Stand up the Tanemaki monorepo and the first end-to-end vertical slice of Block 1 (offline, encrypted inventory): add a seed → see it in a categorized, searchable list → it persists → reopen and it's still there. Architecture (state management like G1nkgo, adapted to Tane's reality): - flutter_bloc (Cubit-first), but the encrypted Drift DB is the single source of truth; cubits stream from repositories (no hydrated_bloc/Hive, which would write plaintext at rest). - get_it composition root; go_router; slang i18n (ES/EN, Weblate-friendly JSON). Workspace & core: - pub workspace: packages/commons_core (pure Dart) + apps/app_seeds (Flutter). - commons_core primitives: UUIDv7 IdGen, Hybrid Logical Clock, Quantity value type (+ plant-aware QuantityKind), IdentityService root-seed stub. Data & security: - Drift schemaVersion=1 with all 10 Block-1 tables + common CRDT columns (HLC updated_at, last_author, tombstones); Movement append-only. - SQLCipher via an injectable executor that refuses to open a plaintext DB; DB key + root seed in the OS keystore (separate secrets). - Exported drift_schema_v1.json + migration scaffold. Tests (near-TDD; nothing merges without tests): - commons_core units (24), Drift migration test, "no plaintext at rest" security guard (runs where SQLCipher is present, skips otherwise), repository, widget, full quick-add flow, file-reopen persistence, and a no-hardcoded-strings i18n guard. GitLab CI: format + analyze + test + coverage. Follow-on Block-1 stories (item detail/edit, species catalog, germination UI) and all of Block 2 remain out of scope.
45 lines
1.6 KiB
Dart
45 lines
1.6 KiB
Dart
import 'dart:io';
|
|
|
|
import 'package:commons_core/commons_core.dart';
|
|
import 'package:get_it/get_it.dart';
|
|
import 'package:path/path.dart' as p;
|
|
import 'package:path_provider/path_provider.dart';
|
|
|
|
import '../data/variety_repository.dart';
|
|
import '../db/database.dart';
|
|
import '../db/encrypted_executor.dart';
|
|
import '../security/secret_store.dart';
|
|
import '../security/secure_key_store.dart';
|
|
|
|
/// The app's service locator. Kept to the composition root — widgets get their
|
|
/// repositories from here (or via BlocProvider), never by reaching into it deep
|
|
/// in the tree.
|
|
final GetIt getIt = GetIt.instance;
|
|
|
|
/// Wires the encrypted DB, keystore and repositories. Call once from `main`
|
|
/// before `runApp`; the DB key must exist before the DB opens.
|
|
Future<void> configureDependencies() async {
|
|
final keyStore = SecureKeyStore(store: FlutterSecretStore());
|
|
final dbKeyHex = await keyStore.databaseKeyHex();
|
|
final rootSeedHex = await keyStore.rootSeedHex();
|
|
|
|
final database = AppDatabase(
|
|
openEncryptedExecutor(await _databaseFile(), dbKeyHex),
|
|
);
|
|
|
|
// Until real key derivation lands, the node/author id is a stable per-install
|
|
// slice of the root seed. It becomes the user's public key in the social layer.
|
|
final nodeId = rootSeedHex.substring(0, 16);
|
|
|
|
getIt
|
|
..registerSingleton<SecureKeyStore>(keyStore)
|
|
..registerSingleton<AppDatabase>(database)
|
|
..registerSingleton<VarietyRepository>(
|
|
VarietyRepository(database, idGen: IdGen(), nodeId: nodeId),
|
|
);
|
|
}
|
|
|
|
Future<File> _databaseFile() async {
|
|
final dir = await getApplicationDocumentsDirectory();
|
|
return File(p.join(dir.path, 'tane_inventory.sqlite'));
|
|
}
|