15 KiB
15 KiB
Fitness Tracking App - Production Deployment Guide
Architecture Overview
┌─────────────────────────────────────────────────────────────┐
│ Flutter Mobile App │
│ ┌─────────────────────────────────────────────────────────┐ │
│ │ GetX Controller (State Management) │ │
│ │ - WorkoutController: Orchestrates tracking logic │ │
│ │ - LocationService: SQLite background storage │ │
│ └─────────────────────────────────────────────────────────┘ │
│ │ │
│ ┌─────────────────────────┴──────────────────────────────┐ │
│ │ Views & UI Components │ │
│ │ - WorkoutTrackingScreen: MapLibre map + stats │ │
│ │ - Real-time GPS overlay on MapLibre │ │
│ │ - Polyline encoding for route submission │ │
│ └─────────────────────────────────────────────────────────┘ │
│ │ │
│ ┌─────────────────┴──────────────────┐ │
│ │ HMAC-SHA256 Signature Generator │ │
│ └─────────────────┬──────────────────┘ │
│ ▼ │
└───────────────────────────────────────────────────────────────┘
│ HTTPS
│ HMAC-SHA256 Authenticated
▼
┌───────────────────────────────────────────────────────────────┐
│ PHP Backend (REST API) │
│ ┌─────────────────────────────────────────────────────────┐ │
│ │ Authentication Layer │ │
│ │ - HMAC-SHA256 Signature Verification │ │
│ │ - Timestamp Validation (Replay Attack Prevention) │ │
│ │ - Rate Limiting & API Key Management │ │
│ └─────────────────────────────────────────────────────────┘ │
│ │ │
│ ┌─────────────────────────┴──────────────────────────────┐ │
│ │ /api/v1/workouts (POST) │ │
│ │ - WorkoutValidator: Validates payload structure │ │
│ │ - PolylineUtility: Decodes & validates routes │ │
│ │ - Database: Stores workouts & coordinates │ │
│ └─────────────────────────────────────────────────────────┘ │
└───────────────────────────────────────────────────────────────┘
│
▼
┌───────────────────────────────────────────────────────────────┐
│ MySQL Database │
│ ┌──────────────┐ ┌─────────────┐ ┌──────────────────┐ │
│ │ users │ │ workouts │ │ api_logs │ │
│ │ - id │ │ - id │ │ - user_id │ │
│ │ - api_key │ │ - distance │ │ - endpoint │ │
│ │ - api_secret│ │ - polyline │ │ - status_code │ │
│ └──────────────┘ │ - duration │ └──────────────────┘ │
│ │ - calories │ │
│ │ - metadata │ │
│ └─────────────┘ │
└───────────────────────────────────────────────────────────────┘
Backend Setup Instructions
1. Database Initialization
# Connect to MySQL server
mysql -u root -p
# Execute the schema creation
source backend/schema.sql
# Verify tables were created
USE fitness_app;
SHOW TABLES;
2. Database User Configuration
-- Create dedicated database user
CREATE USER 'fitness_app_user'@'localhost' IDENTIFIED BY 'your_secure_password_here';
-- Grant privileges
GRANT SELECT, INSERT, UPDATE, DELETE ON fitness_app.* TO 'fitness_app_user'@'localhost';
GRANT CREATE, ALTER ON fitness_app.* TO 'fitness_app_user'@'localhost';
FLUSH PRIVILEGES;
3. Update PHP Configuration
Edit backend/Database.php:
private $db_host = 'your-db-host.com';
private $db_user = 'fitness_app_user';
private $db_pass = 'your_secure_password_here';
private $db_name = 'fitness_app';
private $db_port = 3306;
4. Deploy PHP Files
# Copy PHP files to web server
cp backend/*.php /var/www/html/api/v1/
# Set permissions
chmod 644 /var/www/html/api/v1/*.php
chown www-data:www-data /var/www/html/api/v1/
5. Configure Web Server (Apache or Nginx)
Apache (.htaccess)
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /api/v1/
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^(.*)$ index.php?url=$1 [QSA,L]
</IfModule>
# Enable HTTPS only
<VirtualHost *:443>
SSLEngine on
SSLCertificateFile /path/to/cert.crt
SSLCertificateKeyFile /path/to/key.key
# ... additional SSL config
</VirtualHost>
Nginx
server {
listen 443 ssl http2;
server_name api.fitness-app.com;
ssl_certificate /path/to/cert.crt;
ssl_certificate_key /path/to/key.key;
ssl_protocols TLSv1.2 TLSv1.3;
location /api/v1/ {
try_files $uri $uri/ @rewrite;
}
location @rewrite {
rewrite ^/api/v1/(.*)$ /api/v1/index.php?url=$1 last;
}
location ~ \.php$ {
fastcgi_pass unix:/var/run/php-fpm.sock;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
}
}
Mobile Setup Instructions
1. Flutter Project Setup
# Create Flutter project
flutter create fitness_tracker
# Navigate to project
cd fitness_tracker
# Replace pubspec.yaml
cp mobile/pubspec.yaml ./
# Get dependencies
flutter pub get
2. Install Dependencies
# All dependencies are specified in pubspec.yaml
flutter pub get
# For iOS
cd ios && pod install && cd ..
