import 'package:flutter_secure_storage/flutter_secure_storage.dart'; import 'package:login_vault_app/constants.dart'; /// Handles app-level authentication and persistence of the local identity. /// /// On first launch the user registers (email+password OR Google). The chosen /// email is stored locally as the key ([AppConstants.secureKeyEmail]) and the /// app password (used to lock the dashboard) is stored in secure storage. class AuthService { final FlutterSecureStorage _storage = const FlutterSecureStorage(); /// Returns the stored email, or null if not registered yet. Future getEmail() async => await _storage.read(key: AppConstants.secureKeyEmail); Future getAppPassword() async => await _storage.read(key: AppConstants.secureKeyAppPassword); /// True if a user identity already exists locally. Future isRegistered() async => (await getEmail()) != null; /// Register with email + app password. Future registerWithEmail(String email, String appPassword) async { await _storage.write(key: AppConstants.secureKeyEmail, value: email); await _storage.write( key: AppConstants.secureKeyAppPassword, value: appPassword); } /// Register with Google (email supplied by Google sign-in). Future registerWithGoogle(String email) async { await _storage.write(key: AppConstants.secureKeyEmail, value: email); // App password defaults to a marker; user can change it later in settings. final existing = await getAppPassword(); if (existing == null) { await _storage.write( key: AppConstants.secureKeyAppPassword, value: '__google__'); } } /// Verify the entered app password against the stored one. Future verifyPassword(String password) async { final stored = await getAppPassword(); if (stored == null) return false; if (stored == '__google__') { // Google users have no password by default; let any entry pass OR force set. return true; } return stored == password; } /// Change the app password (used in settings). Future changePassword(String newPassword) async { await _storage.write( key: AppConstants.secureKeyAppPassword, value: newPassword); } Future logout() async { // Keep email (identity) but we treat logout as returning to auth screen // with the email still known. To fully reset, call [reset]. } /// Wipe local identity (for completeness / debugging). Future reset() async { await _storage.delete(key: AppConstants.secureKeyEmail); await _storage.delete(key: AppConstants.secureKeyAppPassword); } }