# Fitness Tracking App - Production Deployment Guide ## Architecture Overview ``` ┌─────────────────────────────────────────────────────────────┐ │ Flutter Mobile App │ │ ┌─────────────────────────────────────────────────────────┐ │ │ │ GetX Controller (State Management) │ │ │ │ - WorkoutController: Orchestrates tracking logic │ │ │ │ - LocationService: SQLite background storage │ │ │ └─────────────────────────────────────────────────────────┘ │ │ │ │ │ ┌─────────────────────────┴──────────────────────────────┐ │ │ │ Views & UI Components │ │ │ │ - WorkoutTrackingScreen: MapLibre map + stats │ │ │ │ - Real-time GPS overlay on MapLibre │ │ │ │ - Polyline encoding for route submission │ │ │ └─────────────────────────────────────────────────────────┘ │ │ │ │ │ ┌─────────────────┴──────────────────┐ │ │ │ HMAC-SHA256 Signature Generator │ │ │ └─────────────────┬──────────────────┘ │ │ ▼ │ └───────────────────────────────────────────────────────────────┘ │ HTTPS │ HMAC-SHA256 Authenticated ▼ ┌───────────────────────────────────────────────────────────────┐ │ PHP Backend (REST API) │ │ ┌─────────────────────────────────────────────────────────┐ │ │ │ Authentication Layer │ │ │ │ - HMAC-SHA256 Signature Verification │ │ │ │ - Timestamp Validation (Replay Attack Prevention) │ │ │ │ - Rate Limiting & API Key Management │ │ │ └─────────────────────────────────────────────────────────┘ │ │ │ │ │ ┌─────────────────────────┴──────────────────────────────┐ │ │ │ /api/v1/workouts (POST) │ │ │ │ - WorkoutValidator: Validates payload structure │ │ │ │ - PolylineUtility: Decodes & validates routes │ │ │ │ - Database: Stores workouts & coordinates │ │ │ └─────────────────────────────────────────────────────────┘ │ └───────────────────────────────────────────────────────────────┘ │ ▼ ┌───────────────────────────────────────────────────────────────┐ │ MySQL Database │ │ ┌──────────────┐ ┌─────────────┐ ┌──────────────────┐ │ │ │ users │ │ workouts │ │ api_logs │ │ │ │ - id │ │ - id │ │ - user_id │ │ │ │ - api_key │ │ - distance │ │ - endpoint │ │ │ │ - api_secret│ │ - polyline │ │ - status_code │ │ │ └──────────────┘ │ - duration │ └──────────────────┘ │ │ │ - calories │ │ │ │ - metadata │ │ │ └─────────────┘ │ └───────────────────────────────────────────────────────────────┘ ``` ## Backend Setup Instructions ### 1. Database Initialization ```bash # Connect to MySQL server mysql -u root -p # Execute the schema creation source backend/schema.sql # Verify tables were created USE fitness_app; SHOW TABLES; ``` ### 2. Database User Configuration ```sql -- Create dedicated database user CREATE USER 'fitness_app_user'@'localhost' IDENTIFIED BY 'your_secure_password_here'; -- Grant privileges GRANT SELECT, INSERT, UPDATE, DELETE ON fitness_app.* TO 'fitness_app_user'@'localhost'; GRANT CREATE, ALTER ON fitness_app.* TO 'fitness_app_user'@'localhost'; FLUSH PRIVILEGES; ``` ### 3. Update PHP Configuration Edit `backend/Database.php`: ```php private $db_host = 'your-db-host.com'; private $db_user = 'fitness_app_user'; private $db_pass = 'your_secure_password_here'; private $db_name = 'fitness_app'; private $db_port = 3306; ``` ### 4. Deploy PHP Files ```bash # Copy PHP files to web server cp backend/*.php /var/www/html/api/v1/ # Set permissions chmod 644 /var/www/html/api/v1/*.php chown www-data:www-data /var/www/html/api/v1/ ``` ### 5. Configure Web Server (Apache or Nginx) **Apache (.htaccess)** ```apache RewriteEngine On RewriteBase /api/v1/ RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule ^(.