Skip to content

Repository files navigation

CasualChat

An anonymous chat application designed with privacy at its core (Android | Flutter).

CasualChat delivers instant, frictionless group chats by interest and one‑to‑one private messaging without collecting unnecessary permissions or personal data. Private chats use end‑to‑end encryption (RSA + AES‑GCM); group chats are lightweight and easy to browse. The app is built on Flutter with Firebase for realtime data sync.

Highlights

  • Anonymous by default: no registration forms or personal data collection. A UUID credential is generated and used for login on first launch.
  • Interest‑based group chats: browse topics, join groups instantly, and create your own.
  • End‑to‑end private messages: start from a user avatar in a group; RSA‑OAEP protects the session key, and AES‑GCM encrypts messages.
  • Minimal permissions: sensitive data is stored in secure storage with clear separation of concerns.
  • Profile basics: username and avatar (with a sensible default) for simple identity display.
  • Realtime UX: backed by Firebase Firestore snapshot streams for live updates.

Tech Stack

  • App framework: Flutter (Material 3)
  • Cloud services: Firebase (Authentication, Firestore, Storage)
  • Cryptography: RSA 2048 (OAEP) and AES‑256‑GCM
  • Secure storage: FlutterSecureStorage (private keys and session keys), SharedPreferences (non‑sensitive preferences)

Architecture & Modules

  • main.dart: App bootstrap and Firebase initialization.
  • welcome.dart: Welcome screen and entry into the login flow.
  • login.dart: Anonymous login (UUID → email/password); generates RSA keypair on first login and stores public key with signature.
  • navigation.dart: Bottom navigation with Home, Search, Add, and Profile.
  • home.dart: Shows joined conversations split into groups and chats.
  • search.dart: Fetches interests, displays topic lists, and joins relevant groups.
  • add.dart: Create new group chats (title/topics/cover image).
  • profile.dart: Edit username and avatar; sync changes to Firestore and cache locally.
  • messages.dart: Message stream UI; private chat encryption/decryption and session key handling.
  • encryption.dart: RSA helpers, AES‑GCM encrypt/decrypt, signing/verification, PEM encode/decode.

Data Model

Key Firestore collections and fields (examples):

  • users (minimal user profile)

    {
      "userID": "<Firebase Auth UID>",
      "username": "User#abcd1234",
      "profilePicture": "<base64>",
      "publicKey": "-----BEGIN RSA PUBLIC KEY-----...",
      "signature": "<base64 signature>",
      "groups": ["<chatID>", ...],
      "chats": ["<chatID>", ...]
    }
  • chats (group or private conversation metadata)

    • Group example:
      {
        "chatID": "<uuid>",
        "title": "Photography",
        "image": "<base64>",
        "interest": ["Art", "Camera"],
        "isGroup": true
      }
    • Private example:
      {
        "chatID": "<uuid>",
        "user1": "<userID A>",
        "user2": "<userID B>",
        "title": "<peer username>",
        "image": "<peer avatar base64>",
        "isGroup": false,
        "encryptedAESKey_user1": "<RSA‑OAEP encrypted>",
        "encryptedAESKey_user2": "<RSA‑OAEP encrypted>"
      }
  • messages (message records)

    {
      "userID": "<sender userID>",
      "content": "<plaintext for group | AES‑GCM ciphertext for private>",
      "timestamp": "<Firestore Timestamp>",
      "chatID": "<chatID>"
    }
  • interests (topic catalog)

    { "name": "Travel" }

Anonymity & Encryption

  • Credential generation: the app generates a UUID‑based email and a random password on first launch and signs in via Firebase Email/Password. No personal data is requested.
  • Key management:
    • First login creates an RSA 2048 keypair. The private key is stored in FlutterSecureStorage (privateKey).
    • The public key (PEM) and its signature (SHA‑256 with RSA, over the PEM text) are stored in the users document.
    • On subsequent logins, the public key’s signature is verified to detect tampering.
  • End‑to‑end private chat:
    • Initiation: tap a user avatar within a group to open or create a private conversation.
    • Session key: a 32‑byte AES‑256 key is generated per private chat, RSA‑OAEP‑encrypted with both participants’ public keys, and stored in the chats document (encryptedAESKey_user1/2).
    • Local storage: the current user decrypts the AES key with their private key and stores it in FlutterSecureStorage (aesKey_<chatID>).
    • Message encryption: private messages use AES‑GCM with a 96‑bit IV; group messages are plaintext for lightweight browsing and search.

Local Storage

  • FlutterSecureStorage
    • privateKey: RSA private key (PEM).
    • aesKey_<chatID>: AES session key for private chats (base64).
  • SharedPreferences
    • email / password: auto‑generated credentials.
    • username / profilePictureBase64: cached profile edits.

Getting Started

  1. Prerequisites: install Flutter and Android SDK; set up a device or emulator.
  2. Firebase setup:
    • Use FlutterFire CLI to generate and update lib/firebase_options.dart.
    • Place google-services.json in android/app/ (a sample is included in this repo).
  3. Install dependencies:
    • Run flutter pub get.
  4. Launch:
    • Run flutter run. The app performs anonymous login automatically and navigates to the main UI.

Usage

  • Home: browse your joined Groups and Chats; long‑press a card to remove the chat from your list.
  • Search: explore topics and join group chats; tapping a room adds it to your profile and opens messages.
  • Start a private chat: tap a member’s avatar inside a group to create or enter a one‑to‑one conversation (key distribution and encryption happen automatically).
  • Create a group: go to Add, input a title, select topics, upload a cover, and submit.
  • Edit profile: update username and avatar in Profile (default avatar at assets/images/default_profile.png).

Validation (Summary)

  • Login flow (10 devices): auto‑generated UUID credentials; no personal info requested; returning users re‑enter seamlessly.
  • Privacy checks: network monitoring and local storage inspection confirm no personal data transmission or storage beyond UUID and non‑identifiable fields.
  • User feedback (10 participants): smooth login, strong sense of anonymity, comfortable using the app without revealing identity.

Notes & Roadmap

  • Group messages are plaintext today for simplicity and openness. Planned enhancements:
    • Group end‑to‑end encryption (key agreement, member rotation).
    • Offline message caching.
    • Message recall/reporting.
    • Multi‑platform support (iOS, Web) and push notifications.
  • Security note: private chat security depends on key custody and device integrity; avoid using on untrusted devices.

Directory (Excerpt)

lib/
  add.dart           # create group chat
  encryption.dart    # crypto/key/signing utilities
  home.dart          # conversation list
  login.dart         # anonymous login and key generation
  messages.dart      # message UI and crypto
  navigation.dart    # bottom navigation
  profile.dart       # user profile
  search.dart        # topic search and group browsing
  welcome.dart       # welcome screen

Developer Tips

  • Tap a member’s avatar in a group to start a private chat (automatic key distribution).
  • Deleting a chat currently removes its chatID from the user document; it does not delete chats/messages globally (to avoid affecting other participants).
  • Crypto/signing helpers in encryption.dart:
    • RSA‑OAEP: encryptAESKey / decryptAESKey
    • AES‑GCM: encryptMessage / decryptMessage
    • Signing/verification: sign / verify

Acknowledgements

Built on Flutter and Firebase to provide instant realtime chat and robust privacy‑first design. Thanks to the course staff and peers for guidance and feedback.

About

A casual chat application built with Dart/Flutter

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages