Tuesday, September 22, 2026

email problem - SPF and DKIM records

One of our admins reported a problem with replying to mails - they use Zoho - and copy-pasted Claude's solution - 

1. Modify the SPF record to include the zoho domain also - 
- Current value: v=spf1 include:zeptomail.net ~all
- New value: v=spf1 include:zoho.com include:zeptomail.net ~all

2. Publish the DKIM key. In Zoho Mail Admin Console > Domains > ourdomain.in > Email Configuration > DKIM > add selector. Zoho shows you a long key, which is to be added as a DNS TXT record.

The first time we did it, the DKIM record was sent to me by WhatsApp, and perhaps there was some non-printing character or line-break in the middle of the key, because of which the validator tool at https://mxtoolbox.com/SuperTool.aspx complained of invalid syntax for the DKIM key. Then I was sent the record by email as requested, and this time, copy-pasting it into Cloudflare's dashboard worked fine and the validator passed it. Currently no DMARC records are added, we can add those later if need be. And the problem seems to be solved.

Wednesday, September 16, 2026

updating to MacOS 27

The M4 Mac mini asked to download 13+ GB and update MacOS to version 27, Golden Gate - upgrading from MacOS Tahoe 26.6. Since the office fiber internet was down, I hesitated to start the process using Airtel 5G - but since 5G is supposed to be unlimited on my plan, went ahead.

It took nearly 90 minutes to complete the whole update, probably because while downloading, the 5G network was dropping down to 4G and getting throttled due to exhausting today's quota. On 5G, the download was happening at 30-45 Mbps. 

Interestingly, even after the "Downloading" phase completed and the "Preparing" phase started, there was still plenty of downloading activity as seen in Activity Monitor app. "Preparing" took half an hour. Then 8 minutes on the Apple logo screen while restarting. 

traceroutes just for general interest

I had asked an LLM about the network backhaul used by our ISPs like Airtel, BSNL etc, and was told that while there was no publicly available information about the actual specifications of their backhaul, a traceroute might give more information. Some traceroutes to google.com and nebula.tv from BSNLindicated that they terminated at their Points of Presence - POPs in Chennai - nebula.tv via Cloudflare. With Airtel, google.com seems to go to a Mumbai POP - bom.

traceroute to google.com (142.250.183.174), 64 hops max, 40 byte packets
 1  10.219.86.239 (10.219.86.239)  3.068 ms  3.368 ms  3.003 ms
 2  * * *
 3  192.168.116.2 (192.168.116.2)  64.774 ms  35.220 ms  29.967 ms
 4  * * *
 5  * * *
 6  125.21.99.61 (125.21.99.61)  36.796 ms
    dsl-ncr-dynamic-013.32.23.125.airtelbroadband.in (125.23.32.13)  28.051 ms  44.851 ms
 7  182.79.177.69 (182.79.177.69)  40.855 ms
    116.119.68.247 (116.119.68.247)  47.689 ms
    116.119.161.183 (116.119.161.183)  40.998 ms
 8  * 142.250.169.206 (142.250.169.206)  58.361 ms *
 9  142.250.230.197 (142.250.230.197)  158.451 ms *
    64.233.174.17 (64.233.174.17)  289.370 ms
10  142.251.55.67 (142.251.55.67)  38.116 ms
    142.251.55.230 (142.251.55.230)  233.997 ms
    142.251.55.42 (142.251.55.42)  37.590 ms
11  142.251.55.65 (142.251.55.65)  38.276 ms
    142.251.55.67 (142.251.55.67)  41.114 ms
    172.253.71.132 (172.253.71.132)  37.117 ms
12  bom07s32-in-f14.1e100.net (142.250.183.174)  58.148 ms  35.764 ms
    142.250.62.67 (142.250.62.67)  42.145 ms

Then, a couple of traceroutes to a US server, from BSNL fiber to home network done from a Windows machine

tracert ourdomain.org

Tracing route to ourdomain [redacted]
over a maximum of 30 hops:

