Files
termix-mobile/scripts/verify-android-network-security.cjs
Luke Gustafson 6c40d2f0cc v1.4.0 (#31)
* fix: register physical Tab key on iPadOS/iOS hardware keyboards (#14)

The native module only registered Shift+Tab but not bare Tab, so iOS
intercepted it for UI focus navigation. Register an unmodified Tab
UIKeyCommand with wantsPriorityOverSystemBehavior and handle both
Tab and Shift+Tab in the same JS branch.

Fixes Termix-SSH/Support#557

* fix: pass jumpHosts, forceKeyboardInteractive, and overrideCredentialUsername to terminal connection (#15)

These fields were defined on SSHHost but omitted from the terminal
hostConfig passthrough. Without jumpHosts the backend cannot route
through jump servers; without forceKeyboardInteractive hosts that
require keyboard-interactive auth fail silently; without
overrideCredentialUsername shared credentials use the wrong username.

Fixes Termix-SSH/Support#422
Fixes Termix-SSH/Support#638

* fix: improve mobile terminal scroll recovery (#17)

* Add mobile remote desktop sessions (#18)

* feat: add mobile remote desktop sessions

* feat: add remote desktop input controls

* feat: polish remote desktop controls

* feat: add mobile terminal font selection (#19)

* feat: add mobile shift tab hotkey (#20)

* feat: initial UI redesign

* feat: revamp server login system

* chore: update app icon/background color

* fix: remove unused fields in the settings tab

* feat: improve the user pin system and update all settings modals to use new ui

* fix: active server not updating unless app restarts

* feat: add version in settings

* feat: improve host page UI (updated host form and added credential management)

* fix: preserve composed iOS terminal input

* ci: restore mobile checks

* feat: rewrite of connection system for all types

* fix: preserve mobile jump hosts (#30)

* fix: guard android user ca trust (#29)

* fix: capture ios hardware tab key (#27)

* fix: reset terminal input after special keys (#28)

* fix: open oidc in system browser (#26)

* fix: preserve websocket auth context (#25)

* fix: keep none-auth terminal prompts alive (#23)

* fix: allow local network SSL in Android app (#21)

* feat: allow oidc passkeys

* feat: bundeled xterm into app and added docker loading screen

* feat: add 2fa, api key, and active sessions to settings and addressed multiple bug fixes and inconsistencies with termix web

* chore: update repo images and readme

* chore: update readme to split table for screenshots

* chore: rename ios to apple in build workflow

* fix: android build failure

* feat: add snippet management and fix several bugs

* fix: web login and oidc incorrect logic

* chore: run linter

---------

Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-03 16:49:50 -05:00

58 lines
1.8 KiB
JavaScript

/* eslint-env node */
/* global __dirname */
const fs = require("fs");
const path = require("path");
const projectRoot = path.resolve(__dirname, "..");
const appJson = require(path.join(projectRoot, "app.json"));
const networkSecurityPlugin = require(
path.join(projectRoot, "plugins", "withNetworkSecurityConfig.js"),
);
function assert(condition, message) {
if (!condition) {
throw new Error(message);
}
}
const plugins = appJson.expo?.plugins ?? [];
assert(
plugins.includes("./plugins/withNetworkSecurityConfig.js"),
"app.json must include ./plugins/withNetworkSecurityConfig.js",
);
const xml = networkSecurityPlugin.NETWORK_SECURITY_CONFIG;
assert(typeof xml === "string", "network security XML must be exported");
const baseConfig = xml.match(/<base-config[\s\S]*?<\/base-config>/)?.[0];
assert(baseConfig, "network security XML must include a base-config");
assert(
baseConfig.includes('<certificates src="system" />'),
"base-config must trust Android system CAs",
);
assert(
baseConfig.includes('<certificates src="user" />'),
"base-config must trust user-installed CAs",
);
const domainConfig = xml.match(/<domain-config[\s\S]*?<\/domain-config>/)?.[0];
assert(domainConfig, "network security XML must include local domain-config");
assert(
domainConfig.includes('<certificates src="system" />') &&
domainConfig.includes('<certificates src="user" />'),
"local domain-config must keep system and user CA trust anchors",
);
const pluginSource = fs.readFileSync(
path.join(projectRoot, "plugins", "withNetworkSecurityConfig.js"),
"utf8",
);
assert(
pluginSource.includes('"android:networkSecurityConfig"') &&
pluginSource.includes('"@xml/network_security_config"'),
"AndroidManifest must reference @xml/network_security_config",
);
console.log("Android network security config trusts system and user CAs.");