feat(cordn): the migrate screens, and one settings entry instead of five

The Android half of the handoff: a screen that publishes on the old phone
and reads on the new one, and AndroidCordnBlobStore behind it.

That store does NOT reuse account.createBlossomUploadAuth the way
CordnMediaService does. §12 requires the BUD-01 authorization to be signed
by an ephemeral key and never the owner npub — signing as the owner would
tell the storage server, under the account's own name, that this person is
uploading right now, which is the linkage the opaque tip exists to prevent
and would arrive by a side door. Message attachments are already
attributable; a migration blob is meant to link to nobody.

Two things are said where they are decided rather than in a help page,
because neither is discoverable afterwards and both are irreversible in
the ways that matter: before exporting, that the encrypted documents leave
the device for a storage server; before importing, that this replaces
whatever cordn groups are already here, because MLS state cannot be
merged. The handed-off state is deliberately not phrased as an error —
nothing broke and nothing was deleted, the device stood down on purpose,
and taking it back is one button.

The settings entry answers the earlier question: cordn had four flat rows
(link, coordinators, key packages, backup) and migration would have made
five, which made it the largest feature in the account settings list by
count and among the least used. They are now one "cordn" entry into a hub
holding all five, still searchable under one name a user would look for.

./gradlew test green; all three Marmot/cordn isolation guards pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012BfD4txdnsaPRXmNXbup9n
This commit is contained in:
Claude
2026-09-23 02:45:47 +00:00
parent a37308acdd
commit ecb9513b4d
7 changed files with 662 additions and 12 deletions
@@ -0,0 +1,114 @@
/*
* Copyright (c) 2025 Vitor Pamplona
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to use,
* copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the
* Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN
* AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
* WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*/
package com.vitorpamplona.amethyst.model.cordn
import android.content.Context
import com.vitorpamplona.amethyst.Amethyst
import com.vitorpamplona.amethyst.commons.cordn.CordnBlobStore
import com.vitorpamplona.amethyst.service.uploads.blossom.BlossomUploader
import com.vitorpamplona.quartz.nip01Core.core.toHexKey
import com.vitorpamplona.quartz.nip01Core.crypto.KeyPair
import com.vitorpamplona.quartz.nip01Core.signers.NostrSignerInternal
import com.vitorpamplona.quartz.nipB7Blossom.BlossomAuthorizationEvent
import com.vitorpamplona.quartz.utils.sha256.sha256
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.withContext
import okhttp3.Request
import java.io.ByteArrayInputStream
/**
* Where a migration's sealed documents are stored, on Android.
*
* ## The authorization is signed by a throwaway, and that is the point
*
* `multi-device.md` §12 requires the BUD-01 upload authorization to be signed
* by an ephemeral key and **never** the owner `npub` — the same rule as the
* tip. Signing as the owner would tell the storage server, in the clear and
* under the account's own name, that this person is uploading right now. That
* is precisely the linkage the opaque tip is built to avoid, and it would
* arrive by a side door.
*
* So this does NOT reuse `account.createBlossomUploadAuth` the way
* [CordnMediaService] does for message attachments. Those are already
* attributable — they ride inside a group the coordinator can see traffic for
* — whereas the point of a migration blob is that nothing links it to anyone.
* [signer] is minted per instance and derived from nothing.
*/
class AndroidCordnBlobStore(
private val servers: List<String>,
private val context: Context,
) : CordnBlobStore {
private val signer = NostrSignerInternal(KeyPair())
override suspend fun put(blob: ByteArray): List<String> {
val hash = sha256(blob).toHexKey()
return servers.filter { server ->
runCatching {
BlossomUploader()
.upload(
inputStream = ByteArrayInputStream(blob),
hash = hash,
length = blob.size.toLong(),
baseFileName = hash,
// Opaque on purpose: the server learns a size and a
// hash, and nothing about what kind of thing this is.
contentType = OPAQUE,
alt = null,
sensitiveContent = null,
serverBaseUrl = server,
okHttpClient = Amethyst.instance.roleBasedHttpClientBuilder::okHttpClientForUploads,
httpAuth = { h, size, alt -> BlossomAuthorizationEvent.createUploadAuth(h, size, alt ?: "", signer) },
context = context,
useMediaEndpoint = false,
).url != null
}.getOrDefault(false)
}
}
override suspend fun get(
address: String,
servers: List<String>,
): ByteArray? =
withContext(Dispatchers.IO) {
// Ordered: §6 has the reader try the tip's servers as listed, most
// reliable first.
