fix(auth): flutter_web_auth_2 + PKCE manuel (retour OIDC fiable via CallbackActivity)
Build APK / build (push) Successful in 2m28s

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
neckfire
2026-07-13 10:56:19 +02:00
co-authored by Claude Opus 4.8
parent 1fe4528b0b
commit 4a265e0fd2
5 changed files with 146 additions and 85 deletions
+3 -2
View File
@@ -5,7 +5,8 @@ class Config {
// OIDC pocket-id (client public + PKCE) // OIDC pocket-id (client public + PKCE)
static const String oidcIssuer = 'https://pocket.nfteam.ovh'; static const String oidcIssuer = 'https://pocket.nfteam.ovh';
static const String oidcClientId = '83678fb3-9268-42c1-8dcb-0fb141692a6d'; static const String oidcClientId = '83678fb3-9268-42c1-8dcb-0fb141692a6d';
// App Link HTTPS (fiable ; le schéma custom est bloqué par Chrome au retour) // Schéma custom capté par flutter_web_auth_2 (CallbackActivity dédiée)
static const String oidcRedirect = 'https://gamemanager-api.nfteam.ovh/oidc/callback'; static const String oidcScheme = 'nfteam.gamemanager';
static const String oidcRedirect = 'nfteam.gamemanager://oidc';
static const List<String> oidcScopes = ['openid', 'profile', 'email']; static const List<String> oidcScopes = ['openid', 'profile', 'email'];
} }
+87 -41
View File
@@ -1,67 +1,113 @@
import 'package:flutter_appauth/flutter_appauth.dart'; import 'dart:convert';
import 'dart:math';
import 'package:crypto/crypto.dart';
import 'package:flutter_secure_storage/flutter_secure_storage.dart'; import 'package:flutter_secure_storage/flutter_secure_storage.dart';
import 'package:flutter_web_auth_2/flutter_web_auth_2.dart';
import 'package:http/http.dart' as http;
import '../config.dart'; import '../config.dart';
/// Authentification OIDC pocket-id (Authorization Code + PKCE, client public). /// Auth OIDC pocket-id : Authorization Code + PKCE via flutter_web_auth_2
/// Le jeton d'identité (JWT) est stocké de façon sécurisée et envoyé à l'API. /// (schéma custom capté de façon fiable), échange de token en direct.
class AuthService { class AuthService {
final _appAuth = const FlutterAppAuth();
final _storage = const FlutterSecureStorage(); final _storage = const FlutterSecureStorage();
static const _kIdToken = 'id_token'; static const _kIdToken = 'id_token';
static const _kRefresh = 'refresh_token'; static const _kRefresh = 'refresh_token';
static const _kExpiry = 'access_expiry'; static const _kExpiry = 'expiry';
Map<String, dynamic>? _discovery;
Future<Map<String, dynamic>> _disco() async {
_discovery ??= jsonDecode((await http.get(
Uri.parse('${Config.oidcIssuer}/.well-known/openid-configuration'),
))
.body) as Map<String, dynamic>;
return _discovery!;
}
Future<String?> get idToken => _storage.read(key: _kIdToken); Future<String?> get idToken => _storage.read(key: _kIdToken);
Future<bool> isLoggedIn() async => (await idToken) != null; Future<bool> isLoggedIn() async => (await idToken) != null;
String _rand(int n) {
final r = Random.secure();
return base64UrlEncode(List<int>.generate(n, (_) => r.nextInt(256)))
.replaceAll('=', '')
.substring(0, n);
}
Future<bool> login() async { Future<bool> login() async {
final result = await _appAuth.authorizeAndExchangeCode( final disco = await _disco();
AuthorizationTokenRequest( final verifier = _rand(64);
Config.oidcClientId, final challenge = base64UrlEncode(sha256.convert(ascii.encode(verifier)).bytes)
Config.oidcRedirect, .replaceAll('=', '');
issuer: Config.oidcIssuer, final state = _rand(24);
