feat(sharing): make going online opt-in, and show what it unlocks

Tane dialled its four default relays at launch, before anyone had asked
for anything — an F-Droid reviewer spotted it, and they were right. The
seed book needs no network at all, so the app should not have one until
the person joins the sharing side.

- SocialSettings gains a three-state `sharingEnabled`. `null` means
  "never asked", which is what lets `migrateSharingEnabled` keep an
  existing install exactly as it was: anyone past the intro was on a
  build that connected at launch, so they keep messaging, device sync
  and offer alerts. A fresh install starts fully offline.
- bootstrap only starts the shared connection when sharing is on. The
  inbox/sync/plantaré/alert listeners are untouched: they react to a
  session, and none arrives.
- SharingSwitch is the single place that moves the stored choice, the
  live connection and the flag the UI listens to, so they cannot drift.
- Agreeing to the community rules is the opt-in — one consent surface,
  reached from the market or from the drawer's invitation.
- SocialConnection.start is now idempotent and gains stop(), so turning
  sharing off goes offline immediately instead of at the next launch.
- The social drawer entries stay visible but padlocked while sharing is
  off; tapping one explains what wakes up and offers to join. Hiding
  them would have kept the tool a secret. "Coming soon" is gone for
  good — everything it labelled is built.

Covered by tests for the migration in both directions, start/stop
lifecycle, the gate turning sharing on, the invitation, and the drawer
in all three states (no social layer / off / on).
This commit is contained in:
vjrj 2026-07-25 16:47:56 +02:00
parent 62123582f5
commit fed0e8200e
35 changed files with 926 additions and 173 deletions

View file

@ -181,4 +181,70 @@ void main() {
expect(await conn.session(), isNotNull); // succeeds on retry
await conn.dispose();
});
test('start is idempotent: a second call adds no second connect', () async {
// Joining sharing calls start() while bootstrap may already have, so a
// repeat must not stack another connectivity subscription or dial again.
final opened = <FakeChannel>[];
final online = StreamController<bool>.broadcast();
final conn = make(opened: opened, online: online.stream);
conn.start();
await conn.session();
conn.start();
await Future<void>.delayed(Duration.zero);
expect(opened, hasLength(1));
// One subscription, so one drop not two competing reactions.
online.add(false);
await Future<void>.delayed(Duration.zero);
expect(conn.current, isNull);
expect(opened.first.closed, isTrue);
await conn.dispose();
await online.close();
});
test('stop goes offline now, not at the next launch', () async {
// Turning sharing off used to leave the live session open until restart.
final opened = <FakeChannel>[];
final online = StreamController<bool>.broadcast();
final conn = make(opened: opened, online: online.stream);
final emitted = <SocialSession?>[];
conn.sessions.listen(emitted.add);
conn.start();
expect(await conn.session(), isNotNull);
await conn.stop();
await Future<void>.delayed(Duration.zero); // let the drop be announced
expect(conn.current, isNull);
expect(opened.single.closed, isTrue);
expect(emitted.last, isNull);
// And it stays off: a connectivity event must not resurrect it.
online.add(true);
await Future<void>.delayed(Duration.zero);
expect(conn.current, isNull);
expect(opened, hasLength(1));
await conn.dispose();
await online.close();
});
test('stop leaves the connection usable: start brings it back', () async {
final opened = <FakeChannel>[];
final online = StreamController<bool>.broadcast();
final conn = make(opened: opened, online: online.stream);
conn.start();
await conn.session();
await conn.stop();
conn.start();
await Future<void>.delayed(Duration.zero);
expect(conn.current, isNotNull);
expect(opened, hasLength(2));
await conn.dispose();
await online.close();
});
}