What you'll learn
Use sensitive device capabilities responsibly with lifecycle-safe media, permission-state UX, privacy declarations, and fallbacks. The lesson turns the APIs into a repeatable engineering workflow instead of a collection of isolated snippets.
By the end of this lesson, you'll be able to:
- Apply Files and directories in a production-shaped Flutter feature
- Apply Camera and media in a production-shaped Flutter feature
- Apply Location in a production-shaped Flutter feature
- Apply Permission states in a production-shaped Flutter feature
Core mental model
Connect each API to the decision it supports. Flutter code stays maintainable when state, ownership, lifecycle, and platform boundaries are explicit.
| Concept | What it means | Decision rule |
|---|---|---|
| Just-in-time permission | A request appears when the user initiates the related feature | Explain value before the system prompt and request only what is needed |
| Capability state | Availability includes hardware, policy, permission, and service state | Model each recoverable state explicitly |
| Data minimization | Collect and retain only data necessary for the stated task | Delete temporary media and avoid background access by default |
Professional workflow
Work in small vertical slices and keep behavior observable from the first iteration.
- Define the permission-aware device workflow boundary: user goal, inputs, visible states, ownership, and expected failures.
- Build the smallest working vertical slice with typed data and explicit dependencies.
- Represent loading, empty, success, and failure behavior where the feature can encounter them.
- Verify logic away from the UI, then exercise the rendered behavior at its public boundary.
- Inspect lifecycle, accessibility, performance, security, and platform behavior before widening the feature.
- Refactor only after behavior is protected by repeatable evidence.
Protect the frame
Guided Flutter lab
Build a focused permission-aware device workflow slice
This compact example keeps the important ownership and data-flow decisions visible so the behavior is easy to extend and test.
Future<LocationOutcome> requestCurrentLocation(LocationGateway gateway) async {
if (!await gateway.serviceEnabled()) return const LocationOutcome.serviceOff();
var permission = await gateway.permission();
if (permission == LocationPermission.denied) {
permission = await gateway.requestPermission();
}
return switch (permission) {
LocationPermission.allowed => LocationOutcome.ready(await gateway.current()),
LocationPermission.denied => const LocationOutcome.denied(canAskAgain: true),
LocationPermission.permanentlyDenied => const LocationOutcome.denied(canAskAgain: false),
};
}Production practice
Contract
Define the permission-aware device workflow inputs, outputs, owner, lifecycle, visible states, and platform assumptions before selecting APIs or packages.
Verification
Protect pure rules with unit tests and the rendered public contract with widget or integration evidence; include one unavailable or failure case.
Operations
Keep dependencies replaceable, log actionable context without user secrets, and measure user-visible behavior before optimizing.
Common failure mode
Independent workshop
Extend the guided lab into a review-ready permission-aware device workflow feature that fits the running course portfolio app.
Your finished workshop must include:
- Files and directories
- Camera and media
- Location
- Permission states
- Platform manifests
- Automated verification and a short design note
Definition of done
Recap & quick check
Key takeaways
- Just-in-time permission: Explain value before the system prompt and request only what is needed
- Capability state: Model each recoverable state explicitly
- Data minimization: Delete temporary media and avoid background access by default
Quick check
1. Which rule best applies to Just-in-time permission?
2. Which rule best applies to Capability state?
3. Which rule best applies to Data minimization?
Next: Firebase & Backend Services