Restructure the backup IA around a single Backups hub - #574
Merged
Merged
Conversation
Users read "Generate Key" as password generation; the button derives an encryption key from the typed password. Rename the action to "Set Backup Password", show derivation as progress with distinct cancelled/error copy, and re-copy the About details to match. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AutoBackupSettingsView vended a Section into the Backup form, which made its enabled/error states unreachable from snapshot tests and buried the destination behind the toggle. It becomes AutoBackupView, a pushed screen backed by AutoBackupViewModel: - state seeded synchronously (the service publishers do not replay), with injectable provider states for tests — the initial-state refactor deferred in #573 - destination row shows provider name and folder, not just the folder leaf, with an explicit Change affordance - provider configure failures surface as an error row with a recovery suggestion; previously swallowed by an empty catch - activeProvider resolves from configuration.providerID instead of hardcoding availableProviders.first Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Two sidebar peers split one feature: "Backup" stacked password management, auto-backup, PDF export, and device transfer in a single form, while "Restore" lived elsewhere. Replace both with a "Backups" sidebar item opening BackupHomeView: a last-backup status banner (revives the orphaned LastBackupSummaryView) and rows for Auto-Backup, Export, Restore, and Backup Password. The hub is reachable without device auth — it exposes navigation and backup recency only. Every key-touching surface (export, auto-backup, password change, restore imports) authenticates on entry exactly as before. BackupCreateView becomes BackupExportView (PDF + transfer only); its strings-only view model and the orphaned xcstrings keys are deleted. LastBackupSummaryView takes an injectable "now" so the staleness snapshots are deterministic. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Hide "Set Backup Password" until a password is entered and move it into the entry section, mirroring how the confirm field reveals. The status footer joins the section footer. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The backup surface was split across two sidebar peers ("Backup" and "Restore"), with the Backup screen stacking four unrelated jobs — password management, inline auto-backup settings, PDF export, and device transfer — into one form. The password screen's "Generate Key" action also read as password generation when it actually derives an encryption key from a typed password. This PR restructures the IA:
LastBackupSummaryView) plus rows for Auto-Backup, Export, Restore, and Backup Password.BackupCreateViewbecomesBackupExportView(PDF + device transfer only); its strings-only view model and nine orphaned xcstrings keys are deleted.AutoBackupViewModel(the initial-state-injection refactor deferred in Snapshot the rebuilt backup and encryption-edit screens #573): state is seeded synchronously from the service, provider states are injectable for tests, the destination row shows provider name + folder with a "Change" affordance, folder-configure failures surface as an error row with a recovery suggestion (previously swallowed by an emptycatch), and the active provider resolves from configuration instead of a hardcodedavailableProviders.first.Manifesto review
Reviewed against
MANIFESTO.md, corollary by corollary, since backups are explicitly governed by it. This is a navigation and copy restructure: backup payloads, encryption, and every action's mechanics are untouched. C1 — no bulk operation added; nothing touches per-item safety fields. C2/C3 — no new logging, telemetry, or error channels near duress features; the one new error surface (auto-backup folder configuration failures, previously swallowed by an emptycatch) reports storage-provider errors only. C4 — device authentication still gates every operation that loads or uses the backup key: export, password set/change, the auto-backup screen, and restore imports all authenticate exactly as before; the new un-gated hub adds navigation, not capability. C5 — the hub banner shows backup recency and kind, never contents; no enumeration of protected items. C6 — no undo, no audit surface. C7 — no protective default flipped; auto-backup remains opt-in and its configuration remains behind device auth. C8 — no sensitive operation lost a step: merging the sidebar items removes a hop between two navigation screens, while every export, restore, and password flow retains its full sequence including authentication; the password screen reframe changes verbs ("Generate Key" → "Set Backup Password"), not gates. C9 — backup surfaces never referenced duress features; unchanged. C10 — backup, export, and transfer payloads are byte-identical. One visibility change flagged deliberately: the last-backup banner (date + kind) is now visible without device auth, where the old Backup screen showed nothing pre-auth. Weighed against C4/C7: the same fact is already discoverable without auth (the Restore screen is un-gated today; auto-backup files are visible in the Files app), the banner reveals neither destination, contents, nor protected-item structure, and surfacing backup staleness is itself a data-loss protection.Testing
iOSAllTestsplan passes locally on iPhone 18 Pro Max / iOS 27.0.AutoBackupViewModelTests(19 tests),AutoBackupViewSnapshotTests(7 scenarios — the coverage Snapshot the rebuilt backup and encryption-edit screens #573 deferred),LastBackupSummaryViewSnapshotTests(4, with an injectablenowfor deterministic staleness).BackupKeyChangeViewSnapshotTests,BackupViewSnapshotTests(hub + export),VaultMainNavigationViewSnapshotTests..fileImporter— needs one manual run with iCloud Drive.🤖 Generated with Claude Code