Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4a265e0fd2 | ||
|
|
1fe4528b0b |
@@ -5,6 +5,8 @@ class Config {
|
|||||||
// OIDC pocket-id (client public + PKCE)
|
// OIDC pocket-id (client public + PKCE)
|
||||||
static const String oidcIssuer = 'https://pocket.nfteam.ovh';
|
static const String oidcIssuer = 'https://pocket.nfteam.ovh';
|
||||||
static const String oidcClientId = '83678fb3-9268-42c1-8dcb-0fb141692a6d';
|
static const String oidcClientId = '83678fb3-9268-42c1-8dcb-0fb141692a6d';
|
||||||
|
// Schéma custom capté par flutter_web_auth_2 (CallbackActivity dédiée)
|
||||||
|
static const String oidcScheme = 'nfteam.gamemanager';
|
||||||
static const String oidcRedirect = 'nfteam.gamemanager://oidc';
|
static const String oidcRedirect = 'nfteam.gamemanager://oidc';
|
||||||
static const List<String> oidcScopes = ['openid', 'profile', 'email'];
|
static const List<String> oidcScopes = ['openid', 'profile', 'email'];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,67 +1,113 @@
|
|||||||
import 'package:flutter_appauth/flutter_appauth.dart';
|
import 'dart:convert';
|
||||||
|
import 'dart:math';
|
||||||
|
|
||||||
|
import 'package:crypto/crypto.dart';
|
||||||
import 'package:flutter_secure_storage/flutter_secure_storage.dart';
|
import 'package:flutter_secure_storage/flutter_secure_storage.dart';
|
||||||
|
import 'package:flutter_web_auth_2/flutter_web_auth_2.dart';
|
||||||
|
import 'package:http/http.dart' as http;
|
||||||
|
|
||||||
import '../config.dart';
|
import '../config.dart';
|
||||||
|
|
||||||
/// Authentification OIDC pocket-id (Authorization Code + PKCE, client public).
|
/// Auth OIDC pocket-id : Authorization Code + PKCE via flutter_web_auth_2
|
||||||
/// Le jeton d'identité (JWT) est stocké de façon sécurisée et envoyé à l'API.
|
/// (schéma custom capté de façon fiable), échange de token en direct.
|
||||||
class AuthService {
|
class AuthService {
|
||||||
final _appAuth = const FlutterAppAuth();
|
|
||||||
final _storage = const FlutterSecureStorage();
|
final _storage = const FlutterSecureStorage();
|
||||||
|
|
||||||
static const _kIdToken = 'id_token';
|
static const _kIdToken = 'id_token';
|
||||||
static const _kRefresh = 'refresh_token';
|
static const _kRefresh = 'refresh_token';
|
||||||
static const _kExpiry = 'access_expiry';
|
static const _kExpiry = 'expiry';
|
||||||
|
|
||||||
|
Map<String, dynamic>? _discovery;
|
||||||
|
|
||||||
|
Future<Map<String, dynamic>> _disco() async {
|
||||||
|
_discovery ??= jsonDecode((await http.get(
|
||||||
|
Uri.parse('${Config.oidcIssuer}/.well-known/openid-configuration'),
|
||||||
|
))
|
||||||
|
.body) as Map<String, dynamic>;
|
||||||
|
return _discovery!;
|
||||||
|
}
|
||||||
|
|
||||||
Future<String?> get idToken => _storage.read(key: _kIdToken);
|
Future<String?> get idToken => _storage.read(key: _kIdToken);
|
||||||
|
|
||||||
Future<bool> isLoggedIn() async => (await idToken) != null;
|
Future<bool> isLoggedIn() async => (await idToken) != null;
|
||||||
|
|
||||||
|
String _rand(int n) {
|
||||||
|
final r = Random.secure();
|
||||||
|
return base64UrlEncode(List<int>.generate(n, (_) => r.nextInt(256)))
|
||||||
|
.replaceAll('=', '')
|
||||||
|
.substring(0, n);
|
||||||
|
}
|
||||||
|
|
||||||
Future<bool> login() async {
|
Future<bool> login() async {
|
||||||
final result = await _appAuth.authorizeAndExchangeCode(
|
final disco = await _disco();
|
||||||
AuthorizationTokenRequest(
|
final verifier = _rand(64);
|
||||||
Config.oidcClientId,
|
