Supplements the five curated highlights (docs#34) with the remaining distinct frames from the same live smoke-test session, in flow order: home/connected, signed-out + signed-in drawers, login + empty 2FA step, account overview, recovery-codes pre-generate, and the untrust-all to empty-list to TOTP-required-again sequence. Extends the screenshots README with a walkthrough table. Excludes the raws superseded by the five highlights and pure automation artifacts (soft-keyboard popups, mid-transition spinners, duplicate Home landings) that do not represent a distinct app state. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgyHnrNa8WwG3doxvxjuCr
50 lines
4.5 KiB
Markdown
50 lines
4.5 KiB
Markdown
# Android app — trusted devices & recovery codes (live smoke test)
|
|
|
|
Screenshots from a live end-to-end smoke test of the trusted-device + MFA feature on
|
|
the Android client (app PR `RunicGateway/Android-app#23`), captured against the local
|
|
Node server (`127.0.0.1:3000`) and a `uomysticmoon` MariaDB, on an API 36 emulator.
|
|
See `../PLAN.md §4.1.1` for the design and `../../website/TRUSTED_DEVICES_MFA.md` for
|
|
the canonical contract.
|
|
|
|
| # | Screenshot | Shows |
|
|
|---|---|---|
|
|
| 1 | [`01-login-2fa-trust-device.png`](01-login-2fa-trust-device.png) | The `401 { totpRequired }` login step: the **authentication code** field, the **"Use a recovery code instead"** toggle, and the **"Trust this device (skip codes for 30 days)"** checkbox (ticked). |
|
|
| 2 | [`02-account-security-section.png`](02-account-security-section.png) | The new **Security** section on the account screen linking to Trusted devices and Recovery codes. |
|
|
| 3 | [`03-trusted-devices.png`](03-trusted-devices.png) | The **Trusted Devices** screen listing this device (`Google sdk_gphone64_x86_64` — the `device_name` sent at login) with revoke / trust-this-device / untrust-all. |
|
|
| 4 | [`04-recovery-codes-show-once.png`](04-recovery-codes-show-once.png) | The **Recovery Codes** screen after a password-stepped regenerate: the one-time batch shown once with copy / share, and the updated remaining count. |
|
|
| 5 | [`05-recovery-code-login.png`](05-recovery-code-login.png) | Signing in with a **single-use recovery code** instead of the authenticator code. |
|
|
|
|
## Verified flows (all passed)
|
|
|
|
1. **2FA login + "Trust this device"** → `200`, trust token stored; server logged `device trusted`.
|
|
2. **Trust survives logout** — after signing out, a **password-only** sign-in skipped the
|
|
TOTP step entirely (server: a clean `200` with **no** preceding `401 totpRequired`).
|
|
This is the headline behaviour: the trust token is *only* consulted at a fresh login,
|
|
so it must outlive logout (see PLAN §4.1.1).
|
|
3. **Trusted Devices** — list, and the device's `last_used` stamp advancing after the
|
|
trust-skip login.
|
|
4. **Untrust all** — cleared the server rows **and** the local token; the next
|
|
password-only sign-in correctly required the TOTP step again (server: `401`).
|
|
5. **Recovery codes** — generate (password step-up, shown once) and a successful
|
|
**recovery-code login** (server: `mobile login via recovery code` → `200`).
|
|
|
|
## Full step-by-step walkthrough
|
|
|
|
The five images above are the curated highlights. These `walkthrough-*` frames are the
|
|
rest of the same smoke-test session, in flow order, for a complete record. (Pure
|
|
automation-artifact frames — soft-keyboard popups, mid-transition spinners, and
|
|
duplicate Home landings — are omitted; the raws that the highlights above supersede are
|
|
not repeated here.)
|
|
|
|
| # | Screenshot | Shows |
|
|
|---|---|---|
|
|
| 1 | [`walkthrough-01-home-connected.png`](walkthrough-01-home-connected.png) | Home with the shard **Online** (already connected to the local server), signed out. |
|
|
| 2 | [`walkthrough-02-drawer-signed-out.png`](walkthrough-02-drawer-signed-out.png) | Navigation drawer while signed out — **Sign in** entry. |
|
|
| 3 | [`walkthrough-03-login-screen.png`](walkthrough-03-login-screen.png) | The native login screen (no SSO providers configured in dev). |
|
|
| 4 | [`walkthrough-04-login-2fa-step.png`](walkthrough-04-login-2fa-step.png) | The `401 { totpRequired }` step with the fields empty — the **"Use a recovery code instead"** toggle and **"Trust this device"** checkbox before entry (companion to highlight #1, which shows them filled). |
|
|
| 5 | [`walkthrough-05-drawer-signed-in.png`](walkthrough-05-drawer-signed-in.png) | Drawer once signed in — **My account**, Notifications, player groups, **Sign out**. |
|
|
| 6 | [`walkthrough-06-account-overview.png`](walkthrough-06-account-overview.png) | Top of the account screen: identity, username/password, **two-factor ENABLED**. |
|
|
| 7 | [`walkthrough-07-recovery-codes-before-generate.png`](walkthrough-07-recovery-codes-before-generate.png) | Recovery Codes screen before generating — **0 codes remaining** + the password-step-up form. |
|
|
| 8 | [`walkthrough-08-trusted-devices-empty-after-untrust.png`](walkthrough-08-trusted-devices-empty-after-untrust.png) | Trusted Devices after **Untrust all** — "All devices untrusted." and the empty state. |
|
|
| 9 | [`walkthrough-09-login-2fa-required-after-untrust.png`](walkthrough-09-login-2fa-required-after-untrust.png) | The next sign-in **re-prompting for the TOTP step** — proof that untrust-all cleared the local trust token. |
|