  1     1 ms    <1 ms    <1 ms  192.168.1.1
  2     2 ms     4 ms     2 ms  117.192.80.1
  3     4 ms     3 ms     3 ms  10.219.29.194
  4     *        *        *     Request timed out.
  5     *        *        *     Request timed out.
  6    13 ms    13 ms    13 ms  10.200.120.225
  7     *        *        *     Request timed out.
  8    15 ms    14 ms    15 ms  115.110.161.189.static.vsnl.net.in [115.110.161.189]
  9    37 ms    50 ms    37 ms  172.25.199.34
 10    37 ms    36 ms    38 ms  172.28.124.134
 11    39 ms    36 ms    75 ms  172.25.138.206
 12     *        *        *     Request timed out.
 13     *        *        *     Request timed out.
 14     *        *        *     Request timed out.
 15     *      278 ms     *     if-bundle-12-2.qcore2.pvu-paris.as6453.net [80.231.245.13]
 16   272 ms   271 ms     *     ae0.cr2.dfw7.us.zip.zayo.com [64.125.20.63]
 17   272 ms   272 ms   293 ms  ae1.cr2.chd4.us.zip.zayo.com [64.125.25.76]
 18   257 ms     *      353 ms  ae9.cr1.phx4.us.zip.zayo.com [64.125.27.186]
 19     *        *        *     Request timed out.
 20   274 ms   272 ms   273 ms  64.125.199.194.IDIA-409280-003-ZYO.zip.zayo.com [64.125.199.194]
 21   241 ms   246 ms   241 ms  core1-edge2-lag1.phx1.codero.com [216.55.160.6]
 22   254 ms   251 ms   251 ms  216-55-160-81.dedicated.codero.net [216.55.160.81]
(and the next hop was our server in Phoenix.)

So apparently BSNL routed this request via Tata Communications (vsnl), via Paris interconnect to Zayo, and there to Phoenix. Of course, routes would vary from time to time, too.

Trying from a Mac via Airtel 5G network,

traceroute ourdomain.org
traceroute to ourdomain.org (redacted), 64 hops max, 40 byte packets
 1  10.219.86.239 (10.219.86.239)  3.615 ms  2.808 ms  2.575 ms
 2  * * *
 3  192.168.116.2 (192.168.116.2)  28.903 ms  32.648 ms  70.657 ms
 4  * 192.168.116.49 (192.168.116.49)  42.654 ms  33.930 ms
 5  * * *
 6  dsl-ncr-dynamic-013.32.23.125.airtelbroadband.in (125.23.32.13)  49.859 ms
    125.21.99.61 (125.21.99.61)  60.570 ms
    dsl-ncr-dynamic-013.32.23.125.airtelbroadband.in (125.23.32.13)  27.138 ms
 7  116.119.167.20 (116.119.167.20)  249.939 ms
    116.119.167.119 (116.119.167.119)  339.057 ms
    116.119.167.20 (116.119.167.20)  251.139 ms
 8  * * *
 9  be3271.ccr41.lax01.atlas.cogentco.com (154.54.42.101)  348.294 ms  258.764 ms  332.531 ms
10  be2932.ccr32.phx01.atlas.cogentco.com (154.54.45.161)  284.207 ms
    be2931.ccr31.phx01.atlas.cogentco.com (154.54.44.85)  256.272 ms  418.788 ms
11  be3452.rcr21.phx02.atlas.cogentco.com (66.28.4.242)  308.459 ms
    be3451.rcr21.phx02.atlas.cogentco.com (66.28.4.26)  432.845 ms  248.367 ms
12  38.122.88.107 (38.122.88.107)  253.042 ms  252.078 ms  246.671 ms
13  core1-edge1-lag1.phx1.codero.com (216.55.160.4)  273.957 ms  253.373 ms  259.721 ms
14  59-160-55-216.dedicated.codero.net (216.55.160.59)  303.754 ms  307.035 ms
    216-55-160-71.dedicated.codero.net (216.55.160.71)  259.048 ms
15  ourdomain.org (redacted)  444.128 ms  405.611 ms  409.528 ms

In this case, the route seemed to be within Airtel (Bharti Telecom) till the 8th hop, and then directly LA and then Phoenix.

