checksumKey top-level constant
HMAC checksum layer sitting on top of StorageService's
exportAll()/importAll() — sign a save file on export, verify it on
import, so a consuming game can detect a save that was hand-edited
(e.g. someone bumped their coin count with an external tool).
What this defends against: casual save editing — opening the
exported JSON in a text editor / hex editor / save-editor app and
changing a value, then feeding it back through importAll. Any such
edit changes the HMAC, which verifyAndStrip catches before the data
ever reaches importAll.
What this does NOT defend against: a determined attacker who
extracts the app binary and recovers String secret passed here. This
is a client-side, best-effort deterrent ("chống gian lận local-first"),
not a substitute for server-side validation — same honest framing as
lib/core/utils/clamped_clock.dart. That's why the secret is supplied
by the consuming app rather than baked into this package: a secret
shared by every game built on this kit would leak the moment anyone
decompiles a single one of them.
Implementation
const String checksumKey = '_checksum';