- Add Gitea Actions workflow; point README to gitea.d-bis.org/Sankofa_Phoenix/SMOA - Expand .gitignore for Spring H2 data, secrets, Kotlin .kotlin/, tooling - Track docs/api/generated ReDoc bundle; refresh api docs README - Android: network/auth/sync, UI shell, tests; backend credentials/integrity APIs - Docs, scripts (generate-api-docs), modules and core updates Made-with: Cursor
5.4 KiB
5.4 KiB
SMOA – Task status (post-sweep)
This file tracks what the repository delivers versus what remains outside the repo (legal gates, Xcode app binary, live vendor APIs).
Master index: TASKS.md
Build: docs/development/BUILD.md — run ./gradlew smoaVerify --no-daemon (or ./scripts/build-all.sh) for backend tests + debug APK.
Completed in repository (optional + remaining)
Backend
- Prod profile, Flyway, PostgreSQL documentation
- Tenant filter (
smoa.tenant.require-unit,X-Unit) - Pagination / OpenAPI
@Parameter - ETag (
ShallowEtagHeaderFilter), Request ID, API versioning doc - Gradle:
pluginManagementfor:backend, no project-local repos underFAIL_ON_PROJECT_REPOS - Tests:
application-test.yml, MockK fixes,:backend:testgreen
Android
- Sync/pull, Gson, BuildConfig backend URL + API key + STUN/signaling URLs
- Android 16 documentation
- Connection quality:
NetworkEstimatesConnectionQualityMonitor(link bandwidth fromNetworkCapabilities) - WebRTC / screen share / file transfer: documented stubs;
WebRTCManager+VideoTransportflags (no AAR bundled) - SmartCardReader: explicit no-hardware stub
- Knox: integration guide only — KNOX-INTEGRATION.md
iOS
- API contract + checklist + Swift samples — docs/ios/README.md, docs/ios/SAMPLES.md
- Shipped Xcode app — create in a separate Xcode project (not stored here)
Web
- Scaffold: info, health, directory pull, touch-friendly UI
- PWA:
manifest.webmanifest,sw.js, service worker registration - Offline helper:
offline-queue.js(IndexedDB queue pattern) - Deploy + CORS: docs/web-scaffold/DEPLOY.md
Infrastructure
- Nginx example, docker-compose, k8s Deployment/Service example
- TURN/signaling: docs/infrastructure/TURN-SIGNALING.md
Domain / compliance
- ATF local storage: Room
ATFFormDraftEntity+ DAO +ATFFormDatabase - NCIC local log: Room
NCICQueryLogEntity+ DAO +NCICQueryDatabase(+ Room deps on:modules:ncic) - Digital signatures: JCA
SignatureinDigitalSignatureService - Electronic seal: SHA-256 content verification in
ElectronicSealService - AS4 / eIDAS: stubs documented; roadmap core/as4/README.md
- NCIC/ATF/eIDAS live integrations: clearly marked as simulation or product gate in service code
Testing & CI
- Gitea Actions:
./gradlew smoaVerify --no-daemon— .gitea/workflows/ci.yml - E2E plan doc — docs/testing/E2E-PLAN.md
- Android 80%+ coverage — ongoing goal
Enterprise / auth / networking (coding follow-ups)
See TASKS.md rows A9–A21, T4–T6. Summary:
- OIDC client: AppAuth or SSO WebView; redirect
intent-filter; code exchange →SecureTokenStore.persistTokens - Token refresh: OkHttp
Authenticatoron 401 usingrefresh_token - Pinning + dynamic URL: resolve pin host from
RemoteEndpointStorewhen backend URL comes only from hosted config - Biometric + Keystore:
Cipher+BiometricPrompt.CryptoObjectto wrap/unwrap refresh token withBiometricSecretsVault - Session lock: optional device-credential path (not only biometrics) where policy allows
- Play Integrity: POST token to your backend; add server verification (Play Integrity API) — sample in backend
- Tests:
SessionLockController, pinning factory,SecureTokenStore,navigateSmoa, settings ViewModel - Auth UX: replace demo password/MFA in
AuthFlowHostwith IdP-driven flow or hybrid step-up - Release: R8/proguard shrink test with Integrity + OkHttp pinning enabled
- CI: optional
generate-api-docs.sh+ publishdocs/api/generated - Multi-pin hosts: if pull/config use different origins than
SMOA_BACKEND_BASE_URL, extendCertificatePinnerFactory
Documentation
- Backend README, IMPLEMENTATION_STATUS “next steps”, BUILD.md, TASKS.md
Outside repository (cannot close without external parties)
| Item | Blocker |
|---|---|
| Live NCIC/III API | CJIS approval, agency contract |
| Live ATF eTrace | Federal approval, credentials |
| eIDAS QTSP / EU Trust Lists | Trust service provider, operational URLs |
| Knox SDK in binary | Samsung license / partner program |
| WebRTC production media | Ship google-webrtc or vendor AAR + signaling |
| Full AS4 interop | Partner CPA, CXF/Santuario stack, operations |
| Compliance matrix gaps | Deployment-specific priorities — see COMPLIANCE_EVALUATION.md |
Summary
| Area | Repo-delivered | External / binary app |
|---|---|---|
| Backend | All listed | — |
| Android | All listed except Knox binary | Knox AAR, WebRTC AAR optional |
| iOS | Docs + samples | Xcode application |
| Web | Scaffold + PWA + deploy doc | Your HTTPS host + CORS env |
| Infra | Examples + docs | Your servers |
| Domain | Room + JCA + stubs | Live agency/vendor APIs |
Use TASKS.md for the flat checklist with file pointers.