*)$ index.php?url=$1 [QSA,L] # Enable HTTPS only SSLEngine on SSLCertificateFile /path/to/cert.crt SSLCertificateKeyFile /path/to/key.key # ... additional SSL config ``` **Nginx** ```nginx server { listen 443 ssl http2; server_name api.fitness-app.com; ssl_certificate /path/to/cert.crt; ssl_certificate_key /path/to/key.key; ssl_protocols TLSv1.2 TLSv1.3; location /api/v1/ { try_files $uri $uri/ @rewrite; } location @rewrite { rewrite ^/api/v1/(.*)$ /api/v1/index.php?url=$1 last; } location ~ \.php$ { fastcgi_pass unix:/var/run/php-fpm.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } ``` ## Mobile Setup Instructions ### 1. Flutter Project Setup ```bash # Create Flutter project flutter create fitness_tracker # Navigate to project cd fitness_tracker # Replace pubspec.yaml cp mobile/pubspec.yaml ./ # Get dependencies flutter pub get ``` ### 2. Install Dependencies ```bash # All dependencies are specified in pubspec.yaml flutter pub get # For iOS cd ios && pod install && cd .. # For Android - ensure minimum SDK is 21 # Check android/app/build.gradle: # minSdkVersion 21 # targetSdkVersion 34 ``` ### 3. Set MapLibre Tile Server Update `mobile/workout_tracking_screen.dart`: ```dart MapLibreMap( styleString: 'https://map-saas.intaleqapp.com/styles/basic-preview/style.json', // ... ) ``` ### 4. Configure Native Permissions **iOS (ios/Runner/Info.plist)** ```xml NSLocationWhenInUseUsageDescription This app needs location access to track your workouts NSLocationAlwaysAndWhenInUseUsageDescription This app needs location access to track your workouts NSMotionUsageDescription This app needs motion data to enhance workout tracking ``` **Android (android/app/src/main/AndroidManifest.xml)** ```xml ``` ### 5. Generate API Credentials for Testing ```bash # On server, generate test credentials php -r " require 'backend/AuthenticationHandler.php'; \$creds = AuthenticationHandler::generateApiCredentials(); echo 'API Key: ' . \$creds['api_key'] . PHP_EOL; echo 'API Secret: ' . \$creds['api_secret'] . PHP_EOL; " ``` Insert into database: ```sql INSERT INTO users (uuid, username, email, password_hash, api_key, api_secret, full_name, is_active) VALUES ( UUID(), 'testuser', 'test@example.com', '$2y$12$...', -- bcrypt hash of password 'your_generated_api_key', 'your_generated_api_secret', 'Test User', TRUE ); ``` ### 6. Test API Endpoint ```bash #!/bin/bash API_KEY="your_api_key" API_SECRET="your_api_secret" TIMESTAMP=$(date +%s) ENDPOINT="https://your-api.com/api/v1/workouts" PAYLOAD='{ "workout_type": "running", "distance_meters": 5000, "duration_seconds": 1800, "elevation_gain_meters": 150, "elevation_loss_meters": 100, "calories_burned": 350, "max_speed_mps": 4.5, "route_polyline": "abc123def456", "start_time": "2026-04-21T10:00:00Z", "end_time": "2026-04-21T10:30:00Z", "weather_condition": "sunny", "temperature_celsius": 22.5, "notes": "Great run!", "is_public": false }' MESSAGE="${TIMESTAMP}|${API_KEY}|${PAYLOAD}" SIGNATURE=$(echo -n "$MESSAGE" | openssl dgst -sha256 -hmac "$API_SECRET" | awk '{print $NF}') curl -X POST "$ENDPOINT" \ -H "Content-Type: application/json" \ -H "X-API-Key: $API_KEY" \ -H "X-Signature: $SIGNATURE" \ -H "X-Timestamp: $TIMESTAMP" \ -d "$PAYLOAD" ``` ## Security Checklist - [ ] HTTPS/TLS 1.2+ enforced on all endpoints - [ ] HMAC-SHA256 signatures verified on every request - [ ] Timestamp validation (5-minute window) prevents replay attacks - [ ] Passwords hashed with bcrypt (cost=12) - [ ] API secrets stored securely (never logged) - [ ] Database credentials not in version control - [ ] Flutter app uses flutter_secure_storage for credentials - [ ] Rate limiting implemented per API key - [ ] SQL injection prevented via prepared statements - [ ] CORS properly configured for