Skip to content

v1.0.52 - Enterprise Security Hardening & Full Vulnerability Remediation

Choose a tag to compare

@parthasdey2304 parthasdey2304 released this 09 Sep 06:10
· 12 commits to main since this release
513f475

Vastavik Learning v1.0.52 Release Notes

🛡️ Comprehensive Security Hardening & Vulnerability Remediation (OWASP MASVS & Strix Pentest)

1. Companion CodeOSS Extension (com.vastavik.codeoss)

  • WebView Sandbox & RCE Defense:
    • Intercepts all WebView navigation via shouldOverrideUrlLoading. External web links are prohibited from running inside the internal IDE WebView and safely redirected to the system browser via Intent.ACTION_VIEW.
    • Enforced mixedContentMode = MIXED_CONTENT_NEVER_ALLOW and javaScriptCanOpenWindowsAutomatically = false.
    • Restricted connectCodeServer(serverUrl) strictly to 127.0.0.1 and localhost.
    • Sanitized all dynamic parameters injected into JavaScript (onReady, appendTerminalLine, askMistral, loadPayload) with org.json.JSONObject.quote(), eliminating script injection vulnerabilities.
  • Ubuntu Sandbox Path Traversal Guard (UbuntuTerminalEngine.kt):
    • Implemented getSafeWorkspaceFile() with canonical path validation on readFileContent(), saveFileContent(), createFile(), and deleteFile().
    • Directory traversal attempts (../) escaping the workspace sandbox are strictly blocked.
  • Inter-App Signature Permission:
    • Protected com.vastavik.codeoss.OPEN_EDITOR with custom signature-level permission com.vastavik.codeoss.permission.OPEN_EDITOR.
    • Disabled android:allowBackup="false" to prevent data extraction via ADB.

2. Main Mobile App (com.vastavik.computer)

  • Hardware-Backed Keystore AES-256-GCM Token Storage (TokenManager.kt):
    • Upgraded session token persistence from plaintext SharedPreferences to hardware-backed AndroidKeyStore AES-256-GCM authenticated encryption.
  • Network Security Configuration:
    • Deployed network_security_config.xml enforcing strict TLS/HTTPS everywhere (cleartext permitted only for local developer emulator loopback 10.0.2.2).
    • Disabled android:allowBackup="false" in AndroidManifest.xml.
  • R8 Minification & Obfuscation:
    • Enabled isMinifyEnabled = true and isShrinkResources = true in release builds with optimized ProGuard rules.

3. Backend Engine (vastavikLearning-backend-app)

  • File Upload Extension & MIME Allowlisting:
    • Doubts and Bug Report attachments strictly allow only safe image/doc formats (.jpg, .jpeg, .png, .webp, .pdf, .txt, .log).
    • Disallows .html, .svg, .js, and executables, preventing Stored XSS.
  • Upload Sandbox Security Headers:
    • Injected Content-Security-Policy: default-src 'none'; sandbox and X-Content-Type-Options: nosniff for all /uploads static resources.

📦 Release Assets

  1. vastavikLearning-v1.0.52.apk: Main Android Application (versionCode = 52)
  2. vastavik-codeoss-extension.apk: CodeOSS Companion Extension (versionCode = 20)
  3. source_v1.0.52.zip: Complete source code archive (.zip)
  4. source_v1.0.52.tar.gz: Complete source code archive (.tar.gz)