feat(backup): sealed backups + printable recovery sheet

'Save a backup' now writes a sealed .tanemaki file (AES-256-GCM under a
key HKDF-derived from the root seed; format TANEBK v1, open and stable).
Restoring on the same identity is silent; a copy sealed by another
identity asks for the printed recovery code (TANE1 base32, typo-tolerant)
and adopts that seed — recovering your bank recovers you. Legacy plain
exports still restore. Settings gains a recovery sheet (QR + code PDF).
BackupBox/RecoveryCode live in commons_core, pure Dart, TDD.
This commit is contained in:
vjrj 2026-07-09 22:32:13 +02:00
parent ba87bf2719
commit d6781870d9
19 changed files with 1016 additions and 81 deletions

View file

@ -0,0 +1,158 @@
import 'dart:convert';
import 'dart:typed_data';
import 'package:commons_core/commons_core.dart';
import 'package:flutter_test/flutter_test.dart';
import 'package:tane/data/export_import/inventory_json_codec.dart';
import 'package:tane/db/database.dart';
import 'package:tane/security/secure_key_store.dart';
import 'package:tane/services/export_import_service.dart';
import 'package:tane/services/file_service.dart';
import '../support/test_support.dart';
class _FakeFiles implements FileService {
Uint8List? saved;
String? savedName;
Uint8List? toPick;
@override
Future<String?> saveFile({
required String suggestedName,
required Uint8List bytes,
}) async {
saved = bytes;
savedName = suggestedName;
return '/picked/$suggestedName';
}
@override
Future<Uint8List?> pickFileBytes({List<String>? allowedExtensions}) async =>
toPick;
}
void main() {
late AppDatabase dbA;
late AppDatabase dbB;
setUp(() {
dbA = newTestDatabase();
dbB = newTestDatabase();
});
tearDown(() async {
await dbA.close();
await dbB.close();
});
(ExportImportService, _FakeFiles, SecureKeyStore) newService(
AppDatabase db, {
String nodeId = 'node',
}) {
final files = _FakeFiles();
final keys = SecureKeyStore(store: InMemorySecretStore());
final service = ExportImportService(
repository: newTestRepository(db, nodeId: nodeId),
files: files,
keys: keys,
);
return (service, files, keys);
}
test('a saved backup is sealed — no plaintext leaves the app', () async {
final (service, files, _) = newService(dbA);
final repo = newTestRepository(dbA);
await repo.addQuickVariety(label: 'Secret heirloom');
await service.exportBackup();
expect(files.savedName, endsWith('.tanemaki'));
expect(BackupBox.looksSealed(files.saved!), isTrue);
expect(String.fromCharCodes(files.saved!).contains('Secret'), isFalse);
});
test('restore with the local seed needs no code (same identity)', () async {
final (serviceA, filesA, keysA) = newService(dbA);
final repoA = newTestRepository(dbA);
await repoA.addQuickVariety(label: 'Maize');
await serviceA.exportBackup();
// A fresh DB but the SAME keystore = your device after a reinstall.
final filesB = _FakeFiles()..toPick = filesA.saved;
final serviceB = ExportImportService(
repository: newTestRepository(dbB),
files: filesB,
keys: keysA,
);
final summary = await serviceB.restoreBackup(
(await serviceB.pickBackup())!,
);
expect(summary.inserted, 1);
final restored = await dbB.select(dbB.varieties).get();
expect(restored.single.label, 'Maize');
});
test(
'restore on a new device needs the recovery code and adopts the seed',
() async {
final (serviceA, filesA, keysA) = newService(dbA, nodeId: 'device-a');
final repoA = newTestRepository(dbA, nodeId: 'device-a');
await repoA.addQuickVariety(label: 'Grandma tomato');
await serviceA.exportBackup();
final code = await serviceA.recoveryCode();
final (serviceB, filesB, keysB) = newService(dbB, nodeId: 'device-b');
// Force device B to have its own (different) identity first.
final seedB = await keysB.rootSeedHex();
expect(seedB, isNot(await keysA.rootSeedHex()));
filesB.toPick = filesA.saved;
final pending = (await serviceB.pickBackup())!;
// Without the code: authentication fails, nothing imported.
await expectLater(
serviceB.restoreBackup(pending),
throwsA(isA<BackupAuthException>()),
);
expect(await dbB.select(dbB.varieties).get(), isEmpty);
// With the printed code: data restored AND identity recovered.
final summary = await serviceB.restoreBackup(pending, recoveryCode: code);
expect(summary.inserted, 1);
final restored = await dbB.select(dbB.varieties).get();
expect(restored.single.label, 'Grandma tomato');
expect(await keysB.rootSeedHex(), await keysA.rootSeedHex());
},
);
test('a sloppy typed code (lowercase, spaces) still opens', () async {
final (serviceA, filesA, _) = newService(dbA);
final repoA = newTestRepository(dbA);
await repoA.addQuickVariety(label: 'Bean');
await serviceA.exportBackup();
final code = await serviceA.recoveryCode();
final (serviceB, filesB, _) = newService(dbB);
filesB.toPick = filesA.saved;
final pending = (await serviceB.pickBackup())!;
final summary = await serviceB.restoreBackup(
pending,
recoveryCode: code.toLowerCase().replaceAll('-', ' '),
);
expect(summary.inserted, 1);
});
test('legacy plain exports still restore (no seal, direct parse)', () async {
final repoA = newTestRepository(dbA);
await repoA.addQuickVariety(label: 'Old export');
final legacy = utf8.encode(
const InventoryJsonCodec().encode(await repoA.exportInventory()),
);
final (serviceB, filesB, _) = newService(dbB);
filesB.toPick = Uint8List.fromList(legacy);
final summary = await serviceB.restoreBackup(
(await serviceB.pickBackup())!,
);
expect(summary.inserted, 1);
});
}

