Show HN: Gander, an Android file viewer that asks for no permissions at all
摘要
Gander 是一个约 15 MB 的开源 Android 文件查看器,完全离线,不申请任何权限(甚至没有 INTERNET 权限),无广告、无追踪、无账号。它通过 Storage Access Framework 和 “打开方式” 接收文件,在沙箱 WebView 中渲染 Office 格式,支持 PDF、Word、Excel、PPT、图片、音视频、Markdown、文本和代码等格式,提供缩略图、文件夹浏览、文档内搜索、分享与定位等功能,运行于 Android 8.0+。项目采用 MIT 许可证,附带构建说明和路线图。
荐读理由
零权限架构是现成的可抄方案:靠 SAF 和 Open with 收文件、WebViewAssetLoader 拦截所有请求、干脆不声明 INTERNET 权限,这套组合拳能直接搬到你自己的移动端或隐私敏感项目里,省去自己摸索权限边界的功夫。
原文
Gander 🪿
Take a gander at any file. A tiny, open source, fully offline file viewer for Android that opens PDF, Word, Excel, PowerPoint, photos, videos, audio, Markdown, text and code in one app, with zero permissions, no ads, no tracking and no internet access at all.
Every phone ships with a dozen half-viewers that bounce your documents to cloud services. Gander is the opposite: one small APK (about 15 MB) that renders everything on the device. It cannot phone home because it does not even hold the INTERNET permission.
Screenshots
| Home: recents and folders | Folder browsing | |
|---|---|---|
![]() |
![]() |
![]() |
| Word (.docx) | PowerPoint (.pptx) | Excel (.xlsx) |
|---|---|---|
![]() |
![]() |
![]() |
Features
One viewer for everything: documents, spreadsheets, slides, images, video, audio, Markdown, code
Pinch zoom and smooth scrolling everywhere, with deep zoom into huge photos (tiled decoding)
Recent files with thumbnail previews (image, video frame, PDF first page)
Folder browsing through one-time system grants, still without any storage permission
Share sheet and "Open with" integration: share a file from any app (chat, mail, browser) into Gander, or tap it in a file manager
Find in document: search inside Word, Excel, slides, Markdown, text and code with match navigation
Share and locate: send the open file to any app, or jump to its folder in the file manager
Private by construction: no permissions, no INTERNET, no analytics, no accounts, nothing leaves the phone
Modern Android: Material 3, dark mode, edge to edge, works on Android 8.0+
Supported formats
| Category | Formats | Renderer |
|---|---|---|
| Documents | Pdfium (native) | |
Word .docx |
docx-preview, offline in a sandboxed WebView | |
| Spreadsheets | .xlsx .xls .xlsm .xlsb .csv .ods |
SheetJS, offline |
| Slides | PowerPoint .pptx |
PPTXjs, offline |
| Photos | JPG, PNG, WebP, BMP, HEIC/HEIF | Tiled deep-zoom image view, EXIF aware |
| GIF (animated), SVG, AVIF, ICO | WebView | |
| Video | MP4, M4V, MOV, MKV, WebM, 3GP, AVI, FLV, MPEG-TS | Media3 ExoPlayer |
| Audio | MP3, M4A, AAC, FLAC, WAV, OGG, Opus, AMR | Media3 ExoPlayer |
| Markdown | .md rendered as formatted HTML |
marked + DOMPurify, offline |
| Text and code | .txt .json .xml logs, most source files |
Text viewer |
Legacy binary .doc and .ppt are not supported (no faithful offline renderer exists); the app explains this and suggests re-saving as .docx / .pptx. Binary .xls works.
Install
Runs on Android 8.0 (API 26) and up.
Download the latest APK from Releases:
Gander-x.y-arm64.apkfits practically every phone from 2017 onward (use theuniversalAPK for very old or x86 devices).Copy it to your phone, tap it, and allow "install unknown apps" when asked.
Optional: Play Protect may warn about an unknown developer; that is what sideloaded open source looks like. Tap "Install anyway".
Updating: install the new APK over the old one; recents and folder grants survive.
Automatic updates without a store: install Obtainium and add https://github.com/mokshablr/gander as an app source. It follows the tagged GitHub releases here and updates Gander like a store would.
Verify before installing: every release is signed with the same key, so you can confirm an APK really came from this repo. Obtainium can pin the fingerprint below, and for a file you have already downloaded:
apksigner verify --print-certs Gander-x.y-arm64.apk
Signing certificate SHA-256:
5B:5C:F6:4A:94:23:7C:D5:F0:E0:85:76:00:38:BC:1C:EB:DF:18:DA:BA:5C:B3:EA:CA:7C:15:9F:22:A7:E2:4B
How the zero-permission trick works
Gander receives files through the Storage Access Framework and "Open with" intents, so the OS hands it exactly the documents you chose and nothing else. Office formats render inside a locked-down WebView whose every request is intercepted by WebViewAssetLoader: bundled JS libraries load from app assets and the document streams from the content URI. No network stack is ever touched, and the app does not declare the INTERNET permission, so there is nothing to audit or trust.
Folder browsing uses ACTION_OPEN_DOCUMENT_TREE grants. Note that Android itself refuses to grant the Downloads root to any app; grant Documents, DCIM or a subfolder of Downloads instead.
Build from source
To build it yourself you need JDK 17+ and the Android SDK (platform 35). These are build requirements only. The installed app runs on Android 8.0 (API 26) and up.
./gradlew assembleDebug # installable debug build
./gradlew assembleRelease # unsigned without a keystore
Release signing expects a local, untracked keystore at keystore/gander.jks (store and key password gander-local, alias gander); generate one with:
keytool -genkeypair -keystore keystore/gander.jks -alias gander \
-keyalg RSA -keysize 2048 -validity 10000 \
-storepass gander-local -keypass gander-local -dname "CN=Gander"
The keystore is gitignored on purpose: it is a personal signing key and must never land in a public repo.
Architecture in one paragraph
ViewerActivity routes by file extension first, MIME type second (FileKind.kt), into one of four surfaces: a native Pdfium view for PDF, a tiled SubsamplingScaleImageView for photos, Media3 ExoPlayer for video and audio, or a sandboxed WebView for everything rendered by vendored JS libraries (app/src/main/assets/viewer/). The home screen (MainActivity) lists recents (persisted SAF grants) and granted folders (DocumentsContract child queries), with thumbnails generated off-thread and cached (Thumbs.kt).
Vendored viewer libraries and their licenses: JSZip (MIT), docx-preview (Apache-2.0), SheetJS CE (Apache-2.0), PPTXjs + divs2slides (MIT), jQuery 1.11 (MIT), D3 3.x + NVD3 (BSD/Apache), marked (MIT), DOMPurify (Apache-2.0/MPL).
Roadmap
F-Droid listing
Legacy
.doc/.pptsupport if a usable offline renderer appearsiOS companion (thin QuickLook wrapper)
Contributing
Issues and small PRs are welcome, see CONTRIBUTING.md. If Gander is useful to you, a star helps other people find it.
License
MIT. Vendored viewer libraries keep their own licenses, listed above; all are MIT/Apache/BSD and compatible.
这条对你有帮助吗?







