core/save_integrity library

Constants

checksumKey → const String
HMAC checksum layer sitting on top of StorageService's exportAll()/importAll() — sign a save file on export, verify it on import, so a consuming game can detect a save that was hand-edited (e.g. someone bumped their coin count with an external tool).

Functions

signExport(Map<String, Object?> data, String secret) → Map<String, Object?>
Signs data (the output of StorageService.exportAll()) with an HMAC-SHA256 keyed by secret, returning a new map equal to data plus one reserved checksumKey entry holding the hex-encoded digest.
verifyAndStrip(Map<String, Object?> signed, String secret) → Map<String, Object?>
Verifies a map produced by signExport and, if the checksum matches, returns the original data with checksumKey removed — ready to pass straight into StorageService.importAll().