From ecb9513b4d30a9fbfc484879cc34d0e42d3aa135 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 23 Sep 2026 02:45:47 +0000 Subject: [PATCH] feat(cordn): the migrate screens, and one settings entry instead of five MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Android half of the handoff: a screen that publishes on the old phone and reads on the new one, and AndroidCordnBlobStore behind it. That store does NOT reuse account.createBlossomUploadAuth the way CordnMediaService does. §12 requires the BUD-01 authorization to be signed by an ephemeral key and never the owner npub — signing as the owner would tell the storage server, under the account's own name, that this person is uploading right now, which is the linkage the opaque tip exists to prevent and would arrive by a side door. Message attachments are already attributable; a migration blob is meant to link to nobody. Two things are said where they are decided rather than in a help page, because neither is discoverable afterwards and both are irreversible in the ways that matter: before exporting, that the encrypted documents leave the device for a storage server; before importing, that this replaces whatever cordn groups are already here, because MLS state cannot be merged. The handed-off state is deliberately not phrased as an error — nothing broke and nothing was deleted, the device stood down on purpose, and taking it back is one button. The settings entry answers the earlier question: cordn had four flat rows (link, coordinators, key packages, backup) and migration would have made five, which made it the largest feature in the account settings list by count and among the least used. They are now one "cordn" entry into a hub holding all five, still searchable under one name a user would look for. ./gradlew test green; all three Marmot/cordn isolation guards pass. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_012BfD4txdnsaPRXmNXbup9n --- .../model/cordn/AndroidCordnBlobStore.kt | 114 ++++++ .../amethyst/ui/navigation/AppNavigation.kt | 4 + .../amethyst/ui/navigation/routes/Routes.kt | 5 + .../settings/SettingsCatalogBuilder.kt | 22 +- .../loggedIn/settings/cordn/CordnHubScreen.kt | 116 ++++++ .../settings/cordn/CordnMigrateScreen.kt | 372 ++++++++++++++++++ .../composeResources/values/strings.xml | 41 ++ 7 files changed, 662 insertions(+), 12 deletions(-) create mode 100644 amethyst/src/main/java/com/vitorpamplona/amethyst/model/cordn/AndroidCordnBlobStore.kt create mode 100644 amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/cordn/CordnHubScreen.kt create mode 100644 amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/cordn/CordnMigrateScreen.kt diff --git a/amethyst/src/main/java/com/vitorpamplona/amethyst/model/cordn/AndroidCordnBlobStore.kt b/amethyst/src/main/java/com/vitorpamplona/amethyst/model/cordn/AndroidCordnBlobStore.kt new file mode 100644 index 0000000000..39b8dad7a5 --- /dev/null +++ b/amethyst/src/main/java/com/vitorpamplona/amethyst/model/cordn/AndroidCordnBlobStore.kt @@ -0,0 +1,114 @@ +/* + * Copyright (c) 2025 Vitor Pamplona + * + * Permission is hereby granted, free of charge, to any person obtaining a copy of + * this software and associated documentation files (the "Software"), to deal in + * the Software without restriction, including without limitation the rights to use, + * copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the + * Software, and to permit persons to whom the Software is furnished to do so, + * subject to the following conditions: + * + * The above copyright notice and this permission notice shall be included in all + * copies or substantial portions of the Software. + * + * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS + * FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR + * COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN + * AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION + * WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + */ +package com.vitorpamplona.amethyst.model.cordn + +import android.content.Context +import com.vitorpamplona.amethyst.Amethyst +import com.vitorpamplona.amethyst.commons.cordn.CordnBlobStore +import com.vitorpamplona.amethyst.service.uploads.blossom.BlossomUploader +import