feat(beta): External Beta — passwords, channel join, mute, bookmarks, encrypted identity
The v0.3 client could only ever connect to a hardcoded default
channel with no password and offered no controls mid-call.
External Beta closes those gaps and tightens identity-at-rest.
User-facing additions
---------------------
* **Server password** on the connect form. Plumbed through
`BridgeError`-aware `connect(host, nickname, password)`. Empty
string means "no password" — no behaviour change for open
servers.
* **Channel join**: tapping a row (or its login icon) in the
channel tree issues a `client_move`. Names containing "🔒" or
"password" prompt for a channel password first.
* **Self-mute** for both microphone (`client_input_muted`) and
speaker (`client_output_muted`) via FilterChips. Output mute
also flips the audio engine's local output-muted flag so
playback silences immediately, before the server acknowledges.
* **Master output gain** slider (0–200%). Plumbed through an
`AtomicU32` (f32 bits) on the engine that the cpal output
callback multiplies into every sample.
* **Bookmarks**: SQLite-backed list with Save / Connect / Delete
actions. Bookmarks persist across app restarts; tapping one
pre-fills the form and dials immediately.
Hardening
---------
* **Encrypted identity at rest** (RISK-PoC-002 closure for the
file-only threat model). ChaCha20-Poly1305 envelope: nonce +
ciphertext written atomically with mode 0600; 32-byte DEK in a
separate `identity.dek` file. Legacy plaintext identity files
are auto-detected, read, and upgraded on the next save. Full OS-
keyring integration is still v0.4 work — documented in the
store's doc comment.
* **Mobile voice-comm routing**: on Android, `AudioEngine::start`
uses JNI to set `AudioManager.setMode(MODE_IN_COMMUNICATION)`
when `cfg.mobile_voice_preset` is true (default). This engages
the device-side AEC/NS pipeline on most Pixel/Moto/Samsung
hardware even though cpal still opens the AAudio default input
preset. Full `setInputPreset(VOICE_COMMUNICATION)` switch is
still RISK-AUDIO-MOBILE-001 (needs cpal upstream or an Oboe
fork).
* **Log noise**: bridge default `EnvFilter` now silences
`tsproto::resend=error` and `tsproto::packet_codec=error` so
the redacted diagnostic export is human-readable. Still
overridable via `RUST_LOG=...`.
Engineering
-----------
* **`chanora_storage`** gains `BookmarkRepository` (rusqlite
bundled) with `add` / `update` / `delete` / `list`. The
identity store now layers on `chacha20poly1305` + `rand` +
`zeroize` for the envelope.
* **`chanora_protocol`** exposes `move_to_channel` and
`set_muted` on `ProtocolClient`, dispatched through the
existing `connection_task` request channel onto tsclientlib's
generated `client.client_move(...)` and
`state.client_update().set_input_muted/set_output_muted(...)`
paths.
* **`chanora_core::ChanoraSession`** wires the bookmark store
next to the identity store inside `init_storage`, and adds
`list_bookmarks` / `add_bookmark` / `update_bookmark` /
`delete_bookmark` / `move_to_channel` / `set_self_muted` /
`set_output_gain`.
* **`chanora_audio::AudioEngine`** carries `output_gain` and
`output_muted` atomics; the output callback consults both. The
Android branch of `start()` engages MODE_IN_COMMUNICATION via
a small JNI helper that reuses the `ndk_context` global set by
the bridge's `android_init` hook.
* **`chanora_bridge::api`** adds `set_input_muted`,
`set_output_muted`, `set_output_gain`, `move_to_channel`,
`list_bookmarks`, `add_bookmark`, `update_bookmark`,
`delete_bookmark`, and the `BridgeBookmark` DTO. FRB v2.12
codegen regenerated.
Tests + CI
----------
* `chanora_storage` test count rises from 3 to 8 — bookmark CRUD
round-trip, missing-row → `NotFound`, encrypted round-trip
(verifies ciphertext is not the plaintext on disk), and the
legacy plaintext upgrade path.
