feat(sharing): make going online opt-in, and show what it unlocks
Tane dialled its four default relays at launch, before anyone had asked for anything — an F-Droid reviewer spotted it, and they were right. The seed book needs no network at all, so the app should not have one until the person joins the sharing side. - SocialSettings gains a three-state `sharingEnabled`. `null` means "never asked", which is what lets `migrateSharingEnabled` keep an existing install exactly as it was: anyone past the intro was on a build that connected at launch, so they keep messaging, device sync and offer alerts. A fresh install starts fully offline. - bootstrap only starts the shared connection when sharing is on. The inbox/sync/plantaré/alert listeners are untouched: they react to a session, and none arrives. - SharingSwitch is the single place that moves the stored choice, the live connection and the flag the UI listens to, so they cannot drift. - Agreeing to the community rules is the opt-in — one consent surface, reached from the market or from the drawer's invitation. - SocialConnection.start is now idempotent and gains stop(), so turning sharing off goes offline immediately instead of at the next launch. - The social drawer entries stay visible but padlocked while sharing is off; tapping one explains what wakes up and offers to join. Hiding them would have kept the tool a secret. "Coming soon" is gone for good — everything it labelled is built. Covered by tests for the migration in both directions, start/stop lifecycle, the gate turning sharing on, the invitation, and the drawer in all three states (no social layer / off / on).
This commit is contained in:
parent
62123582f5
commit
fed0e8200e
35 changed files with 926 additions and 173 deletions
|
|
@ -63,8 +63,11 @@ class SocialConnection {
|
|||
SocialSession? get current => _current;
|
||||
|
||||
/// Begins watching connectivity (reconnect on regain, drop when offline) and
|
||||
/// attempts an initial connect. Idempotent-ish; call once at startup.
|
||||
/// attempts an initial connect. Called at startup when sharing is already on,
|
||||
/// and again the moment someone joins the sharing side — hence the guard, so
|
||||
/// a second call never stacks a second connectivity subscription.
|
||||
void start() {
|
||||
if (_started || _disposed) return;
|
||||
_started = true;
|
||||
_onlineSub = (_online ?? _connectivityOnline()).listen((isOnline) {
|
||||
_knownOffline = !isOnline;
|
||||
|
|
@ -139,6 +142,19 @@ class SocialConnection {
|
|||
}
|
||||
}
|
||||
|
||||
/// Goes offline for good until [start] is called again: stops watching
|
||||
/// connectivity, cancels any pending retry and tears the live session down.
|
||||
/// This is what "turn sharing off" must do — before it existed, clearing the
|
||||
/// server list only took effect on the next launch, because the already-open
|
||||
/// session was never closed. Unlike [dispose] the object stays usable.
|
||||
Future<void> stop() async {
|
||||
_started = false;
|
||||
_cancelRetry();
|
||||
await _onlineSub?.cancel();
|
||||
_onlineSub = null;
|
||||
_drop();
|
||||
}
|
||||
|
||||
Future<void> dispose() async {
|
||||
_disposed = true;
|
||||
_cancelRetry();
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue