This repository is the Android implementation surface for Shut Up and Serve (SUAS). It is one of three implementation repositories. If you cloned only this repo, start here so you do not treat the tree as a standalone product.
SUAS coordinates consented veteran support. Canonical product rules live in SUAS-specs, not in this scaffold.
- Name the sibling surfaces: suas (web and API), suas-ios (iOS), and SUAS-specs (canonical contract).
- Treat this app as a native client of the product API. Call
/api/v0only. - Read AGENTS.md before you change code.
- Open MOBILE_SURFACE.md in SUAS-specs (decision D-033) before you change networking.
| Surface | Repository | Role |
|---|---|---|
| Web and API | scrimshawlife-ctrl/suas | Product API, OpenAPI, and web /app HTML. |
| iOS | scrimshawlife-ctrl/suas-ios | Private Swift client over /api/v0. |
| Android | scrimshawlife-ctrl/suas-android | This repo. Kotlin Compose launcher plus Retrofit /api/v0 client. |
| Specs | scrimshawlife-ctrl/SUAS-specs | Canonical released contract. Native clients follow MOBILE_SURFACE.md. |
Keep all three implementation repositories (suas, suas-ios, and suas-android) in future considerations. Do not collapse the product into this Android tree.
The Android app is an ordinary authenticated client of the SUAS product API.
- Path prefix:
/api/v0. That prefix is the only version selector. - Contract file: docs/openapi/v0.json in suas.
- Auth: opaque, server-revocable Bearer session (
Authorization: Bearer <credential>), held in memory (SessionStore). Do not write it to disk (D-034). - Sign-in:
POST /api/v0/auth/challengesthenPOST /api/v0/auth/challenges/commands/verify. - Open a Case:
POST /api/v0/caseswithIdempotency-Key. NeverPOST /app/qrf/deploy. - Do not add
/api/mobile, a client-type header,/api/v0/dev/*, or a second version selector. - Do not drive HTML
/app/*form commands from Android. Those routes belong to the web surface in suas. - Do not introduce a mobile test harness in this repository.
Default Retrofit host is staging https://suasqrf.com (Backend.STAGING_BASE). Emulator LOCAL is http://10.0.2.2:3000. Clients may still send build-pinned Backend.SYNTHETIC_TENANT_ID; the Worker resolves enrolled email → tenant and treats tenant_id as optional. The person must not pick an organization.
Synthetic staging is https://suasqrf.com. Use it only for non-production builds. Staging must not use real veteran data or real external support effects.
This tree is a Kotlin Jetpack Compose client. It is a fork of RuntimeSquad/Suas. Observed today:
- Launcher activity is
RootActivity(email sign-in, then ride / food / shelter / peer support). com.example.suas.apiholds RetrofitSuasApi,SessionStore(memory only), and submit helpers for transportation, food, shelter, and peer support after a signed-in Case open.- Package and application ID remain
com.example.suas. That identifier is a placeholder. Specs do not name a production application ID, so this tree does not invent one. - All four MVP categories are on the launcher home cards.
MainActivityis a debug-only test harness. It is not in the release manifest and it is not exported. The product launcher isRootActivity.- Chat and dashboard-style totals stay unavailable / not computable. Do not print “dispatched now” or lives-saved numbers.
- JVM tests cover the API contract baseline. Instrumented Compose tests still exercise the dummy home.
MVP request categories are FOOD, TRANSPORTATION, temporary SHELTER, and PEER_SUPPORT. Do not add medical or VA-treatment claims in the Android UI.
Do not treat on-screen copy as released crisis copy. D-012 approved wording lives in SUAS-specs.
| Item | Status | What it means here |
|---|---|---|
| D-033 | Decided. Native client surface released in MOBILE_SURFACE.md. |
You may implement an Android client of /api/v0. |
| D-034 | Pending. On-device protection of veteran data. | Persist no veteran domain data locally until this decision closes. Hold the bearer in memory only. |
| SPEC-018 | Blocked. Pilot and production go/no-go. | Do not ship to real veterans, claim a live pilot, or submit to an application store. |
| Production | NOT_READY |
Implementation authority is not production authority. |
Device push, social login, contact-list access, continuous location, and long-lived unrevocable credentials remain forbidden on a native client.
- Never commit secrets, session credentials,
.envfiles, provider keys, or real contact details. - Do not claim HIPAA, SOC 2, ISO, or any other compliance certification from this repository or the app UI.
- Do not put provider credentials in the application bundle.
You need Android Studio (or the Android SDK) with JDK 11 or later.
./gradlew :app:testOpen the project in Android Studio and run the app configuration (RootActivity) on an emulator or device. Point builds at staging or a local Worker; do not invent a production host.
SUAS is not an EHR, a diagnosis system, a suicide-prediction product, or an automated emergency dispatcher. The client must not auto-dial 911 or 988. Present crisis destinations only after an explicit person-initiated action, using released copy from SUAS-specs.