You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 304a46c
Browse filesBrowse the repository at this point in the historyBrowse files
ADFA-4751: Rebrand remaining Sentry references to GlitchTip (#1548)
* ADFA-4751: Rebrand remaining Sentry references to GlitchTip
The functional migration (ADFA-4397) kept the io.sentry SDK because
GlitchTip is Sentry-protocol-compatible, and re-pointed only the DSN.
This is the follow-up branding cleanup it left behind.
User-facing / docs / naming:
- privacy_disclosure_message onboarding string (English + Indonesian):
now names GlitchTip instead of Sentry.
- REVIEW.md / SECURITY.md prose -> GlitchTip (kept the Sentry.captureException
code example, which is the real SDK API).
- Renamed our own identifiers: SentryDiagnosticsContext ->
GlitchTipDiagnosticsContext (file + test), SENTRY_ENV_* -> GLITCHTIP_ENV_*,
shouldReportToSentry -> shouldReportToGlitchTip, sentryLogAppender ->
glitchTipLogAppender.
- Backend/product comments and log strings -> GlitchTip.
Deliberately kept (would break crash reporting): all io.sentry.* imports and
Sentry.* API calls, the manifest io.sentry.* meta-data keys and ${sentryDsn}
placeholder, the io.sentry deps / plugin / sentry {} block, and the proguard
-keep io.sentry.** rules. Each kept anchor now carries a one-line note that the
Sentry SDK is our GlitchTip client. Historical "(Sentry APPDEVFORALL-####)"
provenance notes are left as-is.
Spotless (ratchet) retabbed a few touched files that were previously
space-indented; those whitespace-only hunks bring them to the tab standard.
Note: local.properties (gitignored) still uses old sentryDsn* keys pointing at
sentry.io while the build now reads GLITCHTIP_DSN -- a per-developer config
drift to fix separately, not part of this PR.
* ADFA-4751: Use ASCII hyphen in touched WhitelistEngineTest comment
Follow-up to code review: the retab re-touched this comment line, so
swap its pre-existing em-dash for an ASCII '-' per CLAUDE.md code-style.
Copy file name to clipboardExpand all lines: REVIEW.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,7 +16,7 @@ A review isn't done because it *looks* fine; it's done when you can **show what
16
16
| Area | Evidence to show |
17
17
|---|---|
18
18
| Ticket / feature completeness | Requirements list from ADFA-####, each mapped to code + test (or flagged missing) |
19
-
| §1 Exceptions | Where new failure paths are caught; nothing new can reach the Sentry wrapper |
19
+
| §1 Exceptions | Where new failure paths are caught; nothing new can reach the GlitchTip wrapper |
20
20
| §2 Leaks | LeakCanary result for the touched flows (clean, or the leak addressed) |
21
21
| §3 Threading/StrictMode | No new main-thread I/O or long compute; StrictMode run clean, no app-code whitelist |
22
22
| §4 Security | Which untrusted inputs were validated; secrets checked |
@@ -31,7 +31,7 @@ Keep it proportional — a two-line change needs a two-line ledger.
31
31
## The 60-second checklist
32
32
33
33
-[ ]**Feature complete:** does what the linked ticket asks — requirements implemented, intended flow covered by tests.
34
-
-[ ]**Exceptions** are handled locally — nothing unexpected reaches the global Sentry crash handler.
34
+
-[ ]**Exceptions** are handled locally — nothing unexpected reaches the global GlitchTip crash handler.
35
35
-[ ]**No leaks** LeakCanary would catch later: every register/open/subscribe has a matching unregister/close in the right lifecycle callback.
36
36
-[ ]**No main-thread disk/network I/O** — no new StrictMode violations, and no whitelisting of *our own* code.
37
37
-[ ]**Security:** untrusted input (zip entries, URLs, file paths, web-server requests) is validated; no secrets in code, logs, or analytics.
@@ -46,9 +46,9 @@ Keep it proportional — a two-line change needs a two-line ledger.
46
46
47
47
---
48
48
49
-
## 1. Exception handling — stay out of the Sentry crash wrapper
49
+
## 1. Exception handling — stay out of the GlitchTip crash wrapper
50
50
51
-
`IDEApplication` installs a global uncaught-exception handler (`handleUncaughtException`) that reports to **Sentry** and then runs the device/credential-protected loaders' handlers. An exception that escapes your code lands there and is recorded as a **crash**. That handler is a safety net, not a control-flow tool.
51
+
`IDEApplication` installs a global uncaught-exception handler (`handleUncaughtException`) that reports to **GlitchTip** and then runs the device/credential-protected loaders' handlers. An exception that escapes your code lands there and is recorded as a **crash**. That handler is a safety net, not a control-flow tool.
