<?xml version="1.0" encoding="utf-8"?>
<!--
  Debug-only overlay. The one thing it changes is cleartext HTTP.

  The main manifest sets android:usesCleartextTraffic="false" on purpose, and
  that stays true for every release build. But the emulator reaches a server
  running on the developer's own machine as http://10.0.2.2:7372, and with the
  flag off the platform blocks that connection outright, before any code runs.
  There is no certificate to install and no hostname to except, so the flag has
  to be flipped for the debug build.

  tools:replace is required: manifest merger keeps the stricter value from the
  main manifest otherwise, and reports a conflict rather than overriding it.

  This cannot leak into a release: the merger only reads src/debug for the debug
  build type, which also carries its own applicationIdSuffix.
-->
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
    xmlns:tools="http://schemas.android.com/tools">

    <application
        android:usesCleartextTraffic="true"
        tools:replace="android:usesCleartextTraffic" />
</manifest>