cross-origin requests - [ ] Input validation on all endpoints - [ ] Error messages don't leak sensitive information - [ ] Regular security audits scheduled - [ ] Audit logs maintained in api_logs table - [ ] API keys rotated periodically ## Performance Optimization ### Database Indexes All critical queries have indexes: - `users(api_key)` - API authentication - `workouts(user_id, created_at)` - User workout history - `api_logs(user_id, created_at)` - Audit logging ### Caching Strategy - User stats cached in `user_stats_cache` table - Cache invalidated on new workout submission - Consider Redis for high-traffic scenarios ### Mobile Optimization - GPS coordinates batched before SQLite insertion - Polyline encoding reduces payload size by ~75% - Map updates throttled to prevent UI jank - Background location updates configurable ## Monitoring & Analytics ### Key Metrics to Track 1. **API Performance** - Average response time per endpoint - 95th percentile latency - Request volume and patterns 2. **User Activity** - Active users (DAU/MAU) - Workouts submitted per day - Average workout distance/duration 3. **System Health** - Database connection pool status - Server CPU/memory usage - Error rate and types ### Logging - All API requests logged in `api_logs` table - Failed authentication attempts tracked - Unusual access patterns monitored ## Deployment Checklist ### Pre-Deployment - [ ] All tests passing - [ ] Code review completed - [ ] Security scan completed - [ ] Performance tested under load - [ ] Backup strategy in place - [ ] Rollback plan documented ### Deployment - [ ] Database migrations executed - [ ] PHP files deployed and tested - [ ] SSL certificates valid - [ ] API credentials generated - [ ] Monitoring configured - [ ] Alerts set up ### Post-Deployment - [ ] Smoke tests passed - [ ] API response times acceptable - [ ] Database queries optimized - [ ] Logs reviewed for errors - [ ] Metrics collected and analyzed ## Troubleshooting ### Common Issues **Invalid Signature Error** - Verify API key and secret are correct - Check timestamp is within 5 minutes - Ensure payload JSON is not modified after signing - Verify HMAC algorithm is SHA256 **Database Connection Error** - Check MySQL server is running - Verify credentials in Database.php - Ensure firewall allows connection - Check max_connections limit **Location Tracking Not Working** - Verify location permissions on device - Check GPS is enabled - Ensure app has foreground/background permission - Check location_service package initialization **Map Not Displaying** - Verify MapLibre tile server is accessible - Check API key for tile server - Ensure device has internet connection - Verify style JSON URL is correct ## Scaling Considerations For production deployments with 100k+ users: 1. **Database** - Implement read replicas for analytics queries - Archive old workout data to separate table - Implement partitioning by user_id 2. **API Server** - Deploy multiple PHP instances behind load balancer - Implement API gateway with rate limiting - Use CDN for static assets 3. **Caching** - Implement Redis for session/stats caching - Cache user stats for 1 hour - Cache API responses for 5 minutes 4. **Background Jobs** - Use queue system for async processing - Recalculate user stats in background - Generate reports/analytics offline ## Support & Maintenance ### Regular Maintenance Tasks - Monitor API logs for errors - Review security audit logs - Update dependencies monthly - Performance tuning as needed - Database optimization (ANALYZE/OPTIMIZE) - Backup verification ### Contact For issues or questions, contact: support@fitness-app.com