com.vitorpamplona.quartz.nip01Core.core.toHexKey +import com.vitorpamplona.quartz.nip01Core.crypto.KeyPair +import com.vitorpamplona.quartz.nip01Core.signers.NostrSignerInternal +import com.vitorpamplona.quartz.nipB7Blossom.BlossomAuthorizationEvent +import com.vitorpamplona.quartz.utils.sha256.sha256 +import kotlinx.coroutines.Dispatchers +import kotlinx.coroutines.withContext +import okhttp3.Request +import java.io.ByteArrayInputStream + +/** + * Where a migration's sealed documents are stored, on Android. + * + * ## The authorization is signed by a throwaway, and that is the point + * + * `multi-device.md` §12 requires the BUD-01 upload authorization to be signed + * by an ephemeral key and **never** the owner `npub` — the same rule as the + * tip. Signing as the owner would tell the storage server, in the clear and + * under the account's own name, that this person is uploading right now. That + * is precisely the linkage the opaque tip is built to avoid, and it would + * arrive by a side door. + * + * So this does NOT reuse `account.createBlossomUploadAuth` the way + * [CordnMediaService] does for message attachments. Those are already + * attributable — they ride inside a group the coordinator can see traffic for + * — whereas the point of a migration blob is that nothing links it to anyone. + * [signer] is minted per instance and derived from nothing. + */ +class AndroidCordnBlobStore( + private val servers: List, + private val context: Context, +) : CordnBlobStore { + private val signer = NostrSignerInternal(KeyPair()) + + override suspend fun put(blob: ByteArray): List { + val hash = sha256(blob).toHexKey() + + return servers.filter { server -> + runCatching { + BlossomUploader() + .upload( + inputStream = ByteArrayInputStream(blob), + hash = hash, + length = blob.size.toLong(), + baseFileName = hash, + // Opaque on purpose: the server learns a size and a + // hash, and nothing about what kind of thing this is. + contentType = OPAQUE, + alt = null, + sensitiveContent = null, + serverBaseUrl = server, + okHttpClient = Amethyst.instance.roleBasedHttpClientBuilder::okHttpClientForUploads, + httpAuth = { h, size, alt -> BlossomAuthorizationEvent.createUploadAuth(h, size, alt ?: "", signer) }, + context = context, + useMediaEndpoint = false, + ).url != null + }.getOrDefault(false) + } + } + + override suspend fun get( + address: String, + servers: List, + ): ByteArray? = + withContext(Dispatchers.IO) { + // Ordered: §6 has the reader try the tip's servers as listed, most + // reliable first. + servers.firstNotNullOfOrNull { server -> + runCatching { + val url = "${server.trimEnd('/')}/$address" + Amethyst.instance.roleBasedHttpClientBuilder + .okHttpClientForImage(url) + .newCall( + Request + .Builder() + .url(url) + .get() + .build(), + ).execute() + .use { if (it.isSuccessful) it.body?.bytes() else null } + }.getOrNull() + } + } + + companion object { + private const val OPAQUE = "application/octet-stream" + } +} diff --git a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/navigation/AppNavigation.kt b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/navigation/AppNavigation.kt index 7e08652fc0..7b863d3296 100644 --- a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/navigation/AppNavigation.kt +++ b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/navigation/AppNavigation.kt @@ -301,8 +301,10 @@ import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.UserSettingsScreen import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.VideoPlayerSettingsScreen import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnBackupScreen import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnCoordinatorsScreen +import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnHubScreen import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnKeyPackagesScreen import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnLinkScreen +import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn.CordnMigrateScreen import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.nip46.Nip46ConnectedAppsScreen import com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.nip46.Nip46SignerScreen import com.vitorpamplona.amethyst.ui.screen.loggedIn.shorts.ShortsScreen @@ -673,6 +675,8 @@ fun