The macOS ApprovalBar put the title and action buttons on one row, so a long file-path title got truncated. Stack title above the buttons so it wraps to as many lines as needed. Bump the iOS card's input summary cap from 3 to 8 lines. Both made text-selectable. Co-Authored-By: Claude Opus 4.8 <[email protected]>
115 lines
4.5 KiB
Swift
115 lines
4.5 KiB
Swift
import SwiftUI
|
|
import LocalAuthentication
|
|
import NucleicProtocol
|
|
|
|
/// The defining interaction (UX_IOS §5): answer an approval. High-risk (destructive/network)
|
|
/// requires Face ID/Touch ID before Allow is enabled — deliberate friction mirroring the Mac.
|
|
/// First-responder-wins: if the Mac (or another phone) answers first, the host's
|
|
/// `approvalResolved` removes this card.
|
|
struct ApprovalCardView: View {
|
|
@EnvironmentObject var store: RemoteStore
|
|
let approval: ApprovalRequest
|
|
|
|
@State private var biometricPassed = false
|
|
@State private var authError: String?
|
|
@State private var showAlwaysMenu = false
|
|
|
|
private var requiresBiometric: Bool { approval.risk.isHigh }
|
|
private var allowEnabled: Bool {
|
|
store.connectivity.isLive && (!requiresBiometric || biometricPassed)
|
|
}
|
|
|
|
var body: some View {
|
|
VStack(alignment: .leading, spacing: 10) {
|
|
HStack(spacing: 6) {
|
|
Image(systemName: "exclamationmark.triangle.fill").foregroundStyle(.orange)
|
|
Text("Permission requested").font(.subheadline.weight(.semibold))
|
|
}
|
|
HStack(spacing: 6) {
|
|
Text(approval.toolName).font(.caption.weight(.bold))
|
|
Text(approval.risk.label)
|
|
.font(.caption2.weight(.semibold))
|
|
.padding(.horizontal, 6).padding(.vertical, 2)
|
|
.background(approval.risk.color.opacity(0.2), in: Capsule())
|
|
.foregroundStyle(approval.risk.color)
|
|
}
|
|
Text(approval.input.compactSummary)
|
|
.font(.caption.monospaced())
|
|
.lineLimit(8)
|
|
.textSelection(.enabled)
|
|
.padding(8)
|
|
.frame(maxWidth: .infinity, alignment: .leading)
|
|
.background(Color(.secondarySystemBackground), in: RoundedRectangle(cornerRadius: 8))
|
|
|
|
if requiresBiometric && !biometricPassed {
|
|
Button {
|
|
authenticate()
|
|
} label: {
|
|
Label("Face ID required to allow", systemImage: "faceid").font(.caption)
|
|
}
|
|
.buttonStyle(.bordered)
|
|
}
|
|
if let authError {
|
|
Text(authError).font(.caption2).foregroundStyle(.red)
|
|
}
|
|
|
|
HStack(spacing: 10) {
|
|
Button(role: .destructive) {
|
|
store.respond(approval, .deny(reason: nil))
|
|
} label: {
|
|
Text("Deny").frame(maxWidth: .infinity)
|
|
}
|
|
.buttonStyle(.bordered)
|
|
|
|
Button {
|
|
store.respond(approval, .allow())
|
|
} label: {
|
|
Text("Allow").frame(maxWidth: .infinity)
|
|
}
|
|
.buttonStyle(.borderedProminent)
|
|
.disabled(!allowEnabled)
|
|
}
|
|
|
|
if !store.capabilities.allowAlwaysScopes.isEmpty {
|
|
Menu("Allow always…") {
|
|
ForEach(store.capabilities.allowAlwaysScopes, id: \.self) { scope in
|
|
Button(alwaysLabel(scope)) {
|
|
store.respond(approval, .allowAlways(scope))
|
|
}
|
|
.disabled(!allowEnabled)
|
|
}
|
|
}
|
|
.font(.caption)
|
|
}
|
|
}
|
|
.padding()
|
|
.background(.thinMaterial, in: RoundedRectangle(cornerRadius: 14))
|
|
.onChange(of: approval.id) { _, _ in biometricPassed = false; authError = nil }
|
|
}
|
|
|
|
private func alwaysLabel(_ scope: AlwaysScope) -> String {
|
|
switch scope {
|
|
case .session: "This command, this session"
|
|
case .toolName: "Any \(approval.toolName), this session"
|
|
case .toolNameWithPattern: "\(approval.toolName) matching this pattern"
|
|
}
|
|
}
|
|
|
|
private func authenticate() {
|
|
let context = LAContext()
|
|
var error: NSError?
|
|
guard context.canEvaluatePolicy(.deviceOwnerAuthenticationWithBiometrics, error: &error) else {
|
|
authError = "Biometrics unavailable"; return
|
|
}
|
|
context.evaluatePolicy(
|
|
.deviceOwnerAuthenticationWithBiometrics,
|
|
localizedReason: "Approve a \(approval.risk.label) action"
|
|
) { success, evalError in
|
|
Task { @MainActor in
|
|
if success { biometricPassed = true; authError = nil }
|
|
else { authError = evalError?.localizedDescription ?? "Authentication failed" }
|
|
}
|
|
}
|
|
}
|
|
}
|