trackslash
VAULT-21 P2

Add an app lock that asks for device authentication

0
All issues

Description

Add a Settings option that locks the whole app behind device authentication (Face ID, Touch ID or passcode). It's off by default, for new installs and for existing users when they update.

When it's on:

  • Launching the app, or coming back to it after it leaves the foreground, shows a lock screen until you authenticate.
  • As soon as the app becomes inactive, a privacy cover hides the whole vault, so the app switcher never shows codes, notes or item details.
  • Turning the lock off requires authenticating first.

Today:

  • There's no app-level lock.
  • When the app goes inactive, only the codes on feed cards are hidden (scenePhaseDidChange → obfuscateForPrivacy()). Note previews, detail pages and everything else stay visible in the app switcher.
  • When the app goes to the background, VaultMainNavigationView calls purgeSensitiveData().
  • The per-item locks (VaultItemLockState) stay as they are.

To decide:

  • When to lock: the lock applies on .background. Decide whether .inactive alone (Control Center, the notification pull-down) should also lock. The privacy cover should appear either way.
  • Widgets and AutoFill: both show codes outside the app. Decide whether the lock applies to them, and if it doesn't, say so in the setting's footer.

Tests:

  • View model tests for the lock transitions: launch, background, foreground, and authentication failing or being cancelled.
  • Snapshot tests of the lock screen and the setting, in light and dark mode.

VAULT-22 adds an optional password on top of this.

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/vault-app/pull/615 (merged as 55a041f6).

The setting: App Lock sits in a new Security section in Settings. It's off by default, stored in App Group defaults so the extensions can read it, and turning it on or off needs authentication. If the device has no passcode, the toggle is disabled with an explanation.

Locking:

  • With the lock on, the app starts locked and locks on background. Nothing of the vault is built while it's locked.
  • Locking purges sensitive data and clears the search.
  • Deep links wait until you unlock.
  • Going inactive only shows a privacy cover, drawn in its own window above sheets and driven by UIKit scene notifications, so the app-switcher snapshot never catches the vault.

Lock screen: the vault door. Face ID is asked for automatically, with an Unlock button after a cancel or failure. A stale authentication result can't unlock a newer lock.

Extensions:

  • Widgets show "Vault Locked" and never read the vault.
  • AutoFill asks for Face ID before listing codes. QuickType requests need user interaction.

Also changed:

  • App-wide, "Enter Password" in a Face ID prompt now falls back to the passcode.
  • Locking resets navigation; VAULT-33 adds a delay.

Structure: AppLockService in VaultFeed is a step-based unlock state machine, ready for VAULT-22's password step.

Tests: 37 service tests, plus settings, widget and AutoFill tests, and snapshots of every lock state in light and dark.