* New `.github/workflows/ci.yml`: `cargo check --workspace`,
`cargo test --workspace --no-fail-fast`, `cargo clippy`
(advisory), `flutter analyze`, and `flutter test` excluding
the live-server `e2e` tag.
Live-verified on Moto G Stylus 5G against cn.teamspeak.app:
saved a bookmark, reconnected via it, joined a non-default
channel via tap, toggled both mutes, slid the volume, and the
redacted diagnostic export confirmed `AudioManager mode set to
MODE_IN_COMMUNICATION`, `client_move sent`, and `client_update
sent` lines.
This commit is contained in:
@@ -10,15 +10,23 @@ import 'package:freezed_annotation/freezed_annotation.dart' hide protected;
|
||||
part 'api.freezed.dart';
|
||||
|
||||
// These functions are ignored because they are not marked as `pub`: `log_sink`, `runtime`, `session`
|
||||
// These function are ignored because they are on traits that is not defined in current crate (put an empty `#[frb]` on it to unignore): `clone`, `clone`, `clone`, `clone`, `clone`, `clone`, `fmt`, `fmt`, `fmt`, `fmt`, `fmt`, `fmt`, `from`, `from`, `from`
|
||||
// These function are ignored because they are on traits that is not defined in current crate (put an empty `#[frb]` on it to unignore): `clone`, `clone`, `clone`, `clone`, `clone`, `clone`, `clone`, `fmt`, `fmt`, `fmt`, `fmt`, `fmt`, `fmt`, `fmt`, `from`, `from`, `from`, `from`, `from`
|
||||
|
||||
/// Connect to a TeamSpeak-compatible server and return the initial
|
||||
/// state snapshot. Honours the DEC-006 single-connection invariant
|
||||
/// via [`BridgeError::AlreadyConnected`].
|
||||
///
|
||||
/// `password` is optional — pass an empty string for servers that
|
||||
/// don't require one.
|
||||
Future<BridgeSnapshot> connect({
|
||||
required String host,
|
||||
required String nickname,
|
||||
}) => RustLib.instance.api.crateApiConnect(host: host, nickname: nickname);
|
||||
required String password,
|
||||
}) => RustLib.instance.api.crateApiConnect(
|
||||
host: host,
|
||||
nickname: nickname,
|
||||
password: password,
|
||||
);
|
||||
|
||||
/// Re-fetch a fresh snapshot from the active connection.
|
||||
Future<BridgeSnapshot> snapshot() => RustLib.instance.api.crateApiSnapshot();
|
||||
@@ -37,6 +45,36 @@ Future<void> startAudio() => RustLib.instance.api.crateApiStartAudio();
|
||||
Future<void> setPtt({required bool active}) =>
|
||||
RustLib.instance.api.crateApiSetPtt(active: active);
|
||||
|
||||
/// Move our own client to `channel_id`. Optional channel password
|
||||
/// for password-protected channels — pass an empty string when not
|
||||
/// required.
|
||||
Future<void> moveToChannel({
|
||||
required BigInt channelId,
|
||||
required String password,
|
||||
}) => RustLib.instance.api.crateApiMoveToChannel(
|
||||
channelId: channelId,
|
||||
password: password,
|
||||
);
|
||||
|
||||
/// Toggle self input-mute (microphone) on the server. Independent
|
||||
/// of push-to-talk: a muted client never transmits regardless of
|
||||
/// PTT state.
|
||||
Future<void> setInputMuted({required bool muted}) =>
|
||||
RustLib.instance.api.crateApiSetInputMuted(muted: muted);
|
||||
|
||||
/// Toggle self output-mute (speaker). Mutes locally *and* informs
|
||||
/// the server. The server uses this for the channel icon next to
|
||||
/// the client name; the local mute kicks in immediately even
|
||||
/// before the server acknowledges.
|
||||
Future<void> setOutputMuted({required bool muted}) =>
|
||||
RustLib.instance.api.crateApiSetOutputMuted(muted: muted);
|
||||
|
||||
/// Set master output gain. `1.0` is unity, `0.0` is silent. Values
|
||||
/// above `1.0` amplify and can clip downstream. Errors when audio
|
||||
/// is not started.
