Adds opt-in biometric login to the Capacitor app. Replaces the password step on subsequent sign-ins; the 2FA step (if any) still applies — by design, defense in depth. How it works: - After a successful password sign-in on a Capacitor build, prompt the user to enroll. If they accept, capacitor-native-biometric.setCredentials stores the (email, password) pair in the iOS Keychain / Android Keystore with biometric-protected access. The local flag ped_bio_enabled=1 is set so the next launch knows to probe. - On the login form, if isNativeApp() + bioStored() + bioAvailable.ok, reveal the "Sign in with Face ID / Touch ID / fingerprint" button at the top. Label is set from the actual biometryType returned by the plugin so users see what their device supports. - Tap → verifyIdentity (OS prompt) → getCredentials → fill the email + password fields → fire the existing form submit so all the regular flow runs (turnstile, 2FA prompt, error handling, session storage). - Explicit logout deletes credentials AND clears the local flag, hiding the button on the next visit. Auto-logout (token expiry, network) does NOT come through that path, so biometric persists across silent session resets. Storage choice — password not JWT: - JWTs expire and the storage would constantly need refresh. - Storing the password lets the standard /api/auth/login flow run, which already handles password-rotation (a stale stored password just fails 401 → user falls back to typing the new one → re-enrolls). - The password sits in OS-level secure storage, accessible only after successful biometric verification — same security posture as a password manager autofill. Files: - mobile/package.json: add capacitor-native-biometric@^5.0.0 (Capacitor 6 compat) - mobile/android/app/src/main/AndroidManifest.xml: add USE_BIOMETRIC uses-permission - mobile/ios/App/App/Info.plist: add NSFaceIDUsageDescription string - public/js/auth.js: bioPlugin/bioAvailable/bioStored/bioEnroll/ bioRetrieve/bioForget helpers; window.PedBio surface; reveal-on-load; click handler; post-login enrollment prompt; logout cleanup - public/index.html: hidden #btn-bio-login + #bio-divider above the email field on the login form - public/css/styles.css: themed gradient button + hover lift - mobile/README.md: feature list updated Build steps for Daniel: cd mobile && npm install # picks up capacitor-native-biometric npx cap sync # ports the plugin into android/ + ios/ # then build APK / IPA as usual
84 lines
3.9 KiB
XML
84 lines
3.9 KiB
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<manifest xmlns:android="http://schemas.android.com/apk/res/android">
|
|
|
|
<!-- Biometric login (capacitor-native-biometric). USE_BIOMETRIC is the
|
|
API 28+ permission; older devices ignore it. No legacy FINGERPRINT
|
|
entry needed because capacitor-native-biometric targets API 23+. -->
|
|
<uses-permission android:name="android.permission.USE_BIOMETRIC" />
|
|
|
|
<application
|
|
android:allowBackup="false"
|
|
android:fullBackupContent="false"
|
|
android:dataExtractionRules="@xml/data_extraction_rules"
|
|
android:icon="@mipmap/ic_launcher"
|
|
android:label="@string/app_name"
|
|
android:roundIcon="@mipmap/ic_launcher_round"
|
|
android:supportsRtl="true"
|
|
android:theme="@style/AppTheme">
|
|
|
|
<activity
|
|
android:configChanges="orientation|keyboardHidden|keyboard|screenSize|locale|smallestScreenSize|screenLayout|uiMode"
|
|
android:name=".MainActivity"
|
|
android:label="@string/title_activity_main"
|
|
android:theme="@style/AppTheme.NoActionBarLaunch"
|
|
android:launchMode="singleTask"
|
|
android:exported="true">
|
|
|
|
<intent-filter>
|
|
<action android:name="android.intent.action.MAIN" />
|
|
<category android:name="android.intent.category.LAUNCHER" />
|
|
</intent-filter>
|
|
|
|
<!-- Deep linking: pedscribe:// and https://app.pedshub.com -->
|
|
<intent-filter android:autoVerify="true">
|
|
<action android:name="android.intent.action.VIEW" />
|
|
<category android:name="android.intent.category.DEFAULT" />
|
|
<category android:name="android.intent.category.BROWSABLE" />
|
|
<data android:scheme="pedscribe" />
|
|
</intent-filter>
|
|
<intent-filter android:autoVerify="true">
|
|
<action android:name="android.intent.action.VIEW" />
|
|
<category android:name="android.intent.category.DEFAULT" />
|
|
<category android:name="android.intent.category.BROWSABLE" />
|
|
<data android:scheme="https" android:host="app.pedshub.com" />
|
|
</intent-filter>
|
|
|
|
<!-- Share intent: receive text/files from other apps -->
|
|
<intent-filter>
|
|
<action android:name="android.intent.action.SEND" />
|
|
<category android:name="android.intent.category.DEFAULT" />
|
|
<data android:mimeType="text/plain" />
|
|
</intent-filter>
|
|
<intent-filter>
|
|
<action android:name="android.intent.action.SEND" />
|
|
<category android:name="android.intent.category.DEFAULT" />
|
|
<data android:mimeType="application/pdf" />
|
|
</intent-filter>
|
|
|
|
</activity>
|
|
|
|
<service
|
|
android:name=".AudioRecordingService"
|
|
android:foregroundServiceType="microphone"
|
|
android:exported="false" />
|
|
|
|
<provider
|
|
android:name="androidx.core.content.FileProvider"
|
|
android:authorities="${applicationId}.fileprovider"
|
|
android:exported="false"
|
|
android:grantUriPermissions="true">
|
|
<meta-data
|
|
android:name="android.support.FILE_PROVIDER_PATHS"
|
|
android:resource="@xml/file_paths"></meta-data>
|
|
</provider>
|
|
</application>
|
|
|
|
<!-- Permissions -->
|
|
<uses-permission android:name="android.permission.INTERNET" />
|
|
<uses-permission android:name="android.permission.RECORD_AUDIO" />
|
|
<uses-permission android:name="android.permission.MODIFY_AUDIO_SETTINGS" />
|
|
<uses-permission android:name="android.permission.FOREGROUND_SERVICE" />
|
|
<uses-permission android:name="android.permission.FOREGROUND_SERVICE_MICROPHONE" />
|
|
<uses-permission android:name="android.permission.POST_NOTIFICATIONS" />
|
|
<uses-permission android:name="android.permission.WAKE_LOCK" />
|
|
</manifest>
|