Releases: vastavikCodingStuff/vastavikLearning-app
Release list
v1.0.62 - Clerk Auth with Email OTP & OAuth, Watermark Removal & Capture Overlay Fix
Vastavik Learning v1.0.62 - Release Notes
Welcome to Vastavik Learning v1.0.62! This release adds full Clerk authentication (email + OTP, Google & GitHub OAuth), removes the app-wide privacy watermark, kills the false-positive "SCREEN CAPTURE BLOCKED" overlay, fixes the blank Practice tabs after deleting everything, and hardens the login/sign-up error UX — plus a required Android toolchain bump (AGP 8.9.1, Kotlin 2.4.20, compileSdk 36).
What's New and Improved
1. Clerk Authentication — Email/Password + Email OTP + Google & GitHub OAuth
- Opt-in by key: set
CLERK_PUBLISHABLE_KEY=pk_...inlocal.propertiesand the app switches all sign-in/sign-up to Clerk; leave it blank and the existing backend/Firebase auth keeps working untouched (VastavikApplication.ktinitializescom.clerk.api.Clerkonly when the key is present). - Sign-up with email OTP:
SignupScreennow has a verification step —AuthViewModel.signUpWithClerkcreates the Clerk sign-up, sends the code (sendCode), and the form swaps to a 6-digit code field with Verify Email, Resend, and Use a different email controls;verifyClerkOtpcompletes it (verifyCode(code, VerificationType.EMAIL)). Password policy follows Clerk (min 8 chars) when enabled. - Sign-in:
signInWithClerkusessignInWithPassword; aNEEDS_SECOND_FACTOR/NEEDS_CLIENT_TRUSTstatus routes into the same OTP step (sendMfaEmailCode+verifyMfaCode(..., EMAIL_CODE)). The Sign in with Google and Sign in with GitHub buttons go throughClerk.auth.signInWithOAuth(OAuthProvider.GOOGLE/GITHUB)when Clerk is enabled — the SDK'sSSOReceiverActivityhandles theclerk://<appId>.callbackredirect (auto-merged from the Clerk AAR, no manifest change needed). - Backend session bridge: after any Clerk flow,
ClerkSessionBridgeexchanges the Clerk session token (Clerk.auth.getToken()) for this backend's own JWTs via the newPOST /api/v1/auth/clerk(backend verifies the token against Clerk's JWKS + issuer, resolves the email from claims orGET /v1/users/{sub}, then provisions/links the user by email so existing accounts merge). Every existing API call keeps working unchanged. - Session restore:
SplashScreennow accepts a backend JWT or a live Clerk session (AuthViewModel.hasPersistedSession()), re-bridging to backend tokens on cold start;signOut()also revokes the Clerk session. - Errors stay inline: every Clerk failure (
errorMessage) flows into the existingformErrorline under the buttons — never a toast.
2. "SCREEN CAPTURE BLOCKED" False Positives Fixed
SecurityProtectionManagernow reveals the blocked message only when the app is still resumed 250 ms after a focus-loss trigger, and cancels stale blackout jobs the moment focus returns — brief window switches no longer flash the overlay (isBlockedMessageVisible+setActivityResumed+blackoutJobcancellation).FocusLossBlackoutCurtainshows the message only whenshowMessageis set, with clearer copy: "Another app is covering this screen or a screenshot was attempted…". Screenshot detection (Activity.ScreenCaptureCallback, API 34+) and the app-switcher peek trigger still get the message; key-based triggers are unchanged.
3. Practice Tabs — Real Empty States That Survive Deletion
- All four tabs (MCQ, Predict the Output, Coding, PYQ) render an
EmptyState(icon, message, "tap + icon", CTA that opens the AI generate dialog) instead of a blank screen. - Seeding now keys off
VastavikAiDiskCache.hasSaved*(prefs.contains) instead of the in-memory list, so deletions persist across restarts — the tabs no longer resurrect wiped content or show empty white space. - PYQ rows gained a delete button (trash icon →
savePYQs+ toast), mirroring MCQ/Coding/Predict.
4. Watermark & Auth UX Cleanup
- Removed the app-wide
PrivacyWatermarkOverlay, its component file, the "Anti-Leak Forensic Watermark" settings row, and updated the emulator banner/curtain copy that still mentioned it. - Login & Sign Up validate inline (email pattern, required fields, password ≥ 6/8, confirm match) and show all server errors as red text under the primary button — no more floating toasts.
