feat(block1): inventory walking skeleton + first quick-add slice

Stand up the Tanemaki monorepo and the first end-to-end vertical slice of
Block 1 (offline, encrypted inventory): add a seed → see it in a categorized,
searchable list → it persists → reopen and it's still there.

Architecture (state management like G1nkgo, adapted to Tane's reality):
- flutter_bloc (Cubit-first), but the encrypted Drift DB is the single source
  of truth; cubits stream from repositories (no hydrated_bloc/Hive, which would
  write plaintext at rest).
- get_it composition root; go_router; slang i18n (ES/EN, Weblate-friendly JSON).

Workspace & core:
- pub workspace: packages/commons_core (pure Dart) + apps/app_seeds (Flutter).
- commons_core primitives: UUIDv7 IdGen, Hybrid Logical Clock, Quantity value
  type (+ plant-aware QuantityKind), IdentityService root-seed stub.

Data & security:
- Drift schemaVersion=1 with all 10 Block-1 tables + common CRDT columns
  (HLC updated_at, last_author, tombstones); Movement append-only.
- SQLCipher via an injectable executor that refuses to open a plaintext DB;
  DB key + root seed in the OS keystore (separate secrets).
- Exported drift_schema_v1.json + migration scaffold.

Tests (near-TDD; nothing merges without tests):
- commons_core units (24), Drift migration test, "no plaintext at rest"
  security guard (runs where SQLCipher is present, skips otherwise),
  repository, widget, full quick-add flow, file-reopen persistence, and a
  no-hardcoded-strings i18n guard. GitLab CI: format + analyze + test + coverage.

Follow-on Block-1 stories (item detail/edit, species catalog, germination UI)
and all of Block 2 remain out of scope.
This commit is contained in:
vjrj 2026-07-07 15:16:14 +02:00
parent 57c0eeadaf
commit 040f15a898
131 changed files with 19855 additions and 20 deletions

View file

@ -0,0 +1,41 @@
import 'package:flutter_test/flutter_test.dart';
import 'package:tane/security/secret_store.dart';
import 'package:tane/security/secure_key_store.dart';
class InMemorySecretStore implements SecretStore {
final Map<String, String> _values = {};
int writeCount = 0;
@override
Future<String?> read(String key) async => _values[key];
@override
Future<void> write(String key, String value) async {
_values[key] = value;
writeCount++;
}
}
void main() {
group('SecureKeyStore', () {
test('creates a 256-bit (64 hex char) db key on first run', () async {
final keys = SecureKeyStore(store: InMemorySecretStore());
final key = await keys.databaseKeyHex();
expect(key, matches(RegExp(r'^[0-9a-f]{64}$')));
});
test('reuses the same db key across calls (created once)', () async {
final store = InMemorySecretStore();
final keys = SecureKeyStore(store: store);
final first = await keys.databaseKeyHex();
final second = await keys.databaseKeyHex();
expect(second, first);
expect(store.writeCount, 1);
});
test('db key and root seed are independent secrets', () async {
final keys = SecureKeyStore(store: InMemorySecretStore());
expect(await keys.databaseKeyHex(), isNot(await keys.rootSeedHex()));
});
});
}