Repository navigation
Conversation
Backgrounding should hide the wallet immediately, and resume authentication has to wait until Android will actually show the prompt. Co-authored-by: Cursor <cursoragent@cursor.com>
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
Smart E2E Test SelectionSelected E2E tags: ALL Selected Performance tags@PerformanceLogin AI Confidence: 100 E2E reasoningExpand to readThis PR fundamentally rewrites the app lock, privacy cover, and authentication resume system — one of the most security-critical flows in the wallet. Key changes:
Impact on E2E tests: This change affects:
The hard rule seed already selected ALL tags, which is correct given the critical nature of these changes. The lock/authentication system is foundational — any regression could break every user flow that requires the app to be unlocked. Running ALL E2E tags is the only safe approach. Performance reasoningExpand to readTwo performance areas are directly impacted: 1) @PerformanceLogin — the unlock/biometric flow is completely rewritten. The new AppLockService handles biometric unlock on resume differently (native privacy cover + waitUntilAuthenticationReady on Android), and the performance test warm-start-to-login.spec.ts already has its Android threshold increased from 3000ms to 3500ms, confirming the team expects measurable timing changes. 2) @PerformanceLaunch — AppLockService.initialize() is now called in index.js at cold start, adding a new AppState listener subscription to the startup path. The privacy cover native module initialization also happens earlier. These changes could affect cold-start and warm-start times. Other performance tags (@PerformanceAccountList, @PerformanceSwaps, @PerformanceAssetLoading, etc.) are not directly impacted by the lock/privacy cover changes. |
| }} | ||
| /> | ||
| </RootStack.Navigator> | ||
| ); |
There was a problem hiding this comment.
Card and Ramp drop auto-lock pause
Medium Severity
Card and Ramp no longer pause auto-lock during verification handoff. The old stopListening / startListening calls were removed, and AppLockService never gained the dangerousPauseAutoLock / dangerousResumeAutoLock API the PR says still exists. Leaving the app for email, SMS, camera, or bank verification now locks on Immediate (and on timed lock after the timeout), and the biometric prompt on return can interrupt the handoff.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit 7f86533. Configure here.
There was a problem hiding this comment.
This removal is intentional. Resume unlock uses navigationBehavior: 'preserve', so returning from a verification handoff stays on the Card or Ramp screen after authentication instead of resetting to Home. The privacy cover still shows, and the user's lock timeout still applies. The PR description no longer says dangerousPauseAutoLock / dangerousResumeAutoLock exist.
PR template — items to address before "Ready for review"Warnings — informational, address before merging:
See docs/readme/ready-for-review.md for the full Definition of Ready for Review. |
Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
There are 2 total unresolved issues (including 1 from previous review).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 930749e. Configure here.
… biometric fails on foreground
⚡ Performance Test Results
Branch: |
AccessibilityNative privacy cover replaces the old LockScreen fox loader — nice direction. One TalkBack gap on Android vs what iOS already does: Android cover doesn't block AT on the app underneath While the cover is shown, mark the underlying content unavailable to TalkBack (or treat the cover as a modal layer the way iOS does), then restore a11y when
Happy to take another look. |
|





Description
The lock screen route is gone. Backgrounding the app now shows a native privacy cover (theme fill and the splash fox) and keeps it up until resume authentication finishes or the wallet is still unlocked and can continue.
Auto-lock is decided on return from wall-clock time. Immediate lock (
0) locks on background. Timed locks lock only if enough time has passed when the user comes back. Never (-1) does not lock. Deeplinks that arrive during that decision wait until it finishes.On Android, the biometric or device-credential prompt starts only after
onPostResume. Leaving again before the prompt appears cancels that attempt, and the next resume starts a new one. iOS starts the prompt when the app becomes active. The cover is not shown for iOSinactive(app switcher, Control Center, Face ID).Android 13+ blanks the Recents card with
setRecentsScreenshotEnabled(false). Android 12 and older holdFLAG_SECUREfrom login until logout.Card and Ramp do not pause auto-lock. Resume unlock keeps the current screen, so a verification handoff stays on that flow after authentication instead of resetting to Home. The cover still shows, and the user's lock timeout still applies.
Changelog
CHANGELOG entry: Added a privacy cover while the app is in the background and prompt unlock on return
Related issues
Fixes:
Refs: https://consensyssoftware.atlassian.net/browse/MCWP-940
Manual testing steps
Screenshots/Recordings
Before
N/A
After
iOS
ios-privacy-screen.mov
Android
android-privacy-screen.mov
Pre-merge author checklist
Performance checks (if applicable)
trace()for usage andaddTokenfor an exampleFor performance guidelines and tooling, see the Performance Guide.
Pre-merge reviewer checklist
Note
High Risk
Changes wallet security UX (lock timing, resume auth, deeplink ordering) and native lifecycle integration on both platforms; regressions could leak UI in Recents or strand users behind the cover or wrong navigation.
Overview
Replaces the LockScreen navigation route with a native privacy overlay (splash-themed cover on Android
onPause/ iOSapplicationDidEnterBackground) that JS dismisses viaPrivacyCoverModuleafter resume handling completes.Introduces
AppLockServiceas the single owner of background/foreground behavior: privacy cover timing (minimum visible duration), auto-lock fromsettings.lockTime(immediate lock on background, timed lock evaluated on resume, never off), biometric unlock withnavigationBehavior: 'preserve'so users return to the same screen, deeplink holds until lock/unlock settles, and AndroidwaitUntilAuthenticationReadytied toonPostResume.LockManagerService,AppStateService, and lock-screen sagas are removed; auth saga only callsAppLockService.initialize/start/stopon login lifecycle.Authentication.tryBiometricUnlockcentralizes cold start and resume prompts. Card and Ramp no longer pause auto-lock. Android 13+ usessetRecentsScreenshotEnabled(false); older Android holdsFLAG_SECUREfor the logged-in session viaPreventScreenshot.Reviewed by Cursor Bugbot for commit b28b1a3. Bugbot is set up for automated code reviews on this repo. Configure here.