From 8ebe28b275bed4cab5857b6e07e5f0dade867883 Mon Sep 17 00:00:00 2001 From: charlesoj6205 Date: Tue, 28 Jul 2026 10:42:40 +0100 Subject: [PATCH 1/2] Update Approov service layer to latest published versions Point the quickstart at the current release on Maven Central, and align the Approov SDK reference with the version the service layer actually resolves transitively (verified against the service POM). Co-Authored-By: Claude Opus 5 --- README.md | 2 +- SHAPES-EXAMPLE.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index e97a643..ed338b3 100644 --- a/README.md +++ b/README.md @@ -11,7 +11,7 @@ The Approov integration is available via [`maven`](https://mvnrepository.com/rep The `Maven` repository is already present in the gradle.build file so the only import you need to make is the actual service layer itself: ``` -implementation("io.approov:service.httpsurlconn:3.5.3") +implementation("io.approov:service.httpsurlconn:3.5.4") ``` Make sure you do a Gradle sync (by selecting `Sync Now` in the banner at the top of the modified `.gradle` file) after making these changes. diff --git a/SHAPES-EXAMPLE.md b/SHAPES-EXAMPLE.md index ead6c8a..410e1f6 100644 --- a/SHAPES-EXAMPLE.md +++ b/SHAPES-EXAMPLE.md @@ -45,7 +45,7 @@ The `approov-service-httpsurlconn` dependency needs to be added as follows to th ![App Build Gradle](readme-images/app-gradle.png) ``` -implementation("io.approov:service.httpsurlconn:3.5.3") +implementation("io.approov:service.httpsurlconn:3.5.4") ``` Make sure you do a Gradle sync (by selecting `Sync Now` in the banner at the top of the modified `.gradle` file) after making these changes. From 54080862ef43f57690378e35e1728fb85a4ab913 Mon Sep 17 00:00:00 2001 From: charlesoj6205 Date: Tue, 29 Sep 2026 14:01:33 +0100 Subject: [PATCH 2/2] Update the Shapes app build for approov-service-httpsurlconn 3.5.4 Service layer 3.5.4 needs minSdk 23 and core library desugaring. The Shapes app used minSdk 21 and Android Gradle plugin 7.1.1, so the guide dependency failed in the manifest merge, and D8 crashed on the 3.5.4 jar. - Upgrade Android Gradle plugin 7.1.1 -> 8.9.0 and Gradle 7.2 -> 8.11.1. - Add namespace and remove the manifest package attribute. - Raise minSdk 21 -> 23, compileSdk 31 -> 35 and targetSdk 31 -> 34. targetSdk 34 passes the lint check for release builds and keeps the layout unchanged, because targetSdk 35 enforces edge-to-edge. - Enable core library desugaring with desugar_jdk_libs 2.1.4. - Add R8 -dontwarn rules for the optional Google Play services and Play Integrity classes that the Approov SDK refers to. - Document minSdk 23, desugaring, the R8 rules and the Android Studio and JDK requirements in README.md and SHAPES-EXAMPLE.md. Tested: debug and release builds pass, with and without the guide dependency. On an Android 17 emulator, the app initialized SDK 3.5.3 and fetched a token for the v3 endpoint. Refs approov/core-project-approov#644 Co-Authored-By: Claude Opus 5.5 --- README.md | 28 ++++++++++++++++++- SHAPES-EXAMPLE.md | 4 ++- shapes-app/app/build.gradle | 10 +++++-- shapes-app/app/proguard-rules.pro | 6 ++++ shapes-app/app/src/main/AndroidManifest.xml | 3 +- shapes-app/build.gradle | 2 +- .../gradle/wrapper/gradle-wrapper.properties | 2 +- 7 files changed, 46 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index ed338b3..9001c48 100644 --- a/README.md +++ b/README.md @@ -14,6 +14,32 @@ The `Maven` repository is already present in the gradle.build file so the only i implementation("io.approov:service.httpsurlconn:3.5.4") ``` +The service layer requires [core library desugaring](https://developer.android.com/studio/write/java8-support#library-desugaring) and a minimum SDK version of 23. Add the following to the app-level `build.gradle` file: + +``` +android { + defaultConfig { + minSdkVersion 23 + } + compileOptions { + coreLibraryDesugaringEnabled true + } +} + +dependencies { + coreLibraryDesugaring 'com.android.tools:desugar_jdk_libs:2.1.4' +} +``` + +Use Android Gradle plugin 8.x or later. With Android Gradle plugin 7.x, the build fails in D8 with a `NullPointerException` while it processes the service layer. With Android Gradle plugin 8.x and no desugaring, the build fails with `Dependency 'io.approov:service.httpsurlconn:3.5.4' requires core library desugaring to be enabled`. + +If your release build uses R8 (`minifyEnabled true`), add these rules to your ProGuard rules file. The Approov SDK refers to optional Google Play services and Play Integrity classes, and Android Gradle plugin 8 stops the build with `Missing class` errors if they are not present: + +``` +-dontwarn com.google.android.gms.tasks.** +-dontwarn com.google.android.play.core.integrity.