feat(sharing): make going online opt-in, and show what it unlocks

Tane dialled its four default relays at launch, before anyone had asked
for anything — an F-Droid reviewer spotted it, and they were right. The
seed book needs no network at all, so the app should not have one until
the person joins the sharing side.

- SocialSettings gains a three-state `sharingEnabled`. `null` means
  "never asked", which is what lets `migrateSharingEnabled` keep an
  existing install exactly as it was: anyone past the intro was on a
  build that connected at launch, so they keep messaging, device sync
  and offer alerts. A fresh install starts fully offline.
- bootstrap only starts the shared connection when sharing is on. The
  inbox/sync/plantaré/alert listeners are untouched: they react to a
  session, and none arrives.
- SharingSwitch is the single place that moves the stored choice, the
  live connection and the flag the UI listens to, so they cannot drift.
- Agreeing to the community rules is the opt-in — one consent surface,
  reached from the market or from the drawer's invitation.
- SocialConnection.start is now idempotent and gains stop(), so turning
  sharing off goes offline immediately instead of at the next launch.
- The social drawer entries stay visible but padlocked while sharing is
  off; tapping one explains what wakes up and offers to join. Hiding
  them would have kept the tool a secret. "Coming soon" is gone for
  good — everything it labelled is built.

Covered by tests for the migration in both directions, start/stop
lifecycle, the gate turning sharing on, the invitation, and the drawer
in all three states (no social layer / off / on).
This commit is contained in:
vjrj 2026-07-25 16:47:56 +02:00
parent 62123582f5
commit fed0e8200e
35 changed files with 926 additions and 173 deletions

View file

@ -0,0 +1,46 @@
import 'package:flutter/foundation.dart';
import 'social_connection.dart';
import 'social_settings.dart';
/// The one place that turns the sharing side of Tane on and off.
///
/// Sharing is opt-in: until someone joins it, the app opens no connection at
/// all and the seed book is entirely offline. Joining has to move three things
/// at once the stored choice, the live relay connection, and the flag the UI
/// listens to and doing that from several screens is how they drift apart.
/// So every caller (the community-rules gate, the invite sheet, the sharing
/// setup) goes through here instead.
class SharingSwitch {
SharingSwitch({
required SocialSettings settings,
SocialConnection? connection,
bool enabled = false,
}) : _settings = settings,
_connection = connection,
on = ValueNotifier(enabled);
final SocialSettings _settings;
final SocialConnection? _connection;
/// Whether sharing is on right now. Screens listen so the drawer's social
/// entries light up the moment someone joins, with no restart.
final ValueNotifier<bool> on;
Future<void> enable() async {
await _settings.setSharingEnabled(true);
// Safe to call even if it is already running: `start` guards itself.
_connection?.start();
on.value = true;
}
/// Turning it off must actually go offline closing the live session, not
/// just recording the choice for the next launch.
Future<void> disable() async {
await _settings.setSharingEnabled(false);
await _connection?.stop();
on.value = false;
}
void dispose() => on.dispose();
}