Files
docs/android/screenshots
wtclaude 1809f15456 docs(android): add full trusted-devices/MFA smoke-test walkthrough frames
Supplements the five curated highlights (docs#34) with the remaining
distinct frames from the same live smoke-test session, in flow order:
home/connected, signed-out + signed-in drawers, login + empty 2FA step,
account overview, recovery-codes pre-generate, and the untrust-all to
empty-list to TOTP-required-again sequence. Extends the screenshots
README with a walkthrough table.

Excludes the raws superseded by the five highlights and pure automation
artifacts (soft-keyboard popups, mid-transition spinners, duplicate Home
landings) that do not represent a distinct app state.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NgyHnrNa8WwG3doxvxjuCr
2026-07-22 01:33:48 -05:00
..
@
2026-07-22 01:23:58 -05:00
@
2026-07-22 01:23:58 -05:00
@
2026-07-22 01:23:58 -05:00
@
2026-07-22 01:23:58 -05:00
@
2026-07-22 01:23:58 -05:00

Android app — trusted devices & recovery codes (live smoke test)

Screenshots from a live end-to-end smoke test of the trusted-device + MFA feature on the Android client (app PR RunicGateway/Android-app#23), captured against the local Node server (127.0.0.1:3000) and a uomysticmoon MariaDB, on an API 36 emulator. See ../PLAN.md §4.1.1 for the design and ../../website/TRUSTED_DEVICES_MFA.md for the canonical contract.

# Screenshot Shows
1 01-login-2fa-trust-device.png The 401 { totpRequired } login step: the authentication code field, the "Use a recovery code instead" toggle, and the "Trust this device (skip codes for 30 days)" checkbox (ticked).
2 02-account-security-section.png The new Security section on the account screen linking to Trusted devices and Recovery codes.
3 03-trusted-devices.png The Trusted Devices screen listing this device (Google sdk_gphone64_x86_64 — the device_name sent at login) with revoke / trust-this-device / untrust-all.
4 04-recovery-codes-show-once.png The Recovery Codes screen after a password-stepped regenerate: the one-time batch shown once with copy / share, and the updated remaining count.
5 05-recovery-code-login.png Signing in with a single-use recovery code instead of the authenticator code.

Verified flows (all passed)

  1. 2FA login + "Trust this device"200, trust token stored; server logged device trusted.
  2. Trust survives logout — after signing out, a password-only sign-in skipped the TOTP step entirely (server: a clean 200 with no preceding 401 totpRequired). This is the headline behaviour: the trust token is only consulted at a fresh login, so it must outlive logout (see PLAN §4.1.1).
  3. Trusted Devices — list, and the device's last_used stamp advancing after the trust-skip login.
  4. Untrust all — cleared the server rows and the local token; the next password-only sign-in correctly required the TOTP step again (server: 401).
  5. Recovery codes — generate (password step-up, shown once) and a successful recovery-code login (server: mobile login via recovery code200).

Full step-by-step walkthrough

The five images above are the curated highlights. These walkthrough-* frames are the rest of the same smoke-test session, in flow order, for a complete record. (Pure automation-artifact frames — soft-keyboard popups, mid-transition spinners, and duplicate Home landings — are omitted; the raws that the highlights above supersede are not repeated here.)

# Screenshot Shows
1 walkthrough-01-home-connected.png Home with the shard Online (already connected to the local server), signed out.
2 walkthrough-02-drawer-signed-out.png Navigation drawer while signed out — Sign in entry.
3 walkthrough-03-login-screen.png The native login screen (no SSO providers configured in dev).
4 walkthrough-04-login-2fa-step.png The 401 { totpRequired } step with the fields empty — the "Use a recovery code instead" toggle and "Trust this device" checkbox before entry (companion to highlight #1, which shows them filled).
5 walkthrough-05-drawer-signed-in.png Drawer once signed in — My account, Notifications, player groups, Sign out.
6 walkthrough-06-account-overview.png Top of the account screen: identity, username/password, two-factor ENABLED.
7 walkthrough-07-recovery-codes-before-generate.png Recovery Codes screen before generating — 0 codes remaining + the password-step-up form.
8 walkthrough-08-trusted-devices-empty-after-untrust.png Trusted Devices after Untrust all — "All devices untrusted." and the empty state.
9 walkthrough-09-login-2fa-required-after-untrust.png The next sign-in re-prompting for the TOTP step — proof that untrust-all cleared the local trust token.