Skip to content

feat(mobile): app-lock / lock screen with biometric unlock - #596

Open
Lazyartist1 wants to merge 1 commit into
Miracle656:mainfrom
Lazyartist1:feat/mobile-app-lock
Open

feat(mobile): app-lock / lock screen with biometric unlock#596
Lazyartist1 wants to merge 1 commit into
Miracle656:mainfrom
Lazyartist1:feat/mobile-app-lock

Conversation

@Lazyartist1

Copy link
Copy Markdown

Summary

Adds the app-lock / lock screen (backlog item 28) — the wallet locks after inactivity or when backgrounded, and a device biometric is required to return. Ports the web wallet's inactivity-lock behaviour to native AppState + expo-local-authentication, so a lost or borrowed phone doesn't expose funds.

Changes

  • lib/idleLock.ts — framework-agnostic countdown (native port of the web lib/idle-lock.ts). Pure, with an injectable clock; keeps the 5 / 15 / 30 / never options and the "defer while a transaction is in flight" behaviour.
  • hooks/useInactivityLock.ts — wires the countdown to AppState and expo-router: background locks immediately, foreground restarts the idle countdown, and either trigger routes to /lock. Re-arms off the current route so it never fights the lock screen it just pushed.
  • app/lock.tsx — lock screen. Unlock requires a real biometric via LocalAuthentication.authenticateAsync (Face ID / fingerprint, with device-passcode fallback); on success it returns to the dashboard.
  • app/_layout.tsx — mounts the lock gate once at the root, alongside the existing connectivity gate.
  • Adds the expo-local-authentication dependency (listed in the issue).

Acceptance

  • App locks after an inactivity timeout
  • App locks when backgrounded
  • Face ID / fingerprint unlocks (device-passcode fallback)

Testing

  • tsc --noEmit clean
  • jest lib/__tests__/idleLock.test.ts — 6/6 passing (timeout fires, reset postpones, stop cancels, never-disabled, defer-while-busy, ms conversion)

Closes #456

Protect the wallet when the device is idle or the app is backgrounded by
requiring a biometric to return, so a lost or borrowed phone doesn't expose
funds. Ports the web wallet's inactivity lock to native AppState and
expo-local-authentication.

- lib/idleLock.ts: framework-agnostic countdown (native port of idle-lock.ts),
  pure and injectable-clock testable, with the 5/15/30/never options and the
  defer-while-busy behaviour.
- hooks/useInactivityLock.ts: wires the countdown to AppState + expo-router —
  background locks immediately, foreground restarts the countdown, both route
  to /lock. Mounted once at the root in _layout.tsx.
- app/lock.tsx: lock screen; unlock requires a real biometric via
  LocalAuthentication.authenticateAsync (Face ID / fingerprint, device-passcode
  fallback), then returns to the dashboard.

Closes Miracle656#456
@Lazyartist1
Lazyartist1 requested a review from Miracle656 as a code owner July 30, 2026 06:54
@vercel

vercel Bot commented Jul 30, 2026

Copy link
Copy Markdown

@Lazyartist1 is attempting to deploy a commit to the miracle656's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Jul 30, 2026

Copy link
Copy Markdown

@Lazyartist1 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

28. App-lock / lock screen

1 participant