# For Android - ensure minimum SDK is 21
# Check android/app/build.gradle:
# minSdkVersion 21
# targetSdkVersion 34
3. Set MapLibre Tile Server
Update mobile/workout_tracking_screen.dart:
MapLibreMap(
styleString: 'https://map-saas.intaleqapp.com/styles/basic-preview/style.json',
// ...
)
4. Configure Native Permissions
iOS (ios/Runner/Info.plist)
<key>NSLocationWhenInUseUsageDescription</key>
<string>This app needs location access to track your workouts</string>
<key>NSLocationAlwaysAndWhenInUseUsageDescription</key>
<string>This app needs location access to track your workouts</string>
<key>NSMotionUsageDescription</key>
<string>This app needs motion data to enhance workout tracking</string>
Android (android/app/src/main/AndroidManifest.xml)
<uses-permission android:name="android.permission.ACCESS_FINE_LOCATION" />
<uses-permission android:name="android.permission.ACCESS_COARSE_LOCATION" />
<uses-permission android:name="android.permission.ACCESS_BACKGROUND_LOCATION" />
<uses-permission android:name="android.permission.INTERNET" />
<service
android:name=".LocationService"
android:foregroundServiceType="location"
android:enabled="true"
android:exported="true" />
5. Generate API Credentials for Testing
# On server, generate test credentials
php -r "
require 'backend/AuthenticationHandler.php';
\$creds = AuthenticationHandler::generateApiCredentials();
echo 'API Key: ' . \$creds['api_key'] . PHP_EOL;
echo 'API Secret: ' . \$creds['api_secret'] . PHP_EOL;
"
Insert into database:
INSERT INTO users (uuid, username, email, password_hash, api_key, api_secret, full_name, is_active)
VALUES (
UUID(),
'testuser',
'test@example.com',
'$2y$12$...', -- bcrypt hash of password
'your_generated_api_key',
'your_generated_api_secret',
'Test User',
TRUE
);
6. Test API Endpoint
#!/bin/bash
API_KEY="your_api_key"
API_SECRET="your_api_secret"
TIMESTAMP=$(date +%s)
ENDPOINT="https://your-api.com/api/v1/workouts"
PAYLOAD='{
"workout_type": "running",
"distance_meters": 5000,
"duration_seconds": 1800,
"elevation_gain_meters": 150,
"elevation_loss_meters": 100,
"calories_burned": 350,
"max_speed_mps": 4.5,
"route_polyline": "abc123def456",
"start_time": "2026-04-21T10:00:00Z",
"end_time": "2026-04-21T10:30:00Z",
"weather_condition": "sunny",
"temperature_celsius": 22.5,
"notes": "Great run!",
"is_public": false
}'
MESSAGE="${TIMESTAMP}|${API_KEY}|${PAYLOAD}"
SIGNATURE=$(echo -n "$MESSAGE" | openssl dgst -sha256 -hmac "$API_SECRET" | awk '{print $NF}')
curl -X POST "$ENDPOINT" \
-H "Content-Type: application/json" \
-H "X-API-Key: $API_KEY" \
-H "X-Signature: $SIGNATURE" \
-H "X-Timestamp: $TIMESTAMP" \
-d "$PAYLOAD"
Security Checklist
- HTTPS/TLS 1.2+ enforced on all endpoints
- HMAC-SHA256 signatures verified on every request
- Timestamp validation (5-minute window) prevents replay attacks
- Passwords hashed with bcrypt (cost=12)
- API secrets stored securely (never logged)
- Database credentials not in version control
- Flutter app uses flutter_secure_storage for credentials
- Rate limiting implemented per API key
- SQL injection prevented via prepared statements
- CORS properly configured for cross-origin requests
- Input validation on all endpoints
- Error messages don't leak sensitive information
- Regular security audits scheduled
