fints 0.1.2
fints: ^0.1.2 copied to clipboard
FinTS 3.0 and 4.1 client for German banks. Retrieves accounts, balances and transactions with PIN/TAN, two-step TAN, decoupled approval and PSD2 strong customer authentication.
0.1.2 #
- Link the homepage coderoftime.dev and the repository's new location in the pub.dev listing
- Require Dart 3.11, the lowest SDK that package:xml 7 supports (0.1.0 and 0.1.1 claimed 3.8 but could not be resolved below 3.11)
0.1.1 #
- Make repository and issue tracker appear in pub.dev listing
- No code changes included
0.1.0 #
First release.
- FinTS 3.0 and 4.1 PIN/TAN clients (
FinTs3Client,FinTs4Client): accounts, balances and transactions (camt.052 and MT940/MT942), with paging and SEPA account details. - One-step and two-step TAN, PSD2 strong customer authentication and decoupled approval (pushTAN, SecureGo plus);
TAN method and medium selection, chipTAN flicker codes and photoTAN images. The TAN callback answers with a
TanAnswer. - Bank parameter data, customer system ID and the chosen TAN method are kept in an exportable state string, which holds neither PIN nor TAN.
- A client never sends its PIN again once the bank has refused a login, so that a retrying app cannot lock the access; see the README for the return codes after which it logs in once more. An error in the TAN or app approval of a login, such as an expired TAN, is not a refused login, and a login that would lack a required TAN medium is not sent at all.
- The bank's warnings reach the app through
onWarning, apart from those the client acts on itself. New login data (3072) end the dialog and fail the call and all later ones withFinTsLoginDataChangedException, which names them. - An error thrown by
onBankMessage,onWarningorloggerfails the call once its exchange with the bank is over. - https only, no redirects, bounded request time, response size and query size; PIN and TANs are masked in the log,
along with the sizes that would tell their length, and
toStringof the models leaves out account data. - Follows the parameter data: sends only what the user parameter data and HIPINS permit, takes BIC and complete
balance from the account extension of the user parameter data and passes its data status on
(
Account.dataStatus, withmt940TransactionsIdandcamtTransactionsId), checks the PIN length before the first message signed with it, and logs in anew after a dialog was idle for longer than the bank's maximum timeout. - Parsers for MT940 (German structured
:86:fields and SEPA keywords) and camt.052/053; malformed bank data raiseFinTsProtocolExceptioninstead of being guessed, as does a request for a TAN or an app approval without a challenge, after which the bank has not executed the order.