1. Bootstrap and identity boundary
main.dart initializes Firebase and opens LoginPage. Email sign-in, sign-up and password reset call Firebase Auth directly; Google exchanges provider credentials for a Firebase session. Success uses pushReplacement to enter MainPage, removing authentication from the back stack.
2. Shell and navigation boundary
MainPage owns the selected tab and transition AnimationController. BottomBarView changes four tabs through a callback, while its raised center action pushes the 3D MapView as a separate route. Adding screens requires coordinated tab state, controller disposal and route-state decisions.
3. Wellness presentation composition
My Diary and training/account compose meal, water-wave, exercise, body and identity widgets. Each receives an interval from a parent animation controller for staggered entry. Values are built around local models and sample presentation; a synchronized persistence repository is not confirmed.
4. 3D model path
MapView uses flutter_3d_controller to choose B2, B1 and 1F–4F GLB floors, route FBX files and animations. Floor controls change bundled asset paths, while the renderer exposes orbit, camera, texture and playback operations. The heavy 3D state stays outside the regular tab shell.
Firebase configuration differs across Android, iOS and web, while 3D behavior depends on platform GPU, WebGL and asset loading. Facebook currently reports provider success without completing the commented Firebase credential exchange. A web options file exists, but public web delivery and provider compatibility still require separate validation.
6. State and asset ownership
Firebase owns the identity session, main_page and bottom navigation own the current tab, and Map.dart owns floor selection and the 3D controller. GLB and FBX files are bundled assets, so server refresh and version negotiation are missing.
Model weight and GPU/WebGL capability determine startup and memory cost. Floor-level lazy loading, controller disposal, low-end fallback imagery and asset-decode error states require validation. FPS and memory have not been measured.
8. Security, observability and debt
Every identity provider must complete the Firebase credential exchange to share one security contract. Crash and asset-latency observability are missing. Platform branches and login logic should move into dedicated service boundaries.