Git Product home page Git Product logo

react-native-sensitive-info's Introduction

React Native Sensitive Info

npm version License: MIT Open Source Love

react-native-sensitive-info is the next generation of react-native-get-shared-prefs.

Introduction

react-native-sensitive-info manages all data stored in Android Shared Preferences, iOS Keychain and Windows Credentials. You can set and get all key/value using simple methods.

RN SensitiveInfo Version Description
4.0+ Compatible with RN 0.40+
<= 3.0.2 Compatible with RN 0.40 or below

Install

Install react-native-sensitive-info using:

npm i -S react-native-sensitive-info or yarn add react-native-sensitive-info

Linking project

Automatically

react-native link react-native-sensitive-info

Manually

iOS

If you are using Cocoapods add the following line to your Podfile:

pod 'react-native-sensitive-info', path: "../node_modules/react-native-sensitive-info"

otherwise follow those steps:

In XCode, in the project navigator:

  • Right click Libraries
  • Add Files to [your project's name]
  • Go to node_modules/react-native-sensitive-info
  • Add the .xcodeproj file

In XCode, in the project navigator, select your project.

  • Add the libRNSensitiveInfo.a from the RNSensitiveInfo project to your project's Build Phases โžœ Link Binary With Libraries
  • Click .xcodeproj file you added before in the project navigator and go the Build Settings tab. Make sure 'All' is toggled on (instead of 'Basic').
  • Look for Header Search Paths and make sure it contains both $(SRCROOT)/../react-native/React and $(SRCROOT)/../../React - mark both as recursive. (Should be OK by default.)

Run your project (Cmd+R)

Same steps as iOS but change the Base SDK to macOS in Libraries/RNSensitiveInfo.xcodeproj.

Android

Go to settings.gradle inside your android project folder and paste this lines there:

include ':react-native-sensitive-info'

project(':react-native-sensitive-info').projectDir = new File(rootProject.projectDir, '../node_modules/react-native-sensitive-info/android')

and paste it into build.gradle:

compile project(':react-native-sensitive-info')

In your MainApplication.java add:

import br.com.classapp.RNSensitiveInfo.RNSensitiveInfoPackage; //<- You must import this

protected List<ReactPackage> getPackages() {
    return Arrays.<ReactPackage>asList(
        new MainReactPackage(),
        new RNSensitiveInfoPackage(), // <- Add this line
    );
}

Sync gradle and go :)

Windows

  • Open the solution in Visual Studio for your Windows apps.

  • Right click your in the Explorer and click Add > Existing Project....

  • Navigate to .//node_modules/react-native-sensitive-info/windows/RNSensitiveInfo/RNSensitiveInfo/ and add RNSensitiveInfo.csproj.

  • Right click on your React Native Windows app under your solutions directory and click Add > Reference....

  • Check the RNSensitiveInfo you just added and press Ok

  • Open MainPage.cs in your app

using RNSqlite2;

get
  {
      return new List<IReactPackage>
      {
          new MainReactPackage(),
          new RNSensitiveInfoPackage(),
      };
  }

Expo

As noted by by @Palisand in this issue, it's not possible to use this module with Expo, unless your project is detached. The same is true for any modules with native code, it's not an issue with react-native-sensitive-info. You may want to try SecureStore from Expo itself.

Methods

We unified our library's methods to bring more efficiency and simplify the usability for other developers. We hope that you enjoy it. :)

isHardwareDetected(): resolves to a boolean that indicates the detection of fingerprint hardware

hasEnrolledFingerprints(): resolves to a boolean that indicates the enrollment status of fingerprints on the device

isSensorAvailable: resolves to a boolean that indicates the overall availability of fingerprint sensor (a combination of the previous two methods)

setItem(key, value, options): You can insert data into shared preferences & keychain using this promise method.

getItem(key, options): This promise will get value from given key.

deleteItem(key, options): It will delete value from given key

getAllItems(options): Will retrieve all keys and values from Shared Preferences & Keychain

"Options" is a new parameter (optional) that you can pass to our methods. But what does it do? Now, you can select which keychain's service (iOS) and shared preferences's name (android) you can use. To do so:

SInfo.setItem('key1', 'value1', {
sharedPreferencesName: 'mySharedPrefs',
keychainService: 'myKeychain'});

But if you prefer to not use it, our default sharedPreferencesName is: shared_preferences and keychainService is: app. For that, use:

SInfo.setItem('key1', 'value1', {});

If you used Android's getDefaultSharedPreferences in your project the shared preference's name that you are looking for is: com.mypackage.MyApp_preferences. On the other hand if you used iOS's Keychain the default service is: app which is our default too.

