Done in https://github.com/badbundle/vault-app/pull/654.
Access mode: a single VaultAccessMode (plain, deviceKey, password, unavailable) decides what every surface may do. Any mid-change state (encrypting, erasing, turning off or on) is unavailable.
With the password turned off (device-key mode):
- Widgets:
- They open the file with the device key afresh for every read. These show-only opens don't lock, stamp or write.
- The small widget's HOTP tap opens the app. Incrementing inside the widget would run out of memory on a device.
- AutoFill:
- It asks for device authentication only, never a password, and opens with the device key only after authentication.
- It checks the mode before and after opening. A new
VaultAccessGuardre-checks the mode on every read and write of a vault an extension opened, so an open sheet can't keep showing codes after the password is turned on, or after an erase. - Leaving the sheet locks the vault. Coming back re-checks.
- QuickType:
- Refilled when the password is turned off, and emptied when it's turned on. Both steps are journaled (
syncingSystemSurfaces/clearingSystemSurfaces) and finished at launch after a crash. - It's skipped when Vault isn't an AutoFill provider. Widgets reload either way.
- Refilled when the password is turned off, and emptied when it's turned on. Both steps are journaled (
Also: the attempt counter's flock retries with LOCK_NB up to a timeout. Plain-mode AutoFill also locks immediately now (C7).
Documented: the design doc's device-key column, and residual limit 11: widget memory with a 16 MiB+ file, HOTP increments sent to the app, and AutoFill's stricter memory check.
Tests:
- The full mode × transition table.
- Mode flips between prepares, between authentication and display, during the open, and as a save starts.
- Widget
.unavailable, show-only opens leaving nothing behind, and QuickType locking after a read.
Review: a security review found one blocker (an open AutoFill sheet ignored the password being turned on or an erase, and opened with the device key before authentication) and two should-fixes. All were fixed and re-reviewed.