scopes: Config.oidcScopes, final authUrl = Uri.parse(disco['authorization_endpoint'] as String).replace(queryParameters: {
promptValues: ['login'], 'response_type': 'code',
), 'client_id': Config.oidcClientId,
'redirect_uri': Config.oidcRedirect,
'scope': Config.oidcScopes.join(' '),
'state': state,
'code_challenge': challenge,
'code_challenge_method': 'S256',
'prompt': 'login',
});
final result = await FlutterWebAuth2.authenticate(
url: authUrl.toString(),
callbackUrlScheme: Config.oidcScheme,
); );
if (result.idToken == null) return false; final params = Uri.parse(result).queryParameters;
await _storage.write(key: _kIdToken, value: result.idToken); if (params['state'] != state || params['code'] == null) return false;
await _storage.write(key: _kRefresh, value: result.refreshToken);
await _storage.write( final token = await http.post(
key: _kExpiry, Uri.parse(disco['token_endpoint'] as String),
value: result.accessTokenExpirationDateTime?.toIso8601String(), headers: {'Content-Type': 'application/x-www-form-urlencoded'},
body: {
'grant_type': 'authorization_code',
'code': params['code']!,
'redirect_uri': Config.oidcRedirect,
'client_id': Config.oidcClientId,
'code_verifier': verifier,
},
); );
if (token.statusCode != 200) return false;
await _store(jsonDecode(token.body) as Map<String, dynamic>);
return true; return true;
} }
/// Rafraîchit le jeton si expiré (via refresh_token), renvoie l'id_token courant. Future<void> _store(Map<String, dynamic> t) async {
Future<String?> validToken() async { await _storage.write(key: _kIdToken, value: t['id_token'] as String?);
final expiry = await _storage.read(key: _kExpiry); if (t['refresh_token'] != null) {
final refresh = await _storage.read(key: _kRefresh); await _storage.write(key: _kRefresh, value: t['refresh_token'] as String);
if (expiry != null && refresh != null) { }
final exp = DateTime.tryParse(expiry); final expiresIn = (t['expires_in'] as num?)?.toInt() ?? 3600;
if (exp != null && exp.isBefore(DateTime.now().add(const Duration(seconds: 30)))) {
try {
final r = await _appAuth.token(TokenRequest(
Config.oidcClientId,
Config.oidcRedirect,
issuer: Config.oidcIssuer,
refreshToken: refresh,
scopes: Config.oidcScopes,
));
if (r.idToken != null) {
await _storage.write(key: _kIdToken, value: r.idToken);
await _storage.write(key: _kRefresh, value: r.refreshToken ?? refresh);
await _storage.write( await _storage.write(
key: _kExpiry, key: _kExpiry,
value: r.accessTokenExpirationDateTime?.toIso8601String(), value: DateTime.now().add(Duration(seconds: expiresIn)).toIso8601String(),
); );
} }
} catch (_) {/* on garde l'ancien token, l'API renverra 401 si mort */}
} /// Rafraîchit si expiré, renvoie l'id_token courant.
Future<String?> validToken() async {
final expiry = DateTime.tryParse(await _storage.read(key: _kExpiry) ?? '');
final refresh = await _storage.read(key: _kRefresh);
if (expiry != null && refresh != null &&
expiry.isBefore(DateTime.now().add(const Duration(seconds: 30)))) {
try {
final disco = await _disco();
final r = await http.post(
Uri.parse(disco['token_endpoint'] as String),
headers: {'Content-Type': 'application/x-www-form-urlencoded'},
body: {
'grant_type': 'refresh_token',
'refresh_token': refresh,
'client_id': Config.oidcClientId,
},
);
if (r.statusCode == 200) await _store(jsonDecode(r.body) as Map<String, dynamic>);
} catch (_) {/* garde l'ancien */}
} }
return idToken; return idToken;
} }
+40 -16
View File
@@ -33,6 +33,14 @@ packages:
url: "https://pub.dev" url: "https://pub.dev"
source: hosted source: hosted
version: "1.18.0" version: "1.18.0"
