features/wallet/wallet_composition
library
Functions
-
resolveWalletDbDir()
→ Future<String>
-
The wallet onboarding COMPOSITION ROOT (spec §3.2g iii-B-2-b): the one place
that wires the production adapters into the onboarding seams. Building the
provisioner, the store, and the screen-security adapter TOGETHER (with the
co-wiring assertion below) is what makes them impossible to wire apart — a
refactor cannot ship the seed-revealing provisioner without the screenshot
protection on a platform that supports it (crypto audit H2).
Resolve the wallet data directory to a PLAIN, already-created path — call
this in
main(), fold it into the host's WalletConfig (the reference
buildWalletConfig does this), and pass that config to
walletOnboardingOverrides BEFORE building the ProviderScope. This is a
REFERENCE helper (it picks a per-network leaf under the app support dir and
wires iOS backup-exclusion); a host with its own data-dir convention
resolves its own path and puts it on its WalletConfig.dbDir. It must NOT
be recomputed inside a provider
build(): an async re-resolve on every rebuild would spawn a fresh
provisioner mid-flight and risk a double-create (the footgun the port and
controller both warn about).
-
screenSecurityCoWiringHolds({required bool provisionerIsReal, required ScreenSecurity security, required bool supportsBlock})
→ bool
-
The co-wiring invariant (crypto audit H2), as a pure predicate so it is
directly testable (true AND false cases) without tripping an assert: a REAL
provisioner — which can reveal the seed onto the backup screen — must ship
with a REAL screen-security adapter on any platform that can block the
screen. Where no block exists (iOS/desktop/web), the honest NoopScreenSecurity
is correct and the rule holds.
-
walletOnboardingOverrides({required WalletConfig config, bool? supportsScreenshotBlock, WalletProvisioner decorateProvisioner(WalletProvisioner provisioner)?})
→ List<Override>
-
The production onboarding seam overrides, co-wired.