 

Tuesday, September 15, 2026

unable to update plugins after a Moodle update

After upgrading our 4 Moodle instances to the latest minor version, 

Site Administration > Plugins > Plugins overview > Check for available updates button returns "Unable to fetch available updates data - unexpected HTTP response code."

Probably the cause is Moodle's Cloudflare ray rejecting the request from our server with a 403 (I verified that it was sending a 403 with curl) as mentioned in this thread, https://moodle.org/mod/forum/discuss.php?d=429373

So I'll try again later.

Monday, September 14, 2026

exporting all LLM conversations to a private repo

Started work on exporting all conversations from Gemini (via aistudio.google.com), Claude, ChatGPT and Github Copilot to a private repo. 

Claude was the simplest - clicking on my initials (bottom left) → Settings → Privacy → Export data
Got an email with a download link (valid ~24 hours) containing a ZIP of your full conversation history as JSON files within a minute. The download link actually downloaded a json file, which had links to the actual conversations and metadata zip file downloads. Then, parsed the conversations using https://github.com/tyashin/Claude-export-data-parser and a full indexed repo of markdown files was ready for me to sync to my private repo.

OpenAI says it will take a few days for them to prepare and send me the export - had to do the export from the Android app, the web version just went into a loop with Confirm export > ask for one-time password sent to email > Confirm export > ask for one-time password sent to email ... The export initiated from the Android app successfully sent an email to me with "ChatGPT - Your data export has started" and the next day, I got an email with "ChatGPT - Your data export is ready" and a download link. The data export included json files as well as a large chat.html file. Unfortunately, the chat.html had only the text of the  conversations, but no date info. So, following the path of creating a json parser for this data too, as mentioned below.

AIStudio did not seem to have any export ability, even with google takeout (please see the next paragraph). Third-party tools can scrape and export as json, what worked for me was saveai.net AI Chat Exporter. Now I've to parse the json and create an index like Claude-export-data-parser does for Claude. 

Correction to the above paragraph - AIStudio seemed to be storing all conversations in Google Drive, and downloading the directory "Google AI Studio" as a zip file seemed to get us all the conversations.

Made this public repo - https://github.com/hn-88/ai-json-parsers - with the json-to-markdown conversion python scripts generated by Gemini and Claude, which would parse the json files exported by each service and create an indexed set of markdown files. When I host this on github, (in a private repo, since some info does not need to be public) I can search for phrases in all the conversations as well as have a detailed reference of all the LLM replies (some of which are wrong, some of which are useful.)

Sunday, September 13, 2026

resizing Azure VM - moved to D2asv5

There was a request to bump up the capacity of a Moodle instance for an in-person workshop on 12th and 13th. 

Used Chrome on Android to log in to the Azure portal, shut down the instance and size it higher (D2asv4 8 GB to D4asv5 16 GB).

When down-sizing it back, found that D2asv5 (<$41 per month) was cheaper than the original D2asv4 (<$46 per month). So, used D2asv5 8 GB instead.

Saturday, September 12, 2026

app for automating sending of SMS / WhatsApp messages

This is what it does:
1. take the phone number from the clipboard
2. check if that number has an associated whatsapp account
3. If whatsapp account exists, create a preformatted whatsapp message to that whatsapp account - i.e. opens Whatsapp with the draft message, which the user can then send
4. creates an SMS draft too, in the default SMS app, which we can send if required.

Created with Claude in just one prompt - what I wanted initially, and the sequence of prompts, is at
and the one issue with the generated code and fix are at

Friday, September 11, 2026

repeated Cloudflare "human check"

One of our content admins wrote,

For the past week (or so), each time we go to our website, and even click on a sub-page, etc, Cloudflare makes us check that we are human (not a bot). See screenshot attached. 
Do you experience this as well, or is it just me?

