feat(apple): saved devices and targeted transfers UI

Adds the native SwiftUI Saved Devices experience on top of the production
saved-device core, as a top-level destination in the iOS tab bar and the
macOS sidebar.

Core seam:
- App-facing saved-device domain models mirroring core/SavedDeviceModels.kt,
  with lifecycle helpers (canReceive/canResume/canCancel/canDelete) so views
  never hand-roll state checks.
- 21 gateway methods through CoreGateway/CoreRepository with UniFFI mapping.
  cancelTargetedTransfer, forgetSavedDevice and blockDevice run off the serial
  lane: each must reach the core while a targeted receive is blocking it.
- Payload-free pairingChanged/targetedTransferChanged signals, dispatched
  before the numeric-transferId guard since saved-device events identify
  their subject by peer endpoint or a string transfer id.

Experience:
- Screen lists saved devices and outstanding consent requests only; the
  global targeted-transfer history stays out, reachable per device.
- Details as a sheet with detents on compact layouts and a native inspector
  on macOS, owning Send, label, forget/block and that device's transfers.
- Label editing is transactional: the draft and editor survive a failed
  write, conflicting actions are refused while saving, and the editor closes
  only after the core confirms.
- Pairing and targeted-offer consent hosted at the app root, answerable from
  any tab and suppressed while a transfer approval is up. Dismissing a
  pairing prompt suppresses locally without consuming the single-use
  eligibility; dismissing an offer declines it, since an unanswered offer
  holds a slot in the core's bounded per-sender queue.
- Targeted send reuses the invitation composer's affordances with file,
  folder, rename, replace and cleanup parity. Picker copies are released on
  replace/remove/clear/cancel and after a successful create, but kept after a
  failure so retry does not require re-picking.
- Notifications for pairing requests and offers (withdrawn once answered) and
  for terminal targeted transfers. Wording follows direction: on the sending
  device the peer finished receiving, not us.

Localization:
- Widens 52 saved-device keys from kmp-only to both platforms.
- Five keys carried a literal %1$s with no declared args, which Compose
  renders positionally but the Apple generator emits as a plain constant,
  leaking the placeholder into the UI. They now use named args; Compose
  output is byte-identical.
- Adds targeted_offer_title/body. Reusing the invitation approval copy stated
  the roles backwards, announcing the sender as the receiver.

Also surfaces core startup failures: the startup overlay is drawn above the
snackbar host, so a failed initialize() was indistinguishable from an app
that never finished loading. AppModel now keeps the reason, logs it, and the
overlay shows it with a retry, plus the technical detail in DEBUG builds.

Send and receive between two devices is verified only partially; a missing
endpoint-identity credential currently blocks startup on the test device.
This commit is contained in:
2026-08-13 19:42:37 +02:00
parent bece2af179
commit 8bb1442338
33 changed files with 3837 additions and 247 deletions

