3.6 KiB
Discord Rich Presence builds
SpotiFLAC uses the official Discord Social SDK 1.10.19337 on Android. The integration was inspired by @itsmegaaa's contribution and issue #575. It publishes through the installed, signed-in Discord Android client. It does not collect a Discord user token. iOS support is not implemented.
Local release builds
Download the standalone C++ archive from the Discord Developer Portal for your SDK-enabled application, then stage it once:
python3 scripts/prepare_discord_sdk.py --archive /path/to/DiscordSocialSdk-1.10.19337.zip
An already extracted SDK works too:
python3 scripts/prepare_discord_sdk.py --source-dir /path/to/discord_social_sdk
The helper verifies pinned SHA-256 checksums and stages only the Android release
AAR and license notices under .dart_tool/discord-sdk/1.10.19337. Do not commit
unencrypted SDK binaries or the decryption key. Use the repository's pinned
Flutter, Java, NDK and CMake versions:
fvm exec bash scripts/build_android.sh --target lib/main.dart
Both split APKs and the universal APK are checked for the Discord JNI library, SDK library, surviving JNI/SDK classes in DEX, correct ARM ELF architectures, and license notices. Release builds fail if the SDK is missing. Debug builds without the SDK remain available for contributor development.
CI and releases
The Android-only archive is stored at
third_party/discord/discord-android-1.10.19337.zip.gpg, encrypted with GnuPG
AES-256. Set the repository Actions secret DISCORD_SDK_PASSPHRASE to its
decryption key. This follows GitHub's documented
large-secret storage pattern,
so releases need no external hosting or expiring portal download URL.
CI and Release use the same preparation action to decrypt the archive with
GnuPG (included on Ubuntu runners), verify both pinned file checksums, and
export SPOTIFLAC_DISCORD_SDK_DIR before Gradle runs. The key is passed over
standard input to GnuPG and is never printed or put in its command arguments.
Missing keys, failed decryption, and checksum failures stop the build.
Gradle caches are limited to public dependency downloads; transformed SDK
binaries are not saved in the shared Actions cache.
The release workflow rechecks the final signed APKs before uploading them.
Fork PRs, which cannot access repository secrets, run debug/native validation
without generating release APKs.
The archive contains only lib/release/discord_partner_sdk.aar and
License-Notices.txt. To update the SDK, obtain the official archive, update
the pinned version/checksums in the preparation helper and Gradle cache path,
and encrypt a new Android-only ZIP using gpg --symmetric --cipher-algo AES256.
Keep the passphrase outside the checkout and save it in Actions secrets;
never add it to Git, workflow logs, or build artifacts.
Verification
python3 -m unittest discover -s scripts -p 'test_prepare_discord_sdk.py'
python3 -m unittest discover -s scripts -p 'test_check_backend_apk.py'
fvm flutter test test/discord_presence_service_test.dart
DiscordPresenceTest exercises the real SDK lifecycle on an Android emulator
without Discord installed. This proves native loading and callback handling;
visible presence still needs testing on a device with a signed-in Discord
client, including playback, seeking, pausing, and disabling the feature.