A saved place is a named point the user keeps: it frames the map now, and once the worker publishes station data it is what the nearest-station readings and, later, the rain notifications will hang off. Free points rather than stations, because people think in terms of home and work, not in terms of which weather station happens to represent them. Everything stays on the device. Places live in SharedPreferences under a versioned key, and there is no account to attach them to and no server that would accept them. That is what keeps the Data safety declaration able to say no location is collected, and it must survive the notification work: the device will subscribe to the topic for the cell containing a place, so the link between a person and a place never leaves their phone. Location is coarse only, and that took enforcing. geolocator declares ACCESS_FINE_LOCATION in its own manifest and the merger pulls it in, so the system dialog offered "Precise" despite the app asking for nothing of the sort; the manifest now removes it with tools:node="remove", and the dialog reads "approximate location" with no choice offered. Requests also go through the platform LocationManager rather than the Play Services fused provider, which prompts about Location Accuracy and, when declined, returns no fix at all — an absurd outcome for an app that only ever wanted an approximate one, and one that also tied location to Play Services being present. The prominent disclosure comes before the system dialog, as Play requires, and is repeated in Settings so someone who already answered can still read what the permission is for. Declining leaves the app fully usable. Two more defects found by running it and by a test: - MapLibreMap leaves cameraPosition null unless trackCameraPosition is set, so "save the map centre" silently saved the region default rather than what the user was looking at. - Place ids came straight from the microsecond clock, so two places saved in the same microsecond shared an id and rename, remove and the duplicate-name check all acted on the wrong one. A test caught it on a fast machine. Saving refuses points outside the region rather than accepting them: a place in Rome would look like it worked and then show nothing forever. Also corrects CLAUDE.md, which still said ARPA states no licence, and records the ARPA realtime API there with the property that governs how it may be used — it lags about 4.5 hours, so it is an observation archive and must never sit next to 5-minute radar looking current. Verified: analyze clean, 158 tests passing, and on the emulator the disclosure precedes the system dialog, the dialog asks only for approximate location, a place survives restart and reinstall, and tapping one moves the map onto it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
209 lines
9.5 KiB
Markdown
209 lines
9.5 KiB
Markdown
# Roadmap
|
|
|
|
Each milestone ends with `tool/verify.ps1` green and one commit. A milestone is not
|
|
done until its acceptance criteria hold, **and until it has been seen running on the
|
|
emulator** — twice now that step has caught defects the tests did not.
|
|
|
|
Legend: ✅ done · 🔨 in progress · ⛔ blocked on something the project owner must supply
|
|
|
|
> **Scope**: radar on a map, saved places, ground-station observations, official alerts,
|
|
> rain notifications. Forecasts, lightning, a home-screen widget and advertising are all
|
|
> out — see CLAUDE.md.
|
|
|
|
---
|
|
|
|
## M0 — Toolchain and repository hygiene ✅
|
|
|
|
Flutter 3.47.3 stable, Android SDK (platform-tools, platform 36, build-tools 36.0.0),
|
|
JDK 21, environment variables. Commit the removal of the old Xamarin skeleton.
|
|
|
|
**Done.** `flutter doctor -v` reports "No issues found!". Installed: Flutter 3.47.3 at
|
|
`C:\src\flutter` (telemetry disabled), Android SDK at `C:\Android\Sdk` with platform 36,
|
|
build-tools 36.0.0, platform-tools and all licences accepted, and `JAVA_HOME` pointing at
|
|
the JDK 21 a previous Visual Studio install had already left on the machine.
|
|
|
|
## M1 — Scaffold, Italian l10n, region config, CI ✅
|
|
|
|
`flutter create` with applicationId `it.nuvolari.app`; `flutter_localizations` + `intl`
|
|
with `app_it.arb` as template and no hardcoded UI strings; `RegionConfig` loaded from
|
|
`assets/regions/piemonte.json` with parsing tests; `.gitignore`, `env.example.json`,
|
|
`tool/verify.ps1`, `.gitea/workflows/ci.yml`.
|
|
|
|
**Done.** All four stages green; the AAB carries applicationId `it.nuvolari.app`,
|
|
minSdk 24, targetSdk 36. Tests assert against the shipped Piemonte asset and a captured
|
|
copy of the live ARPA CAP feed.
|
|
|
|
> The Gitea instance may have no Actions runner. The workflow file is written to be
|
|
> GitHub-Actions compatible, but `tool/verify.ps1` is the verification that must pass.
