mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-09 08:04:45 +00:00
Phase 5 (Desktop-only). Wraps the Messages deck column behind a PBKDF2-hashed password gate; drops the Android-app slice. - PrivacyLockSettings gains passwordHashed field + setter (salt$hash, base64). Backed by java.util.prefs on desktop. - PasswordHasher: PBKDF2-HmacSHA256, 100k iterations, 16-byte salt, 256-bit key, constant-time compare. Same primitive family as SecureKeyStorage. - DesktopMessagesLockGate: synchronous branch select in composition (no LaunchedEffect guard) — closes the deep-link race per plan §Security Hardening H1. Renders content when Disabled/Unlocked; renders inline password TextField when Locked. Fires MessagesLockState.onLeaveRoute() in DisposableEffect onDispose so navigating away from the Messages column re-locks immediately. - DesktopMessagesLockGate handles the "no password set" edge case with a Disable-lock affordance. - LocalPrivacyLockSettings CompositionLocal + LocalMessagesLockState (from commons) both provided once at the App composition root in Main.kt. Constructed with the existing windowScope so the state holder's idle timer coroutines are lifecycle-scoped to the Window. - DeckColumnContainer: DesktopMessagesScreen wrapped in DesktopMessagesLockGate for the Messages column. - Desktop PrivacyLockSettingsScreen: Column + Card layout matching LocalRelaySettingsScreen (no Scaffold). Toggle, "Change password" affordance with a full set/change dialog (old + new + confirm), inactivity timer dropdown (1m / 5m / 15m / 1h / Never), redaction level dropdown (Hidden / Full), honest limitations copy. Auto-opens the set-password dialog if user toggles ON with no password set. - Slotted into the existing Settings pane in Main.kt right after LocalRelaySettings.