Analyzer::Mobile::Android
Inherits Analyzer < FileHelper < Reference < Object
Parses AndroidManifest.xml to surface mobile app entry points:
- custom URL scheme deep links (intent-filter > data android:scheme)
- verified App Links (autoVerify intent-filter on http/https)
- exported components with a data-less action filter (IPC surface)
- exported components with no intent-filter (explicit-intent surface)
- exported ContentProviders (content://authority IPC surface)
- Jetpack Navigation deep links (res/navigation/*.xml <deepLink>)
One endpoint is emitted per deep-link URI; the handling component lives
in metadata["via"], not a separate entry. A bare intent://component
endpoint models the Android IPC surface: it is emitted for an exported
component whose filter declares an action but no <data> URI (and isn't
the launcher), and for an exported component with no intent-filter at all
— the latter is still reachable by an explicit intent naming the component
(tagged explicit in metadata).
All endpoints keep method = "GET"; the mobile semantics live in
protocol (mobile-scheme / universal-link / android-intent). @string/
values are resolved against res/values/strings.xml when present, and
gradle manifest placeholders (${applicationId}, custom
manifestPlaceholders) against the nearest build.gradle(.kts).
Constants
Unquoted value: a gradle constant reference, e.g. applicationId APP_ID
(groovy) or applicationId = NEWPIPE_APPLICATION_ID_OLD (kts). The
(?![A-Za-z0-9_]) after the key keeps applicationIdSuffix out, and
the UPPER_SNAKE value requirement keeps prose in a // applicationId is ... comment from matching (gradle constants are upper-case by
convention; a camelCase val is intentionally not followed).
applicationId "com.x" (groovy) / applicationId = "com.x" (kts);
the quote requirement keeps applicationIdSuffix from matching.
How far up from the module script to look for a buildSrc/ source tree
holding shared gradle constants.
Generic/standard schemes carry no app-specific meaning on their own.
A host-less http:// / https:// / file:// / content:// is a
content-source qualifier — typically paired with a <data mimeType>
so the component can open a file type from a browser / file manager —
not a deep-link entry point. Custom schemes (myapp://) stay even
host-less, since that's how a runtime-routed custom scheme is declared.
Local-content schemes. file:// / content:// URIs always point at
on-device content (a file picked from a file manager, a ContentProvider
row), never a remotely reachable deep link — so they are suppressed
regardless of host (including a bare * wildcard host).
Upper bound on endpoints emitted from a single intent-filter. A media router / browser filter can declare dozens of hosts × paths; the full cross product would flood the inventory with near-duplicates, so past the cap the path dimension is dropped (scheme × host) and, if still over, the result is truncated.
Scheme emitted for scheme-less Navigation URIs. Navigation matches both http and https for them; one canonical https endpoint keeps the inventory free of http/https twins.
Opaque (authority-less) schemes: mailto:foo@bar, tel:123, geo:….
They take no //host part, so the URL is rendered as scheme: rather
than scheme://. Deliberately conservative: market://details?id=…
(Play Store) and mms://host (media streaming, e.g. VLC) DO use an
authority, so they are NOT listed here.
manifestPlaceholders["key"] = "value" / manifestPlaceholders.put("key", "value") (kts).
The bracketed segment after manifestPlaceholders — a groovy map
literal (= [k: "v"]), a kts += mapOf("k" to "v"), or a
putAll(mapOf(...)) — captured up to the first closing bracket.
key: "value", "key": "value" (groovy) and "key" to "value" (kts).
manifestPlaceholders.key = "value" — groovy property-access form on
the placeholder map. Termux declares its whole package name this way
(manifestPlaceholders.TERMUX_PACKAGE_NAME = "com.termux"), and without
it every ${TERMUX_PACKAGE_NAME} authority stayed unresolved in the
emitted content:// URL. \.put is excluded so the call form above
can't be read as a property named put.
Schemes that only ever appear as the data qualifier of a protected
system broadcast, never as an addressable URI. package: is the
canonical one: <data android:scheme="package"/> pairs with
ACTION_PACKAGE_ADDED / PACKAGE_FULLY_REMOVED / … so the receiver can
read the affected package name out of intent.data. Those actions can
only be broadcast by the system, and package: is opaque anyway, so
rendering it produced a bare, meaningless package:// endpoint
(WordPress-Android's JetpackAppUninstallReceiver). The receiver's own
IPC surface is still reported through the intent:// path when it is
exported with a non-system action.
Per-endpoint gate, evaluated for every emitted deep-link/provider URL.
String#matches? (PCRE2 JIT) replaces three OR-ed String#includes?
scans with a single pass; Regex.union auto-escapes each literal, so
it is provably equivalent to the OR-of-substrings it replaces.
Class methods
Instance methods
Instance-side view of the same declaration. The per-file rescues live on
this base class, which has no way to name the analyzer that is running
inside them, so a skipped file could not be attributed to a tech.
Deriving it from analyzer_for keeps the name written exactly once.