- GitHub sign-in (non-Clerk mode): real browser OAuth flow via
GitHubOAuth.kt(SecureRandom state,vastavik://oauth/githubdeep link,MainActivity.handleOAuthRedirect), with friendly messaging for the backend's 501 whenGITHUB_CLIENT_ID/GITHUB_CLIENT_SECRETaren't set on Render.
5. Toolchain Bump Required by Clerk (AGP 8.9.1 / Kotlin 2.4.20 / compileSdk 36)
- Gradle: AGP
8.7.3 → 8.9.1, Kotlin2.0.20 → 2.4.20, Hilt2.52 → 2.58,compileSdk 35 → 36(targetSdk stays 35, minSdk 24) — Clerk 1.1.9's AARs require API 36. - Migrations:
jvmTargetmoved to thekotlin { compilerOptions { ... } }DSL in both modules;kotlin-metadata-jvm:2.4.20pinned on the kapt classpath (Dagger/Hilt must read Kotlin 2.4 metadata); OkHttp resolves to 5.4.0 (Clerk's line) with a packaging exclude for the duplicateMETA-INF/versions/9/OSGI-INF/MANIFEST.MF. - Verified:
.\gradlew.bat :app:assembleDebugand:app:assembleRelease :companion-codeoss:assembleReleaseboth BUILD SUCCESSFUL (R8 kotlin-metadata warnings are non-fatal); backendpy_compile+ module import pass.
6. Version Bump
- App
versionCode 62/versionName 1.0.62(app/build.gradle.kts:21) and CompanionversionCode 29/versionName 1.0.62(companion-codeoss/build.gradle.kts:15).
Release Assets
| Asset | Description | Size |
|---|---|---|
| vastavikLearning-v1.0.62.apk | Main Vastavik Learning Android app (versionCode 62, versionName 1.0.62, minSdk 24, targetSdk 35) | ~61.6 MB |
| vastavik-codeoss-extension.apk | CodeOSS Companion Extension Pack with Monaco/VS Code Web and Ubuntu Terminal (versionCode 29, versionName 1.0.62) | ~13.4 MB |
Upgrade Notes
- Install
vastavikLearning-v1.0.62.apkover your existing build — user data, login session, anduser_profileprefs are preserved. The companion APK installs side-by-side. - To enable Clerk: add
CLERK_PUBLISHABLE_KEY=pk_...to the app'slocal.properties(placeholder already added; blank = built-in auth stays active), enable Google/GitHub connections in the Clerk Dashboard, then on Render setCLERK_PUBLISHABLE_KEYandCLERK_SECRET_KEYand redeployvastavikLearning-backend-appsoPOST /api/v1/auth/clerkcan issue backend JWTs. - GitHub sign-in without Clerk: set
GITHUB_CLIENT_ID/GITHUB_CLIENT_SECRETon Render (the endpoint currently returns a friendly 501 until then). - New backend dependencies already in
requirements.txt(pyjwt>=2.8.0) — no Python package changes required.
Built with love by the Vastavik Learning Team
v1.0.61 - Curriculum Delete & Video Not Found Fix
Vastavik Learning v1.0.61 - Release Notes
Welcome to Vastavik Learning v1.0.61! This release fixes the Curriculum Editor delete flow and the “Video not found” error that appeared for every lesson, plus the underlying backend lesson-resolution that was hitting the wrong document.
What's New and Improved
1. Curriculum Editor — Delete for Lessons and Collections
- Per-lesson delete: each lesson row in
String in Java / Functions in Java / Array in Javanow shows a trash button on the right. Tap → confirmDelete lesson "X" from this part?→ optional second confirmAlso delete the linked video file itself?→ the row disappears optimistically, rolls back and shows an alert if the server fails, then refetches. Useshooks/useCourses.ts: add removeLessonFromPart / removePart(optimistic + localStorage +DELETE /admin/courses/{cid}/parts/{pid}/subparts/{sid}?delete_video=true). - Per-collection delete: each part header (
1 String in Java — 4 lessons,2 Functions in Java — 1 lessons,3 Array in Java — 0 lessons) now has Delete Part next to Add Video Lesson (red outline, trash icon). Confirm → deletes the whole part and all its lessons. - Backend: new
DELETE /admin/courses/{courseId}/parts/{partId}/subparts/{subpartId}(cascades nestedlessonssubcollection, optional?delete_video=truefor flatvideos/{id}, theninvalidate_catalog_cache()) andDELETE /admin/courses/{courseId}/parts/{partId}(cascades all subparts + nested lessons) inapp/routers/admin_dashboard.py:1911.
