Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,7 @@ build
/gradle.properties
.attach_pid*
fastlane/Fastfile
fastlane/ruby
*.hprof
captures/
.navigation/
Expand Down
38 changes: 22 additions & 16 deletions fastlane/Fastfile
Original file line number Diff line number Diff line change
@@ -1,22 +1,28 @@
# SPDX-FileCopyrightText: 2018-2024 Nextcloud GmbH and Nextcloud contributors
# SPDX-License-Identifier: GPL-3.0-or-later

# This is the minimum version number required.
fastlane_version "2.58.0"

## config
# add following to your shell rc:
# export FASTLANE_TALK_UPLOAD_STORE_FILE=""
# export FASTLANE_TALK_UPLOAD_STORE_PASSWORD=""
# export FASTLANE_TALK_UPLOAD_KEY_ALIAS=""
# export FASTLANE_TALK_UPLOAD_KEY_PASSWORD=""
# export FASTLANE_NEXTCLOUD_GITHUB_API_TOKEN=""




skip_docs

## public lanes

desc "Upload Alpha version to play store"
lane :uploadAlphaToPlayStore do |options|
upload_to_play_store(
skip_upload_images: true,
skip_upload_aab: true,
skip_upload_changelogs: true,
skip_upload_metadata: true,
skip_upload_screenshots: true,
track: 'alpha',
apk: "/home/androiddaily/apks-talk/android-talk-" + options[:version] + ".apk",
)
end
APP="talk"
REPO="nextcloud/talk-android"

GRADLE_SIGNING_PROPERTIES = {
"android.injected.signing.store.file" => ENV["FASTLANE_TALK_UPLOAD_STORE_FILE"],
"android.injected.signing.store.password" => ENV["FASTLANE_TALK_UPLOAD_STORE_PASSWORD"],
"android.injected.signing.key.alias" => ENV["FASTLANE_TALK_UPLOAD_KEY_ALIAS"],
"android.injected.signing.key.password" => ENV["FASTLANE_TALK_UPLOAD_KEY_PASSWORD"],
}.freeze
Comment on lines +21 to +26

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟑 Minor | ⚑ Quick win

Validate the signing environment variables before use.

GRADLE_SIGNING_PROPERTIES reads four ENV values with no presence check. If a variable is unset, the value is nil. Gradle then receives a missing signing property. The build can fail late with an unclear error. It can also produce an unsigned or wrongly signed artifact.

Fail fast if a value is missing or empty. Use ENV.fetch with a check, or UI.user_error!.

Proposed fix
+SIGNING_ENV_KEYS = %w[
+  FASTLANE_TALK_UPLOAD_STORE_FILE
+  FASTLANE_TALK_UPLOAD_STORE_PASSWORD
+  FASTLANE_TALK_UPLOAD_KEY_ALIAS
+  FASTLANE_TALK_UPLOAD_KEY_PASSWORD
+].freeze
+
+missing = SIGNING_ENV_KEYS.select { |k| ENV[k].to_s.empty? }
+UI.user_error!("Missing env vars: #{missing.join(', ')}") unless missing.empty?
+
 GRADLE_SIGNING_PROPERTIES = {

If these values are only needed by some lanes, run the check inside those lanes instead of at load time. The load-time check would also break lanes that need no signing.

Based on learnings: validate that security-sensitive values from environment variables are present and non-empty, and fail fast if they are missing.

πŸ“ Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
GRADLE_SIGNING_PROPERTIES = {
"android.injected.signing.store.file" => ENV["FASTLANE_TALK_UPLOAD_STORE_FILE"],
"android.injected.signing.store.password" => ENV["FASTLANE_TALK_UPLOAD_STORE_PASSWORD"],
"android.injected.signing.key.alias" => ENV["FASTLANE_TALK_UPLOAD_KEY_ALIAS"],
"android.injected.signing.key.password" => ENV["FASTLANE_TALK_UPLOAD_KEY_PASSWORD"],
}.freeze
SIGNING_ENV_KEYS = %w[
FASTLANE_TALK_UPLOAD_STORE_FILE
FASTLANE_TALK_UPLOAD_STORE_PASSWORD
FASTLANE_TALK_UPLOAD_KEY_ALIAS
FASTLANE_TALK_UPLOAD_KEY_PASSWORD
].freeze
missing = SIGNING_ENV_KEYS.select { |k| ENV[k].to_s.empty? }
UI.user_error!("Missing env vars: #{missing.join(', ')}") unless missing.empty?
GRADLE_SIGNING_PROPERTIES = {
"android.injected.signing.store.file" => ENV["FASTLANE_TALK_UPLOAD_STORE_FILE"],
"android.injected.signing.store.password" => ENV["FASTLANE_TALK_UPLOAD_STORE_PASSWORD"],
"android.injected.signing.key.alias" => ENV["FASTLANE_TALK_UPLOAD_KEY_ALIAS"],
"android.injected.signing.key.password" => ENV["FASTLANE_TALK_UPLOAD_KEY_PASSWORD"],
}.freeze

Source: Learnings

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

makes sense, @tobiasKaminsky ?


import("./common.Fastfile")
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Loading