View file

@ -1,15 +1,17 @@
import 'dart:convert';
import 'dart:typed_data';
import 'package:commons_core/commons_core.dart';
import 'package:flutter/material.dart';
import 'package:flutter_localizations/flutter_localizations.dart';
import 'package:flutter_test/flutter_test.dart';
import 'package:tane/data/export_import/inventory_json_codec.dart';
import 'package:tane/data/export_import/inventory_snapshot.dart';
import 'package:tane/db/database.dart';
import 'package:tane/i18n/strings.g.dart';
import 'package:tane/security/secure_key_store.dart';
import 'package:tane/services/export_import_service.dart';
import 'package:tane/services/file_service.dart';
import 'package:tane/services/recovery_sheet_service.dart';
import 'package:tane/ui/backup_section.dart';
import 'package:tane/ui/settings_screen.dart';
@ -39,15 +41,20 @@ class FakeFileService implements FileService {
void main() {
late AppDatabase db;
late FakeFileService files;
late SecureKeyStore keys;
late ExportImportService service;
late RecoverySheetService sheet;
setUp(() {
db = newTestDatabase();
files = FakeFileService();
keys = SecureKeyStore(store: InMemorySecretStore());
service = ExportImportService(
repository: newTestRepository(db),
files: files,
keys: keys,
);
sheet = RecoverySheetService(files: files);
});
tearDown(() => db.close());
@ -66,6 +73,12 @@ void main() {
);
}
Widget section() => wrap(
Scaffold(
body: BackupSection(service: service, sheet: sheet),
),
);
testWidgets('settings shows the backup section with its actions', (
tester,
) async {
@ -76,6 +89,7 @@ void main() {
expect(find.text('Backup & restore'), findsOneWidget);
expect(find.text('Save a backup'), findsOneWidget);
expect(find.text('Restore a backup'), findsOneWidget);
expect(find.text('Your recovery code'), findsOneWidget);
expect(find.text('Export to a spreadsheet'), findsOneWidget);
expect(find.text('Import a list'), findsOneWidget);
});
@ -83,9 +97,7 @@ void main() {
testWidgets('spreadsheet export saves a .csv file and confirms', (
tester,
) async {
await tester.pumpWidget(
wrap(Scaffold(body: BackupSection(service: service))),
);
await tester.pumpWidget(section());
await tester.tap(find.text('Export to a spreadsheet'));
await tester.pumpAndSettle();
@ -94,35 +106,31 @@ void main() {
expect(find.text('Copy saved'), findsOneWidget);
});
testWidgets('saving a backup writes a versioned .json file', (tester) async {
await tester.pumpWidget(
wrap(Scaffold(body: BackupSection(service: service))),
);
testWidgets('saving a backup writes a sealed .tanemaki file', (tester) async {
await tester.pumpWidget(section());
await tester.tap(find.text('Save a backup'));
await tester.pumpAndSettle();
expect(files.savedName, endsWith('.json'));
final root =
jsonDecode(utf8.decode(files.savedBytes!)) as Map<String, dynamic>;
expect(root['formatVersion'], inventoryFormatVersion);
expect(files.savedName, endsWith('.tanemaki'));
expect(BackupBox.looksSealed(files.savedBytes!), isTrue);
expect(find.text('Copy saved'), findsOneWidget);
});
testWidgets('import asks for confirmation, imports and reports counts', (
tester,
) async {
// A valid one-variety export produced by another repository.
testWidgets('restoring my own sealed copy needs no code', (tester) async {
final otherDb = newTestDatabase();
addTearDown(otherDb.close);
final other = newTestRepository(otherDb, nodeId: 'node-other');
final otherFiles = FakeFileService();
final mine = ExportImportService(
repository: newTestRepository(otherDb, nodeId: 'other'),
files: otherFiles,
keys: keys, // same identity
);
final other = newTestRepository(otherDb, nodeId: 'other');
await other.addQuickVariety(label: 'Imported bean');
