datatheorem / datatheorem/TrustKit-Android
java.lang.NoClassDefFoundError: Failed resolution of: Landroidx/preference/PreferenceManager;
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 604
- Forks
- 90
- Avg merge
- 1h 29m
- Merged PRs (30d)
- 2
Description
Describe the bug
Below exception is thrown when I init the trust kit for android using below line
TrustKit.initializeWithNetworkSecurityConfiguration(context)
java.lang.NoClassDefFoundError: Failed resolution of: Landroidx/preference/PreferenceManager;
at com.datatheorem.android.trustkit.utils.VendorIdentifier.getOrCreate(VendorIdentifier.java:24)
at com.datatheorem.android.trustkit.TrustKit.(TrustKit.java:209)
at com.datatheorem.android.trustkit.TrustKit.initializeWithNetworkSecurityConfiguration(TrustKit.java:321)
at com.datatheorem.android.trustkit.TrustKit.initializeWithNetworkSecurityConfiguration(TrustKit.java:271)
To Reproduce
There are no steps just the init line causes this issue and this issue has nothing to do with network_security_config and thats added under application tag in app's manifest and in xml directory under res.
The pattern for my base url is added and I am using 64 char length pinset.
My network config is below for ref.
Expected behavior
I want to implement SSL pinning for Android 21 and above.
TrustKit configuration
<?xml version="1.0" encoding="utf-8"?>
<network-security-config>
<domain-config cleartextTrafficPermitted="false">
<domain includeSubdomains="true">abcd.abcd-abcd.com</domain>
<pin-set>
<pin digest="SHA-256">XXX</pin>
<pin digest="SHA-256">XXX</pin>
<pin digest="SHA-256">XXX</pin>
</pin-set>
<trustkit-config enforcePinning="true" />
</domain-config>
</network-security-config>
App details:
- App target SDK: 30
- App Min SDK: 21
- App language: Java, Kotlin
- Android R or API 30 (Tested on pixel 2 emulator)
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at VendorIdentifier.getOrCreate in VendorIdentifier.java and the initialization path in TrustKit.java, using the reported TrustKit.initializeWithNetworkSecurityConfiguration call as the entry point. Reproduce the failure on the stated Android configuration and trace the missing androidx/preference/PreferenceManager resolution. Done means initialization no longer throws NoClassDefFoundError while preserving the reported SSL-pinning setup.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, java
- Domain
- mobile-dev, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100