mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 19:28:25 +00:00
Toggling the Messages lock OFF now prompts for the current password via a new RemovePasswordDialog. On successful verification, the password hash is cleared AND the lock is disabled — re-enabling later requires setting a fresh password. Rationale: a user should not be able to disable the lock without proving they know the password. Clearing the hash on remove prevents a "silent re-enable" attack where someone toggles OFF then ON again and inherits the old password. Matches Signal PIN, WhatsApp Chat Lock, macOS FileVault disable posture. - New RemovePasswordDialog in SetPasswordDialog.kt: single Current password field, reveal toggle, red "Remove" button (colorScheme.error), Cancel + Escape dismiss. Auto-focus + Enter submits. Uses the same Dialog+Surface+DialogHeader shell as SetPasswordDialog. - DialogHeader refactored to take a title String (was isChange Bool). - PrivacyLockSettingsScreen toggle-off path routes through the new dialog when a hash exists. Corner case (lockEnabled=true but no hash — user manually cleared prefs) still disables directly. - On successful remove: setLockEnabled(false) + setPasswordHashed(null) + "Privacy lock removed" snackbar.