- Audit logs maintained in api_logs table
- API keys rotated periodically
Performance Optimization
Database Indexes
All critical queries have indexes:
users(api_key)- API authenticationworkouts(user_id, created_at)- User workout historyapi_logs(user_id, created_at)- Audit logging
Caching Strategy
- User stats cached in
user_stats_cachetable - Cache invalidated on new workout submission
- Consider Redis for high-traffic scenarios
Mobile Optimization
- GPS coordinates batched before SQLite insertion
- Polyline encoding reduces payload size by ~75%
- Map updates throttled to prevent UI jank
- Background location updates configurable
Monitoring & Analytics
Key Metrics to Track
-
API Performance
- Average response time per endpoint
- 95th percentile latency
- Request volume and patterns
-
User Activity
- Active users (DAU/MAU)
- Workouts submitted per day
- Average workout distance/duration
-
System Health
- Database connection pool status
- Server CPU/memory usage
- Error rate and types
Logging
- All API requests logged in
api_logstable - Failed authentication attempts tracked
- Unusual access patterns monitored
Deployment Checklist
Pre-Deployment
- All tests passing
- Code review completed
- Security scan completed
- Performance tested under load
- Backup strategy in place
- Rollback plan documented
Deployment
- Database migrations executed
- PHP files deployed and tested
- SSL certificates valid
- API credentials generated
- Monitoring configured
- Alerts set up
Post-Deployment
- Smoke tests passed
- API response times acceptable
- Database queries optimized
- Logs reviewed for errors
- Metrics collected and analyzed
Troubleshooting
Common Issues
Invalid Signature Error
- Verify API key and secret are correct
- Check timestamp is within 5 minutes
- Ensure payload JSON is not modified after signing
- Verify HMAC algorithm is SHA256
Database Connection Error
- Check MySQL server is running
- Verify credentials in Database.php
- Ensure firewall allows connection
- Check max_connections limit
Location Tracking Not Working
- Verify location permissions on device
- Check GPS is enabled
- Ensure app has foreground/background permission
- Check location_service package initialization
Map Not Displaying
- Verify MapLibre tile server is accessible
- Check API key for tile server
- Ensure device has internet connection
- Verify style JSON URL is correct
Scaling Considerations
For production deployments with 100k+ users:
-
Database
- Implement read replicas for analytics queries
- Archive old workout data to separate table
- Implement partitioning by user_id
-
API Server
- Deploy multiple PHP instances behind load balancer
- Implement API gateway with rate limiting
- Use CDN for static assets
-
Caching
- Implement Redis for session/stats caching
- Cache user stats for 1 hour
- Cache API responses for 5 minutes
-
Background Jobs
- Use queue system for async processing
- Recalculate user stats in background
- Generate reports/analytics offline
Support & Maintenance
Regular Maintenance Tasks
- Monitor API logs for errors
- Review security audit logs
- Update dependencies monthly
- Performance tuning as needed
- Database optimization (ANALYZE/OPTIMIZE)
- Backup verification
Contact
For issues or questions, contact: support@fitness-app.com