Releases¶
All releases are published on the GitHub Releases page.
Library versions are published to Maven Central:
v0.6.1 — 1st August 2026¶
Sign-in no longer needs the overlay permission, Solid profiles become real Android accounts, and sessions stop expiring after a day. Several release-only defects are fixed.
New — Sign-in¶
AuthorizeWithSolid, anActivityResultContractyour app launches from its own foreground. The app no longer requestsSYSTEM_ALERT_WINDOWat all, and the dialog that used to demand it on first launch is gone. See Getting Started.- Solid accounts in Android Settings. Each signed-in WebID appears under Settings → Accounts.
"Add account" there opens sign-in and returns where it was invoked; removing an account signs
that profile out.
ChooseSolidAccountoffers the system account chooser to apps that want it. - Add an account mid-sign-in — the authorize dialog can hand off to login, and the new account is waiting in the list on return.
Improvements¶
- No dangerous permissions.
SYSTEM_ALERT_WINDOWwent with the overlay dialog, and the three account permissions were dropped —GET_ACCOUNTSbelongs to Android's Contacts group, so the app looked like it wanted your contacts, whileAUTHENTICATE_ACCOUNTSandMANAGE_ACCOUNTShave been deprecated since API 23 and 22. Only normal-level permissions remain. - Static client registration. The app identifies itself with a hosted Client ID Document instead of registering dynamically with each provider. Dynamic registrations expire — Inrupt discards them after 24 hours and the refresh token dies with them, which is what forced a fresh sign-in roughly once a day. Existing sessions keep the registration they were created with; only new sign-ins use the hosted identity. Your own app can do the same: see Client ID Document.
- PATCH on SPARQL-only servers — a
text/n3patch refused with 415 is restated as SPARQL Update and retried, so patching works on Inrupt ESS over IPC too. - Versions come from the git tag, so a release is a tag and nothing is edited by hand.
- The
clientSDK gained a test suite — 36 unit and 152 instrumented tests driving every call across a real binder, running on an emulator in CI.
Bug fixes¶
- Metadata calls failed in release builds. R8 renamed the parcelable models, and their names
travel inside the parcel, so
head,headPublic,readContainerand enrichedlistContainerraisedBadParcelableExceptionin every consumer. - A crash in the app hung the caller forever. Failures now arrive as typed errors, and a call left parked on a dead service is retried after a rebind.
- Out-of-range enum values crashed the app — any app could reach the exported sharing and notification services with an unknown share mode or receiver kind.
- Third-party apps could not build —
Sharedexposed AppAuth, forcing consumers to declare anappAuthRedirectSchemeplaceholder for a flow they never run. - A provider address without
https://crashed the app when signing in with a custom provider. - A login finishing after the main screen opened left no system account until the next cold start.
- The authorize dialog flashed a purple status bar as it opened and closed.
requestLogin no longer works
The deprecated SolidSignInClient.requestLogin drew its picker over the calling app from a
background service, which Android allows only with the overlay permission the app has now
dropped. It fails immediately with SolidServicesDrawPermissionDeniedException instead of
leaving you waiting on a callback that cannot arrive. Migrate to AuthorizeWithSolid.
Note
The account type changed from a placeholder to com.erfangholami.androidsolidservices. Android
purges accounts of the old type on update, and they are re-registered on first launch — sessions
and pod data are untouched.
v0.6.0 — 30th July 2026¶
Tickets, WebID profiles, streaming and live notifications, on a unified result type. Adds crash reporting on the Play build and a Firebase-free build for F-Droid. Source-breaking for SDK consumers (the project is pre-1.0 and unstable).
New — Tickets¶
- Store passes and reservations on a pod, with full
.pkpassparity — pass identity and web-service block, beacons, relevancy interval, colours and rich detail fields — plus BCBP coverage for boarding passes. - Pass images live in per-ticket sub-containers; colours are cached on index rows so a wallet list paints from a single GET.
New — Profiles, streaming and live updates¶
- WebID profile API: read a profile (merging linked documents), update name fields, set an avatar.
- Streaming read/write with progress, so large files no longer buffer entirely in memory.
- Live resource notifications over
WebSocketChannel2023, exposed as a lifecycle-scopedFlowalongside the existing inbox polling.
