rspl_secure_vault 0.0.4 copy "rspl_secure_vault: ^0.0.4" to clipboard
rspl_secure_vault: ^0.0.4 copied to clipboard

Secure Flutter plugin for storing sensitive data with hardware-backed encryption (iOS Secure Enclave, Android Keystore).

Changelog #

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

0.0.4 #

Changed #

  • Raised environment.sdk floor to >=3.10.0 <4.0.0 to match the actual requirements of updated dependencies, and added an explicit environment.flutter floor of >=3.37.0.
  • Bumped flutter_secure_storage to ^10.3.1 (federated iOS/macOS implementation now lives in flutter_secure_storage_darwin, which ships a Package.swift alongside its podspec).
  • Bumped flutter_lints to ^6.0.0 and pigeon to ^27.2.0.
  • Added the FlutterFramework dependency declaration to the plugin's iOS Package.swift, per Flutter's Swift Package Manager plugin-authoring guidance.
  • Removed the deprecated encryptedSharedPreferences option from the internal AndroidOptions configuration (ignored as of flutter_secure_storage 10.x; migration to the replacement cipher happens automatically).
  • Migrated the example app's iOS project from CocoaPods to Swift Package Manager, and modernized the example app's Android project to Kotlin DSL (build.gradle.kts) with current AGP/Kotlin/Gradle versions.
  • Pigeon swiftOut path updated to match the new iOS source layout.

Fixed #

  • iOS: Swift Package Manager resolution failed with “target … is outside the package root” when using Flutter’s SPM integration. Native sources now live under ios/rspl_secure_vault/Sources/rspl_secure_vault/ with an updated Package.swift and podspec source_files paths; CocoaPods behavior is unchanged.
  • Example app's Android namespace collided with the plugin's own Android namespace (com.rishabhsoft.rspl_secure_vault), which newer AGP versions reject as a manifest merge error. The example app now uses com.rishabhsoft.rspl_secure_vault.example as its namespace (its applicationId is unchanged).

0.0.3 #

Changed #

  • Converted LICENSE file from markdown to plain text format for better compatibility

0.0.2 #

Changed #

  • Shortened package description for better pub.dev search optimization
  • Updated license to Rishabh Software Source Available License (Non-Commercial) v1.0

Added #

  • Test coverage badge (100%) in README
  • Platform declaration in pubspec.yaml

0.0.1 #

Added #

  • Initial release of RSPL Secure Vault
  • Envelope encryption with unique DEK (Data Encryption Key) per operation
  • Hardware-backed key storage:
    • iOS: Secure Enclave + Keychain
    • Android: Android Keystore with StrongBox support (when available)
  • AES-256-GCM encryption for all stored data
  • ECDH P-256 key agreement for secure key derivation
  • HKDF-SHA256 for key derivation function
  • Simple, secure-by-default API:
    • store(key, value) - Encrypt and store data
    • retrieve(key) - Retrieve and decrypt data
    • remove(key) - Remove specific key-value pair
    • clear() - Remove all stored data
    • containsKey(key) - Check if key exists
  • Internal security audit (62/62 checks passed)
  • 100% Dart test coverage

Security #

  • Cryptographically secure random number generators for all encryption
  • Per-operation unique nonces prevent nonce reuse attacks
  • GCM authentication tags (128-bit) ensure data integrity
  • Master keys never leave hardware security module
  • Debug logging gated behind kDebugMode (Dart) and #if DEBUG (native)
  • No sensitive data in error messages or logs

Documentation #

  • Comprehensive README with quick start guide
  • Common use cases (auth tokens, API keys)
  • Error handling guide
  • FAQ section
  • Security Audit report (SECURITY_AUDIT.md)
  • Architecture diagrams
4
likes
140
points
17
downloads

Documentation

API reference

Publisher

verified publisherrishabhsoft.com

Weekly Downloads

Secure Flutter plugin for storing sensitive data with hardware-backed encryption (iOS Secure Enclave, Android Keystore).

Repository (GitHub)
View/report issues
Contributing

Topics

#encryption #security #secure-storage #keychain #keystore

License

unknown (license)

Dependencies

flutter, flutter_secure_storage, plugin_platform_interface

More

Packages that depend on rspl_secure_vault

Packages that implement rspl_secure_vault