** +``` + Make sure you do a Gradle sync (by selecting `Sync Now` in the banner at the top of the modified `.gradle` file) after making these changes. This package is actually an open source wrapper layer that allows you to easily use Approov with `HttpsUrlConnection`. This has a further dependency to the closed source [Approov SDK](https://central.sonatype.com/artifact/io.approov/approov-android-sdk). @@ -26,7 +52,7 @@ The following app permissions need to be available in the manifest to use Approo ``` -Note that the minimum SDK version you can use with the Approov package is 21 (Android 5.0). +Note that the minimum SDK version you can use with the Approov package is 23 (Android 6.0). Please [read this](https://approov.io/docs/latest/approov-usage-documentation/#targeting-android-11-and-above) section of the reference documentation if targeting Android 11 (API level 30) or above. diff --git a/SHAPES-EXAMPLE.md b/SHAPES-EXAMPLE.md index 410e1f6..bf10408 100644 --- a/SHAPES-EXAMPLE.md +++ b/SHAPES-EXAMPLE.md @@ -5,7 +5,7 @@ This quickstart is written specifically for native Android apps that are written ## WHAT YOU WILL NEED * Access to a trial or paid Approov account * The `approov` command line tool [installed](https://approov.io/docs/latest/approov-installation/) with access to your account -* [Android Studio](https://developer.android.com/studio) installed (Android Studio Bumblebee 2021.1.1 is used in this guide) +* [Android Studio](https://developer.android.com/studio) installed, in a version that supports Android Gradle plugin 8.9 (see the [compatibility table](https://developer.android.com/build/releases/gradle-plugin#android_gradle_plugin_and_android_studio_compatibility)). The Shapes app uses Android Gradle plugin 8.9.0 and Gradle 8.11.1, which require JDK 17. * The contents of this repo ## RUNNING THE SHAPES APP WITHOUT APPROOV @@ -48,6 +48,8 @@ The `approov-service-httpsurlconn` dependency needs to be added as follows to th implementation("io.approov:service.httpsurlconn:3.5.4") ``` +The service layer requires [core library desugaring](https://developer.android.com/studio/write/java8-support#library-desugaring) and a minimum SDK version of 23. The Shapes app already sets `minSdkVersion 23`, `coreLibraryDesugaringEnabled true` and the `coreLibraryDesugaring 'com.android.tools:desugar_jdk_libs:2.1.4'` dependency in `app/build.gradle`, so no other change is necessary. If you add Approov to your own app, see [ADDING APPROOV SERVICE DEPENDENCY](README.md#adding-approov-service-dependency). + Make sure you do a Gradle sync (by selecting `Sync Now` in the banner at the top of the modified `.gradle` file) after making these changes. Note that `approov-service-httpsurlconn` is actually an open source wrapper layer that allows you to easily use Approov with `HttpsUrlConnection`. This has a further dependency to the closed source Approov SDK itself. diff --git a/shapes-app/app/build.gradle b/shapes-app/app/build.gradle index 1f496e7..d3690b4 100644 --- a/shapes-app/app/build.gradle +++ b/shapes-app/app/build.gradle @@ -1,11 +1,12 @@ apply plugin: 'com.android.application' android { - compileSdkVersion 31 + namespace "io.approov.shapes" + compileSdkVersion 35 defaultConfig { applicationId "io.approov.shapes" - minSdkVersion 21 - targetSdkVersion 31 + minSdkVersion 23 + targetSdkVersion 34 versionCode 3 versionName "3.0" } @@ -27,11 +28,14 @@ android { compileOptions { sourceCompatibility JavaVersion.VERSION_1_8 targetCompatibility JavaVersion.VERSION_1_8 + // Required by io.approov:service.httpsurlconn 3.5.4 and later + coreLibraryDesugaringEnabled true } } } dependencies { + coreLibraryDesugaring 'com.android.tools:desugar_jdk_libs:2.1.4' implementation fileTree(dir: 'libs', include: ['*.jar']) implementation 'androidx.appcompat:appcompat:1.4.1' } diff --git a/shapes-app/app/proguard-rules.pro b/shapes-app/app/proguard-rules.pro index f185b4d..5f35773 100644 --- a/shapes-app/app/proguard-rules.pro +++ b/shapes-app/app/proguard-rules.pro @@ -16,3 +16,9 @@ # public *; #} -keep class com.criticalblue.approovsdk.** {*;} + +# The Approov SDK refers to optional Google Play services and Play Integrity classes that +# are not present unless the app includes those libraries. Android Gradle plugin 8 treats +# missing classes as an error in R8. +-dontwarn com.google.android.gms.tasks.** +-dontwarn com.google.android.play.core.integrity.** diff --git a/shapes-app/app/src/main/AndroidManifest.xml b/shapes-app/app/src/main/AndroidManifest.xml index 4780fdd..3b66e07 100644 --- a/shapes-app/app/src/main/AndroidManifest.xml +++ b/shapes-app/app/src/main/AndroidManifest.xml @@ -1,6 +1,5 @@ - + diff --git a/shapes-app/build.gradle b/shapes-app/build.gradle index 8fb329d..8d721f0 100644 --- a/shapes-app/build.gradle +++ b/shapes-app/build.gradle @@ -8,7 +8,7 @@ buildscript { mavenCentral() } dependencies { - classpath 'com.android.tools.build:gradle:7.1.1' + classpath 'com.android.tools.build:gradle:8.9.0' // NOTE: Do not place your application dependencies here; they belong // in the individual module build.gradle files } diff --git a/shapes-app/gradle/wrapper/gradle-wrapper.properties b/shapes-app/gradle/wrapper/gradle-wrapper.properties index 63deabe..31dc497 100644 --- a/shapes-app/gradle/wrapper/gradle-wrapper.properties +++ b/shapes-app/gradle/wrapper/gradle-wrapper.properties @@ -3,4 +3,4 @@ distributionBase=GRADLE_USER_HOME distributionPath=wrapper/dists zipStoreBase=GRADLE_USER_HOME zipStorePath=wrapper/dists -distributionUrl=https\://services.gradle.org/distributions/gradle-7.2-bin.zip +distributionUrl=https\://services.gradle.org/distributions/gradle-8.11.1-bin.zip