Files
smoa/TODO.md
T
defiQUG a2dc194a49 Monorepo: Gitea CI, docs, auth/sync, backend APIs, gitignore
- Add Gitea Actions workflow; point README to gitea.d-bis.org/Sankofa_Phoenix/SMOA
- Expand .gitignore for Spring H2 data, secrets, Kotlin .kotlin/, tooling
- Track docs/api/generated ReDoc bundle; refresh api docs README
- Android: network/auth/sync, UI shell, tests; backend credentials/integrity APIs
- Docs, scripts (generate-api-docs), modules and core updates

Made-with: Cursor
2026-03-23 20:19:24 -07:00

102 lines
5.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# SMOA – Task status (post-sweep)
This file tracks **what the repository delivers** versus **what remains outside the repo** (legal gates, Xcode app binary, live vendor APIs).
**Master index:** [TASKS.md](./TASKS.md)
**Build:** [docs/development/BUILD.md](docs/development/BUILD.md) — run **`./gradlew smoaVerify --no-daemon`** (or `./scripts/build-all.sh`) for backend tests + debug APK.
---
## Completed in repository (optional + remaining)
### Backend
- [x] Prod profile, Flyway, PostgreSQL documentation
- [x] Tenant filter (`smoa.tenant.require-unit`, `X-Unit`)
- [x] Pagination / OpenAPI `@Parameter`
- [x] ETag (`ShallowEtagHeaderFilter`), Request ID, API versioning doc
- [x] Gradle: `pluginManagement` for `:backend`, no project-local repos under `FAIL_ON_PROJECT_REPOS`
- [x] Tests: `application-test.yml`, MockK fixes, `:backend:test` green
### Android
- [x] Sync/pull, Gson, BuildConfig backend URL + API key + STUN/signaling URLs
- [x] Android 16 documentation
- [x] **Connection quality:** `NetworkEstimatesConnectionQualityMonitor` (link bandwidth from `NetworkCapabilities`)
- [x] **WebRTC / screen share / file transfer:** documented stubs; `WebRTCManager` + `VideoTransport` flags (no AAR bundled)
- [x] **SmartCardReader:** explicit no-hardware stub
- [x] **Knox:** integration guide only — [KNOX-INTEGRATION.md](docs/reference/KNOX-INTEGRATION.md)
### iOS
- [x] API contract + checklist + **Swift samples** — [docs/ios/README.md](docs/ios/README.md), [docs/ios/SAMPLES.md](docs/ios/SAMPLES.md)
- [ ] **Shipped Xcode app** — create in a separate Xcode project (not stored here)
### Web
- [x] Scaffold: info, health, directory pull, touch-friendly UI
- [x] **PWA:** `manifest.webmanifest`, `sw.js`, service worker registration
- [x] **Offline helper:** `offline-queue.js` (IndexedDB queue pattern)
- [x] **Deploy + CORS:** [docs/web-scaffold/DEPLOY.md](docs/web-scaffold/DEPLOY.md)
### Infrastructure
- [x] Nginx example, docker-compose, k8s Deployment/Service example
- [x] **TURN/signaling:** [docs/infrastructure/TURN-SIGNALING.md](docs/infrastructure/TURN-SIGNALING.md)
### Domain / compliance
- [x] **ATF local storage:** Room `ATFFormDraftEntity` + DAO + `ATFFormDatabase`
- [x] **NCIC local log:** Room `NCICQueryLogEntity` + DAO + `NCICQueryDatabase` (+ Room deps on `:modules:ncic`)
- [x] **Digital signatures:** JCA `Signature` in `DigitalSignatureService`
- [x] **Electronic seal:** SHA-256 content verification in `ElectronicSealService`
- [x] **AS4 / eIDAS:** stubs documented; roadmap [core/as4/README.md](core/as4/README.md)
- [x] NCIC/ATF/eIDAS **live** integrations: clearly marked as **simulation or product gate** in service code
### Testing & CI
- [x] Gitea Actions: `./gradlew smoaVerify --no-daemon` — [.gitea/workflows/ci.yml](.gitea/workflows/ci.yml)
- [x] E2E plan doc — [docs/testing/E2E-PLAN.md](docs/testing/E2E-PLAN.md)
- [ ] Android 80%+ coverage — ongoing goal
### Enterprise / auth / networking (coding follow-ups)
See [TASKS.md](./TASKS.md) rows **A9–A21**, **T4–T6**. Summary:
- [ ] **OIDC client:** AppAuth or SSO WebView; redirect `intent-filter`; code exchange → `SecureTokenStore.persistTokens`
- [ ] **Token refresh:** OkHttp `Authenticator` on 401 using `refresh_token`
- [ ] **Pinning + dynamic URL:** resolve pin host from `RemoteEndpointStore` when backend URL comes only from hosted config
- [ ] **Biometric + Keystore:** `Cipher` + `BiometricPrompt.CryptoObject` to wrap/unwrap refresh token with `BiometricSecretsVault`
- [ ] **Session lock:** optional device-credential path (not only biometrics) where policy allows
- [ ] **Play Integrity:** POST token to your backend; add **server** verification (Play Integrity API) — sample in backend
- [ ] **Tests:** `SessionLockController`, pinning factory, `SecureTokenStore`, `navigateSmoa`, settings ViewModel
- [ ] **Auth UX:** replace demo password/MFA in `AuthFlowHost` with IdP-driven flow or hybrid step-up
- [ ] **Release:** R8/proguard shrink test with Integrity + OkHttp pinning enabled
- [ ] **CI:** optional `generate-api-docs.sh` + publish `docs/api/generated`
- [ ] **Multi-pin hosts:** if pull/config use different origins than `SMOA_BACKEND_BASE_URL`, extend `CertificatePinnerFactory`
### Documentation
- [x] Backend README, IMPLEMENTATION_STATUS “next steps”, BUILD.md, TASKS.md
---
## Outside repository (cannot close without external parties)
| Item | Blocker |
|------|---------|
| Live **NCIC/III** API | CJIS approval, agency contract |
| Live **ATF eTrace** | Federal approval, credentials |
| **eIDAS QTSP** / EU Trust Lists | Trust service provider, operational URLs |
| **Knox SDK** in binary | Samsung license / partner program |
| **WebRTC** production media | Ship `google-webrtc` or vendor AAR + signaling |
| **Full AS4** interop | Partner CPA, CXF/Santuario stack, operations |
| **Compliance matrix gaps** | Deployment-specific priorities — see [COMPLIANCE_EVALUATION.md](docs/reference/COMPLIANCE_EVALUATION.md) |
---
## Summary
| Area | Repo-delivered | External / binary app |
|------|----------------|------------------------|
| Backend | All listed | — |
| Android | All listed except Knox binary | Knox AAR, WebRTC AAR optional |
| iOS | Docs + samples | Xcode application |
| Web | Scaffold + PWA + deploy doc | Your HTTPS host + CORS env |
| Infra | Examples + docs | Your servers |
| Domain | Room + JCA + stubs | Live agency/vendor APIs |
Use [TASKS.md](./TASKS.md) for the flat checklist with file pointers.