It is a bit annoying to do it for EVERY page. Is there a way to do it randomly, or at least once (so it knows this IP address is fine), etc.?

Another admin mentioned that 

I remember (another) website team making some changes to the Cloudflare settings following the phishing attacks and bot injection issues we faced on the (other) website. I believe the human verification check you are seeing could be related to those security measures.  

And I added,

I think one way to avoid getting the bot-check "every time" would be to keep a tab open with a page from our domain - then the session would remain open for around 10 minutes, and any other page in our domain you open within those 10 minutes will not ask you for a bot-check. If you are doing some content editing work which takes more than 10 minutes, if you navigate to another page in the open tab within 10 minutes or refresh that page within 10 minutes, you can avoid the bot-checks.


logo update for sign-in with Google screen

One of our CMS admins mentioned that the 'Sign in with Google' screen still displays the old logo, and that it needed to be replace with the new logo of the organization.

The process according to Claude was,

  1. Go to Google Cloud Console → select your project.

  2. Navigate to APIs & Services → OAuth consent screen (in newer UI it may be under APIs & Services → Branding).

  3. Under the App information section, you'll see an App logo field — upload your logo there (square image, recommended 120x120px, max 1MB, JPG/PNG/BMP).

  4. Save changes. 
I had to find the account under which the project had been created from our old emails - there is no way to easily find the email id under which the project was created from the project id which is present in the php code. But Claude says that the Super Admin for Google Workspace can give themselves the permissions in order to get this info, but I did not try it. Private URL for my reference, https://claude.ai/chat/5e521ed1-ec1a-4301-8c89-f7a21939b6e1

Wednesday, September 09, 2026

Claude's review of swayam plus integration local plugin for Moodle

Created a wiki page at https://github.com/hn-88/swayamplus-sso-api-integration/wiki
and populated it with Claude's comments during its review of code for this plugin which had been generated by Gemini in a single prompt.

Tuesday, September 08, 2026

Google Maps Street View video

Private URL for my reference - https://claude.ai/chat/859a7468-53e7-4e90-96ce-deca9ab6f363

Claude was happy to write code for me when I prompted, "If it is feasible, please write a google apps project which will work with google street view, capturing street view images between two points which the user chooses, and exporting the images as a video journey between the two places on the map similar to what is seen by a dashcam on a car. If not feasible, please suggest alternatives."

But the code requires a project with billing enabled, apparently it does not work with the demo api key provided at https://developers.google.com/maps/demo-key

So, pivoted to making screenshots of the google.com/maps page open in street-view instead - tested using SikuliX IDE 2.0.5 from https://github.com/oculix-org/SikuliX1/releases/download/v2.0.5/sikulixide-2.0.5-linux.jar

Points to note - the delay needs to be more than 5 seconds for me, the images load quite slowly. Alt+Shift+C to abort the SikuliX task.

ffmpeg -framerate 1 -i frame_%04d.png -vf "scale=trunc(iw/2)*2:trunc(ih/2)*2,minterpolate=fps=10:mi_mode=blend" -c:v libx264 -pix_fmt yuv420p journey.mp4

for frame blending, but a timelapse style with more frames per second would probably be needed for longer journeys. The scaling is because the libx264 codec needs even numbered pixel counts for width and height, which may not be guaranteed when choosing a rectangle onscreen.

Monday, September 07, 2026

debugging and testing local Moodle plugin with Claude

Private URL for my reference - https://claude.ai/chat/12096022-e224-4e6b-9e01-40149a93cef7

Used Claude to debug (add missing version.php, and many other omissions) the local plugin for swayamplus api integration generated by Gemini - github repo at https://github.com/hn-88/swayamplus-sso-api-integration. Also added some features like retry logic and test url generation.

