Every permission is declared with <uses-permission>; its protection level decides the rest:
| Type | Granted | Examples |
|---|---|---|
| Normal | At install, silently | INTERNET, VIBRATE, ACCESS_NETWORK_STATE |
| Signature | At install, only to apps signed like the definer | Autofill and VPN services, your own app suite |
| Dangerous (runtime) | By the user, via a dialog | CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION |
| Special | By the user, in a Settings screen | SYSTEM_ALERT_WINDOW, SCHEDULE_EXACT_ALARM |
BookNest marks the camera feature optional, or Google Play 1 hides it from devices without a camera:
<uses-permission android:name="android.permission.CAMERA" />
<uses-feature android:name="android.hardware.camera" android:required="false" />
...
<intent-filter> <!-- booknest://book/<id> -->
<action android:name="android.intent.action.VIEW" />
<category android:name="android.intent.category.DEFAULT" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="booknest" android:host="book" />
</intent-filter>
</activity>
<activity android:name=".NoteActivity" android:exported="false" />Library manifests merge into yours and can add permissions you never wrote, as androidx.core did in the merged manifest of AndroidManifest.xml, so read the merged manifest before every release.