|
||||
Future<void> setOutputGain({required double gain}) =>
|
||||
RustLib.instance.api.crateApiSetOutputGain(gain: gain);
|
||||
|
||||
/// User-initiated diagnostic export. Returns a multi-line text
|
||||
/// blob, redacted per the production policy, that the user can
|
||||
/// share or copy. DEC-016 forbids automatic uploads — this is the
|
||||
@@ -58,6 +96,23 @@ String exportDiagnostics() => RustLib.instance.api.crateApiExportDiagnostics();
|
||||
Future<void> initStorage({required String dir}) =>
|
||||
RustLib.instance.api.crateApiInitStorage(dir: dir);
|
||||
|
||||
/// List persisted bookmarks.
|
||||
Future<List<BridgeBookmark>> listBookmarks() =>
|
||||
RustLib.instance.api.crateApiListBookmarks();
|
||||
|
||||
/// Insert a bookmark and return its assigned id. The `id` field on
|
||||
/// the input is ignored.
|
||||
Future<PlatformInt64> addBookmark({required BridgeBookmark b}) =>
|
||||
RustLib.instance.api.crateApiAddBookmark(b: b);
|
||||
|
||||
/// Update an existing bookmark.
|
||||
Future<void> updateBookmark({required BridgeBookmark b}) =>
|
||||
RustLib.instance.api.crateApiUpdateBookmark(b: b);
|
||||
|
||||
/// Delete a bookmark by id.
|
||||
Future<void> deleteBookmark({required PlatformInt64 id}) =>
|
||||
RustLib.instance.api.crateApiDeleteBookmark(id: id);
|
||||
|
||||
/// Notify the core of the latest OS-reported connectivity state.
|
||||
/// Called by the Flutter side from `connectivity_plus` callbacks.
|
||||
/// The core's supervisor uses this to (a) pre-charge the watchdog
|
||||
@@ -107,6 +162,52 @@ class BridgeAudioStats {
|
||||
pttActive == other.pttActive;
|
||||
}
|
||||
|
||||
/// Bookmark DTO mirroring [`chanora_core::Bookmark`].
|
||||
class BridgeBookmark {
|
||||
/// Row id assigned by SQLite. Use `0` when adding new rows;
|
||||
/// the returned id is then meaningful.
|
||||
final PlatformInt64 id;
|
||||
|
||||
/// User-facing label.
|
||||
final String displayName;
|
||||
|
||||
/// `hostname[:port]` or TSDNS name.
|
||||
final String host;
|
||||
|
||||
/// Nickname to use for this bookmark.
|
||||
final String nickname;
|
||||
|
||||
/// Optional remembered password. Empty string = none.
|
||||
final String password;
|
||||
|
||||
const BridgeBookmark({
|
||||
required this.id,
|
||||
required this.displayName,
|
||||
required this.host,
|
||||
required this.nickname,
|
||||
required this.password,
|
||||
});
|
||||
|
||||
@override
|
||||
int get hashCode =>
|
||||
id.hashCode ^
|
||||
displayName.hashCode ^
|
||||
host.hashCode ^
|
||||
nickname.hashCode ^
|
||||
password.hashCode;
|
||||
|
||||
@override
|
||||
bool operator ==(Object other) =>
|
||||
identical(this, other) ||
|
||||
other is BridgeBookmark &&
|
||||
runtimeType == other.runtimeType &&
|
||||
id == other.id &&
|
||||
displayName == other.displayName &&
|
||||
host == other.host &&
|
||||
nickname == other.nickname &&
|
||||
password == other.password;
|
||||
}
|
||||
|
||||
/// Channel as seen by Dart. Matches `chanora_protocol::ChannelInfo`
|
||||
/// but with primitive `u64` ids so the Dart side gets `BigInt`s
|
||||
/// without any wrapper-type ceremony.
|
||||
|
||||
Reference in New Issue
Block a user