Files
smoa/TODO.md
T
defiQUG a2dc194a49 Monorepo: Gitea CI, docs, auth/sync, backend APIs, gitignore
- Add Gitea Actions workflow; point README to gitea.d-bis.org/Sankofa_Phoenix/SMOA
- Expand .gitignore for Spring H2 data, secrets, Kotlin .kotlin/, tooling
- Track docs/api/generated ReDoc bundle; refresh api docs README
- Android: network/auth/sync, UI shell, tests; backend credentials/integrity APIs
- Docs, scripts (generate-api-docs), modules and core updates

Made-with: Cursor
2026-03-23 20:19:24 -07:00

5.4 KiB
Raw Blame History

SMOA – Task status (post-sweep)

This file tracks what the repository delivers versus what remains outside the repo (legal gates, Xcode app binary, live vendor APIs).

Master index: TASKS.md Build: docs/development/BUILD.md — run ./gradlew smoaVerify --no-daemon (or ./scripts/build-all.sh) for backend tests + debug APK.


Completed in repository (optional + remaining)

Backend

  • Prod profile, Flyway, PostgreSQL documentation
  • Tenant filter (smoa.tenant.require-unit, X-Unit)
  • Pagination / OpenAPI @Parameter
  • ETag (ShallowEtagHeaderFilter), Request ID, API versioning doc
  • Gradle: pluginManagement for :backend, no project-local repos under FAIL_ON_PROJECT_REPOS
  • Tests: application-test.yml, MockK fixes, :backend:test green

Android

  • Sync/pull, Gson, BuildConfig backend URL + API key + STUN/signaling URLs
  • Android 16 documentation
  • Connection quality: NetworkEstimatesConnectionQualityMonitor (link bandwidth from NetworkCapabilities)
  • WebRTC / screen share / file transfer: documented stubs; WebRTCManager + VideoTransport flags (no AAR bundled)
  • SmartCardReader: explicit no-hardware stub
  • Knox: integration guide only — KNOX-INTEGRATION.md

iOS

Web

  • Scaffold: info, health, directory pull, touch-friendly UI
  • PWA: manifest.webmanifest, sw.js, service worker registration
  • Offline helper: offline-queue.js (IndexedDB queue pattern)
  • Deploy + CORS: docs/web-scaffold/DEPLOY.md

Infrastructure

Domain / compliance

  • ATF local storage: Room ATFFormDraftEntity + DAO + ATFFormDatabase
  • NCIC local log: Room NCICQueryLogEntity + DAO + NCICQueryDatabase (+ Room deps on :modules:ncic)
  • Digital signatures: JCA Signature in DigitalSignatureService
  • Electronic seal: SHA-256 content verification in ElectronicSealService
  • AS4 / eIDAS: stubs documented; roadmap core/as4/README.md
  • NCIC/ATF/eIDAS live integrations: clearly marked as simulation or product gate in service code

Testing & CI

Enterprise / auth / networking (coding follow-ups)

See TASKS.md rows A9–A21, T4–T6. Summary:

  • OIDC client: AppAuth or SSO WebView; redirect intent-filter; code exchange → SecureTokenStore.persistTokens
  • Token refresh: OkHttp Authenticator on 401 using refresh_token
  • Pinning + dynamic URL: resolve pin host from RemoteEndpointStore when backend URL comes only from hosted config
  • Biometric + Keystore: Cipher + BiometricPrompt.CryptoObject to wrap/unwrap refresh token with BiometricSecretsVault
  • Session lock: optional device-credential path (not only biometrics) where policy allows
  • Play Integrity: POST token to your backend; add server verification (Play Integrity API) — sample in backend
  • Tests: SessionLockController, pinning factory, SecureTokenStore, navigateSmoa, settings ViewModel
  • Auth UX: replace demo password/MFA in AuthFlowHost with IdP-driven flow or hybrid step-up
  • Release: R8/proguard shrink test with Integrity + OkHttp pinning enabled
  • CI: optional generate-api-docs.sh + publish docs/api/generated
  • Multi-pin hosts: if pull/config use different origins than SMOA_BACKEND_BASE_URL, extend CertificatePinnerFactory

Documentation

  • Backend README, IMPLEMENTATION_STATUS “next steps”, BUILD.md, TASKS.md

Outside repository (cannot close without external parties)

Item Blocker
Live NCIC/III API CJIS approval, agency contract
Live ATF eTrace Federal approval, credentials
eIDAS QTSP / EU Trust Lists Trust service provider, operational URLs
Knox SDK in binary Samsung license / partner program
WebRTC production media Ship google-webrtc or vendor AAR + signaling
Full AS4 interop Partner CPA, CXF/Santuario stack, operations
Compliance matrix gaps Deployment-specific priorities — see COMPLIANCE_EVALUATION.md

Summary

Area Repo-delivered External / binary app
Backend All listed —
Android All listed except Knox binary Knox AAR, WebRTC AAR optional
iOS Docs + samples Xcode application
Web Scaffold + PWA + deploy doc Your HTTPS host + CORS env
Infra Examples + docs Your servers
Domain Room + JCA + stubs Live agency/vendor APIs

Use TASKS.md for the flat checklist with file pointers.