servers.firstNotNullOfOrNull { server ->
runCatching {
val url = "${server.trimEnd('/')}/$address"
Amethyst.instance.roleBasedHttpClientBuilder
.okHttpClientForImage(url)
.newCall(
Request
.Builder()
.url(url)
.get()
.build(),
).execute()
.use { if (it.isSuccessful) it.body?.bytes() else null }
}.getOrNull()
}
}
companion object {
private const val OPAQUE = "application/octet-stream"
}
}
@@ -301,8 +301,10 @@ import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.UserSettingsScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.VideoPlayerSettingsScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnBackupScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnCoordinatorsScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnHubScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnKeyPackagesScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnLinkScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnMigrateScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.nip46.Nip46ConnectedAppsScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.nip46.Nip46SignerScreen
import com.vitorpamplona.amethyst.ui.screen.loggedIn.shorts.ShortsScreen
@@ -673,6 +675,8 @@ fun BuildNavigation(
composableFromEnd<Route.CordnCoordinators> { CordnCoordinatorsScreen(accountViewModel, nav) }
composableFromEnd<Route.CordnKeyPackages> { CordnKeyPackagesScreen(accountViewModel, nav) }
composableFromEnd<Route.CordnBackup> { CordnBackupScreen(accountViewModel, nav) }
composableFromEnd<Route.CordnHub> { CordnHubScreen(accountViewModel, nav) }
composableFromEnd<Route.CordnMigrate> { CordnMigrateScreen(accountViewModel, nav) }
composableFromEnd<Route.EditFavoriteAlgoFeeds> { FavoriteAlgoFeedsListScreen(accountViewModel, nav) }
composableFromEnd<Route.EditPaymentTargets> { PaymentTargetsScreen(accountViewModel, nav) }
composableFromEnd<Route.EditBolt12Offers> { Bolt12OffersScreen(accountViewModel, nav) }
@@ -667,6 +667,11 @@ sealed class Route {
@Serializable object CordnBackup : Route()
/** The one cordn entry in settings; everything else hangs off it. */
@Serializable object CordnHub : Route()
@Serializable object CordnMigrate : Route()
@Serializable
data class AgentConsole(
val relayUrl: String,
@@ -43,14 +43,8 @@ import com.vitorpamplona.amethyst.commons.resources.call_settings
import com.vitorpamplona.amethyst.commons.resources.call_settings_search_keywords
import com.vitorpamplona.amethyst.commons.resources.compose_search_keywords
import com.vitorpamplona.amethyst.commons.resources.compose_settings
import com.vitorpamplona.amethyst.commons.resources.cordn_backup_search_keywords
import com.vitorpamplona.amethyst.commons.resources.cordn_backup_title
import com.vitorpamplona.amethyst.commons.resources.cordn_coordinators_search_keywords
import com.vitorpamplona.amethyst.commons.resources.cordn_coordinators_title
import com.vitorpamplona.amethyst.commons.resources.cordn_keypackages_search_keywords
import com.vitorpamplona.amethyst.commons.resources.cordn_keypackages_title
import com.vitorpamplona.amethyst.commons.resources.cordn_link_search_keywords
import com.vitorpamplona.amethyst.commons.resources.cordn_link_title
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_search_keywords
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_title
import com.vitorpamplona.amethyst.commons.resources.danger_zone
import com.vitorpamplona.amethyst.commons.resources.drawer_search_keywords
import com.vitorpamplona.amethyst.commons.resources.drawer_settings
@@ -170,10 +164,14 @@ fun buildSettingsCatalog(
symEntry(Res.string.napplet_permissions_title, MaterialSymbols.Apps, Res.string.napplet_connected_apps_search_keywords, Route.ConnectedApps),
symEntry(Res.string.relay_auth_settings_title, MaterialSymbols.Lock, Res.string.relay_auth_search_keywords, Route.RelayAuthSettings),
symEntry(Res.string.call_settings, MaterialSymbols.Phone, Res.string.call_settings_search_keywords, Route.CallSettings),
symEntry(Res.string.cordn_link_title, MaterialSymbols.Dns, Res.string.cordn_link_search_keywords, Route.CordnLink),
symEntry(Res.string.cordn_coordinators_title, MaterialSymbols.Dns, Res.string.cordn_coordinators_search_keywords, Route.CordnCoordinators),
symEntry(Res.string.cordn_keypackages_title, MaterialSymbols.Key, Res.string.cordn_keypackages_search_keywords, Route.CordnKeyPackages),
symEntry(Res.string.cordn_backup_title, MaterialSymbols.Dns, Res.string.cordn_backup_search_keywords, Route.CordnBackup),
// One entry, not five. cordn's screens are coordinators,
// key packages, link inspection, backup and migration —
// each a page a user visits rarely and only because they
// are already thinking about cordn. Five flat rows made it
// the largest feature in this list by count and the least
// used by far; the hub keeps them all reachable and
// searchable under one name.