Android Specific Options

showModal & strings

When passing in touchID and showModal (Android only) options as true, an Android native prompt will show up asking for user's authentication. This behavior is similar to that of iOS.

You can control strings associated with a modal prompt via strings option:

strings: {
    header: 'Sign in',
    description: 'Place finger to authenticate',
    hint: 'Touch',
    success: 'Fingerprint recognized',
    notRecognized: 'Fingerprint not recognized, try again',
    cancel: 'Cancel',
    cancelled: 'Authentication was cancelled', // reject error message
}

iOS Specific Options

kSecAccessControl

When passing in the touchID option as true, you can also set kSecAccessControl. For example:

SInfo.setItem('key1', 'value1', {
  keychainService: 'myKeychain',
  kSecAccessControl: 'kSecAccessControlTouchIDCurrentSet',
  sharedPreferencesName: 'mySharedPrefs',
  touchID: true,
});

Note: By default kSecAccessControl will get set to kSecAccessControlUserPresence.

How to use?

Here is a simple example:

import SInfo from 'react-native-sensitive-info';

SInfo.setItem('key1', 'value1', {
sharedPreferencesName: 'mySharedPrefs',
keychainService: 'myKeychain'
}).then((value) =>
        console.log(value) //value 1
);

SInfo.setItem('key2', 'value2', {});

SInfo.getItem('key1', {
sharedPreferencesName: 'mySharedPrefs',
keychainService: 'myKeychain'}).then(value => {
    console.log(value) //value1
});

SInfo.getItem('key2',{}).then(value => {
    console.log(value) //value2
});

SInfo.getAllItems({
sharedPreferencesName: 'mySharedPrefs',
keychainService: 'myKeychain'}).then(values => {
    console.log(values) //value1, value2
});

Protect your item with fingerprint

As jailbroken device can access your iOS Keychain/ Android shared preference and key store in plain text, it is necessary to add another layer of protection so even jailbreaking won't leak your data (like refresh_token or bank account password).

  • for iOS it is implemented though Access Control. Everytime when app wants to access the protected keychain item, a prompt by iOS will show up. Only when authentication success will the app get the keychain item.
  • for Android it is implemented though FingerprintManager + Keystore. Keystore has a function called setUserAuthenticationRequired which makes Keystore requires user authentication before getting value. However Android doesn't nicely user to scan their finger, it just throws error. Here is where FingerprintManager comes in. However (AGAIN) FingerprintManager doesn't show prompt for you, so you need to build UI yourself to let user to know that it is time to scan fingerprint.

The example in the repo shows how to use this feature and how to build some Android UI based on callbacks.

NOTE: fingerprint will only work with Android 6.0 and above.

HELP NEEDED: It will be nice if someone can build an Android native prompt to make Android touch as easy to use as iOS. Maybe we can borrow some code from google's example

Use with redux-persist

If you would like to use redux-persist to store information from your Redux state into secure storage, you can use redux-persist-sensitive-storage, which provides a custom storage back-end for redux-persist that uses react-native-sensitive-info.

Contributing

Pull requests are always welcome :)

react-native-sensitive-info's People

Contributors

ajcrites avatar andrejcesen avatar denissb avatar futuun avatar hilkeheremans avatar mcodex avatar npomfret avatar randycoulman avatar rianniello avatar samin avatar serayuzgur avatar somoso avatar ugiacoman avatar ultrasecreth avatar un3qual avatar vspedr avatar ycai2 avatar zerglingno1 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.