AndroidManifest.xml
⎇
Raw
1<?xml version="1.0" encoding="utf-8"?>
2<!--
3 The one file with no Gradle equivalent. Everything here is either a permission,
4 a component declaration, or an <application> attribute that replaces a whole
5 res/ file:
6
7 label replaces values/strings.xml
8 allowBackup=false replaces backup_rules.xml + data_extraction_rules.xml
9 usesCleartextTraffic replaces network_security_config.xml
10
11 allowBackup="false" is a deliberate security decision, not a shortcut: the data
12 directory holds this device's token key, and restoring it onto a second device
13 would silently clone a credential.
14-->
15<manifest xmlns:android="http://schemas.android.com/apk/res/android">
16
17 <uses-permission android:name="android.permission.INTERNET" />
18 <uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />
19
20 <!-- COARSE must be requested alongside FINE: asking for FINE alone on
21 API 31+ can be silently downgraded to COARSE by the system dialog. -->
22 <uses-permission android:name="android.permission.ACCESS_COARSE_LOCATION" />
23 <uses-permission android:name="android.permission.ACCESS_FINE_LOCATION" />
24 <uses-permission android:name="android.permission.ACCESS_BACKGROUND_LOCATION" />
25
26 <uses-permission android:name="android.permission.FOREGROUND_SERVICE" />
27 <!-- Mandatory from API 34: without it startForeground(TYPE_LOCATION) throws
28 SecurityException. -->
29 <uses-permission android:name="android.permission.FOREGROUND_SERVICE_LOCATION" />
30
31 <uses-permission android:name="android.permission.POST_NOTIFICATIONS" />
32 <uses-permission android:name="android.permission.RECEIVE_BOOT_COMPLETED" />
33 <uses-permission android:name="android.permission.WAKE_LOCK" />
34 <uses-permission android:name="android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS" />
35
36 <!-- Deliberately NOT SCHEDULE_EXACT_ALARM: the watchdog uses inexact
37 setAndAllowWhileIdle, which needs no permission and is why the heartbeat
38 is 15 minutes rather than 5. -->
39
40 <uses-feature
41 android:name="android.hardware.location.gps"
42 android:required="false" />
43
44 <application
45 android:allowBackup="false"
46 android:icon="@android:drawable/ic_menu_mylocation"
47 android:label="opentracker"
48 android:supportsRtl="true"
49 android:theme="@style/Theme.OpenTracker"
50 android:usesCleartextTraffic="false">
51
52 <activity
53 android:name=".MainActivity"
54 android:exported="true"
55 android:launchMode="singleTask">
56 <intent-filter>
57 <action android:name="android.intent.action.MAIN" />
58 <category android:name="android.intent.category.LAUNCHER" />
59 </intent-filter>
60 </activity>
61
62 <!-- stopWithTask=false: swiping the app away must not stop sharing.
63 location has no FGS runtime timeout (unlike dataSync) and is exempt
64 from the API 35 restriction on services started from
65 BOOT_COMPLETED — which is exactly why it is the right type. -->
66 <service
67 android:name=".TrackerService"
68 android:exported="false"
69 android:foregroundServiceType="location"
70 android:stopWithTask="false" />
71
72 <!-- MY_PACKAGE_REPLACED covers `adb install -r`, which otherwise leaves
73 tracking silently stopped after every reinstall. -->
74 <receiver
75 android:name=".BootReceiver"
76 android:exported="true">
77 <intent-filter>
78 <action android:name="android.intent.action.BOOT_COMPLETED" />
79 <action android:name="android.intent.action.MY_PACKAGE_REPLACED" />
80 </intent-filter>
81 </receiver>
82
83 <receiver
84 android:name=".WatchdogReceiver"
85 android:exported="false" />
86 </application>
87</manifest>
88