feat: add Android app and end-to-end encrypted library sync

Introduce the Kotlin/Compose Android companion app and extend the TMDB
proxy into a combo server that synchronizes the whole library as an
encrypted snapshot, with all three components (Go server, Android,
desktop) sharing one zero-knowledge crypto envelope and JSON schema.

- server: add PostgreSQL-backed /sync/library (GET/PUT) with optimistic
  concurrency (revision + 409 on conflict); sync stays disabled unless
  DATABASE_URL is set. Add docker-compose with Postgres.
- desktop: add libsodium CryptoEnvelope, LibrarySerializer and SyncClient;
  storage-mode and passphrase settings; a "Sync now" toolbar action with
  conflict resolution.
- android: Room-backed library with local/cloud storage modes, encrypted
  sync client, and settings UI. The proxy server (URL + token) can be
  configured as a TMDB proxy even in local-only mode.

Crypto is identical across platforms: Argon2id (libsodium crypto_pwhash,
INTERACTIVE) + XChaCha20-Poly1305 in a versioned "UMTS" envelope, so a
snapshot encrypted on one client decrypts on the other.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Tronax 2026-06-21 00:35:54 +02:00
parent 83a26ef0cf
commit de353f0218
Signed by: Tronax
SSH key fingerprint: SHA256:2pKKXDZucWvaF/GzXNz0FY53EAO1YDLN80bqS+TTz/o
65 changed files with 4178 additions and 0 deletions

View file

@ -72,6 +72,28 @@ void AppSettings::setRawgApiKey(const QString &key) {
m_s.setValue(QStringLiteral("providers/rawgKey"), key);
}
QString AppSettings::storageMode() const {
return m_s.value(QStringLiteral("sync/storageMode"),
QStringLiteral("local")).toString();
}
void AppSettings::setStorageMode(const QString &mode) {
m_s.setValue(QStringLiteral("sync/storageMode"), mode);
}
QString AppSettings::syncPassphrase() const {
return m_s.value(QStringLiteral("sync/passphrase")).toString();
}
void AppSettings::setSyncPassphrase(const QString &pass) {
m_s.setValue(QStringLiteral("sync/passphrase"), pass);
}
qlonglong AppSettings::syncRevision() const {
return m_s.value(QStringLiteral("sync/revision"), 0).toLongLong();
}
void AppSettings::setSyncRevision(qlonglong revision) {
m_s.setValue(QStringLiteral("sync/revision"), revision);
}
bool AppSettings::autoFetchCovers() const {
return m_s.value(QStringLiteral("providers/autoCovers"), true).toBool();
}