New — Monitoring and distribution¶
- Crash reporting and performance monitoring on the Google Play build, through a
TelemetrySinkseam inShared. The published libraries take on no monitoring dependency and stay silent until a host app installs a sink — you can plug in your own (Sentry, OpenTelemetry, logs). - Network spans report the origin only (
scheme://host[:port]), never pod paths. See the Privacy Policy. - A FOSS build flavour with no Firebase or Play Services, for F-Droid.
Improvements¶
- One result type: every API returns
SolidResult<T>with a typedSolidError(machine code, retryable), replacing six historical error idioms. Breaking. - String IRIs replace
URIacross the public API. Breaking. - The
clientSDK reaches everyapicapability over IPC — tickets, contacts, derived resource verbs and streaming. - Lost-update protection: contact, group and ticket edits use conditional
If-Matchwrites with retry, falling back to weak ETags on servers like NSS. - New resource helpers —
exists,ensureContainer,probeAccess. - Contacts gain instant-messaging handles, vCard
GEOandLANG. - Type-index registration uses compare-and-swap instead of a blind write.
- Narrowed the
apiconsumer R8 rules: jjwt's implementation tree keeps only what is reached reflectively instead of every member, so apps embeddingapipin far less. - Build and tooling: ktlint and detekt in CI on every PR, a published
API reference,
targetSdk36, AGP and SDK 37.
Bug fixes¶
- Login: restored the lowercase Solid-OIDC
webidscope and ID-token claim, and 303 redirects are now followed when resolving a WebID. - Sessions: accounts issued no refresh token stay signed in until their access token actually expires; expired sessions stay visible instead of silently disappearing.
- Sharing: ACP grant/revoke fails fast instead of silently wiping co-shares; WAC surfaces inherited access.
- Transport: redirects re-sign DPoP per hop, PATCH negotiates its format, and pod storage is discovered rather than assumed.
- Fixed binary corruption over IPC; cancellation is no longer retried.
v0.5.1 — 16th June 2026¶
Improvements¶
- The libraries ship consumer ProGuard rules, so minified apps need no keep rules of their own.
v0.5.0 — 16th June 2026¶
Headline release: resource sharing and a Linked Data Notifications inbox, plus a security-focused overhaul of authentication and a clean-architecture refactor of the libraries. Source-breaking for external SDK consumers (the project is pre-1.0 and unstable).
New — Resource sharing¶
SharingManager(api) /Solid.getSharingClient()(client): share any pod resource or container with another WebID at a chosen level — View (Read), Add (append-only), or Edit (read/write) — and change the level or revoke it later, optionally notifying the receiver.- Authorization works on both Web Access Control (WAC) and Access Control Policy (ACP) pods; the backend is auto-selected from the resource's advertised authorization links.
- Make a resource private (owner-only) in one call; add-only recipients can upload into a shared
container via
createInContainer(...)without read/write on its other contents. - Share links as
https://solidshare.app/s…Android App Links, a public catalog of given/received shares (rebuildable from the pod's own ACLs), and a typedSharingExceptionhierarchy.
New — Notifications & inbox (Linked Data Notifications)¶
NotificationsManager(api) /Solid.getNotificationsClient()(client): a full LDN loop over the user's inbox. An owner offers access — or a peer requests it — the notification lands in the target's inbox, and the recipient accepts or rejects, with a response sent back.- The inbox is auto-provisioned with public append-but-not-read access. Notification senders are verified cross-pod by reading their WebID profile anonymously. Pull-only (no push subscription yet).
New — Authentication¶
- Solid-OIDC Client ID Document — authenticate with a stable, hosted
client_idinstead of per-device dynamic registration, removing forced re-logins when a provider drops an old registration. See Using a Client ID Document. - Per-account DPoP keys — each account gets its own DPoP keypair in the Android Keystore.
New — Resources & contacts over IPC¶
head(),patch(), and conditionalupdate(…, ifMatch)(ETag optimistic concurrency) are now reachable over IPC throughSolidResourceClient.- New size, created-time, and modified-time accessors on the resource models.
- The contacts data module is now wired end-to-end over the IPC service and
clientSDK.
Improvements¶
- Authentication hardening — the token/profile store is now encrypted at rest (AES-256-GCM
via an Android Keystore key, with transparent migration of pre-0.5.0 plaintext stores); logins are
rejected unless the token issuer is authorized by the WebID (
solid:oidcIssuer); the ID token returned by a refresh is re-validated; silent token refresh is fixed against servers that enforce aDPoP-Nonceon the token endpoint (e.g. Inrupt ESS), with per-origin nonce tracking and coalesced concurrent refreshes. Transport-level token/header plumbing was removed from the publicAuthenticator(source-breaking; no known external caller). - Networking —
SolidHttpClientgained an in-memory response cache (per-account keyed, TTL freshness, ETag/Last-Modified revalidation, single-flight de-duplication, LRU eviction) with write-through invalidation, on by default. - Library refactor —
Sharedreorganized into intent-based packages (model/,rdf/,http/, …) and stripped of okhttp / titanium-json-ld types on its public API (resource models now expose aStringcontent-type and aSolidHeadersvalue type); theclientlibrary extracted a shared, self-healingServiceConnectorand unified its error contract so every method throwsSolidException(source-breaking for resource calls).
Bug fixes¶
- Fixed adding received shares from notifications when a cross-pod access probe fails.
- Fixed ACP grants to write the implied ACL modes, matching WAC behaviour.
- 401 retry handling now distinguishes a DPoP-nonce rotation from an expired token and never returns an expired or post-failed-refresh token to callers.
v0.4.1 — 12th May 2026¶
Namespace migration release. No new features; everything moves under com.erfangholami.androidsolidservices.
Maven coordinates¶
The three published libraries now share one groupId with short artifact ids:
| Previous coordinates | New coordinates |
|---|---|
com.pondersource.solidandroidclient:solidandroidclient |
com.erfangholami.androidsolidservices:client |
com.pondersource.solidandroidapi:solidandroidapi |
com.erfangholami.androidsolidservices:api |
com.pondersource.shared:shared |
com.erfangholami.androidsolidservices:shared |
Update the dependency lines in your module-level build.gradle.kts.
Gradle modules and Kotlin packages¶
The local Gradle module folders (SolidAndroidApi/ → api/, SolidAndroidClient/ → client/) and source packages (com.pondersource.* → com.erfangholami.androidsolidservices.*) were renamed to match the new coordinates. If you consume the libraries via Maven Central, this affects only your import statements; if you build this project from source, update local module paths in scripts and CI.
App-level changes (Android Solid Services host app)¶
applicationIdis nowcom.erfangholami.androidsolidservices. The host app on existing devices cannot auto-upgrade — users have to uninstall the old build and install 0.4.1 fresh.- The AccountManager
accountTypechanged to match. Existing Solid accounts on user devices will be orphaned and must be re-added. - The AppAuth redirect scheme changed. If you registered the OAuth callback with a specific Solid identity provider, update the redirect URI provider-side.
v0.4.0 — 3rd May 2026¶
New API — SolidResourceManager¶
head(webid, uri)— HTTP HEAD returns aSolidMetadataobject (ETag, Content-Type, Content-Length, WAC-Allow, ACL link, Accept-Patch/Post, Last-Modified, and more) without transferring the resource body. Ideal for caching checks and permission discovery before a full read.patch(webid, uri, patch)/patchRaw(webid, uri, n3Body)— N3 Patch support for atomic partial updates to RDF resources. The typed overload accepts anN3Patchvalue; the raw overload accepts a pre-serialisedtext/n3string.update()now acceptsifMatch— pass the ETag from a priorheadorreadcall for optimistic-concurrency protection (server returns 412 on version mismatch).delete(webid, resourceUri: URI)— delete a resource by URI directly, without reading it first.
New Type — N3Patch¶
Type-safe DSL and diff-based factory for building Solid N3 Patch documents:
// DSL builder
val patch = N3Patch.build {
where(contactUri, VCARD.FN, variable = "oldName")
deleteVar(contactUri, VCARD.FN, variable = "oldName")
insertLiteral(contactUri, VCARD.FN, "Alice")
}
// Auto-diff from two resource states
val patch = N3Patch.fromDiff(originalResource, modifiedResource)
Authentication¶
- DPoP algorithm negotiation — the DPoP generator now reads the
WWW-Authenticateresponse header and selects the best algorithm the server supports; improves compatibility with different pod implementations. - ID token verification — new
IdTokenVerifiervalidates claims in the received ID token. - DPoP nonce conflict fix — token refresh no longer races with an in-flight nonce update.
- WebID parsing fix — correctly extracts the WebID string from the token response.
- Crash fixes — multiple crash points removed from the token exchange and session handling paths.
