checksumKey top-level constant

String const checksumKey

HMAC checksum layer sitting on top of StorageService's exportAll()/importAll() — sign a save file on export, verify it on import, so a consuming game can detect a save that was hand-edited (e.g. someone bumped their coin count with an external tool).

What this defends against: casual save editing — opening the exported JSON in a text editor / hex editor / save-editor app and changing a value, then feeding it back through importAll. Any such edit changes the HMAC, which verifyAndStrip catches before the data ever reaches importAll.

What this does NOT defend against: a determined attacker who extracts the app binary and recovers String secret passed here. This is a client-side, best-effort deterrent ("chống gian lận local-first"), not a substitute for server-side validation — same honest framing as lib/core/utils/clamped_clock.dart. That's why the secret is supplied by the consuming app rather than baked into this package: a secret shared by every game built on this kit would leak the moment anyone decompiles a single one of them.

Implementation

const String checksumKey = '_checksum';