symEntry(Res.string.cordn_hub_title, MaterialSymbols.Dns, Res.string.cordn_hub_search_keywords, Route.CordnHub),
),
)
@@ -0,0 +1,116 @@
/*
* Copyright (c) 2025 Vitor Pamplona
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to use,
* copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the
* Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN
* AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
* WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*/
package com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.verticalScroll
import androidx.compose.material3.Card
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Scaffold
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.ui.Modifier
import androidx.compose.ui.unit.dp
import com.vitorpamplona.amethyst.commons.resources.Res
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_backup
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_backup_desc
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_coordinators
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_coordinators_desc
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_explainer
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_keypackages
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_keypackages_desc
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_link
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_link_desc
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_migrate
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_migrate_desc
import com.vitorpamplona.amethyst.commons.resources.cordn_hub_title
import com.vitorpamplona.amethyst.ui.navigation.navs.INav
import com.vitorpamplona.amethyst.ui.navigation.routes.Route
import com.vitorpamplona.amethyst.ui.navigation.topbars.TopBarWithBackButton
import com.vitorpamplona.amethyst.ui.screen.loggedIn.AccountViewModel
import com.vitorpamplona.amethyst.ui.stringRes
import org.jetbrains.compose.resources.StringResource
/**
* One door into cordn, instead of five rows in the account settings list.
*
* cordn's pages — coordinators, key packages, link inspection, backup,
* migration — are each visited rarely and only by someone already thinking
* about cordn. As flat entries they made it the biggest feature in that list
* by count and among the least used, pushing everything else down. Grouping
* them costs one tap and keeps every page searchable under a name a user
* would actually look for.
*/
@Composable
fun CordnHubScreen(
accountViewModel: AccountViewModel,
nav: INav,
) {
Scaffold(
topBar = { TopBarWithBackButton(stringRes(Res.string.cordn_hub_title), nav) },
) { padding ->
Column(
modifier =
Modifier
.padding(padding)
.fillMaxSize()
.verticalScroll(rememberScrollState())
.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(12.dp),
) {
Text(
text = stringRes(Res.string.cordn_hub_explainer),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
HubEntry(Res.string.cordn_hub_coordinators, Res.string.cordn_hub_coordinators_desc) { nav.nav(Route.CordnCoordinators) }
HubEntry(Res.string.cordn_hub_keypackages, Res.string.cordn_hub_keypackages_desc) { nav.nav(Route.CordnKeyPackages) }
HubEntry(Res.string.cordn_hub_link, Res.string.cordn_hub_link_desc) { nav.nav(Route.CordnLink) }
HubEntry(Res.string.cordn_hub_backup, Res.string.cordn_hub_backup_desc) { nav.nav(Route.CordnBackup) }
HubEntry(Res.string.cordn_hub_migrate, Res.string.cordn_hub_migrate_desc) { nav.nav(Route.CordnMigrate) }
}
}
}
@Composable
private fun HubEntry(
title: StringResource,
description: StringResource,
onClick: () -> Unit,
) {
Card(modifier = Modifier.fillMaxWidth().clickable(onClick = onClick)) {
Column(Modifier.padding(16.dp), verticalArrangement = Arrangement.spacedBy(4.dp)) {
Text(stringRes(title), style = MaterialTheme.typography.titleSmall)
Text(
text = stringRes(description),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
}
@@ -0,0 +1,372 @@
/*
* Copyright (c) 2025 Vitor Pamplona
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to use,
* copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the
* Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN
* AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
* WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*/
package com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.text.selection.SelectionContainer
import androidx.compose.foundation.verticalScroll
import androidx.compose.material3.Button
import androidx.compose.material3.Card
import androidx.compose.material3.HorizontalDivider
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.OutlinedButton
import androidx.compose.material3.OutlinedTextField
import androidx.compose.material3.Scaffold
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.LocalContext
import androidx.compose.ui.unit.dp
import androidx.lifecycle.compose.collectAsStateWithLifecycle
import com.vitorpamplona.amethyst.R
import com.vitorpamplona.amethyst.commons.cordn.CordnMigration
import com.vitorpamplona.amethyst.commons.resources.Res
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_cancel
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_cancel_desc
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_code_note
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_done
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_explainer
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_export
