SEC-1: build-inject Google Maps Android key; remove leaked literal
Removes the leaked Google Maps API key literal from README.md and the
live com.google.android.geo.API_KEY in AndroidManifest.xml (which shipped
in every built APK). The manifest value is now the build-time placeholder
${MAPS_API_KEY}, injected via AndroidManifestPlaceholders from the
MapsApiKey MSBuild property, resolved from a CI secret (-p:MapsApiKey=),
the MAPS_API_KEY env var, or a gitignored maps.key.props at the repo root
(maps.key.props.example committed as the template). maps.key.props is
gitignored so a real key is never committed.
No rotated key is included here; the human supplies it via CI secret.
Pairs with the console key rotation to close SEC-1 (decisions.md
2026-08-20; security/sec-1-gmaps-key.md). Git history intentionally not
rewritten (recorded risk-acceptance relies on revocation of the old key).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
13
maps.key.props.example
Normal file
13
maps.key.props.example
Normal file
@@ -0,0 +1,13 @@
|
||||
<!--
|
||||
SEC-1: local Google Maps key injection for Android builds.
|
||||
|
||||
Copy this file to `maps.key.props` (same directory) and paste your restricted key.
|
||||
`maps.key.props` is gitignored — never commit a real key. CI supplies the key instead
|
||||
via `-p:MapsApiKey=$SECRET` or the MAPS_API_KEY environment variable, so this file is
|
||||
only for local development.
|
||||
-->
|
||||
<Project>
|
||||
<PropertyGroup>
|
||||
<MapsApiKey>YOUR_GOOGLE_MAPS_ANDROID_API_KEY</MapsApiKey>
|
||||
</PropertyGroup>
|
||||
</Project>
|
||||
Reference in New Issue
Block a user