Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungKI half beim Finden: iOS 27 schließt mehr als 100 Sicherheitslücken(21.09.2026 um 06:00 Uhr)
Sichere ProgrammierungWhat Is Rowhammer? How Can Repeated Memory Access Flip Bits in RAM?(21.09.2026 um 07:12 Uhr)
Sichere Programmierungnpm publish Ignores .gitignore: The .npmignore Override Rule(21.09.2026 um 07:15 Uhr)
Sichere ProgrammierungAphelion Editor - A free node-based video / VFX editor(21.09.2026 um 07:21 Uhr)
Sichere ProgrammierungGovernance Attack Surface Review: OKX(21.09.2026 um 07:31 Uhr)
Sichere ProgrammierungJSM Portal Request Create Property Panel Submit(21.09.2026 um 07:34 Uhr)
Reverse Engineeringsearch instructions assembly easy (X86,RISCV,AARCH64,etc)(20.09.2026 um 15:44 Uhr)
Sichere ProgrammierungKI half beim Finden: iOS 27 schließt mehr als 100 Sicherheitslücken(21.09.2026 um 06:00 Uhr)
Sichere ProgrammierungWhat Is Rowhammer? How Can Repeated Memory Access Flip Bits in RAM?(21.09.2026 um 07:12 Uhr)
Sichere Programmierungnpm publish Ignores .gitignore: The .npmignore Override Rule(21.09.2026 um 07:15 Uhr)
Sichere ProgrammierungAphelion Editor - A free node-based video / VFX editor(21.09.2026 um 07:21 Uhr)
Sichere ProgrammierungGovernance Attack Surface Review: OKX(21.09.2026 um 07:31 Uhr)
Sichere ProgrammierungJSM Portal Request Create Property Panel Submit(21.09.2026 um 07:34 Uhr)
Reverse Engineeringsearch instructions assembly easy (X86,RISCV,AARCH64,etc)(20.09.2026 um 15:44 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

The reinstall bug almost every Flutter app ships

Reagiere als Erste:r — dein Feedback zählt!

You can't see it in the simulator. Your testers won't hit it. Your crash reporter won't catch it — because it isn't a crash. It's a returning user quietly losing their app.

The setup. Your app stores data locally (drift, sqflite, Hive, Isar) and syncs to a cloud backend (Supabase, Firebase, your own API). Standard, sensible architecture.

Now a user does something completely ordinary: new phone, or they delete the app to free space and reinstall next week. The OS wipes local storage. Your local database is empty.

They open the app. What happens?

The bug. Most launch logic, stripped down, is:

final hasLocalData = await db.hasAnyData();
if (hasLocalData) goToHome();
else goToOnboarding(); // 👈 the bug

An empty local DB is treated as "new user." So your returning user — whose data is sitting intact in your cloud — gets onboarding or a blank home screen. To them, it looks like your app deleted everything. The data isn't gone, but the experience is indistinguishable from data loss, and that's what they write in the review.

"Easy — if local is empty, pull from cloud." That breaks in four ways, each its own outage:

  1. New vs. returning is ambiguous. A genuinely new user also has an empty local DB. Always-pull hammers your backend on every signup; never-pull loses returning users. And after a reinstall the auth session is gone too — you can't even check until they sign in.
  2. The encryption key is gone. If the local DB is encrypted, the key lived in secure storage — also wiped. You must recover it before writing a single row. That's a real design decision, not an afterthought.
  3. It isn't resumable. A 4,000-record pull dies at 2,200 on hotel wifi. Without a checkpoint, the next launch can't tell "done" from "half-full" — so you lose rows or restart from zero.
  4. A failed check silently becomes "new user." A timed-out request falls through to the onboarding path, and a returning user stares at a fresh-install screen. A transient blip must mean "retry," never data loss.

The shape of the real fix is a small state machine, not an if. Resolve the launch from four signals: an interrupted checkpoint → resume; local data present → normal launch; no account → onboarding/sign-in then re-check; local empty + authenticated → probe the cloud cheaply (a manifest), then restore or treat as a legitimately empty account. Then the restore itself: recover the key, pull in cursor-paged batches, upsert (idempotent), checkpoint after every batch, and treat any failure as retryable-into-resume.

None of it is exotic — but every piece is where teams get it subtly wrong, and the failure mode is invisible until it's a one-star review.

I packaged it. I kept rebuilding this across apps, so I extracted it into a small, tested, pure-Dart engine: RestoreKit. Zero Flutter/DB/network deps in the core; your stack plugs in through six interfaces. It ships Supabase, drift, and secure-storage adapters, a runnable demo (wipe the device, watch it restore, interrupt it, hit retry), and 36 tests — including the "interrupted restore resumes with no duplicates" case nobody writes a test for.

It's available now — full source, lifetime updates, one-time license: 👉 https://restorekit.dev

Either way: go check your own app's cold-launch path on an empty database with a signed-in returning user. I'd bet a coffee a good number of you ship this bug right now. 👀

What's the worst "looked like data loss but wasn't" bug you've shipped? I collect these.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten The reinstall bug almost every Flutter app ships

Thematisch verwandte Begriffe: reinstall, almost, every, Flutter · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94111 | Tencent BrowserSkill through 0.3.0 contains an authentication bypass vul…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick