Phase 5 · Data, State & Device CapabilitiesModule 35~58 min read

Files, Camera, Location & Permissions

Use sensitive device capabilities responsibly with lifecycle-safe media, permission-state UX, privacy declarations, and fallbacks.

What you'll learn

Use sensitive device capabilities responsibly with lifecycle-safe media, permission-state UX, privacy declarations, and fallbacks. The lesson turns the APIs into a repeatable engineering workflow instead of a collection of isolated snippets.

By the end of this lesson, you'll be able to:

  • Apply Files and directories in a production-shaped Flutter feature
  • Apply Camera and media in a production-shaped Flutter feature
  • Apply Location in a production-shaped Flutter feature
  • Apply Permission states in a production-shaped Flutter feature

Core mental model

Connect each API to the decision it supports. Flutter code stays maintainable when state, ownership, lifecycle, and platform boundaries are explicit.

ConceptWhat it meansDecision rule
Just-in-time permissionA request appears when the user initiates the related featureExplain value before the system prompt and request only what is needed
Capability stateAvailability includes hardware, policy, permission, and service stateModel each recoverable state explicitly
Data minimizationCollect and retain only data necessary for the stated taskDelete temporary media and avoid background access by default

Professional workflow

Work in small vertical slices and keep behavior observable from the first iteration.

  1. Define the permission-aware device workflow boundary: user goal, inputs, visible states, ownership, and expected failures.
  2. Build the smallest working vertical slice with typed data and explicit dependencies.
  3. Represent loading, empty, success, and failure behavior where the feature can encounter them.
  4. Verify logic away from the UI, then exercise the rendered behavior at its public boundary.
  5. Inspect lifecycle, accessibility, performance, security, and platform behavior before widening the feature.
  6. Refactor only after behavior is protected by repeatable evidence.

Protect the frame

Keep build methods predictable, move side effects to explicit owners, and measure before introducing caches, isolates, or architectural layers.

Guided Flutter lab

Build a focused permission-aware device workflow slice

This compact example keeps the important ownership and data-flow decisions visible so the behavior is easy to extend and test.

lib/device/location_flow.dart
Future<LocationOutcome> requestCurrentLocation(LocationGateway gateway) async {
  if (!await gateway.serviceEnabled()) return const LocationOutcome.serviceOff();

  var permission = await gateway.permission();
  if (permission == LocationPermission.denied) {
    permission = await gateway.requestPermission();
  }
  return switch (permission) {
    LocationPermission.allowed => LocationOutcome.ready(await gateway.current()),
    LocationPermission.denied => const LocationOutcome.denied(canAskAgain: true),
    LocationPermission.permanentlyDenied => const LocationOutcome.denied(canAskAgain: false),
  };
}

Production practice

Contract

Define the permission-aware device workflow inputs, outputs, owner, lifecycle, visible states, and platform assumptions before selecting APIs or packages.

Verification

Protect pure rules with unit tests and the rendered public contract with widget or integration evidence; include one unavailable or failure case.

Operations

Keep dependencies replaceable, log actionable context without user secrets, and measure user-visible behavior before optimizing.

Common failure mode

Requesting camera, photos, and precise location at startup gives no context, harms trust, and may violate store expectations for unused permissions.

Independent workshop

Extend the guided lab into a review-ready permission-aware device workflow feature that fits the running course portfolio app.

Your finished workshop must include:

  • Files and directories
  • Camera and media
  • Location
  • Permission states
  • Platform manifests
  • Automated verification and a short design note

Definition of done

Demonstrate the happy path, an empty or unavailable state, and at least one failure path. Add an automated check and a short note explaining one design decision.

Recap & quick check

Key takeaways

  • Just-in-time permission: Explain value before the system prompt and request only what is needed
  • Capability state: Model each recoverable state explicitly
  • Data minimization: Delete temporary media and avoid background access by default

Quick check

1. Which rule best applies to Just-in-time permission?

2. Which rule best applies to Capability state?

3. Which rule best applies to Data minimization?

Next: Firebase & Backend Services