line / line/line-sdk-android

Package signature and channelID security

Open
#164 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Java
Stars
149
Forks
54
PR merge metrics
No merged PRs in 30d

Description

Hello, what is the purpose of adding package signatures on the line developer console? My understanding was that it can limit usage of channel ID to specific signatures but when I add different SHA than my app uses then I can still use the SDK.

The documentation only explains how to add the signatures, not the purpose of it https://developers.line.biz/en/docs/line-login-sdks/android-sdk/integrate-line-login/#link-app-to-channel

Could you explain what is the benefit of adding SHA signatures? Also should I make my `channelID` secure by injecting it through the CI?

Thanks!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the LINE Login Android SDK integration section linked in the issue, focusing on package signatures, channel IDs, and the stated CI question. Clarify the security purpose of SHA signatures and whether channel IDs need CI injection, then update the documentation so the behavior and recommended setup are explicit.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, java
Domain
authentication, documentation, mobile
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.