final challenge = base64UrlEncode(sha256.convert(ascii.encode(verifier)).bytes)
|
||||||
Config.oidcRedirect,
|
.replaceAll('=', '');
|
||||||
issuer: Config.oidcIssuer,
|
final state = _rand(24);
|
||||||
scopes: Config.oidcScopes,
|
final authUrl = Uri.parse(disco['authorization_endpoint'] as String).replace(queryParameters: {
|
||||||
promptValues: ['login'],
|
'response_type': 'code',
|
||||||
),
|
'client_id': Config.oidcClientId,
|
||||||
|
'redirect_uri': Config.oidcRedirect,
|
||||||
|
'scope': Config.oidcScopes.join(' '),
|
||||||
|
'state': state,
|
||||||
|
'code_challenge': challenge,
|
||||||
|
'code_challenge_method': 'S256',
|
||||||
|
'prompt': 'login',
|
||||||
|
});
|
||||||
|
|
||||||
|
final result = await FlutterWebAuth2.authenticate(
|
||||||
|
url: authUrl.toString(),
|
||||||
|
callbackUrlScheme: Config.oidcScheme,
|
||||||
);
|
);
|
||||||
if (result.idToken == null) return false;
|
final params = Uri.parse(result).queryParameters;
|
||||||
await _storage.write(key: _kIdToken, value: result.idToken);
|
if (params['state'] != state || params['code'] == null) return false;
|
||||||
await _storage.write(key: _kRefresh, value: result.refreshToken);
|
|
||||||
await _storage.write(
|
final token = await http.post(
|
||||||
key: _kExpiry,
|
Uri.parse(disco['token_endpoint'] as String),
|
||||||
value: result.accessTokenExpirationDateTime?.toIso8601String(),
|
headers: {'Content-Type': 'application/x-www-form-urlencoded'},
|
||||||
|
body: {
|
||||||
|
'grant_type': 'authorization_code',
|
||||||
|
'code': params['code']!,
|
||||||
|
'redirect_uri': Config.oidcRedirect,
|
||||||
|
'client_id': Config.oidcClientId,
|
||||||
|
'code_verifier': verifier,
|
||||||
|
},
|
||||||
);
|
);
|
||||||
|
if (token.statusCode != 200) return false;
|
||||||
|
await _store(jsonDecode(token.body) as Map<String, dynamic>);
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Rafraîchit le jeton si expiré (via refresh_token), renvoie l'id_token courant.
|
Future<void> _store(Map<String, dynamic> t) async {
|
||||||
Future<String?> validToken() async {
|
await _storage.write(key: _kIdToken, value: t['id_token'] as String?);
|
||||||
final expiry = await _storage.read(key: _kExpiry);
|
if (t['refresh_token'] != null) {
|
||||||
final refresh = await _storage.read(key: _kRefresh);
|
await _storage.write(key: _kRefresh, value: t['refresh_token'] as String);
|
||||||
if (expiry != null && refresh != null) {
|
}
|
||||||
final exp = DateTime.tryParse(expiry);
|
final expiresIn = (t['expires_in'] as num?)?.toInt() ?? 3600;
|
||||||
if (exp != null && exp.isBefore(DateTime.now().add(const Duration(seconds: 30)))) {
|
|
||||||
try {
|
|
||||||
final r = await _appAuth.token(TokenRequest(
|
|
||||||
Config.oidcClientId,
|
|
||||||
Config.oidcRedirect,
|
|
||||||
issuer: Config.oidcIssuer,
|
|
||||||
refreshToken: refresh,
|
|
||||||
scopes: Config.oidcScopes,
|
|
||||||
));
|
|
||||||
if (r.idToken != null) {
|
|
||||||
await _storage.write(key: _kIdToken, value: r.idToken);
|
|
||||||
await _storage.write(key: _kRefresh, value: r.refreshToken ?? refresh);
|
|
||||||
await _storage.write(
|
await _storage.write(
|
||||||
key: _kExpiry,
|
key: _kExpiry,
|
||||||
value: r.accessTokenExpirationDateTime?.toIso8601String(),
|
value: DateTime.now().add(Duration(seconds: expiresIn)).toIso8601String(),
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
} catch (_) {/* on garde l'ancien token, l'API renverra 401 si mort */}
|
|
||||||
}
|
/// Rafraîchit si expiré, renvoie l'id_token courant.
