Package signature and channelID security
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 149
- Forks
- 54
- PR merge metrics
- No merged PRs in 30d
Description
Hello, what is the purpose of adding package signatures on the line developer console? My understanding was that it can limit usage of channel ID to specific signatures but when I add different SHA than my app uses then I can still use the SDK.
The documentation only explains how to add the signatures, not the purpose of it https://developers.line.biz/en/docs/line-login-sdks/android-sdk/integrate-line-login/#link-app-to-channel
Could you explain what is the benefit of adding SHA signatures? Also should I make my `channelID` secure by injecting it through the CI?
Thanks!
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the LINE Login Android SDK integration section linked in the issue, focusing on package signatures, channel IDs, and the stated CI question. Clarify the security purpose of SHA signatures and whether channel IDs need CI injection, then update the documentation so the behavior and recommended setup are explicit.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, java
- Domain
- authentication, documentation, mobile
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 38/100