Part of VAULT-83. Needs VAULT-88 (the UI test target).
Why
The lock is Vault's front door, and no test uses it the way a person does. Some behaviour can only be checked from a UI test:
- nothing from the vault is on screen or in the accessibility tree while locked;
- the app switcher snapshot is covered;
- the password screen, the duress password and the wait between attempts all work in the real app.
Launch hooks
Today -screenshot-scene is the only launch hook, and it turns App Lock off. These tests need DEBUG-only hooks next to ScreenshotMode, compiled out of release builds just like it:
- A throwaway storage directory. The simulator's real vault must never be touched.
- The device authentication result: approve or deny.
DeviceAuthenticationPolicy already has alwaysAllow, alwaysDeny and cannotAuthenticate.
- Cheap Argon2 parameters for the App Lock Password.
- Separate
UserDefaults suites and keychain items, so nothing leaks between tests or into the simulator's real vault.
- Preset state: App Lock on, and optionally an App Lock Password and a duress password, each opening a vault with different known items.
An unknown value fails loudly, as -screenshot-scene does. Add a unit test that the hooks do nothing in a release configuration, or show they're compiled out.
Tests
- Launch locked, unlock with device authentication:
- With App Lock on, the app launches to the lock screen, and no vault content is in the accessibility tree.
- Approving opens the feed.
- Denying stays locked.
- Backgrounding locks:
- Unlock with Require Unlock set to "Immediately".
- Press home, and the privacy cover shows, not the codes. Capture the screen while the app is inactive.
- Bring the app back, and it's locked again.
- Relaunching locks whatever the delay is.
- App Lock Password:
- Launch with a password set.
- A wrong password shows the error and stays locked.
- The right password opens the vault with its items.
- Lock, then enter the duress password: the other vault opens, with only its own items.
- Passcode Required (optional): with the authentication hook set to
cannotAuthenticate, the app shows "Passcode Required" and no password field (VAULT-61).
Done when
- Tests 1–3 pass in
make validate.
- The hooks are DEBUG-only and documented next to
ScreenshotMode.