PROPFIND walk / diff / GET / PUT mirror with conflicts, per-account state,
BGTaskScheduler background runs, and conflict notifications with Keep local /
Use server. Reviewed by Codex against the Kotlin original; its data-loss
findings are fixed and each has a regression test (fake-server end-to-end
tests, 68 Swift tests total): truncated/unusable PROPFIND answers are never a
manifest, unreadable state aborts the run, server paths can't leave the mirror,
case/Unicode collisions are skipped, atomic downloads, a locally edited file
deleted on the server is kept, '/' scope matching, serialised removal,
tracked/cancellable background runs, per-account conflicts, and sign-out vs
background-off credentials (cancel gains a 'forget' flag).
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The sheet remembered one unlock for its whole lifetime, so later account picks
and hidden toggles skipped Face ID. Each switch / each turning-on of hidden
folders now prompts again; one action needing both is a single prompt.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Two menu chips start at the account's app settings (hidden filter, storage
scope - now published per account), hidden-on asks for the app's unlock, and
external storage is detected via nc:mount-type incl. everything under a
mount. Adds logging for which accounts get published and why one is skipped.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Login lock, lock account switching and lock hidden files no longer depend on
each other: passGate prompts on its own flag, the two sub-locks can be set
with login lock off, and disabling login lock leaves them alone. Turning any
lock on or off asks for device auth (on also checks the device can). The iOS
Share Extension's unlock rules follow. The avatar dropdown's additional
accounts lose the 44px spacer so their avatars sit at the right edge.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The app now publishes every uploadable account, the active one, the three
lock settings and each account's own hidden-files filter (ShareAccountSync).
The sheet lists accounts first when there are several, asks for unlock to use
a non-active account (login lock + account-switching lock), and shows hidden
folders per the account's app setting behind the hidden-files unlock.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The Share Extension's session had no delegate, so a fast upload finished
unseen and the invalidated session was discarded before the app could hear of
it - no summary notification. Results are now handled by a shared delegate in
whichever process is alive, started/finished notifications replace each
other in place, and the app refreshes the folder the extension uploaded to.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
SwiftUI folder picker in the extension (WebDAV PROPFIND), account shared via
a Keychain group, upload on a background session that outlives the extension
and is finished by the app. The inbox + notification hand-off remains as the
fallback (no account / 'choose later'). Shared code moves to ios/Shared.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
ShareExtension target copies shared files into group.dev.ayushya.noo and
leaves a manifest; the app consumes it on launch/activation through the
existing share_intent channel into the destination picker. Extension is
embedded before Flutter's script phases; versions follow FLUTTER_BUILD_*.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Swift implementation of the upload_service/download_service channels:
background PUT/GET against the account's WebDAV root, one summary local
notification per batch, Downloads visible in the Files app. Pure helpers
covered by RunnerTests.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Share/pick/sync calls and streams no longer throw MissingPluginException at
startup; upload/download/sync-now show 'X isn't available on this platform
yet'. Offline/sync mirror dir no longer uses the Android-only external dir.
Info.plist: Face ID and photo library usage strings.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Uploads run entirely in ShareUploadService.kt, an Android foreground
service with no channel back to Dart once started - by design, so
closing the app mid-upload doesn't interrupt it. That meant
FilesController had no way to know a batch had finished, so a newly
uploaded file only appeared after a manual pull-to-refresh.
Adds a one-shot completion signal instead of a full stream: the
service publishes into a new UploadEventBus (in-process pub/sub,
mirroring SyncStatusBus) once a batch finishes with at least one
success, MainActivity forwards it to Dart over a new
dev.ayushya.noo/upload_service/status EventChannel, and
FilesController (subscribed in its own constructor, same pattern
OfflineController already uses for sync completion) calls
refreshData() when the event's destination folder matches
currentFolderPath. Covers both upload entry points (share-to-Noo and
Files' own "+" -> Upload file), since they already share the same
ShareUploadView/UploadService path.
