Share Extension: account picker first, hidden folders follow the app's filter + unlock
The app now publishes every uploadable account, the active one, the three lock settings and each account's own hidden-files filter (ShareAccountSync). The sheet lists accounts first when there are several, asks for unlock to use a non-active account (login lock + account-switching lock), and shows hidden folders per the account's app setting behind the hidden-files unlock. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5.5
parent
0cda4a1241
commit
a37524e959
@@ -7,6 +7,30 @@ struct DavFolder: Equatable {
|
||||
let path: String
|
||||
}
|
||||
|
||||
/// The app's Files "hidden files" filter (`HiddenFilesFilter` in Dart):
|
||||
/// leave dot-folders out (`hide`, the default), list only them (`only`), or
|
||||
/// list everything (`include`). A folder counts as hidden when it - or any
|
||||
/// folder above it - starts with a dot, exactly as in the app.
|
||||
enum HiddenFilter: String {
|
||||
case hide, only, include
|
||||
|
||||
init(raw: String) {
|
||||
self = HiddenFilter(rawValue: raw) ?? .hide
|
||||
}
|
||||
|
||||
static func isHidden(path: String) -> Bool {
|
||||
path.split(separator: "/").contains { $0.hasPrefix(".") }
|
||||
}
|
||||
|
||||
func shows(path: String) -> Bool {
|
||||
switch self {
|
||||
case .hide: return !Self.isHidden(path: path)
|
||||
case .only: return Self.isHidden(path: path)
|
||||
case .include: return true
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Parses a WebDAV `PROPFIND` multistatus into folders. Pure (no
|
||||
/// networking), so it's unit-tested. Compiled into both targets.
|
||||
enum DavFolderParser {
|
||||
@@ -67,11 +91,11 @@ enum DavFolderParser {
|
||||
return "/" + parts.joined(separator: "/")
|
||||
}
|
||||
|
||||
/// Child folders of [currentPath], sorted by name. The requested folder
|
||||
/// itself (which a Depth-1 PROPFIND also returns) and - unless
|
||||
/// [includeHidden] - dot-folders are left out.
|
||||
/// Child folders of [currentPath], sorted by name, filtered by [hidden].
|
||||
/// The requested folder itself (which a Depth-1 PROPFIND also returns) is
|
||||
/// always left out.
|
||||
static func folders(
|
||||
from xml: Data, excluding currentPath: String, includeHidden: Bool = false
|
||||
from xml: Data, excluding currentPath: String, hidden: HiddenFilter = .hide
|
||||
) -> [DavFolder] {
|
||||
let delegate = Delegate()
|
||||
let parser = XMLParser(data: xml)
|
||||
@@ -84,7 +108,7 @@ enum DavFolderParser {
|
||||
.compactMap { response -> DavFolder? in
|
||||
guard let path = relativePath(fromHref: response.href), path != current else { return nil }
|
||||
let name = (path as NSString).lastPathComponent
|
||||
guard !name.isEmpty, includeHidden || !name.hasPrefix(".") else { return nil }
|
||||
guard !name.isEmpty, hidden.shows(path: path) else { return nil }
|
||||
return DavFolder(name: name, path: path)
|
||||
}
|
||||
.sorted { $0.name.localizedCaseInsensitiveCompare($1.name) == .orderedAscending }
|
||||
@@ -99,7 +123,7 @@ enum DavClient {
|
||||
<d:propfind xmlns:d="DAV:"><d:prop><d:resourcetype/></d:prop></d:propfind>
|
||||
"""
|
||||
|
||||
static func listFolders(account: SharedAccount, path: String) async throws -> [DavFolder] {
|
||||
static func listFolders(account: SharedAccount, path: String, hidden: HiddenFilter) async throws -> [DavFolder] {
|
||||
guard let url = WebDAV.fileURL(serverUrl: account.serverUrl, username: account.username, remotePath: path)
|
||||
else { throw TransferError(message: "Invalid server address.") }
|
||||
var request = URLRequest(url: url)
|
||||
@@ -115,6 +139,6 @@ enum DavClient {
|
||||
guard status == 207 else {
|
||||
throw TransferError(message: status == 401 ? "Signed out - open Noo to sign in again." : "Server returned \(status).")
|
||||
}
|
||||
return DavFolderParser.folders(from: data, excluding: path)
|
||||
return DavFolderParser.folders(from: data, excluding: path, hidden: hidden)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,27 +1,57 @@
|
||||
import Foundation
|
||||
import Security
|
||||
|
||||
/// The signed-in account, as much of it as the Share Extension needs to list
|
||||
/// folders and upload: the app writes it when an account becomes active and
|
||||
/// clears it on sign-out. Compiled into both targets.
