Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

NativePHP Secure Storage

Implements NativePHP Mobile's SecureStorage facade on Android and iOS: SecureStorage::set(), get(), read() and delete().

nativephp/mobile core ships the PHP side (Native\Mobile\Facades\SecureStorage) but registers the SecureStorage.* bridge functions on neither platform, so without a plugin every call silently returns false / null on a device. This plugin adds the native side only. There is no new facade to learn.

How values are stored

  • Android: AES-256-GCM, with the key held in the Android Keystore (it never leaves secure hardware or the TEE). The ciphertext lives in the app's private SharedPreferences. No Gradle dependencies; EncryptedSharedPreferences is deprecated, so it isn't used.
  • iOS: one Keychain generic-password item per key, scoped to the app's bundle id. Every accessibility is a ThisDeviceOnly one, so items never sync to iCloud Keychain or restore onto another device.

Uninstalling the app removes everything on Android. On iOS the Keychain can outlive an uninstall, as it does for every app.

Requirements

  • nativephp/mobile ^4.1
  • Android API 23+
  • iOS 15.0+

Installation

composer require smronju/nativephp-secure-storage
php artisan vendor:publish --tag=nativephp-plugins-provider
php artisan native:plugin:register smronju/nativephp-secure-storage

Then rebuild: php artisan native:run.

Don't install it alongside nativephp/mobile-secure-storage: both register the same SecureStorage.* functions.

Usage

Exactly as core documents it:

use Native\Mobile\Facades\SecureStorage;
use Native\Mobile\SecureStorageAccessibility;

SecureStorage::set('api_token', $token);
SecureStorage::set('refresh_token', $refresh, SecureStorageAccessibility::AfterFirstUnlock);

$token = SecureStorage::get('api_token');   // ?string

$result = SecureStorage::read('api_token'); // found() / missing() / unavailable() / failed()

SecureStorage::set('api_token', null);      // null deletes
SecureStorage::delete('refresh_token');

read() statuses:

Status Android iOS
found stored and decrypted stored
not_found never stored, or deleted never stored, or deleted
unavailable never (see below) device locked and the item is WhenUnlocked / WhenPasscodeSet
error DECRYPT_FAILED: the Keystore key is gone, e.g. after a credential reset KEYCHAIN_<OSStatus>

The accessibility argument is ignored on Android, as core documents: a Keystore key without user-authentication requirements is usable whenever the app runs, which is already after-first-unlock behaviour.

Testing

composer test

License

MIT

About

Free SecureStorage for NativePHP Mobile: implements the SecureStorage.Set/Get/Delete bridge functions so core's SecureStorage facade works on device. Android Keystore (AES-256-GCM) and iOS Keychain, no dependencies.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages