Files
vnidrop/apple/VniDrop/Core/SavedDeviceModels.swift
cdricms 8bb1442338 feat(apple): saved devices and targeted transfers UI
Adds the native SwiftUI Saved Devices experience on top of the production
saved-device core, as a top-level destination in the iOS tab bar and the
macOS sidebar.

Core seam:
- App-facing saved-device domain models mirroring core/SavedDeviceModels.kt,
  with lifecycle helpers (canReceive/canResume/canCancel/canDelete) so views
  never hand-roll state checks.
- 21 gateway methods through CoreGateway/CoreRepository with UniFFI mapping.
  cancelTargetedTransfer, forgetSavedDevice and blockDevice run off the serial
  lane: each must reach the core while a targeted receive is blocking it.
- Payload-free pairingChanged/targetedTransferChanged signals, dispatched
  before the numeric-transferId guard since saved-device events identify
  their subject by peer endpoint or a string transfer id.

Experience:
- Screen lists saved devices and outstanding consent requests only; the
  global targeted-transfer history stays out, reachable per device.
- Details as a sheet with detents on compact layouts and a native inspector
  on macOS, owning Send, label, forget/block and that device's transfers.
- Label editing is transactional: the draft and editor survive a failed
  write, conflicting actions are refused while saving, and the editor closes
  only after the core confirms.
- Pairing and targeted-offer consent hosted at the app root, answerable from
  any tab and suppressed while a transfer approval is up. Dismissing a
  pairing prompt suppresses locally without consuming the single-use
  eligibility; dismissing an offer declines it, since an unanswered offer
  holds a slot in the core's bounded per-sender queue.
- Targeted send reuses the invitation composer's affordances with file,
  folder, rename, replace and cleanup parity. Picker copies are released on
  replace/remove/clear/cancel and after a successful create, but kept after a
  failure so retry does not require re-picking.
- Notifications for pairing requests and offers (withdrawn once answered) and
  for terminal targeted transfers. Wording follows direction: on the sending
  device the peer finished receiving, not us.

Localization:
- Widens 52 saved-device keys from kmp-only to both platforms.
- Five keys carried a literal %1$s with no declared args, which Compose
  renders positionally but the Apple generator emits as a plain constant,
  leaking the placeholder into the UI. They now use named args; Compose
  output is byte-identical.
- Adds targeted_offer_title/body. Reusing the invitation approval copy stated
  the roles backwards, announcing the sender as the receiver.

Also surfaces core startup failures: the startup overlay is drawn above the
snackbar host, so a failed initialize() was indistinguishable from an app
that never finished loading. AppModel now keeps the reason, logs it, and the
overlay shows it with a retry, plus the technical detail in DEBUG builds.

Send and receive between two devices is verified only partially; a missing
endpoint-identity credential currently blocks startup on the test device.
2026-08-13 19:42:37 +02:00

183 lines
6.0 KiB
Swift

import Foundation
/// App-facing saved-device domain models, ported from `core/SavedDeviceModels.kt`.
/// The repository maps the generated UniFFI records into these so the UI never
/// depends on the binding surface directly.
///
/// A saved device is a remote VniDrop *app-installation identity*, not a person,
/// account, or piece of hardware. Display names and platform hints are untrusted
/// peer-supplied hints and must never be used to merge or match identities.
struct SavedDeviceModel: Equatable, Identifiable, Sendable {
/// The remote iroh endpoint identity. Stable, cryptographic, and the only
/// safe way to identify a peer.
let endpointId: String
/// User-owned local label. Takes precedence over `remoteDisplayName`.
let localLabel: String?
/// Untrusted display-name hint supplied by the peer.
let remoteDisplayName: String?
let createdAt: Int64
let lastAuthenticatedAt: Int64?
var id: String { endpointId }
/// The name to show, or nil when neither side supplied one. Callers fall back
/// to `L10n.SavedDevices.unnamed` (see `SavedDeviceTransferHistory.kt`).
var displayNameOrNil: String? {
if let localLabel, !localLabel.trimmed.isEmpty { return localLabel }
if let remoteDisplayName, !remoteDisplayName.trimmed.isEmpty { return remoteDisplayName }
return nil
}
}
/// Durable consent lifecycle for one remote app-installation identity. A
/// relationship is usable only in `saved`; the pending states are bounded
/// operations that cannot initiate a transfer.
enum DeviceRelationshipStateModel: Equatable, Sendable {
case pendingOutgoing
case pendingIncoming
case saved
case revoked
case blocked
}
struct DeviceRelationshipModel: Equatable, Identifiable, Sendable {
let remoteEndpointId: String
let state: DeviceRelationshipStateModel
let generation: UInt64
let minimumProtocolVersion: UInt16
let createdAt: Int64
let updatedAt: Int64
var id: String { remoteEndpointId }
}
/// Single-use permission to *ask* to pair, created by a fully completed
/// authenticated transfer and expiring 24 hours later. Consumed by pairing,
/// declining, expiry, forget, block, or reset.
struct PairingEligibilityModel: Equatable, Identifiable, Sendable {
let peerEndpointId: String
/// Untrusted display-name hint from the qualifying transfer. Usually the only
/// name available for a peer that is not saved yet.
let remoteDisplayName: String?
let sessionId: String
let protocolVersion: UInt16
let createdAt: Int64
let expiresAt: Int64
var id: String { peerEndpointId }
}
/// A pre-approval targeted offer awaiting a local approve/decline. Lives only in
/// the core's bounded live-session queue a restart, timeout, disconnect, or
/// sender cancellation removes it, so it is never durable UI state.
struct PendingTargetedOfferModel: Equatable, Identifiable, Sendable {
let transferId: String
let senderEndpointId: String
let receiverEndpointId: String
let manifestId: String
let contentHash: String
/// Peer-supplied and untrusted; render it as text, never as a path.
let transferName: String
let fileCount: UInt64
let totalSize: UInt64
let protocolVersion: UInt16
let receivedAt: Int64
var id: String { transferId }
}
/// Durable targeted-transfer lifecycle. Rust validates every transition; the UI
/// only invokes typed operations and renders the snapshot it gets back.
enum TargetedTransferStateModel: Equatable, Sendable {
case preparing
case offering
case awaitingApproval
case approved
case connecting
case transferring
case interrupted
case completed
case declined
case cancelled
case failed
case deleted
}
struct TargetedTransferModel: Equatable, Identifiable, Sendable {
let id: String
let senderEndpointId: String
let receiverEndpointId: String
let manifestId: String
/// Peer-supplied and untrusted; render it as text, never as a path.
let transferName: String
let fileCount: UInt64
let totalSize: UInt64
/// Bytes verified so far; survives interruption for resume.
let verifiedBytes: UInt64
let state: TargetedTransferStateModel
let createdAt: Int64
let updatedAt: Int64
}
/// Outcome of responding to a targeted offer. `alreadySettled` is the idempotent
/// replay path the core returns the existing result rather than creating a
/// duplicate approval.
enum TargetedOfferResponseModel: Equatable, Sendable {
case approved(transferId: String)
case declined
case alreadySettled(transferId: String)
}
// MARK: - Lifecycle helpers
extension TargetedTransferStateModel {
/// States where bytes may still move, so progress is meaningful.
var isActive: Bool {
switch self {
case .connecting, .transferring: return true
default: return false
}
}
/// No further transition is possible without creating a new transfer.
var isTerminal: Bool {
switch self {
case .completed, .declined, .cancelled, .failed, .deleted: return true
default: return false
}
}
/// Cancellation withdraws the offer before approval and stops authorization
/// plus active streaming after it. Terminal transfers have nothing to stop.
var canCancel: Bool { !isTerminal }
/// An interrupted transfer keeps its verified progress and resumes the same
/// immutable transfer without asking for approval again.
var canResume: Bool { self == .interrupted }
/// The receiver pulls content once the sender's authorization is in place.
var canReceive: Bool { self == .approved }
/// Deletion makes authorization unusable and removes resumable state. Offered
/// on anything already terminal except an entry that is itself deleted.
var canDelete: Bool { isTerminal && self != .deleted }
}
extension TargetedTransferModel {
/// Fraction of verified payload in `0...1`, or nil when the total is unknown
/// or the state carries no meaningful progress.
var progressFraction: Double? {
guard totalSize > 0, state.isActive || state == .interrupted else { return nil }
return min(1, Double(verifiedBytes) / Double(totalSize))
}
}
extension PairingEligibilityModel {
func isExpired(now: Int64) -> Bool { now >= expiresAt }
}
private extension String {
var trimmed: String { trimmingCharacters(in: .whitespacesAndNewlines) }
}