trackslash
VAULT-20 P2

Add a header to the Restore page and lock it behind device authentication

0
All issues

Description

Two changes to the Restore page (BackupRestoreView):

  1. Header: add a BackupHeroHeader at the top, like the one on Export. It should say what restoring does: it imports from a PDF backup or another device, and needs the password that backup was made with.
  2. Lock: require device authentication before any restore option appears. Below the header, show the same "Locked" and "Authentication Failed" sections as Export and Auto-Backup.

Current behavior:

  • The page shows the import buttons straight away.
  • Tapping one calls loadBackupPassword(), which only asks you to authenticate when a backup password exists.
  • So with no password set, "Import & Override", which replaces the whole vault, needs no authentication at all.

What to change:

  • Gate the page on DeviceAuthenticationService.validateAuthentication, the way the Backup Password sheet does (BackupKeyChangeViewModel), rather than on loading the backup password. That way the page is locked whether or not a password is set.
  • Keep loading the backup password when an import starts, as now.
  • Decide whether the page locks again each time you leave it, as the Backup Password sheet does.
  • Follow MANIFESTO.md C4: device authentication guards against someone using an unattended device, and against nothing else.

Add snapshot tests for the locked, failed and unlocked states, with an empty and a non-empty vault.

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/vault-app/pull/621 (merged as 0d893203).

  • Header: the Restore page now opens with a header in the style of Export ("Restore Your Vault"), and the navigation title is inline.
  • Lock: the page stays locked behind device authentication until the user authenticates, whether or not a backup password is set, so Import & Override can't run unauthenticated. It uses the same Locked / Authentication Failed sections as Export and Auto-Backup.
  • When it locks again: on leaving the page or backgrounding the app. Opening the import sheet doesn't count as leaving.
  • No passcode: a device without a passcode can't unlock the page, which is consistent with Export, Backup Password and Danger Zone.