feat: Phase 3 — E2EE calls, Jitsi conferencing, help tab, web security model
- LiveKit call E2EE: CallE2EEManager exchanges encryption keys via Matrix to-device events (m.rtc.encryption_keys) for interop with Element X - Olm bootstrapped in index.html before Flutter init; main.dart logs result - Encrypted messages shown with lock icon and informative fallback text - Profile screen: key restore dialog + security setup (cross-signing/backup) - Jitsi feature: welcome screen (public, no login), conference tab, full-screen embed via JitsiMeetExternalAPI, JitsiLink parser for all common link formats - Help tab: expandable cards for encryption, video calls, account management - Web security model: no session persistence — device ID only across visits - Media auth: MSC3916 authenticated endpoint for avatars (Synapse 1.120+) - Router: welcome route as public landing page; jitsi route as public - Manifest/index.html: M8Chat branding, dark theme colours Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -1,88 +1,28 @@
|
||||
// Version: 1.1.1 | Created: 2026-04-01
|
||||
// Version: 2.0.0 | Created: 2026-04-01 | Updated: 2026-04-11
|
||||
// Riverpod notifier that owns the auth state machine.
|
||||
// All login/logout/session-restore transitions go through here.
|
||||
|
||||
import 'dart:async';
|
||||
//
|
||||
// WEB SECURITY MODEL: Every visit requires a fresh login. No session
|
||||
// persistence. Only the Matrix device ID is saved across sessions so
|
||||
// encryption keys accumulate on one device instead of creating ghosts.
|
||||
|
||||
import 'package:flutter/foundation.dart';
|
||||
import 'package:riverpod_annotation/riverpod_annotation.dart';
|
||||
|
||||
import '../../features/auth/data/auth_repository.dart';
|
||||
import '../../features/auth/domain/auth_failure.dart';
|
||||
import '../storage/sync_persistence_service.dart';
|
||||
import 'auth_state.dart';
|
||||
import 'secure_storage.dart';
|
||||
|
||||
part 'auth_notifier.g.dart';
|
||||
|
||||
/// The single source of truth for authentication state.
|
||||
///
|
||||
/// keepAlive: true — auth state must persist for the entire app lifetime.
|
||||
/// GoRouter watches this provider to decide which route to show.
|
||||
@Riverpod(keepAlive: true)
|
||||
class AuthNotifier extends _$AuthNotifier {
|
||||
@override
|
||||
AuthState build() {
|
||||
// Kick off session restore immediately; start in [AuthInitial].
|
||||
_restoreSession();
|
||||
return const AuthState.initial();
|
||||
// No session restore on web — always require fresh login.
|
||||
return const AuthState.unauthenticated();
|
||||
}
|
||||
|
||||
/// Tries to restore a previous session from secure storage.
|
||||
Future<void> _restoreSession() async {
|
||||
state = const AuthState.loading();
|
||||
|
||||
final storage = ref.read(secureStorageProvider);
|
||||
final credentials = await storage.loadCredentials();
|
||||
|
||||
if (credentials == null) {
|
||||
state = const AuthState.unauthenticated();
|
||||
return;
|
||||
}
|
||||
|
||||
try {
|
||||
final repo = ref.read(authRepositoryProvider);
|
||||
|
||||
// Timeout: client.init() starts the Matrix sync loop and can hang
|
||||
// indefinitely if the token is expired or the server is unreachable.
|
||||
// After 12 seconds we give up and send the user to the login screen.
|
||||
await repo
|
||||
.restoreSession(
|
||||
accessToken: credentials.accessToken,
|
||||
userId: credentials.userId,
|
||||
deviceId: credentials.deviceId,
|
||||
)
|
||||
.timeout(
|
||||
const Duration(seconds: 12),
|
||||
onTimeout: () => throw Exception('Session restore timed out'),
|
||||
);
|
||||
|
||||
state = AuthState.authenticated(
|
||||
userId: credentials.userId,
|
||||
accessToken: credentials.accessToken,
|
||||
deviceId: credentials.deviceId,
|
||||
);
|
||||
|
||||
// Resume background persistence — fire-and-forget so it never blocks auth.
|
||||
try {
|
||||
ref.read(syncPersistenceServiceProvider).start();
|
||||
} catch (_) {
|
||||
// Persistence failure is non-fatal; the app works without it.