2. “Video not found — pull to refresh Learn and try again” Fixed for Every Lesson
- Root cause:
GET /api/v1/courses/{id}/curriculumreturnslesson_id = subpart.lesson_id or subpart_doc.id. For manually created subparts with nolesson_idfield, the app received the subpart doc ID (e.g.8kdGIQMKX7dCbBv81m1Din your screenshot) as the lesson ID, butdb.get_lesson()only searched flatvideos+collection_group("lessons")— never the subpart itself. - Backend fix:
app/db/firebase.py:472get_lessonnow has step 3 —collection_group("subparts")search: if the subpart doc itself carriesyoutubeUrl/youtubeVideoIdit is returned as a lesson, else its nestedlessonssubcollection is checked (exact id, else first), else the linked flatvideos/{lesson_id}is followed. Addedget_lesson_by_subpart(course, part, subpart)and newGET /api/v1/lessons/by-subpart/{course}/{part}/{subpart}inapp/routers/catalog.py:129that reuses the same premium/normalization path. - App fix:
VideoLessonViewModel.kt:36now triesgetLessonV1(lessonId)(title/desc/whiteboard/code), thengetLessonBySubpart(course, part, subpart)(fixes your “Testing — vid_1789106985472” and all8kd...cases), then legacygetLesson, then one-shotstreamLessons().first()with timeout — never hangs, always clearsisLoadingwith a clear Retry / Back to Learn error instead of a spinner. - If videos still 404 after deploy:
GET /api/v1/health/firestoreon the backend will now reportuse_live_firestore: falsewith an explicit in-memory warning — setFIREBASE_CREDENTIALS_BASE64on Render so uploads persist and are visible to the app's direct Firestore listeners.
3. Version Bump for Hotfix
- App
versionCode 61/versionName 1.0.61(app/build.gradle.kts:21) and CompanionversionCode 28/versionName 1.0.61(companion-codeoss/build.gradle.kts:15).
Release Assets
| Asset | Description | Size |
|---|---|---|
| vastavikLearning-v1.0.61.apk | Main Vastavik Learning Android app (versionCode 61, versionName 1.0.61, minSdk 24, targetSdk 35) | ~59.3 MB |
| vastavik-codeoss-extension.apk | CodeOSS Companion Extension Pack with Monaco/VS Code Web and Ubuntu Terminal (versionCode 28, versionName 1.0.61) | ~13.4 MB |
Upgrade Notes
- Install
vastavikLearning-v1.0.61.apkover your existing build — user data, login session, anduser_profileprefs are preserved. The companion APK is side-by-side. - After upgrading, open Curriculum Editor — every lesson row now has a trash button and every part header has Delete Part. After deleting, pull to refresh Learn (the Refresh button on the Learn row) and the Duolingo path updates instantly.
- If a video still shows “Video not found” after an admin upload, check
GET /api/v1/health/firestoreon the backend — an in-memory warning there means Firestore credentials are missing on Render.
Built with love by the Vastavik Learning Team
v1.0.60 - Neo Square Update Banner, Instant Learn Refresh & Video Fixes
Vastavik Learning v1.0.60 - Release Notes
Welcome to Vastavik Learning v1.0.60! This release makes the update gate unmissable with a Neo Brutalistic square banner, wires the Learn feed for instant video updates, fixes lesson loading so titles and descriptions always appear, and rounds out the admin video workflow with whiteboard, code, and shorts alongside every link.
What's New and Improved
1. Neo Brutalistic Square Update Banner — Thick Black Borders, Centered, With UPDATE Button
- Replaced the old pill
Update Required — Tap the red banner above to updatewith a square Neo Brutalistic banner in the middle of the grey blocking overlay (ui/screens/home/HomeScreen.kt:676). - Style: white square,
RoundedCornerShape(20.dp), 6dp black offset shadow for the thick bottom/right borders, red warning icon block, all-capsUPDATE REQUIRED, theYou can't use the app without updating it...message, and a full-width redUPDATE NOWbutton (Border 2.5dp black) that navigates straight toapp_update. - Behaviour unchanged: the rest of the app stays greyed and non-interactive until updated; only the top bar, red banner, and this square banner respond.
