<?xml version="1.0" encoding="utf-8"?>
<!--
  The one file with no Gradle equivalent. Everything here is either a permission,
  a component declaration, or an <application> attribute that replaces a whole
  res/ file:

    label                 replaces values/strings.xml
    allowBackup=false     replaces backup_rules.xml + data_extraction_rules.xml
    usesCleartextTraffic  replaces network_security_config.xml

  allowBackup="false" is a deliberate security decision, not a shortcut: the data
  directory holds this device's token key, and restoring it onto a second device
  would silently clone a credential.
-->
<manifest xmlns:android="http://schemas.android.com/apk/res/android">

    <uses-permission android:name="android.permission.INTERNET" />
    <uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />

    <!-- COARSE must be requested alongside FINE: asking for FINE alone on
         API 31+ can be silently downgraded to COARSE by the system dialog. -->
    <uses-permission android:name="android.permission.ACCESS_COARSE_LOCATION" />
    <uses-permission android:name="android.permission.ACCESS_FINE_LOCATION" />
    <uses-permission android:name="android.permission.ACCESS_BACKGROUND_LOCATION" />

    <uses-permission android:name="android.permission.FOREGROUND_SERVICE" />
    <!-- Mandatory from API 34: without it startForeground(TYPE_LOCATION) throws
         SecurityException. -->
    <uses-permission android:name="android.permission.FOREGROUND_SERVICE_LOCATION" />

    <uses-permission android:name="android.permission.POST_NOTIFICATIONS" />
    <uses-permission android:name="android.permission.RECEIVE_BOOT_COMPLETED" />
    <uses-permission android:name="android.permission.WAKE_LOCK" />
    <uses-permission android:name="android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS" />

    <!-- Deliberately NOT SCHEDULE_EXACT_ALARM: the watchdog uses inexact
         setAndAllowWhileIdle, which needs no permission and is why the heartbeat
         is 15 minutes rather than 5. -->

    <uses-feature
        android:name="android.hardware.location.gps"
        android:required="false" />

    <application
        android:allowBackup="false"
        android:icon="@android:drawable/ic_menu_mylocation"
        android:label="opentracker"
        android:supportsRtl="true"
        android:theme="@style/Theme.OpenTracker"
        android:usesCleartextTraffic="false">

        <activity
            android:name=".MainActivity"
            android:exported="true"
            android:launchMode="singleTask">
            <intent-filter>
                <action android:name="android.intent.action.MAIN" />
                <category android:name="android.intent.category.LAUNCHER" />
            </intent-filter>
        </activity>

        <!-- stopWithTask=false: swiping the app away must not stop sharing.
             location has no FGS runtime timeout (unlike dataSync) and is exempt
             from the API 35 restriction on services started from
             BOOT_COMPLETED — which is exactly why it is the right type. -->
        <service
            android:name=".TrackerService"
            android:exported="false"
            android:foregroundServiceType="location"
            android:stopWithTask="false" />

        <!-- MY_PACKAGE_REPLACED covers `adb install -r`, which otherwise leaves
             tracking silently stopped after every reinstall. -->
        <receiver
            android:name=".BootReceiver"
            android:exported="true">
            <intent-filter>
                <action android:name="android.intent.action.BOOT_COMPLETED" />
                <action android:name="android.intent.action.MY_PACKAGE_REPLACED" />
            </intent-filter>
        </receiver>

        <receiver
            android:name=".WatchdogReceiver"
            android:exported="false" />
    </application>
</manifest>
