I store my credential keys inside a cpp native file and use CMake to build then link it to my app:
Current code:
My src/main/cpp/credentials-provider-dev.cpp file:
JNIEXPORT jobject JNICALL
Java_com_{package}_CredentialsProvider_extractApiCredentials(JNIEnv *env, jobject instance) {
jclass cls = env -> FindClass("com/{path}/models/ApiCredentials");
jmethodID methodId = env -> GetMethodID(cls, "<init>",
"(Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;)V");
return env -> NewObject(cls, methodId,
env->NewStringUTF("key"),
env->NewStringUTF("other key"),
env->NewStringUTF("another key"),
env->NewStringUTF("key again"),
NULL, NULL
);
}
My build.gradle defines the link to CMakeLists.txt file:
externalNativeBuild {
cmake {
path 'src/main/cpp/CMakeLists.txt'
}
}
My src/main/cpp/CMakeLists.txt file:
cmake_minimum_required(VERSION 3.4.1)
add_library(
credentials-provider-dev
SHARED
credentials-provider-dev.cpp)
The credentials-provider-dev file only define my dev environment credentials and this code works fine when I build in Debug Type.
Problem:
I also have staging and release build and I want to use different credentials-provider-{dev/staging/production}.cpp file for each build type:
debug {
ext.alwaysUpdateBuildId = false
applicationIdSuffix ".debug"
}
staging {
initWith debug
debuggable true
}
release {
minifyEnabled true
proguardFiles getDefaultProguardFile('proguard-android.txt'), 'proguard-rules-app.pro'
signingConfig signingConfigs.release
}
Attempts:
I use native code to store these keys because of better key protection. And I don't want to merge all the build keys into 1 file because of repo security. Only the person has the responsibility to access production build have the credentials-provider-production.cpp file and be able to build release. So my teammates can only have the dev file and build debug mode only.
I tried with find_library to check for staging cpp file existence before calling add_library like this but it didn't work, the lib is still not added:
find_file(
STAGING_KEY_LIB
PATHS main/cpp/credentials-provider-staging.cpp)
if (STAGING_KEY_LIB)
add_library(
credentials-provider-staging
SHARED
main/cpp/credentials-provider-staging.cpp)
endif()
I also tried the CMAKE_BUILD_TYPE parameter sent to the CMakeLists.txt like below. But base on the document: The valid values are Release and Debug. I want to have Staging build too so this method didn't work
add_library(
credentials-provider-${CMAKE_BUILD_TYPE}
SHARED
credentials-provider-${CMAKE_BUILD_TYPE}.cpp)
In summary:
Using native code: How can I separate my secret-key files into different build type-based files? Anyone has experience with this please help. Thanks