2. Learn Feed Refresh — Button on the Right of the Course Chips
- Moved the Refresh control into the same row as the course chips (
Java for ICSE Class 10,Kotlin Classes Begeineers, ...) —LazyRow(weight=1f)+FilledTonalButton(Refresh)on the right (LearningPathScreen.kt:150). - Same force path:
LearningViewModel.refresh()callsGET /api/v1/catalog/home?force=trueandGET /api/v1/courses/{id}/curriculum?force=true, so videos uploaded in the admin panel appear in the Duolingo path instantly.
3. Lesson Loading — Titles and Descriptions Always Appear
- Root cause fixed:
VideoLessonViewModel.loadLesson()tried the legacy endpoint first and then hung forever in an infinite Firestorecollect, leavingtitle ?: "Loading..."on screen. - Now: tries canonical
GET /api/v1/lessons/{id}first (real title/description/whiteboard/code from admin), then legacy endpoints, then a one-shot Firestore read with an 8-second timeout —isLoadingalways clears with a clear error plus Retry and Back to Learn buttons. - Invalid links: the player now explains the fix (
needs an 11-character video ID — ask admin to check the URL, pull to refresh Learn after) and reportsonError("invalid_video_link"); the backend rejects bad links with 400 at upload time.
4. Learn With Vastavik Playback, Likes, Comments
- Branding: new
Learn with Vastavikheader chip (+ PRO badge) above the player; unlisted videos play via the existing modest-branding player with the anti-YouTube-logo shield, so students never see a bare YouTube frame. Admin keeps the live preview screenshot in the modal. - Engagement works: like/dislike/comment states persist per lesson in
lesson_feedbackprefs and emitvideoLike/video_dislike/video_commenttelemetry, surviving process death.
5. Admin Videos + Backend Health
- Upload modal: whiteboard (URL + 5 MB image upload), code sample, and shorts URL are now always visible alongside the video link, with privacy (
public/unlisted/private) and published toggles; cards show privacy/whiteboard/code/draft pills. - Backend: new
GET /api/v1/health/firestore(live-vs-memory, project, collection counts with an explicit in-memory warning),POST /api/v1/admin/uploads/whiteboard, and an empty-catalog warning log sothings not loadingis diagnosable in one call.
Release Assets
| Asset | Description | Size |
|---|---|---|
| vastavikLearning-v1.0.60.apk | Main Vastavik Learning Android app (versionCode 60, versionName 1.0.60, minSdk 24, targetSdk 35) | ~59.3 MB |
| vastavik-codeoss-extension.apk | CodeOSS Companion Extension Pack with Monaco/VS Code Web and Ubuntu Terminal (versionCode 27, versionName 1.0.60) | ~13.4 MB |
Upgrade Notes
- Install
vastavikLearning-v1.0.60.apkover your existing build — user data, login session, anduser_profileprefs are preserved. The companion APK installs side-by-side. - If Render lacks
FIREBASE_CREDENTIALS_BASE64, hitGET /api/v1/health/firestore— an in-memory warning there explains any missing uploads; set the secret and redeploy to restore live sync. - After upgrading, open Learn, tap the Refresh button at the right of the course chips, and new admin videos appear without killing the app.
Built with love by the Vastavik Learning Team
v1.0.59 - Learn Refresh Hotfix (Build Fix)
Vastavik Learning v1.0.59 - Release Notes
Welcome to Vastavik Learning v1.0.59! This hotfix corrects the Learn screen build failure introduced while adding instant refresh, leaving the refresh button intact for instant video updates after admin uploads. The app now builds cleanly and the Learn Duolingo path refreshes on demand.
