This document reflects the current single-module implementation (version 0.1.0). It will evolve; it is not a frozen API contract.
LDAPADvisor Android is a native Kotlin app with:
- Jetpack Compose + Material 3 UI
- Manual DI via
AppContainer - Room + DataStore persistence
- UnboundID LDAP engine
- MiniDNS AD discovery
- DiagnosticEngine + AdvisorEngine + report export
- Android Keystore–backed
SecretStore
- Single-activity Compose application (
MainActivity) - MVVM with
StateFlowUI state - Repositories for profiles, settings, history
- Specialized services for LDAP, DNS, TLS, diagnostics, reports
- Kotlin coroutines /
Dispatchers.IOfor network and directory I/O - Clear separation:
feature(UI) →domain→data/core - No LDAP/AD data sent to third-party analytics backends
UI (Compose screens / ViewModels)
↓
Domain models + AdvisorEngine
↓
Repositories / SessionManager
↓
LdapClientFactory, DnsResolver, DiagnosticEngine, ReportGenerator, SecretStore, Room, DataStore
| Package | Role |
|---|---|
app |
LdapAdvisorApp, AppContainer |
feature.* |
Screens + ViewModels (dashboard, profiles, directory, search, users/groups/computers, diagnostics, advisor, reports, settings, connection) |
domain.model / domain.service |
Domain types, advisor rules |
data.ldap |
UnboundID client, session, errors |
data.dns |
MiniDNS resolver + AD discovery |
data.tls |
Trust modes, SSL factories, TLS diagnostics |
data.diagnostics |
DiagnosticEngine and probes |
data.report |
Sanitizer + generators |
data.database / data.datastore / data.repository |
Persistence |
core.security |
SecretStore, SecureWindow |
core.ad |
AD attribute helpers |
core.logging / core.util |
Sanitized logging, escaping, fingerprints |
ui.theme / ui.components |
Material theme and shared widgets |
- Multi-module over-engineering before need
- Cloud backends / telemetry
- Optional Kerberos client stacks beyond the embedded Kerby path already shipped
Credentials and directory content are treated as sensitive. Logging and exports sanitize by default. Backup and device-transfer extraction are denied. See security.md and PRIVACY.md.