# SMOA iOS app (scaffold) This folder is a **scaffold** for the SMOA iOS app. The actual app is to be implemented in a separate Xcode project or repo, targeting **iOS 15, 16, and 17** (last three generations). ## Contract - Use the same **REST API** as Android and Web: see [PLATFORM-REQUIREMENTS.md](../reference/PLATFORM-REQUIREMENTS.md) and [REQUIREMENTS-ALIGNMENT.md](../reference/REQUIREMENTS-ALIGNMENT.md). - **Sync:** POST to `/api/v1/sync/directory`, `/api/v1/sync/order`, etc.; DELETE for sync delete. - **Pull:** GET `/api/v1/directory`, `/api/v1/orders`, `/api/v1/evidence`, `/api/v1/credentials`, `/api/v1/reports` (with `since`, `limit`, optional filters). - **Auth:** Header `X-API-Key` or query `api_key`. - **Response:** JSON; when `conflict: true`, `remoteData` is base64-encoded JSON. ## Implementation checklist - [x] **Scaffold + samples** – API contract documented here; Swift snippets in [SAMPLES.md](SAMPLES.md) (Keychain, offline queue outline, biometrics, pinning). - [ ] Create Xcode project (Swift/SwiftUI); minimum deployment target iOS 15.0 (deliver in Xcode repo). - [x] **Keychain pattern** – See SAMPLES.md `saveApiKey` / `loadApiKey`. - [ ] Implement **PullAPI** in app (URLSession): GET endpoints above. - [ ] Implement **SyncAPI** in app: POST sync + DELETE; parse `SyncResponse`. - [x] **Offline queue** – Pattern described in SAMPLES.md; app-specific Core Data/SwiftData TBD in Xcode project. - [x] **Optional auth/pinning** – Documented in SAMPLES.md; wire in app when needed. ## Discovery - GET `/api/v1/info` returns `endpoints` (sync, delete, pull) and `auth` for client discovery. ## References - [SAMPLES.md](SAMPLES.md) – Keychain, offline queue, Face ID/Touch ID, certificate pinning - Backend: [backend/README.md](../../backend/README.md) - Platform requirements: [docs/reference/PLATFORM-REQUIREMENTS.md](../reference/PLATFORM-REQUIREMENTS.md)