Part of VAULT-77. This is BackupKeyDecryptorView, which the import sheet shows when a backup needs its password.
Now
- There's a
PlaceholderView card with a black shield, left-aligned, the title "Encrypted" and a four-line explanation.
- Under it are the Backup Password field and a Decrypt button.
- The field isn't focused when the screen opens, and Return doesn't decrypt.
- While decrypting, the only change is that the button and Cancel turn grey and interactive dismissal is off. Nothing shows progress, and there's no way out. Recreating the key uses the same key derivation that
BackupKeyChangeView says "can take up to 3 minutes".
- A wrong password turns the whole card's text red, with no haptic and no motion.
- Success dismisses the sheet straight away.
Change
- Header: use a
BackupHeroHeader with lock.shield.fill in the accent colour. Since VAULT-71, the shield marks the backup password, as it does on the screen that sets it. Use a short title, such as "Enter Backup Password", and a one-line subtitle, such as "Use the password this backup was made with." Don't let the header change state: the status goes in the footer.
- Field: focus it when the screen appears, and make Return decrypt, as
BackupKeyChangeView does with @FocusState and .onSubmit.
- Progress: while decrypting, show a
ProgressView and a line such as "Decrypting. This can take up to 3 minutes." in the footer, like setPasswordStatus's .creating case. Measure how long recreateEncryptionKey takes on a device and word the line to match.
- Cancel: keep Cancel enabled while decrypting, as
BackupKeyChangeView deliberately does as the escape hatch from the same derivation. Cancel the task. Check whether the key deriver can actually stop part way through; if it can't, make sure a late result is dropped.
- Wrong password: use
wrongPasswordFeedback(trigger:) on the field (a shake and an error haptic; a fade with Reduce Motion). Give the field the .error() status, and put a red footer label with the error's title, like "Passwords do not match". Post an accessibility announcement, as EncryptedItemDetailView does.
- Success: swap the shield for
lock.open.fill (a symbol replace effect) and play a success haptic, then dismiss. Keep any pause short, and have none with Reduce Motion.
- Make the title inline, as on the other screens.
Done when
- The screen matches the backup password screen: the header, the focused field, the progress line, and footer errors.
- A wrong password shakes the field and buzzes. A right one shows the lock opening.
- You can cancel while decrypting.
BackupKeyDecryptorViewSnapshotTests covers the idle, decrypting and wrong-password states. Replace the lone layoutDecryptFailure.1.png with the standard size and appearance matrix, and re-record.