Files
sure/mobile/lib/utils/money_masker.dart
ghost 401cd6ab08 feat(mobile): privacy mode to mask money values (#2386)
* feat(mobile): add privacy mode to mask money values

Adds an app-wide "privacy mode" so users can hide monetary amounts from
over-the-shoulder view.

- PrivacyProvider (ChangeNotifier) backed by PreferencesService, so the
  choice persists across launches and every money widget rebuilds on
  toggle.
- MoneyMasker.mask() collapses an amount's numeric portion into a short
  fixed run of bullets while keeping the currency symbol and sign
  (e.g. CA$1,234.56 -> CA$••••). A fixed run avoids leaking the value's
  magnitude and reads cleanly without stray separators. Currency- and
  locale-agnostic — it operates on already-formatted strings.
- Masking applied at every money render site: net worth + per-currency
  totals + breakdown sheet (NetWorthCard), account balances (AccountCard,
  AccountDetailHeader, transaction form account selector), and transaction
  amounts (transactions list, recent transactions, calendar).
- Two entry points: a "Hide amounts" switch in Settings -> Security, and a
  quick eye toggle in the top bar (visible on every tab).

Tests: MoneyMasker unit tests (fixed-run mask, magnitude hidden, symbol/
sign kept, passthrough, idempotent) + a widget test asserting the net
worth masks/unmasks as the provider flips; account_card_test updated to
provide the new provider. flutter analyze: no new issues; full suite
(123) green.

* fix(mobile): address privacy-mode review feedback

- Startup masking (Codex P1): read the privacy preference in main() before
  runApp and seed PrivacyProvider with it, so the first frame already has
  the correct value — money is never briefly rendered unmasked for a user
  who enabled "Hide amounts". Provider stays fail-closed otherwise: starts
  masked, SureApp's no-arg default is masked, and a failed read keeps it
  masked. A late-completing initial load no longer clobbers an explicit
  user toggle.
- setHidden() reverts the in-memory state (and logs) if persistence fails,
  keeping the UI consistent with what's actually stored.
- Mask the cash-balance detail chip in AccountDetailHeader (was leaking
  the cash position in privacy mode).
- Privacy top-bar toggle gets a "Toggle privacy" tooltip + icon semantic
  label for accessibility (kept as an InkWell to match the adjacent
  settings control).
- Tests: assert fail-closed initial state; assert the exact masked count;
  test the persistence round-trip (set -> reload); add
  PreferencesService.resetForTest() and reset between tests so the cached
  singleton can't leak state.

125 tests pass; flutter analyze: no new issues.

* refactor(mobile): thread hideAmounts through calendar tiles

Per review: the calendar tile builders read PrivacyProvider via
context.read, relying implicitly on the parent build()'s context.watch to
rebuild them — fragile if a tile is later extracted or wrapped in a
RepaintBoundary. Pass hideAmounts down explicitly instead, matching the
recent_transactions_screen pattern:

- build() (context.watch) -> _buildCalendar -> _buildDayCell
- _showTransactionsDialog reads once when the modal opens ->
  _buildTransactionTile

No more context.read inside tile methods. 125 tests pass; analyze clean.

* fix(mobile): watch PrivacyProvider inside calendar dialog builder

Moving the hideAmounts read inside the showDialog builder and switching
from context.read to context.watch ensures the dialog re-masks transaction
amounts if the user toggles privacy mode while the dialog is open.
2026-06-30 06:49:05 +02:00

33 lines
1.5 KiB
Dart

/// Masks monetary values for "privacy mode", where the user wants amounts
/// hidden from over-the-shoulder view.
///
/// The numeric portion of an amount (its digits and any embedded grouping/
/// decimal separators) is collapsed into a short, fixed run of bullets, while
/// the currency symbol/code and sign are kept. So `CA$1,234.56` -> `CA$••••`
/// and `-$42,078.35` -> `-$••••`. A fixed run (rather than one bullet per
/// digit) avoids leaking the value's magnitude and reads cleanly without stray
/// separators. Non-numeric characters are untouched, so the masker is currency-
/// and locale-agnostic — it works on any already-formatted amount string.
class MoneyMasker {
const MoneyMasker._();
/// The character used to mask digits.
static const String maskChar = ''; // •
/// The fixed run of [maskChar] that replaces the numeric portion of an amount.
static const String maskedNumber = '$maskChar$maskChar$maskChar$maskChar';
/// A maximal run of digits and the separators embedded within them, requiring
/// at least one digit so symbol-only strings (e.g. the `--` placeholder) are
/// left alone.
static final RegExp _numericRun = RegExp(r'[\d.,]*\d[\d.,]*');
/// Returns [formatted] with its numeric portion replaced by [maskedNumber],
/// preserving the currency symbol/code and sign. If [hidden] is false,
/// [formatted] is returned unchanged.
static String mask(String formatted, {bool hidden = true}) {
if (!hidden) return formatted;
return formatted.replaceAll(_numericRun, maskedNumber);
}
}