Class Cefrium

java.lang.Object
com.cefrium.Cefrium

public final class Cefrium extends Object
Entry point for the Cefrium SDK. Initialize once before creating browsers.

User-Agent

Cefrium identifies itself as Chrome (because it IS Chromium) with a Cefrium product token appended:

Mozilla/5.0 (Linux; Android ...) AppleWebKit/537.36 (KHTML, like Gecko)
    Chrome/149.0.7827.102 Cefrium/1.0 Mobile Safari/537.36

This ensures full site compatibility while transparently identifying the client. The User-Agent is configured via CefSettings.user_agent_product in the native layer. To customize it, use the --user-agent-product command-line switch before calling initialize():

// Custom product string (replaces the default):
CommandLine.getInstance().appendSwitchWithValue(
    "user-agent-product",
    "Chrome/149.0.7827.102 MyApp/2.0 Mobile");
Cefrium.initialize(context);

Basic usage

No setup is required: the SDK's CefriumInitProvider performs the per-process plumbing at app launch, and the engine initializes lazily the first time a browser is created. Just create one:

CefriumBrowser browser = CefriumBrowser.createWithSurface(activity);
browser.loadUrl("https://example.com");

// When done:
Cefrium.shutdown();

Advanced: to control init timing (e.g. to pass command-line switches before native init) call initialize(Context) yourself before the first browser. It is idempotent and self-sufficient — no custom Application needed.

  • Field Details

    • VERSION

      public static final String VERSION
      Cefrium SDK version. Kept in lockstep with the release by cut-release.sh.
      See Also:
    • CHROMIUM_VERSION

      public static final String CHROMIUM_VERSION
      Bundled Chromium engine version (pinned to the build).
      See Also:
  • Method Details

    • setComponentUpdatesEnabled

      public static void setComponentUpdatesEnabled(boolean enabled)
      Control whether the engine keeps its security data up to date over the network. Enabled by default. Must be called before the engine initializes, i.e. before initialize(Context) and before the first browser is created; afterwards it has no effect and logs a warning.

      When enabled (the default), Chromium's component updater contacts update.googleapis.com and downloads data files the engine relies on: the certificate revocation list (CRLSet), Certificate Transparency log metadata, the dangerous-download file-type policy, TLS error diagnostics, Trust Token key commitments, First-Party Sets and the subresource filtering ruleset. The request carries component ids and versions, the platform, and a random per-component install identifier. It carries no URL, no account and nothing the user typed.

      What you give up by disabling it. This is a security trade-off, not merely a privacy setting. With component updates off, all of the above freeze at the state baked into the SDK version you shipped. In particular certificate revocation data stops being refreshed, so a certificate revoked after your build date will still be accepted. The failure mode is silent: nothing crashes and no user complains. If you disable this, you are taking on responsibility for shipping SDK updates promptly.

      Legitimate reasons to disable it: an air-gapped or offline deployment where the requests cannot succeed anyway, a kiosk on a metered or whitelisted network, or a deployment whose compliance regime forbids unattended third-party requests. In those cases pin the SDK version deliberately and track releases.

      Implemented with Chromium's own --disable-component-update switch, which suppresses RegisterComponentsForUpdate() in the browser process. It is an upstream switch, so it keeps working across engine updates.

      Parameters:
      enabled - false to stop the engine's component update checks.
    • areComponentUpdatesEnabled

      public static boolean areComponentUpdatesEnabled()
      Returns:
      whether engine component updates are enabled (default true).
    • setNetworkTimeQueriesEnabled

      public static void setNetworkTimeQueriesEnabled(boolean enabled)
      Control whether the engine queries Google's time service. Disabled by default in Cefrium, which is a deliberate divergence from Chromium, where the feature is enabled by default on Android. Must be called before the engine initializes, i.e. before initialize(Context) and before the first browser is created; afterwards it has no effect and logs a warning.

      When enabled, the engine performs an occasional request to http://clients2.google.com/time/1/current (roughly daily by design) to detect a badly set device clock. The request carries no identifier and no user data.

      Why Cefrium defaults this off. The query's only purpose is to explain a certificate error better: on a device whose clock is wrong, Chromium can say so instead of showing a generic "certificate expired". It carries no security data, so switching it off costs no freshness -- unlike setComponentUpdatesEnabled(boolean). On Android the system clock is already synchronised by the carrier or by NTP, so the diagnosis is rarely needed, and an unconditional daily request to a third party is a poor trade for an embedded engine whose host app did not ask for it. Certificate validation itself is unaffected either way.

      Pass true to restore Chromium's upstream behaviour. That is the right call if your deployment runs on hardware with no reliable clock source -- devices with no cellular modem and no NTP reachability, or a kiosk whose RTC has no battery -- where a clock far enough off to break HTTPS is a real support case and a precise error message saves a call.

      Implemented by disabling Chromium's NetworkTimeServiceQuerying feature. Any disable-features value already on the command line is preserved and appended to, not overwritten.

      Parameters:
      enabled - true to restore the engine's network time queries.
    • areNetworkTimeQueriesEnabled

      public static boolean areNetworkTimeQueriesEnabled()
      Returns:
      whether engine network time queries are enabled (default false).
    • setupProcess

      public static void setupProcess(android.content.Context context)
      Run the per-process Chromium setup the browser process needs before native init. Idempotent and safe to call from any process: it is a no-op in Chromium child processes (sandboxed renderer/GPU/utility), which self-init via ChildProcessService. The SDK's CefriumInitProvider calls this automatically at app launch, and initialize(Context) calls it too, so consumers normally never call it directly.
      Parameters:
      context - Any context (its application context is used).
    • initialize

      public static boolean initialize()
      Initialize the Cefrium engine using the application context captured during per-process setup. Equivalent to initialize(Context) but for callers that have no Context handy (e.g. off-screen browser creation). Requires that setupProcess(Context) has run — which the SDK's CefriumInitProvider guarantees at app launch.
      Returns:
      true if initialization succeeded.
    • initialize

      public static boolean initialize(android.content.Context context)
      Initialize the Cefrium engine. Safe to call more than once (idempotent) and self-sufficient: it runs setupProcess(Context) itself, so no Application boilerplate is required. Must be called on the main thread (the SDK does this lazily on first browser creation).
      Parameters:
      context - Application context.
      Returns:
      true if initialization succeeded.
    • shutdown

      public static void shutdown()
      Shut down the Cefrium engine. Call when the app is finishing. After this call, no Cefrium APIs may be used.
    • isInitialized

      public static boolean isInitialized()
      Returns:
      true if Cefrium has been initialized.
    • getVersion

      public static String getVersion()
      Returns:
      the Cefrium SDK version, e.g. "0.5.0".
    • getChromiumVersion

      public static String getChromiumVersion()
      Returns:
      the bundled Chromium engine version, e.g. "149.0.7827.102".
    • loadAdBlockList

      public static int loadAdBlockList(String path)
      Load ad-blocking filter rules from an EasyList-format file. Can be called multiple times to load additional lists.
      Parameters:
      path - Absolute path to the filter list file.
      Returns:
      Number of rules loaded.
    • downloadAndLoadEasyList

      public static void downloadAndLoadEasyList(android.content.Context context)
      Download and load EasyList from the internet. Call from a background thread — performs network I/O.
      Parameters:
      context - Application context for file storage.