feat: add Android app and end-to-end encrypted library sync
Introduce the Kotlin/Compose Android companion app and extend the TMDB proxy into a combo server that synchronizes the whole library as an encrypted snapshot, with all three components (Go server, Android, desktop) sharing one zero-knowledge crypto envelope and JSON schema. - server: add PostgreSQL-backed /sync/library (GET/PUT) with optimistic concurrency (revision + 409 on conflict); sync stays disabled unless DATABASE_URL is set. Add docker-compose with Postgres. - desktop: add libsodium CryptoEnvelope, LibrarySerializer and SyncClient; storage-mode and passphrase settings; a "Sync now" toolbar action with conflict resolution. - android: Room-backed library with local/cloud storage modes, encrypted sync client, and settings UI. The proxy server (URL + token) can be configured as a TMDB proxy even in local-only mode. Crypto is identical across platforms: Argon2id (libsodium crypto_pwhash, INTERACTIVE) + XChaCha20-Poly1305 in a versioned "UMTS" envelope, so a snapshot encrypted on one client decrypts on the other. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
83a26ef0cf
commit
de353f0218
65 changed files with 4178 additions and 0 deletions
|
|
@ -22,6 +22,7 @@ type Config struct {
|
|||
SessionKey []byte // HMAC secret for signing access tokens / state cookies
|
||||
AllowGroups []string // if set, the user must be in one of these Authentik groups
|
||||
TokenTTL time.Duration // lifetime of issued desktop-app tokens
|
||||
DatabaseURL string // PostgreSQL DSN for library sync; empty disables sync
|
||||
}
|
||||
|
||||
func getenv(key, def string) string {
|
||||
|
|
@ -41,6 +42,7 @@ func loadConfig() (*Config, error) {
|
|||
ClientID: getenv("OIDC_CLIENT_ID", ""),
|
||||
ClientSecret: getenv("OIDC_CLIENT_SECRET", ""),
|
||||
RedirectURL: getenv("OIDC_REDIRECT_URL", ""),
|
||||
DatabaseURL: getenv("DATABASE_URL", ""),
|
||||
}
|
||||
|
||||
if c.RedirectURL == "" {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue