Conversation
Signed-off-by: xd-bobo <caojianbo@xd.com>
|
| export const GOOGLE_PLAY_MANIFEST_OVERLAY = `<manifest xmlns:android="http://schemas.android.com/apk/res/android" | ||
| xmlns:tools="http://schemas.android.com/tools"> | ||
| <uses-permission android:name="android.permission.REQUEST_INSTALL_PACKAGES" tools:node="remove" /> | ||
| </manifest>\n`; |
There was a problem hiding this comment.
Play 强更入口未分流 Play 变体移除安装包权限后,原生安装器会判定它不支持应用内安装。但 Global 的强更页面仍使用同一 Android 发布记录中的安装地址,没有转到 Play 商店的分流。若该地址是官网 APK,Play 用户点击“去更新”会打开 APK 下载地址,无法通过预期的 Play 更新路径解除强更阻断。发布此 AAB 前,需要让商店更新入口的配套改动生效。
Knowledge Base Used: Mobile application architecture
Prompt To Fix With AI
This is a comment left during a code review.
Path: apps/mobile/scripts/lib/android-local.mjs
Line: 68-71
Comment:
**Play 强更入口未分流** Play 变体移除安装包权限后,原生安装器会判定它不支持应用内安装。但 Global 的强更页面仍使用同一 Android 发布记录中的安装地址,没有转到 Play 商店的分流。若该地址是官网 APK,Play 用户点击“去更新”会打开 APK 下载地址,无法通过预期的 Play 更新路径解除强更阻断。发布此 AAB 前,需要让商店更新入口的配套改动生效。
**Knowledge Base Used:** [Mobile application architecture](https://app.greptile.com/xindong/-/custom-context/knowledge-base/makecindy/cindy/-/docs/mobile-application.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| describe('Global Android distribution manifests', () => { | ||
| it('官网和 Play 使用独立变体,Play overlay 移除安装权限', () => { | ||
| const source = 'android {\n signingConfigs {\n }\n}\n'; | ||
| const patched = patchBuildGradleDistributionFlavors(source); | ||
| expect(patched).toContain('website { dimension "distribution" }'); | ||
| expect(patched).toContain('play { dimension "distribution" }'); | ||
| expect(patchBuildGradleDistributionFlavors(patched)).toBe(patched); | ||
| expect(GOOGLE_PLAY_MANIFEST_OVERLAY).toContain('android.permission.REQUEST_INSTALL_PACKAGES" tools:node="remove"'); | ||
| expect(() => patchBuildGradleDistributionFlavors('missing')).toThrow(/android/); | ||
| }); | ||
|
|
||
| it('验证最终 APK 有权限,AAB 无权限', () => { | ||
| expect(() => assertAndroidInstallPermissionPresent('android.permission.REQUEST_INSTALL_PACKAGES')) | ||
| .not.toThrow(); | ||
| expect(() => assertAndroidInstallPermissionPresent('android.permission.INTERNET')) | ||
| .toThrow(/缺少/); | ||
| expect(() => assertGooglePlayInstallPermissionAbsent(Buffer.from('manifest'))).not.toThrow(); | ||
| expect(() => assertGooglePlayInstallPermissionAbsent(Buffer.from('android.permission.REQUEST_INSTALL_PACKAGES'))) | ||
| .toThrow(/仍包含/); |
There was a problem hiding this comment.
缺少实际产物回归测试 新测试只用手写的 Gradle 片段和普通 UTF-8 Buffer 检查变体及权限逻辑,没有自动检查 Expo prebuild 后的 Gradle 配置、Manifest 合并结果或 AAB 内嵌 Manifest。后续构建配置变化即使使 Play 权限移除失效,这些测试仍可能通过,问题要到发布构建时才会暴露。建议增加可重复执行的最终产物权限测试。
Prompt To Fix With AI
This is a comment left during a code review.
Path: apps/mobile/src/__tests__/androidLocal.test.ts
Line: 61-79
Comment:
**缺少实际产物回归测试** 新测试只用手写的 Gradle 片段和普通 UTF-8 Buffer 检查变体及权限逻辑,没有自动检查 Expo prebuild 后的 Gradle 配置、Manifest 合并结果或 AAB 内嵌 Manifest。后续构建配置变化即使使 Play 权限移除失效,这些测试仍可能通过,问题要到发布构建时才会暴露。建议增加可重复执行的最终产物权限测试。
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
这次改了什么
摘要
Global Android 冷更从同一次 Expo prebuild 生成官网 APK 与 Google Play AAB 两个 Gradle 变体。官网 APK 保留
REQUEST_INSTALL_PACKAGES供应用内安装更新;Play AAB 在 Manifest 合并时移除该权限,避免 Play Console 要求声明不适用的安装包权限。变更类型
fix缺陷修复feat新功能refactor/perf重构或性能优化docs/test/chore文档、测试或工程维护范围
REQUEST_INSTALL_PACKAGES。website/play变体、Play Manifest overlay、产物路径与最终权限校验、回归测试。UI 变化
怎么验证的
自动验证
手工验证
在隔离 worktree 的本地 Expo 预构建工程中,模拟 Global 自建主 Manifest 的安装权限,实际执行
:app:bundlePlayRelease和:app:assembleWebsiteRelease。Play AAB 内嵌 Manifest 不含REQUEST_INSTALL_PACKAGES;官网 APK 经aapt2 dump permissions确认包含该权限;两份产物回读的runtimeVersion相同。AGP 产物与 metadata 路径符合脚本预期。未执行的验证
未用正式 Global 区域配置与 release keystore 运行完整发布任务,也未上传 Play Console。该验证需在两仓改动集成后的发布环境执行。
风险
风险分类
影响与回滚
提交前检查
git commit -s)