BuildNavigation( composableFromEnd { CordnCoordinatorsScreen(accountViewModel, nav) } composableFromEnd { CordnKeyPackagesScreen(accountViewModel, nav) } composableFromEnd { CordnBackupScreen(accountViewModel, nav) } + composableFromEnd { CordnHubScreen(accountViewModel, nav) } + composableFromEnd { CordnMigrateScreen(accountViewModel, nav) } composableFromEnd { FavoriteAlgoFeedsListScreen(accountViewModel, nav) } composableFromEnd { PaymentTargetsScreen(accountViewModel, nav) } composableFromEnd { Bolt12OffersScreen(accountViewModel, nav) } diff --git a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/navigation/routes/Routes.kt b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/navigation/routes/Routes.kt index b89fda933d..fc380f74aa 100644 --- a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/navigation/routes/Routes.kt +++ b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/navigation/routes/Routes.kt @@ -667,6 +667,11 @@ sealed class Route { @Serializable object CordnBackup : Route() + /** The one cordn entry in settings; everything else hangs off it. */ + @Serializable object CordnHub : Route() + + @Serializable object CordnMigrate : Route() + @Serializable data class AgentConsole( val relayUrl: String, diff --git a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/SettingsCatalogBuilder.kt b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/SettingsCatalogBuilder.kt index eaeddcec1d..6dcdb4c372 100644 --- a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/SettingsCatalogBuilder.kt +++ b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/SettingsCatalogBuilder.kt @@ -43,14 +43,8 @@ import com.vitorpamplona.amethyst.commons.resources.call_settings import com.vitorpamplona.amethyst.commons.resources.call_settings_search_keywords import com.vitorpamplona.amethyst.commons.resources.compose_search_keywords import com.vitorpamplona.amethyst.commons.resources.compose_settings -import com.vitorpamplona.amethyst.commons.resources.cordn_backup_search_keywords -import com.vitorpamplona.amethyst.commons.resources.cordn_backup_title -import com.vitorpamplona.amethyst.commons.resources.cordn_coordinators_search_keywords -import com.vitorpamplona.amethyst.commons.resources.cordn_coordinators_title -import com.vitorpamplona.amethyst.commons.resources.cordn_keypackages_search_keywords -import com.vitorpamplona.amethyst.commons.resources.cordn_keypackages_title -import com.vitorpamplona.amethyst.commons.resources.cordn_link_search_keywords -import com.vitorpamplona.amethyst.commons.resources.cordn_link_title +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_search_keywords +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_title import com.vitorpamplona.amethyst.commons.resources.danger_zone import com.vitorpamplona.amethyst.commons.resources.drawer_search_keywords import com.vitorpamplona.amethyst.commons.resources.drawer_settings @@ -170,10 +164,14 @@ fun buildSettingsCatalog( symEntry(Res.string.napplet_permissions_title, MaterialSymbols.Apps, Res.string.napplet_connected_apps_search_keywords, Route.ConnectedApps), symEntry(Res.string.relay_auth_settings_title, MaterialSymbols.Lock, Res.string.relay_auth_search_keywords, Route.RelayAuthSettings), symEntry(Res.string.call_settings, MaterialSymbols.Phone, Res.string.call_settings_search_keywords, Route.CallSettings), - symEntry(Res.string.cordn_link_title, MaterialSymbols.Dns, Res.string.cordn_link_search_keywords, Route.CordnLink), - symEntry(Res.string.cordn_coordinators_title, MaterialSymbols.Dns, Res.string.cordn_coordinators_search_keywords, Route.CordnCoordinators), - symEntry(Res.string.cordn_keypackages_title, MaterialSymbols.Key, Res.string.cordn_keypackages_search_keywords, Route.CordnKeyPackages), - symEntry(Res.string.cordn_backup_title, MaterialSymbols.Dns, Res.string.cordn_backup_search_keywords, Route.CordnBackup), + // One entry, not five. cordn's screens are coordinators, + // key packages, link inspection, backup and migration — + // each a page a user visits rarely and only because they + // are already thinking about cordn. Five flat rows made it + // the largest feature in this list by count and the least + // used by far; the hub keeps them all reachable and + // searchable under