" ios/Mattermost/Info.plist; then
|
|
echo ""
|
|
echo "❌ COMMIT BLOCKED"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "Your Info.plist contains Intune-specific configuration."
|
|
echo "Intune settings are applied by Fastlane during internal builds only."
|
|
echo ""
|
|
echo "To fix this:"
|
|
echo " 1. Restore OSS Info.plist:"
|
|
echo " git checkout -- ios/Mattermost/Info.plist"
|
|
echo ""
|
|
echo " 2. OR disable Intune completely:"
|
|
echo " npm run intune:disable"
|
|
echo ""
|
|
echo " 3. Then retry your commit"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
# Intune protection: prevent committing entitlements with Intune keychain groups
|
|
if git diff --cached --name-only | grep -q "^ios/Mattermost/Mattermost.entitlements$"; then
|
|
if grep -q "com\.microsoft\.adalcache\|com\.microsoft\.intune\.mam\|\.intunemam" ios/Mattermost/Mattermost.entitlements; then
|
|
echo ""
|
|
echo "❌ COMMIT BLOCKED"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "Your Mattermost.entitlements contains Intune keychain groups."
|
|
echo "Intune keychain groups are added by Fastlane during internal builds only."
|
|
echo ""
|
|
echo "To fix this:"
|
|
echo " 1. Restore OSS entitlements:"
|
|
echo " git checkout -- ios/Mattermost/Mattermost.entitlements"
|
|
echo ""
|
|
echo " 2. OR disable Intune completely:"
|
|
echo " npm run intune:disable"
|
|
echo ""
|
|
echo " 3. Then retry your commit"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
# Intune protection: prevent committing project.pbxproj with Intune frameworks
|
|
if git diff --cached --name-only | grep -q "^ios/Mattermost.xcodeproj/project.pbxproj$"; then
|
|
if grep -q "MSAL\|IntuneMAM\|IntuneMAMSwift" ios/Mattermost.xcodeproj/project.pbxproj; then
|
|
echo ""
|
|
echo "❌ COMMIT BLOCKED"
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
echo "Your project.pbxproj contains Intune framework references."
|
|
echo "Intune frameworks are added by Fastlane during internal builds only."
|
|
echo ""
|
|
echo "To fix this:"
|
|
echo " 1. Restore OSS project.pbxproj:"
|
|
echo " git checkout -- ios/Mattermost.xcodeproj/project.pbxproj"
|
|
echo ""
|
|
echo " 2. OR disable Intune completely:"
|
|
echo " npm run intune:disable"
|
|
echo ""
|
|
echo " 3. Then retry your commit"
|
|
echo ""
|
|
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
|
|
echo ""
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
jsfiles=$(git diff --cached --name-only --diff-filter=ACM | grep -E '\.js$|\.ts$|\.tsx$')
|
|
exit_code=0
|
|
|
|
if [ -z "$jsfiles" ]; then
|
|
exit 0
|
|
fi
|
|
|
|
if [ -n "$jsfiles" ]; then
|
|
echo "Checking lint for:"
|
|
for js in $jsfiles; do
|
|
echo "$js"
|
|
e=$(node_modules/.bin/eslint --quiet --fix --config eslint.precommit.config.mjs $js)
|
|
if [ -n "$e" ]; then
|
|
echo "ERROR: Check eslint hints."
|
|
echo "$e"
|
|
exit_code=1
|
|
fi
|
|
done
|
|
|
|
echo "Checking for TSC (fast incremental check)"
|
|
# Use incremental TypeScript checking - much faster on subsequent runs
|
|
tsc=$(node_modules/.bin/tsc --noEmit --incremental --tsBuildInfoFile .tsbuildinfo.precommit 2>&1)
|
|
if [ $? -ne 0 ]; then
|
|
echo "ERROR: TypeScript issues found."
|
|
echo "$tsc"
|
|
exit_code=1
|
|
fi
|
|
fi
|
|
|
|
# scripts/precommit/i18n.sh
|
|
|
|
exit $exit_code
|