trackslash
VAULT-89 P2

UI test: launch locked, unlock, and lock again

0
Sub-issue of VAULT-83 P2 Test that lock, unlock, encryption and restore work end to end

Description

Part of VAULT-83. Needs VAULT-88 (the UI test target).

Why

The lock is Vault's front door, and no test uses it the way a person does. Some behaviour can only be checked from a UI test:

  • nothing from the vault is on screen or in the accessibility tree while locked;
  • the app switcher snapshot is covered;
  • the password screen, the duress password and the wait between attempts all work in the real app.

Launch hooks

Today -screenshot-scene is the only launch hook, and it turns App Lock off. These tests need DEBUG-only hooks next to ScreenshotMode, compiled out of release builds just like it:

  • A throwaway storage directory. The simulator's real vault must never be touched.
  • The device authentication result: approve or deny. DeviceAuthenticationPolicy already has alwaysAllow, alwaysDeny and cannotAuthenticate.
  • Cheap Argon2 parameters for the App Lock Password.
  • Separate UserDefaults suites and keychain items, so nothing leaks between tests or into the simulator's real vault.
  • Preset state: App Lock on, and optionally an App Lock Password and a duress password, each opening a vault with different known items.

An unknown value fails loudly, as -screenshot-scene does. Add a unit test that the hooks do nothing in a release configuration, or show they're compiled out.

Tests

  1. Launch locked, unlock with device authentication:
    • With App Lock on, the app launches to the lock screen, and no vault content is in the accessibility tree.
    • Approving opens the feed.
    • Denying stays locked.
  2. Backgrounding locks:
    • Unlock with Require Unlock set to "Immediately".
    • Press home, and the privacy cover shows, not the codes. Capture the screen while the app is inactive.
    • Bring the app back, and it's locked again.
    • Relaunching locks whatever the delay is.
  3. App Lock Password:
    • Launch with a password set.
    • A wrong password shows the error and stays locked.
    • The right password opens the vault with its items.
    • Lock, then enter the duress password: the other vault opens, with only its own items.
  4. Passcode Required (optional): with the authentication hook set to cannotAuthenticate, the app shows "Passcode Required" and no password field (VAULT-61).

Done when

  • Tests 1–3 pass in make validate.
  • The hooks are DEBUG-only and documented next to ScreenshotMode.

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Done in https://github.com/badbundle/vault-app/pull/696, merged as 1e135405.

  • Launch hooks (debug builds only):
    • -ui-test-vault app-lock|app-lock-password|open gives the tests a vault in their own directory, defaults and keychain services (UITestVaultStorage).
    • -ui-test-authentication answers each device authentication prompt in turn.
    • -ui-test-app-lock-delay sets Require Unlock.
    • The tests use cheap Argon2 parameters.
  • Four tests: launching locked; backgrounding, where the app switcher shows the privacy cover and the app locks; the wrong, right and duress passwords; and Passcode Required.
  • Two launches per test: preparing a vault and opening it are separate launches, so each test starts from a real cold launch.
  • Not tested here: the wait between attempts. The first wait lasts a minute, which is too slow for a UI test. The unit tests cover it (#684).
  • Run time: the UI test step now takes about 100 s of test time.