Is it possible for a trusted web activity to have a configurable start url?

Viewed 310

I have a situation where my web application is not on the world wide web. Rather, there are deployments to multiple customer's private environments. My customers would like an Android app that wraps this web application. It looks to me that the Trusted Web Activity is an appropriate route to go.

However, there is one sticking point. Following the integration guide, it looks to me that the url opened by the Trusted Web Activity needs to be declared in the Android Manifest. This approach would require building a different app for each customer, as each customer will have a different url for their deployment. Is it possible to set up a Trusted Web Activity, where the start url can be chosen in settings, or in a managed configuration?

1 Answers

You should be able to use a multi-origin trusted web activity for this.

The asset_statements declaration in your app would end up looking like this:

<string name="asset_statements">
[{
    \"relation\": [\"delegate_permission/common.handle_all_urls\"],
    \"target\": {
        \"namespace\": \"web\",
        \"site\": \"https://app.customer1.example\"
    }
}],
[{
    \"relation\": [\"delegate_permission/common.handle_all_urls\"],
    \"target\": {
        \"namespace\": \"web\",
        \"site\": \"https://app.customer2.example\"
    }
}],
[{
    \"relation\": [\"delegate_permission/common.handle_all_urls\"],
    \"target\": {
        \"namespace\": \"web\",
        \"site\": \"https://app.customer3.example\"
    }
}],
...
</string>

You would still need to update your app each time a customer is onboarded, but there's no way around that - it's called a "trusted" list for a reason.

Also consider the security ramifications of this setup - it may allow some cross-domain shenanigans from one client's site to another, so be sure you understand the attack surface and are able to fully lock down the app to a single client site.

Related