crypto:
dependency: "direct main"
description:
name: crypto
sha256: c8ea0233063ba03258fbcf2ca4d6dadfefe14f02fab57702265467a19f27fadf
url: "https://pub.dev"
source: hosted
version: "3.0.7"
cupertino_icons: cupertino_icons:
dependency: "direct main" dependency: "direct main"
description: description:
@@ -41,6 +49,14 @@ packages:
url: "https://pub.dev" url: "https://pub.dev"
source: hosted source: hosted
version: "1.0.8" version: "1.0.8"
desktop_webview_window:
dependency: transitive
description:
name: desktop_webview_window
sha256: "57cf20d81689d5cbb1adfd0017e96b669398a669d927906073b0e42fc64111c0"
url: "https://pub.dev"
source: hosted
version: "0.2.3"
ffi: ffi:
dependency: transitive dependency: transitive
description: description:
@@ -62,22 +78,6 @@ packages:
description: flutter description: flutter
source: sdk source: sdk
version: "0.0.0" version: "0.0.0"
flutter_appauth:
dependency: "direct main"
description:
name: flutter_appauth
sha256: "0aa449d8991f70e7847d55b8bff0890fb41dc62c1d8526337e4073e806813bcb"
url: "https://pub.dev"
source: hosted
version: "8.0.3"
flutter_appauth_platform_interface:
dependency: transitive
description:
name: flutter_appauth_platform_interface
sha256: ccf5e1d8c40dd35b297290b33cc1896648b4b92a2ec3f62a436c62a8eef9a9db
url: "https://pub.dev"
source: hosted
version: "8.0.0"
flutter_lints: flutter_lints:
dependency: "direct dev" dependency: "direct dev"
description: description:
@@ -134,6 +134,22 @@ packages:
url: "https://pub.dev" url: "https://pub.dev"
source: hosted source: hosted
version: "3.1.2" version: "3.1.2"
flutter_web_auth_2:
dependency: "direct main"
description:
name: flutter_web_auth_2
sha256: "3c14babeaa066c371f3a743f204dd0d348b7d42ffa6fae7a9847a521aff33696"
url: "https://pub.dev"
source: hosted
version: "4.1.0"
flutter_web_auth_2_platform_interface:
dependency: transitive
description:
name: flutter_web_auth_2_platform_interface
sha256: c63a472c8070998e4e422f6b34a17070e60782ac442107c70000dd1bed645f4d
url: "https://pub.dev"
source: hosted
version: "4.1.0"
flutter_web_plugins: flutter_web_plugins:
dependency: transitive dependency: transitive
description: flutter description: flutter
@@ -456,6 +472,14 @@ packages:
url: "https://pub.dev" url: "https://pub.dev"
source: hosted source: hosted
version: "5.10.1" version: "5.10.1"
window_to_front:
dependency: transitive
description:
name: window_to_front
sha256: "14fad8984db4415e2eeb30b04bb77140b180e260d6cb66b26de126a8657a9241"
url: "https://pub.dev"
source: hosted
version: "0.0.4"
xdg_directories: xdg_directories:
dependency: transitive dependency: transitive
description: description:
+2 -1
View File
@@ -10,7 +10,8 @@ dependencies:
flutter: flutter:
sdk: flutter sdk: flutter
http: ^1.2.2 http: ^1.2.2
flutter_appauth: ^8.0.0 flutter_web_auth_2: ^4.1.0
crypto: ^3.0.6
flutter_secure_storage: ^9.2.2 flutter_secure_storage: ^9.2.2
shared_preferences: ^2.3.2 shared_preferences: ^2.3.2
package_info_plus: ^8.1.1 package_info_plus: ^8.1.1
+12 -23
View File
@@ -2,7 +2,7 @@
"""Patche le scaffold Android généré par `flutter create` : """Patche le scaffold Android généré par `flutter create` :
- permissions (internet + auto-install APK) - permissions (internet + auto-install APK)
- signature release depuis key.properties - signature release depuis key.properties
- schéma de redirection OIDC (flutter_appauth) - CallbackActivity flutter_web_auth_2 (retour OIDC, schéma nfteam.gamemanager)
Lancé dans la CI après `flutter create`. Idempotent.""" Lancé dans la CI après `flutter create`. Idempotent."""