|
|
|
|
## M2 — Map, attribution, Sources screen ✅
|
|
|
|
MapLibre on OpenStreetMap tiles, permanent OSM/OpenMapTiles attribution, and a
|
|
Sources / Licenses / Disclaimer screen with the explicit "not an official app"
|
|
disclaimer.
|
|
|
|
**Done and verified on the emulator.** The attribution bar lists only the sources
|
|
actually rendered — crediting OpenStreetMap while showing the offline fallback would be
|
|
a false attribution — and sits below the map, inside a SafeArea, so neither a map control
|
|
nor the system gesture pill can cover a credit the licences require to be visible.
|
|
|
|
Running it caught two defects the unit tests could not: the configured initial zoom put
|
|
the viewport entirely inside the region so the map read as a blank expanse, and the
|
|
attribution bar sat behind the gesture pill. The camera now fits the region bounds at
|
|
runtime, which works at any screen size.
|
|
|
|
## M3 — Animation and timeline ✅
|
|
|
|
`RadarSource` with `MockRadarSource` (synthetic frames in assets), `DpcRadarSource`
|
|
(reads our CDN) and `ArpaRadarSource` (disabled stub). Timeline scrubber, play/pause,
|
|
adjacent-frame prefetch, `FrameCache` LRU, animation suspended in background, graceful
|
|
degradation with a data-age banner.
|
|
|
|
**Done and verified on the emulator.** The overlay is double buffered, the timeline
|
|
lands on the newest frame, playback advances and wraps, scrubbing takes over from
|
|
playback, and the legend is drawn from the manifest rather than a constant.
|
|
|
|
Running it caught three more defects:
|
|
|
|
- The notifier wrote to `state` from inside `build()`, which Riverpod rejects as an
|
|
uninitialised provider. This broke startup, not just tests.
|
|
- Eight-month-old demo frames rendered as "Aggiornato 342535 minuti fa". The age
|
|
formatter now steps up to hours and days.
|
|
- Demo mode sat permanently behind a stale-data warning, so it never showed the
|
|
working state it exists to demonstrate. `MockRadarSource` now shifts the bundled
|
|
timestamps onto the present, leaving images, order and spacing untouched.
|
|
|
|
Frame caching is in memory only for now: mock frames are already in the asset bundle
|
|
and a disk layer belongs with the network adapter, where it would save a real request.
|
|
|
|
---
|
|
|
|
## M4 — Saved places and device location ✅
|
|
|
|
A named point the user keeps, used to frame the map and — once notifications exist — to
|
|
anchor them. Stored in `SharedPreferences` on the device and nowhere else.
|
|
|
|
**Done and verified on the emulator.** The prominent disclosure appears before the
|
|
system dialog, the permission is optional throughout, places survive an app restart and
|
|
a reinstall, and tapping one moves the map onto it.
|
|
|
|
Running it caught three defects the tests could not:
|
|
|
|
- `geolocator` injects `ACCESS_FINE_LOCATION` into the merged manifest, so the system
|
|
dialog offered "Precise" despite the app declaring only coarse. Removed with
|
|
`tools:node="remove"`; the dialog now reads "approximate location" and offers no
|
|
choice.
|
|
- The Play Services fused provider prompts about Location Accuracy, and declining it
|
|
yields no fix at all. Switched to the platform `LocationManager`, which also drops the
|
|
Play Services dependency.
|
|
- `MapLibreMap` leaves `cameraPosition` null unless `trackCameraPosition` is set, so
|
|
"save the map centre" silently saved the region default instead of what the user was
|
|
looking at.
|
|
|
|
A unit test also caught an id collision: ids came straight from the microsecond clock,
|
|
so two places saved in the same microsecond shared an id and rename, remove and the
|
|
duplicate check all acted on the wrong one.
|
|
|
|
## M5 — Backend worker ⛔
|
|
|
|
The critical path. Until this exists, `DpcRadarSource` has nothing to read and the app
|
|
can only show demo frames.
|
|
|
|
`backend/nuvolari_worker/`: `dpc_client` (with the `origin` header), `crop` (bbox +
|
|
reproject to EPSG:3857 — the source CRS is read from each file, never assumed),
|
|
`palette` (dBZ colormap, legend exported into the manifest), `render` (RGBA PNG,
|
|
transparent below threshold), `manifest`, and a `publisher/` with `LocalPublisher` and
|
|
`S3Publisher`. Also publishes, so the app never polls ARPA directly:
|
|
|
|
- `alerts.json` from the ARPA CAP bulletin;
|
|
- `stations.json` from the ARPA realtime API — rain accumulations
|
|
(1/3/6/12/24 h) and 72 hours of hourly temperature for the 374 stations, joined to
|
|
their coordinates from `/pie_anag`. The feed lags about 4.5 hours, so every reading
|
|
carries its own timestamp and the UI must present it as an observation, never as the
|
|
current conditions.
