Stay signed in, come back online by itself, and let a machine be given up

Three things a machine that has been set up could not do. Unlock now takes
Enter, which is the gesture everybody makes after typing a password and which
did nothing until they found the button.

Signing in survives a relaunch. The refresh token is kept in the local cache,
sealed under the vault's own cache key, so a later launch resumes the session
through the refresh grant with no browser and nobody present — and because it
is sealed under that key, only an unlocked vault can resume it. A locked
client therefore cannot reach the server at all, which is a consequence worth
stating rather than working around; docs/crypto.md §3.2 records it. Every sync
pass asks the shell for a connection rather than reading one captured at
unlock, so a laptop that unlocked on a train is online within a minute of
finding a network, with nothing pressed. Unlocking itself still never waits on
a socket.

Signing out empties this machine: the profile, the cached items, the outbox
and this machine's device key, with the account's row withdrawn when the
server can be reached. It asks first and says what it costs — the outbox count
when the vault is open, an admission that it cannot be counted when it is not,
and the shells that keep running either way. The vault is on the server and is
untouched, which is what makes the same button the only honest answer to a
forgotten passphrase, so it is on the unlock screen as well as in preferences.
It cannot end the session at the identity provider, and says so.

Two defects surfaced on the way. The synchronisation pass that runs when the
vault opens never ran at all: the loop is started from inside the unlock
command, so the busy flag it yields to was raised by that command — the first
sync was a minute late on every launch. And signing in from preferences while
unlocked threw an unlock screen over an open vault whose keys were still in
memory.

The unlock card and the new confirmation live in their own controls because
MainWindow cannot be laid out headless, so markup left inside it is markup no
test can measure; both are now measured at the window's minimum size in the
shapes that grow. What is still unverified is the composed window itself.
This commit is contained in:
2026-07-31 11:07:36 +02:00
parent 94e11f5e38
commit 0b261c4d39
28 changed files with 2323 additions and 80 deletions
@@ -0,0 +1,55 @@
<UserControl xmlns="https://github.com/avaloniaui"
xmlns:x="http://schemas.microsoft.com/winfx/2006/xaml"
xmlns:vm="using:DodoSSH.Client.App.ViewModels"
x:Class="DodoSSH.Client.App.Views.SignOutCard"
x:DataType="vm:MainWindowViewModel">
<!--
The sign-out confirmation.
One control used in two places — the preferences screen, where somebody is leaving a machine on
purpose, and the unlock screen, where somebody has forgotten their passphrase and this is the only way
forward. The two moments are different and the warning is not, which is why this is a shared control
rather than two blocks that would drift apart.
It is a bare StackPanel and not a card: the two hosts frame it differently, because a card that centres
itself is right over a lock screen and wrong halfway down a scrolling column of preferences.
Everything it says is something the state machine can actually answer. The count comes from the outbox,
the shell count from the workspace, and the sentence about the identity provider is there because
nothing here can end that session — see MainWindowViewModel.ConfirmSignOutAsync.
-->
<StackPanel Spacing="10">
<TextBlock Classes="heading" FontSize="15" Text="Sign out of this machine?" />
<TextBlock Text="{Binding SignOutWarning}" Foreground="{StaticResource WarnText}"
TextWrapping="Wrap" />
<TextBlock Classes="hint" FontSize="11" TextWrapping="Wrap"
Text="This deletes this machine's copy of the vault — the profile, the cached hosts, keys and passwords, and this machine's device key. Your vault is on the server and is not touched: signing in again brings it all back." />
<Border Background="{StaticResource Panel}" BorderBrush="{StaticResource Border}"
BorderThickness="1" CornerRadius="4" Padding="10,8"
IsVisible="{Binding HasLiveSessions, FallbackValue=False}">
<StackPanel Spacing="4">
<TextBlock Text="{Binding LiveSessionSummary}" Foreground="{StaticResource Info}"
FontWeight="SemiBold" TextWrapping="Wrap" />
<TextBlock Classes="hint" FontSize="11" TextWrapping="Wrap"
Text="Signing out does not close them, exactly as locking does not. Quit DodoSSH to end them." />
</StackPanel>
</Border>
<StackPanel Orientation="Horizontal" Spacing="8">
<Button Classes="danger" Content="SIGN OUT AND DELETE"
Command="{Binding ConfirmSignOutCommand}" IsEnabled="{Binding !IsBusy}" />
<Button Classes="ghost" Content="CANCEL" Command="{Binding CancelSignOutCommand}" />
</StackPanel>
<TextBlock Classes="hint" FontSize="10" TextWrapping="Wrap"
Text="Your session at the identity provider is not ended by this — DodoSSH has no way to end it — so on a machine that is not yours, sign out there too." />
</StackPanel>
</UserControl>