import 'dart:io'; /// ───────────────────────────────────────────────────────────────────────── /// THE APP VALIDATES CERTIFICATES AGAIN /// /// This class used to override `badCertificateCallback` to return `true` for /// every certificate, on every host, and it was installed globally in three /// places — `main`, the background isolate and the notification handler. That /// is not a lenient setting; it is **TLS switched off**. Any network the rider's /// phone joins could present a self-signed certificate for `api.doormile.com` /// and the app would hand over his session token, his live position and the /// day's cash figures without a word. /// /// It is the kind of thing that gets added once to get past a staging server /// and then ships. Both live hosts were checked before removing it and both /// present valid, publicly-trusted certificates — `api.doormile.com` and /// `queue.workolik.com` verify strictly under TLS 1.3 against Let's Encrypt. /// Nothing needed the bypass. /// /// ── What is left, and why the class is still here ── /// /// Dart's default `HttpClient` already validates properly, so the honest /// version of this override is one that changes nothing about trust. It stays /// as a named place to put a real connection policy — a timeout, a proxy, a /// pinned certificate — so that the next person who needs one has somewhere /// obvious to put it that is not "turn the checks off". /// /// **Never restore the callback.** If a host genuinely cannot present a valid /// certificate, pin *that host's* certificate here; do not trust every host on /// the internet to work around one. /// ───────────────────────────────────────────────────────────────────────── class MyHttpOverrides extends HttpOverrides { @override HttpClient createHttpClient(SecurityContext? context) => super.createHttpClient(context); }