feat(sharing): make going online opt-in, and show what it unlocks

Tane dialled its four default relays at launch, before anyone had asked
for anything — an F-Droid reviewer spotted it, and they were right. The
seed book needs no network at all, so the app should not have one until
the person joins the sharing side.

- SocialSettings gains a three-state `sharingEnabled`. `null` means
  "never asked", which is what lets `migrateSharingEnabled` keep an
  existing install exactly as it was: anyone past the intro was on a
  build that connected at launch, so they keep messaging, device sync
  and offer alerts. A fresh install starts fully offline.
- bootstrap only starts the shared connection when sharing is on. The
  inbox/sync/plantaré/alert listeners are untouched: they react to a
  session, and none arrives.
- SharingSwitch is the single place that moves the stored choice, the
  live connection and the flag the UI listens to, so they cannot drift.
- Agreeing to the community rules is the opt-in — one consent surface,
  reached from the market or from the drawer's invitation.
- SocialConnection.start is now idempotent and gains stop(), so turning
  sharing off goes offline immediately instead of at the next launch.
- The social drawer entries stay visible but padlocked while sharing is
  off; tapping one explains what wakes up and offers to join. Hiding
  them would have kept the tool a secret. "Coming soon" is gone for
  good — everything it labelled is built.

Covered by tests for the migration in both directions, start/stop
lifecycle, the gate turning sharing on, the invitation, and the drawer
in all three states (no social layer / off / on).
This commit is contained in:
vjrj 2026-07-25 16:47:56 +02:00
parent 62123582f5
commit fed0e8200e
35 changed files with 926 additions and 173 deletions

View file

@ -3,17 +3,29 @@ import 'package:go_router/go_router.dart';
import '../i18n/strings.g.dart';
import '../services/onboarding_store.dart';
import '../services/sharing_switch.dart';
import 'theme.dart';
/// Makes sure the community rules have been accepted once before the user
/// joins the market or publishes anything. Returns true when the rules are
/// (or become) accepted; false when the user declines. Play/App Store UGC
/// policies require this acceptance before content can be created.
///
/// This is also where Tane goes online for the first time: agreeing here is the
/// opt-in that turns [sharing] on. Keeping both in one step means there is a
/// single moment where someone says yes, and it is a moment that explains
/// itself rather than a connection that happened at launch without asking.
Future<bool> ensureMarketRulesAccepted(
BuildContext context,
OnboardingStore store,
) async {
if (await store.marketRulesAccepted()) return true;
OnboardingStore store, {
SharingSwitch? sharing,
}) async {
if (await store.marketRulesAccepted()) {
// Already agreed, but sharing may still be off (they turned it off in the
// sharing setup, or agreed on a build that had no switch): honour the ask.
if (sharing != null && !sharing.on.value) await sharing.enable();
return true;
}
if (!context.mounted) return false;
final accepted = await showModalBottomSheet<bool>(
context: context,
@ -24,6 +36,7 @@ Future<bool> ensureMarketRulesAccepted(
);
if (accepted == true) {
await store.markMarketRulesAccepted();
await sharing?.enable();
return true;
}
return false;
@ -77,6 +90,14 @@ class MarketGateSheet extends StatelessWidget {
height: 1.4,
),
),
const SizedBox(height: 8),
Text(
t.marketGate.networkNote,
style: theme.textTheme.bodySmall?.copyWith(
color: seedMuted,
height: 1.4,
),
),
TextButton.icon(
style: TextButton.styleFrom(
padding: EdgeInsets.zero,