What's New and Improved
1. Learn Screen Build Fix (Brace Correction)
- Fix: removed the extra
PullToRefreshBoxwrapper that causedExpecting a top level declarationatLearningPathScreen.kt:641duringkaptGenerateStubsReleaseKotlin. - Kept: the Refresh button inside the
LazyColumn(after course chips) that callsviewModel.refresh()withforce=true—GET /api/v1/catalog/home?force=trueandGET /api/v1/courses/{id}/curriculum?force=trueplusinvalidate_catalog_cache()on the backend — so new videos appear instantly when Learn is re-clicked or the button is tapped (Duolingo-style path updates). - Result:
BUILD SUCCESSFUL in 6m15s, notar.gz/zip, only the two APKs.
2. Version Bump for Hotfix
- App
versionCode 59/versionName 1.0.59(app/build.gradle.kts:21) and CompanionversionCode 26/versionName 1.0.59(companion-codeoss/build.gradle.kts:15) so the updater correctly detects1.0.58 → 1.0.59.
Release Assets
| Asset | Description | Size |
|---|---|---|
| vastavikLearning-v1.0.59.apk | Main Vastavik Learning Android app (versionCode 59, versionName 1.0.59, minSdk 24, targetSdk 35) | ~60.6 MB |
| vastavik-codeoss-extension.apk | CodeOSS Companion Extension Pack with Monaco/VS Code Web and Ubuntu Terminal (versionCode 26, versionName 1.0.59) | ~13.4 MB |
Upgrade Notes
- Install
vastavikLearning-v1.0.59.apkover your existing build — user data, login session, anduser_profileprefs are preserved. The companion APK is side-by-side. - After this update, the Learn tab's Refresh button and the backend
?force=truecache bust ensure that videos uploaded inhttps://vastavikadmin.vercel.app/dashboard/videosappear in the app's Duolingo path without killing the app. - If you are on
1.0.58and saw a build failure in CI, this hotfix resolves it; no data migration is needed.
Built with love by the Vastavik Learning Team
v1.0.57 - Dynamic Learn Screen Curriculum & Security Remediation
Vastavik Learning v1.0.57 Release Notes
🚀 Dynamic Curriculum in Learn Screen & Strix Security Audit Remediation
1. Dynamic Course & Curriculum Synchronization in Learn Screen
- Real Backend & Firestore Curriculum: Replaced hardcoded courses and static nodes with dynamic data from \LearningViewModel.
- Live Modules on Winding Road: The course road now dynamically displays the exact modules configured in the Curriculum Editor (e.g. String in Java, Functions in Java, Array in Java).
- Interactive Video Lesson Drawer: Tapping a module opens the lesson drawer rendering real video lessons (String Function Making, Question solving, Function arguemenets) with lesson IDs and direct navigation to the video player.
- Dynamic Course Switcher: Course chips at the top dynamically render all published courses (Java Class 10, Kotlin Classes for Beginners, etc.) with live curriculum switching.
2. Security Vulnerability Remediations
- IDOR Remediation (CWE-639): Enforced strict JWT authentication on search and practice history endpoints, removing unauthenticated client \uid\ overrides.
- Client-Controlled Identity Elimination (CWE-807): Enforced JWT authentication on practice submissions and AI telemetry sync, ensuring identity is bound to verified bearer tokens and enforcing document ownership checks.
- Log Privacy Protection (CWE-532): Replaced unredacted chat prompt/response logging in \ChatScreen.kt\ with privacy-safe \ActivityLog.aiChat\ while preserving full conversational history in the dedicated \�i_chat_sessions\ Firestore store for admin inspection.
📦 Release Assets
- **\�astavikLearning-v1.0.57.apk**: Main Vastavik Learning Android Application (\�ersionCode = 57)
- **\�astavik-codeoss-extension.apk**: CodeOSS Companion Extension APK (\�ersionCode = 24)
v1.0.56 - Cross-Device Sync, Practice & Search Telemetry, Admin Inspection Console
Vastavik Learning v1.0.56 Release Notes
🚀 Cross-Device Synchronization, Comprehensive Practice Telemetry & Admin Audit Console
1. User-Scoped Isolation & Cross-Device Sync
- Identity & Token Persistence: Securely persisted \userId,
ame, and \email\ in \TokenManager\ across all authentication flows (Email, Google, GitHub, and profile fetch). - User-Isolated Storage: Chat conversation caches are strictly isolated per student (\�i_conversations_.json), preventing conversation leakage when switching accounts on shared devices.