Multi-account in client¶
Third-party apps must now pass the target WebID on each resource and contacts call. This enables per-account IPC routing when the user has multiple Solid accounts logged in.
Resource Operations¶
- ETag on writes — PUT requests now include
ETagheaders for optimistic concurrency. - Special characters in URIs — resource URIs containing spaces and other characters are now percent-encoded correctly.
- Unified delete —
deleteanddeleteContainerpaths merged; redundant network round-trips removed.
Architecture¶
- Removed Inrupt Java Client library — replaced with a custom
SolidHttpClient; significantly leaner dependency footprint. - API binary compatibility enforcement — API Validator plugin added to all modules; the public surface is tracked via
.apifiles to prevent accidental breakage. - AIDL consolidated in
Shared— all parcelable definitions moved to theSharedmodule; no more duplication across modules. - ProGuard + minification — release builds of the ASS app are now minified.
- Extended vocabulary — new RDF vocabulary constants added to the
Sharedmodule for broader developer use.
Bug Fixes¶
- Fixed wrong Dublin Core namespace in the Contacts data module; old data using the incorrect namespace is still readable.
- Fixed
ETagheader name casing. - Fixed granted apps not persisting across process restarts.
UI¶
- ASS now shows a dialog prompting users to grant the overlay draw permission when it is missing.
- Updated "Sign in with Solid" login screen.
- UI strings moved to Android string resources.
Dependencies¶
- Updated several library versions across all modules.
v0.3.1 — 14th April 2026¶
- Fix saving accounts bug.
v0.3.0 — 13th April 2026¶
- Multi-account support — log in with multiple Solid accounts and switch between them from the Settings page.
- Suspend functions — all resource and contacts data module methods are now Kotlin
suspendfunctions instead of callback-based, for cleaner coroutine integration. - Unified result types — resource operations return
SolidNetworkResponse<T>(sealed:Success,Error,Exception); contacts operations returnDataModuleResult<T>. - Structured exceptions — new
SolidExceptionsealed class hierarchy with typed subclasses (SolidAppNotFoundException,SolidServiceConnectionException,SolidNotLoggedInException,SolidResourceException, etc.). - DPoP authentication — proper DPoP (Demonstration of Proof-of-Possession) token support for all authenticated pod requests.
- kotlinx.serialization — replaced Gson for better Kotlin compatibility.
- JVM 17 — upgraded project JVM target from 11 to 17.
- Compile SDK 36 — updated compile SDK from 35 to 36.
- CI/CD — GitHub Actions workflows for publishing libraries and the application.
- Internal API encapsulation — implementation classes are now
internal, exposing only the public SDK surface.
v0.2.1 — 19th December 2024¶
- Remove SolidCommunity.net from the login provider list (simplify provider options).
- Add app screenshots to documentation.
v0.2.0 — 17th December 2024¶
- Contacts data module — full contacts management over IPC: create, read, rename, and delete address books, contacts, and groups stored on the pod.
- Suspend functions for contacts — all contacts data module methods converted from callbacks to
suspendfunctions. - Service connection flow — added
Flow<Boolean>connection state for all IPC services so apps can react to connect/disconnect events. - Container deletion — recursive deletion of LDP containers and their contents.
- Private and public type indexes — support for Solid type index registration.
- Disconnect from Solid — apps can now programmatically revoke their own access grant.
- Shared module — extracted common types (resource model, AIDL parcelables, contacts types) into a standalone
Sharedlibrary. - Bug fixes — token saving on network error, app relogin flow, authentication edge cases, reading RDF resources as NonRDF.
v0.1 — 20th March 2024¶
Initial public release.
- Authentication — OpenID Connect login with Inrupt and SolidCommunity.net identity providers; browser-based auth flow via AppAuth.
- DPoP — DPoP authentication headers on all pod requests.
- Resource CRUD — read, create, update, and delete resources on a Solid pod over IPC (AIDL).
- SolidContainer — support for listing and navigating pod containers (directories).
- WebID —
getWebId()exposed as an IPC service. - Access grants — permission dialog in ASS when a third-party app requests access; grants tracked in the Settings page.
- ASS app — initial Jetpack-based UI with login, settings, and access grant management.
- Client library — first version of
clientconnecting to ASS over AIDL.
Found a bug or want to request a feature?
Please open an issue on GitHub. Include your device/emulator Android version, library version, and any relevant error output.