fix: clear CodeQL alerts and keep Android surfaces in sync with the app theme - #7
Merged
Merged
Conversation
- go/zipslip:zip/tar 解压改用 filepath.IsLocal 正向守卫(CodeQL 只识别该形式),删掉 safeArchiveTargetPath,补两个穿越用例。 - java/android/implicit-pendingintents:通知用的 PendingIntent 改为 Intent() + setClass 显式组件,并删除两个从未被读取的自定义 action。 - node_modules 里的 Capacitor 源码随 Gradle 子项目进入 Kotlin 数据库:新增 .github/codeql/codeql-config.yml 的 paths-ignore 并在 init 步骤引用。
- 渲染进程被系统回收后由 MainActivity 重建 WebView(进程、Go runtime 与运行中的探测任务不中断);启动窗口、窗口背景与 WebView 底色取同一颜色,frontend/index.html 的内联首帧启动画面兜住 Vue 挂载前的空档。 - 主题跟随前端配置:frontend/src/lib/surfaceTheme.ts 把解析结果写入 localStorage 并调用 SetSurfaceTheme,AndroidSurfaceTheme 缓存到 SharedPreferences,MainActivity 在 super.onCreate 之前按缓存值 setTheme,切换主题时刷新窗口与 WebView 底色。 - Android 12+ 启动窗口图标改用 @mipmap/ic_launcher;values-night 覆盖系统深色模式下的启动窗口底色。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
内容
1. Code Scanning 告警(5 个 open)
go/zipslip(high)internal/app/update.gofilepath.IsLocal正向守卫(CodeQL 的IsLocalCheck只识别这个形式),删除safeArchiveTargetPath,新增两个穿越回归测试java/android/implicit-pendingintents(high) ×2AndroidKeepAliveForegroundService.kt、ProbeForegroundService.ktPendingIntent改用Intent()+setClass(this, MainActivity::class.java)显式组件;顺带删除两个从未被读取的自定义 actionjava/xss(high)、java/error-message-exposure(medium)MessageHandler.java(位于node_modules内).github/codeql/codeql-config.yml的paths-ignore: node_modules/**,并在 CodeQL init 步骤用config-file引用2. Android 白屏与主题
MainActivity重建 WebView,不再终止整个进程(运行中的探测任务保持不中断、不会被标记为recovery_required)。frontend/index.html的内联首帧启动画面兜住 Vue 挂载前的空档。SetSurfaceTheme→AndroidSurfaceTheme→SharedPreferences,冷启动与recreate()都按缓存主题setTheme,切换主题时立即刷新窗口与 WebView 底色。@mipmap/ic_launcher(此前是系统通用图标),values-night覆盖系统深色模式下的启动窗口底色。验证
scripts/checks/check.sh通过:Go 全量测试、go test -tags webui ./internal/app/、frontend boundary / vapor / 单测(27 passed)/ typecheck / 生产构建。golangci-lint run、actionlint、markdownlint-cli2:0 issues。assembleDebug detektDebug detektDebugUnitTest ktlintMainSourceSetCheck testDebugUnitTest --offlineBUILD SUCCESSFUL;debug APK 已确认assets/public/index.html含首帧与主题脚本、app_background_dark进入资源。行为变化说明
\开头的条目现在会被跳过(旧实现会去掉前导分隔符后照常解压);没有..逃逸的条目不受影响。