Fixed in https://github.com/badbundle/vault-app/pull/615 (merged as 55a041f6).
The setting: App Lock sits in a new Security section in Settings. It's off by default, stored in App Group defaults so the extensions can read it, and turning it on or off needs authentication. If the device has no passcode, the toggle is disabled with an explanation.
Locking:
- With the lock on, the app starts locked and locks on background. Nothing of the vault is built while it's locked.
- Locking purges sensitive data and clears the search.
- Deep links wait until you unlock.
- Going inactive only shows a privacy cover, drawn in its own window above sheets and driven by UIKit scene notifications, so the app-switcher snapshot never catches the vault.
Lock screen: the vault door. Face ID is asked for automatically, with an Unlock button after a cancel or failure. A stale authentication result can't unlock a newer lock.
Extensions:
- Widgets show "Vault Locked" and never read the vault.
- AutoFill asks for Face ID before listing codes. QuickType requests need user interaction.
Also changed:
- App-wide, "Enter Password" in a Face ID prompt now falls back to the passcode.
- Locking resets navigation; VAULT-33 adds a delay.
Structure: AppLockService in VaultFeed is a step-based unlock state machine, ready for VAULT-22's password step.
Tests: 37 service tests, plus settings, widget and AutoFill tests, and snapshots of every lock state in light and dark.