merge: Android runtime security (B1, B3)

Correct the POST_NOTIFICATIONS mechanism: the lockscreen notification is exempt
because of the MediaSession token, not because it belongs to a foreground
service — FGS notifications are explicitly NOT exempt. So no permission prompt
and no checkSelfPermission gate; instead both notification builders bind the
token once and log loudly if it is ever null, turning a silent failure into a
logcat line. Stop the webview undoing the network security config:
mixedContentMode COMPATIBILITY, allowFileAccess/allowContentAccess false.

Conflict resolution: this branch's DR-198 collided with the Tauri branch's, so
it was renumbered DR-200 (3 TRACES in JellyTauPlaybackService.kt and the UR-006
matrix row updated). DR-199 was uncontested. Pinned counts summed to DR 191 /
total 334; UR-071 takes both DR-198 and DR-199.
This commit is contained in:
2026-08-16 23:03:29 +02:00
8 changed files with 221 additions and 15 deletions
@@ -12,7 +12,12 @@
remote server still has to be HTTPS — this must not become a blanket
cleartext opt-in.
TRACES: UR-071 | DR-138
This file is only half the policy. MainActivity.configureWebViewSettings sets
the webview's mixedContentMode and its file/content access flags; setting
MIXED_CONTENT_ALWAYS_ALLOW there re-opened by hand what this config closes,
which is DR-199. Change the two together, or not at all.
TRACES: UR-071 | DR-138, DR-199
-->
<network-security-config>
<base-config cleartextTrafficPermitted="false" />