one name. + symEntry(Res.string.cordn_hub_title, MaterialSymbols.Dns, Res.string.cordn_hub_search_keywords, Route.CordnHub), ), ) diff --git a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/cordn/CordnHubScreen.kt b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/cordn/CordnHubScreen.kt new file mode 100644 index 0000000000..2d45a9932f --- /dev/null +++ b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/cordn/CordnHubScreen.kt @@ -0,0 +1,116 @@ +/* + * Copyright (c) 2025 Vitor Pamplona + * + * Permission is hereby granted, free of charge, to any person obtaining a copy of + * this software and associated documentation files (the "Software"), to deal in + * the Software without restriction, including without limitation the rights to use, + * copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the + * Software, and to permit persons to whom the Software is furnished to do so, + * subject to the following conditions: + * + * The above copyright notice and this permission notice shall be included in all + * copies or substantial portions of the Software. + * + * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS + * FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR + * COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN + * AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION + * WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + */ +package com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn + +import androidx.compose.foundation.clickable +import androidx.compose.foundation.layout.Arrangement +import androidx.compose.foundation.layout.Column +import androidx.compose.foundation.layout.fillMaxSize +import androidx.compose.foundation.layout.fillMaxWidth +import androidx.compose.foundation.layout.padding +import androidx.compose.foundation.rememberScrollState +import androidx.compose.foundation.verticalScroll +import androidx.compose.material3.Card +import androidx.compose.material3.MaterialTheme +import androidx.compose.material3.Scaffold +import androidx.compose.material3.Text +import androidx.compose.runtime.Composable +import androidx.compose.ui.Modifier +import androidx.compose.ui.unit.dp +import com.vitorpamplona.amethyst.commons.resources.Res +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_backup +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_backup_desc +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_coordinators +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_coordinators_desc +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_explainer +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_keypackages +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_keypackages_desc +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_link +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_link_desc +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_migrate +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_migrate_desc +import com.vitorpamplona.amethyst.commons.resources.cordn_hub_title +import com.vitorpamplona.amethyst.ui.navigation.navs.INav +import com.vitorpamplona.amethyst.ui.navigation.routes.Route +import com.vitorpamplona.amethyst.ui.navigation.topbars.TopBarWithBackButton +import com.vitorpamplona.amethyst.ui.screen.loggedIn.AccountViewModel +import com.vitorpamplona.amethyst.ui.stringRes +import org.jetbrains.compose.resources.StringResource + +/** + * One door into cordn, instead of five rows in the account settings list. + * + * cordn's pages — coordinators, key packages, link inspection, backup, + * migration — are each visited rarely and only by someone already thinking + * about cordn. As flat entries they made it the biggest feature in that list + * by count and among the least used, pushing everything else down. Grouping + * them costs one tap and keeps every page searchable under a name a user + * would actually look for. + */ +@Composable +fun CordnHubScreen( + accountViewModel: AccountViewModel, + nav: INav, +) { + Scaffold( + topBar = { TopBarWithBackButton(stringRes(Res.string.cordn_hub_title), nav) }, + ) { padding -> + Column( + modifier = + Modifier + .padding(padding) + .fillMaxSize() + .verticalScroll(rememberScrollState()) + .padding(16.dp), + verticalArrangement = Arrangement.spacedBy(12.dp), + ) { + Text( + text = stringRes(Res.string.cordn_hub_explainer), + style = MaterialTheme.typography.bodyMedium, + color = MaterialTheme.colorScheme.onSurfaceVariant, + ) + + HubEntry(Res.string.cordn_hub_coordinators, Res.string.cordn_hub_coordinators_desc) { nav.nav(Route.CordnCoordinators) } + HubEntry(Res.string.cordn_hub_keypackages, Res.string.cordn_hub_keypackages_desc) { nav.nav(Route.CordnKeyPackages) } + HubEntry(Res.string.cordn_hub_link, Res.string.cordn_hub_link_desc) { nav.nav(Route.CordnLink) } + HubEntry(Res.string.cordn_hub_backup, Res.string.cordn_hub_backup_desc) { nav.nav(Route.CordnBackup) } + HubEntry(Res.string.cordn_hub_migrate, Res.string.cordn_hub_migrate_desc) { nav.nav(Route.CordnMigrate) } + } + } +} + +@Composable +private fun HubEntry( + title: StringResource, + description: StringResource, + onClick: () -> Unit, +) { + Card(modifier = Modifier.fillMaxWidth().clickable(onClick = onClick)) { + Column(Modifier.padding(16.dp), verticalArrangement = Arrangement.spacedBy(4.dp)) { + Text(stringRes(title), style = MaterialTheme.typography.titleSmall) + Text( + text = stringRes(description), + style = MaterialTheme.typography.bodySmall, + color = MaterialTheme.colorScheme.onSurfaceVariant, + ) + } + } +} diff --git a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/cordn/CordnMigrateScreen.kt b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/cordn/CordnMigrateScreen.kt new file mode 100644 index 0000000000..35bb381ff5 --- /dev/null +++ b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/settings/cordn/CordnMigrateScreen.kt @@ -0,0 +1,372 @@ +/* + * Copyright (c) 2025 Vitor Pamplona + * + * Permission is hereby granted, free of charge, to any person obtaining a copy of + * this software and associated documentation files (the "Software"), to deal in + * the Software without restriction, including without limitation the rights to use, + * copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the + * Software, and to permit persons to whom the Software is furnished to do so, + * subject to the following conditions: + * + * The above copyright notice and this permission notice shall be included in all + * copies or substantial portions of the Software. + * + * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS + * FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR + * COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN + * AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION + * WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + */ +package com.vitorpamplona.amethyst.ui.screen.loggedIn.settings.cordn + +import androidx.compose.foundation.layout.Arrangement +import androidx.compose.foundation.layout.Column +import androidx.compose.foundation.layout.fillMaxSize +import androidx.compose.foundation.layout.fillMaxWidth +import androidx.compose.foundation.layout.padding +import androidx.compose.foundation.layout.size +import androidx.compose.foundation.rememberScrollState +import androidx.compose.foundation.text.selection.SelectionContainer +import androidx.compose.foundation.verticalScroll +import androidx.compose.material3.Button +import androidx.compose.material3.Card +import androidx.compose.material3.HorizontalDivider +import androidx.compose.material3.MaterialTheme +import androidx.compose.material3.OutlinedButton +import androidx.compose.material3.OutlinedTextField +import androidx.compose.material3.Scaffold +import androidx.compose.material3.Text +import androidx.compose.runtime.Composable +import androidx.compose.runtime.getValue +import androidx.compose.runtime.mutableStateOf +import androidx.compose.runtime.remember +import androidx.compose.runtime.rememberCoroutineScope +import androidx.compose.runtime.setValue +import androidx.compose.ui.Alignment +import androidx.compose.ui.Modifier +import androidx.compose.ui.platform.LocalContext +import androidx.compose.ui.unit.dp +import androidx.lifecycle.compose.collectAsStateWithLifecycle +import com.vitorpamplona.amethyst.R +import com.vitorpamplona.amethyst.commons.cordn.CordnMigration +import com.vitorpamplona.amethyst.commons.resources.Res +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_cancel +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_cancel_desc +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_code_note +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_done +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_explainer +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_export +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_exporting +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_exposure_body +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_exposure_title +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_handed_off +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_handed_off_desc +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_import +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_importing +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_no_groups +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_no_server +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_paste +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_receive +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_replaces_warning +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_scan +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_scan_this +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_sign_in_first +import com.vitorpamplona.amethyst.commons.resources.cordn_migrate_title +import com.vitorpamplona.amethyst.model.cordn.AndroidCordnBlobStore +import com.vitorpamplona.amethyst.model.cordn.CordnRuntime +import com.vitorpamplona.amethyst.ui.navigation.navs.INav +import com.vitorpamplona.amethyst.ui.navigation.topbars.TopBarWithBackButton +import com.vitorpamplona.amethyst.ui.screen.loggedIn.AccountViewModel +import com.vitorpamplona.amethyst.ui.screen.loggedIn.qrcode.QrCodeDrawer +import com.vitorpamplona.amethyst.ui.screen.loggedIn.qrcode.SimpleQrCodeScanner +import com.vitorpamplona.amethyst.ui.stringRes +import com.vitorpamplona.quartz.cordn.appMultiDevice.CordnHandoffCode +import kotlinx.coroutines.launch + +/** + * Moving this account's cordn groups to a phone the user is switching to. + * + * ## Why this is a handoff and not sync + * + * `spec/applications/multi-device.md` §10 leaves one case unresolved: two + * devices of one identity committing inside a single delivery round-trip reach + * the same epoch with different states, and §15 concedes that equal-epoch MLS + * states have no merge function. This screen is buildable because a migration + * has one writer — which is only true if this device stops afterwards, which + * is what the handed-off state below is. + * + * ## What the user is told, and where + * + * Two things are said at the moment they are decided rather than in a help + * page. Before exporting: the encrypted documents leave the device for a + * storage server. Before importing: this replaces whatever cordn groups are + * already here, because MLS state cannot be merged. Both are irreversible in + * the ways that matter, and neither is discoverable afterwards. + */ +@Composable +fun CordnMigrateScreen( + accountViewModel: AccountViewModel, + nav: INav, +) { + val runtime = accountViewModel.account.cordnRuntime + + Scaffold( + topBar = { TopBarWithBackButton(stringRes(Res.string.cordn_migrate_title), nav) }, + ) { padding -> + if (runtime == null) { + Column(Modifier.fillMaxSize().padding(padding).padding(24.dp)) { + Text(stringRes(R.string.cordn_group_unavailable)) + } + return@Scaffold + } + + val handedOff by runtime.handoff.handedOff.collectAsStateWithLifecycle() + + Column( + modifier = + Modifier + .padding(padding) + .fillMaxSize() + .verticalScroll(rememberScrollState()) + .padding(16.dp), + verticalArrangement = Arrangement.spacedBy(12.dp), + ) { + if (handedOff) { + HandedOff(runtime) + return@Column + } + + Text( + text = stringRes(Res.string.cordn_migrate_explainer), + style = MaterialTheme.typography.bodyMedium, + color = MaterialTheme.colorScheme.onSurfaceVariant, + ) + + SendSide(runtime, accountViewModel) + + HorizontalDivider(Modifier.padding(vertical = 8.dp)) + + ReceiveSide(runtime, accountViewModel) + } + } +} + +/** + * The state that makes the rest of this safe. + * + * Deliberately not phrased as an error. Nothing is broken and nothing was + * deleted — the device stood down on purpose, and the