|
||||||
|
Future<String?> validToken() async {
|
||||||
|
final expiry = DateTime.tryParse(await _storage.read(key: _kExpiry) ?? '');
|
||||||
|
final refresh = await _storage.read(key: _kRefresh);
|
||||||
|
if (expiry != null && refresh != null &&
|
||||||
|
expiry.isBefore(DateTime.now().add(const Duration(seconds: 30)))) {
|
||||||
|
try {
|
||||||
|
final disco = await _disco();
|
||||||
|
final r = await http.post(
|
||||||
|
Uri.parse(disco['token_endpoint'] as String),
|
||||||
|
headers: {'Content-Type': 'application/x-www-form-urlencoded'},
|
||||||
|
body: {
|
||||||
|
'grant_type': 'refresh_token',
|
||||||
|
'refresh_token': refresh,
|
||||||
|
'client_id': Config.oidcClientId,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
if (r.statusCode == 200) await _store(jsonDecode(r.body) as Map<String, dynamic>);
|
||||||
|
} catch (_) {/* garde l'ancien */}
|
||||||
}
|
}
|
||||||
return idToken;
|
return idToken;
|
||||||
}
|
}
|
||||||
|
|||||||
+40
-16
@@ -33,6 +33,14 @@ packages:
|
|||||||
url: "https://pub.dev"
|
url: "https://pub.dev"
|
||||||
source: hosted
|
source: hosted
|
||||||
version: "1.18.0"
|
version: "1.18.0"
|
||||||
|
crypto:
|
||||||
|
dependency: "direct main"
|
||||||
|
description:
|
||||||
|
name: crypto
|
||||||
|
sha256: c8ea0233063ba03258fbcf2ca4d6dadfefe14f02fab57702265467a19f27fadf
|
||||||
|
url: "https://pub.dev"
|
||||||
|
source: hosted
|
||||||
|
version: "3.0.7"
|
||||||
cupertino_icons:
|
cupertino_icons:
|
||||||
dependency: "direct main"
|
dependency: "direct main"
|
||||||
description:
|
description:
|
||||||
@@ -41,6 +49,14 @@ packages:
|
|||||||
url: "https://pub.dev"
|
url: "https://pub.dev"
|
||||||
source: hosted
|
source: hosted
|
||||||
version: "1.0.8"
|
version: "1.0.8"
|
||||||
|
desktop_webview_window:
|
||||||
|
dependency: transitive
|
||||||
|
description:
|
||||||
|
name: desktop_webview_window
|
||||||
|
sha256: "57cf20d81689d5cbb1adfd0017e96b669398a669d927906073b0e42fc64111c0"
|
||||||
|
url: "https://pub.dev"
|
||||||
|
source: hosted
|
||||||
|
version: "0.2.3"
|
||||||
ffi:
|
ffi:
|
||||||
dependency: transitive
|
dependency: transitive
|
||||||
description:
|
description:
|
||||||
@@ -62,22 +78,6 @@ packages:
|
|||||||
description: flutter
|
description: flutter
|
||||||
source: sdk
|
source: sdk
|
||||||
version: "0.0.0"
|
version: "0.0.0"
|
||||||
flutter_appauth:
|
|
||||||
dependency: "direct main"
|
|
||||||
description:
|
|
||||||
name: flutter_appauth
|
|
||||||
sha256: "0aa449d8991f70e7847d55b8bff0890fb41dc62c1d8526337e4073e806813bcb"
|
|
||||||
url: "https://pub.dev"
|
|
||||||
source: hosted
|
|
||||||
version: "8.0.3"
|
|
||||||
flutter_appauth_platform_interface:
|
|
||||||
dependency: transitive
|
|
||||||
description:
|
|
||||||
name: flutter_appauth_platform_interface
|
|
||||||
sha256: ccf5e1d8c40dd35b297290b33cc1896648b4b92a2ec3f62a436c62a8eef9a9db
|
|
||||||