Move/Copy needed no fix - ItemOperations already calls
files.invalidateCache() + refreshData() on success.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Nextcloud's WebDAV server has no real per-file creation-time tracking
for most setups, so its creationdate property routinely comes back as
a placeholder Unix-epoch date ("Thu, 01 Jan 1970 00:00:00 GMT")
instead of being omitted. _parseDavDate parsed that "successfully"
into a real (if bogus) DateTime, so every item's dateCreated stuck at
the epoch instead of falling back to lastModified as it would for a
genuinely missing/unparseable value.
Add _parseDavCreationDate, which treats that placeholder the same as
an absent value, and use it at all four PROPFIND/SEARCH call sites
that read creationdate (folder listing, search, favorites, recent).
- Offline tab is now FilesView(offline: true) over a FolderBrowser interface
(FilesController / OfflineController) sharing controls, tiles, thumbnails
- Synced files follow the Files Cache rule (default: refresh every 15 min):
per-account WorkManager jobs, in-app timer, resume and pull triggers;
root-etag shortcut skips full walks when nothing changed
- Single sync at a time (shared lock); logging out stops that account's sync
- Sync safety: PROPFIND failures skip the path instead of deleting local files
- Mirror empty folders and remove deleted ones; drop synced paths deleted on
the server; missing local files are re-downloaded
- Notifications: silent per-account sync notifications, "Background sync
notifications" setting, audible upload/download completion
- Files refresh in place (no spinner flash); retry after network returns
- Fix sync badges not updating (shared native status stream), "Sync off" on
launch (eager providers), Files Cache section moved under Device Sync
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Folders now show the synced status badge themselves, not just their
nested files - device-sync state never tracked folders individually, so
syncStatusFor derives a folder's badge from whether its path falls
within sync scope instead.
- Turning sync off for a path now deletes its local mirror and clears its
native sync-state entries (SyncEngine.removeLocalSync), instead of just
stopping future updates and leaving the downloaded copy behind.
- "Sync to device" in Files' selection toolbar now works over the whole
selection at once instead of being gated to a single selected item.
- The sync header's expanded panel shows real folder/item counts instead
of a static "Synced" label that stayed accurate-sounding even before
anything had actually synced.
- Confirmation SnackBars on starting/stopping sync from both the
selection toolbar and Settings' Device Sync card.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Consolidates duplicated GET/PUT/notification-channel logic across
DownloadService/ShareUploadService/SyncEngine into shared Kotlin helpers,
gives upload/download real batch queueing instead of dropping a second
concurrent batch, and dedupes repeated Dart channel-argument boilerplate.
Replaces the 2300+ line ServerProvider god object with ten focused
ChangeNotifiers (SessionController, SettingsController, FilesController,
PhotosController, FavoritesController, TrashController, SharesController,
RecentController, SyncStatusController, PickController) plus ItemOperations,
a plain coordinator for cross-domain item mutations - fixing the coupling
where device-sync status, per-tab data, and global UI prefs all lived in
one object. Updates every view/widget call site accordingly and refreshes
the architecture/server/standards/styling docs to match.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- New native sync engine (SyncEngine/SyncWorker/ConflictResolveWorker,
WorkManager-based) that mirrors selected Nextcloud folders or files to
app-private local storage, periodically and on-demand ("Sync now"),
with never-auto-resolved conflict notifications.
- Single files (not just folders) can now be marked "Sync to device".
- Live sync status (syncing/synced/conflicts) pushes from native to Dart
over a new EventChannel; the persistent header chip/panel now reflects
device-sync status instead of the WebDAV-refresh loading state, with a
cloud_off/cloud_sync/cloud_done/cloud_alert icon set and an expandable
conflicts list with in-app "Keep local"/"Use server" resolution.
Per-item cloud_done/sync badges show on Files tiles.
- Share/Download short-circuit to the local copy for already-synced
files instead of a fresh network fetch.
- Settings gained a Device Sync section (per-folder list, "Sync
everything", Wi-Fi-only toggle, manual "Sync now").
