trackslash
VAULT-59 P2

App lock password: lock screen entry and Settings screens

0
Sub-issue of VAULT-22 P2 Add an optional password to the app lock

Description

The UI part of VAULT-22, built against a small password service protocol. The storage side implements it: VAULT-46 unlock, VAULT-47 turn on, and VAULT-48 change, turn off and turn back on. Until those land, a fake implementation backs previews, tests and snapshots. The real one is wired in when VAULT-47/48 merge.

What to build:

  • Password entry on the lock screen, after device authentication, from VAULT-21's lock screen.
    • Wrong, real and duress passwords must look and feel identical: same animation, haptics and timing, driven by the service's fixed deadline (C2).
    • Show the escalating delay from the attempt-counter sub-issue.
  • The app lock password screen in Settings, reached from the Security section. It covers:
    • set the password, which says plainly that a forgotten password means erasing the vault and restoring a backup
    • change it, which needs the current password
    • turn it off, which needs the current password
  • Naming: make it clearly a different password from the backup password.
  • Leave space for the duress action. VAULT-23's "make duress database" action will live on this screen, so design with room for one more action. Don't build it here.

The protocol:

  • Define it in this PR and keep it minimal.
  • The crypto agent's VAULT-46/47/48 conform to it, so describe it in the PR for them.

Tests:

  • View model unit tests against the fake service.
  • Snapshot tests of the password entry and of the setup, change and turn-off screens, in light and dark mode.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Done in https://github.com/badbundle/vault-app/pull/643 (merged as d0f7e169).

Lock screen:

  • After Face ID, Touch ID or the passcode, and only if a password is set, a secure App Lock Password field appears. It uses .secretTextInput(.verbatim) and has a VoiceOver label.
  • A wrong password shakes the field, or fades it with Reduce Motion, and plays the error haptic.
  • During a delay, the field is disabled and shows "Try again in N minutes". It never shows an attempt count.
  • Real and duress passwords get identical feedback (C2).

Settings:

  • An App Lock Password row appears under App Lock, only while App Lock is on. It opens a sheet to set, change or turn off the password.
  • Setting it needs device authentication first. It then warns that a forgotten password can't be reset, even with Face ID or the passcode (C4), and that the way out is erasing the vault and restoring a backup. It shows the last backup date.
  • Rules: at least 8 characters, not only numbers, plus a confirmation. The screen explains why: the file can be guessed offline.
  • Changing or turning off the password needs the current one, and wrong attempts count toward the delay.
  • The App Lock toggle is disabled while a password is set.
  • There's room for one more action, VAULT-23's.

Protocol: AppLockPasswordService (@MainActor, in VaultFeed), with FakeAppLockPasswordService for previews and tests. VAULT-46's unlock service maps onto it one to one.

Gating: VaultRoot passes passwordService: nil, so none of this is reachable in a release until the storage side is wired in after VAULT-47/48.

Shared change: the lock screen's overlay window now becomes key while the password field shows, so the keyboard appears straight away.

Tests:

  • View model and service tests against the fake.
  • Light and dark snapshots of password entry (normal, wrong, delayed), setup, change and turn off.
  • The full flow was driven in the simulator against the fake.