|
||||
}
|
||||
} on AuthFailure {
|
||||
// Stored credentials are invalid; force re-login.
|
||||
await storage.clearCredentials();
|
||||
state = const AuthState.unauthenticated();
|
||||
} on Exception {
|
||||
// Covers: timeout, network offline, Olm init failure.
|
||||
// Clear stale credentials so the login screen appears cleanly.
|
||||
await storage.clearCredentials();
|
||||
state = const AuthState.unauthenticated();
|
||||
}
|
||||
}
|
||||
|
||||
/// Attempts to log in with [username] and [password].
|
||||
///
|
||||
/// Transitions: loading → authenticated | unauthenticated(failure).
|
||||
Future<void> login({
|
||||
required String username,
|
||||
required String password,
|
||||
@@ -91,38 +31,38 @@ class AuthNotifier extends _$AuthNotifier {
|
||||
|
||||
try {
|
||||
final repo = ref.read(authRepositoryProvider);
|
||||
final response = await repo.login(username: username, password: password);
|
||||
debugPrint('[Auth] Logging in...');
|
||||
|
||||
final storage = ref.read(secureStorageProvider);
|
||||
await storage.saveCredentials(
|
||||
accessToken: response.accessToken,
|
||||
userId: response.userId,
|
||||
deviceId: response.deviceId,
|
||||
final response = await repo.login(
|
||||
username: username,
|
||||
password: password,
|
||||
);
|
||||
|
||||
debugPrint('[Auth] Login OK as ${response.userId} '
|
||||
'device=${response.deviceId}');
|
||||
|
||||
state = AuthState.authenticated(
|
||||
userId: response.userId,
|
||||
accessToken: response.accessToken,
|
||||
deviceId: response.deviceId,
|
||||
);
|
||||
|
||||
// Start background sync-to-database persistence now that we are logged in.
|
||||
ref.read(syncPersistenceServiceProvider).start();
|
||||
// Start background sync-to-database persistence.
|
||||
try {
|
||||
ref.read(syncPersistenceServiceProvider).start();
|
||||
} catch (_) {}
|
||||
} on AuthFailure catch (failure) {
|
||||
state = AuthState.unauthenticated(failure: failure.userMessage);
|
||||
}
|
||||
}
|
||||
|
||||
/// Logs out the current user, clears storage, and resets to unauthenticated.
|
||||
Future<void> logout() async {
|
||||
state = const AuthState.loading();
|
||||
|
||||
final repo = ref.read(authRepositoryProvider);
|
||||
await repo.logout();
|
||||
|
||||
final storage = ref.read(secureStorageProvider);
|
||||
await storage.clearCredentials();
|
||||
|
||||
// Keep the device ID in storage so the next login reuses it.
|
||||
state = const AuthState.unauthenticated();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,83 +1,30 @@
|
||||
// Version: 1.0.0 | Created: 2026-04-01
|
||||
// Typed wrapper around flutter_secure_storage.
|
||||
// All token read/write operations go through this class — never call
|
||||
// flutter_secure_storage directly from feature code.
|
||||
// Version: 2.0.0 | Created: 2026-04-01 | Updated: 2026-04-11
|
||||
// Minimal storage: only the Matrix device ID is persisted so that
|
||||
// encryption keys accumulate on one device across logins.
|
||||
// Access tokens are NOT stored — every browser visit requires login.
|
||||
|
||||
import 'package:flutter_secure_storage/flutter_secure_storage.dart';
|
||||
import 'package:riverpod_annotation/riverpod_annotation.dart';
|
||||
|
||||
import '../config/app_config.dart';
|
||||
|
||||
part 'secure_storage.g.dart';
|
||||
|
||||
/// Provides a configured [SecureStorage] instance.
|
||||
@Riverpod(keepAlive: true)
|
||||
SecureStorage secureStorage(Ref ref) => const SecureStorage();
|
||||
|
||||
/// Typed wrapper around [FlutterSecureStorage].
|
||||
///
|
||||
/// Uses AES encryption on Android and Keychain on iOS.
|
||||
/// On Web, data is stored in localStorage with encryption — acceptable for
|
||||
/// access tokens but NOT for E2EE private keys (Phase 2 concern).
