Done in https://github.com/badbundle/vault-app/pull/646.
While the vault is encrypted (any non-plain mode):
- Widgets:
- They show the locked placeholder.
- The configuration list is empty, and HOTP can't be advanced.
- The app ignores widget HOTP links.
- Timelines reload when the password is set.
- The setup screen says to remove existing widgets, and that AutoFill will ask for the password.
- QuickType:
- Every write goes through a mode check, and a full sync empties the store.
- Requests return
userInteractionRequiredwithout reading the vault. - Clearing is journaled and retried. Every non-plain launch empties the store again.
- AutoFill:
- Mode: it's read fresh on every request. The vault is locked and purged before any UI shows. Anything but a settled password mode (encrypting, erasing, turning off or on, device-key mode until VAULT-50) shows "Open Vault".
- Unlocking: the sheet asks for device authentication, then the App Lock Password, through the same unlock service and shared attempt counter. It's never Face ID alone.
- Memory: it's checked before each attempt is counted and before each save. If it's short, the user is sent to Vault.
- Locking: the vault locks before the sheet completes or cancels, and when it disappears. The extension's lock delay is always immediate.
- The state file: the extension only reads the deadline, and never writes it.
Also: the attempt counter now holds an App Group flock around its read-modify-write, so the app and AutoFill can't lose counts.
Tests:
- Unit tests for the QuickType gate, the adapter, widget loading, provider, query and HOTP, and the AutoFill view model, including a mode change mid-process.
- Light and dark snapshots of the AutoFill checking, password and "Open Vault" states, and of the widget's locked state.
Review: a security review found one blocker (AutoFill deciding the mode once per process, which could show cached codes behind Face ID alone) and five should-fixes. All were fixed and re-reviewed. The review's note about AutoFill not erasing at the threshold is handled in VAULT-34.