Stand up the Tanemaki monorepo and the first end-to-end vertical slice of Block 1 (offline, encrypted inventory): add a seed → see it in a categorized, searchable list → it persists → reopen and it's still there. Architecture (state management like G1nkgo, adapted to Tane's reality): - flutter_bloc (Cubit-first), but the encrypted Drift DB is the single source of truth; cubits stream from repositories (no hydrated_bloc/Hive, which would write plaintext at rest). - get_it composition root; go_router; slang i18n (ES/EN, Weblate-friendly JSON). Workspace & core: - pub workspace: packages/commons_core (pure Dart) + apps/app_seeds (Flutter). - commons_core primitives: UUIDv7 IdGen, Hybrid Logical Clock, Quantity value type (+ plant-aware QuantityKind), IdentityService root-seed stub. Data & security: - Drift schemaVersion=1 with all 10 Block-1 tables + common CRDT columns (HLC updated_at, last_author, tombstones); Movement append-only. - SQLCipher via an injectable executor that refuses to open a plaintext DB; DB key + root seed in the OS keystore (separate secrets). - Exported drift_schema_v1.json + migration scaffold. Tests (near-TDD; nothing merges without tests): - commons_core units (24), Drift migration test, "no plaintext at rest" security guard (runs where SQLCipher is present, skips otherwise), repository, widget, full quick-add flow, file-reopen persistence, and a no-hardcoded-strings i18n guard. GitLab CI: format + analyze + test + coverage. Follow-on Block-1 stories (item detail/edit, species catalog, germination UI) and all of Block 2 remain out of scope.
61 lines
2.2 KiB
Dart
61 lines
2.2 KiB
Dart
import 'dart:ffi';
|
|
import 'dart:io';
|
|
|
|
import 'package:drift/drift.dart';
|
|
import 'package:drift/native.dart';
|
|
import 'package:sqlcipher_flutter_libs/sqlcipher_flutter_libs.dart';
|
|
import 'package:sqlite3/open.dart';
|
|
import 'package:sqlite3/sqlite3.dart';
|
|
|
|
/// Routes package:sqlite3 to the **SQLCipher** build instead of plain SQLite.
|
|
///
|
|
/// - Android: the bundled SQLCipher `.so` (from sqlcipher_flutter_libs).
|
|
/// - Linux: the system `libsqlcipher.so` (dev machines / CI install it).
|
|
/// - iOS & macOS: SQLCipher is linked into the app binary — no override needed.
|
|
void useSqlCipher() {
|
|
open
|
|
..overrideFor(OperatingSystem.android, openCipherOnAndroid)
|
|
..overrideFor(OperatingSystem.linux, _openLinuxCipher);
|
|
}
|
|
|
|
DynamicLibrary _openLinuxCipher() {
|
|
// The dev package ships `libsqlcipher.so`; the runtime package only the
|
|
// versioned `libsqlcipher.so.0`. Accept either.
|
|
try {
|
|
return DynamicLibrary.open('libsqlcipher.so');
|
|
} on ArgumentError {
|
|
return DynamicLibrary.open('libsqlcipher.so.0');
|
|
}
|
|
}
|
|
|
|
/// Opens [file] as an encrypted database using the raw 256-bit [keyHex].
|
|
///
|
|
/// Verifies SQLCipher is actually linked (`PRAGMA cipher_version`) and refuses
|
|
/// to fall back to plaintext — enforcing "no plaintext at rest, ever".
|
|
QueryExecutor openEncryptedExecutor(File file, String keyHex) {
|
|
return LazyDatabase(() async {
|
|
if (Platform.isAndroid) {
|
|
await applyWorkaroundToOpenSqlCipherOnOldAndroidVersions();
|
|
}
|
|
return NativeDatabase.createInBackground(
|
|
file,
|
|
isolateSetup: useSqlCipher,
|
|
setup: (db) => applyKeyAndVerify(db, keyHex),
|
|
);
|
|
});
|
|
}
|
|
|
|
/// Applies the SQLCipher key to [db] and asserts encryption is active.
|
|
///
|
|
/// `x'…'` passes the key as raw bytes, skipping the KDF (our key is already a
|
|
/// random 256-bit value from the OS keystore). Exposed for the security test.
|
|
void applyKeyAndVerify(Database db, String keyHex) {
|
|
db.execute('PRAGMA key = "x\'$keyHex\'";');
|
|
final cipher = db.select('PRAGMA cipher_version;');
|
|
if (cipher.isEmpty) {
|
|
throw StateError(
|
|
'SQLCipher is not linked: PRAGMA cipher_version is empty. Encryption at '
|
|
'rest is mandatory — refusing to open a plaintext database.',
|
|
);
|
|
}
|
|
}
|