rspl_secure_vault 0.0.4
rspl_secure_vault: ^0.0.4 copied to clipboard
Secure Flutter plugin for storing sensitive data with hardware-backed encryption (iOS Secure Enclave, Android Keystore).
Changelog #
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
0.0.4 #
Changed #
- Raised
environment.sdkfloor to>=3.10.0 <4.0.0to match the actual requirements of updated dependencies, and added an explicitenvironment.flutterfloor of>=3.37.0. - Bumped
flutter_secure_storageto^10.3.1(federated iOS/macOS implementation now lives influtter_secure_storage_darwin, which ships aPackage.swiftalongside its podspec). - Bumped
flutter_lintsto^6.0.0andpigeonto^27.2.0. - Added the
FlutterFrameworkdependency declaration to the plugin's iOSPackage.swift, per Flutter's Swift Package Manager plugin-authoring guidance. - Removed the deprecated
encryptedSharedPreferencesoption from the internalAndroidOptionsconfiguration (ignored as offlutter_secure_storage10.x; migration to the replacement cipher happens automatically). - Migrated the example app's iOS project from CocoaPods to Swift Package Manager, and modernized the example app's Android project to Kotlin DSL (
build.gradle.kts) with current AGP/Kotlin/Gradle versions. - Pigeon
swiftOutpath updated to match the new iOS source layout.
Fixed #
- iOS: Swift Package Manager resolution failed with “target … is outside the package root” when using Flutter’s SPM integration. Native sources now live under
ios/rspl_secure_vault/Sources/rspl_secure_vault/with an updatedPackage.swiftand podspecsource_filespaths; CocoaPods behavior is unchanged. - Example app's Android
namespacecollided with the plugin's own Android namespace (com.rishabhsoft.rspl_secure_vault), which newer AGP versions reject as a manifest merge error. The example app now usescom.rishabhsoft.rspl_secure_vault.exampleas its namespace (itsapplicationIdis unchanged).
0.0.3 #
0.0.2 #
0.0.1 #
Added #
- Initial release of RSPL Secure Vault
- Envelope encryption with unique DEK (Data Encryption Key) per operation
- Hardware-backed key storage:
- iOS: Secure Enclave + Keychain
- Android: Android Keystore with StrongBox support (when available)
- AES-256-GCM encryption for all stored data
- ECDH P-256 key agreement for secure key derivation
- HKDF-SHA256 for key derivation function
- Simple, secure-by-default API:
store(key, value)- Encrypt and store dataretrieve(key)- Retrieve and decrypt dataremove(key)- Remove specific key-value pairclear()- Remove all stored datacontainsKey(key)- Check if key exists
- Internal security audit (62/62 checks passed)
- 100% Dart test coverage
Security #
- Cryptographically secure random number generators for all encryption
- Per-operation unique nonces prevent nonce reuse attacks
- GCM authentication tags (128-bit) ensure data integrity
- Master keys never leave hardware security module
- Debug logging gated behind
kDebugMode(Dart) and#if DEBUG(native) - No sensitive data in error messages or logs
Documentation #
- Comprehensive README with quick start guide
- Common use cases (auth tokens, API keys)
- Error handling guide
- FAQ section
- Security Audit report (SECURITY_AUDIT.md)
- Architecture diagrams