|
||||
struct SharedAccount: Codable, Equatable {
|
||||
/// One signed-in account, as much of it as the Share Extension needs to list
|
||||
/// folders and upload. Compiled into both targets.
|
||||
struct SharedAccount: Codable, Equatable, Identifiable {
|
||||
let id: String
|
||||
let serverUrl: String
|
||||
let username: String
|
||||
/// `Basic ...` - the app password never leaves the Keychain as plain text.
|
||||
let authHeader: String
|
||||
/// Shown in the picker, e.g. "alice@cloud.example.com".
|
||||
let displayName: String
|
||||
/// The app's Files "hidden files" filter for this account - `hide` (the
|
||||
/// default), `only` or `include` (see `HiddenFilter`). The share sheet
|
||||
/// follows it instead of having a setting of its own.
|
||||
let hiddenFilter: String
|
||||
}
|
||||
|
||||
/// Keeps the [SharedAccount] in a Keychain access group both the app and the
|
||||
/// Everything the app publishes for the extension: every account that can
|
||||
/// upload, which one is active in the app, and the app-lock settings the
|
||||
/// extension has to honour. The app rewrites it whenever any of that changes.
|
||||
struct SharedAccounts: Codable, Equatable {
|
||||
var accounts: [SharedAccount]
|
||||
var activeId: String?
|
||||
/// Settings -> Security: the master "login lock" and its two sub-toggles.
|
||||
/// The sub-toggles only count while the master one is on (as in the app).
|
||||
var loginLockEnabled: Bool
|
||||
var lockAccountSwitching: Bool
|
||||
var lockHiddenFiles: Bool
|
||||
|
||||
/// The account the app is currently using, else the first one.
|
||||
var active: SharedAccount? {
|
||||
accounts.first { $0.id == activeId } ?? accounts.first
|
||||
}
|
||||
|
||||
/// Uploading to an account other than the active one is "switching" in
|
||||
/// the app's terms, so it needs the same unlock.
|
||||
var needsUnlockToSwitchAccount: Bool { loginLockEnabled && lockAccountSwitching }
|
||||
|
||||
/// Showing hidden folders needs the same unlock the app asks for when you
|
||||
/// turn hidden files on.
|
||||
var needsUnlockForHidden: Bool { loginLockEnabled && lockHiddenFiles }
|
||||
}
|
||||
|
||||
/// Keeps the [SharedAccounts] in a Keychain access group both the app and the
|
||||
/// extension are entitled to (`keychain-access-groups`). The group's full id
|
||||
/// carries the signing team's prefix, so it's injected into each target's
|
||||
/// Info.plist as `NooKeychainAccessGroup` (= `$(AppIdentifierPrefix)` +
|
||||
/// `dev.ayushya.noo.shared`) instead of being hard-coded - both processes
|
||||
/// then always agree on it, with or without a team.
|
||||
enum SharedAccountStore {
|
||||
private static let service = "dev.ayushya.noo.shared-account"
|
||||
private static let account = "active"
|
||||
private static let service = "dev.ayushya.noo.shared-accounts"
|
||||
private static let account = "all"
|
||||
|
||||
static var accessGroup: String? {
|
||||
Bundle.main.object(forInfoDictionaryKey: "NooKeychainAccessGroup") as? String
|
||||
@@ -39,7 +69,7 @@ enum SharedAccountStore {
|
||||
return query
|
||||
}
|
||||
|
||||
static func save(_ value: SharedAccount) throws {
|
||||
static func save(_ value: SharedAccounts) throws {
|
||||
let data = try JSONEncoder().encode(value)
|
||||
clear()
|
||||
var query = baseQuery()
|
||||
@@ -51,15 +81,17 @@ enum SharedAccountStore {
|
||||
}
|
||||
}
|
||||
|
||||
static func load() -> SharedAccount? {
|
||||
static func load() -> SharedAccounts? {
|
||||
var query = baseQuery()
|
||||
query[kSecReturnData as String] = true
|
||||
query[kSecMatchLimit as String] = kSecMatchLimitOne
|
||||
var result: AnyObject?
|
||||
guard SecItemCopyMatching(query as CFDictionary, &result) == errSecSuccess,
|
||||
let data = result as? Data
|
||||
let data = result as? Data,
|
||||
let decoded = try? JSONDecoder().decode(SharedAccounts.self, from: data),
|
||||
!decoded.accounts.isEmpty
|
||||
else { return nil }
|
||||
return try? JSONDecoder().decode(SharedAccount.self, from: data)
|
||||
return decoded
|
||||
}
|
||||
|
||||
static func clear() {
|
||||
|
||||
Reference in New Issue
Block a user