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_exporting
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_exposure_body
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_exposure_title
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_handed_off
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_handed_off_desc
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_import
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_importing
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_no_groups
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_no_server
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_paste
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_receive
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_replaces_warning
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_scan
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_scan_this
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_sign_in_first
import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_title
import com.vitorpamplona.amethyst.model.cordn.AndroidCordnBlobStore
import com.vitorpamplona.amethyst.model.cordn.CordnRuntime
import com.vitorpamplona.amethyst.ui.navigation.navs.INav
import com.vitorpamplona.amethyst.ui.navigation.topbars.TopBarWithBackButton
import com.vitorpamplona.amethyst.ui.screen.loggedIn.AccountViewModel
import com.vitorpamplona.amethyst.ui.screen.loggedIn.qrcode.QrCodeDrawer
import com.vitorpamplona.amethyst.ui.screen.loggedIn.qrcode.SimpleQrCodeScanner
import com.vitorpamplona.amethyst.ui.stringRes
import com.vitorpamplona.quartz.cordn.appMultiDevice.CordnHandoffCode
import kotlinx.coroutines.launch
/**
* Moving this account's cordn groups to a phone the user is switching to.
*
* ## Why this is a handoff and not sync
*
* `spec/applications/multi-device.md` §10 leaves one case unresolved: two
* devices of one identity committing inside a single delivery round-trip reach
* the same epoch with different states, and §15 concedes that equal-epoch MLS
* states have no merge function. This screen is buildable because a migration
* has one writer — which is only true if this device stops afterwards, which
* is what the handed-off state below is.
*
* ## What the user is told, and where
*
* Two things are said at the moment they are decided rather than in a help
* page. Before exporting: the encrypted documents leave the device for a
* storage server. Before importing: this replaces whatever cordn groups are
* already here, because MLS state cannot be merged. Both are irreversible in
* the ways that matter, and neither is discoverable afterwards.
*/
@Composable
fun CordnMigrateScreen(
accountViewModel: AccountViewModel,
nav: INav,
) {
val runtime = accountViewModel.account.cordnRuntime
Scaffold(
topBar = { TopBarWithBackButton(stringRes(Res.string.cordn_migrate_title), nav) },
) { padding ->
if (runtime == null) {
Column(Modifier.fillMaxSize().padding(padding).padding(24.dp)) {
Text(stringRes(R.string.cordn_group_unavailable))
}
return@Scaffold
}
val handedOff by runtime.handoff.handedOff.collectAsStateWithLifecycle()
Column(
modifier =
Modifier
.padding(padding)
.fillMaxSize()
.verticalScroll(rememberScrollState())
.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(12.dp),
) {
if (handedOff) {
HandedOff(runtime)
return@Column
}
Text(
text = stringRes(Res.string.cordn_migrate_explainer),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
SendSide(runtime, accountViewModel)
HorizontalDivider(Modifier.padding(vertical = 8.dp))
ReceiveSide(runtime, accountViewModel)
}
}
}
/**
* The state that makes the rest of this safe.
*
* Deliberately not phrased as an error. Nothing is broken and nothing was
* deleted — the device stood down on purpose, and the groups are still on
* disk so taking it back is possible.
*/
@Composable
private fun HandedOff(runtime: CordnRuntime) {
val scope = rememberCoroutineScope()
var busy by remember { mutableStateOf(false) }
Card(Modifier.fillMaxWidth()) {
Column(Modifier.padding(16.dp), verticalArrangement = Arrangement.spacedBy(8.dp)) {
Text(stringRes(Res.string.cordn_migrate_handed_off), style = MaterialTheme.typography.titleSmall)
Text(
text = stringRes(Res.string.cordn_migrate_handed_off_desc),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
Text(
text = stringRes(Res.string.cordn_migrate_cancel_desc),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
OutlinedButton(
onClick = {
busy = true
scope.launch {
try {
runtime.cancelHandOff()
} finally {
busy = false
}
}
},
enabled = !busy,
modifier = Modifier.fillMaxWidth(),
) {
Text(stringRes(Res.string.cordn_migrate_cancel))
}
}
@Composable
private fun SendSide(
runtime: CordnRuntime,
accountViewModel: AccountViewModel,
) {
val scope = rememberCoroutineScope()
val context = LocalContext.current
var code by remember { mutableStateOf<String?>(null) }
var error by remember { mutableStateOf<String?>(null) }
var busy by remember { mutableStateOf(false) }
val noServer = stringRes(Res.string.cordn_migrate_no_server)
val noGroups = stringRes(Res.string.cordn_migrate_no_groups)
Text(
text = stringRes(Res.string.cordn_migrate_sign_in_first),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
// Said before the button, because this is the moment the decision is made
// and the upload cannot be taken back afterwards.