The readme file has some info about how ngrok was used for testing with a mock python server - https://github.com/hn-88/swayamplus-sso-api-integration/tree/main/test-python-api-server

Some points to note:

  1. The plugin uses the "Manual enrolment" enrolment method, which is enabled by default on all courses - we can see the enabled methods by going to the relevant course > Participants > Enrolled users (dropdown) > Enrolment methods. 

  2. Guest access should probably be removed from the same place as above, in case enabled earlier.

  3. Currently the classes/privacy/provider.php is not implemented, so the mdl_local_swayamplus_enrol table is not updated by deleting rows if / when users are deleted.

  4. If the user is already present on our system, they are directly enrolled in the course.

  5. If the user is new to our system, the user is dropped into the profile completion and agreement to terms and conditions workflows. Following that, the user is actually enrolled in the course automatically, but dropped into their Profile page. According to Claude, we can add a large link to "My Courses" in the Profile page as follows: 

    1. Go to any page where you can add a block sitewide — the Front Page is the standard choice. Turn editing on.
    2. Add a block → HTML.
    3. Give it a title (e.g. "Continue learning") and content — something like a large, bold link:
      <p style="text-align:center;">  
      <a href="https://ourdomain.org/my/courses.php"     
      style="font-size:1.4em; font-weight:bold; 
      display:inline-block; padding:10px 20px;">
      → Go to My Courses  </a></p>
      
    4. On that block's own settings (gear icon → Configure), under "Where this block appears" → Page contexts, set it to "Display throughout the entire site." Save.
    5. Now navigate to any user's profile page — your own is fine. The block should appear there too (since you just made it sitewide). Open that same block's settings again, and this time change "Display on page types" to "Only user profile pages." Save.


network problems were due to overheating SFP module

On two consecutive days, internet at the Planetarium went down at around 9 am, working fine before that. The network folks tried sending light down the fiber, it was fine. But the SFP module in the media converter at our end was very hot. They swapped out the media converter, and the network started working again. 

Saturday, September 05, 2026

avidemux on Mac - default settings are fine

Verified that with the default settings on Avidemux 2.8.2 compiled for ARM on Mac,

MPEG4 ASP (xvid4) video and AC3 lav audio work for playout on the DVD player, 1920x1080.

For 4K - 3840x2160 - the Videotoolbox HEVC default settings are 2000 bitrate and 4000 max bitrate, which can be increased to 5000 bitrate and 8000 max bitrate to be on par with the settings in python-ffmpeg-warp.

Friday, September 04, 2026

investigating lack of referrals

The Moodle plugin in this previous post was not reporting any referrals for the month of August. Investigating, found that
  1. In the new site (swayamplus.education.gov.in redirected from swayam-plus.swayam2.ac.in) login is via email sent to our email id, and my previous email registration doesn't seem to work. Maybe because I had unsubscribed from course alerts?

  2. After logging in with a fresh email, found that swayamplus is no longer adding a referer id to the course URL. There is no &ref=ABC123 part in the URL.
Since they are not sending referral IDs, we cannot report what they don't send!

Moodle server error alert - due to .jpeg extension

One of our Moodle admins reported that
trying to add a content update. I keep getting this error: "servererror,moodle". What could be the problem?

I asked for the URL, and what he had been trying to do. Apparently, the issue was with adding image files with .jpeg extension in a rich-text box. When I renamed the files to .jpg and added them to the box, there was no error. 

Thursday, September 03, 2026

creating m3u playlists with Claude

Tried out creating new playlists for playout in Kodi atop LibreElec on Raspberry Pi 4, using Claude instead of manually copy-pasting filenames. Perhaps a time saving of half-an-hour or so? Private URL for my reference at https://claude.ai/chat/cf6e6881-2424-4a24-a1a7-ed38bc9b4942

Uploaded a playlist and prompted

Just like this playlist, please create a playlist called U055newname.m3u where the items #EXTINF:0,1.mp4
 /var/media/1.mp4
 #EXTINF:0,2.mp4
 /var/media/2.mp4
 #EXTINF:0,3.mp4
 /var/media/3.mp4
 are replaced by the files

/var/media/4.mp4
 /var/media/5.mp4
 /var/media/6.mp4
 /var/media/7.mp4

and the appropriate EXTINF lines.

Claude did catch some typos I had made, and double-checked some files, like

Note the last item keeps its .mp4 extension (matching what you specified: only.mp4), unlike the ENG version which was .avi. Let me know if that should also be .avi.

Also asked Claude to create a python script with the prompt

Now, please write a python script to check each m3u file in the current directory if it has all these items as the first few items of the playlist,

(lines of playlist pasted here)

(for playlists which have TEL in the name)

and if any items are missing, to add them in this order.

Similarly, for m3u files with 3lang or ENG in the name, 

(lines of playlist pasted here)

and for playlists with HIN in the name, 

(lines of playlist pasted here)

which worked well - I have uploaded to the private repo upstairs-Kodi-playlists

Wednesday, September 02, 2026

dotnet api timeouts and action taken

The developers on one of our apps noted that 
The API is intermittently failing, and we are seeing a CORS error in the browser Network tab.

Claude noted that the CORS error is misleading, and it is probably because of a backend API timeout. 

this is almost never an actual CORS policy misconfiguration — it's the browser's error message for "the actual response didn't carry an Access-Control-Allow-Origin header," which happens whenever the request fails or errors out before your CORS middleware gets a chance to run. Since it's intermittent, that's your biggest clue.

Since a lot of bot traffic was seen looking for Wordpress files, they requested blocking those bots which look for non-existent Wordpress files.

Taking Gemini's advice, 
1. Disabled php on the api server, since it's not required by our services - 
sudo a2dismod php8.3
sudo systemctl restart apache2

2. Added one more firewall rule to Cloudflare, the URL being like

ourdomain.org/security/security-rules

(http.host contains "ourdomainname" and http.request.uri.path contains "wp-") or (http.host contains "ourdomainname" and http.request.uri.path contains ".php")
then Block

Friday, August 28, 2026

All of your Google Play apps have been successfully registered

There was an email from Google saying that Android apps in the Play store (and outside) need to be registered, and we need to register keys if we are signing outside the Play Store.

One of our apps was being signed outside the Play Store, so in the URL
play.google.com/console/u/6/developers/android-developer-verification
clicking the arrow against that app, it asks us to add the public key.
To find the public key,
where I'm using this method in a github action,

      - name: Extract SHA-256 fingerprint only
        run: |
          BUILD_TOOLS="$ANDROID_HOME/build-tools/34.0.0"
          "$BUILD_TOOLS/apksigner" verify --print-certs app-release.apk \
            | grep -i "SHA-256"

I clicked on Add Key and added the digest, at first it showed Pending verification, in 10 minutes it showed verified.

Here is part of Gemini's reply on why this key is needed - 

To ensure your app functions flawlessly whether it is downloaded from the Play Store, sideloaded by a QA tester, or downloaded directly from your website, your backend services (Firebase, Google Cloud, etc.) should always have both fingerprints registered:
  1. The Google Play App Signing SHA-256 (found in Play Console -> Release > Setup > App Integrity).
  2. Your Local Keystore SHA-256 (the one generated from yourkey.keystore).

major changes needed for Moodle app

I asked Gemini 3.1 Pro Preview via aistudio.google.com -
Does the Moodle Android App at https://github.com/moodlehq/moodleapp support optimization using R8?

Gemini said, in short, "The short answer is no, not out of the box. The Moodle App is optimized using Angular/JS minification tools (Terser/Webpack) rather than Android's native R8. You should not enable R8 in the Moodle App's Android build configuration, as it will likely break the bridge between the app's JavaScript and native Android plugins."

Then, I asked, 
Then how can this app (and other similar cordova apps) meet the upcoming quality requirements in https://android-developers.googleblog.com/2026/08/app-quality-memory-optimization-secure-onboarding.html ? The play store quality check tool seems to mandate R8 optimization.

Gemini's answer is pasted below.

