Platform, Build, and Security
Build and Platform Configuration
Unity Project Settings
The root ProjectSettings.asset still contains template-like values:
companyName: DefaultCompanyproductName: CGPUbundleVersion: 0.1.0
This should not be assumed to represent the final shipped Android identity.
Build Profiles
The project uses Unity 6 build profiles under Assets/Settings/Build Profiles.
Meta Quest 1 Build Profile
This appears to be the meaningful Android profile at present.
Notable configuration:
- Overrides the global scene list
- Includes
Assets/Scenes/MainScene.unity - Uses:
companyName: HolonautsproductName: Cassandra
- Sets
ForceInternetPermission: 1 - Sets
insecureHttpOption: 2
Meta Quest Build Profile
This profile appears closer to template/default state:
- Does not override scenes
- Has empty scene list
- Uses template-like names and product metadata
Operationally, the repository suggests Meta Quest 1.asset is the build profile that matches the current product identity.
Quality and Render Pipeline Assets
The project defines quality tiers in ProjectSettings/QualitySettings.asset:
MobilePCMeta Quest (Build Profile)
Render pipeline assets:
Assets/Settings/Mobile_RPAsset.asset- Render scale
0.8 - MSAA
4 - Shadow distance
2.5
- Render scale
Assets/Settings/PC_RPAsset.asset- Render scale
1.0 - MSAA
4 - Shadow distance
50 - Additional lights enabled
- Render scale
Current quality settings indicate:
Mobile->Mobile_RPAssetPC->PC_RPAssetMeta Quest (Build Profile)-> currently referencesPC_RPAsset
That last mapping should be validated because it may not match the expected mobile optimization path.
Android Customization
Files
Assets/Plugins/Android/AndroidManifest.xmlAssets/android_config/AllowClearText/res/xml/network_security_config.xmlAssets/Editor/ForceHttpAllowed.csAssets/Editor/ZipAlignPostBuild.cs
Current Android Behavior
- Custom manifest defines Quest-compatible activity setup
- Supported devices include Quest 2, Quest Pro, Quest 3, Quest 3S
- Head tracking feature is marked required
- Network security config allows cleartext traffic
- Editor build hook forces insecure HTTP to be allowed
- Post-build hook tries to
zipalignand re-sign APKs
ForceFFR
Assets/Scripts/XR/ForceFFR.cs forces high foveated rendering on Meta/Oculus runtime startup.
Networking and Security Configuration
This section documents the current implementation, not a recommended production posture.
Current State
- REST endpoint uses HTTPS
- Websocket endpoint uses plain
ws:// CertsHandleraccepts all TLS certificates- Android network config allows cleartext traffic
- Build preprocessing forces insecure HTTP allowance
Practical Meaning
The app is currently optimized for connectivity and deployment convenience rather than hardened transport security. That may be acceptable for a lab prototype or controlled environment, but it is not a secure production configuration for a medical system.