|
||||
class SecureStorage {
|
||||
const SecureStorage();
|
||||
|
||||
static const _kDeviceId = 'm8chat_device_id';
|
||||
|
||||
static const FlutterSecureStorage _storage = FlutterSecureStorage(
|
||||
aOptions: AndroidOptions(encryptedSharedPreferences: true),
|
||||
);
|
||||
|
||||
Future<void> saveCredentials({
|
||||
required String accessToken,
|
||||
required String userId,
|
||||
required String deviceId,
|
||||
}) async {
|
||||
await _storage.write(
|
||||
key: AppConfig.storageKeyAccessToken,
|
||||
value: accessToken,
|
||||
);
|
||||
await _storage.write(key: AppConfig.storageKeyUserId, value: userId);
|
||||
await _storage.write(key: AppConfig.storageKeyDeviceId, value: deviceId);
|
||||
await _storage.write(
|
||||
key: AppConfig.storageKeyHomeserver,
|
||||
value: AppConfig.matrixBaseUrl,
|
||||
);
|
||||
Future<void> saveDeviceId(String deviceId) async {
|
||||
await _storage.write(key: _kDeviceId, value: deviceId);
|
||||
}
|
||||
|
||||
Future<StoredCredentials?> loadCredentials() async {
|
||||
final accessToken = await _storage.read(
|
||||
key: AppConfig.storageKeyAccessToken,
|
||||
);
|
||||
final userId = await _storage.read(key: AppConfig.storageKeyUserId);
|
||||
final deviceId = await _storage.read(key: AppConfig.storageKeyDeviceId);
|
||||
|
||||
if (accessToken == null || userId == null || deviceId == null) {
|
||||
return null;
|
||||
}
|
||||
|
||||
return StoredCredentials(
|
||||
accessToken: accessToken,
|
||||
userId: userId,
|
||||
deviceId: deviceId,
|
||||
);
|
||||
}
|
||||
|
||||
Future<void> clearCredentials() async {
|
||||
await _storage.delete(key: AppConfig.storageKeyAccessToken);
|
||||
await _storage.delete(key: AppConfig.storageKeyUserId);
|
||||
await _storage.delete(key: AppConfig.storageKeyDeviceId);
|
||||
await _storage.delete(key: AppConfig.storageKeyHomeserver);
|
||||
Future<String?> loadDeviceId() async {
|
||||
return _storage.read(key: _kDeviceId);
|
||||
}
|
||||
}
|
||||
|
||||
/// Holds the credentials retrieved from secure storage.
|
||||
class StoredCredentials {
|
||||
const StoredCredentials({
|
||||
required this.accessToken,
|
||||
required this.userId,
|
||||
required this.deviceId,
|
||||
});
|
||||
|
||||
final String accessToken;
|
||||
final String userId;
|
||||
final String deviceId;
|
||||
}
|
||||
|
||||
@@ -1,9 +1,6 @@
|
||||
// Version: 1.0.0 | Created: 2026-04-01
|
||||
// Version: 2.0.0 | Created: 2026-04-01 | Updated: 2026-04-11
|
||||
// App-wide constants. Change matrixBaseUrl for different environments.
|
||||
|
||||
/// Central configuration for the M8Chat application.
|
||||
/// All server URLs and app-level constants live here — never scatter
|
||||
/// magic strings through feature code.
|
||||
abstract final class AppConfig {
|
||||
static const String matrixBaseUrl = 'https://matrix.m8chat.au';
|
||||
static const String matrixServerName = 'matrix.m8chat.au';
|
||||
@@ -14,11 +11,8 @@ abstract final class AppConfig {
|
||||
'turns:matrix.m8chat.au:5349',
|
||||
];
|
||||
static const String appName = 'M8Chat';
|
||||
static const String appVersion = '1.0.0';
|
||||
static const String appVersion = '1.3.0';
|
||||
|
||||
// Secure storage key names
|
||||
static const String storageKeyAccessToken = 'access_token';
|
||||
static const String storageKeyUserId = 'user_id';
|
||||
static const String storageKeyDeviceId = 'device_id';
|
||||
static const String storageKeyHomeserver = 'homeserver';
|
||||
// Jitsi conferencing
|
||||
static const String jitsiDomain = 'conf.m8chat.au';
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user