The recent Google Play announcement from August 2026 (enforcing new memory and
code optimization standards by February 2027) definitely changes the landscape
for hybrid frameworks like Cordova, Capacitor, and Ionic, which power apps like
Moodle.

According to the new Google Play requirements, apps must have a minimum of 25%
coverage across optimization, shrinking, and obfuscation for their native DEX
code using R8 (or a similar tool), and they must stay below strict memory/bitmap
thresholds.

Here is how the Moodle app, and Cordova apps in general, can meet these upcoming
requirements without breaking their architecture:

1. Hitting the 25% R8 DEX Coverage Rule

While blindly enabling R8 (minifyEnabled true) breaks the Cordova JS-to-Native
bridge, it can be enabled safely if properly configured. To meet the 25%
threshold, Cordova apps do not need to obfuscate their entire codebase; they
just need to shrink enough of it.

  - Targeting Heavy Dependencies: In a standard Cordova app, the actual Cordova
    wrapper code and plugins make up a very small percentage of the compiled
    .dex (native Android) file. The vast majority of the native code comes from
    heavy dependencies like AndroidX libraries, Google Play Services, Firebase,
    and other third-party native SDKs.
  - Targeted ProGuard/R8 Rules: Developers will need to enable minifyEnabled
    true but use a highly specific proguard-rules.pro file. They will use
    aggressive -keep rules to protect the Cordova framework (-keep class
    org.apache.cordova.** { *; }) and plugin reflection methods so the app
    doesn't crash.
  - By allowing R8 to shrink and dead-code-eliminate the massive AndroidX and
    Google Play Services libraries while leaving the Cordova bridge alone,
    hybrid apps can easily surpass the 25% optimization threshold required by
    Google Play.

2. Meeting the Dynamic Memory & Bitmap Thresholds

The new requirements aren't just about R8; they strictly monitor dynamic memory
and background bitmap usage. This is actually the bigger challenge for Cordova
apps because they run inside an Android WebView, which is notoriously
memory-heavy.

To prevent the Play Store from penalizing or down-ranking the app, hybrid apps
will have to aggressively optimize their web layers:

  - Background DOM Management: The Moodle Angular app will need to actively
    destroy heavy DOM elements (like large course lists or forums) when the app
    goes into the background, replacing them with placeholders to free up RAM.
  - Bitmap/Image Eviction: The WebView caches images heavily. When the user
    navigates away from an image-heavy course, the app must ensure the WebView
    releases those bitmaps from memory rather than keeping them cached in
    non-visible states.
  - Garbage Collection: Relying more heavily on WeakReferences in JavaScript and
    ensuring Angular observables are cleanly unsubscribed to prevent memory
    leaks in the Node/V8 engine powering the WebView.

3. Implementing the "Zero-Tap Sign-In" (Device Migration)

The blog post also mandates the adoption of the Android Restore Credentials API
for seamless device migration. For the Moodle app, this means updating the
native Android authentication plugins to hook into Android's Credential Manager
API. Instead of relying solely on standard web cookies or isolated local
storage, the app's native layer will need to back up the user's secure token so
that if a student buys a new phone, Moodle logs them in automatically.

The Path Forward for Moodle (and Cordova)

Because the enforcement deadline is February 2027, framework maintainers have
several months to react. You can expect the following to happen across the
ecosystem:

1.  Upstream Updates: The Apache Cordova and Ionic Capacitor teams will likely
    push updates to their Android build templates that include safe, boilerplate
    proguard-rules.pro files out of the box.
2.  Plugin Consumer Rules: Native plugin authors will increasingly embed
    consumerProguardFiles in their Gradle setups. This tells R8 exactly what to
    preserve automatically, taking the burden off the app developer.
3.  Moodle HQ Patches: For the Moodle app specifically, Moodle HQ will update
    their build pipeline before the 2027 deadline. If you are compiling your own
    custom version of the Moodle app, you should wait for Moodle HQ to release
    their compliant ProGuard configurations rather than trying to force R8 on
    your own today.