import os import os
import re import re
@@ -11,7 +11,7 @@ KSPW = os.environ["KSPW"]
ALIAS = os.environ["ALIAS"] ALIAS = os.environ["ALIAS"]
KEYSTORE_PATH = os.environ.get("KEYSTORE_PATH", os.path.abspath("gamemanager.keystore")) KEYSTORE_PATH = os.environ.get("KEYSTORE_PATH", os.path.abspath("gamemanager.keystore"))
# 1) key.properties (chemin absolu du keystore, robuste peu importe le cwd gradle) # 1) key.properties (chemin absolu du keystore)
with open("android/key.properties", "w") as f: with open("android/key.properties", "w") as f:
f.write( f.write(
f"storePassword={KSPW}\n" f"storePassword={KSPW}\n"
@@ -20,39 +20,34 @@ with open("android/key.properties", "w") as f:
f"storeFile={KEYSTORE_PATH}\n" f"storeFile={KEYSTORE_PATH}\n"
) )
# 2) AndroidManifest : permissions + App Link HTTPS (retour OIDC fiable) # 2) AndroidManifest : permissions + CallbackActivity OIDC
man = "android/app/src/main/AndroidManifest.xml" man = "android/app/src/main/AndroidManifest.xml"
s = open(man).read() s = open(man).read()
# namespace tools (pour merger dans l'activity de flutter_appauth)
if "xmlns:tools" not in s:
s = s.replace("<manifest ", '<manifest xmlns:tools="http://schemas.android.com/tools" ', 1)
perms = ( perms = (
'<uses-permission android:name="android.permission.INTERNET"/>\n' '<uses-permission android:name="android.permission.INTERNET"/>\n'
' <uses-permission android:name="android.permission.REQUEST_INSTALL_PACKAGES"/>\n' ' <uses-permission android:name="android.permission.REQUEST_INSTALL_PACKAGES"/>\n'
) )
if "REQUEST_INSTALL_PACKAGES" not in s: if "REQUEST_INSTALL_PACKAGES" not in s:
s = s.replace("<application", perms + " <application", 1) s = s.replace("<application", perms + " <application", 1)
# App Link https://gamemanager-api.nfteam.ovh/oidc/callback → capté par l'app callback = (
applink = ( ' <activity android:name="com.linusu.flutter_web_auth_2.CallbackActivity" '
' <activity android:name="net.openid.appauth.RedirectUriReceiverActivity" ' 'android:exported="true">\n'
'android:exported="true" tools:node="merge">\n' ' <intent-filter android:label="flutter_web_auth_2">\n'
' <intent-filter android:autoVerify="true">\n'
' <action android:name="android.intent.action.VIEW"/>\n' ' <action android:name="android.intent.action.VIEW"/>\n'
' <category android:name="android.intent.category.DEFAULT"/>\n' ' <category android:name="android.intent.category.DEFAULT"/>\n'
' <category android:name="android.intent.category.BROWSABLE"/>\n' ' <category android:name="android.intent.category.BROWSABLE"/>\n'
' <data android:scheme="https" android:host="gamemanager-api.nfteam.ovh" ' ' <data android:scheme="nfteam.gamemanager"/>\n'
'android:path="/oidc/callback"/>\n'
' </intent-filter>\n' ' </intent-filter>\n'
' </activity>\n' ' </activity>\n'
) )
if "gamemanager-api.nfteam.ovh" not in s: if "flutter_web_auth_2.CallbackActivity" not in s:
s = s.replace("</application>", applink + " </application>", 1) s = s.replace("</application>", callback + " </application>", 1)
open(man, "w").write(s) open(man, "w").write(s)
# 3) build.gradle : signature + schéma OIDC # 3) build.gradle : signature release
gr = "android/app/build.gradle" gr = "android/app/build.gradle"
s = open(gr).read() s = open(gr).read()
# ⚠️ Rien n'est autorisé AVANT le bloc plugins {} → on insère juste avant `android {` # ⚠️ Rien avant plugins {} → insérer juste avant `android {`
if "keystoreProperties" not in s: if "keystoreProperties" not in s:
s = s.replace( s = s.replace(
"android {", "android {",
@@ -62,12 +57,6 @@ if "keystoreProperties" not in s:
'android {', 'android {',
1, 1,
) )
if "appAuthRedirectScheme" not in s:
s = s.replace(
"defaultConfig {",
'defaultConfig {\n manifestPlaceholders += [appAuthRedirectScheme: "nfteam.gamemanager"]',
1,
)
if "signingConfigs {" not in s: if "signingConfigs {" not in s:
s = re.sub( s = re.sub(
r"(\n\s*buildTypes\s*\{)", r"(\n\s*buildTypes\s*\{)",