- Fixed two release-only bugs found via on-device testing: Android's
HttpURLConnection silently rejects the PROPFIND method (switched to
OkHttp), and R8 was stripping WorkManager's reflection-instantiated
internals (broadened proguard-rules.pro to keep androidx.work.**
wholesale rather than chasing individual classes).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- WebDAV MOVE/COPY-backed copy/move for files and folders, with a
destination picker (independent nav state so it doesn't disturb the
Files tab's browsing position) and a conflict-resolution sheet
(overwrite all / keep both / decide per item).
- Downloads now use the same foreground-service + notification approach
as uploads, surviving app closure.
- Favorites is now its own tab (account-wide, via a WebDAV SEARCH query)
instead of a Files-tab filter toggle, which couldn't represent
favorited items outside the currently browsed folder correctly.
- Share sheet restyled to match the app's design language, plus a
"share file directly" action via the OS share sheet; details sheet
tab icons resized to match the bottom nav.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Let Noo be picked as a source (Files + Photos) by other apps' native
file/photo pickers via Android's GET_CONTENT intent, mirroring the
existing "Share to Noo" plumbing: MainActivity.kt/PickIntentService/
PickRequest, ServerProvider.pickRequest/confirmPick/cancelPick, and
pick-mode tap handling in FilesView/PhotosView. While picking, the
bottom nav and MoreTabsButton are restricted to Files/Photos only.
- Fix two account bugs: testConnection() failures no longer delete a
still-valid stored app password (only an actual 401 does), and
switchAccount() now retries a nominally-active-but-logged-out account
instead of no-op'ing - both were silently locking users out of "Continue
as" with no way back in except removing and re-adding the account
(now exposed via login_view.dart's inline remove button).
- Fix the login WebView: clear cookies before every load so "Add Account"
can't silently reuse an existing session, and push it as a
non-animated route to avoid a known WebView-as-PlatformView black-screen-
on-pop issue under Impeller.
- Redesign the Files/Photos selection toolbar to take over the top app bar
entirely (SyncedHeaderScaffold.selectionBar) instead of sitting as a
second bar under the controls row, with a horizontally-scrollable,
uniformly-colored actions row and the same one-shot scroll-hint nudge
the controls row uses.
- Redesign ShareUploadView to share the same SyncedHeaderScaffold chrome
as every tab, with the uploading-file summary (marqueed via the new
shared MarqueeTitle widget) and upload button grouped into one
rounded/elevated bottom sheet.
- Restyle ShareSheet to open on the same DetailsHeader every other
per-item sheet uses, and fix a couple of small design-language drifts
(hardcoded text style, a non-rounded icon).
- Settings' account card: icon buttons with tooltips instead of text
buttons for refresh/logout/remove, divider removed.
The Chrome Custom Tab path for the first/only login had real costs -
no way to close it automatically on success, and it's a separate task
outside the app's own navigation - that only bought Chrome's own
autofill in exchange. LoginWebViewView now handles every login, not
just add-account, which was already using it to avoid a Custom Tab
silently reusing Chrome's session for a different account.
url_launcher is no longer a dependency as a result.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Documents the app-lock layer and multi-account storage/session model in
architecture.md/server.md, and adds a standards.md note that `flutter
install` wipes app data (it uninstalls before installing) — use `adb
install -r` for local test deploys instead.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Add SavedAccount/AccountStore and rework ServerProvider around a list
of saved accounts: switch/remove/add, swipe-to-cycle on the avatar
button, per-account browsing prefs (sort/view/filters/cache), and a
session-generation guard so a stale fetch from an abandoned account
can't land in the newly active one
- Migrate existing single-account installs into the new schema
automatically so upgrading users stay logged in
- Settings gains an Accounts section; LoginView gains an "add account"
mode pushed on top of the main shell instead of replacing it
- Give every Scrollbar in the app a thicker, draggable, Android-style
thumb via a shared ScrollbarTheme instead of the default hairline
- Splash screen: use the monochrome app icon (tinted per theme) and a
smaller spinner
- Update CLAUDE.md and .claude/context/*.md to reflect the accumulated
multi-account, sharing, and UI changes across this session, and add
a standing instruction to keep these docs current going forward
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Split project context into .claude/context/ (architecture, server,
styling, standards) instead of one large file, referenced from a
minimal root CLAUDE.md.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>