fix(mobile): Remote video playback and asset download on Android with mTLS #16403
+95
−12
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This is a first stab at supporting remote video playback and asset download for servers which require a client certificate (mTLS). Some discussions about this topic can be found in #15230.
The underlying problem is that these parts of the app don't use Dart's HTTPS client, but the native one, which obviously doesn't care about the
HttpOverride
. This (Android-only) implementation does a similar thing though by setting the default SSL context for the native sockets.It shouldn't be a big deal to allow self-signed certificates by providing a
TrustManager
, but I first want to be sure that this approach is acceptable.The only feasible alternative seems to be switchiting to cronet, but I think my way is much less intrusive.
How Has This Been Tested?
I've configured my nginx reverse proxy to require mTLS and it's working fine with that. Further tests to be done for "normal" setups and iOS (I only have Android though).
Checklist:
src/services
uses repositories implementations for database calls, filesystem operations, etc.src/repositories/
is pretty basic/simple and does not have any immich specific logic (that belongs insrc/services
)