Skip to content

v0.4.0

Choose a tag to compare

@Project516 Project516 released this 05 Sep 00:02
· 4 commits to main since this release
2b71e78

Adds the central Spectrum App Platform handshake, so SpectrumStrategy and SpectrumPit share one implementation instead of each carrying a copy.

Added

  • CentralRestAuthClient — the REST handshake (Google ID token, central session, getCustomToken) for any platform that cannot use cloud_functions. That is Linux desktop, and mobile wherever registering a second native FlutterFire app on the central project is not wanted.
  • CentralAuthErrorKind and classifyCentralAuthError — one place that decides whether a failure means "not approved" or "unreachable". That distinction is the difference between a member working fine offline and being signed out, so two apps disagreeing about it is a silent lockout. Takes either spelling of the callable's status, PERMISSION_DENIED from the REST error or permission-denied from a FlutterFire FirebaseFunctionsException.code, so a FlutterFire caller reuses it without this package depending on cloud_functions.
  • runCentralApprovalRecheck and CentralRecheckOutcome — the periodic approval re-check against a persisted central session. Takes a CentralSessionStorage and plain onApproved/onDenied callbacks rather than SharedPreferences, so the cadence and denial threshold stay app policy while the network call and its classification live here.
  • CentralHandshake, CentralProfile, CentralAuthException.
  • TimeoutHttpClient — bounds every request. FirebaseAuthSession sets no deadline of its own, so an unbounded client meant sign-in could hang forever on a black-holed connection. It is the constructor default, so a caller cannot reintroduce that by omission.

Notes

Additive. Dependencies are unchanged, still crypto and http only, which is the point of this package: it works where FlutterFire does not.

Two fixes went in during review that are worth calling out. The default transport deadline now covers the callable's own 90 second allowance, so a cold start no longer dies in the socket and get misreported as unreachable. And the callable base URL is validated as HTTPS, since every call to it carries the central session's bearer token.

97 tests pass.