files.bytesToPick = utf8.encode(
const InventoryJsonCodec().encode(await other.exportInventory()),
);
await mine.exportBackup();
files.bytesToPick = otherFiles.savedBytes;
await tester.pumpWidget(
wrap(Scaffold(body: BackupSection(service: service))),
);
await tester.pumpWidget(section());
await tester.tap(find.text('Restore a backup'));
await tester.pumpAndSettle();
expect(find.text('Restore a backup?'), findsOneWidget);
@ -135,11 +143,64 @@ void main() {
expect(varieties.single.label, 'Imported bean');
});
testWidgets('a copy from another identity asks for the recovery code', (
tester,
) async {
final otherDb = newTestDatabase();
addTearDown(otherDb.close);
final otherFiles = FakeFileService();
final otherKeys = SecureKeyStore(store: InMemorySecretStore());
final theirs = ExportImportService(
repository: newTestRepository(otherDb, nodeId: 'other'),
files: otherFiles,
keys: otherKeys,
);
final other = newTestRepository(otherDb, nodeId: 'other');
await other.addQuickVariety(label: 'Recovered bean');
await theirs.exportBackup();
final code = await theirs.recoveryCode();
files.bytesToPick = otherFiles.savedBytes;
await tester.pumpWidget(section());
await tester.tap(find.text('Restore a backup'));
await tester.pumpAndSettle();
await tester.tap(find.text('Import'));
await tester.pumpAndSettle();
// Wrong seed the code prompt appears; type the printed code.
expect(find.text('Enter your recovery code'), findsOneWidget);
await tester.enterText(find.byKey(const Key('backup.recoveryField')), code);
await tester.tap(find.byKey(const Key('backup.recoveryConfirm')));
await tester.pumpAndSettle();
expect(find.text('Imported: 1 new, 0 updated'), findsOneWidget);
final varieties = await db.select(db.varieties).get();
expect(varieties.single.label, 'Recovered bean');
// The identity travelled with the code.
expect(await keys.rootSeedHex(), await otherKeys.rootSeedHex());
});
testWidgets('legacy plain exports still restore', (tester) async {
final otherDb = newTestDatabase();
addTearDown(otherDb.close);
final other = newTestRepository(otherDb, nodeId: 'node-other');
await other.addQuickVariety(label: 'Old bean');
files.bytesToPick = utf8.encode(
const InventoryJsonCodec().encode(await other.exportInventory()),
);
await tester.pumpWidget(section());
await tester.tap(find.text('Restore a backup'));
await tester.pumpAndSettle();
await tester.tap(find.text('Import'));
await tester.pumpAndSettle();
expect(find.text('Imported: 1 new, 0 updated'), findsOneWidget);
});
testWidgets('an unreadable file reports a friendly error', (tester) async {
files.bytesToPick = utf8.encode('this is not json');
await tester.pumpWidget(
wrap(Scaffold(body: BackupSection(service: service))),
);
await tester.pumpWidget(section());
await tester.tap(find.text('Restore a backup'));
await tester.pumpAndSettle();
await tester.tap(find.text('Import'));
@ -150,4 +211,25 @@ void main() {
findsOneWidget,
);
});
testWidgets('the recovery dialog shows the code and saves the sheet', (
tester,
) async {
await tester.pumpWidget(section());
await tester.tap(find.byKey(const Key('backup.recovery')));
await tester.pumpAndSettle();
final code = await service.recoveryCode();
expect(find.text(code), findsOneWidget);
await tester.tap(find.byKey(const Key('backup.recoverySave')));
await tester.pumpAndSettle();
expect(files.savedName, 'tanemaki-recovery.pdf');
expect(String.fromCharCodes(files.savedBytes!.take(5)), '%PDF-');
// The seed itself never appears in the clear in the PDF stream metadata;
// the QR encodes the human code, which IS the secret that's the point
// of the sheet. Just assert it saved and confirmed.
expect(find.text('Copy saved'), findsOneWidget);
});
}