52
52
53
53
-**Catch where you can recover.** Wrap I/O, parsing, IPC to the `tooling-api`, git, and plugin calls. Convert failures into a sealed error state (`…UiEffect.ShowError`, `Result`, `BuildState.Failed`) the UI can render.
54
54
-**Never swallow silently.** A bare `catch (e: Exception) {}` hides bugs. At minimum log it; if it's notable-but-handled, report it explicitly with the established idiom:
@@ -89,7 +89,7 @@ This app extracts archives, runs a local web server, stores git credentials and
89
89
90
90
-**Injection / path traversal (Zip Slip):** template/project extraction (`ZipRecipeExecutor`) and any unzip must reject entries that resolve outside the target dir (`canonicalPath.startsWith(targetDir)`). Validate file paths built from user/project input.
91
91
-**SQL:** use parameterized queries (`rawQuery(sql, args)` with `?` placeholders), never string-concatenated SQL. (Existing `WebServer`/tooltip queries already do this — match them.)
92
-
-**Secrets & credential storage:** git tokens, keystore/signing passwords → `EncryptedSharedPreferences` / the Android Keystore, never plaintext files, never committed, **never logged or sent to analytics/Sentry**. Scrub secrets from breadcrumbs and exception messages.
92
+
-**Secrets & credential storage:** git tokens, keystore/signing passwords → `EncryptedSharedPreferences` / the Android Keystore, never plaintext files, never committed, **never logged or sent to analytics/GlitchTip**. Scrub secrets from breadcrumbs and exception messages.
93
93
-**Local web server (`WebServer`):** bind to loopback, scope what it serves, and don't reflect unsanitized input into responses. Treat every request as untrusted.
94
94
-**Network:** HTTPS only; no disabled TLS/hostname verification; verify git remotes.
95
95
-**Untrusted code/plugins:** respect the plugin manifest permission model (`plugin.permissions` in `AndroidManifest.xml`); don't widen plugin capabilities or load classes from untrusted sources without the manager's checks.
@@ -188,7 +188,7 @@ Hold the change to the patterns in [ARCHITECTURE.md](ARCHITECTURE.md). The key r
188
188
CoGo is meant to work **without a network** — editing, building, and running an app on-device must not depend on connectivity. Hold new work to that:
189
189
190
190
-**Degrade gracefully offline.** A feature that needs the network must still launch, explain itself, and leave the rest of the app usable when there's no connection — never block a core flow (edit/build/run) on a request.
191
-
-**Network calls are non-blocking and failure-tolerant.** Analytics, Sentry, and Gemini calls run off the main thread and must tolerate timeouts/failures silently (no crash, no hang, no lost user action). A dropped analytics event is acceptable; a dropped keystroke is not.
191
+
-**Network calls are non-blocking and failure-tolerant.** Analytics, GlitchTip, and Gemini calls run off the main thread and must tolerate timeouts/failures silently (no crash, no hang, no lost user action). A dropped analytics event is acceptable; a dropped keystroke is not.
192
192
-**No network on the critical path.** Don't introduce a connectivity dependency into startup, the editor, or the build pipeline.
193
193
-**Verify it offline.** For a change to a network-touching flow, actually exercise it with the network off — `adb shell svc wifi disable && adb shell svc data disable` (re-enable after), or airplane mode — and confirm the core edit/build/run flow still works. Add an explicit offline test case for the path rather than trusting it by inspection.
Copy file name to clipboardExpand all lines: SECURITY.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -78,7 +78,7 @@ We render content in WebViews (tooltips, markdown preview, APK viewer) and run a
78
78
### 6. Android component & data exposure
79
79
-**Exported components** — `activity`/`service`/`receiver`/`provider` with `android:exported="true"` and no permission is a standard finding. Export only what must be, and protect it with a signature-level permission. Validate all incoming `Intent` extras (intent-redirection / spoofing).
80
80
-**PendingIntent** — must be `FLAG_IMMUTABLE` unless mutability is genuinely required.
81
-
-**Insecure storage** — no `MODE_WORLD_READABLE/WRITEABLE`; don't put sensitive data on external/shared storage; don't log file contents, tokens, or PII (scanners flag `Log`/print of tainted data, and it also leaks into Sentry/analytics).
81
+
-**Insecure storage** — no `MODE_WORLD_READABLE/WRITEABLE`; don't put sensitive data on external/shared storage; don't log file contents, tokens, or PII (scanners flag `Log`/print of tainted data, and it also leaks into GlitchTip/analytics).
82
82
-**Manifest hygiene** — `android:allowBackup` and `android:debuggable` are flagged for sensitive apps; set deliberately.
83
83
- Request the minimum permissions; over-requesting is flagged.
0 commit comments