Part of VAULT-83.
Why
AppLockServiceTests (58 tests) covers the service's own rules well:
- background locks and purges; inactive doesn't lock;
- the Require Unlock delay, including the clock going backwards;
- relaunch always locks;
- stale prompt results are thrown away.
What's untested is the code that calls the service, and what a lock does to the rest of the app. AppLockServicePasswordTests runs against FakeAppLockPasswordService.
Tests to add
- Scene wiring:
AppLockContainer passes scene phase changes and didEnterBackgroundNotification to the service.
- Locked content isn't built while the app is locked.
- The overlay window shows over the app.
OverlayWindow has no tests.
- Device lock:
VaultRoot.setup() registers the protectedDataWillBecomeUnavailable observer.
- Posting that notification locks the app.
- With an App Lock Password set, it locks even inside a Require Unlock delay.
deviceWillLock() against the real EncryptedVaultPasswordService: the session is locked and VaultDataModel is purged. Reading the store afterwards needs the password again.
- What a lock clears:
purgeSensitiveDataForAppLock() runs purgeSensitiveData() synchronously, then purgeVaultContents() asynchronously. Test the two together.
- After a lock, none of these is left: decrypted encrypted-note or recovery-phrase text, open detail state, search text, items in
VaultDataModel.
- Require Unlock delay with a real password vault:
- Back within the delay: the keys stay and the app doesn't ask again.
- Back after the delay: the vault is locked and needs the password.
- Relaunch locks whatever the delay.
- AutoFill: pin what happens in two cases, and compare it with the "Widgets, AutoFill and QuickType" section of the design doc:
- the device locks while the AutoFill sheet is open;
- the sheet is dismissed and opened again.
If the behaviour doesn't match, fix it or file a follow-up (neutrally worded, per VAULT-82).
- Widgets:
OTPWidgetLoadingTests and WidgetVaultLoaderCodeActionTests already cover them. Check that nothing above changes that.
Only a UI test can check that the app switcher snapshot hides the vault. That's in VAULT-89.
Done when
Each bullet has a test, or a comment here says why it can't be tested and where it's checked instead.