- Cross-Device Remote Restoration: Historical AI chat conversations are automatically restored from the backend database whenever a student logs in on any Android device.
2. Full Student Practice & Activity Telemetry
- Predict the Output Evaluation: Captures the student's typed prediction, the actual execution output, pass/fail verdict, and AI explanation to both local activity logs and backend database.
- Coding Practice Tracking: Logs code generation requests, student prompt requirements, and generated solutions.
- MCQ & Quiz Telemetry: Captures overall quiz scores, percentages, and question-by-question choices (student selection vs correct answer).
- In-App Search Auditing: Live search connected to catalog with debouncing, logging all search queries to Firestore and /api/v1/search.
3. Admin Inspection Console
- Student profile inspection console with 5 dedicated tabs:
- Overview: Student credentials, stats, joined/last active timestamps.
- Activity Timeline: Chronological stream of all student actions.
- Search Audit: Audit trail of search queries with timestamp and result counts.
- AI Chats: Interactive session selector and message viewer with student questions and AI responses.
- Practice History: Detailed cards with filters for MCQ attempts, Predict Output (showing code snippet, student guess vs actual output, verdict, and explanation), and Coding solutions.
- Code Runs: Historical Judge0 execution logs.
📦 Release Assets
- **\�astavikLearning-v1.0.56.apk**: Main Vastavik Learning Android Application (\�ersionCode = 56)
- **\�astavik-codeoss-extension.apk**: CodeOSS Companion Extension APK (\�ersionCode = 23)
v1.0.55 - Companion CodeOSS Extension Rendering Fix for BlueStacks & Android 9
Vastavik Learning v1.0.55 Release Notes
🚀 Companion CodeOSS Extension Rendering Fix & BlueStacks/Android 9 Hardware Compatibility
1. Root-Cause Resolution for Black/Blank Screen on Launch
- Direct Native WebView Content View: Eliminated Compose
AndroidViewsurface wrapping incompanion-codeoss/MainActivity.kt. DirectsetContentView(webView)completely resolves the OpenGL hardware layer composition conflict between Android Compose canvas and WebView on BlueStacks App Player and Android 9 (Pie 64-bit). - Correct Viewport & File URL Settings:
- Configured
allowFileAccessFromFileURLs = trueandallowUniversalAccessFromFileURLs = trueso local assets and Monaco loader modules load seamlessly without CORS/file-scheme restriction errors. - Set
useWideViewPort = falseandloadWithOverviewMode = falseto prevent desktop viewport scaling and keep responsive 100% mobile view dimensions. - Set
cacheMode = LOAD_NO_CACHEandmixedContentMode = MIXED_CONTENT_ALWAYS_ALLOW. - Added
WebChromeClientandWebViewClientwith verbose console logging and error diagnostics.
- Configured
2. Viewport & Flex Container CSS Hardening (vscode/index.html)
- Replaced
width: 100vw; height: 100vh;withposition: absolute; top:0; left:0; right:0; bottom:0; width:100%; height:100%;to prevent WebView measurement race conditions. - Added
min-width: 0; min-height: 0;to all flex containers (#workspace-body,#main-stage,#terminal-pane,.term-body,#editor-pane,#monaco-mount), preventing flexbox container overflow.
3. Decoupled UI & Terminal Execution from Monaco Loader
- Decoupled the top application bar, activity bar, file explorer, status bar, and interactive Ubuntu terminal from the Monaco AMD loader.
- Terminal session (
projects $,npm run dev,curl -s :3000,python3 -V, etc.) renders immediately upon app launch with 0ms delay. - Monaco Editor initializes gracefully in the background and mounts safely with defensive error handling.
4. Zero Password Barrier & Instant Access
- Directly launches straight into the official VS Code Code-Server workspace and terminal.
- No password prompt or authentication screen.