|
|
|
|
WebSocket trigger on `wss://radar-wss.protezionecivile.it`, with a 5-minute cron as
|
|
fallback.
|
|
|
|
**Accepts when:** `python -m pytest` passes and one full run produces PNGs plus a
|
|
`manifest.json` that the app consumes from a local server, showing real Piedmont
|
|
precipitation on the emulator.
|
|
|
|
**Blocked on (publishing only):** VPS / object storage endpoint and credentials.
|
|
Development proceeds against `LocalPublisher` and a LAN `python -m http.server`.
|
|
|
|
## M6 — Official alerts
|
|
|
|
`ArpaCapAlertSource` reading `alerts.json` from our CDN. Zones `Piem-A`…`Piem-M` with
|
|
levels shown **verbatim** and a link to the official bulletin next to every one.
|
|
|
|
Six level values, not four: `VERDE`, `GIALLO`, `ARANCIONE`, `ROSSO`, plus `BIANCO`
|
|
(avalanche scale, out of season) and `-` (not published). `BIANCO` and `-` are their own
|
|
state and must never be collapsed into `VERDE` — that would report "no alert" where the
|
|
bulletin reports "not assessed".
|
|
|
|
**Accepts when:** the eleven zones render with the levels the live feed carries, the
|
|
captured fixture parses, and every alert view links the official bulletin.
|
|
|
|
## M7 — Rain notifications ⛔
|
|
|
|
FCM topics per geographic cell, subscribed **from the device**, so no user location ever
|
|
reaches a server. The worker publishes per-cell rain state.
|
|
|
|
**Accepts when:** subscribing and unsubscribing works, and a published cell state
|
|
produces a notification on the emulator.
|
|
|
|
**Blocked on:** Firebase project and `google-services.json`.
|
|
|
|
## M8 — Play Store release preparation ⛔
|
|
|
|
Signing config reading `key.properties`, release AAB, target API 36, privacy policy,
|
|
store listing copy, Data safety declaration, prominent disclosure for location.
|
|
|
|
Data safety is unusually simple here: no advertising, no analytics, no accounts, and no
|
|
location leaving the device.
|
|
|
|
**Blocked on:** upload keystore and Play Console account.
|
|
|
|
---
|
|
|
|
## Pending inputs from the project owner
|
|
|
|
| Needed for | Item |
|
|
|---|---|
|
|
| M5 | VPS / object storage endpoint and credentials |
|
|
| M7 | Firebase project and `google-services.json` |
|
|
| M8 | Play Console account and upload keystore |
|
|
| ARPA radar adapter | The email to `info.meteo@arpa.piemonte.it` asking for the real-time access link **and the reuse licence**. Free of charge is not a licence, and without stated terms the frames cannot be republished. |
|
|
|
|
Nothing is needed for the base map: OpenFreeMap requires no key and no account.
|
|
|
|
---
|
|
|
|
## Verifying on the emulator
|
|
|
|
An AVD named `nuvolari` is set up on this machine: API 36.1, `google_apis`, x86_64,
|
|
GPU passthrough to the host. It uses a 2 GB data partition and no SD card because disk
|
|
is tight, and quickboot snapshots are disabled — they cost 2.6 GB to save a few seconds
|
|
of boot, which is the wrong trade here. Expect a cold boot of a minute or so.
|
|
|
|
In VS Code, just press **F5**: every emulator debug configuration boots it first. From a
|
|
shell:
|
|
|
|
```bash
|
|
# Boot it (idempotent — returns at once if a device is attached)
|
|
powershell -File tool/start_emulator.ps1
|
|
|
|
# Build, install, launch
|
|
cd app
|
|
flutter build apk --debug
|
|
adb install -r build/app/outputs/flutter-apk/app-debug.apk
|
|
adb shell am start -n it.nuvolari.app/.MainActivity
|
|
|
|
# Capture what it looks like
|
|
adb exec-out screencap -p > screen.png
|
|
```
|
|
|
|
`flutter run -d emulator-5554` works too and gives hot reload; the steps above are what
|
|
a non-interactive session uses.
|