Card(Modifier.fillMaxWidth()) {
Column(Modifier.padding(16.dp), verticalArrangement = Arrangement.spacedBy(4.dp)) {
Text(stringRes(Res.string.cordn_migrate_exposure_title), style = MaterialTheme.typography.titleSmall)
Text(
text = stringRes(Res.string.cordn_migrate_exposure_body),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
code?.let {
Column(
modifier = Modifier.fillMaxWidth(),
horizontalAlignment = Alignment.CenterHorizontally,
verticalArrangement = Arrangement.spacedBy(8.dp),
) {
Text(stringRes(Res.string.cordn_migrate_scan_this), style = MaterialTheme.typography.titleSmall)
QrCodeDrawer(it, Modifier.size(260.dp))
SelectionContainer { Text(it, style = MaterialTheme.typography.labelSmall) }
Text(
text = stringRes(Res.string.cordn_migrate_code_note),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
error?.let { Text(it, style = MaterialTheme.typography.bodyMedium, color = MaterialTheme.colorScheme.error) }
Button(
onClick = {
busy = true
error = null
scope.launch {
try {
val servers = listOfNotNull(accountViewModel.account.settings.defaultFileServer.baseUrl)
if (servers.isEmpty()) {
error = noServer
return@launch
}
if (runtime.migrationSnapshot().groups.isEmpty()) {
error = noGroups
return@launch
}
val migration =
CordnMigration(
accountViewModel.account.client,
accountViewModel.account.signer,
AndroidCordnBlobStore(servers, context),
)
code = runtime.handOff(migration, accountViewModel.account.outboxRelays.flow.value).encode()
} catch (e: Exception) {
error = e.message
} finally {
busy = false
}
}
},
enabled = !busy && code == null,
modifier = Modifier.fillMaxWidth(),
) {
Text(stringRes(if (busy) Res.string.cordn_migrate_exporting else Res.string.cordn_migrate_export))
}
}
@Composable
private fun ReceiveSide(
runtime: CordnRuntime,
accountViewModel: AccountViewModel,
) {
val scope = rememberCoroutineScope()
val context = LocalContext.current
var typed by remember { mutableStateOf("") }
var scanning by remember { mutableStateOf(false) }
var busy by remember { mutableStateOf(false) }
var error by remember { mutableStateOf<String?>(null) }
var done by remember { mutableStateOf<Int?>(null) }
val badCode = stringRes(Res.string.cordn_migrate_scan)
Text(stringRes(Res.string.cordn_migrate_receive), style = MaterialTheme.typography.titleSmall)
// Said before the button, for the same reason as the exposure card: an
// import replaces, and MLS state cannot be merged back afterwards.