📦 Release Assets
vastavikLearning-v1.0.55.apk: Main Vastavik Learning Android Application (versionCode = 55)vastavik-codeoss-extension.apk: CodeOSS Companion Extension APK (versionCode = 22)app-debug.apk: Standard Debug APK for Main Appcompanion-codeoss-debug.apk: Standard Debug APK for Extension App
v1.0.54 - Official Mobile VS Code Code-Server UI & Ubuntu APT Terminal
Vastavik Learning v1.0.54 Release Notes
💻 Official Mobile VS Code Code-Server UI & Ubuntu Terminal Suite
1. 100% Pixel-Perfect Mobile VS Code Web / Code-Server UI (companion-codeoss)
- Replaced custom layout and emoji elements with the official mobile VS Code Code-Server design system:
- Top Application Bar: Includes the official VS Code logo, navigation arrows (
←/→), central breadcrumb pill (projects ~ ⌄), and four window layout toggles (Split Editor, Primary Side Bar, Terminal Panel, Secondary Side Bar). - Activity Bar: Full set of crisp vector Codicons (Hamburger
≡, Explorer, Search, Source Controlgit, Run & Debug, Extensions, Testing, Account, Settings). - Primary Side Bar (EXPLORER): Features collapsible
PROJECTSsection with file badges (README.mdMarkdownM↓,server.jsJavaScriptJS, andpackage.jsonJSON{ }), plus collapsibleOUTLINEandTIMELINEsections. - Status Bar: Clean dark status bar matching VS Code modern theme with remote connection indicator (
><), diagnostics (⊗ 0 ▲ 0),Layout: us,✓ Prettier, amber notification pill (⚡ 5), and notification bell.
- Top Application Bar: Includes the official VS Code logo, navigation arrows (
2. Interactive Sandboxed Ubuntu & Node Terminal (UbuntuTerminalEngine.kt)
- Updated terminal prompt to
projects $in high-contrast terminal green. - Pre-populated and fully interactive commands matching the reference terminal session:
npm run dev&node server.js(Up on 3000)curl -s :3000(multiline JSON response)python3 -V(Python 3.12.11)git --version(git version 2.55.0)npm -v(11.6.1)rg --version(ripgrep 14.1.1)tmux ls(dev: 2 windows (attached))
- Built-in headless Ubuntu APT package manager simulation (
apt update,apt install <pkg>,apt list,apt search). - Touch accessory bar with quick navigation keys (
ESC,TAB,CTRL+C,|,~,/,-,UP,DOWN,NPM,CURL,APT).
3. Zero Authentication / Password Barrier
- Completely bypasses any login/auth wall on application launch:
- Opens straight into the mobile Code-Server workspace immediately.
- No Code Server password dialog or authentication prompt.
4. Monaco Code Editor & Multi-Window Layout
- Real-time syntax highlighting for Markdown, JavaScript, JSON, and Python.
- Seamless one-tap toggling between Editor, Terminal, or Split view via the top layout controls.
- Auto-saves file edits directly into sandboxed workspace storage.
📦 Release Assets
vastavikLearning-v1.0.54.apk: Main Android Application (versionCode = 54)vastavik-codeoss-extension.apk: CodeOSS Companion Extension (versionCode = 21)source_v1.0.54.zip: Complete source code archive (.zip)source_v1.0.54.tar.gz: Complete source code archive (.tar.gz)
v1.0.53 - YouTube Video Pipeline Resilience, Player Fallback & PIN Security
Vastavik Learning v1.0.53 Release Notes
🎬 YouTube Video Lecture Pipeline & Player Enhancements
1. Robust Multi-Format YouTube Video ID Extraction (HmacUtil.kt)
- Full support for:
- Direct 11-character video IDs (with leading/trailing whitespace trimming)
- Standard watch URLs (
youtube.com/watch?...v=IDregardless of query parameter order) - Shortened URLs (
youtu.be/IDwith or without?si=tracking parameters) - YouTube Shorts (
youtube.com/shorts/ID) - Embeds and Live stream URLs (
youtube.com/embed/ID,youtube.com/live/ID)
- Prevents unlisted or mobile-shared URLs from failing video ID resolution.
2. Dual Naming Persistence & Resilient Deserialization (CourseModel.kt & admin_dashboard.py)
- Upgraded
LessonModel.fromSnapshot()to parse bothsnake_case(youtube_url,youtube_video_id,duration_sec,video_format) andcamelCase(youtubeUrl,youtubeVideoId,durationSec,videoFormat) Firestore attributes. - Fixed root cause where admin web uploads stored in snake_case resolved to empty video IDs in direct Firestore stream listeners.
- Backend
/admin/videosnow persists both naming conventions simultaneously.
3. Fail-Safe Video Player with Direct Fallback (VastavikYouTubePlayer.kt)
- Added resilient video ID resolution directly in the player composable.