url: "https://pub.dev"
|
|
||||||
source: hosted
|
|
||||||
version: "8.0.0"
|
|
||||||
flutter_lints:
|
flutter_lints:
|
||||||
dependency: "direct dev"
|
dependency: "direct dev"
|
||||||
description:
|
description:
|
||||||
@@ -134,6 +134,22 @@ packages:
|
|||||||
url: "https://pub.dev"
|
url: "https://pub.dev"
|
||||||
source: hosted
|
source: hosted
|
||||||
version: "3.1.2"
|
version: "3.1.2"
|
||||||
|
flutter_web_auth_2:
|
||||||
|
dependency: "direct main"
|
||||||
|
description:
|
||||||
|
name: flutter_web_auth_2
|
||||||
|
sha256: "3c14babeaa066c371f3a743f204dd0d348b7d42ffa6fae7a9847a521aff33696"
|
||||||
|
url: "https://pub.dev"
|
||||||
|
source: hosted
|
||||||
|
version: "4.1.0"
|
||||||
|
flutter_web_auth_2_platform_interface:
|
||||||
|
dependency: transitive
|
||||||
|
description:
|
||||||
|
name: flutter_web_auth_2_platform_interface
|
||||||
|
sha256: c63a472c8070998e4e422f6b34a17070e60782ac442107c70000dd1bed645f4d
|
||||||
|
url: "https://pub.dev"
|
||||||
|
source: hosted
|
||||||
|
version: "4.1.0"
|
||||||
flutter_web_plugins:
|
flutter_web_plugins:
|
||||||
dependency: transitive
|
dependency: transitive
|
||||||
description: flutter
|
description: flutter
|
||||||
@@ -456,6 +472,14 @@ packages:
|
|||||||
url: "https://pub.dev"
|
url: "https://pub.dev"
|
||||||
source: hosted
|
source: hosted
|
||||||
version: "5.10.1"
|
version: "5.10.1"
|
||||||
|
window_to_front:
|
||||||
|
dependency: transitive
|
||||||
|
description:
|
||||||
|
name: window_to_front
|
||||||
|
sha256: "14fad8984db4415e2eeb30b04bb77140b180e260d6cb66b26de126a8657a9241"
|
||||||
|
url: "https://pub.dev"
|
||||||
|
source: hosted
|
||||||
|
version: "0.0.4"
|
||||||
xdg_directories:
|
xdg_directories:
|
||||||
dependency: transitive
|
dependency: transitive
|
||||||
description:
|
description:
|
||||||
|
|||||||
+2
-1
@@ -10,7 +10,8 @@ dependencies:
|
|||||||
flutter:
|
flutter:
|
||||||
sdk: flutter
|
sdk: flutter
|
||||||
http: ^1.2.2
|
http: ^1.2.2
|
||||||
flutter_appauth: ^8.0.0
|
flutter_web_auth_2: ^4.1.0
|
||||||
|
crypto: ^3.0.6
|
||||||
flutter_secure_storage: ^9.2.2
|
flutter_secure_storage: ^9.2.2
|
||||||
shared_preferences: ^2.3.2
|
shared_preferences: ^2.3.2
|
||||||
package_info_plus: ^8.1.1
|
package_info_plus: ^8.1.1
|
||||||
|
|||||||
+18
-11
@@ -2,7 +2,7 @@
|
|||||||
"""Patche le scaffold Android généré par `flutter create` :
|
"""Patche le scaffold Android généré par `flutter create` :
|
||||||
- permissions (internet + auto-install APK)
|
- permissions (internet + auto-install APK)
|
||||||
- signature release depuis key.properties
|
- signature release depuis key.properties
|
||||||
- schéma de redirection OIDC (flutter_appauth)
|
- CallbackActivity flutter_web_auth_2 (retour OIDC, schéma nfteam.gamemanager)
|
||||||
Lancé dans la CI après `flutter create`. Idempotent."""
|
Lancé dans la CI après `flutter create`. Idempotent."""