groups are still on + * disk so taking it back is possible. + */ +@Composable +private fun HandedOff(runtime: CordnRuntime) { + val scope = rememberCoroutineScope() + var busy by remember { mutableStateOf(false) } + + Card(Modifier.fillMaxWidth()) { + Column(Modifier.padding(16.dp), verticalArrangement = Arrangement.spacedBy(8.dp)) { + Text(stringRes(Res.string.cordn_migrate_handed_off), style = MaterialTheme.typography.titleSmall) + Text( + text = stringRes(Res.string.cordn_migrate_handed_off_desc), + style = MaterialTheme.typography.bodySmall, + color = MaterialTheme.colorScheme.onSurfaceVariant, + ) + } + } + + Text( + text = stringRes(Res.string.cordn_migrate_cancel_desc), + style = MaterialTheme.typography.labelSmall, + color = MaterialTheme.colorScheme.onSurfaceVariant, + ) + + OutlinedButton( + onClick = { + busy = true + scope.launch { + try { + runtime.cancelHandOff() + } finally { + busy = false + } + } + }, + enabled = !busy, + modifier = Modifier.fillMaxWidth(), + ) { + Text(stringRes(Res.string.cordn_migrate_cancel)) + } +} + +@Composable +private fun SendSide( + runtime: CordnRuntime, + accountViewModel: AccountViewModel, +) { + val scope = rememberCoroutineScope() + val context = LocalContext.current + var code by remember { mutableStateOf(null) } + var error by remember { mutableStateOf(null) } + var busy by remember { mutableStateOf(false) } + val noServer = stringRes(Res.string.cordn_migrate_no_server) + val noGroups = stringRes(Res.string.cordn_migrate_no_groups) + + Text( + text = stringRes(Res.string.cordn_migrate_sign_in_first), + style = MaterialTheme.typography.bodySmall, + color = MaterialTheme.colorScheme.onSurfaceVariant, + ) + + // Said before the button, because this is the moment the decision is made + // and the upload cannot be taken back afterwards. + Card(Modifier.fillMaxWidth()) { + Column(Modifier.padding(16.dp), verticalArrangement = Arrangement.spacedBy(4.dp)) { + Text(stringRes(Res.string.cordn_migrate_exposure_title), style = MaterialTheme.typography.titleSmall) + Text( + text = stringRes(Res.string.cordn_migrate_exposure_body), + style = MaterialTheme.typography.bodySmall, + color = MaterialTheme.colorScheme.onSurfaceVariant, + ) + } + } + + code?.let { + Column( + modifier = Modifier.fillMaxWidth(), + horizontalAlignment = Alignment.CenterHorizontally, + verticalArrangement = Arrangement.spacedBy(8.dp), + ) { + Text(stringRes(Res.string.cordn_migrate_scan_this), style = MaterialTheme.typography.titleSmall) + QrCodeDrawer(it, Modifier.size(260.dp)) + SelectionContainer { Text(it, style = MaterialTheme.typography.labelSmall) } + Text( + text = stringRes(Res.string.cordn_migrate_code_note), + style = MaterialTheme.typography.labelSmall, + color = MaterialTheme.colorScheme.onSurfaceVariant, + ) + } + } + + error?.let { Text(it, style = MaterialTheme.typography.bodyMedium, color = MaterialTheme.colorScheme.error) } + + Button( + onClick = { + busy = true + error = null + scope.launch { + try { + val servers = listOfNotNull(accountViewModel.account.settings.defaultFileServer.baseUrl) + if (servers.isEmpty()) { + error = noServer + return@launch + } + if (runtime.migrationSnapshot().groups.isEmpty()) { + error = noGroups + return@launch + } + + val migration = + CordnMigration( + accountViewModel.account.client, + accountViewModel.account.signer, + AndroidCordnBlobStore(servers, context), + ) + code = runtime.handOff(migration, accountViewModel.account.outboxRelays.flow.value).encode() + } catch (e: Exception) { + error = e.message + } finally { + busy = false + } + } + }, + enabled = !busy && code == null, + modifier = Modifier.fillMaxWidth(), + ) { + Text(stringRes(if (busy) Res.string.cordn_migrate_exporting else Res.string.cordn_migrate_export)) + } +} + +@Composable +private fun ReceiveSide( + runtime: CordnRuntime, + accountViewModel: AccountViewModel, +) { + val scope = rememberCoroutineScope() + val context = LocalContext.current + var typed by remember { mutableStateOf("") } + var scanning by remember { mutableStateOf(false) } + var busy by remember { mutableStateOf(false) } + var error by remember { mutableStateOf(null) } + var done by remember { mutableStateOf(null) } + val badCode = stringRes(Res.string.cordn_migrate_scan) + + Text(stringRes(Res.string.cordn_migrate_receive), style = MaterialTheme.typography.titleSmall) + + // Said before the button, for the same reason as the exposure card: an + // import replaces, and MLS state cannot be merged back afterwards. + Text( + text = stringRes(Res.string.cordn_migrate_replaces_warning), + style = MaterialTheme.typography.bodySmall, + color = MaterialTheme.colorScheme.onSurfaceVariant, + ) + + if (scanning) { + SimpleQrCodeScanner { + scanning = false + if (it != null) typed = it + } + } + + OutlinedButton(onClick = { scanning = true }, modifier = Modifier.fillMaxWidth()) { + Text(stringRes(Res.string.cordn_migrate_scan)) + } + + OutlinedTextField( + value = typed, + onValueChange = { + typed = it + error = null + }, + label = { Text(stringRes(Res.string.cordn_migrate_paste)) }, + singleLine = true, + modifier = Modifier.fillMaxWidth(), + ) + + done?.let { Text(stringRes(Res.string.cordn_migrate_done, it), style = MaterialTheme.typography.bodyMedium) } + error?.let { Text(it, style = MaterialTheme.typography.bodyMedium, color = MaterialTheme.colorScheme.error) } + + Button( + onClick = { + val parsed = CordnHandoffCode.decodeOrNull(typed.trim()) + if (parsed == null) { + error = badCode + return@Button + } + busy = true + error = null + scope.launch { + try { + val migration = + CordnMigration( + accountViewModel.account.client, + accountViewModel.account.signer, + AndroidCordnBlobStore(emptyList(), context), + ) + val snapshot = migration.fetch(parsed) + runtime.adoptMigration(snapshot) + done = snapshot.groups.size + typed = "" + } catch (e: Exception) { + error = e.message + } finally { + busy = false + } + } + }, + enabled = !busy && typed.isNotBlank(), + modifier = Modifier.fillMaxWidth(), + ) { + Text(stringRes(if (busy) Res.string.cordn_migrate_importing else Res.string.cordn_migrate_import)) + } +} diff --git a/commonsUI/src/commonMain/composeResources/values/strings.xml b/commonsUI/src/commonMain/composeResources/values/strings.xml index 1466792b78..05c43f4914 100644 --- a/commonsUI/src/commonMain/composeResources/values/strings.xml +++ b/commonsUI/src/commonMain/composeResources/values/strings.xml @@ -5392,4 +5392,45 @@ The coordinator learns who is in the group and when you talk, even though it cannot read what you say. Invited to a cordn group? Review invitations + + + cordn + cordn coordinator group mls chat migrate backup key package link move device + Groups delivered by a coordinator you choose, instead of by relays. + Inspect a group link + See what a cordn1… link points at before you act on it + Coordinators + The servers that carry your groups + Key packages + What lets people add you to a group + Backup and restore + A passphrase-encrypted file you keep + Move to a new phone + Hand your groups to a device you are switching to + + Move to a new phone + cordn migrate move new phone device transfer handoff switch qr + Your cordn groups live on this device. Moving them takes one code: this phone publishes them, the new phone reads them, and this phone stops. + Sign in with the same account on the new phone first. This moves your groups, never your key. + Start the handoff + Publishing… + Scan this on the new phone + The code is only a pointer. Anyone who photographs it learns nothing — what it points at is encrypted to you. + This device has handed its groups over + It has stopped sending and receiving, because two phones sending from one group would break it for everyone in it. Your groups are still on this device and nothing was deleted. + Take this device back + Use this if the move did not finish. Only do it if the new phone has not started sending. + Receive from another phone + Scan the code + or paste it + Bring the groups here + Fetching… + This replaces any cordn groups already on this phone. They cannot be merged. + %1$d groups moved + There are no cordn groups on this device to move. + Set a media server first — the encrypted documents need somewhere to sit while the other phone fetches them. + What leaves this device + Your group state is encrypted and uploaded to your media server so the other phone can fetch it. It is unreadable to that server, which sees only a size and a time. Delete the blobs afterwards if you want nothing left behind.