Files
sure/mobile/lib/providers/privacy_provider.dart
ghost 401cd6ab08 feat(mobile): privacy mode to mask money values (#2386)
* feat(mobile): add privacy mode to mask money values

Adds an app-wide "privacy mode" so users can hide monetary amounts from
over-the-shoulder view.

- PrivacyProvider (ChangeNotifier) backed by PreferencesService, so the
  choice persists across launches and every money widget rebuilds on
  toggle.
- MoneyMasker.mask() collapses an amount's numeric portion into a short
  fixed run of bullets while keeping the currency symbol and sign
  (e.g. CA$1,234.56 -> CA$••••). A fixed run avoids leaking the value's
  magnitude and reads cleanly without stray separators. Currency- and
  locale-agnostic — it operates on already-formatted strings.
- Masking applied at every money render site: net worth + per-currency
  totals + breakdown sheet (NetWorthCard), account balances (AccountCard,
  AccountDetailHeader, transaction form account selector), and transaction
  amounts (transactions list, recent transactions, calendar).
- Two entry points: a "Hide amounts" switch in Settings -> Security, and a
  quick eye toggle in the top bar (visible on every tab).

Tests: MoneyMasker unit tests (fixed-run mask, magnitude hidden, symbol/
sign kept, passthrough, idempotent) + a widget test asserting the net
worth masks/unmasks as the provider flips; account_card_test updated to
provide the new provider. flutter analyze: no new issues; full suite
(123) green.

* fix(mobile): address privacy-mode review feedback

- Startup masking (Codex P1): read the privacy preference in main() before
  runApp and seed PrivacyProvider with it, so the first frame already has
  the correct value — money is never briefly rendered unmasked for a user
  who enabled "Hide amounts". Provider stays fail-closed otherwise: starts
  masked, SureApp's no-arg default is masked, and a failed read keeps it
  masked. A late-completing initial load no longer clobbers an explicit
  user toggle.
- setHidden() reverts the in-memory state (and logs) if persistence fails,
  keeping the UI consistent with what's actually stored.
- Mask the cash-balance detail chip in AccountDetailHeader (was leaking
  the cash position in privacy mode).
- Privacy top-bar toggle gets a "Toggle privacy" tooltip + icon semantic
  label for accessibility (kept as an InkWell to match the adjacent
  settings control).
- Tests: assert fail-closed initial state; assert the exact masked count;
  test the persistence round-trip (set -> reload); add
  PreferencesService.resetForTest() and reset between tests so the cached
  singleton can't leak state.

125 tests pass; flutter analyze: no new issues.

* refactor(mobile): thread hideAmounts through calendar tiles

Per review: the calendar tile builders read PrivacyProvider via
context.read, relying implicitly on the parent build()'s context.watch to
rebuild them — fragile if a tile is later extracted or wrapped in a
RepaintBoundary. Pass hideAmounts down explicitly instead, matching the
recent_transactions_screen pattern:

- build() (context.watch) -> _buildCalendar -> _buildDayCell
- _showTransactionsDialog reads once when the modal opens ->
  _buildTransactionTile

No more context.read inside tile methods. 125 tests pass; analyze clean.

* fix(mobile): watch PrivacyProvider inside calendar dialog builder

Moving the hideAmounts read inside the showDialog builder and switching
from context.read to context.watch ensures the dialog re-masks transaction
amounts if the user toggles privacy mode while the dialog is open.
2026-06-30 06:49:05 +02:00

75 lines
2.6 KiB
Dart

import 'package:flutter/foundation.dart';
import '../services/log_service.dart';
import '../services/preferences_service.dart';
/// App-wide "privacy mode" toggle. When [hidden] is true, money values are
/// masked across the app (see [MoneyMasker]). The choice is persisted so it
/// survives relaunches, and changes notify listeners so every money widget
/// rebuilds immediately.
///
/// The preference is read before `runApp` and passed in as [initialHidden], so
/// the very first build already has the correct value — no startup window where
/// balances could flash. When [initialHidden] is omitted (e.g. in tests) the
/// provider starts masked (fail-closed) and hydrates asynchronously, so a user
/// who had privacy mode on still never flashes their balances.
class PrivacyProvider extends ChangeNotifier {
// Fail closed: assume masked until the stored preference is known.
bool _hidden;
// Set once the user explicitly toggles, so a late-completing initial load
// can't clobber their choice (see _load).
bool _userOverrode = false;
/// Whether monetary values should be masked.
bool get hidden => _hidden;
PrivacyProvider({bool? initialHidden}) : _hidden = initialHidden ?? true {
if (initialHidden == null) {
_load();
}
}
Future<void> _load() async {
bool? stored;
try {
stored = await PreferencesService.instance.getMoneyHidden();
} catch (e) {
// Keep the fail-closed default (masked) if the preference can't be read.
LogService.instance.warning(
'PrivacyProvider',
'Failed to load privacy preference with ${e.runtimeType}',
);
}
// Only apply the loaded value if the user hasn't toggled in the meantime,
// so the initial hydration never overwrites an explicit choice.
if (!_userOverrode && stored != null) {
_hidden = stored;
}
notifyListeners();
}
/// Sets the masked state and persists it. No-ops if unchanged. If persistence
/// fails the in-memory state is reverted so the UI stays consistent with what
/// is actually stored.
Future<void> setHidden(bool value) async {
_userOverrode = true;
if (_hidden == value) return;
final previous = _hidden;
_hidden = value;
notifyListeners();
try {
await PreferencesService.instance.setMoneyHidden(value);
} catch (e) {
_hidden = previous;
notifyListeners();
LogService.instance.warning(
'PrivacyProvider',
'Failed to persist privacy preference with ${e.runtimeType}',
);
}
}
/// Flips the masked state.
Future<void> toggle() => setHidden(!_hidden);
}