- If YouTube's embedded player encounters an embedding block (e.g. "Allow embedding" not yet saved by creator) or temporary playback error, the player displays an informative message along with an "Open Video" button that seamlessly opens the lecture in the YouTube app or browser so students are never blocked.
4. Emulator Security PIN UI Cleanup (EmulatorSecurityCurtain.kt)
- Removed hardcoded
vastavik2026password from the UI placeholder and error messages while keeping the admin bypass PIN active for developer testing.
📦 Release Assets
vastavikLearning-v1.0.53.apk: Main Android Application (versionCode = 53)vastavik-codeoss-extension.apk: CodeOSS Companion Extension (versionCode = 20)source_v1.0.53.zip: Complete source code archive (.zip)source_v1.0.53.tar.gz: Complete source code archive (.tar.gz)
v1.0.52 - Enterprise Security Hardening & Full Vulnerability Remediation
Vastavik Learning v1.0.52 Release Notes
🛡️ Comprehensive Security Hardening & Vulnerability Remediation (OWASP MASVS & Strix Pentest)
1. Companion CodeOSS Extension (com.vastavik.codeoss)
- WebView Sandbox & RCE Defense:
- Intercepts all WebView navigation via
shouldOverrideUrlLoading. External web links are prohibited from running inside the internal IDE WebView and safely redirected to the system browser viaIntent.ACTION_VIEW. - Enforced
mixedContentMode = MIXED_CONTENT_NEVER_ALLOWandjavaScriptCanOpenWindowsAutomatically = false. - Restricted
connectCodeServer(serverUrl)strictly to127.0.0.1andlocalhost. - Sanitized all dynamic parameters injected into JavaScript (
onReady,appendTerminalLine,askMistral,loadPayload) withorg.json.JSONObject.quote(), eliminating script injection vulnerabilities.
- Intercepts all WebView navigation via
- Ubuntu Sandbox Path Traversal Guard (
UbuntuTerminalEngine.kt):- Implemented
getSafeWorkspaceFile()with canonical path validation onreadFileContent(),saveFileContent(),createFile(), anddeleteFile(). - Directory traversal attempts (
../) escaping the workspace sandbox are strictly blocked.
- Implemented
- Inter-App Signature Permission:
- Protected
com.vastavik.codeoss.OPEN_EDITORwith custom signature-level permissioncom.vastavik.codeoss.permission.OPEN_EDITOR. - Disabled
android:allowBackup="false"to prevent data extraction via ADB.
- Protected
2. Main Mobile App (com.vastavik.computer)
- Hardware-Backed Keystore AES-256-GCM Token Storage (
TokenManager.kt):- Upgraded session token persistence from plaintext SharedPreferences to hardware-backed
AndroidKeyStoreAES-256-GCM authenticated encryption.
- Upgraded session token persistence from plaintext SharedPreferences to hardware-backed
- Network Security Configuration:
- Deployed
network_security_config.xmlenforcing strict TLS/HTTPS everywhere (cleartext permitted only for local developer emulator loopback10.0.2.2). - Disabled
android:allowBackup="false"inAndroidManifest.xml.
- Deployed
- R8 Minification & Obfuscation:
- Enabled
isMinifyEnabled = trueandisShrinkResources = truein release builds with optimized ProGuard rules.
- Enabled
3. Backend Engine (vastavikLearning-backend-app)
- File Upload Extension & MIME Allowlisting:
- Doubts and Bug Report attachments strictly allow only safe image/doc formats (
.jpg,.jpeg,.png,.webp,.pdf,.txt,.log). - Disallows
.html,.svg,.js, and executables, preventing Stored XSS.
- Doubts and Bug Report attachments strictly allow only safe image/doc formats (
- Upload Sandbox Security Headers:
- Injected
Content-Security-Policy: default-src 'none'; sandboxandX-Content-Type-Options: nosnifffor all/uploadsstatic resources.
- Injected
📦 Release Assets
vastavikLearning-v1.0.52.apk: Main Android Application (versionCode = 52)vastavik-codeoss-extension.apk: CodeOSS Companion Extension (versionCode = 20)source_v1.0.52.zip: Complete source code archive (.zip)source_v1.0.52.tar.gz: Complete source code archive (.tar.gz)