Phase 6 · Architecture, Testing & PerformanceModule 43~56 min read

Security, Privacy & Safe Storage

Threat-model client boundaries, protect tokens and data, validate inputs, review dependencies, and design consent and deletion flows.

What you'll learn

Threat-model client boundaries, protect tokens and data, validate inputs, review dependencies, and design consent and deletion flows. The lesson turns the APIs into a repeatable engineering workflow instead of a collection of isolated snippets.

By the end of this lesson, you'll be able to:

  • Apply Threat modeling in a production-shaped Flutter feature
  • Apply Auth and authorization in a production-shaped Flutter feature
  • Apply Secure storage in a production-shaped Flutter feature
  • Apply Client secret limits in a production-shaped Flutter feature

Core mental model

Connect each API to the decision it supports. Flutter code stays maintainable when state, ownership, lifecycle, and platform boundaries are explicit.

ConceptWhat it meansDecision rule
Trust boundaryA point where data or authority crosses between systemsValidate input and enforce authorization on the trusted side
Secure storageOS-backed protection for small sensitive valuesStore minimal short-lived tokens, not general application databases
Client secretA credential embedded in a distributed applicationAssume it can be extracted and keep privileged secrets on a backend

Professional workflow

Work in small vertical slices and keep behavior observable from the first iteration.

  1. Define the threat-modeled session boundary boundary: user goal, inputs, visible states, ownership, and expected failures.
  2. Build the smallest working vertical slice with typed data and explicit dependencies.
  3. Represent loading, empty, success, and failure behavior where the feature can encounter them.
  4. Verify logic away from the UI, then exercise the rendered behavior at its public boundary.
  5. Inspect lifecycle, accessibility, performance, security, and platform behavior before widening the feature.
  6. Refactor only after behavior is protected by repeatable evidence.

Protect the frame

Keep build methods predictable, move side effects to explicit owners, and measure before introducing caches, isolates, or architectural layers.

Guided Flutter lab

Build a focused threat-modeled session boundary slice

This compact example keeps the important ownership and data-flow decisions visible so the behavior is easy to extend and test.

lib/auth/session_store.dart
abstract interface class SessionStore {
  Future<void> saveRefreshToken(String token);
  Future<String?> readRefreshToken();
  Future<void> clear();
}

class SecureSessionStore implements SessionStore {
  SecureSessionStore(this.storage);
  final FlutterSecureStorage storage;
  static const key = 'refresh_token';

  @override Future<void> saveRefreshToken(String token) => storage.write(key: key, value: token);
  @override Future<String?> readRefreshToken() => storage.read(key: key);
  @override Future<void> clear() => storage.delete(key: key);
}

// Authorization still belongs on the server for every protected operation.

Production practice

Contract

Define the threat-modeled session boundary inputs, outputs, owner, lifecycle, visible states, and platform assumptions before selecting APIs or packages.

Verification

Protect pure rules with unit tests and the rendered public contract with widget or integration evidence; include one unavailable or failure case.

Operations

Keep dependencies replaceable, log actionable context without user secrets, and measure user-visible behavior before optimizing.

Common failure mode

Obfuscation, environment files, and compile-time defines do not turn a secret shipped in the app binary into a protected credential.

Independent workshop

Extend the guided lab into a review-ready threat-modeled session boundary feature that fits the running course portfolio app.

Your finished workshop must include:

  • Threat modeling
  • Auth and authorization
  • Secure storage
  • Client secret limits
  • Deep-link and WebView risks
  • Automated verification and a short design note

Definition of done

Demonstrate the happy path, an empty or unavailable state, and at least one failure path. Add an automated check and a short note explaining one design decision.

Recap & quick check

Key takeaways

  • Trust boundary: Validate input and enforce authorization on the trusted side
  • Secure storage: Store minimal short-lived tokens, not general application databases
  • Client secret: Assume it can be extracted and keep privileged secrets on a backend

Quick check

1. Which rule best applies to Trust boundary?

2. Which rule best applies to Secure storage?

3. Which rule best applies to Client secret?

Next: Native Integration, Flavors & Configuration