|
||||||
import os
|
import os
|
||||||
import re
|
import re
|
||||||
@@ -11,7 +11,7 @@ KSPW = os.environ["KSPW"]
|
|||||||
ALIAS = os.environ["ALIAS"]
|
ALIAS = os.environ["ALIAS"]
|
||||||
KEYSTORE_PATH = os.environ.get("KEYSTORE_PATH", os.path.abspath("gamemanager.keystore"))
|
KEYSTORE_PATH = os.environ.get("KEYSTORE_PATH", os.path.abspath("gamemanager.keystore"))
|
||||||
|
|
||||||
# 1) key.properties (chemin absolu du keystore, robuste peu importe le cwd gradle)
|
# 1) key.properties (chemin absolu du keystore)
|
||||||
with open("android/key.properties", "w") as f:
|
with open("android/key.properties", "w") as f:
|
||||||
f.write(
|
f.write(
|
||||||
f"storePassword={KSPW}\n"
|
f"storePassword={KSPW}\n"
|
||||||
@@ -20,7 +20,7 @@ with open("android/key.properties", "w") as f:
|
|||||||
f"storeFile={KEYSTORE_PATH}\n"
|
f"storeFile={KEYSTORE_PATH}\n"
|
||||||
)
|
)
|
||||||
|
|
||||||
# 2) AndroidManifest : permissions
|
# 2) AndroidManifest : permissions + CallbackActivity OIDC
|
||||||
man = "android/app/src/main/AndroidManifest.xml"
|
man = "android/app/src/main/AndroidManifest.xml"
|
||||||
s = open(man).read()
|
s = open(man).read()
|
||||||
perms = (
|
perms = (
|
||||||
@@ -29,12 +29,25 @@ perms = (
|
|||||||
)
|
)
|
||||||
if "REQUEST_INSTALL_PACKAGES" not in s:
|
if "REQUEST_INSTALL_PACKAGES" not in s:
|
||||||
s = s.replace("<application", perms + " <application", 1)
|
s = s.replace("<application", perms + " <application", 1)
|
||||||
|
callback = (
|
||||||
|
' <activity android:name="com.linusu.flutter_web_auth_2.CallbackActivity" '
|
||||||
|
'android:exported="true">\n'
|
||||||
|
' <intent-filter android:label="flutter_web_auth_2">\n'
|
||||||
|
' <action android:name="android.intent.action.VIEW"/>\n'
|
||||||
|
' <category android:name="android.intent.category.DEFAULT"/>\n'
|
||||||
|
' <category android:name="android.intent.category.BROWSABLE"/>\n'
|
||||||
|
' <data android:scheme="nfteam.gamemanager"/>\n'
|
||||||
|
' </intent-filter>\n'
|
||||||
|
' </activity>\n'
|
||||||
|
)
|
||||||
|
if "flutter_web_auth_2.CallbackActivity" not in s:
|
||||||
|
s = s.replace("</application>", callback + " </application>", 1)
|
||||||
open(man, "w").write(s)
|
open(man, "w").write(s)
|
||||||
|
|
||||||
# 3) build.gradle : signature + schéma OIDC
|
# 3) build.gradle : signature release
|
||||||
gr = "android/app/build.gradle"
|
gr = "android/app/build.gradle"
|
||||||
s = open(gr).read()
|
s = open(gr).read()
|
||||||
# ⚠️ Rien n'est autorisé AVANT le bloc plugins {} → on insère juste avant `android {`
|
# ⚠️ Rien avant plugins {} → insérer juste avant `android {`
|
||||||
if "keystoreProperties" not in s:
|
if "keystoreProperties" not in s:
|
||||||
s = s.replace(
|
s = s.replace(
|
||||||
"android {",
|
"android {",
|
||||||
@@ -44,12 +57,6 @@ if "keystoreProperties" not in s:
|
|||||||
'android {',
|
'android {',
|
||||||
1,
|
1,
|
||||||
)
|
)
|
||||||
if "appAuthRedirectScheme" not in s:
|
|
||||||
s = s.replace(
|
|
||||||
"defaultConfig {",
|
|
||||||
'defaultConfig {\n manifestPlaceholders += [appAuthRedirectScheme: "nfteam.gamemanager"]',
|
|
||||||
1,
|
|
||||||
)
|
|
||||||
if "signingConfigs {" not in s:
|
if "signingConfigs {" not in s:
|
||||||
s = re.sub(
|
s = re.sub(
|
||||||
r"(\n\s*buildTypes\s*\{)",
|
r"(\n\s*buildTypes\s*\{)",
|
||||||
|
|||||||
Reference in New Issue
Block a user