Text(
text = stringRes(Res.string.cordn_migrate_replaces_warning),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
if (scanning) {
SimpleQrCodeScanner {
scanning = false
if (it != null) typed = it
}
}
OutlinedButton(onClick = { scanning = true }, modifier = Modifier.fillMaxWidth()) {
Text(stringRes(Res.string.cordn_migrate_scan))
}
OutlinedTextField(
value = typed,
onValueChange = {
typed = it
error = null
},
label = { Text(stringRes(Res.string.cordn_migrate_paste)) },
singleLine = true,
modifier = Modifier.fillMaxWidth(),
)
done?.let { Text(stringRes(Res.string.cordn_migrate_done, it), style = MaterialTheme.typography.bodyMedium) }
error?.let { Text(it, style = MaterialTheme.typography.bodyMedium, color = MaterialTheme.colorScheme.error) }
Button(
onClick = {
val parsed = CordnHandoffCode.decodeOrNull(typed.trim())
if (parsed == null) {
error = badCode
return@Button
}
busy = true
error = null
scope.launch {
try {
val migration =
CordnMigration(
accountViewModel.account.client,
accountViewModel.account.signer,
AndroidCordnBlobStore(emptyList(), context),
)
val snapshot = migration.fetch(parsed)
runtime.adoptMigration(snapshot)
done = snapshot.groups.size
typed = ""
} catch (e: Exception) {
error = e.message
} finally {
busy = false
}
}
},
enabled = !busy && typed.isNotBlank(),
modifier = Modifier.fillMaxWidth(),
) {
Text(stringRes(if (busy) Res.string.cordn_migrate_importing else Res.string.cordn_migrate_import))
}
}
@@ -5392,4 +5392,45 @@
<string name="new_conversation_cordn_con_1">The coordinator learns who is in the group and when you talk, even though it cannot read what you say.</string>
<string name="cordn_invitations_entry">Invited to a cordn group?</string>
<string name="cordn_invitations_entry_action">Review invitations</string>
<!-- cordn device migration (spec/applications/multi-device.md §9/§11), as a
one-shot handoff rather than continuous sync. The exposure strings say
what leaves the device; the fork strings say why the old phone stops. -->
<string name="cordn_hub_title">cordn</string>
<string name="cordn_hub_search_keywords" translatable="false">cordn coordinator group mls chat migrate backup key package link move device</string>
<string name="cordn_hub_explainer">Groups delivered by a coordinator you choose, instead of by relays.</string>
<string name="cordn_hub_link">Inspect a group link</string>
<string name="cordn_hub_link_desc">See what a cordn1… link points at before you act on it</string>
<string name="cordn_hub_coordinators">Coordinators</string>
<string name="cordn_hub_coordinators_desc">The servers that carry your groups</string>
<string name="cordn_hub_keypackages">Key packages</string>
<string name="cordn_hub_keypackages_desc">What lets people add you to a group</string>
<string name="cordn_hub_backup">Backup and restore</string>
<string name="cordn_hub_backup_desc">A passphrase-encrypted file you keep</string>
<string name="cordn_hub_migrate">Move to a new phone</string>
<string name="cordn_hub_migrate_desc">Hand your groups to a device you are switching to</string>
<string name="cordn_migrate_title">Move to a new phone</string>
<string name="cordn_migrate_search_keywords" translatable="false">cordn migrate move new phone device transfer handoff switch qr</string>
<string name="cordn_migrate_explainer">Your cordn groups live on this device. Moving them takes one code: this phone publishes them, the new phone reads them, and this phone stops.</string>
<string name="cordn_migrate_sign_in_first">Sign in with the same account on the new phone first. This moves your groups, never your key.</string>
<string name="cordn_migrate_export">Start the handoff</string>
<string name="cordn_migrate_exporting">Publishing…</string>
<string name="cordn_migrate_scan_this">Scan this on the new phone</string>
<string name="cordn_migrate_code_note">The code is only a pointer. Anyone who photographs it learns nothing — what it points at is encrypted to you.</string>
<string name="cordn_migrate_handed_off">This device has handed its groups over</string>
<string name="cordn_migrate_handed_off_desc">It has stopped sending and receiving, because two phones sending from one group would break it for everyone in it. Your groups are still on this device and nothing was deleted.</string>
<string name="cordn_migrate_cancel">Take this device back</string>
<string name="cordn_migrate_cancel_desc">Use this if the move did not finish. Only do it if the new phone has not started sending.</string>
<string name="cordn_migrate_receive">Receive from another phone</string>
<string name="cordn_migrate_scan">Scan the code</string>
<string name="cordn_migrate_paste">or paste it</string>
<string name="cordn_migrate_import">Bring the groups here</string>
<string name="cordn_migrate_importing">Fetching…</string>
<string name="cordn_migrate_replaces_warning">This replaces any cordn groups already on this phone. They cannot be merged.</string>
<string name="cordn_migrate_done">%1$d groups moved</string>
<string name="cordn_migrate_no_groups">There are no cordn groups on this device to move.</string>
<string name="cordn_migrate_no_server">Set a media server first — the encrypted documents need somewhere to sit while the other phone fetches them.</string>
<string name="cordn_migrate_exposure_title">What leaves this device</string>
<string name="cordn_migrate_exposure_body">Your group state is encrypted and uploaded to your media server so the other phone can fetch it. It is unreadable to that server, which sees only a size and a time. Delete the blobs afterwards if you want nothing left behind.</string>
</resources>