View File

@@ -9,6 +9,9 @@ struct RootView: View {
@StateObject private var sendModel: SendModel
@StateObject private var receiveModel: ReceiveModel
@StateObject private var settingsModel: SettingsModel
@StateObject private var savedDevicesModel: SavedDevicesModel
/// Held so it stays alive for the app's lifetime; it has no view of its own.
@StateObject private var savedDeviceNotifications: SavedDeviceNotificationCoordinator
@Environment(\.scenePhase) private var scenePhase
@@ -44,6 +47,21 @@ struct RootView: View {
messages: graph.messages,
bugReports: NoopBugReportService()
))
let savedDevices = SavedDevicesModel(
repository: graph.coreRepository,
fileSystemService: dependencies.fileSystemService,
preferences: graph.preferencesRepository,
messages: graph.messages
)
_savedDevicesModel = StateObject(wrappedValue: savedDevices)
// Reads the model's snapshot rather than the core directly, so it observes
// exactly the state the UI is showing.
_savedDeviceNotifications = StateObject(wrappedValue: SavedDeviceNotificationCoordinator(
model: savedDevices,
notifications: dependencies.notificationService,
visibility: graph.visibility,
messages: graph.messages
))
}
var body: some View {
@@ -52,6 +70,13 @@ struct RootView: View {
let isDark = resolveDarkTheme(appModel.themeMode, systemDark: systemDark)
ZStack {
navigation(windowClass: windowClass)
// Hosted at the root so a pairing request or targeted offer is
// answerable from any tab, and suppressed while a transfer approval
// is up so two blocking decisions never stack.
.savedDevicePrompts(
model: savedDevicesModel,
suppressed: graph.approvalCoordinator.state.current != nil
)
// Observe the coordinator/messages from the *persisted* `graph`
// StateObject. Deriving them in `init` bound the view to a throwaway
// AppGraph rebuilt on every re-init, whose coordinator never receives
@@ -68,7 +93,11 @@ struct RootView: View {
// A small, unobtrusive indicator while the core finishes its async
// startup otherwise the lists look empty and the app feels stalled.
if !sendModel.coreState.isInitialized {
CoreStartingOverlay()
CoreStartingOverlay(
error: appModel.startupError,
detail: appModel.startupErrorDetail,
onRetry: appModel.retryStartup
)
}
}
.animation(.easeInOut(duration: 0.25), value: sendModel.coreState.isInitialized)
@@ -167,6 +196,8 @@ struct RootView: View {
switch destination {
case .send: SendScreen(model: sendModel, windowClass: windowClass)
case .receive: ReceiveScreen(model: receiveModel, windowClass: windowClass)
case .savedDevices:
SavedDevicesScreen(model: savedDevicesModel, windowClass: windowClass)
case .settings:
SettingsScreen(model: settingsModel, windowClass: windowClass)
}
@@ -253,21 +284,65 @@ private struct ApprovalLayer: View {
}
}
/// A full-window cover with a centered spinner shown while the core is starting.
/// A full-window cover shown while the core is starting or, when startup fails,
/// the reason and a retry. This overlay sits above the snackbar host, so a failure
/// reported only through a toast would be invisible behind it and the app would
/// look like it was loading forever.
private struct CoreStartingOverlay: View {
let error: UiText?
/// Debug builds only; nil in Release.
let detail: String?
let onRetry: () -> Void
var body: some View {
ZStack {
backgroundColor.ignoresSafeArea()
VStack(spacing: 16) {
ProgressView().controlSize(.large)
Text(String(localized: L10n.App.starting))
.font(.headline)
.foregroundStyle(.secondary)
if let error {
VStack(spacing: 16) {
Image(systemSymbol: .exclamationmarkTriangleFill)
.font(.system(size: 34))
.foregroundStyle(.orange)
// Not "Starting": startup has stopped, and saying otherwise
// while showing an error contradicts itself.
Text(String(localized: L10n.Error.initialization))
.font(.headline)
.multilineTextAlignment(.center)
Text(error.resolved())
.font(.subheadline)
.foregroundStyle(.secondary)
.multilineTextAlignment(.center)
.textSelection(.enabled)
.frame(maxWidth: 420)
if let detail {
ScrollView {
Text(detail)
.font(.caption.monospaced())
.foregroundStyle(.secondary)
.textSelection(.enabled)
.multilineTextAlignment(.leading)
.frame(maxWidth: .infinity, alignment: .leading)
.padding(10)
}
.frame(maxWidth: 420, maxHeight: 180)
.background(.quaternary.opacity(0.5), in: RoundedRectangle(cornerRadius: 10))
}
Button(String(localized: L10n.Button.retry), action: onRetry)
.buttonStyle(.borderedProminent)
.controlSize(.large)
}
.padding(32)
} else {
VStack(spacing: 16) {
ProgressView().controlSize(.large)
Text(String(localized: L10n.App.starting))
.font(.headline)
.foregroundStyle(.secondary)
}
}
}
.transition(.opacity)
.accessibilityElement(children: .combine)
.accessibilityLabel(Text(String(localized: L10n.App.starting)))
.accessibilityLabel(Text(error?.resolved() ?? String(localized: L10n.App.starting)))
}
private var backgroundColor: Color {
@@ -284,10 +359,3 @@ import UIKit
#else
import AppKit
#endif
/// Hosts the device-history consent prompts, alongside `ApprovalLayer`.
///
/// Separate from the approval layer because the two never compete: an approval
/// belongs to a transfer this device is sending, and these belong to a device
/// asking to reach it. Both are suppressed while the other is up so the user is
/// never answering two modals at once.