device infos
This commit is contained in:
@@ -31,11 +31,23 @@
|
||||
<uses-permission android:name="android.permission.WAKE_LOCK" />
|
||||
|
||||
<!-- ===== Application ===== -->
|
||||
<!-- usesCleartextTraffic was `true`, commented "allows http if any". There
|
||||
is no http:// endpoint left in the app: every host it talks to —
|
||||
api.doormile.com, queue.workolik.com, the OSM tile server and the OSRM
|
||||
router — is https, and all of them present valid publicly trusted
|
||||
certificates.
|
||||
|
||||
Left on, the flag is a standing invitation: a URL that later arrives
|
||||
from a payload or a config would be fetched in the clear on the
|
||||
rider's mobile network, carrying his session and his position. Off,
|
||||
that request fails and somebody fixes the URL. Turned off alongside
|
||||
the certificate bypass in MyHttpOverrides, which was the other half
|
||||
of the same hole. -->
|
||||
<application
|
||||
android:label="Doormile Rider"
|
||||
android:name="${applicationName}"
|
||||
android:icon="@mipmap/ic_launcher"
|
||||
android:usesCleartextTraffic="true"> <!-- allows http if any -->
|
||||
android:usesCleartextTraffic="false">
|
||||
|
||||
<!-- No maps key. The Google Maps SDK is no longer used: tiles come
|
||||
from OpenStreetMap and routes from OSRM, both keyless, drawn by
|
||||
|
||||
Reference in New Issue
Block a user