feat(block1): inventory walking skeleton + first quick-add slice

Stand up the Tanemaki monorepo and the first end-to-end vertical slice of
Block 1 (offline, encrypted inventory): add a seed → see it in a categorized,
searchable list → it persists → reopen and it's still there.

Architecture (state management like G1nkgo, adapted to Tane's reality):
- flutter_bloc (Cubit-first), but the encrypted Drift DB is the single source
  of truth; cubits stream from repositories (no hydrated_bloc/Hive, which would
  write plaintext at rest).
- get_it composition root; go_router; slang i18n (ES/EN, Weblate-friendly JSON).

Workspace & core:
- pub workspace: packages/commons_core (pure Dart) + apps/app_seeds (Flutter).
- commons_core primitives: UUIDv7 IdGen, Hybrid Logical Clock, Quantity value
  type (+ plant-aware QuantityKind), IdentityService root-seed stub.

Data & security:
- Drift schemaVersion=1 with all 10 Block-1 tables + common CRDT columns
  (HLC updated_at, last_author, tombstones); Movement append-only.
- SQLCipher via an injectable executor that refuses to open a plaintext DB;
  DB key + root seed in the OS keystore (separate secrets).
- Exported drift_schema_v1.json + migration scaffold.

Tests (near-TDD; nothing merges without tests):
- commons_core units (24), Drift migration test, "no plaintext at rest"
  security guard (runs where SQLCipher is present, skips otherwise),
  repository, widget, full quick-add flow, file-reopen persistence, and a
  no-hardcoded-strings i18n guard. GitLab CI: format + analyze + test + coverage.

Follow-on Block-1 stories (item detail/edit, species catalog, germination UI)
and all of Block 2 remain out of scope.
This commit is contained in:
vjrj 2026-07-07 15:16:14 +02:00
parent 57c0eeadaf
commit 040f15a898
131 changed files with 19855 additions and 20 deletions

View file

@ -0,0 +1,27 @@
import 'package:flutter_secure_storage/flutter_secure_storage.dart';
/// Minimal secret key/value store, backed by the OS keystore in production and
/// trivially fakeable in tests. Keeps [SecureKeyStore] free of plugin calls.
abstract class SecretStore {
Future<String?> read(String key);
Future<void> write(String key, String value);
}
/// OS-keystore-backed implementation (Android Keystore / iOS Keychain / etc.).
class FlutterSecretStore implements SecretStore {
FlutterSecretStore([FlutterSecureStorage? storage])
: _storage =
storage ??
const FlutterSecureStorage(
aOptions: AndroidOptions(encryptedSharedPreferences: true),
);
final FlutterSecureStorage _storage;
@override
Future<String?> read(String key) => _storage.read(key: key);
@override
Future<void> write(String key, String value) =>
_storage.write(key: key, value: value);
}

View file

@ -0,0 +1,45 @@
import 'package:commons_core/commons_core.dart';
import 'secret_store.dart';
/// Owns the app's secrets in the OS keystore and creates them on first run:
///
/// - the **DB key**: a random 256-bit symmetric key for SQLCipher (NOT derived
/// from any user password see CLAUDE.md identity section);
/// - the **root seed**: the Duniter/Ğ1-style identity seed (stub for now).
///
/// Both are stored as lowercase hex strings.
class SecureKeyStore {
SecureKeyStore({required SecretStore store, IdentityService? identity})
: _store = store,
_identity = identity ?? IdentityService();
final SecretStore _store;
final IdentityService _identity;
static const dbKeyName = 'tane.db_key';
static const rootSeedName = 'tane.root_seed';
static const _dbKeyLengthBytes = 32;
/// The SQLCipher database key as hex, created and persisted on first access.
Future<String> databaseKeyHex() =>
_readOrCreate(dbKeyName, () => randomBytes(_dbKeyLengthBytes));
/// The root identity seed as hex, created and persisted on first access.
Future<String> rootSeedHex() =>
_readOrCreate(rootSeedName, _identity.generateRootSeed);
Future<String> _readOrCreate(
String key,
List<int> Function() generate,
) async {
final existing = await _store.read(key);
if (existing != null) return existing;
final hex = _toHex(generate());
await _store.write(key, hex);
return hex;
}
static String _toHex(List<int> bytes) =>
bytes.map((b) => b.toRadixString(16).padLeft(2, '0')).join();
}