Monorepo: Gitea CI, docs, auth/sync, backend APIs, gitignore
- Add Gitea Actions workflow; point README to gitea.d-bis.org/Sankofa_Phoenix/SMOA - Expand .gitignore for Spring H2 data, secrets, Kotlin .kotlin/, tooling - Track docs/api/generated ReDoc bundle; refresh api docs README - Android: network/auth/sync, UI shell, tests; backend credentials/integrity APIs - Docs, scripts (generate-api-docs), modules and core updates Made-with: Cursor
This commit is contained in:
+8
-6
@@ -12,12 +12,13 @@ This folder is a **scaffold** for the SMOA iOS app. The actual app is to be impl
|
||||
|
||||
## Implementation checklist
|
||||
|
||||
- [ ] Create Xcode project (Swift/SwiftUI or cross-platform); minimum deployment target iOS 15.0.
|
||||
- [ ] Store API key in **Keychain**.
|
||||
- [ ] Implement **PullAPI** (URLSession or Alamofire): GET endpoints above.
|
||||
- [ ] Implement **SyncAPI**: POST sync + DELETE; parse `SyncResponse`, decode `remoteData` when conflict.
|
||||
- [ ] **Offline queue:** Queue sync when offline; retry when online; optional Core Data / SwiftData for persistence.
|
||||
- [ ] Optional: Face ID / Touch ID for app unlock; certificate pinning for API.
|
||||
- [x] **Scaffold + samples** – API contract documented here; Swift snippets in [SAMPLES.md](SAMPLES.md) (Keychain, offline queue outline, biometrics, pinning).
|
||||
- [ ] Create Xcode project (Swift/SwiftUI); minimum deployment target iOS 15.0 (deliver in Xcode repo).
|
||||
- [x] **Keychain pattern** – See SAMPLES.md `saveApiKey` / `loadApiKey`.
|
||||
- [ ] Implement **PullAPI** in app (URLSession): GET endpoints above.
|
||||
- [ ] Implement **SyncAPI** in app: POST sync + DELETE; parse `SyncResponse`.
|
||||
- [x] **Offline queue** – Pattern described in SAMPLES.md; app-specific Core Data/SwiftData TBD in Xcode project.
|
||||
- [x] **Optional auth/pinning** – Documented in SAMPLES.md; wire in app when needed.
|
||||
|
||||
## Discovery
|
||||
|
||||
@@ -25,5 +26,6 @@ This folder is a **scaffold** for the SMOA iOS app. The actual app is to be impl
|
||||
|
||||
## References
|
||||
|
||||
- [SAMPLES.md](SAMPLES.md) – Keychain, offline queue, Face ID/Touch ID, certificate pinning
|
||||
- Backend: [backend/README.md](../../backend/README.md)
|
||||
- Platform requirements: [docs/reference/PLATFORM-REQUIREMENTS.md](../reference/PLATFORM-REQUIREMENTS.md)
|
||||
|
||||
@@ -0,0 +1,47 @@
|
||||
# iOS samples (Keychain, API key, offline queue)
|
||||
|
||||
Use with [docs/ios/README.md](../ios/README.md). These snippets are **reference only** (not a full Xcode project).
|
||||
|
||||
## Store API key in Keychain
|
||||
|
||||
```swift
|
||||
import Security
|
||||
|
||||
func saveApiKey(_ value: String, service: String = "com.smoa.api") throws {
|
||||
let data = Data(value.utf8)
|
||||
let query: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: service,
|
||||
kSecAttrAccount as String: "apiKey",
|
||||
kSecValueData as String: data
|
||||
]
|
||||
SecItemDelete(query as CFDictionary)
|
||||
let status = SecItemAdd(query as CFDictionary, nil)
|
||||
guard status == errSecSuccess else { throw NSError(domain: NSOSStatusErrorDomain, code: Int(status)) }
|
||||
}
|
||||
|
||||
func loadApiKey(service: String = "com.smoa.api") -> String? {
|
||||
let query: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: service,
|
||||
kSecAttrAccount as String: "apiKey",
|
||||
kSecReturnData as String: true
|
||||
]
|
||||
var out: AnyObject?
|
||||
guard SecItemCopyMatching(query as CFDictionary, &out) == errSecSuccess,
|
||||
let data = out as? Data else { return nil }
|
||||
return String(data: data, encoding: .utf8)
|
||||
}
|
||||
```
|
||||
|
||||
## Simple offline sync queue (UserDefaults + retry)
|
||||
|
||||
Persist operation JSON strings; on `NWPathMonitor` satisfied, POST to `/api/v1/...` with `URLSession` and remove on success.
|
||||
|
||||
## Face ID / Touch ID
|
||||
|
||||
Wrap Keychain access with `LAContext().evaluatePolicy(.deviceOwnerAuthenticationWithBiometrics, …)` before reading sensitive items.
|
||||
|
||||
## Certificate pinning
|
||||
|
||||
Use `URLSessionDelegate` `urlSession(_:didReceive:completionHandler:)` and compare `SecTrust` server pins to your SPKI hashes.
|
||||
Reference in New Issue
Block a user