smronju / nativephp-secure-storage
Implements NativePHP Mobile's SecureStorage::set()/get()/delete() on both platforms — Android Keystore (AES-256-GCM) on Android, the Keychain on iOS.
Package info
github.com/smronju/nativephp-secure-storage
Type:nativephp-plugin
pkg:composer/smronju/nativephp-secure-storage
Requires
- php: ^8.2
- nativephp/mobile: ^4.1
Requires (Dev)
- pestphp/pest: ^3.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
Implements NativePHP Mobile's SecureStorage facade
on Android and iOS: SecureStorage::set(), get(), read() and delete().
nativephp/mobile core ships the PHP side (Native\Mobile\Facades\SecureStorage)
but registers the SecureStorage.* bridge functions on neither platform, so
without a plugin every call silently returns false / null on a device.
This plugin adds the native side only. There is no new facade to learn.
How values are stored
- Android: AES-256-GCM, with the key held in the Android Keystore (it
never leaves secure hardware or the TEE). The ciphertext lives in the app's
private SharedPreferences. No Gradle dependencies;
EncryptedSharedPreferencesis deprecated, so it isn't used. - iOS: one Keychain generic-password item per key, scoped to the app's
bundle id. Every accessibility is a
ThisDeviceOnlyone, so items never sync to iCloud Keychain or restore onto another device.
Uninstalling the app removes everything on Android. On iOS the Keychain can outlive an uninstall, as it does for every app.
Requirements
nativephp/mobile^4.1- Android API 23+
- iOS 15.0+
Installation
composer require smronju/nativephp-secure-storage php artisan vendor:publish --tag=nativephp-plugins-provider php artisan native:plugin:register smronju/nativephp-secure-storage
Then rebuild: php artisan native:run.
Don't install it alongside nativephp/mobile-secure-storage: both register
the same SecureStorage.* functions.
Usage
Exactly as core documents it:
use Native\Mobile\Facades\SecureStorage; use Native\Mobile\SecureStorageAccessibility; SecureStorage::set('api_token', $token); SecureStorage::set('refresh_token', $refresh, SecureStorageAccessibility::AfterFirstUnlock); $token = SecureStorage::get('api_token'); // ?string $result = SecureStorage::read('api_token'); // found() / missing() / unavailable() / failed() SecureStorage::set('api_token', null); // null deletes SecureStorage::delete('refresh_token');
read() statuses:
| Status | Android | iOS |
|---|---|---|
found |
stored and decrypted | stored |
not_found |
never stored, or deleted | never stored, or deleted |
unavailable |
never (see below) | device locked and the item is WhenUnlocked / WhenPasscodeSet |
error |
DECRYPT_FAILED: the Keystore key is gone, e.g. after a credential reset |
KEYCHAIN_<OSStatus> |
The accessibility argument is ignored on Android, as core documents: a Keystore key without user-authentication requirements is usable whenever the app runs, which is already after-first-unlock behaviour.
Testing
composer test
License
MIT