tane/apps/app_seeds/lib/db/encrypted_executor.dart
vjrj 040f15a898 feat(block1): inventory walking skeleton + first quick-add slice
Stand up the Tanemaki monorepo and the first end-to-end vertical slice of
Block 1 (offline, encrypted inventory): add a seed → see it in a categorized,
searchable list → it persists → reopen and it's still there.

Architecture (state management like G1nkgo, adapted to Tane's reality):
- flutter_bloc (Cubit-first), but the encrypted Drift DB is the single source
  of truth; cubits stream from repositories (no hydrated_bloc/Hive, which would
  write plaintext at rest).
- get_it composition root; go_router; slang i18n (ES/EN, Weblate-friendly JSON).

Workspace & core:
- pub workspace: packages/commons_core (pure Dart) + apps/app_seeds (Flutter).
- commons_core primitives: UUIDv7 IdGen, Hybrid Logical Clock, Quantity value
  type (+ plant-aware QuantityKind), IdentityService root-seed stub.

Data & security:
- Drift schemaVersion=1 with all 10 Block-1 tables + common CRDT columns
  (HLC updated_at, last_author, tombstones); Movement append-only.
- SQLCipher via an injectable executor that refuses to open a plaintext DB;
  DB key + root seed in the OS keystore (separate secrets).
- Exported drift_schema_v1.json + migration scaffold.

Tests (near-TDD; nothing merges without tests):
- commons_core units (24), Drift migration test, "no plaintext at rest"
  security guard (runs where SQLCipher is present, skips otherwise),
  repository, widget, full quick-add flow, file-reopen persistence, and a
  no-hardcoded-strings i18n guard. GitLab CI: format + analyze + test + coverage.

Follow-on Block-1 stories (item detail/edit, species catalog, germination UI)
and all of Block 2 remain out of scope.
2026-07-07 15:16:14 +02:00

61 lines
2.2 KiB
Dart

import 'dart:ffi';
import 'dart:io';
import 'package:drift/drift.dart';
import 'package:drift/native.dart';
import 'package:sqlcipher_flutter_libs/sqlcipher_flutter_libs.dart';
import 'package:sqlite3/open.dart';
import 'package:sqlite3/sqlite3.dart';
/// Routes package:sqlite3 to the **SQLCipher** build instead of plain SQLite.
///
/// - Android: the bundled SQLCipher `.so` (from sqlcipher_flutter_libs).
/// - Linux: the system `libsqlcipher.so` (dev machines / CI install it).
/// - iOS & macOS: SQLCipher is linked into the app binary — no override needed.
void useSqlCipher() {
open
..overrideFor(OperatingSystem.android, openCipherOnAndroid)
..overrideFor(OperatingSystem.linux, _openLinuxCipher);
}
DynamicLibrary _openLinuxCipher() {
// The dev package ships `libsqlcipher.so`; the runtime package only the
// versioned `libsqlcipher.so.0`. Accept either.
try {
return DynamicLibrary.open('libsqlcipher.so');
} on ArgumentError {
return DynamicLibrary.open('libsqlcipher.so.0');
}
}
/// Opens [file] as an encrypted database using the raw 256-bit [keyHex].
///
/// Verifies SQLCipher is actually linked (`PRAGMA cipher_version`) and refuses
/// to fall back to plaintext — enforcing "no plaintext at rest, ever".
QueryExecutor openEncryptedExecutor(File file, String keyHex) {
return LazyDatabase(() async {
if (Platform.isAndroid) {
await applyWorkaroundToOpenSqlCipherOnOldAndroidVersions();
}
return NativeDatabase.createInBackground(
file,
isolateSetup: useSqlCipher,
setup: (db) => applyKeyAndVerify(db, keyHex),
);
});
}
/// Applies the SQLCipher key to [db] and asserts encryption is active.
///
/// `x'…'` passes the key as raw bytes, skipping the KDF (our key is already a
/// random 256-bit value from the OS keystore). Exposed for the security test.
void applyKeyAndVerify(Database db, String keyHex) {
db.execute('PRAGMA key = "x\'$keyHex\'";');
final cipher = db.select('PRAGMA cipher_version;');
if (cipher.isEmpty) {
throw StateError(
'SQLCipher is not linked: PRAGMA cipher_version is empty. Encryption at '
'rest is mandatory — refusing to open a plaintext database.',
);
}
}