CertificatePinningConfig class

Configuration for optional TLS certificate pinning.

When pinningMode is 'disabled' (the default), the transport uses the platform's default trust store.

When pinningMode is 'enforce', the transport verifies the server certificate chain against certificatePins. If no pin matches, the connection is rejected with a non-retryable TLS error.

Pin format: sha256/<base64-encoded-SPKI-hash>

PCI boundary: pin values are SHA-256 hashes of public key info — not secrets. However, toString excludes them to avoid leaking the set of hosts the SDK communicates with.

Constructors

CertificatePinningConfig({String pinningMode = 'disabled', List<String> certificatePins = const [], List<String> pinnedHosts = const []})
const

Properties

certificatePins → List<String>
SHA-256 SPKI pins in sha256/<base64> format.
final
hashCode → int
The hash code for this object.
no setterinherited
isEnabled → bool
Whether enforcement is active.
no setter
pinnedHosts → List<String>
When non-empty, pins are enforced only for these hosts. When empty, pins apply to all gateway connections.
final
pinningMode → String
'disabled' or 'enforce'.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toMap() → Map<String, dynamic>
Convert to a map suitable for MethodChannel transport.
toString() → String
Intentionally excludes pin values and host names.
override

Operators

operator ==(Object other) → bool
The equality operator.
inherited