From e88a664df6a172b7b6625214f225d3eea07b9387 Mon Sep 17 00:00:00 2001 From: Bradley Duck Date: Wed, 26 Aug 2026 16:24:16 +0100 Subject: [PATCH 1/2] chore: stop naming client projects in a public repository MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two places named internal client projects. The publishing-check comment was the worse of them: it named two of them and disclosed which toolbox modules each app depends on, which is more than the comment needed to make its point. Generalised to "one consumer" and "another" — the reasoning about why a green consumer proved nothing is what mattered, not which apps they were. The Nav3Navigation credit keeps the thanks and drops the project name. Co-Authored-By: Claude Opus 5 (1M context) --- Nav3Navigation/README.md | 2 +- publishing-check/build.gradle.kts | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/Nav3Navigation/README.md b/Nav3Navigation/README.md index 098a3cb..c99f4c2 100644 --- a/Nav3Navigation/README.md +++ b/Nav3Navigation/README.md @@ -660,4 +660,4 @@ Two traps that produce false failures: - **Use `am kill`, never `force-stop`.** `force-stop` discards saved instance state, so it proves nothing about restore. -Thanks to the Accelerate Android team for the cold-restore verification and both traps above. +Thanks to the consuming-app team who ran the cold-restore verification and found both traps above. diff --git a/publishing-check/build.gradle.kts b/publishing-check/build.gradle.kts index 472c776..66547ce 100644 --- a/publishing-check/build.gradle.kts +++ b/publishing-check/build.gradle.kts @@ -12,10 +12,10 @@ import org.gradle.api.attributes.java.TargetJvmEnvironment // // The 1.8.2 duplicate-class regression was invisible to the toolbox's own build: the library // compiled and published perfectly, and only an Android *consumer* resolving the published metadata -// could see the problem. It was also invisible to most consumers — WenWe was green on identical -// artifacts because it does not depend on MockInterceptor, and AssistantHood's `live` flavour built -// fine because it only pulls MockInterceptor into `staging`. A defect visible only to consumers who -// happen to pull one particular module should not be discovered by consumers. +// could see the problem. It was also invisible to most consumers — one was green on identical +// artifacts because it does not depend on MockInterceptor, and another's release flavour built fine +// because it only pulls MockInterceptor into a debug-side flavour. A defect visible only to +// consumers who happen to pull one particular module should not be discovered by consumers. // // So: resolve the published modules the way an Android app would, and assert the outcome. // From 1652b5fed3c71c5b0835dc95780eb42a212dc4f7 Mon Sep 17 00:00:00 2001 From: Bradley Duck Date: Wed, 26 Aug 2026 16:29:14 +0100 Subject: [PATCH 2/2] chore: remove test credentials from the demo app's documentation MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The AuthApi KDoc published a working email and password pair — a real corporate address alongside `secret123` — for a live Forge-hosted backend. The host now returns 522 (Cloudflare up, origin gone), so it appears decommissioned, but the pairing should not have been committed regardless: an email and password published together are what credential-stuffing lists are built from, and that risk attaches to the address rather than to the server. Scrubbing the file does not undo it — git history keeps both values — so treat them as harvested and rotate the password anywhere it was reused. Also notes at BASE_URL that the host is gone, so the next person to try the network-backed parts of the demo learns it from the source rather than from a timeout. Co-Authored-By: Claude Opus 5 (1M context) --- .../uk/co/appoly/droid/network/TestBackendApis.kt | 12 ++++++++---- .../droid/network/TestBackendRetrofitClient.kt | 5 +++++ 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/app/src/main/java/uk/co/appoly/droid/network/TestBackendApis.kt b/app/src/main/java/uk/co/appoly/droid/network/TestBackendApis.kt index e54ed72..8e2588b 100644 --- a/app/src/main/java/uk/co/appoly/droid/network/TestBackendApis.kt +++ b/app/src/main/java/uk/co/appoly/droid/network/TestBackendApis.kt @@ -57,7 +57,7 @@ import uk.co.appoly.droid.data.remote.BaseService * ```json * { * "email": "user@example.com", - * "password": "secret123" + * "password": "" * } * ``` * @@ -83,9 +83,13 @@ import uk.co.appoly.droid.data.remote.BaseService * ``` * * ## Test Credentials - * The test server accepts these credentials: - * - Email: `bradley@appoly.co.uk` - * - Password: `secret123` + * None are published here. The backend this demo was written against + * (a throwaway server used while building the multipart uploader) has been decommissioned, and + * real credentials do not belong in a public repository regardless — an email and password + * committed together are what credential-stuffing lists are built from. + * + * To exercise this against a live backend, point [TestBackendRetrofitClient.BASE_URL] at your own + * server and supply your own account. * * @see LoginRequest * @see LoginResponse diff --git a/app/src/main/java/uk/co/appoly/droid/network/TestBackendRetrofitClient.kt b/app/src/main/java/uk/co/appoly/droid/network/TestBackendRetrofitClient.kt index 0e43893..1fb11d2 100644 --- a/app/src/main/java/uk/co/appoly/droid/network/TestBackendRetrofitClient.kt +++ b/app/src/main/java/uk/co/appoly/droid/network/TestBackendRetrofitClient.kt @@ -75,6 +75,11 @@ class TestBackendRetrofitClient( * This server provides: * - `/api/login` - Authentication endpoint * - `/api/s3/multipart/x` - Multipart upload endpoints + * + * **This host is no longer running.** It was a throwaway backend stood up while building + * the multipart uploader and has since been decommissioned, so the network-backed parts of + * this demo will fail until you point this at a server of your own implementing the two + * endpoint groups above. The rest of the demo app does not depend on it. */ const val BASE_URL = "https://multipart-uploader.on-forge.com/"